I've been making money finding bugs for H1 and have made >100k. I finally stopped when two large companies have stopped communicating with me over the last year (all bugs have been triaged on the H1 side). They owe me a total of around 30k. H1 can't do anything about it. It seems there is no actual contract in place to protect researchers.
Same experience where I reported a bug, the company ghosted me, and H1 did not even allow disclosure through their platform. I generally refuse to go through platforms now (also because I really hate being subject to the psychological pressure of a "social credit system", even though I understand why the platforms do it), so if your company doesn't have an alternative reporting form, or refuses bug bounty payouts whe…
1 bug, $50k in bounties, a Zendesk backdoor
271–280 of 437 posts
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#272Earlier quoted context omitted.
Accessory?
Relies on intent of the seller, who would need to be found via a valid subpoena that needs to pass a threshold of cause who would then argue they also sold it to security researchers, journalists and assumed everyone was or didnt discriminate or have any intent at all
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#273Earlier quoted context omitted.
If it's anything like ServiceNow, they have insane feature bloat and poor overall software architecture.
What's interesting is that Frank Slootman touts this transformation as a huge success in his book and talks at length about his conflict with Fred Luddy (who originally authored the simple ticketing incarnation of the ServiceNow monsterblob). The focus on keeping things simple is highlighted as an example of nerds' nearsighted thinking.
Like any SaaS, the more feature boxes you check, the more potential customers you can "satisfy". And the worse the UX gets for the average user (which then gets driven to purchasing more support).
Great for business (the few), terrible for users (the many). No contradiction there.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#274Our team at Zendesk has posted some more details about this bug here: https://support.zendesk.com/hc/en-us/articles/8187090244506-...
According to the researcher, they only contacted 3rd parties after Zendesk rejected the disclosure as out of scope, as they are free to do.
If this timeline is incorrect, Zendesk should immediately correct the record. As it stands, accusing the researcher of violating ethical principles looks very bad for Zendesk. Perhaps even libelous.
That it affected Slack was a side-effect of the original bug, and not a new, previously undisclosed bug. Zendesk fixed the original bug, after rejecting the disclosure. Given all that, Zendesk is still ethically bound to honor the bounty, 3rd party disclosures notwithstanding.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#275Earlier quoted context omitted.
>Without a broader PoC to show how it could be weaponized, it's hard to say that Zendesk was egregiously wrong here There was a PoC of how to view someone else's ticket (assuming you know the other person's email and approximately when the ticket was filed). >it's not crazy to think a security engineer reading the report may assume that stuff would cover their butts It sounds like they got a report saying "I can spoo…
I suppose my point is "read someone else's ticket" is far from the worst case scenario here. It certainly sounds like zendesk didn't care to protect ticket contents ... Which the more I think about it is pretty egregious, as support tickets can include PII. In general, I do expect for the folks reading hackerone reports to make some mistakes; there's a lot of people who will just run a vulnerability scanner and repor…
I'm not sure. Anybody that keeps up to date with security (e.g. those working in a security team) should know that ticketing systems also contains credentials sometimes. For example when Okta was breached, the main concern was that Okta support tickets contain.... session tokens, cookies, and credentials!
https://www.bleepingcomputer.com/news/security/okta-says-its...
What's the point of having a security team that can't directly link external experience to their own system? Learning the same mistakes that have already been known?
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#276Reported this exact bug to Zendesk, Apple, and Slack in June 2024, both through HackerOne and by escalating directly to engs or PMs at each company. I doubt we were the first. That is presumably the reason they failed to pay out. The real issue is that non-directory SSO options like Sign in with Apple (SIWA) have been incorrectly implemented almost everywhere, including by Slack and other large companies we alerted i…
Presumably one of the PMs you’re referring to has posted this article for additional information. Feels like they’re doubling down on their initial position. https://support.zendesk.com/hc/en-us/articles/8187090244506-...
Wow... there was no indication that they even intended on fixing the issue, what was Daniel hackermondev supposed to do? Disclosing this to the affected users probably was the most ethical thing to do. I don't think he posted the vulnerability publicly until after the fix. "Forfeiture of their award" -- they said multiple times that it didn't qualify, they had no intention of ever giving a reward.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#277Re: 1 bug, $50k in bounties, a Zendesk backdoor
#278Earlier quoted context omitted.
Presumably one of the PMs you’re referring to has posted this article for additional information. Feels like they’re doubling down on their initial position. https://support.zendesk.com/hc/en-us/articles/8187090244506-...
> Although the researcher did initially submit the vulnerability through our established process, they violated key ethical principles by directly contacting third parties about their report prior to remediation. This was in violation of bug bounty terms of service, which are industry standard and intended to protect the white hat community while also supporting responsible disclosure. This breach of trust resulted i…
Edit: to those downvoting, the fact of the matter is that Zendesk's maximum bounty is far lower than 50k; yet OP made 50k; meaning by definition the value of the vulnerability was at least 50k.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#279Re: 1 bug, $50k in bounties, a Zendesk backdoor
#280Our team at Zendesk has posted some more details about this bug here: https://support.zendesk.com/hc/en-us/articles/8187090244506-...