news.volyx.in

1 bug, $50k in bounties, a Zendesk backdoor (gist.github.com)

1637 points by mmsc · 664 days ago · 417 comments on HN

Article summary

A 15-year-old bug hunter discovered a vulnerability in Zendesk that allowed attackers to read customer support tickets from any company using the platform. The bug was initially reported to Zendesk through their bug bounty program, but was rejected as out of scope. The bug hunter then used the vulnerability to exploit a Slack takeover, which was later fixed by Zendesk. The bug hunter earned over $50,000 in bounties from individual companies, but Zendesk refused to award a bounty.

Main themes

  • Bug bounty programs
  • Vulnerability disclosure
  • Security exploits
  • Responsible disclosure
  • Bug hunting

What commenters say

  • The title of the article is misleading because the $50,000 earned by the bug hunter came from unrelated bug bounties, not from Zendesk.
  • Zendesk's refusal to award a bounty for the reported bug is seen as unfair, especially since the bug hunter was forced to disclose the vulnerability to affected companies after Zendesk initially dismissed it as out of scope.
  • The use of HackerOne as a bug bounty platform can lead to issues with triage and mediation, potentially causing valid bugs to be dismissed or ignored.
  • The economic value of bugs is often underestimated by companies, and the black market for exploits can offer higher payouts, creating a disincentive for bug hunters to report vulnerabilities through official channels.
  • The liability for exploiting a bug lies with the person who uses it for unauthorized access, not with the person who discovers or sells the bug.
  • Companies like Zendesk have a responsibility to ensure that their bug bounty programs are fair and effective in encouraging responsible disclosure of vulnerabilities.
  • The decision to disclose a vulnerability to affected companies after a company has dismissed it as out of scope is a complex issue, with some arguing that it is justified and others seeing it as a violation of disclosure guidelines.