Zendesk Mega Backdoor

Zendesk Mega Backdoor

Source: YouTube · The PrimeTime · published Nov 2, 2024 · 36:45

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

A 15-year-old security researcher discovered a critical vulnerability in Zendesk that allowed attackers to read customer support tickets and access internal systems through email spoofing 0:01. The vulnerability exploited Zendesk's email collaboration feature where CC'd emails were automatically granted access to tickets without proper verification 6:36-7:53.

Key Takeaways:
• The researcher initially reported the vulnerability through Zendesk's bug bounty program, but it was rejected as "out of scope" despite affecting hundreds of Fortune 500 companies 10:22-12:26
• By chaining the vulnerability with Apple ID verification, the researcher gained unauthorized access to company Slack workspaces through SSO 14:56-18:19
• After individually reporting the issue to affected companies, the researcher earned over $50,000 in bug bounties while Zendesk refused to pay anything 21:55-22:00
• Zendesk eventually patched the vulnerability after two months but still refused to award a bounty, claiming disclosure violations 26:28-29:47
• As of the video, Zendesk reportedly still hasn't completely fixed the underlying vulnerability 35:29-35:55

The case highlights issues with bug bounty programs and corporate security responsibility, with the researcher demonstrating that proper disclosure can pressure companies to address critical vulnerabilities.

Sources:

  • 0:01 Introduction to the 15-year-old's Zendesk vulnerability discovery
  • 6:36-7:53 Explanation of how the email collaboration vulnerability worke

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

all right we're doing this thing 15-year-old kid back doors Zen desk to create accounts in a bunch of Fortune 500 slack workplaces nice nice I absolutely love hearing this one all right so zenes uh let's see before this let's see before uh 2024 0702 allows remote attackers to read ticket history via email spoofing because CC fields are extracted from incoming email messages and used to Grant additional authorization for Ticket viewing the mechanism for detecting spoofed email messages is insufficient and the support email addresses associated with individual tickets are predictable Oh weird okay so you're spoofing an email address and it just it just or you're spoofing an email and it just accepts whatever and just starts giving out permission so if it just like is Zen is zenes strategy is…