This is another reason not to use XML, plain and simple It's too much hidden power in the hands of those who don't know what they're doing (loading external entities pointed in an XML automatically? what kind of joke is that?)
How we got read access on Google’s production servers
81–90 of 197 posts
Re: How we got read access on Google’s production servers
#82Just $10k? This sells for at least 10 times more on the black market. Why would one rationally chose to "sell" this to google instead of the black market. Some people don't break the law because they are afraid to get caught, but I like to believe that most people don't break the law because of the moral aspect. To me at least, selling this on the black market poses no moral questions, so, leaving aside "I'm afraid t…
You should include damage to the company's reputation, should this get leaked. Specially since they work with security - and who would trust their security to people who sell vulnerabilities to the highest bidder?
This could cost than much more than your quote.
Re: How we got read access on Google’s production servers
#83The pricing models has apparently worked so far. Are any active users of Detectify here and can share their experience?
Re: How we got read access on Google’s production servers
#84Earlier quoted context omitted.
Your word is incredibly important for criminal enterprises. If you fuck someone over and somebody finds out, nobody will ever do business with you again (besides the whole 'getting shot' thing). Escrow services (by way of a middle-man you both trust) are only necessary for really big jobs. In general you pay first and get your goods once payment is confirmed.
I can see that working in meatspace but here we're talking about selling an idea on the web - the buyer is very unlikely to be able to track you so they're unlikely to front the money. Suppose you found a bug, couldn't cash it in with Google because of where you live and so were selling it on. The buyer won't release the funds, would you really give up the goods? Even with an escrow, proving the transfer and performi…
the buyer will probably be easily able to track you, if they are paying 100k for hacks on the black market, they would have the resources to find you easily
Re: How we got read access on Google’s production servers
#85This is another reason not to use XML, plain and simple It's too much hidden power in the hands of those who don't know what they're doing (loading external entities pointed in an XML automatically? what kind of joke is that?)
XML made it for more manageable to create machine to machine API's. I can say we surely would not want go back to the 80's and 90's when dong that stuff was a nightmare.
What I don't agree is that it allows a "load this" where this can be a local file, an url in some cases, anything basically
Re: How we got read access on Google’s production servers
#86Is there a startup that can help automate custom attacks on websites? Like guide the webmaster to look for holes in their setup. I'm guessing some security expert can do a good job educating new businesses on how to prepare for the big bad world.
Re: How we got read access on Google’s production servers
#87In large production environments it's almost impossible to avoid bugs - and some of them are going to be nasty. What sets great and security conscious companies apart from the rest is how they deal with them. This is an examplary response from google. They respond promptly (with humor no less) and thank the guys that found the bug. Then they proceeded to pay out a bounty of $10.000. Well done google.
Re: How we got read access on Google’s production servers
#88So, when you have read access to googles prod servers, what else would be fun to do besides reading /etc/passwd ? Getting the source?
Re: How we got read access on Google’s production servers
#89The guys behind this report have an interesting pricing model: Pay what you want! https://detectify.com/pricing The pricing models has apparently worked so far. Are any active users of Detectify here and can share their experience?
Re: How we got read access on Google’s production servers
#90I hope it doesn't get unnoticed that the guys who discovered this vulnerability created a really great product, Detectify : https://detectify.com/ They also discovered vulnerabilities in many big websites (dropbox, facebook, mega, ...). Their blog also has many great write-ups : http://blog.detectify.com/