Live data from Hacker News

Google Bug Bounty – The $5k Error Page

slashcrypto.org

1–10 of 144 posts

Re: Google Bug Bounty – The $5k Error Page

#2
I discovered the same error/bug a few weeks ago when a co-worker linked "this weird page" to me, I just looked around and thought it's pretty cool too see that part of Google and didn't thought too much of it, closed the tab and went back to my Terminal. :)

Re: Google Bug Bounty – The $5k Error Page

#3
In at least two other companies I've worked at we also use query params to enable debug information on live production sites. At one of those companies the only requirement was that you be on a corporate ip address but it actually still works if you're on our guest wifi.

Re: Google Bug Bounty – The $5k Error Page

#5
So I was thinking recently... with Google (amongst others, of course) themselves pushing towards AI applications, it seems to me that many of these less-advanced* bounty hunts might perhaps be able to be automated with a fuzzer+scraper+AI based approach. The fact that bug bounties are still being awarded does suggest that this is not that trivial, however, but might still be fun to explore nonetheless. I.e. can one train an agent that goes off and tries this sort of things autonomously? Might be fun to translate the HTTP intrusion domain into a deep learning architecture.

Similar things are being applied on the "defensive" side of things already anyway (i.e. Iranian, Turkish, Chinese firewall systems using machine learning to identify and block new patterns), so why not apply this on the offensive side.

*: Not to demean the author in any way; I understand that putting the time in to explore these things is easier said than done in hindsight.

Re: Google Bug Bounty – The $5k Error Page

#7
post #2

I discovered the same error/bug a few weeks ago when a co-worker linked "this weird page" to me, I just looked around and thought it's pretty cool too see that part of Google and didn't thought too much of it, closed the tab and went back to my Terminal. :)

I am a bit jealous :).

I also did a subdomain search on google a few weeks ago. I stumbled upon a lot of login sites.

A subdomain search leaded to 95 subdomains under corp.google.com.

There is some strange javascript in those pages, there is a function called riskMi.

I don't want to get sucked into it, I'm also closing the tab and going back to my terminal :).

Re: Google Bug Bounty – The $5k Error Page

#9
post #5

So I was thinking recently... with Google (amongst others, of course) themselves pushing towards AI applications, it seems to me that many of these less-advanced* bounty hunts might perhaps be able to be automated with a fuzzer+scraper+AI based approach. The fact that bug bounties are still being awarded does suggest that this is not that trivial, however, but might still be fun to explore nonetheless. I.e. can one t…

It is an interesting subject to research but not easy. Finding and the exploiting a bug is art and science.

Augmenting fuzzying with AI is an interesting approach.

Re: Google Bug Bounty – The $5k Error Page

#10

I'm surprised that anyone at the big Corp actually bothered to even reply to this guy reporting the bug much less actually give him a bounty!

Where is this resentment and skepticism coming from? The facts say otherwise. Google is known to be receptive to bounties and payout.
Post reply on HN