Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

71–80 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#71
post #57
post #11

A $1.3 billion revenue company being too tight to pay this after all, even on their 2nd chance, is so short-sighted it's absurd. They're putting out a huge sign saying "When you find a vuln, definitely contact all our clients because we won't be giving you a penny!". Incredible. This must be some kind of "damaged ego" or ass-covering, as it's clearly not a rational decision. Edit: Another user here has pointed out th…

It all makes sense if you consider bug bounties are largely: 1) created for the purpose of either PR/marketing, or a checklist ("auditing"), 2) seen as a cheaper alternative to someone who knows anything about security - "why hire someone that actually knows anything about security when we can just pay a pittance to strangers and believe every word they say?" The amusing and ironic thing about the second point is tha…

Our company has a bug bounty program:

- handled with priority, but sometimes it takes a couple of weeks for a more definite fix

- handled by the security department within the company ( to forward to relevant PO's and to follow up)

The unfortunate thing about bug bounties is that you will be hammered with crawlers that would sometimes even resemble a DDOS

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#72
post #64

Reported this exact bug to Zendesk, Apple, and Slack in June 2024, both through HackerOne and by escalating directly to engs or PMs at each company. I doubt we were the first. That is presumably the reason they failed to pay out. The real issue is that non-directory SSO options like Sign in with Apple (SIWA) have been incorrectly implemented almost everywhere, including by Slack and other large companies we alerted i…

This is very important to keep in mind when implementing OAuth authentication! Not every SSO provider is the same. Even if the SSO provider tells you that the user's email is X, they might not even have confirmed that email address! Don't trust it and confirm the email yourself!

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#73
post #60

Earlier quoted context omitted.

zendesk is 6k employees, they have general council on staff

This is worse than Docusign. What do 6000 people at Zendesk do? It's a simple ticket management software with maybe 10 features

I am actually seriously interested in what people there do day to day. I’m wondering this about a lot of very large companies, I would definitely watch a documentary about that.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#74
The amount of software that could have been some spreadsheets and an email chain and companies pay enormous amounts of money for and create glaring vulnerabilities in their systems is a big reason why I'll never understand or thrive in a corporate setting.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#76
post #3

It sounds like the author got stiffed by Zendesk on this bug, $0 due to email spoofing being out of scope. The $50k was from other bug bounties he was awarded on hackerone. It's too bad Zendesk basically said "thanks" but then refused to pay anything. That's a good way to get people not to bother with your big bounty program. It is often better to build goodwill than to be a stickler for rules and technicalities. Sid…

If I am not mistaken, it wasn't zendesk that didn't want to recognize the bug, but HackerOne that did not escalate to Zendesk that they should reconsider the exclusion ground in this case. As an aside, I wonder if those bounties in general reflect the real value of those bugs. The economic damage could be way higher, given that people share logins in support tickets. I would have expected that the price on the black…

[deleted]

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#77
post #21

I help corporates evaluate and buy software. Having an ineffective bug bounty program, especially one that rewards black market activity on a terms & conditions technicality like this, is enough for me to put a black mark on your software services. I don’t care if you’re the only company in the market, I’ll still blackball you for this in my recommendations. Zendesk should pay up, apologize and correct their bug boun…

Would love to see the parts of the market where you've marked off every current option, given each would represent new business opportunities.

Probably any SK company. Bounties are awful and only paid out to SK citizens. Everyone else gets a pat on the back for being a sucker.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#78

> Personally, I’ve always found it surprising that these massive companies, worth billions, rely on third-party tools like Zendesk instead of building their own in-house ticketing systems. Do you find it surprising that they use Microsoft Office too? Paying someone else to handle things like this is cheaper than paying developers and hosting a service like this.

I’d give the author a break-he’s just 15, after all. I was far less savvy at his age.

Agreed, I smiled a this line. Good reminder that you don’t have to be super experienced to have big insights and impact.

And also that being brilliant doesn’t magically correlate with being knowledgeable.

https://xkcd.com/1053

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#79
post #60

Earlier quoted context omitted.

zendesk is 6k employees, they have general council on staff

This is worse than Docusign. What do 6000 people at Zendesk do? It's a simple ticket management software with maybe 10 features

I previously worked for a mortgage software startup that attracted interest from big banks.

To ease concerns about our scalability and longevity, we move from a tiny office to an office with a lot of empty space.

This strategic move supposes signaled to prospective corporate clients that we were committed to sustaining our solution over the long term, rather than just a few years but in the end the company went out of business. so much for that.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#80
post #20

Another example of how weasley Zendesk can be: They created a fake band called "Zendesk Alternative" just in an attempt to pollute the Google results if you search for an alternative to Zendesk. http://zendeskalternative.com/ While not illegal, it shows the way they think, a sort of manipulative pettiness.

The entire keyword buying SEM operates that way too right? At least they call it out as Sponsored results though.
Post reply on HN