The $60k bug was an exploit. the extra $37,604 was pure recon. read this:
bug 1: internal Google API with NO permission checks
firefly-pa.googleapis[.]com
inside: a copy job โ path A โ path B.
problem? it stayed NEW forever. ๐งฑ
so he found the worker callback that tells the scheduler โtask completeโ - with no caller verification.
called it himself:
{"taskId":"a030d1a000000000","status":{"status":"STATUS_COMPLETE_SUCCESS"}}
scheduler trusted him. job ran. ๐จ
then bigstoreIdentifier turned out to accept more than Bigstore paths.
he tried:
[/]etc[/]passwd.borg
๐ฅ millions of lines, including Google employee accounts.
Panel awards โข $60,000
bug 2 โข 3 days later ๐
that single idea paid $37,604 at Google.
the setup: an unauthenticated endpoint copies any file you name โ
{"refFilename":"[/]etc[/]passwd"}
and on success returns {}. no filename, no path. the file is right there, but invisible.
what he did instead of giving up:
โ sent [/]etc[/]shadow instead. it FAILS, and the failure leaks the full destination path + filename format
โ wrapped the hidden copy in a /batch request, pinning everything to the same server
โ read the neighboring filenames from the failures โ consecutive worker IDs, one gap. that gap was his file
โ interpolated the timestamps, predicted the cycle counter, streamed 771,000 candidates
the server confirmed the exact path. then he read it with his other bug ($60k one):
root:x:0:0:root:/root:/bin/bash โก
Panel awards $37,604.40