Email Bombs Exploit Lax Authentication in Zendesk

26 pointsposted 4 hours ago
by todsacerdoti

8 Comments

fckgw

5 minutes ago

If you start getting an email bombed out of nowhere, being signed up for hundreds of newsletters or other email notifications, take a quick look at your credit card statements for any unknown purchases. Email bombs are often used by card thieves to hide legitimate purchase notifcation email from retailers when they use your stolen creds.

bombcar

24 minutes ago

You know, combing "bomb" with LAX makes me think really different things for awhile until my parser finally woke up ...

ianhawes

31 minutes ago

Brian Krebs is a saint for being the perennial punching bag and target of cybercriminals but continuing to publish important information independently.

bgc

4 minutes ago

Another fun Zendesk “feature,” that, to my knowledge, has never been fixed is if you CC it on a thread with any other email address that auto-replies, it will get stuck in a loop and ping-pong emails back and forth until the mailbox fills up.

dboreham

2 hours ago

Ah. This explains a bunch of odd emails I received all at the same time last week.

Volundr

2 hours ago

Yeah I got enough of these from discord, that I emailed their abuse@ and put in a support ticket, but they ignored me. Nice to have it confirmed. I ended up doing a password rotation on the off chance it was me.

Ekaros

2 hours ago

I was kinda confused why I got one from company that really doesn't even operate here and what was the vector with it...

whatamidoingyo

2 hours ago

Yeah, I got like 50 from bugcrowd. I figured someone found a bug somewhere, lol.