
Zendesk Mega Backdoor
Source: YouTube · The PrimeTime · published Nov 2, 2024 · 36:45
A 15-year-old security researcher discovered a critical vulnerability in Zendesk that allowed attackers to read customer support tickets and access internal systems through email spoofing 0:01. The vulnerability exploited Zendesk's email collaboration feature where CC'd emails were automatically granted access to tickets without proper verification 6:36-7:53.
Key Takeaways:
• The researcher initially reported the vulnerability through Zendesk's bug bounty program, but it was rejected as "out of scope" despite affecting hundreds of Fortune 500 companies 10:22-12:26
• By chaining the vulnerability with Apple ID verification, the researcher gained unauthorized access to company Slack workspaces through SSO 14:56-18:19
• After individually reporting the issue to affected companies, the researcher earned over $50,000 in bug bounties while Zendesk refused to pay anything 21:55-22:00
• Zendesk eventually patched the vulnerability after two months but still refused to award a bounty, claiming disclosure violations 26:28-29:47
• As of the video, Zendesk reportedly still hasn't completely fixed the underlying vulnerability 35:29-35:55
The case highlights issues with bug bounty programs and corporate security responsibility, with the researcher demonstrating that proper disclosure can pressure companies to address critical vulnerabilities.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
all right we're doing this thing 15-year-old kid back doors Zen desk to create accounts in a bunch of Fortune 500 slack workplaces nice nice I absolutely love hearing this one all right so zenes uh let's see before this let's see before uh 2024 0702 allows remote attackers to read ticket history via email spoofing because CC fields are extracted from incoming email messages and used to Grant additional authorization for Ticket viewing the mechanism for detecting spoofed email messages is insufficient and the support email addresses associated with individual tickets are predictable Oh weird okay so you're spoofing an email address and it just it just or you're spoofing an email and it just accepts whatever and just starts giving out permission so if it just like is Zen is zenes strategy is…