Live data from Hacker News

$36k Google App Engine RCE

sites.google.com

41–50 of 164 posts

Re: $36k Google App Engine RCE

#41

> I am 18-year-old student at the University of the Republic [Uruguay] interested in computer security Someone could say that he could have gotten even more money by selling his findings in the black market, very difficult but doable. However, as someone who understands how studying computer science in a 3rd-world country is, getting USD +36k in a legal way and from a company that is considered one of the best in the…

Selling and getting paid in the black market is probably not very easy unless you already have quite a lot of contacts.

Re: $36k Google App Engine RCE

#42
post #24
post #23

Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in money), and a bounty from Google under his belt - he won't have trouble finding work. If I was considering hiring him, the creative bit of guerilla marketing for The Expanse he threw in there wouldn't hurt his chances either.

As someone who worked in a bug bounty program, the skill and age of this individual isn't what sets them apart. It's the write up.

As someone who has been on the other end of receiving incoherent and inaccurate bug bounty reports, this!

To find the bug is impressive. To write about it so well is truly exceptional.

Re: $36k Google App Engine RCE

#43
post #23

Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in money), and a bounty from Google under his belt - he won't have trouble finding work. If I was considering hiring him, the creative bit of guerilla marketing for The Expanse he threw in there wouldn't hurt his chances either.

Let's try a thought experiment. To make things easier, imagine you're 21 years old, not 18, and have made up those 3 years working in the industry. You found this vulnerability, and have decided not to submit it for a bounty, but rather to the black market.

Who do you sell it to? I assume your answer will involve putting it up on some darknet version of Craigslist. That's fine, but then tell me: who's paying for it? What price do they assign to it? For instance: if you think you can sell it for $50k, who's paying that, and for what purpose?

Finally, what are the steps you take to safely complete the transaction?

(This is intended only to clarify arguments about the market for vulnerabilities like these, and not to suggest that the finding and the writeup aren't excellent, which they sure appear to be.)

Re: $36k Google App Engine RCE

#44
post #28

I used to work support for GAE and recognize all of this. This is really impressive, congrats on the great work and huge bounty. Keep it up!

Same; I worked on GAE in 2013 and it's so funny to read the story of someone exploring, discovering, and being so close to breaking something you know really well. There's a few moments in here where I thought "oh man, you could have done XXXX and that would have been so bad!". Definitely understand why they gave them the big bucks for this one.

I’ve been on the receiving end where hobbyists were trying (and eventually succeeded) to hack our DRM scheme.

It was really fun to read the forums and see how, day by day, they managed to get closer. Since it wasn’t really crucial IP to begin with, we were rooting for the little guys to see how close they would get, secure in the knowledge that our algorithm was solid. :-)

The final exploit that granted them access was due to a supplier who replaced an earlier validated random generator with something not quite as random, which enabled replay attacks.

Re: $36k Google App Engine RCE

#45
post #23

Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in money), and a bounty from Google under his belt - he won't have trouble finding work. If I was considering hiring him, the creative bit of guerilla marketing for The Expanse he threw in there wouldn't hurt his chances either.

I’m not sure how familiar you are with South America but Uruguay is one of the most developed countries in the Western Hemisphere, in the group right behind the US and Canada.

Re: $36k Google App Engine RCE

#47
post #43
post #23

Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in money), and a bounty from Google under his belt - he won't have trouble finding work. If I was considering hiring him, the creative bit of guerilla marketing for The Expanse he threw in there wouldn't hurt his chances either.

Let's try a thought experiment. To make things easier, imagine you're 21 years old, not 18, and have made up those 3 years working in the industry. You found this vulnerability, and have decided not to submit it for a bounty, but rather to the black market. Who do you sell it to? I assume your answer will involve putting it up on some darknet version of Craigslist. That's fine, but then tell me: who's paying for it?…

You don't have to think about it too hard, there's companies that will help you with the transaction. https://www.zerodium.com/

Re: $36k Google App Engine RCE

#48
"When issuing the reward, we'll take into account what you could have achieved with this access" makes me laugh.

How scary must that be for the Google team? You know you've messed up so badly and the person who is investigating is doing so blindly with no knowledge or accountability if he breaks something. Yikes.

Kudos to everyone for doing the right things. And great bounty- the average yearly income in Uruguay is $2000-$3000 USD per household. This guy just got awarded more than ten times that.

Re: $36k Google App Engine RCE

#49
post #45
post #23

Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in money), and a bounty from Google under his belt - he won't have trouble finding work. If I was considering hiring him, the creative bit of guerilla marketing for The Expanse he threw in there wouldn't hurt his chances either.

I’m not sure how familiar you are with South America but Uruguay is one of the most developed countries in the Western Hemisphere, in the group right behind the US and Canada.

His bounty is equivalent to a year's salary for a very good senior developer in here. So I believe his point stands.

Re: $36k Google App Engine RCE

#50
post #43

Earlier quoted context omitted.

Let's try a thought experiment. To make things easier, imagine you're 21 years old, not 18, and have made up those 3 years working in the industry. You found this vulnerability, and have decided not to submit it for a bounty, but rather to the black market. Who do you sell it to? I assume your answer will involve putting it up on some darknet version of Craigslist. That's fine, but then tell me: who's paying for it?…

You don't have to think about it too hard, there's companies that will help you with the transaction. https://www.zerodium.com/

First, you can just go look at Zerodium's website and see what they'll buy. Notice that one-off vulnerabilities aren't there at all: there are no vulnerability types on their rate sheet that a single vendor can instantaneously fix worldwide with a single patch.

Notice also that with just a couple exceptions, RCEs in extremely widespread serverside web components are valued at $10k (if you believe their price list; I'm skeptical of it). Those are vulnerabilities that all have half-lives after patches are issued --- that's a ceiling for what anything like this could be worth.

Second, Zerodium isn't "the black market".

Post reply on HN