Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

161–170 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#161
post #57
post #11

A $1.3 billion revenue company being too tight to pay this after all, even on their 2nd chance, is so short-sighted it's absurd. They're putting out a huge sign saying "When you find a vuln, definitely contact all our clients because we won't be giving you a penny!". Incredible. This must be some kind of "damaged ego" or ass-covering, as it's clearly not a rational decision. Edit: Another user here has pointed out th…

It all makes sense if you consider bug bounties are largely: 1) created for the purpose of either PR/marketing, or a checklist ("auditing"), 2) seen as a cheaper alternative to someone who knows anything about security - "why hire someone that actually knows anything about security when we can just pay a pittance to strangers and believe every word they say?" The amusing and ironic thing about the second point is tha…

“2) seen as a cheaper alternative to someone who knows anything about security - "why hire someone that actually knows anything about security when we can just pay a pittance to strangers and believe every word they say?"”

It doesn’t make sense, companies with less revenue aren’t the ones doing this. It’s usually the richer tech companies.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#162
post #140
post #99

Earlier quoted context omitted.

If it's anything like ServiceNow, they have insane feature bloat and poor overall software architecture.

Every single click in ServiceNow takes a full 2 seconds to do anything. For a ticketing system. Insane. What’s more insane is that it is still better than the vast majority of ticketing software. I don’t know what it is about ticketing and Helpdesk that it ALwAYs ends up like that.

We are using Helpscout wich is very nice over all. The also do not send the weirdly formatted ticket email, with 'respond above this line' etc.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#163
post #150

Earlier quoted context omitted.

The attack requires getting yourself CC’d on a support ticket. In this case to show how bad that is, it was a support ticket that had an oauth ticket to log into slack as “support@company.com”.

From the description, sending an email to support@company.com creates a support ticket, to which you can later latch on by adding a Cc. My understandig is that, at least in order to get the full history of a ticket, including any other emails sent to support-$ticket-ID@company.com, the primary sender needs to be from the company as well. Otherwise, why would you need the Cc hack?

My understanding is that, the original sender (spoofed apple in this case) can send the reply to support-$ticket-$id@ with CC field to grant full access to the thread for CC'ed email.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#164

Earlier quoted context omitted.

I am actually seriously interested in what people there do day to day. I’m wondering this about a lot of very large companies, I would definitely watch a documentary about that.

Hour-long meetings about whether the copy should read "data center," "datacenter," "data-center," or whether it is really even correct to say any of these at all. And then negotiating with the design folks to fit in the extra character. Only to throw it all away because nobody thought about the fact that it has to support 5 different languages. I wish I was kidding. Used to work at a place that did crap like that, pu…

I had a similar meeting with documentation folks about "dataset" vs. "data set". With Google trend charts and all... I also wish I was kidding.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#165
post #141
post #20

Another example of how weasley Zendesk can be: They created a fake band called "Zendesk Alternative" just in an attempt to pollute the Google results if you search for an alternative to Zendesk. http://zendeskalternative.com/ While not illegal, it shows the way they think, a sort of manipulative pettiness.

I have a similar conspiracy theory for DDG, the rapper. I used to go to DuckDuckGo by typing "ddg" in Google. Now, it's all mentions to DDG the rapper.

https://duck.com works.

Ironically, the domain was given to DDG from Google.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#167
post #161
post #57

Earlier quoted context omitted.

It all makes sense if you consider bug bounties are largely: 1) created for the purpose of either PR/marketing, or a checklist ("auditing"), 2) seen as a cheaper alternative to someone who knows anything about security - "why hire someone that actually knows anything about security when we can just pay a pittance to strangers and believe every word they say?" The amusing and ironic thing about the second point is tha…

“2) seen as a cheaper alternative to someone who knows anything about security - "why hire someone that actually knows anything about security when we can just pay a pittance to strangers and believe every word they say?"” It doesn’t make sense, companies with less revenue aren’t the ones doing this. It’s usually the richer tech companies.

>It doesn’t make sense, companies with less revenue aren’t the ones doing this. It’s usually the richer tech companies.

Because for some reason, it's larger tech companies that love to bean-count their way through security.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#168
post #87
post #60

Earlier quoted context omitted.

This is worse than Docusign. What do 6000 people at Zendesk do? It's a simple ticket management software with maybe 10 features

If you google "Zendesk annual revenue" you will find that perhaps many of those 6000 employees are doing something after all.

Big companies are places where you get kudos for only taking two weeks to solve a problem you’ve solved elsewhere in two days. To an extent it’s Little’s Law. The latency requires more “CPUs” to handle the traffic.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#170
post #98
post #38

Earlier quoted context omitted.

I think paulpauper is saying the researcher that finds the vulnerability needs a lawyer.

I thought the point of bug bounties was to incentivize whitehat behavior, not scare them off with legal BS. Lol.

Tarpit?
Post reply on HN