Live data from Hacker News

$36k Google App Engine RCE

sites.google.com

121–130 of 164 posts

Re: $36k Google App Engine RCE

#121
post #50

Earlier quoted context omitted.

First, you can just go look at Zerodium's website and see what they'll buy. Notice that one-off vulnerabilities aren't there at all: there are no vulnerability types on their rate sheet that a single vendor can instantaneously fix worldwide with a single patch. Notice also that with just a couple exceptions, RCEs in extremely widespread serverside web components are valued at $10k (if you believe their price list; I'…

Genuinely curious, what qualifies as one-off in these circumstances? Your phrasing-- "vulnerability...that a single vendor can instantaneously fix worldwide with a single patch" seems to me (non-professional but security interested techizen) to describe what a lot of vulnerabilities are. How would you (or a company like Zerodium) differentiate between a "one off" RCE exploit vs. the kind they would pay out for? BTW -…

> How would you (or a company like Zerodium) differentiate between a "one off" RCE exploit vs. the kind they would pay out for?

In the GAE case, Google can patch all deployments of their service on the same day, which is an "instantaneous fix".

If it were an RCE with a webserver, OS or some other popular software, that can't be patched "instantaneously" "worldwide". Each entity who maintains their own (i.e. nginx, Drupal, Redis, etc.) instance needs to be alerted to the patch and then apply it. That's an incredibly long tail.

Re: $36k Google App Engine RCE

#123

Earlier quoted context omitted.

I suspect the bug bounties are much more about deterring the sale of exploits to bad actors than about recruiting employees.

It's both. You could do the former by throwing huge sums of money at the problem.

What's your definition of huge?

Re: $36k Google App Engine RCE

#124
post #79
post #68

Earlier quoted context omitted.

Wow, a digital arms dealer. How is that they have not been destroyed or captured by someone's military?

There are dozens of firms like this, and have been for something like a decade now. The ostensibly totally above-board ones, like Zerodium, aren't "arms dealers"; they're controlled disclosure venues, which capture a premium from big companies and government buyers for access to threat intelligence information before they sit in vendor bug tracking systems for 3-9 months waiting for patches. There are, of course, rea…

I guess IC means "Intelligence Community", but what is a LEO? A Google search didn't provide meaningful results.

Re: $36k Google App Engine RCE

#125
post #124
post #79

Earlier quoted context omitted.

There are dozens of firms like this, and have been for something like a decade now. The ostensibly totally above-board ones, like Zerodium, aren't "arms dealers"; they're controlled disclosure venues, which capture a premium from big companies and government buyers for access to threat intelligence information before they sit in vendor bug tracking systems for 3-9 months waiting for patches. There are, of course, rea…

I guess IC means "Intelligence Community", but what is a LEO? A Google search didn't provide meaningful results.

Probably Law-Enforcement Organization?

Re: $36k Google App Engine RCE

#126
post #31
post #5

Earlier quoted context omitted.

That's pretty advanced stuff for an 18y/o, even for most senior developers. No doubt Google will try to recruit him after he finishes university.

(Edit: I appear to be a broken record) I spent a spell on a bug bounty program. There are some beasts out there in the 16-20yo age range, it's pretty crazy.

Their minds probably haven't been numbed by years of fixing shoddy code and writing CRUD apps yet.

Re: $36k Google App Engine RCE

#127
post #124
post #79

Earlier quoted context omitted.

There are dozens of firms like this, and have been for something like a decade now. The ostensibly totally above-board ones, like Zerodium, aren't "arms dealers"; they're controlled disclosure venues, which capture a premium from big companies and government buyers for access to threat intelligence information before they sit in vendor bug tracking systems for 3-9 months waiting for patches. There are, of course, rea…

I guess IC means "Intelligence Community", but what is a LEO? A Google search didn't provide meaningful results.

[deleted]

Re: $36k Google App Engine RCE

#128

> I am 18-year-old student at the University of the Republic [Uruguay] interested in computer security Someone could say that he could have gotten even more money by selling his findings in the black market, very difficult but doable. However, as someone who understands how studying computer science in a 3rd-world country is, getting USD +36k in a legal way and from a company that is considered one of the best in the…

That's a lot of money, even in a first world country. That could get you a new car, or a deposit on a house (depending on where you are), or pay off a substantial chunk of your student loan (or all of it, if you're not in the USA).

Re: $36k Google App Engine RCE

#129

Earlier quoted context omitted.

Dude has cashed out a $10k and $30k bug bounty at the age of 18. Either he's lucky or he's very good. If he's the latter that $400k turns into an annual bounty. And very, very few Google engineers make that kind of money.

> And very, very few Google engineers make that kind of money. You'd be surprised. In Mountain View, everyone level 6 or above makes at least that amount, and most level 5s probably do as well. I'd guess that probably 20% of engineers are T5 or above, which is a ton of people when you multiply by tens of thousands of engineers.

Very few as a ratio. There aren't that many T6's and I'm not sold on the idea that "most" T5's are making $400,000 when the average is around $350,000 according to levels.fyi.

Re: $36k Google App Engine RCE

#130
post #23

Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in money), and a bounty from Google under his belt - he won't have trouble finding work. If I was considering hiring him, the creative bit of guerilla marketing for The Expanse he threw in there wouldn't hurt his chances either.

> the integrity to not sell something like this on the black market

Wouldn't the investigation lead to him? He noted he did not know, at the time, that it was an RCE. So he would need to research further (where he might trigger an alarm). He also noted he utilized staging environment, which he had access to due to previous found vulnerabilities (so Google had his personal details).

So, now imagine he found something and he had sold it. If it was used, Google would do a thorough investigation to find if given vulnerability was abused in the past. And they find this guy using it exploratory and nothing else. It's not hard to put 1+1 together after that.

While the idea of finding an exploit and selling it for hundreds of thousands of dollars on black market sounds exciting, it wouldn't be so easy in this case.

Post reply on HN