5 ms·
I think any xoogler will agree https://sites.google.com/site/testsitehacking/-36k-google-app-engine-rce https://sites.google.com/site/testsitehacking/-36k-googl
by shockinglytrue 6y ago
I think any xoogler will agree https://sites.google.com/site/testsitehacking/-36k-google-app-engine-rce https://sites.google.com/site/testsitehacking/-36k-google-ap... is far more impressive.
It seems fairly safe to assume someone has already snapped this guy up. I can't recall the last time I felt so impressed reading some security writeup
- ikiris 6y ago!
- jchw 6y agoThis one was good too, especially because the screenshot definitely gave many some heart palpitations. https://opnsec.com/2018/07/into-the-borg-ssrf-inside-google-production-network/ https://opnsec.com/2018/07/into-the-borg-ssrf-inside-google-...
- saagarjha 6y agoThat's a lot of internal information. I'm not sure I'd be comfortable publishing that, even if the company was friendly to security researchers.
- jchw 6y agoI think if I were an outsider I would’ve probably gotten pretty shy just after discovering an internal SSRF at a big corp. However, that also probably explains why I am not a security researcher.
- jotm 6y agoAm I reading this right? 13,337 for a unrestricted file access vulnerability? Seems rather cheap, I think even other interested parties would pay more :/
- jchw 6y agoIt was treated as an unrestricted file access vulnerability. I don’t want to accidentally disclose any non-public information (as an employee of Google) so I’ll just say I suspect there wasn’t really a ton more to see other than status and debug pages. Not to downplay the value of such a vulnerability, just saying that with defense-in-depth risks like this should be relatively well contained. It sounds like they got access to some confidential operational information but were nowhere near user data, and there was no obvious path to get there without much worse vulnerabilities.
- gameofcode 6y agoLooks like Google themselves have hired him as an intern: https://twitter.com/epereiralopez/status/1220781461504176129 https://twitter.com/epereiralopez/status/1220781461504176129
- LunaSea 6y agoAs an intern, wow, how charitable of them.
- OJFord 6y agoWhat do you expect, 18yo gets hired as director of product security?
- cameronbrown 6y agoInterns contribute a lot of value - they don't run around making coffee. Being an intern makes it much more likely to get an FTE role too which is more than most 18 year olds. Source: Also a 19 y/o Googler.
- LunaSea 6y agoRight, and are your valued contributions rewarded as such?
- jsmith45 6y agoNot a googler/xoogler, but if if FILE_GOOGLE3_ACCESS means what I think it means.... Yikes! (Especially since FILE_GOOGLE3_READ_ONLY_ACCESS is a separate permission, that implies the possibility of writes, but even read-only access is not something Google would want a random outsider to have.) And that is almost surely only a tiny subset of what could be done via the the whole run with arbitrary permissions thing. Most of the other don't jump out as me as much as that one does, but I may just not recognize the significance of some of the permissions. It is interesting that he could only make it work in the non-production environment, but I'm not sure if that would actually limit the capabilities meaningfully.