The $60k bug was an exploit. the extra $37,604 was pure recon. read this:
bug 1: internal Google API with NO permission checks
firefly-pa.googleapis[.]com
inside: a copy job → path A → path B.
problem? it stayed NEW forever. 🧱
so he found the worker callback that tells the scheduler “task complete” - with no caller verification.
called it himself:
{"taskId":"a030d1a000000000","status":{"status":"STATUS_COMPLETE_SUCCESS"}}
scheduler trusted him. job ran. 🚨
then bigstoreIdentifier turned out to accept more than Bigstore paths.
he tried:
[/]etc[/]passwd.borg
💥 millions of lines, including Google employee accounts.
Panel awards ⇢ $60,000
bug 2 ⇢ 3 days later 👀
that single idea paid $37,604 at Google.
the setup: an unauthenticated endpoint copies any file you name —
{"refFilename":"[/]etc[/]passwd"}
and on success returns {}. no filename, no path. the file is right there, but invisible.
what he did instead of giving up:
→ sent [/]etc[/]shadow instead. it FAILS, and the failure leaks the full destination path + filename format
→ wrapped the hidden copy in a /batch request, pinning everything to the same server
→ read the neighboring filenames from the failures — consecutive worker IDs, one gap. that gap was his file
→ interpolated the timestamps, predicted the cycle counter, streamed 771,000 candidates
the server confirmed the exact path. then he read it with his other bug ($60k one):
root:x:0:0:root:/root:/bin/bash ⚡
Panel awards $37,604.40