TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Bug, $50K+ in bounties: how Zendesk left a backdoor in companies

20 pointsby hackermondev7 months ago

5 comments

politelemon7 months ago
&gt; Personally, I’ve always found it surprising that these massive companies, worth billions, rely on third-party tools like Zendesk instead of building their own in-house ticketing systems.<p>The same reason hackers&#x2F;developers, use existing tools instead of writing their own. Of course it is more efficient. But also, if they did it themselves it would be much worse, buggier, and likely vulnerable than using something from a third party that&#x27;s focusing on that one thing. To put it another way, the self made ones would have more and worse problems than the ones found in many third party tools.
DarkerInk7 months ago
Great find, it&#x27;s a shame Zendesk didn&#x27;t pay a bounty (very stupid Imo) but at least you got some bounties from reporting it to affected companies.
o11c7 months ago
Not sure why this got flagged, unless related to the &quot;keep it up&quot; comments? It&#x27;s an interesting read ...
slater7 months ago
great job astroturfers, keep it up
sairamkunala7 months ago
(as a devops&#x2F;security minded engineer) ...and companies wonder how supply chain attacks are possible