TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Zendesk: Email user verification bug bounty report retrospective

11 点作者 mmsc7 个月前

2 条评论

gnabgib7 个月前
Related Discussion <i>1 bug, $50k in bounties, a Zendesk backdoor</i> (817 points, 11 hours ago, 254 comments) <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=41818459">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=41818459</a>
motrm7 个月前
I submitted a comment to this article but it&#x27;s unclear if it&#x27;s going to be moderated or indeed published, here&#x27;s what I said:<p><pre><code> I think it&#x27;s a bit discourteous to shoo Daniel away due to an out of scope report, then cry wolf when your clients do actually feel that this warrants a response. The fact that you made changes to your systems in response indicates that this wasn&#x27;t as benign as it first seemed. IMO Zendesk should do the right thing and issue a reward. An issue was reported and ultimately resolved in some fashion. Continue to encourage researchers to bother reporting things to you. Yes, you have a little egg on your face due to the end-run via your clients, but that&#x27;s life, Zendesk will survive.</code></pre>
评论 #41823715 未加载