Earlier quoted context omitted.
Out of curiosity, do you know of open source projects or any resources that someone less familiar with SSO can use/read to properly implement SSO?
Something like Keycloak?
1 bug, $50k in bounties, a Zendesk backdoor
221–230 of 437 posts
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#222Earlier quoted context omitted.
This feels like a case in the gray area. On the one hand, companies need to declare certain stuff out of scope - whether they know about it and are planning to work on it, or consider it acceptable risk, as the point for the company is to help them improve their security posture within the scope of the resources they have to run the bug bounty program. What's weird here is that the blog author found an email problem…
>Without a broader PoC to show how it could be weaponized, it's hard to say that Zendesk was egregiously wrong here There was a PoC of how to view someone else's ticket (assuming you know the other person's email and approximately when the ticket was filed). >it's not crazy to think a security engineer reading the report may assume that stuff would cover their butts It sounds like they got a report saying "I can spoo…
In general, I do expect for the folks reading hackerone reports to make some mistakes; there's a lot of people who will just run a vulnerability scanner and report all the results like they've done something useful. Sometimes for real bugs you have to explain the impact with a good "look what I can do with this."
Also, the poster didn't share their submission with us, just the responses. So it's hard to know how clear they were to zendesk. A good bug with a bag explanation o would not expect to get paid
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#223Earlier quoted context omitted.
“I will consider not disclosing if you compensate me for my time.”
You can't ask for money in exchange for not revealing a bug. That's blackmail which is illegal and ethically dubious. White hat hackers do not require companies to pay them in exchange for not revealing a bug---the reveal of a bug only happens if a company doesn't fix that bug. Companies can be jerks and refuse to pay anything. That doesn't give you the right to blackmail them---you and other security researchers can…
I also disagree that there's anything ethically dubious about it.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#224The piece the author is missing, and why zendesk likely ignored this is impact, and it's something I continually see submissions lacking. As a researcher, if you can't demonstrate impact of your vulnerability, then it looks like just another bug. A public program like zendesk is going to be swamped with reports, and they're using hackerone triagers to augment that volume. The triage system reads through a lot of repo…
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#225Re: 1 bug, $50k in bounties, a Zendesk backdoor
#226Re: 1 bug, $50k in bounties, a Zendesk backdoor
#227Earlier quoted context omitted.
It all makes sense if you consider bug bounties are largely: 1) created for the purpose of either PR/marketing, or a checklist ("auditing"), 2) seen as a cheaper alternative to someone who knows anything about security - "why hire someone that actually knows anything about security when we can just pay a pittance to strangers and believe every word they say?" The amusing and ironic thing about the second point is tha…
I don’t agree. Bug bounties are taken seriously by at least some companies. Where I have worked, we received very useful reports, some very severe, via HackerOne. The company even ran special sessions where engineers and hackers were brought together to try to maximize the number of bugs found in a few week period. It resulted in more secure software at the end and a community of excited researchers trying to make so…
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#228Earlier quoted context omitted.
I don’t agree. Bug bounties are taken seriously by at least some companies. Where I have worked, we received very useful reports, some very severe, via HackerOne. The company even ran special sessions where engineers and hackers were brought together to try to maximize the number of bugs found in a few week period. It resulted in more secure software at the end and a community of excited researchers trying to make so…
I use a competitor to HackerOne. I view all submissions pre-triage and would have taken it seriously, even if I made a mistake in program scope. I have paid researchers for bugs out of scope before because they were right.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#229Another example of how weasley Zendesk can be: They created a fake band called "Zendesk Alternative" just in an attempt to pollute the Google results if you search for an alternative to Zendesk. http://zendeskalternative.com/ While not illegal, it shows the way they think, a sort of manipulative pettiness.
I love the self report :^)
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#230Earlier quoted context omitted.
HackerOne is an awful company with a terrible product. Not the first time I’ve heard of their triage process or software getting in the way of actual bug bounty.
They all are. Bugcrowd once told me that, "yes, it's not a security issue or even a bug, but we recommend providing small (100€) rewards for non-bugs to keep researchers engaged!"
It’s an imperfect system I agree - but it’s the best we have