Live data from Hacker News

Google Bug Bounty – The $5k Error Page

slashcrypto.org

41–50 of 144 posts

Re: Google Bug Bounty – The $5k Error Page

#41

Earlier quoted context omitted.

I am a bit jealous :). I also did a subdomain search on google a few weeks ago. I stumbled upon a lot of login sites. A subdomain search leaded to 95 subdomains under corp.google.com. There is some strange javascript in those pages, there is a function called riskMi. I don't want to get sucked into it, I'm also closing the tab and going back to my terminal :).

How did you subdomain search? Was it a brute force / dict search?

Shameless self-plug: You can use Fierce! A DNS reconnaissance tool - https://github.com/mschwager/fierce

Re: Google Bug Bounty – The $5k Error Page

#42
Nice , glad he got paid. Whats truly sad is they did try to chisel him out of his bounty if you read the timeline, he had to prod them to get his bounty. Can any of these top-ten companies that make like 200 million per day (google/alphabet, amazon, microsoft) ever do anything in good faith? One time google stiffed me initially on an RMA with a nexus phone until I stamped my feet a bit complaining that a company that makes 200M/day is stiffing me, the loyal android lover, for a $200 hunk of chinese-made plastic. (and just a short while later with things like SafetyNet I can no longer have root on an $800 pixel that isnt even waterproof). So much for dont be evil. Well, they dropped that in favor of -"do the right thing—follow the law, act honorably, and treat each other with respect" yeah, they can respectably be cheap chiseling money grubbers as long as its legal - like helping locate Falun Gong members in China. And the corporate stewardship -in the hands of the employees - they get blinded by the huge pay and instantly fail to see the bad things that go on. Anyways, glad he got paid. Amazing that a company with 57000 employees (and TONS of contractors, they dont want more employees who get benefits and stock when they can string contractors along) needs some random guy to find holes in the back door.

Re: Google Bug Bounty – The $5k Error Page

#43

Nice , glad he got paid. Whats truly sad is they did try to chisel him out of his bounty if you read the timeline, he had to prod them to get his bounty. Can any of these top-ten companies that make like 200 million per day (google/alphabet, amazon, microsoft) ever do anything in good faith? One time google stiffed me initially on an RMA with a nexus phone until I stamped my feet a bit complaining that a company that…

I find it much more likely that they just dropped the ball on paying them, rather than maliciously trying to deny them a bounty.

Re: Google Bug Bounty – The $5k Error Page

#44

Nice , glad he got paid. Whats truly sad is they did try to chisel him out of his bounty if you read the timeline, he had to prod them to get his bounty. Can any of these top-ten companies that make like 200 million per day (google/alphabet, amazon, microsoft) ever do anything in good faith? One time google stiffed me initially on an RMA with a nexus phone until I stamped my feet a bit complaining that a company that…

Sounds like everyone got what they wanted.

Also sounds like you were dealing with humans, who (before escalating) followed company protocols.

Also seems not too far-fetched that those protocols are in place to weed out the whatever% that make bogus claims.

All in all, nothing I'd call "truly sad", "evil" and whatnot. Just big businesses being big businesses.

Re: Google Bug Bounty – The $5k Error Page

#45

Good catch! Also studied Google's 404 pages. Seems like they have unified all but a few of them. One of them I found was vulnerable to old utf-7 injection (specified customizable page title before character encoding) and another was vulnerable to XSS. Got a bounty for the XSS one, the utf-7 one targeted too old browsers, out of scope for the program (I do wonder how many IE6 users Google sees).

It's a very low percentage, somewhere in the low single digits (if not an even lower order of magnitude). Still high enough for it to be worth paying engineers to maintain the backwards compatibility :)

Re: Google Bug Bounty – The $5k Error Page

#46

Earlier quoted context omitted.

Where is this resentment and skepticism coming from? The facts say otherwise. Google is known to be receptive to bounties and payout.

This story from yesterday has raised some resentment about google's support: A startup’s Firebase bill suddenly increased from $25 to $1750 per month https://news.ycombinator.com/item?id=14356409

Their customer/enterprise support is notoriously sketchy, at least from the outside (a la HN) looking in.

That's not the same at all as their bug bounty program, which is generally one of the best out there.

Re: Google Bug Bounty – The $5k Error Page

#47
post #43

Nice , glad he got paid. Whats truly sad is they did try to chisel him out of his bounty if you read the timeline, he had to prod them to get his bounty. Can any of these top-ten companies that make like 200 million per day (google/alphabet, amazon, microsoft) ever do anything in good faith? One time google stiffed me initially on an RMA with a nexus phone until I stamped my feet a bit complaining that a company that…

I find it much more likely that they just dropped the ball on paying them, rather than maliciously trying to deny them a bounty.

Try arguing with them about an SLA violation they had with their cloud infrastructure. The game is setup where they can chisel and have these guffaw and aw garsh moments but every adword and every billable second on their cloud will get paid hell or high water.

Re: Google Bug Bounty – The $5k Error Page

#48

Nice , glad he got paid. Whats truly sad is they did try to chisel him out of his bounty if you read the timeline, he had to prod them to get his bounty. Can any of these top-ten companies that make like 200 million per day (google/alphabet, amazon, microsoft) ever do anything in good faith? One time google stiffed me initially on an RMA with a nexus phone until I stamped my feet a bit complaining that a company that…

Sounds like everyone got what they wanted. Also sounds like you were dealing with humans, who (before escalating) followed company protocols. Also seems not too far-fetched that those protocols are in place to weed out the whatever% that make bogus claims. All in all, nothing I'd call "truly sad", "evil" and whatnot. Just big businesses being big businesses.

Curious why you have such high tolerance for this type of behavior, since it appears that you don't actually approve of it.

Re: Google Bug Bounty – The $5k Error Page

#49
post #43

Earlier quoted context omitted.

I find it much more likely that they just dropped the ball on paying them, rather than maliciously trying to deny them a bounty.

Try arguing with them about an SLA violation they had with their cloud infrastructure. The game is setup where they can chisel and have these guffaw and aw garsh moments but every adword and every billable second on their cloud will get paid hell or high water.

Did you seriously come to hijack a story about a Google bug bounty so you could complain about an irrelevant issue?

Re: Google Bug Bounty – The $5k Error Page

#50

Nice , glad he got paid. Whats truly sad is they did try to chisel him out of his bounty if you read the timeline, he had to prod them to get his bounty. Can any of these top-ten companies that make like 200 million per day (google/alphabet, amazon, microsoft) ever do anything in good faith? One time google stiffed me initially on an RMA with a nexus phone until I stamped my feet a bit complaining that a company that…

[deleted]
Post reply on HN