Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

211–220 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#211

Earlier quoted context omitted.

I don’t agree. Bug bounties are taken seriously by at least some companies. Where I have worked, we received very useful reports, some very severe, via HackerOne. The company even ran special sessions where engineers and hackers were brought together to try to maximize the number of bugs found in a few week period. It resulted in more secure software at the end and a community of excited researchers trying to make so…

HackerOne is an awful company with a terrible product. Not the first time I’ve heard of their triage process or software getting in the way of actual bug bounty.

They all are. Bugcrowd once told me that, "yes, it's not a security issue or even a bug, but we recommend providing small (100€) rewards for non-bugs to keep researchers engaged!"

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#212

Earlier quoted context omitted.

Our company has a bug bounty program: - handled with priority, but sometimes it takes a couple of weeks for a more definite fix - handled by the security department within the company ( to forward to relevant PO's and to follow up) The unfortunate thing about bug bounties is that you will be hammered with crawlers that would sometimes even resemble a DDOS

> The unfortunate thing about bug bounties is that you will be hammered with crawlers you mean your product will be hammered by people testing to find holes, thus garner the bounty? or some other reason?

Yes. Crawlers, security scanners, ...

Eg. Testing all vulnerable wp plugin paths on all domains. Multiple times a minute

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#213
post #46
post #31

The worse part:"We kindly request you keep this report between you and Zendesk". After being notified of a problem on their side, them ignoring it, now they want to keep things hush hush? That's exactly what the author did in the first place, but they chose to brush it aside. That itself is highly unprofessional. With such an attitude, I'm not surprised that they did not pay out the bounty.

“I will consider not disclosing if you compensate me for my time.”

You can't ask for money in exchange for not revealing a bug. That's blackmail which is illegal and ethically dubious.

White hat hackers do not require companies to pay them in exchange for not revealing a bug---the reveal of a bug only happens if a company doesn't fix that bug. Companies can be jerks and refuse to pay anything. That doesn't give you the right to blackmail them---you and other security researchers can just refuse to help them in the future.

A refusal to fix the vulnerability is what happened in the original blogpost, so it was fair game for release since the company doesn't care.

Hackers that don't care about ethics or legality won't bother blackmailing companies with vulnerabilities. They'll sell or use the vulnerability to steal more important data, and blackmail companies for millions of dollars in crypto.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#214
post #188

Earlier quoted context omitted.

This feels like a case in the gray area. On the one hand, companies need to declare certain stuff out of scope - whether they know about it and are planning to work on it, or consider it acceptable risk, as the point for the company is to help them improve their security posture within the scope of the resources they have to run the bug bounty program. What's weird here is that the blog author found an email problem…

>Without a broader PoC to show how it could be weaponized, it's hard to say that Zendesk was egregiously wrong here The implications of being able to read arbitrary email contents from arbitrary domains' support (or otherwise) addresses are well known, and any competent security personnel in ZenDesk's security team should know this is exactly what can happen. Something similar has been discussed on HN before: https:/…

I agree it's bad, but you are assuming a lot of institutional memory which may not exist

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#216
post #60

Earlier quoted context omitted.

zendesk is 6k employees, they have general council on staff

This is worse than Docusign. What do 6000 people at Zendesk do? It's a simple ticket management software with maybe 10 features

Zendesk is not just one product, they have:

- chat stuff you can embed into your site for user support

- managed call center software

- knowledgebase management linking all the other services

- whitelabel consumer forums you can use for offloading some of the support

- a shitton of analytics

- sales CRM

- profile platform you can link to various sources of information to get info on their activity on your site, so that you can use that for support

And there is probably a few more. Sales CRM alone can be its own company.

As usual on hackernews there is a lot more to it, but you are just not exposed to it.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#217
post #3

It sounds like the author got stiffed by Zendesk on this bug, $0 due to email spoofing being out of scope. The $50k was from other bug bounties he was awarded on hackerone. It's too bad Zendesk basically said "thanks" but then refused to pay anything. That's a good way to get people not to bother with your big bounty program. It is often better to build goodwill than to be a stickler for rules and technicalities. Sid…

I too had the worst interview experience with zendesk. The people I talked to were pretty senior folks too. They just seem to have a very petty and toxic work culture.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#218
post #213
post #46

Earlier quoted context omitted.

“I will consider not disclosing if you compensate me for my time.”

You can't ask for money in exchange for not revealing a bug. That's blackmail which is illegal and ethically dubious. White hat hackers do not require companies to pay them in exchange for not revealing a bug---the reveal of a bug only happens if a company doesn't fix that bug. Companies can be jerks and refuse to pay anything. That doesn't give you the right to blackmail them---you and other security researchers can…

Gotcha. The moment you attach a monetary condition it can be seen as extortion. In that case I believe the only responsible thing to do is disclose using customary, reasonable waiting periods.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#219
post #60

Earlier quoted context omitted.

This is worse than Docusign. What do 6000 people at Zendesk do? It's a simple ticket management software with maybe 10 features

I am actually seriously interested in what people there do day to day. I’m wondering this about a lot of very large companies, I would definitely watch a documentary about that.

I work in one of the biggest companies of the world (employee and revenue wise) and it's basically a run-off reaction of well-articulated desk employees jerking each other off that, telling each other that they are so very important.

And the common management approach to anything not working immediately is "throw another 1.000 employees into the project" and the middle-managers measure their success by how many employees they are managing so it's a train without breaks. Hope it goes bankrupt soon.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#220
post #11

A $1.3 billion revenue company being too tight to pay this after all, even on their 2nd chance, is so short-sighted it's absurd. They're putting out a huge sign saying "When you find a vuln, definitely contact all our clients because we won't be giving you a penny!". Incredible. This must be some kind of "damaged ego" or ass-covering, as it's clearly not a rational decision. Edit: Another user here has pointed out th…

it never made sense to me why these white-hat hackers don't require payment before disclosing the vulnerability

Bug bounty people do this all the time. It's almost always a sign that your bug is something silly, like DKIM.

Later

I wrote this comment before rereading the original post and realizing that they had literally submitted a DKIM report (albeit a rare instance of a meaningful one). Just to be clear: in my original comment, I did not mean to suggest this bug was silly; only that in the world of security bug bounties, DKIM reports are universally viewed as silly.

Post reply on HN