4 ms·
To answer a few FAQs I've had over the last few days: - I've not seen a confirmed use of this in the wild yet, despite a few people emailing me stories where t
by TomAnthony 9y ago
To answer a few FAQs I've had over the last few days:
- I've not seen a confirmed use of this in the wild yet, despite a few people emailing me stories where they suspect it.
- I am unsure what is with the bug bounty amount. I think either:
1) The various teams didn't communicate well about the impact until after the award,
2) I haven't fully understood the bug, however as per VRP rules I stopped when I had "discovered a potential security issue", at which point "The panel will consider the maximum impact". It may be I've not understood the impact fully.
3) They want to discourage SEO type research as opposed to pure security research, but I doubt that is the case and it doesn't match up with my previous dealings with the team.
- There are a few technical details not in the article (for example I believe the sitemap has to be an sitemap index file), but nothing that greatly changes it.
- If you are concerned you are affected, I'm happy to take a quick look at your data for free (tom.anthony@distilled.net) to see if I have any insights.
- The best/only way to detect this being done to you is to find the 301/302 redirects for the sitemap in your server logs.
- londons_explore 9y agoGoogle doesn't issue rewards for SEO tricks. My guess is your sitemap redirection trick could be used to leak data about the victim site (search terms, traffic stats, malware urls), or to do other privileged actions on behalf of the victim site now the two domains were linked (for example sign up for google apps or trigger rate limits DoS'ing the victims ability to use certain API's)
- TomAnthony 9y agoPerhaps. We could argue the semantics of it, but it feels within the spirit of the VRP. It directly impacts the secure and correct functioning of a (the!) core Google service. The VRP page [0] talks about the "maximum impact" and this impacts users and advertisers, as well as businesses relying on organic Google traffic. However, I take your point - I'm aware this is not a typical sort of issue for a bounty. To reiterate - I am grateful to Google that they run the bounty programme and that they awarded a bounty for this. I've previously reported several issues (e.g. [1]) that have not been rewarded any bounty, which is the nature of the programme and absolutely fine. [0] https://www.google.com/about/appsecurity/reward-program/ https://www.google.com/about/appsecurity/reward-program/ [1] http://www.tomanthony.co.uk/blog/confirm-google-users-email/ http://www.tomanthony.co.uk/blog/confirm-google-users-email/