Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

111–120 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#111
post #3

It sounds like the author got stiffed by Zendesk on this bug, $0 due to email spoofing being out of scope. The $50k was from other bug bounties he was awarded on hackerone. It's too bad Zendesk basically said "thanks" but then refused to pay anything. That's a good way to get people not to bother with your big bounty program. It is often better to build goodwill than to be a stickler for rules and technicalities. Sid…

If I am not mistaken, it wasn't zendesk that didn't want to recognize the bug, but HackerOne that did not escalate to Zendesk that they should reconsider the exclusion ground in this case. As an aside, I wonder if those bounties in general reflect the real value of those bugs. The economic damage could be way higher, given that people share logins in support tickets. I would have expected that the price on the black…

The author specifically stated: "Realizing this, I asked for the report to be forwarded to an actual Zendesk staff member for review", before getting another reply for H1. I read this as they escalated it to Zendesk directly, who directed it back to HackerOne.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#112
post #20

Another example of how weasley Zendesk can be: They created a fake band called "Zendesk Alternative" just in an attempt to pollute the Google results if you search for an alternative to Zendesk. http://zendeskalternative.com/ While not illegal, it shows the way they think, a sort of manipulative pettiness.

That sounds more like an April Fool's Day joke than something malicious. These were still fun sometimes back in the days (2016).

I wouldn't read too much into this because one unmaintained old website will not going to make or break the SEO game of others.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#113
post #57

Earlier quoted context omitted.

It all makes sense if you consider bug bounties are largely: 1) created for the purpose of either PR/marketing, or a checklist ("auditing"), 2) seen as a cheaper alternative to someone who knows anything about security - "why hire someone that actually knows anything about security when we can just pay a pittance to strangers and believe every word they say?" The amusing and ironic thing about the second point is tha…

> you waste time with the constant spam of people begging for bounties A great blog post on the matter https://www.troyhunt.com/beg-bounties/

[flagged]

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#114
post #109
post #60

Earlier quoted context omitted.

This is worse than Docusign. What do 6000 people at Zendesk do? It's a simple ticket management software with maybe 10 features

Let me guess, you could build it over the weekend?

Never said that, but a competent engineer should be able to build like 75% of the main functionality of Zendesk over a weekend.

Now, I understand there's probably a lot more to it which is why I would expect it to be a company of around 50 engineers and 150 business/marketing/etc and that's being generous.

The hill I'd die on is that, with money not being a scarce resource and a technically feasible challenge present, a team of 200 should be able to build and sustain almost anything in the world. And that's being even generous. I think realistically a team of 50 should be able to build almost anything

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#115
post #60

Earlier quoted context omitted.

This is worse than Docusign. What do 6000 people at Zendesk do? It's a simple ticket management software with maybe 10 features

[flagged]

Never said that, but a competent engineer should be able to build like 75% of the main functionality of Zendesk over a weekend.

Now, I understand there's probably a lot more to it which is why I would expect it to be a company of around 50 engineers and 150 business/marketing/etc and that's being generous.

The hill I'd die on is that, with money not being a scarce resource and a technically feasible challenge present, a team of 200 should be able to build and sustain almost anything in the world. And that's being even generous. I think realistically a team of 50 should be able to build almost anything

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#117
post #109

Earlier quoted context omitted.

Let me guess, you could build it over the weekend?

Never said that, but a competent engineer should be able to build like 75% of the main functionality of Zendesk over a weekend. Now, I understand there's probably a lot more to it which is why I would expect it to be a company of around 50 engineers and 150 business/marketing/etc and that's being generous. The hill I'd die on is that, with money not being a scarce resource and a technically feasible challenge present…

That’s a very HN take but the reality is that the tech is usually never the hard part. Selling, supporting, legal, all the certifications and enterprise contracts you have to do for a product like that are the hard part.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#118
post #57

Earlier quoted context omitted.

It all makes sense if you consider bug bounties are largely: 1) created for the purpose of either PR/marketing, or a checklist ("auditing"), 2) seen as a cheaper alternative to someone who knows anything about security - "why hire someone that actually knows anything about security when we can just pay a pittance to strangers and believe every word they say?" The amusing and ironic thing about the second point is tha…

> you waste time with the constant spam of people begging for bounties A great blog post on the matter https://www.troyhunt.com/beg-bounties/

It's a great read, but it looks like a number of the screenshots are missing.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#119
post #88
post #42

From what I can tell, the vulnerability wasn't even fixed: they just.. changed their spam filter? Whatever that means. So for this to work still, you need to bypass a spam filter. They should just force DMARC and SPF like Google has done, and say "your fault if you misconfigure". Also default-off for the CC thing would be a good idea, too, with a warning of what could happen if they turn it on. Alternatively making a…

Requiring their customers to implement SPF and DMARC as a hard technical requirement is probably bad for business. And as mentioned in TFA, they do note issues regarding SPF/DMARC in their policy.

I think in this case it's the customers of their customers, e.g. people sending emails to support@acme-corp.com. In that light requiring all emails coming into support@acme-corp.com to have SPF and DMARC is bad for business indeed, not only for Zendesk but probably also for the fictional ACME corp.

EDIT: they absolutley should not use an autoincrementing int as a "support-chain token" though, that's a workaround they could easily do.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#120
post #60

Earlier quoted context omitted.

zendesk is 6k employees, they have general council on staff

This is worse than Docusign. What do 6000 people at Zendesk do? It's a simple ticket management software with maybe 10 features

A lot of them are probably sales and support.
Post reply on HN