A few months ago I stumbled upon a bug in a state machine that allowed me to obtain stuff without having to pay for it. It was a weird combination of steps and was kind of hard to explain. I submitted a ticket to the support team advising them in painstaking detail the steps needed to reproduce this vulnerability. They could also look at my account and see that I got stuff without paying. A couple days later I got a…
I have gained admin access to numerous GCloud Organizations by accident
121–130 of 132 posts
Re: I have gained admin access to numerous GCloud Organizations by accident
#122Earlier quoted context omitted.
There are quite a few post on Raymond Chen's "The Old New Thing" blog about bogus security reports e.g. this one [1] from 2022 or this one [2] from 2006. They're often described as requiring you to already be "on the other side of this airtight hatchway" (a Hitchhiker's Guide to the Galaxy reference) because you already need admin rights in order to get admin rights. That seems to suggest that Microsoft takes all sec…
If MS really investigates all bug reports that is good. But, it seems like this should be expected? From misc. articles I've seen (mainly posted here on HN; I don't buy MS products) MS dismisses bug reports as unimportant and sometimes takes an extremely long time to address known security vulnerabilities. This VM escape was initially reported as an RDP bug that MS dismissed as unimportant, until it was used as a VM…
I can't find any articles for this whatsoever on Google. No matter how many times I include "windows" or "microsoft" (quoted or otherwise) I only get clickbait SEO-spam articles talking about pass-the-hash vulnerabilities in general, not any description or reference to a specific incident in Windows.
Could you please link some article about this so I can read about it?
Re: I have gained admin access to numerous GCloud Organizations by accident
#123Earlier quoted context omitted.
If MS really investigates all bug reports that is good. But, it seems like this should be expected? From misc. articles I've seen (mainly posted here on HN; I don't buy MS products) MS dismisses bug reports as unimportant and sometimes takes an extremely long time to address known security vulnerabilities. This VM escape was initially reported as an RDP bug that MS dismissed as unimportant, until it was used as a VM…
> The (in)famous pass-the-hash bug in windows I can't find any articles for this whatsoever on Google. No matter how many times I include "windows" or "microsoft" (quoted or otherwise) I only get clickbait SEO-spam articles talking about pass-the-hash vulnerabilities in general , not any description or reference to a specific incident in Windows. Could you please link some article about this so I can read about it?
Re: I have gained admin access to numerous GCloud Organizations by accident
#124Earlier quoted context omitted.
> The (in)famous pass-the-hash bug in windows I can't find any articles for this whatsoever on Google. No matter how many times I include "windows" or "microsoft" (quoted or otherwise) I only get clickbait SEO-spam articles talking about pass-the-hash vulnerabilities in general , not any description or reference to a specific incident in Windows. Could you please link some article about this so I can read about it?
Try: https://www.coresecurity[.]com/sites/default/files/private-f... for a discussion that mentions Paul Ashton's PtH toolkit from ~1997 or so.
But thank you for the PDF, it seems like an interesting read!
(non-defanged link for any future visitors: https://www.coresecurity.com/sites/default/files/private-fil...)
Re: I have gained admin access to numerous GCloud Organizations by accident
#125Re: I have gained admin access to numerous GCloud Organizations by accident
#126As a person who paid for Google's "Gold" support. They are less than useless. Don't go into these accounts at all. Not even to try and help/contact them. Laws about this are very vague and no one within the ORG would want to admit that they made a mistake by adding you.
I’ve had access to both Google’s and Amazon’s paid support options (up to and including enterprise support). Amazon’s support has gone above and beyond for me over the years in ways I didn’t even expect or ask them to. In comparison, I agree with you that Google’s support is useless. My experiences with AWS support have actually left me with a positive impression of the platform, while my experiences with Google rein…
Re: I have gained admin access to numerous GCloud Organizations by accident
#127Earlier quoted context omitted.
if one is conscientious enough to report themselves be removed, they could also simply ignore the access
There's liability in having access to some random crap, even if you don't intentionally use it. If something goes wrong, someone accesses or modifies something that they shouldn't have, you having access is going to be at _best_ confusing to everyone. At worst the cops or lawyers will come calling. Sure you'll _probably_ be able to talk them down, but does that sound like fun? Or what if someone breaks in to _your_ a…
Re: I have gained admin access to numerous GCloud Organizations by accident
#128I'm the SRE oncall for Cloud IAM. Can you send me a message on linkedin (link in my profile)? I'll give you my Google corp account email address.
Can send you the whole 9 yards over there
Re: I have gained admin access to numerous GCloud Organizations by accident
#129Earlier quoted context omitted.
Google should shut down Cloud because they allow groups to be added to IAM? That’s an interesting take.
I think you misinterpreted OP. He is making a pun with the widespread beliefs that a) Google doesn't care about giving user support for their products even if you pay b) Over a not-so-long time the survival rate of every Google product seems to drop to zero unless it is related to search and ads. So, the joke is that the problem would solve itself when google predictably kills this product.