Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

401–410 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#401
post #392
post #362

Earlier quoted context omitted.

That article claims to have “0 comments”, but currently sits at a score of -7 (negative 7) votes of helpful/not helpful. I think they have turned off comments on that article, but aren’t willing to admit it. EDIT: It’s -11 (negative 11) now. Still “0 comments”.

They have definitely turned off comments. Attempting to post one refreshes the page but nothing happens, and the comment never appears.

Wow, it’s now at -27.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#402
post #213
post #46

Earlier quoted context omitted.

“I will consider not disclosing if you compensate me for my time.”

You can't ask for money in exchange for not revealing a bug. That's blackmail which is illegal and ethically dubious. White hat hackers do not require companies to pay them in exchange for not revealing a bug---the reveal of a bug only happens if a company doesn't fix that bug. Companies can be jerks and refuse to pay anything. That doesn't give you the right to blackmail them---you and other security researchers can…

To correct you, the revealing of a past bug happens almost all the time when a company does fix the bug- that’s what lets researchers publish their findings and show the work they do publicly, and usually gives the company some positive PR for showing their willingness and responsiveness to fix issues. See the CVE program.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#403

Earlier quoted context omitted.

So when the researcher said it was a bug, they said, "No, it's fine. No bug bounty, sorry." THEN the researcher eventually goes public. Later, Zendesk announces the bug and the fix and says there will be no bug bounty because the researcher went public. Is that how it went? I mean if so, that's one way to save on bug bounties.

We have 2 conflicting sides of the story, who knows which one is bullshiting.

[deleted]

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#405
I heard that Zendesk Security team force your _root_ domain to allow their SSL certificates to be issued, per CAA dna record.

I.e. you have domain support.example.com, CNAMEd to Zendesk, so you cannot add any other DNS record to it, but Zendesk should do it on their side. But they refuse, and force you to put CAA to your root domain example.com.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#406
post #64

Reported this exact bug to Zendesk, Apple, and Slack in June 2024, both through HackerOne and by escalating directly to engs or PMs at each company. I doubt we were the first. That is presumably the reason they failed to pay out. The real issue is that non-directory SSO options like Sign in with Apple (SIWA) have been incorrectly implemented almost everywhere, including by Slack and other large companies we alerted i…

Isn't the simplest solution here to not support SSO at all? I get there's a convenience factor, but even more convenient is the password manager built into every modern browser and smartphone. If the client decides to use bad passwords, that's will hurt them whether or not they're using SSO.

SSO is fine, but verify the email address that the SSO provider has given (unless the provider is authoritative for the email domain)

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#407

Earlier quoted context omitted.

And it’s still out of scope for the HackerOne bug bounty program.

Got a -1 on this comment. Must mean that I’m wrong and that it’s become part of the scope now! Maybe someone wants to post a link?

maybe because the issue is not about apple's dns records, so the vulnerability is in scope. One could argue the issue is in zendesk's feature of adding people with an email.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#408
post #375

Earlier quoted context omitted.

I do web app testing and report a similar issue as a risk rather often to my clients. You can replace Google below with many other identity providers. Imagine Bob works at Example Inc. and has email address bob@example.com Bob can get a Google account with primary email address bob@example.com. He can legitimately pass verification. Bob then gets fired for fraud or sexual harassment or something else gross misconduct…

You don't need full blown workspace, which costs money, you can set up "cloud identity free" and claim the domain. When you're setting it up, you can choose what to do with any existing accounts that are part of your domain: kick them out or merge them in.

This is the right answer for this problem. If you're not interested in being a paying workspace customer, get cloud identity free and verify your domain. You can then take over and/or kick out any consumer users in the domain.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#409

Earlier quoted context omitted.

That helps, but I still don't have a full picture. What's the threat here? Is it that: if a hacker gains temporary access to Bob's email bob@example.com, they can create an Apple account attached to it, and use that account to sign in with a service ABC, then that hacker gains access to Bob's private info in service ABC? But if the hacker already has email access, can't he just log into service ABC directly anyway? A…

> Also, is it impossible to have a Google account with a non-gmail address? You can have your own domain if it is a workspace account

You can have a Google ID on any e-mail address, even without workspace. e.g. You don't need gmail to use YouTube.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#410
post #213
post #46

Earlier quoted context omitted.

“I will consider not disclosing if you compensate me for my time.”

You can't ask for money in exchange for not revealing a bug. That's blackmail which is illegal and ethically dubious. White hat hackers do not require companies to pay them in exchange for not revealing a bug---the reveal of a bug only happens if a company doesn't fix that bug. Companies can be jerks and refuse to pay anything. That doesn't give you the right to blackmail them---you and other security researchers can…

"Since you don't consider this a vulnerability worth fixing, I feel obligated to let people know their zendesk might be misconfigured".
Post reply on HN