Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

221–230 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#221

Earlier quoted context omitted.

Out of curiosity, do you know of open source projects or any resources that someone less familiar with SSO can use/read to properly implement SSO?

Something like Keycloak?

I think they're asking for advice on how to more reliably implement the RP side.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#222

Earlier quoted context omitted.

This feels like a case in the gray area. On the one hand, companies need to declare certain stuff out of scope - whether they know about it and are planning to work on it, or consider it acceptable risk, as the point for the company is to help them improve their security posture within the scope of the resources they have to run the bug bounty program. What's weird here is that the blog author found an email problem…

>Without a broader PoC to show how it could be weaponized, it's hard to say that Zendesk was egregiously wrong here There was a PoC of how to view someone else's ticket (assuming you know the other person's email and approximately when the ticket was filed). >it's not crazy to think a security engineer reading the report may assume that stuff would cover their butts It sounds like they got a report saying "I can spoo…

I suppose my point is "read someone else's ticket" is far from the worst case scenario here. It certainly sounds like zendesk didn't care to protect ticket contents ... Which the more I think about it is pretty egregious, as support tickets can include PII.

In general, I do expect for the folks reading hackerone reports to make some mistakes; there's a lot of people who will just run a vulnerability scanner and report all the results like they've done something useful. Sometimes for real bugs you have to explain the impact with a good "look what I can do with this."

Also, the poster didn't share their submission with us, just the responses. So it's hard to know how clear they were to zendesk. A good bug with a bag explanation o would not expect to get paid

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#223
post #213
post #46

Earlier quoted context omitted.

“I will consider not disclosing if you compensate me for my time.”

You can't ask for money in exchange for not revealing a bug. That's blackmail which is illegal and ethically dubious. White hat hackers do not require companies to pay them in exchange for not revealing a bug---the reveal of a bug only happens if a company doesn't fix that bug. Companies can be jerks and refuse to pay anything. That doesn't give you the right to blackmail them---you and other security researchers can…

I don't think this is true. I'm not a lawyer and this is not legal advice, but I think it's hard to fit the elements of an extortion statute to a "threat" to disclose the results of technical research work you yourself did. Moreover, if a vendor is working with HackerOne, they've already implicitly consented to their norm of non-disclosure in exchange for payment. Further, in something like 15 years of bounty programs, I haven't heard of any cases like this having been filed --- and bounty researchers threaten to publish all the time.

I also disagree that there's anything ethically dubious about it.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#224

The piece the author is missing, and why zendesk likely ignored this is impact, and it's something I continually see submissions lacking. As a researcher, if you can't demonstrate impact of your vulnerability, then it looks like just another bug. A public program like zendesk is going to be swamped with reports, and they're using hackerone triagers to augment that volume. The triage system reads through a lot of repo…

I think this is (descriptively) correct, but it's a difficult point to make in a message board argument because of hindsight bias.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#225
If you want to understand the dynamics of what happened here, a very important detail is that the bounty hunter's report implicated DKIM and SPF, and no bug bounty program in the world takes DKIM reports seriously. DKIM is the archetypical beg bounty. You could find DKIM RCE and HackerOne would still round file your report.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#226

Earlier quoted context omitted.

CFAA?

which puts the liability on the person that does the unauthorized access not about else and especially not for merely browsing or using or buying a legal good from a dark net market as I wrote

Accessory?

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#227
post #57

Earlier quoted context omitted.

It all makes sense if you consider bug bounties are largely: 1) created for the purpose of either PR/marketing, or a checklist ("auditing"), 2) seen as a cheaper alternative to someone who knows anything about security - "why hire someone that actually knows anything about security when we can just pay a pittance to strangers and believe every word they say?" The amusing and ironic thing about the second point is tha…

I don’t agree. Bug bounties are taken seriously by at least some companies. Where I have worked, we received very useful reports, some very severe, via HackerOne. The company even ran special sessions where engineers and hackers were brought together to try to maximize the number of bugs found in a few week period. It resulted in more secure software at the end and a community of excited researchers trying to make so…

I use a competitor to HackerOne. I view all submissions pre-triage and would have taken it seriously, even if I made a mistake in program scope. I have paid researchers for bugs out of scope before because they were right.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#228
post #227

Earlier quoted context omitted.

I don’t agree. Bug bounties are taken seriously by at least some companies. Where I have worked, we received very useful reports, some very severe, via HackerOne. The company even ran special sessions where engineers and hackers were brought together to try to maximize the number of bugs found in a few week period. It resulted in more secure software at the end and a community of excited researchers trying to make so…

I use a competitor to HackerOne. I view all submissions pre-triage and would have taken it seriously, even if I made a mistake in program scope. I have paid researchers for bugs out of scope before because they were right.

You can also view all submissions in h1 pre triage. This was incompetence on both h1 and zendesk as gp stated not a limitation of the platform per se.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#229
post #20

Another example of how weasley Zendesk can be: They created a fake band called "Zendesk Alternative" just in an attempt to pollute the Google results if you search for an alternative to Zendesk. http://zendeskalternative.com/ While not illegal, it shows the way they think, a sort of manipulative pettiness.

> It might make you nervous, but this is our purpose.

I love the self report :^)

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#230
post #211

Earlier quoted context omitted.

HackerOne is an awful company with a terrible product. Not the first time I’ve heard of their triage process or software getting in the way of actual bug bounty.

They all are. Bugcrowd once told me that, "yes, it's not a security issue or even a bug, but we recommend providing small (100€) rewards for non-bugs to keep researchers engaged!"

Everything is bad sounds like a defeatist stance. Fact is they are better than triaging everything yourself and also better than outright ignoring all vuln reports.

It’s an imperfect system I agree - but it’s the best we have

Post reply on HN