6 ms·
I used to work support for GAE and recognize all of this. This is really impressive, congrats on the great work and huge bounty. Keep it up!
by funkjunky 8y ago
I used to work support for GAE and recognize all of this. This is really impressive, congrats on the great work and huge bounty. Keep it up!
- haldean 8y agoSame; I worked on GAE in 2013 and it's so funny to read the story of someone exploring, discovering, and being so close to breaking something you know really well. There's a few moments in here where I thought "oh man, you could have done XXXX and that would have been so bad!". Definitely understand why they gave them the big bucks for this one.
- puzzle 8y agoI didn't work on GAE, but I know a fair amount about how it ran and, as I read, too, I could think of quite a few things I would have done, had I been a malicious actor. Denial of service is the first to come to mind. I'm sure a real security person could do a lot more.
- TomV1971 8y agoI’ve been on the receiving end where hobbyists were trying (and eventually succeeded) to hack our DRM scheme. It was really fun to read the forums and see how, day by day, they managed to get closer. Since it wasn’t really crucial IP to begin with, we were rooting for the little guys to see how close they would get, secure in the knowledge that our algorithm was solid. :-) The final exploit that granted them access was due to a supplier who replaced an earlier validated random generator with something not quite as random, which enabled replay attacks.
- eyeareque 8y agoXXXX == what types of things? I’m curious why there was no auth required for his calls.
- londons_explore 8y ago* Grab nearly all of googles source code (no extra auth required for that, since so many libraries read config etc from the source code repo) * Make the right requests to one endpoint he found and retrieve company financials, number of hits to every google service, the name of every application running in every datacenter, etc. * With the above two things, you know the location of services and every RPC endpoint on them, and all access control configs. You can take your sweet time to audit the 10's of millions of lines of code to find vulnerabilities and get to attack as an authenticated (albeit low privilege) user. A lot of stuff is open to all authenticated internal users. * For example, you could take down any google service by quitting all the application servers at the same time by calling the right debugging RPC. You'd be caught obviously tho.
- eyeareque 8y agoWow, that is quite significant. 36k is not a small bounty for an RCE, but I feel like this is more critical to Google than the highest Android payout, for which they pay up to 200k for: https://www.google.com/about/appsecurity/android-rewards/ https://www.google.com/about/appsecurity/android-rewards/
- lathiat 8y agoAndroid is probably one of those markets that are more liquid than most for "black market" sources (as talked about elsewhere in the comments for this)
- londons_explore 8y agoAndroid is wormable, and potentially not repairable by google. For example, with a decent remote android exploit, I could distribute a patched Google Play Services to all vulnerable handsets which disables updates and then listens to my own command and control infrastructure for further actions. I can now hold the phones hostage and extort google for money to regain control of them.
- 8y ago