Live data from Hacker News

Finding a $5,000 Google Maps XSS by fiddling with Protobuf

medium.com

1–10 of 21 posts

Re: Finding a $5,000 Google Maps XSS by fiddling with Protobuf

#3
post #2

I still think $5,000 is ridiculously low. Lots of research like this fails and it happens you do the work just to be told someone already filled a similar bug before.

the guys who were paid to implement this incorrectly were all paid over $5,000 a week. take the bounty out of their paychecks.

Re: Finding a $5,000 Google Maps XSS by fiddling with Protobuf

#8
post #4

Awesome find and write up. Wondering why you did not get the full $7500 for this https://www.google.com/about/appsecurity/reward-program/inde... How come accounts.google.com more severe than others for XSS ?

> How come accounts.google.com more severe than others for XSS ?

Because that's where the jewels are: "Control, protect, and secure your account, all in one place"

Re: Finding a $5,000 Google Maps XSS by fiddling with Protobuf

#9
post #2

I still think $5,000 is ridiculously low. Lots of research like this fails and it happens you do the work just to be told someone already filled a similar bug before.

Pretty elaborate research indeed, I once filed a very simple, but just as dangerous, stored XSS on www.linkedin.com (with access to cookies) + some other bug, hoping to speedup my Partner API Request, got $400 for the XSS and many weeks later $400 for the other bug too (which took them 6+ months to fix). The $/time wasn't worth it, and of course the Partner API Request got declined without explanation.
Post reply on HN