Live data from Hacker News

How we got read access on Google’s production servers

blog.detectify.com

81–90 of 197 posts

Re: How we got read access on Google’s production servers

#81

This is another reason not to use XML, plain and simple It's too much hidden power in the hands of those who don't know what they're doing (loading external entities pointed in an XML automatically? what kind of joke is that?)

XML made it for more manageable to create machine to machine API's. I can say we surely would not want go back to the 80's and 90's when dong that stuff was a nightmare.

Re: How we got read access on Google’s production servers

#82
post #15

Just $10k? This sells for at least 10 times more on the black market. Why would one rationally chose to "sell" this to google instead of the black market. Some people don't break the law because they are afraid to get caught, but I like to believe that most people don't break the law because of the moral aspect. To me at least, selling this on the black market poses no moral questions, so, leaving aside "I'm afraid t…

I fear that your economic analysis is way too simple.

You should include damage to the company's reputation, should this get leaked. Specially since they work with security - and who would trust their security to people who sell vulnerabilities to the highest bidder?

This could cost than much more than your quote.

Re: How we got read access on Google’s production servers

#84

Earlier quoted context omitted.

Your word is incredibly important for criminal enterprises. If you fuck someone over and somebody finds out, nobody will ever do business with you again (besides the whole 'getting shot' thing). Escrow services (by way of a middle-man you both trust) are only necessary for really big jobs. In general you pay first and get your goods once payment is confirmed.

I can see that working in meatspace but here we're talking about selling an idea on the web - the buyer is very unlikely to be able to track you so they're unlikely to front the money. Suppose you found a bug, couldn't cash it in with Google because of where you live and so were selling it on. The buyer won't release the funds, would you really give up the goods? Even with an escrow, proving the transfer and performi…

- the buyer is very unlikely to be able to track you

the buyer will probably be easily able to track you, if they are paying 100k for hacks on the black market, they would have the resources to find you easily

Re: How we got read access on Google’s production servers

#85
post #81

This is another reason not to use XML, plain and simple It's too much hidden power in the hands of those who don't know what they're doing (loading external entities pointed in an XML automatically? what kind of joke is that?)

XML made it for more manageable to create machine to machine API's. I can say we surely would not want go back to the 80's and 90's when dong that stuff was a nightmare.

I give to you that it's better than CORBA

What I don't agree is that it allows a "load this" where this can be a local file, an url in some cases, anything basically

Re: How we got read access on Google’s production servers

#86
post #12

Is there a startup that can help automate custom attacks on websites? Like guide the webmaster to look for holes in their setup. I'm guessing some security expert can do a good job educating new businesses on how to prepare for the big bad world.

Check out https://www.tinfoilsecurity.com

Re: How we got read access on Google’s production servers

#87
post #9

In large production environments it's almost impossible to avoid bugs - and some of them are going to be nasty. What sets great and security conscious companies apart from the rest is how they deal with them. This is an examplary response from google. They respond promptly (with humor no less) and thank the guys that found the bug. Then they proceeded to pay out a bounty of $10.000. Well done google.

I am really glad about how they responded. Whenever Tinfoil has found vulnerabilities in companies like United Airlines[0], for example, those companies mostly respond with anger rather than graciousness.

[0] https://www.tinfoilsecurity.com/blog/132969897

Re: How we got read access on Google’s production servers

#88
post #8

So, when you have read access to googles prod servers, what else would be fun to do besides reading /etc/passwd ? Getting the source?

I'd say logins and passwords of millions of Google accounts would be the most valuable asset for a blackhat.

Re: How we got read access on Google’s production servers

#89
post #83

The guys behind this report have an interesting pricing model: Pay what you want! https://detectify.com/pricing The pricing models has apparently worked so far. Are any active users of Detectify here and can share their experience?

I like the price but they found nothing, honestly, and we're not very nice when I emailed them for support.

Re: How we got read access on Google’s production servers

#90

I hope it doesn't get unnoticed that the guys who discovered this vulnerability created a really great product, Detectify : https://detectify.com/ They also discovered vulnerabilities in many big websites (dropbox, facebook, mega, ...). Their blog also has many great write-ups : http://blog.detectify.com/

While they are probably good at doing this manually, their automated tool finds very little. And they were kind of assholes on support :(
Post reply on HN