1 bug, $50k in bounties, a Zendesk backdoor
251–260 of 437 posts
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#252I've been making money finding bugs for H1 and have made >100k. I finally stopped when two large companies have stopped communicating with me over the last year (all bugs have been triaged on the H1 side). They owe me a total of around 30k. H1 can't do anything about it. It seems there is no actual contract in place to protect researchers.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#253Re: 1 bug, $50k in bounties, a Zendesk backdoor
#254Earlier quoted context omitted.
HackerOne’s mediator dropped the ball here They should absolutely inform a client company of a perceived threat, when they agree on the threat Most of the person’s post and responses here are about Zendesk’s issue, but Zendesk was never informed for a better PR response, I think now Zendesk could reward this after realizing it wouldnt have been disclosed first, and admonish HackerOne for not informing them and the cu…
> Most of the person’s post and responses here are about Zendesk’s issue, but Zendesk was never informed It's not clear whether they were informed. The mediator's email says "after consultations with *the team*", which is likely referring to Zendesk's security team.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#255Our team at Zendesk has posted some more details about this bug here: https://support.zendesk.com/hc/en-us/articles/8187090244506-...
What was the planned response for addressing the vulnerability reported through the Bug Bounty program, and how did the plan change after the researcher escalated the issue directly to Zendesk before remediation was completed?
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#256Re: 1 bug, $50k in bounties, a Zendesk backdoor
#257Earlier quoted context omitted.
>Without a broader PoC to show how it could be weaponized, it's hard to say that Zendesk was egregiously wrong here The implications of being able to read arbitrary email contents from arbitrary domains' support (or otherwise) addresses are well known, and any competent security personnel in ZenDesk's security team should know this is exactly what can happen. Something similar has been discussed on HN before: https:/…
I agree it's bad, but you are assuming a lot of institutional memory which may not exist
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#258Our team at Zendesk has posted some more details about this bug here: https://support.zendesk.com/hc/en-us/articles/8187090244506-...
2. "they violated key ethical principles by directly contacting third parties about their report prior to remediation", what is a violation of ethical principles is to know about a security failure in your application and ignore it, leaving customers at risk, can't wait for some law to pass so people who behave like that face consequences.
3. "We have no evidence that this vulnerability was exploited by a bad actor.", tldr, it don't fixed it until some vendor dropped us, because before that happened, it was cheaper to ignore it.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#259Earlier quoted context omitted.
> A $1.3 billion revenue company being too tight to pay this after all, even on their 2nd chance, is so short-sighted it's absurd. I'll give an "another side" perspective. My company was much smaller. Out of 10+ "I found a vulnerability" emails I got last year, all were something like mass-produced emails generated based on an automated vulnerability scanning tool. Investigating all of those for "is it really an issu…
We have a policy to never acknowledge unsolicited emails like that unless they follow the simple instructions set-out in our /.well-known/security.txt file (see https://en.wikipedia.org/wiki/Security.txt ) - honestly all they have to do is put “I put a banana in my fridge” as the message subject (or use PGP/GPG/SMIME) and it’ll be instantly prioritised. The logic being that any actual security-researcher with even mi…
They also had a security.txt file and had received several emails through that, but all of it was spam. Ironically they had received more real security vulnerabilities through people contacting them on LinkedIn than through their security.txt file.
Your milage may vary, but it didn’t seem like the security.txt file was read by the people one would hope would read it.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#260Earlier quoted context omitted.
I have a similar conspiracy theory for DDG, the rapper. I used to go to DuckDuckGo by typing "ddg" in Google. Now, it's all mentions to DDG the rapper.
https://duck.com works. Ironically, the domain was given to DDG from Google.