Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

421–430 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#421

Earlier quoted context omitted.

CFAA?

which puts the liability on the person that does the unauthorized access not about else and especially not for merely browsing or using or buying a legal good from a dark net market as I wrote

>which puts the liability on the person that does the unauthorized access

Which is almost always the person finding the bug. Most services include language that limit your ability to find vulnerabilities in their systems as part of being allowed to access their service. If you find the vulnerability without ever accessing the service you might have an out, but that also means you have to sell the exploit with less ability to convince the buyer that it is something significant.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#422
post #3

It sounds like the author got stiffed by Zendesk on this bug, $0 due to email spoofing being out of scope. The $50k was from other bug bounties he was awarded on hackerone. It's too bad Zendesk basically said "thanks" but then refused to pay anything. That's a good way to get people not to bother with your big bounty program. It is often better to build goodwill than to be a stickler for rules and technicalities. Sid…

This is a common problem with HackerOne and the likes. It's absolutely awful for anything even a tiny bit more unique or rare.

Blame beg bounty hunters for this

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#423
> Personally, I’ve always found it surprising that these massive companies, worth billions, rely on third-party tools like Zendesk instead of building their own in-house ticketing systems.

For some reason this like cracked me up. Sounds exactly like something 15 year old me might say :-).

Let’s build our own ticketing system! How hard could it be?

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#424
post #126

Earlier quoted context omitted.

It wasn't clear to me as even at that point it was an "H1 Mediator" who responded. Also the bit about SPF, DKIM and DMARC seems to show a misunderstanding of the issue: these are typically excluded because large companies aren't able to do full enforcement on their email domains due to legacy. It's a common bug report. In this case, the problem was that Zendesk wasn't validating emails from external systems.

It doesn't matter if the decision that this bug doesn't matter came from a Zendesk employee or Zendesk contractor (in this case H1). Zendesk authorized them to make decisions on the matter. The audacity to say "this is out of scope" then "how dare you tell anyone else" is something else.

No disagreements there.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#426
post #97

Earlier quoted context omitted.

If you're using Google for identity and authentication, you can definitely control who has an active account in your domain. There can be some lag time before disabling or removing someone truly disables all their downstream accesses, but that's largely outside Google's control. The only way to trick your way into getting a corporate domain email address is to socially engineer a domain admin. Tangentially, this does…

You can also create a non-email Google account as Bob+external@example.com, as long as you can get email sent to bob@example.com (ie, while you are employed by Example, Inc). Then, you leave your job, but still have a google account associated with an example.com email. Depending on how the app checks the login response, they might mistakenly assume you are part of the example.com org.

I'm pretty sure you cannot create a personal account for "bob+external@example.com", as Google both knows about plus-suffixes (didn't they create them?) and any domains already managed under Workspaces. They also, in my experience, seem to have some understanding of domains managed by Microsoft's cloud and perhaps other competitors as well.

But even so, there's another mechanism, which is that when you create an OAuth2-enabled project in Google's console, you can specify that only known users in your domain are allowed to authenticate through it. This would lock out any personal account anyway.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#427
post #386

Earlier quoted context omitted.

That is how it works. Do nothing so that the researcher breaks the rules innadvetedly as an excuse to not pay, and then fix the problem.

Doubtful. It's probably just incompetence, rather than malice. The incident almost certainly cost Zendesk more in (according to the gist) lost contracts and reputational damage than it would've cost to pay the security researcher a bounty.

Or just fix the problem and not pay the bounty. Why pay at all if you can find a way not to?

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#428

Earlier quoted context omitted.

So when the researcher said it was a bug, they said, "No, it's fine. No bug bounty, sorry." THEN the researcher eventually goes public. Later, Zendesk announces the bug and the fix and says there will be no bug bounty because the researcher went public. Is that how it went? I mean if so, that's one way to save on bug bounties.

We have 2 conflicting sides of the story, who knows which one is bullshiting.

When in doubt, go with the side which has been forthcoming. Zendesk didn’t publish details and wrote their post misleadingly describing it as a supply chain problem sounding almost as if they were a victim rather than the supplier of the vulnerability. It’s always possible that there are additional details which haven’t come out yet but that impression of a weasel-like PM is probably accurate.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#429
post #362

Earlier quoted context omitted.

Presumably one of the PMs you’re referring to has posted this article for additional information. Feels like they’re doubling down on their initial position. https://support.zendesk.com/hc/en-us/articles/8187090244506-...

That article claims to have “0 comments”, but currently sits at a score of -7 (negative 7) votes of helpful/not helpful. I think they have turned off comments on that article, but aren’t willing to admit it. EDIT: It’s -11 (negative 11) now. Still “0 comments”.

Yesterday, they allowed but were deleting comments.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#430
post #429
post #362

Earlier quoted context omitted.

That article claims to have “0 comments”, but currently sits at a score of -7 (negative 7) votes of helpful/not helpful. I think they have turned off comments on that article, but aren’t willing to admit it. EDIT: It’s -11 (negative 11) now. Still “0 comments”.

Yesterday, they allowed but were deleting comments.

Yes, it now says “Article is closed for comments.”, but it did not say this originally. (Score is now at -90)
Post reply on HN