登録して招待リンクを共有すると、動画再生報酬と紹介報酬を獲得できます。

Abhishek
@aacle_
Building @Vulncure ⚡| Helping founders fix vulnerabilities before hackers find them. Talk to me about: Bug Bounties, LLM Security & React.
参加 June 2017
292 フォロー中    49.3K ファン
The $60k bug was an exploit. the extra $37,604 was pure recon. read this: bug 1: internal Google API with NO permission checks firefly-pa.googleapis[.]com inside: a copy job → path A → path B. problem? it stayed NEW forever. 🧱 so he found the worker callback that tells the scheduler “task complete” - with no caller verification. called it himself: {"taskId":"a030d1a000000000","status":{"status":"STATUS_COMPLETE_SUCCESS"}} scheduler trusted him. job ran. 🚨 then bigstoreIdentifier turned out to accept more than Bigstore paths. he tried: [/]etc[/]passwd.borg 💥 millions of lines, including Google employee accounts. Panel awards ⇢ $60,000 bug 2 ⇢ 3 days later 👀 that single idea paid $37,604 at Google. the setup: an unauthenticated endpoint copies any file you name — {"refFilename":"[/]etc[/]passwd"} and on success returns {}. no filename, no path. the file is right there, but invisible. what he did instead of giving up: → sent [/]etc[/]shadow instead. it FAILS, and the failure leaks the full destination path + filename format → wrapped the hidden copy in a /batch request, pinning everything to the same server → read the neighboring filenames from the failures — consecutive worker IDs, one gap. that gap was his file → interpolated the timestamps, predicted the cycle counter, streamed 771,000 candidates the server confirmed the exact path. then he read it with his other bug ($60k one): root:x:0:0:root:/root:/bin/bash ⚡ Panel awards $37,604.40
もっと見る