Considering that, Google probably has an extensive monitoring system running in the VM, looking for things happening that shouldn't happen... And they have probably also built a filtering infrastructure between the users and the SQL server so that if any vulnerability is found, they can at least filter attempts to exploit it while a fix is being made.
GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
11–20 of 54 posts
Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#12Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#13I'm pretty impressed with the GCP response, both the fact that they identified the behavior and took the first step in reaching out.
The other way to see it, is that it took them 8 days to notice a full compromise of the hosting OS and an open access to Google’s internal docker image repository URL.
Likewise, GCP Dataflow quite trivially allows you to escape onto the worker machines and take the (huge) binaries that implement it. They have some really nice detailed status pages!
Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#14"Our research began when we identified a gap in GCP’s security layer that was created for SQL Server."
It would have been interesting to see how they identified that security gap.
Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#15I'm pretty impressed with the GCP response, both the fact that they identified the behavior and took the first step in reaching out.
The other way to see it, is that it took them 8 days to notice a full compromise of the hosting OS and an open access to Google’s internal docker image repository URL.
Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#16Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#17I don’t know why, but I was disappointed they didn’t disclose how much the reward was.
https://bughunters.google.com/about/rules/6625378258649088/g...
Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#18Remember that MS SQL server isn't Google code... Any vulnerabilities it may contain they might be powerless to fix. Considering that, Google probably has an extensive monitoring system running in the VM, looking for things happening that shouldn't happen... And they have probably also built a filtering infrastructure between the users and the SQL server so that if any vulnerability is found, they can at least filter…
Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#19Getting access to the host OS won't give you much other than some internal binaries and config.