Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

41–50 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#42
From what I can tell, the vulnerability wasn't even fixed: they just.. changed their spam filter? Whatever that means.

So for this to work still, you need to bypass a spam filter.

They should just force DMARC and SPF like Google has done, and say "your fault if you misconfigure". Also default-off for the CC thing would be a good idea, too, with a warning of what could happen if they turn it on. Alternatively making a non-guessable id for the email.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#43

The piece the author is missing, and why zendesk likely ignored this is impact, and it's something I continually see submissions lacking. As a researcher, if you can't demonstrate impact of your vulnerability, then it looks like just another bug. A public program like zendesk is going to be swamped with reports, and they're using hackerone triagers to augment that volume. The triage system reads through a lot of repo…

"If you won't illustrate the impact of our mistake, we aren't obligated to listen to you" is peak CYA

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#44
This is clever hack and a reminder of how a chain of smaller security issues (guessable ticket IDs, email spoofing, automatically adding emails to tickets, etc.) can lead to larger ones.

Zendesk deserve a lot of flack here, especially after they already realized this is real. However, just to empathize a bit: the amount of spam SPF, DKIM, DMARC "security" reports anyone running a service gets is absolutely insane. So it's very easy to accidentally misclassify what this reporter originally discovered as that by accident.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#45
post #36
post #2

The edited title on HN is incomprehensible. The original is: ”1 bug, $50,000+ in bounties, how Zendesk intentionally left a backdoor in hundreds of Fortune 500 companies” A better edit might be something like: “The $50k bug where Zendesk backdoored Fortune 500 companies”

It was supposed to be 1 bug, 50k: I don't know why the "1" got dropped.

[deleted]

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#46
post #31

The worse part:"We kindly request you keep this report between you and Zendesk". After being notified of a problem on their side, them ignoring it, now they want to keep things hush hush? That's exactly what the author did in the first place, but they chose to brush it aside. That itself is highly unprofessional. With such an attitude, I'm not surprised that they did not pay out the bounty.

“I will consider not disclosing if you compensate me for my time.”

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#47
post #20

Another example of how weasley Zendesk can be: They created a fake band called "Zendesk Alternative" just in an attempt to pollute the Google results if you search for an alternative to Zendesk. http://zendeskalternative.com/ While not illegal, it shows the way they think, a sort of manipulative pettiness.

Google Sliding - Prince Andrew kinda blew the "subtly" of it with his banger about pizza-human trafficking.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#48
Slack seems to be getting off too easy here. The security—as implemented by Fortune 500 customers??—of an org-wide security domain (i.e. what everyone in an org can see) depends on whether any of the supported OAuth providers can be tricked into provisioning an account with @targetorg.com?

This architecture makes 0 sense to me. Even if an org has totally outsourced its identity and auth management to Google (is this possible?), presumably that would include controls over how new @targetorg.com identities are created on the Google end.

No F500 companies are using Apple as an identity provider since they definitely don't sell such services. So why would an F500 company configure Slack to allow Apple OAuth & introduce this vulnerability?

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#49
> Personally, I’ve always found it surprising that these massive companies, worth billions, rely on third-party tools like Zendesk instead of building their own in-house ticketing systems.

Do you find it surprising that they use Microsoft Office too? Paying someone else to handle things like this is cheaper than paying developers and hosting a service like this.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#50
post #20

Another example of how weasley Zendesk can be: They created a fake band called "Zendesk Alternative" just in an attempt to pollute the Google results if you search for an alternative to Zendesk. http://zendeskalternative.com/ While not illegal, it shows the way they think, a sort of manipulative pettiness.

That is pretty bizarre.

Edit: Why don’t they seem to value their credibility?

Post reply on HN