Product Ideas Portal

Got an idea for a new feature? Maybe a tweak to make something work even better? Wish there was an integration with another product to make you even more productive? You've come to the right place.

The Product Ideas Portal lets you submit whatever product feedback you have, good, bad, ugly, and anywhere between.

Want to stay anonymous? Don't worry, no email address or name fields are shared on the public portal. You can create an account which lets you vote on other people's ideas and receive updates when your idea's status changes.

To learn more about how an idea becomes a feature, check out this infographic.


Ability to prevent Representative name enumeration from the public site

It is possible to enumerate representatives first + lastname on bomgar public site.
 
The "id=number" can be iterated over to pull every representative from your appliance.

This returns the bomgar client download page which has the Representative First and Last name due to private_name usually being mapped to *.displayName.  This would assist an attacker to attempt social engineering attacks against representative.  We have since remapped private_name to map to *.givenName, however there should be the ability to disable giving any name or make the endpoint require a token before giving out this information.

Example return, site name has been redacted
 
curl 'https://<bomgar-site>/portal/instructions/customer' -d "id=100&name" 
{"instructions":"\n<script type=\"text\/javascript\"><!--\/\/--><![CDATA[\/\/><!--\n\t\t\t\twindow.onload=function(){\n\t};\n\n\t\/\/--><!]]><\/script>\n\n\n<noscript>\n\t<br \/>\n\n\t<div style=\"text-align:center; font-size:large;\">\n\t\t<a href=\"https:\/\/<site>\/portal\/instructions\/customer?u=portal%2finstructions%2fcustomer&amp;download=1\">Click here to download the Bomgar Support Customer Client.<\/a>\n\t<\/div>\n<\/noscript>\n\n<div id=\"instructions\" style=\"display:inline; text-align: left;\">\n\t\t\tYou are about to start a support session with Mike (local).\n\t\n\t\t\t\n\t\t\t\t\t\t\t\t\t\t\t\t\n\t\t\t\t\t\t\t<ol class=\"clientDownloadInstructions\">\n\t<li><b>Run the file<\/b> you just downloaded. If you don't see the file, <a id=\"fallbackLink\" href=\"https:\/\/<bomgar-site>\/portal\/instructions\/customer?u=portal%2finstructions%2fcustomer&amp;download=1\">click here<\/a><\/li>\n\n\n\t<li><b>Browse<\/b> to the folder containing the downloaded file.<\/li>\n<li><b>Double-click<\/b> on the file you downloaded.<\/li>\n<li>Follow the on-screen instructions.<\/li>\n\n\n<\/ol>\n\n\t\t\t\n\t\t\t\n\t<p class=\"you-may-close\">You may close this window at any time after your session has started.<\/p>\n<\/div>\n\n","url":null}
  • Guest
  • Mar 28 2018
  • Future consideration
  • Attach files