Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

201–210 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#201
post #126

Earlier quoted context omitted.

It wasn't clear to me as even at that point it was an "H1 Mediator" who responded. Also the bit about SPF, DKIM and DMARC seems to show a misunderstanding of the issue: these are typically excluded because large companies aren't able to do full enforcement on their email domains due to legacy. It's a common bug report. In this case, the problem was that Zendesk wasn't validating emails from external systems.

In this case, that probably means that H1 had a Zoom or Slack convo with the team and is relaying their decision into text instead of making them write it down themselves.

Yeah probably, but what information did H1 relay to them? Did they read the email, or did they get H1's interpretation of the bug? Because the SPF/DKIM/DMARC stuff really doesn't make sense with context.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#202
In case it's not clear these are the two separate vulnerabilities:

1. Zendesk allows you to add a CC to any existing support ticket by sending a (spoofed) reply from the original requestor's email address to that ticket's Reply-To address and including a CC in the email.

In some circumstances the Reply-To address is based on an auto-incrementing integer so it can be guessed. (Although this may not alway be the case: my email archives show some emails from Zendesk using the integer and other emails using a random alphanumeric string. It seems to vary by company so it might be some sort of configuration setting?)

2. Slack allows third-party domain-wide logins via Sign in with Apple without additional verification that the email belongs to a real person. Here the author of the article pretends to be support@company.com to Slack and Slack lets them into the company.com channel, despite the fact that support@company.com does not actually represent a real user and is only intended to be a receiving email address that forwards into Zendesk. (This sounds more like a configuration problem than anything else though.)

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#203
post #57

Earlier quoted context omitted.

It all makes sense if you consider bug bounties are largely: 1) created for the purpose of either PR/marketing, or a checklist ("auditing"), 2) seen as a cheaper alternative to someone who knows anything about security - "why hire someone that actually knows anything about security when we can just pay a pittance to strangers and believe every word they say?" The amusing and ironic thing about the second point is tha…

Our company has a bug bounty program: - handled with priority, but sometimes it takes a couple of weeks for a more definite fix - handled by the security department within the company ( to forward to relevant PO's and to follow up) The unfortunate thing about bug bounties is that you will be hammered with crawlers that would sometimes even resemble a DDOS

>The unfortunate thing about bug bounties is that you will be hammered with crawlers

you mean your product will be hammered by people testing to find holes, thus garner the bounty? or some other reason?

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#205
post #11

A $1.3 billion revenue company being too tight to pay this after all, even on their 2nd chance, is so short-sighted it's absurd. They're putting out a huge sign saying "When you find a vuln, definitely contact all our clients because we won't be giving you a penny!". Incredible. This must be some kind of "damaged ego" or ass-covering, as it's clearly not a rational decision. Edit: Another user here has pointed out th…

> A $1.3 billion revenue company being too tight to pay this after all, even on their 2nd chance, is so short-sighted it's absurd. I'll give an "another side" perspective. My company was much smaller. Out of 10+ "I found a vulnerability" emails I got last year, all were something like mass-produced emails generated based on an automated vulnerability scanning tool. Investigating all of those for "is it really an issu…

We have a policy to never acknowledge unsolicited emails like that unless they follow the simple instructions set-out in our /.well-known/security.txt file (see https://en.wikipedia.org/wiki/Security.txt) - honestly all they have to do is put “I put a banana in my fridge” as the message subject (or use PGP/GPG/SMIME) and it’ll be instantly prioritised.

The logic being that any actual security-researcher with even minimal levels of competency will know to check the security.txt file and can follow basic instructions; while if any of our actual (paying) users find a security issue then they’ll go through our internal ticket site and not public e-mail anyway - so all that’s left are low-effort vuln-scanner reports - and it’s always the same non-issues like clickjacking (but only when using IE9 for some reason, even though it’s 2024 now…) or people who think their browser’s Web Inspector is a “hacking tool” that allows anyone to edit any data in our system…

And FWIW, I’ve never received a genuine security issue report with an admission of kitchen refrigeration of fruit in the 18 months we’ve had a security.txt file - it’s almost as-if qualified competent professionals don’t operate like an embarrassingly pathetic shakedown.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#207
post #20

Another example of how weasley Zendesk can be: They created a fake band called "Zendesk Alternative" just in an attempt to pollute the Google results if you search for an alternative to Zendesk. http://zendeskalternative.com/ While not illegal, it shows the way they think, a sort of manipulative pettiness.

Also noted that the song (or "lyrics" at least) has "Open Source" in its title so they can position for the "Zendesk Open Source Alternative" long tail. That's evil!

Black hat SEO.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#208
post #21

I help corporates evaluate and buy software. Having an ineffective bug bounty program, especially one that rewards black market activity on a terms & conditions technicality like this, is enough for me to put a black mark on your software services. I don’t care if you’re the only company in the market, I’ll still blackball you for this in my recommendations. Zendesk should pay up, apologize and correct their bug boun…

HackerOne’s mediator dropped the ball here They should absolutely inform a client company of a perceived threat, when they agree on the threat Most of the person’s post and responses here are about Zendesk’s issue, but Zendesk was never informed for a better PR response, I think now Zendesk could reward this after realizing it wouldnt have been disclosed first, and admonish HackerOne for not informing them and the cu…

This is pretty common on H1, probably due to the amount of crap they receive.

If you are a new user expect your first couple reports to be butchered. It seems to me only reports from well known hackers gets carefully analysed.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#209
post #31

The worse part:"We kindly request you keep this report between you and Zendesk". After being notified of a problem on their side, them ignoring it, now they want to keep things hush hush? That's exactly what the author did in the first place, but they chose to brush it aside. That itself is highly unprofessional. With such an attitude, I'm not surprised that they did not pay out the bounty.

The correct procedure when they fuck up and close the report is to ask the report to be made public. Had he done this, this would have been a non issue.

The reason people don't do this is because they think they have something that can be modified into another bug. Which is exactly what happened here.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#210
post #175

Earlier quoted context omitted.

I had a similar meeting with documentation folks about "dataset" vs. "data set". With Google trend charts and all... I also wish I was kidding.

It's not weird to pick one and keep a consistent style, for example by looking at Google or at Wikipedia or some other source if the dictionary lists both or neither, but to have meetings about it?!

Feels like something the technical writers and copy writers should decide around the watercooler if anything.

Smells like being afraid to make a choice, even a tiny one.

Post reply on HN