1 bug, $50,000+ in bounties, how Zendesk intentionally left a backdoor in hundreds of Fortune 500 companies.

https://gist.github.com/hackermondev/68ec8ed145fcee49d2f5e2b9d2cf2e52

252 points · 4 comments · view on lemmy.world

4 Comments

lvxferre@mander.xyz · 90 pts · 1y (1 reply)
[ removed ]
Badeendje@lemmy.world · 21 pts · 1y

Such a small amount also for a company like Zendesk to pay this kid. Even if they initially did not acknowledge the issue, the moment they did.. all it would have taken was... "Hey kid, we revisited the issue and found that the bug you found was of higher importance than we originally thought, we will implement fixes for the issue and want to thank you by awarding you the bounty per our programme. Keep up the good work and let us know of you find more issues"... And ofc pay him the bounty.

platoose@feddit.uk · 45 pts · 1y

I work with Zendesk and this doesn’t surprise me at all - the product is janky and they’re much more interested in sales and squeezing a few more $$s from their clients than improving it or fixing issues

homesweethomeMrL@lemmy.world · 43 pts · 1y

Zendesk, Lastpass, All-The-Eggs-In-The-Cloud-Basket, all these products require dedicated internal teams to maintain anyway.

IT directors of old didn’t trust FOSS but did get rich signing over their company’s security to whoever showed up with a dog-and-pony show. Surprise - they’re just as lazy and cheap as you!

PixelTron@lemm.ee · 31 pts · 1y

And by a 15 year old no less! Keep up the awesome work young one, you’ll go far…