The piece the author is missing, and why zendesk likely ignored this is impact, and it's something I continually see submissions lacking. As a researcher, if you can't demonstrate impact of your vulnerability, then it looks like just another bug. A public program like zendesk is going to be swamped with reports, and they're using hackerone triagers to augment that volume. The triage system reads through a lot of repo…
I think this is (descriptively) correct, but it's a difficult point to make in a message board argument because of hindsight bias.
1 bug, $50k in bounties, a Zendesk backdoor
371–380 of 437 posts
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#372Earlier quoted context omitted.
Presumably one of the PMs you’re referring to has posted this article for additional information. Feels like they’re doubling down on their initial position. https://support.zendesk.com/hc/en-us/articles/8187090244506-...
In damage control mode, Zendesk can't pay a bounty out here? Come on. This is amateur hour. The reputational damage that comes from "the company that goes on the offensive and doesn't pay out legitimate bounties" impacts the overall results you get from a bug bounty program. "Pissing off the hackers" is not a way to keep people reporting credible bugs to your service. I don't understand what this tries to accomplish.…
That doesn’t matter if your goal with a bug bounty program is not to have people reporting bugs, but instead to have the company appear to care about security. If your only aim is to appear serious about security, it doesn’t matter what you actually do with any bug reports. Until the bugs are made public, of course, which is why companies so often try to stop this by any means.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#373Earlier quoted context omitted.
>but actually kinda charmed by this quirky marketing gimmick. I'm actually pretty annoyed at the stupidity, it's the kind of thing that even a shitty search engine won't be fooled by and hey when I search for Zendesk alternatives I don't see any brand called Zendesk alternative in first few results. I mean it's like they're too stupid to do what every other weaselly scumbag does, get some fake reviews up comparing yo…
> it's the kind of thing that even a shitty search engine won't be fooled by Searching `Zendesk alternative` (no s, no quotes): - Google shows it in the top 5 results. - Bing shows it on the second page. - Brave shows it in the middle of the first page. - DDG doesn't show it. - Yahoo shows it on page 3 - Yandex doesn't show it
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#374Earlier quoted context omitted.
>but actually kinda charmed by this quirky marketing gimmick. I'm actually pretty annoyed at the stupidity, it's the kind of thing that even a shitty search engine won't be fooled by and hey when I search for Zendesk alternatives I don't see any brand called Zendesk alternative in first few results. I mean it's like they're too stupid to do what every other weaselly scumbag does, get some fake reviews up comparing yo…
> wouldn't be fooled So no harm, no foul, right?
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#375Reported this exact bug to Zendesk, Apple, and Slack in June 2024, both through HackerOne and by escalating directly to engs or PMs at each company. I doubt we were the first. That is presumably the reason they failed to pay out. The real issue is that non-directory SSO options like Sign in with Apple (SIWA) have been incorrectly implemented almost everywhere, including by Slack and other large companies we alerted i…
I do web app testing and report a similar issue as a risk rather often to my clients. You can replace Google below with many other identity providers. Imagine Bob works at Example Inc. and has email address bob@example.com Bob can get a Google account with primary email address bob@example.com. He can legitimately pass verification. Bob then gets fired for fraud or sexual harassment or something else gross misconduct…
When you're setting it up, you can choose what to do with any existing accounts that are part of your domain: kick them out or merge them in.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#376Earlier quoted context omitted.
HackerOne’s mediator dropped the ball here They should absolutely inform a client company of a perceived threat, when they agree on the threat Most of the person’s post and responses here are about Zendesk’s issue, but Zendesk was never informed for a better PR response, I think now Zendesk could reward this after realizing it wouldnt have been disclosed first, and admonish HackerOne for not informing them and the cu…
Zendesk was informed. OP specifically said they asked h1 to escalate to the company itself and the second email they present way from someone from Zendesk, who still rejected them, adding that this decision was made “after consulting with the team”.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#377It sounds like the author got stiffed by Zendesk on this bug, $0 due to email spoofing being out of scope. The $50k was from other bug bounties he was awarded on hackerone. It's too bad Zendesk basically said "thanks" but then refused to pay anything. That's a good way to get people not to bother with your big bounty program. It is often better to build goodwill than to be a stickler for rules and technicalities. Sid…
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#378Earlier quoted context omitted.
The author specifically stated: "Realizing this, I asked for the report to be forwarded to an actual Zendesk staff member for review", before getting another reply for H1. I read this as they escalated it to Zendesk directly, who directed it back to HackerOne.
It wasn't clear to me as even at that point it was an "H1 Mediator" who responded. Also the bit about SPF, DKIM and DMARC seems to show a misunderstanding of the issue: these are typically excluded because large companies aren't able to do full enforcement on their email domains due to legacy. It's a common bug report. In this case, the problem was that Zendesk wasn't validating emails from external systems.
The audacity to say "this is out of scope" then "how dare you tell anyone else" is something else.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#379>Personally, I’ve always found it surprising that these massive companies, worth billions, rely on third-party tools like Zendesk instead of building their own in-house ticketing systems. Ah, yes, why do laymen always think this? I mean, I get it, Krupp and mining towns used to be a thing, so it is possible. But every big company should build a ticketing system? Why not an email solution, OS, network routers too?
As someone else mentioned, he is 15. I would have thought the same thing when I was his age.
Re: 1 bug, $50k in bounties, a Zendesk backdoor
#380Earlier quoted context omitted.
(There's a not-very-convincing argument that they declared the ability to view support tickets as out of scope, but were not given a chance to assess the Slack takeover exploit's scope.)
The Slack takeover exploit is a problem on Slack's end (and sounds more like a configuration issue than a bug) so Zendesk would not be responsible for that anyway though.