Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

251–260 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#252
post #249

I've been making money finding bugs for H1 and have made >100k. I finally stopped when two large companies have stopped communicating with me over the last year (all bugs have been triaged on the H1 side). They owe me a total of around 30k. H1 can't do anything about it. It seems there is no actual contract in place to protect researchers.

Would love to hear more! I’m always eager to add companies to my blacklist.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#254

Earlier quoted context omitted.

HackerOne’s mediator dropped the ball here They should absolutely inform a client company of a perceived threat, when they agree on the threat Most of the person’s post and responses here are about Zendesk’s issue, but Zendesk was never informed for a better PR response, I think now Zendesk could reward this after realizing it wouldnt have been disclosed first, and admonish HackerOne for not informing them and the cu…

> Most of the person’s post and responses here are about Zendesk’s issue, but Zendesk was never informed It's not clear whether they were informed. The mediator's email says "after consultations with *the team*", which is likely referring to Zendesk's security team.

It anyways took Zendesk several months to fix the issue and they also didn’t acknowledge the author with what should be a very sizeable bounty. It’s not every day that someone tries to warn you about a massive security hole and then goes out of their way to warn your clients for you because you ignored them.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#255

Our team at Zendesk has posted some more details about this bug here: https://support.zendesk.com/hc/en-us/articles/8187090244506-...

> We also want to address the Bug Bounty program associated with this case. Although the researcher did initially submit the vulnerability through our established process, they violated key ethical principles by directly contacting third parties about their report prior to remediation.

What was the planned response for addressing the vulnerability reported through the Bug Bounty program, and how did the plan change after the researcher escalated the issue directly to Zendesk before remediation was completed?

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#257
post #188

Earlier quoted context omitted.

>Without a broader PoC to show how it could be weaponized, it's hard to say that Zendesk was egregiously wrong here The implications of being able to read arbitrary email contents from arbitrary domains' support (or otherwise) addresses are well known, and any competent security personnel in ZenDesk's security team should know this is exactly what can happen. Something similar has been discussed on HN before: https:/…

I agree it's bad, but you are assuming a lot of institutional memory which may not exist

Yes, I expect a security engineer to hold knowledge. That's why they have a job, instead of replacing the security them with an LLM. If nobody in the team has that experience, it speaks exactly to the issue that has been outlined in the OP: not enough knowledge of security issues beyond the basics.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#258

Our team at Zendesk has posted some more details about this bug here: https://support.zendesk.com/hc/en-us/articles/8187090244506-...

1. "While this specific issue has been resolved", that was a bug, not an issue.

2. "they violated key ethical principles by directly contacting third parties about their report prior to remediation", what is a violation of ethical principles is to know about a security failure in your application and ignore it, leaving customers at risk, can't wait for some law to pass so people who behave like that face consequences.

3. "We have no evidence that this vulnerability was exploited by a bad actor.", tldr, it don't fixed it until some vendor dropped us, because before that happened, it was cheaper to ignore it.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#259

Earlier quoted context omitted.

> A $1.3 billion revenue company being too tight to pay this after all, even on their 2nd chance, is so short-sighted it's absurd. I'll give an "another side" perspective. My company was much smaller. Out of 10+ "I found a vulnerability" emails I got last year, all were something like mass-produced emails generated based on an automated vulnerability scanning tool. Investigating all of those for "is it really an issu…

We have a policy to never acknowledge unsolicited emails like that unless they follow the simple instructions set-out in our /.well-known/security.txt file (see https://en.wikipedia.org/wiki/Security.txt ) - honestly all they have to do is put “I put a banana in my fridge” as the message subject (or use PGP/GPG/SMIME) and it’ll be instantly prioritised. The logic being that any actual security-researcher with even mi…

I saw a great presentation from Finn.no on their bug bounty program. They had had great success, despite the amount of work it took. Much more so than the three different security companies they hired each year to find vulnerabilities.

They also had a security.txt file and had received several emails through that, but all of it was spam. Ironically they had received more real security vulnerabilities through people contacting them on LinkedIn than through their security.txt file.

Your milage may vary, but it didn’t seem like the security.txt file was read by the people one would hope would read it.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#260
post #141

Earlier quoted context omitted.

I have a similar conspiracy theory for DDG, the rapper. I used to go to DuckDuckGo by typing "ddg" in Google. Now, it's all mentions to DDG the rapper.

https://duck.com works. Ironically, the domain was given to DDG from Google.

https://ddg.co works as well.
Post reply on HN