Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in money), and a bounty from Google under his belt - he won't have trouble finding work. If I was considering hiring him, the creative bit of guerilla marketing for The Expanse he threw in there wouldn't hurt his chances either.
I’m not sure how familiar you are with South America but Uruguay is one of the most developed countries in the Western Hemisphere, in the group right behind the US and Canada.
$36k Google App Engine RCE
51–60 of 164 posts
Re: $36k Google App Engine RCE
#52Re: $36k Google App Engine RCE
#53Earlier quoted context omitted.
You don't have to think about it too hard, there's companies that will help you with the transaction. https://www.zerodium.com/
First, you can just go look at Zerodium's website and see what they'll buy. Notice that one-off vulnerabilities aren't there at all: there are no vulnerability types on their rate sheet that a single vendor can instantaneously fix worldwide with a single patch. Notice also that with just a couple exceptions, RCEs in extremely widespread serverside web components are valued at $10k (if you believe their price list; I'…
In the scenario you described, without any other contacts and/or experience with transactions like this, I would approach an exploit broker. As for the payout - I assumed that any RCE vulnerability that qualifies for Google's highest bounty is likely to fetch a higher price elsewhere.
My experience with the field is limited and considering yours, if you are suggesting that this particular exploit would not fetch a significantly higher price, I shall stand corrected.
Re: $36k Google App Engine RCE
#54Earlier quoted context omitted.
First, you can just go look at Zerodium's website and see what they'll buy. Notice that one-off vulnerabilities aren't there at all: there are no vulnerability types on their rate sheet that a single vendor can instantaneously fix worldwide with a single patch. Notice also that with just a couple exceptions, RCEs in extremely widespread serverside web components are valued at $10k (if you believe their price list; I'…
I was in fact thinking of exploit brokers as well, so my wording was unclear. Let's call it the grey/black market. In the scenario you described, without any other contacts and/or experience with transactions like this, I would approach an exploit broker. As for the payout - I assumed that any RCE vulnerability that qualifies for Google's highest bounty is likely to fetch a higher price elsewhere. My experience with…
Re: $36k Google App Engine RCE
#55Earlier quoted context omitted.
I’m not sure how familiar you are with South America but Uruguay is one of the most developed countries in the Western Hemisphere, in the group right behind the US and Canada.
His bounty is equivalent to a year's salary for a very good senior developer in here. So I believe his point stands.
Re: $36k Google App Engine RCE
#56Earlier quoted context omitted.
His bounty is equivalent to a year's salary for a very good senior developer in here. So I believe his point stands.
Yes, but I don’t think you find a ton of highly skilled 18 year old software engineers in the US selling RCEs in the black market for $200K, so I’m not sure you find that in Uruguay.
The $2k limb is shaky because I guess in theory you could buy a GCE RCE for $2k and flip it to Google for their bounty payout, which will probably be at least $3,133.70.
Re: $36k Google App Engine RCE
#57It would be no skin of Google’s back to multiply these bug bounties by 10, and they should.
Re: $36k Google App Engine RCE
#58Earlier quoted context omitted.
I was in fact thinking of exploit brokers as well, so my wording was unclear. Let's call it the grey/black market. In the scenario you described, without any other contacts and/or experience with transactions like this, I would approach an exploit broker. As for the payout - I assumed that any RCE vulnerability that qualifies for Google's highest bounty is likely to fetch a higher price elsewhere. My experience with…
What's an "exploit broker"? Where would you find them? What price would you ask for this vulnerability?
Re: $36k Google App Engine RCE
#59Re: $36k Google App Engine RCE
#60"When issuing the reward, we'll take into account what you could have achieved with this access" makes me laugh. How scary must that be for the Google team? You know you've messed up so badly and the person who is investigating is doing so blindly with no knowledge or accountability if he breaks something. Yikes. Kudos to everyone for doing the right things. And great bounty- the average yearly income in Uruguay is $…
[1] https://www.ceicdata.com/en/indicator/uruguay/annual-househo...