TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

$36k Google App Engine RCE

602 pointsby louis-paulabout 7 years ago

17 comments

gnlabout 7 years ago
Those skills at 18, the integrity to not sell something like this on the black market (assuming here that an 18 year old in Uruguay isn't exactly swimming in money), and a bounty from Google under his belt - he won't have trouble finding work. If I was considering hiring him, the creative bit of guerilla marketing for The Expanse he threw in there wouldn't hurt his chances either.
评论 #17122348 未加载
评论 #17121548 未加载
评论 #17119797 未加载
评论 #17121666 未加载
评论 #17124556 未加载
guessmynameabout 7 years ago
&gt; <i>I am 18-year-old student at the University of the Republic [Uruguay] interested in computer security</i><p>Someone could say that he could have gotten even more money by selling his findings in the black market, very difficult but doable. However, as someone who understands how studying computer science in a 3rd-world country is, getting USD +36k in a legal way and from a company that is considered one of the best in the industry, it must have felt very good to get that mail.<p>Congratulations, and keep the good work.
评论 #17118680 未加载
评论 #17122610 未加载
评论 #17124339 未加载
评论 #17118741 未加载
评论 #17121503 未加载
评论 #17119130 未加载
Artemis2about 7 years ago
This report showcases a ton of tenacity and thoroughness. Not his first time as well: <a href="https:&#x2F;&#x2F;sites.google.com&#x2F;site&#x2F;testsitehacking&#x2F;10k-host-header" rel="nofollow">https:&#x2F;&#x2F;sites.google.com&#x2F;site&#x2F;testsitehacking&#x2F;10k-host-heade...</a>. Very impressive.<p>“Please stop exploring this further, as it seems you could easily break something” has got to be the best reply one can receive to a bug bounty report.
评论 #17120111 未加载
评论 #17122867 未加载
mabboabout 7 years ago
&quot;When issuing the reward, we&#x27;ll take into account what you could have achieved with this access&quot; makes me laugh.<p>How scary must that be for the Google team? You know you&#x27;ve messed up so badly and the person who is investigating is doing so blindly with no knowledge or accountability if he breaks something. Yikes.<p>Kudos to everyone for doing the right things. And great bounty- the average yearly income in Uruguay is $2000-$3000 USD per household. This guy just got awarded more than ten times that.
评论 #17122002 未加载
funkjunkyabout 7 years ago
I used to work support for GAE and recognize all of this. This is really impressive, congrats on the great work and huge bounty. Keep it up!
评论 #17120354 未加载
throwaway66666about 7 years ago
Another thing that is very admirable and bold is that he had no actual idea that he discovered a RCE vuln but went ahead and confidently contacted google.<p>How many would stop at &quot;Eh I managed to fire requests to a hidden RPC service in google, but couldn&#x27;t figure out how to make it do anything useful to qualify&quot;.<p>Put yourselves and your work&#x2F;findings out there people!
评论 #17119615 未加载
londons_exploreabout 7 years ago
He was about 2 API calls from being able to grab nearly all of googles source code from Google3 there...
评论 #17128007 未加载
评论 #17123620 未加载
评论 #17123517 未加载
评论 #17122160 未加载
pcardosoabout 7 years ago
Cute base amount, $31337... :)
评论 #17123510 未加载
评论 #17120352 未加载
sailfastabout 7 years ago
This is not an inconsequential amount of cash, for sure. Especially at 18! Congrats! And a great write-up to boot. Just awesome.<p>All that said an honest question: why would a company like Google not pay insane amounts of money for these kinds of bug finds? What would they pay their own people to find them? Seems like RCE on App Engine should be worth 100K+ and then some on top for giggles just because they can.<p>Obviously having a standard policy makes sense so that your community understands what to expect but as Google, what&#x27;s your operational impact if you triple &#x2F; quadruple vs. market value of the exploits?
评论 #17119649 未加载
degenerateabout 7 years ago
Looks like the &quot;Hall of Fame&quot; link in the bounty confirmation email is broken &#x2F; not rendering:<p><a href="https:&#x2F;&#x2F;www.google.com&#x2F;about&#x2F;appsecurity&#x2F;hall-of-fame&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.google.com&#x2F;about&#x2F;appsecurity&#x2F;hall-of-fame&#x2F;</a>
评论 #17122532 未加载
neosavvyabout 7 years ago
Google should send this guy a request to be hired. Clearly he&#x27;s as good as their internal engineering team and his write up was great.
评论 #17123130 未加载
gigatexalabout 7 years ago
I sure as hell wasnt this competent at 18 let alone now. Kudos to him.
russumabout 7 years ago
Huh, so you can run binaries in GAE by downloading a statically linked app to &#x2F;tmp, chmod&#x27;ing &amp; executing it? And there would be no limits on how it&#x27;s run? That&#x27;s crazy &amp; pretty cool!
评论 #17127736 未加载
ggg9990about 7 years ago
It would be no skin of Google’s back to multiply these bug bounties by 10, and they should.
评论 #17121952 未加载
jotadambalakiriabout 7 years ago
I don&#x27;t think it&#x27;s so easy to sell a vulnerability on the black market. If you send the code first they will have no incentive to send the money, if you get the money, you might not send the code.
评论 #17122868 未加载
doesnt_knowabout 7 years ago
I have almost 15 years on the OP and aren&#x27;t even half as talented. It looks like they&#x27;ve received almost $60k from Google across five bug bounties, very impressive.
Karishma1234about 7 years ago
Any idea how such rewards get taxed ?
评论 #17121425 未加载
评论 #17122640 未加载