Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

191–200 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#191

This was a great writeup, really clear and engagingly written, about an interesting and subtle bug. If the author hadn't mentioned they were 15 I would have assumed it was from a seasoned security professional. To Daniel/hackermondev: whatever you're doing, keep it up!

Agreed, if I was hiring and the author applied, I would base most of my decision on the quality of this article alone. Just goes to show how engaging communication beats whiteboard interviews, at least for me.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#192
post #57

Earlier quoted context omitted.

It all makes sense if you consider bug bounties are largely: 1) created for the purpose of either PR/marketing, or a checklist ("auditing"), 2) seen as a cheaper alternative to someone who knows anything about security - "why hire someone that actually knows anything about security when we can just pay a pittance to strangers and believe every word they say?" The amusing and ironic thing about the second point is tha…

I don’t agree. Bug bounties are taken seriously by at least some companies. Where I have worked, we received very useful reports, some very severe, via HackerOne. The company even ran special sessions where engineers and hackers were brought together to try to maximize the number of bugs found in a few week period. It resulted in more secure software at the end and a community of excited researchers trying to make so…

HackerOne is an awful company with a terrible product. Not the first time I’ve heard of their triage process or software getting in the way of actual bug bounty.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#193
post #11

A $1.3 billion revenue company being too tight to pay this after all, even on their 2nd chance, is so short-sighted it's absurd. They're putting out a huge sign saying "When you find a vuln, definitely contact all our clients because we won't be giving you a penny!". Incredible. This must be some kind of "damaged ego" or ass-covering, as it's clearly not a rational decision. Edit: Another user here has pointed out th…

> A $1.3 billion revenue company being too tight to pay this after all, even on their 2nd chance, is so short-sighted it's absurd.

I'll give an "another side" perspective. My company was much smaller. Out of 10+ "I found a vulnerability" emails I got last year, all were something like mass-produced emails generated based on an automated vulnerability scanning tool.

Investigating all of those for "is it really an issue" is more work than it seems. For many companies looking to improve security, there are higher ROI things to do than investigating all of those emails.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#194
post #18

Zendesk pay the man. He disclosed only after you waved it off as a nonthreat. Pay. The. Man.

Not even really 'disclosing' but just reporting to affected parties that they've got a problem

That this hurts Zendesk is too bad, it's still the morally correct thing to do and Zendesk probably understands that, too

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#195
post #68

Earlier quoted context omitted.

Software developers being surprised that software companies need to do a lot more than just write code is kind of like sailors being surprised that global logistics involves a lot more than handling a ship.

Still naive enough to buy into the lie that they can just be “left alone to do the REAL work” and a business just…spontaneously appears around them.

Solopreneurs making millions just like Pieter Levels are giving wrong impression.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#196
post #21

I help corporates evaluate and buy software. Having an ineffective bug bounty program, especially one that rewards black market activity on a terms & conditions technicality like this, is enough for me to put a black mark on your software services. I don’t care if you’re the only company in the market, I’ll still blackball you for this in my recommendations. Zendesk should pay up, apologize and correct their bug boun…

HackerOne’s mediator dropped the ball here

They should absolutely inform a client company of a perceived threat, when they agree on the threat

Most of the person’s post and responses here are about Zendesk’s issue, but Zendesk was never informed

for a better PR response, I think now Zendesk could reward this after realizing it wouldnt have been disclosed first, and admonish HackerOne for not informing them and the current policies there

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#197
post #97

Slack seems to be getting off too easy here. The security—as implemented by Fortune 500 customers??—of an org-wide security domain (i.e. what everyone in an org can see) depends on whether any of the supported OAuth providers can be tricked into provisioning an account with @targetorg.com? This architecture makes 0 sense to me. Even if an org has totally outsourced its identity and auth management to Google (is this…

If you're using Google for identity and authentication, you can definitely control who has an active account in your domain. There can be some lag time before disabling or removing someone truly disables all their downstream accesses, but that's largely outside Google's control. The only way to trick your way into getting a corporate domain email address is to socially engineer a domain admin. Tangentially, this does…

You can also create a non-email Google account as Bob+external@example.com, as long as you can get email sent to bob@example.com (ie, while you are employed by Example, Inc). Then, you leave your job, but still have a google account associated with an example.com email. Depending on how the app checks the login response, they might mistakenly assume you are part of the example.com org.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#198
post #21

I help corporates evaluate and buy software. Having an ineffective bug bounty program, especially one that rewards black market activity on a terms & conditions technicality like this, is enough for me to put a black mark on your software services. I don’t care if you’re the only company in the market, I’ll still blackball you for this in my recommendations. Zendesk should pay up, apologize and correct their bug boun…

HackerOne’s mediator dropped the ball here They should absolutely inform a client company of a perceived threat, when they agree on the threat Most of the person’s post and responses here are about Zendesk’s issue, but Zendesk was never informed for a better PR response, I think now Zendesk could reward this after realizing it wouldnt have been disclosed first, and admonish HackerOne for not informing them and the cu…

> Most of the person’s post and responses here are about Zendesk’s issue, but Zendesk was never informed

It's not clear whether they were informed. The mediator's email says "after consultations with *the team*", which is likely referring to Zendesk's security team.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#199
post #11

A $1.3 billion revenue company being too tight to pay this after all, even on their 2nd chance, is so short-sighted it's absurd. They're putting out a huge sign saying "When you find a vuln, definitely contact all our clients because we won't be giving you a penny!". Incredible. This must be some kind of "damaged ego" or ass-covering, as it's clearly not a rational decision. Edit: Another user here has pointed out th…

it never made sense to me why these white-hat hackers don't require payment before disclosing the vulnerability

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#200
post #152
post #129

Earlier quoted context omitted.

Are Google and Apple not doing proper SPF/DMARC/DKIM? I think they probably are - but this attack worked anyway. Zendesk wasn't validating the email senders.

Apple and Google weren’t involved as email sender addresses.

Read the repro steps again:

> Create an Apple account with support@company.com email and request a verification code, Apple sends verification code from appleid@id.apple.com to support@company.com and Zendesk automatically creates a ticket

It's a clever attack.

Post reply on HN