Live data from Hacker News

I have gained admin access to numerous GCloud Organizations by accident

news.ycombinator.com

121–130 of 132 posts

Re: I have gained admin access to numerous GCloud Organizations by accident

#121

A few months ago I stumbled upon a bug in a state machine that allowed me to obtain stuff without having to pay for it. It was a weird combination of steps and was kind of hard to explain. I submitted a ticket to the support team advising them in painstaking detail the steps needed to reproduce this vulnerability. They could also look at my account and see that I got stuff without paying. A couple days later I got a…

I can tell you “your obtain stuff without paying by doing a weird combination of steps” is happens quite a bunch of times and is not a bug but some sort of easer egg. For a while there was a chain in Europe where if you scanned products in a specific order at the till it would be kick in difference price :)

Re: I have gained admin access to numerous GCloud Organizations by accident

#122

Earlier quoted context omitted.

There are quite a few post on Raymond Chen's "The Old New Thing" blog about bogus security reports e.g. this one [1] from 2022 or this one [2] from 2006. They're often described as requiring you to already be "on the other side of this airtight hatchway" (a Hitchhiker's Guide to the Galaxy reference) because you already need admin rights in order to get admin rights. That seems to suggest that Microsoft takes all sec…

If MS really investigates all bug reports that is good. But, it seems like this should be expected? From misc. articles I've seen (mainly posted here on HN; I don't buy MS products) MS dismisses bug reports as unimportant and sometimes takes an extremely long time to address known security vulnerabilities. This VM escape was initially reported as an RDP bug that MS dismissed as unimportant, until it was used as a VM…

> The (in)famous pass-the-hash bug in windows

I can't find any articles for this whatsoever on Google. No matter how many times I include "windows" or "microsoft" (quoted or otherwise) I only get clickbait SEO-spam articles talking about pass-the-hash vulnerabilities in general, not any description or reference to a specific incident in Windows.

Could you please link some article about this so I can read about it?

Re: I have gained admin access to numerous GCloud Organizations by accident

#123

Earlier quoted context omitted.

If MS really investigates all bug reports that is good. But, it seems like this should be expected? From misc. articles I've seen (mainly posted here on HN; I don't buy MS products) MS dismisses bug reports as unimportant and sometimes takes an extremely long time to address known security vulnerabilities. This VM escape was initially reported as an RDP bug that MS dismissed as unimportant, until it was used as a VM…

> The (in)famous pass-the-hash bug in windows I can't find any articles for this whatsoever on Google. No matter how many times I include "windows" or "microsoft" (quoted or otherwise) I only get clickbait SEO-spam articles talking about pass-the-hash vulnerabilities in general , not any description or reference to a specific incident in Windows. Could you please link some article about this so I can read about it?

Try: https://www.coresecurity[.]com/sites/default/files/private-f... for a discussion that mentions Paul Ashton's PtH toolkit from ~1997 or so.

Re: I have gained admin access to numerous GCloud Organizations by accident

#124

Earlier quoted context omitted.

> The (in)famous pass-the-hash bug in windows I can't find any articles for this whatsoever on Google. No matter how many times I include "windows" or "microsoft" (quoted or otherwise) I only get clickbait SEO-spam articles talking about pass-the-hash vulnerabilities in general , not any description or reference to a specific incident in Windows. Could you please link some article about this so I can read about it?

Try: https://www.coresecurity[.]com/sites/default/files/private-f... for a discussion that mentions Paul Ashton's PtH toolkit from ~1997 or so.

please don't defang that link. It makes it nearly impossible to access in my browser. Right clicking to copy doesn't work (no "Copy" option in context menu). Selecting to copy doesn't work, because HN cuts off the link. I had to open developer tools just to grab the value of the `href` attribute and then edit out the brackets.

But thank you for the PDF, it seems like an interesting read!

(non-defanged link for any future visitors: https://www.coresecurity.com/sites/default/files/private-fil...)

Re: I have gained admin access to numerous GCloud Organizations by accident

#126

As a person who paid for Google's "Gold" support. They are less than useless. Don't go into these accounts at all. Not even to try and help/contact them. Laws about this are very vague and no one within the ORG would want to admit that they made a mistake by adding you.

I’ve had access to both Google’s and Amazon’s paid support options (up to and including enterprise support). Amazon’s support has gone above and beyond for me over the years in ways I didn’t even expect or ask them to. In comparison, I agree with you that Google’s support is useless. My experiences with AWS support have actually left me with a positive impression of the platform, while my experiences with Google rein…

[deleted]

Re: I have gained admin access to numerous GCloud Organizations by accident

#127

Earlier quoted context omitted.

if one is conscientious enough to report themselves be removed, they could also simply ignore the access

There's liability in having access to some random crap, even if you don't intentionally use it. If something goes wrong, someone accesses or modifies something that they shouldn't have, you having access is going to be at _best_ confusing to everyone. At worst the cops or lawyers will come calling. Sure you'll _probably_ be able to talk them down, but does that sound like fun? Or what if someone breaks in to _your_ a…

And let's say those firms are creating some shady stuff like Silk Road. You'd have a hard time explaining to the Feds that you appear as an administrator because of a mistake.

Re: I have gained admin access to numerous GCloud Organizations by accident

#128

I'm the SRE oncall for Cloud IAM. Can you send me a message on linkedin (link in my profile)? I'll give you my Google corp account email address.

Hey! I sent you a friend request in LinkedIn, it didn’t let me message you directly without having LinkedIn premium

Can send you the whole 9 yards over there

Re: I have gained admin access to numerous GCloud Organizations by accident

#129

Earlier quoted context omitted.

Google should shut down Cloud because they allow groups to be added to IAM? That’s an interesting take.

I think you misinterpreted OP. He is making a pun with the widespread beliefs that a) Google doesn't care about giving user support for their products even if you pay b) Over a not-so-long time the survival rate of every Google product seems to drop to zero unless it is related to search and ads. So, the joke is that the problem would solve itself when google predictably kills this product.

I’m not sure that’s a pun. But on re-read I am seeing the humor. On my first read I just saw the tired vitriol, “google == bad”.
Post reply on HN