6 ms·
This is a puny payout IMO. If they poked around a bit more they may have found a better GAIA->Email vulnerability or perhaps could just use the one they found.
by 55555 2y ago
This is a puny payout IMO. If they poked around a bit more they may have found a better GAIA->Email vulnerability or perhaps could just use the one they found. A database of emails for every major youtube channel would be worth an awful lot.
- croisillon 2y agothe burden of being consciencious, i guess
- aimazon 2y agoMajor YouTube channels are typically managed by multiple people through the channel management features and brand accounts. I don't think it's possible to even log in to the brand account (which has a generated email address like channel-000000000000000000000@pages.plusgoogle.com) instead it can only be accessed through an authorized user's account (which are distinct from the channel, i.e: it's not the email address that would be surfaced by this attack). Granted, things have changed over the years, so there may be old channels lingering with Google account linked email addresses, but from what I can tell, all channels were converted a while back. https://support.google.com/youtube/answer/7001996?hl=en-GB https://support.google.com/youtube/answer/7001996?hl=en-GB edit: My hunch is that the channels the OP's attack was able to target are not actual channels but rather YouTube users (who have a "channel" because that's how YouTube represents users): so "YouTube User" is the correct description of this attack, which is distinct from what you're thinking of as a channel.
- imdsm 2y agoThink this is puny — I found the ability to reveal emails in npmjs.org but as it hadn't been included in the new GitHub/Microsoft bug bounty scope yet, I was given a t-shirt and $1000. Talk about puny!
- KomoD 2y agoI think this is puny: I was able to take over accounts on a cybersecurity platform just by knowing their account email and was only paid $200
- davidmurdoch 2y agoI was able to run JavaScript inside an email in the GMail app on Android (it required the user tap within the email body). I only got a Nexus 7 tablet.
- croisillon 2y agoin an old company of mine they started an intranet but if you opened it as http instead of https you'd see raw codes inclusive sql passwords and everything ; i reported to them, to which they replied "yeah just open it with https like everyone else"
- tptacek 2y agoServerside vulnerabilities have essentially no market outside of bug bounties. This is a hell of a payout for a web finding.
- ajross 2y agoWhat would an appropriate payout be? I mean, the classification ("high exploit probability, abuse-related impact") seems about right to me. Are you saying that abuse bugs should be more valuable? That all bugs should pay more? That this is a rich company so they should pay more? > If they poked around a bit more they may have found a better GAIA->Email vulnerability They still can! Report more bugs, get more bounties. I don't see how this is related to how much they paid for this one. > A database of emails for every major youtube channel would be worth an awful lot. It's pretty clear from the article that you can't use this API to scrape at that kind of volume. This kind of thing was never in the offering. As the title says, you can leak "any" email, not "every" email.
- xyst 2y agoA database of every YT user then x-referencing them with public services (fb/ig/twitter). Build shadow profiles, sell db to highest bidder. Or just plain ole pwning them. Most users still tend to use the same password across different services, not use 2FA, and involved in at least 1 high profile leak (I know I’m in at least a dozen so far per haveibeenpwned). Occasionally you get the victim that uses that same password for their e-mail service and that can allow you to bypass e-mail 2FA if enabled. Even better if the account is used for social SSO (ie, Google, Facebook, Twitter). Then you have access to a treasure trove of services; or just delete them for lulz
- astrange 2y agoI once reported a way to see anyone's gift registry shipping address on Amazon.com and they paid me $0 because they don't have a bug bounty. (But they did fix it.)