4 ms·
I bypassed AWS API Gateway auth with a trailing slash. Got $12K bounty
- A_Duck 4mo ago$1 removing the slash, $11,999 knowing where to remove the slash from
- dizhn 4mo agoAt that rate I would remove it from everywhere.
- throw1234567891 4mo agoBut do you know where they all are
- donalhunt 4mo agoNo. But my AI agent will happily burn electrons finding some... Maybe...
- throw1234567891 4mo agoHopefully it doesn’t hallucinate on you.
- redrove 4mo agoDon’t vibe code your auth path folks.
- darkwater 4mo agoOtherwise a security research will vibe-code an exploit and slop out a blog post about it.
- IshKebab 4mo ago[flagged]
- Deebster 4mo agoI have no idea why you think it's written by AI, unless you think that correct use of quote and dash characters means it must be AI.
- GrinningFool 4mo agoThere are plenty of tells. Quotes and dashes don't even have to enter into it.
- elpocko 4mo agoPlease go away and take your feelings with you.
- tedk-42 4mo agoHmmm 12K seems like a bit much, even if it's fintech. They also didn't mention the company. The title feels clickbaity as it's not specific to AWS API gateway and instead, the implementation of it. And who hosts on blogspot...
- savolai 4mo agoIt's not really fair to criticise hosting choice, but this lead me down a rabbit hole. Noticed that non-responsive blog layouts are rare these days. Most are from blogspot. So I took a look and realized that blogger nowadays actually supports responsive layouts, but apparently... they are not popular? https://blogger.googleblog.com/2017/03/share-your-unique-style-with-new.html https://blogger.googleblog.com/2017/03/share-your-unique-sty...
- Kwpolska 4mo agoGoogle barely maintains Blogger, and people have old blogs with old templates they never felt the need to change.
- Quarrelsome 4mo agogot any more criticisms, font choice, perhaps there's some duplication in their css? I think 12k could be fine given how much it might have cost them if nobody had noticed.
- rithdmc 4mo agoOr if someone with malicious intent noticed.
- utf_8x 4mo agoConsidering it let them do an unauthorized wire transfer from a system account, 12k seems pretty reasonable.
- treszkai 4mo agoYes, it and the other three posts sound positively AI written. The first post on the blog is how OP uploaded a backdoored dataset to HuggingFace and left it there for 6 months – whether made up or not, it doesn't sound great.
- mapcars 4mo agoInteresting story showing how complex todays tech is, and your whole security plan can be compromised by regexp matching rules.
- sammy2255 4mo agoDid you Bypass AWS API Gateway.. or did you bypass it for a company who had their AWS API Gateway misconfigured?
- stuartjohnson12 4mo agoI hate when people say this, as if there's any world in which I would want my AWS API gateway to do this, let alone accidentally. HTTP is littered with these footguns, differences between slashes and no slashes is a classic. A good piece of software would make it hard to do this by accident, and probably should default to having the same behaviour with or without trailing slash. Yes yes, I know, folder/file naming convention dating from... But it's current year now
- sam_lowry_ 4mo agoHTTP footguns? Meh! I routinely bypass domain blocks by appending a dot to the domain name, e.g. amazon.com.
- fiedzia 4mo ago> A good piece of software would make it hard to do this by accident, and probably should default to having the same behaviour with or without trailing slash. Django redirects one version to another by default, which achieves that.
- rvz 4mo agoThe thing that absolutely should not be vibe coded, especially in fintech. Turning a $10 bug into a $12K issue and if this was at a big tech company it would be a $120K+ issue.
- brian_herman 4mo agoYou deserve the trip, nice find!
- praptak 4mo agoAppending stuff to bypass blacklists is eternal. My first job, decades ago. I couldn't update something on my laptop because client's gateway blocked `http://foo.com/update.exe http://foo.com/update.exe`. Guess what, `http://foo.com/update.exe http://foo.com/update.exe?` worked as a bypass.
- sillysaurusx 4mo agoAh, a rare situation where you have to put your URL in angle brackets for it to be parsed correctly here: <http://foo.com/update.exe? http://foo.com/update.exe?> (Not that it matters in this case. Also I would’ve guessed the angle brackets would disappear, but apparently not.) [1] https://news.ycombinator.com/formatdoc https://news.ycombinator.com/formatdoc
- elpocko 4mo agoA DPI firewall at a place of education had a whitelist of allowed domains that you could connect to from the internal network. One entry in the whitelist was "microsoft.com". I installed a web proxy on my VPS, which was accessible under a domain name like "computerthings.example", created a subdomain called "microsoft", and voila: "microsoft.computerthings.example" was good enough to match "^microsoft.com.*" and allowed us to bypass the block for the next two years.
- anacrolix 4mo agoThat's what you get for using Go mux
- deleted 4mo ago[deleted]
- me551ah 4mo agoYou didn’t break API Gateway or bypass it, you broke the company using incorrect api gateway config. Your title is clickbait
- Subdivide8452 4mo agoI want my 5 minutes back. What an absolute waste of time this was.
- alexpandey 4mo ago[flagged]
- GeorgeWoff25 4mo agoThe original article post https://vechron.com/2026/04/i-bypassed-aws-api-gateway-auth-with-a-trailing-slash-got-12k-bounty/ https://vechron.com/2026/04/i-bypassed-aws-api-gateway-auth-...
- deleted 4mo ago[deleted]
- localhoster 4mo agoTbh I always wondered how are we still matching routes using regex and not something like a radix tree? That would eliminate these kinds of issues no?
- flumpcakes 4mo agoThis is a shocking mistake for a 'fintech' to make. This is supremely basic stuff.
- Yilialinn 4mo ago[flagged]