How I hacked hundreds of companies through their helpdesk (2017)
medium.com
medium.com
I don't understand how the author is able to read email sent to support@company.com?
He doesn't say so explicitly, but presumably he did the same thing with ZenDesk as he did with Slack - he signed up for ZenDesk with support@target-company.com and then the target company's service with, say, no-reply@zendesk.com. And then once he had access to their ZenDesk instance he could read all emails sent to support@target-company.com, which opened up all kinds of doors.
He signed up to a target company's Zendesk as feedback@slack.com. This is the email address Slack sends email from. He could do this because Zendesk doesn't require email verification.
Then he signed up to Slack using support@target-company.com. This is the email address the target company uses to open cases in Zendesk.
ASo since Slack send the account confirmation links from feedback@slack.com to support@target-company.com, he could see them and login to the target company's Slack.
He clearly describes how he got access to their Slack instance, which required finding a way to receive an email at a @target-company.com email address. He did this by signing up for the target company's service using feedback@slack.com, in order to trick the company's support desk software into making the email from feedback@slack.com visible to him in the customer-facing support portal. The target company's helpdesk software thought the email confirming ownership of support@target-company.com was from the new user who just signed up with feedback@slack.com, so it made it visible to him in the user-facing support portal as a ticket he had opened. That let him access their Slack instance.
The question was: how was he able to read tickets created when an email was sent to support@target-company.com, such as a password reset email from Twitter. Just joining the company's Slack instance wouldn't let him read emails sent to support@target-company.com. And he says he was able to do that by getting access to their Zendesk instance.
Presumably he used the same process, but substituting ZenDesk for Slack. Or else he used a different method that he doesn't describe.
He does describe the process.
> How does signing up for Zendesk using feedback@slack.com give him access to the target company's Zendesk instance?
Because like the author said "any one could sign up with any e-mail address and effectively read any support tickets created by that e-mail address."
Regarding other methods: passwords are however, guessed, or stolen. If a hacker can grab the app databases store of passwords, they can preform offline cracking and quickly start getting into accounts that have matching hashes to commonly used passwords. All it takes is a few accounts and you can usually pivot around from there to get some more privileged access.
So now that you are effectively able to read emails sent to arbitrary address at the company's domain, you now get access to SSO links, etc sent on it too. Is this what the hack is?