Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

121–130 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#121
post #57
post #11

A $1.3 billion revenue company being too tight to pay this after all, even on their 2nd chance, is so short-sighted it's absurd. They're putting out a huge sign saying "When you find a vuln, definitely contact all our clients because we won't be giving you a penny!". Incredible. This must be some kind of "damaged ego" or ass-covering, as it's clearly not a rational decision. Edit: Another user here has pointed out th…

It all makes sense if you consider bug bounties are largely: 1) created for the purpose of either PR/marketing, or a checklist ("auditing"), 2) seen as a cheaper alternative to someone who knows anything about security - "why hire someone that actually knows anything about security when we can just pay a pittance to strangers and believe every word they say?" The amusing and ironic thing about the second point is tha…

I don’t agree. Bug bounties are taken seriously by at least some companies. Where I have worked, we received very useful reports, some very severe, via HackerOne.

The company even ran special sessions where engineers and hackers were brought together to try to maximize the number of bugs found in a few week period.

It resulted in more secure software at the end and a community of excited researchers trying to make some money and fame on our behalf.

The root cause in this case seems to be that they couldn’t get by HackerOne’s triage process because Zendesk excluded email from being in scope. This seems more like incompetence than malice on both of their parts. Good that the researcher showed how foolish they were.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#123
post #36
post #2

The edited title on HN is incomprehensible. The original is: ”1 bug, $50,000+ in bounties, how Zendesk intentionally left a backdoor in hundreds of Fortune 500 companies” A better edit might be something like: “The $50k bug where Zendesk backdoored Fortune 500 companies”

It was supposed to be 1 bug, 50k: I don't know why the "1" got dropped.

HN mangles submission titles.

If you submit "Why I care" it'll decide that you meant 'I care".

If you submit "10 More Secrets in Pokemon" it'll decide you meamt "More Secrets in Pokemon".

Conversely, there's an entire cottage industry focused on writing attention-catching headlines, which results in patterns like what HN mangles.

If it's annoying, OP can edit immediately after submitting to overwrite the mangled title with the correct one.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#124
While obviously Zendesk leaving such a huge hole was the main reason for this exploit (you should obviously fail closed when email signals suggest it’s an unauthenticated address), a contributing factor is that Apple forced themselves to be added as an SSO provider.

So the hacks put in place to deal with Google SSO hadn’t been put in place for Apple’s.

Also, what Fortune 500 company is leaving slack’s email based login feature enabled? Why wouldn’t they all be using a corporate SSO solution tied to their company’s slack directory?

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#126

Earlier quoted context omitted.

If I am not mistaken, it wasn't zendesk that didn't want to recognize the bug, but HackerOne that did not escalate to Zendesk that they should reconsider the exclusion ground in this case. As an aside, I wonder if those bounties in general reflect the real value of those bugs. The economic damage could be way higher, given that people share logins in support tickets. I would have expected that the price on the black…

The author specifically stated: "Realizing this, I asked for the report to be forwarded to an actual Zendesk staff member for review", before getting another reply for H1. I read this as they escalated it to Zendesk directly, who directed it back to HackerOne.

It wasn't clear to me as even at that point it was an "H1 Mediator" who responded.

Also the bit about SPF, DKIM and DMARC seems to show a misunderstanding of the issue: these are typically excluded because large companies aren't able to do full enforcement on their email domains due to legacy. It's a common bug report.

In this case, the problem was that Zendesk wasn't validating emails from external systems.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#127

Earlier quoted context omitted.

[flagged]

Never said that, but a competent engineer should be able to build like 75% of the main functionality of Zendesk over a weekend. Now, I understand there's probably a lot more to it which is why I would expect it to be a company of around 50 engineers and 150 business/marketing/etc and that's being generous. The hill I'd die on is that, with money not being a scarce resource and a technically feasible challenge present…

Just pick the 50 people who can weekend something and you'll be set to build any 5 things.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#128
post #53

Wait... it looks like Zendesk only fixed the issue of Apple account verification emails being added to tickets, not actually the underlying issue? >In addition to this, we also implemented filters to automatically suspend the following classes of emails: User verification emails sent by Apple based on the Reply-To and Message-Id header values Non-transactional emails from from googleworkspace-noreply@google.com Over…

[deleted]

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#129
post #82
post #3

It sounds like the author got stiffed by Zendesk on this bug, $0 due to email spoofing being out of scope. The $50k was from other bug bounties he was awarded on hackerone. It's too bad Zendesk basically said "thanks" but then refused to pay anything. That's a good way to get people not to bother with your big bounty program. It is often better to build goodwill than to be a stickler for rules and technicalities. Sid…

> due to email spoofing being out of scope. I believe their logic was that only the domain owner can adequately prevent email spoofing by proper SPF/DMARC configuration, and that it’s the customers’ fault if they don’t do that. Which isn’t entirely wrong.

Are Google and Apple not doing proper SPF/DMARC/DKIM? I think they probably are - but this attack worked anyway.

Zendesk wasn't validating the email senders.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#130
post #20

Another example of how weasley Zendesk can be: They created a fake band called "Zendesk Alternative" just in an attempt to pollute the Google results if you search for an alternative to Zendesk. http://zendeskalternative.com/ While not illegal, it shows the way they think, a sort of manipulative pettiness.

Interesting technique but on my side I see it at the very bottom of the second page of Google so I don't think it's very effective.

It’s from 2016, so probably lost its mojo.
Post reply on HN