GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
1–10 of 54 posts
Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#2Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#3Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#4Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#5Oh boy someone's not going to have a fun long weekend
Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#6Oh boy someone's not going to have a fun long weekend
Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#7Oh boy someone's not going to have a fun long weekend
Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#8I'm pretty impressed with the GCP response, both the fact that they identified the behavior and took the first step in reaching out.
With seccompbpf it's pretty simple to have systemwide tripwires on certain files/syscalls/network operations. Even if the attacker gains root, your tripwire will probably alert you before they can disable it.
Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#9I don’t know why, but I was disappointed they didn’t disclose how much the reward was.
Who knows - if Google hadn't detected the intrusion, this attack might be on the black market by now.
Re: GCP CloudSQL Vulnerability Leads to Internal Container Access and Data Exposure
#10I'm pretty impressed with the GCP response, both the fact that they identified the behavior and took the first step in reaching out.