Live data from Hacker News

1 bug, $50k in bounties, a Zendesk backdoor

gist.github.com

1–10 of 437 posts

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#2
The edited title on HN is incomprehensible.

The original is:

”1 bug, $50,000+ in bounties, how Zendesk intentionally left a backdoor in hundreds of Fortune 500 companies”

A better edit might be something like:

“The $50k bug where Zendesk backdoored Fortune 500 companies”

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#3
It sounds like the author got stiffed by Zendesk on this bug, $0 due to email spoofing being out of scope.

The $50k was from other bug bounties he was awarded on hackerone.

It's too bad Zendesk basically said "thanks" but then refused to pay anything. That's a good way to get people not to bother with your big bounty program. It is often better to build goodwill than to be a stickler for rules and technicalities.

Side note: I'm not too surprised, as I had one of the worst experiences ever interviewing with Zendesk a few years back. I have never come away from an interview hating a company, except for Zendesk.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#4
I hate that Zendesk refused to pay out for this bug. The author made a good faith effort to report it. The author also tried to escalate it.

After they decided not to work on it, they later came back and asked him for more information and treat it like a bug...

Author should have gotten a reward. Did everything right if Zendesk claims it's not a in scope bug.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#7
post #4

I hate that Zendesk refused to pay out for this bug. The author made a good faith effort to report it. The author also tried to escalate it. After they decided not to work on it, they later came back and asked him for more information and treat it like a bug... Author should have gotten a reward. Did everything right if Zendesk claims it's not a in scope bug.

That is how it works. Do nothing so that the researcher breaks the rules innadvetedly as an excuse to not pay, and then fix the problem.

Re: 1 bug, $50k in bounties, a Zendesk backdoor

#9
post #3

It sounds like the author got stiffed by Zendesk on this bug, $0 due to email spoofing being out of scope. The $50k was from other bug bounties he was awarded on hackerone. It's too bad Zendesk basically said "thanks" but then refused to pay anything. That's a good way to get people not to bother with your big bounty program. It is often better to build goodwill than to be a stickler for rules and technicalities. Sid…

That is why a black market exists for this stuff.
Post reply on HN