Live data from Hacker News

$36k Google App Engine RCE

sites.google.com

21–30 of 164 posts

Re: $36k Google App Engine RCE

#21

This is not an inconsequential amount of cash, for sure. Especially at 18! Congrats! And a great write-up to boot. Just awesome. All that said an honest question: why would a company like Google not pay insane amounts of money for these kinds of bug finds? What would they pay their own people to find them? Seems like RCE on App Engine should be worth 100K+ and then some on top for giggles just because they can. Obvio…

They pay their own people a salary - having a dependable living (at a very, very nice rate) is a pretty awesome thing. Sometimes there are bonuses involved, but they're usually not on the order of magnitude of external bug bounties.

My understanding of the pricing is that it's designed to make ethical behavior profitable enough that fewer people are tempted to sell the exploits on the black market, not necessarily to out-compete the black market entirely. I think this person's find is a great example - it's a resume-booster, a great experience, a very nice cash infusion, and helps, instead of hindering, their job prospects with future employers.

Re: $36k Google App Engine RCE

#22
post #14

Earlier quoted context omitted.

Soviets, East Germany... in 2018?

The terms first, second and third world were coined during the cold war, during which those countries did exist. First world were countries allied with the US. Second world were countries allied with the USSR. Third world were neutral countries. So Switzerland, Ireland, and Sweden are third world countries.

While the terms may have been originally coined during the Cold War, the meaning and common usage has clearly changed. If you use 'third world countries' in a conversation hardly anyone will assume that you're including Switzerland in that. When enough people use a word "wrong" for a long enough time, they kinda stop being wrong.

Re: $36k Google App Engine RCE

#23
Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in money), and a bounty from Google under his belt - he won't have trouble finding work. If I was considering hiring him, the creative bit of guerilla marketing for The Expanse he threw in there wouldn't hurt his chances either.

Re: $36k Google App Engine RCE

#24
post #23

Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in money), and a bounty from Google under his belt - he won't have trouble finding work. If I was considering hiring him, the creative bit of guerilla marketing for The Expanse he threw in there wouldn't hurt his chances either.

As someone who worked in a bug bounty program, the skill and age of this individual isn't what sets them apart. It's the write up.

Re: $36k Google App Engine RCE

#25
post #10

Earlier quoted context omitted.

Uruguay is not third world country.

Yes it is. I do not want to be that stickler but this is the charts for that term: 1st world: US, UK, West Germany, essentially western countries 2nd world: Soviets, East Germany, communist countries 3rd world: everyone who doesn’t fit the Cold War theater. Either way, a GDP per capita of $15k isn’t considered “first” at whatever category you want to assign it by. Unfortunately there are no “1st world” countries in L…

"X World" has gone he way of "begs the question", "Literally vs. Figuratively", "One bad apple..", etc. Popular usage has destroyed the original meaning, and it's no use trying to get people on board with what those phrases actually mean.

Re: $36k Google App Engine RCE

#26
post #2

This report showcases a ton of tenacity and thoroughness. Not his first time as well: https://sites.google.com/site/testsitehacking/10k-host-heade... . Very impressive. “Please stop exploring this further, as it seems you could easily break something” has got to be the best reply one can receive to a bug bounty report.

That's what struck me. From the well told story I feel like there were several points of "welp probably can't go further then this better move on to something else" but he kept going and going and sure enough he got somewhere. Hope to see more work published by him over the next few years!

Re: $36k Google App Engine RCE

#28

I used to work support for GAE and recognize all of this. This is really impressive, congrats on the great work and huge bounty. Keep it up!

Same; I worked on GAE in 2013 and it's so funny to read the story of someone exploring, discovering, and being so close to breaking something you know really well. There's a few moments in here where I thought "oh man, you could have done XXXX and that would have been so bad!". Definitely understand why they gave them the big bucks for this one.

Re: $36k Google App Engine RCE

#29
post #20

Another thing that is very admirable and bold is that he had no actual idea that he discovered a RCE vuln but went ahead and confidently contacted google. How many would stop at "Eh I managed to fire requests to a hidden RPC service in google, but couldn't figure out how to make it do anything useful to qualify". Put yourselves and your work/findings out there people!

Yes, if he had known more about Google infrastructure, he could have done some damage, both active and passive. He had access to a lot of internals. I was surprised by them at first, too, but they all make sense. On the other hand, he would have probably been caught fairly rapidly.

One thing to note is that Google, like any responsible organization should, has layered security and threat models that include insiders as a potential threat; hopefully, while he could make RPC calls to internal services (which is itself a serious problem, hence the giant bounty) he hopefully could not authenticate to do anything any serious damage or access any sensitive information.
Post reply on HN