Live data from Hacker News

$36k Google App Engine RCE

sites.google.com

81–90 of 164 posts

Re: $36k Google App Engine RCE

#81

Earlier quoted context omitted.

XXXX == what types of things? I’m curious why there was no auth required for his calls.

* Grab nearly all of googles source code (no extra auth required for that, since so many libraries read config etc from the source code repo) * Make the right requests to one endpoint he found and retrieve company financials, number of hits to every google service, the name of every application running in every datacenter, etc. * With the above two things, you know the location of services and every RPC endpoint on t…

Wow, that is quite significant.

36k is not a small bounty for an RCE, but I feel like this is more critical to Google than the highest Android payout, for which they pay up to 200k for: https://www.google.com/about/appsecurity/android-rewards/

Re: $36k Google App Engine RCE

#82
post #43
post #23

Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in money), and a bounty from Google under his belt - he won't have trouble finding work. If I was considering hiring him, the creative bit of guerilla marketing for The Expanse he threw in there wouldn't hurt his chances either.

Let's try a thought experiment. To make things easier, imagine you're 21 years old, not 18, and have made up those 3 years working in the industry. You found this vulnerability, and have decided not to submit it for a bounty, but rather to the black market. Who do you sell it to? I assume your answer will involve putting it up on some darknet version of Craigslist. That's fine, but then tell me: who's paying for it?…

Given the way this exploit was developed, I honestly think he got something on the order of the ceiling that someone who is not already known/connected on the black market could hope for. The act of advertising it in any way that could convey its potential value would likely burn it. Any pitch on the black market would tip your hand to people who had access to service logs for the past several weeks.

The only way you could sell it is if you already had connections directly to people who were known to need an exploit for this service and had a channel to approach them privately, IMO.

For someone in the author's situation, I think he got a very good deal and almost certainly made some great contacts that he will be happy to have in the future.

(That's a long way of saying that when I run that particular thought experiment, in the context of a vulnerability where discovery provides a certain amount of disclosure should anyone go back and check logs, I have a hard time seeing a more lucrative black market. I think the math would be different in less centralized cases.)

Re: $36k Google App Engine RCE

#83

Looks like the "Hall of Fame" link in the bounty confirmation email is broken / not rendering: https://www.google.com/about/appsecurity/hall-of-fame/

It appears to be hosted at https://bughunter.withgoogle.com/rank/hof

(From following this error: "Refused to display 'https://bughunter.withgoogle.com/0x0A?embed=1' in a frame because it set 'X-Frame-Options' to 'deny'.")

Re: $36k Google App Engine RCE

#84
post #53
post #50

Earlier quoted context omitted.

First, you can just go look at Zerodium's website and see what they'll buy. Notice that one-off vulnerabilities aren't there at all: there are no vulnerability types on their rate sheet that a single vendor can instantaneously fix worldwide with a single patch. Notice also that with just a couple exceptions, RCEs in extremely widespread serverside web components are valued at $10k (if you believe their price list; I'…

I was in fact thinking of exploit brokers as well, so my wording was unclear. Let's call it the grey/black market. In the scenario you described, without any other contacts and/or experience with transactions like this, I would approach an exploit broker. As for the payout - I assumed that any RCE vulnerability that qualifies for Google's highest bounty is likely to fetch a higher price elsewhere. My experience with…

It actually turns out to be not that simple to approach organized crime for an one-off transaction. If that would be simple for you, then it would be exceedingly easy for LEO to get to these players as well.

Re: $36k Google App Engine RCE

#85

> I am 18-year-old student at the University of the Republic [Uruguay] interested in computer security Someone could say that he could have gotten even more money by selling his findings in the black market, very difficult but doable. However, as someone who understands how studying computer science in a 3rd-world country is, getting USD +36k in a legal way and from a company that is considered one of the best in the…

I remember crying/laughing/screaming when I won three GameBoy Advance games from some kids magazine. I would say he's pretty happy with himself.

Re: $36k Google App Engine RCE

#86
post #5

> I am 18-year-old student at the University of the Republic [Uruguay] interested in computer security Someone could say that he could have gotten even more money by selling his findings in the black market, very difficult but doable. However, as someone who understands how studying computer science in a 3rd-world country is, getting USD +36k in a legal way and from a company that is considered one of the best in the…

That's pretty advanced stuff for an 18y/o, even for most senior developers. No doubt Google will try to recruit him after he finishes university.

What I appreciated most about it (or maybe this is just his writeup skills), but how not advanced each of the things were. It was just mostly him Googling things and making random guesses at the rabbit hole until he found something.

The skill, I guess, comes in piecing it all together and consistently making good guesses.

Re: $36k Google App Engine RCE

#88
post #40

Any idea how such rewards get taxed ?

On the receiving end if you're non-US-based? You're supposed to figure it out yourself (ie. pay local applicable income tax), they just want a W8BEN. Source: got a Google VRP reward.

so US government does not take an cut ?

Re: $36k Google App Engine RCE

#89
post #5

Earlier quoted context omitted.

That's pretty advanced stuff for an 18y/o, even for most senior developers. No doubt Google will try to recruit him after he finishes university.

What I appreciated most about it (or maybe this is just his writeup skills), but how not advanced each of the things were. It was just mostly him Googling things and making random guesses at the rabbit hole until he found something. The skill, I guess, comes in piecing it all together and consistently making good guesses.

The tenacity is as important as the skill. He knew there was a way, he just had to find it.

Re: $36k Google App Engine RCE

#90
post #53

Earlier quoted context omitted.

I was in fact thinking of exploit brokers as well, so my wording was unclear. Let's call it the grey/black market. In the scenario you described, without any other contacts and/or experience with transactions like this, I would approach an exploit broker. As for the payout - I assumed that any RCE vulnerability that qualifies for Google's highest bounty is likely to fetch a higher price elsewhere. My experience with…

It actually turns out to be not that simple to approach organized crime for an one-off transaction. If that would be simple for you, then it would be exceedingly easy for LEO to get to these players as well.

Clearly. As pointed out/clarified in another comment I was mostly thinking of the grey area companies who buy 0-days and sell them to governments, law enforcement and god knows who.
Post reply on HN