๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Abhishek
@aacle_
Building @Vulncure โšก| Helping founders fix vulnerabilities before hackers find them. Talk to me about: Bug Bounties, LLM Security & React.
๊ฐ€์ž… June 2017
292 ํŒ”๋กœ์ž‰ ์ค‘    49.3K ํŒฌ
The $60k bug was an exploit. the extra $37,604 was pure recon. read this: bug 1: internal Google API with NO permission checks firefly-pa.googleapis[.]com inside: a copy job โ†’ path A โ†’ path B. problem? it stayed NEW forever. ๐Ÿงฑ so he found the worker callback that tells the scheduler โ€œtask completeโ€ - with no caller verification. called it himself: {"taskId":"a030d1a000000000","status":{"status":"STATUS_COMPLETE_SUCCESS"}} scheduler trusted him. job ran. ๐Ÿšจ then bigstoreIdentifier turned out to accept more than Bigstore paths. he tried: [/]etc[/]passwd.borg ๐Ÿ’ฅ millions of lines, including Google employee accounts. Panel awards โ‡ข $60,000 bug 2 โ‡ข 3 days later ๐Ÿ‘€ that single idea paid $37,604 at Google. the setup: an unauthenticated endpoint copies any file you name โ€” {"refFilename":"[/]etc[/]passwd"} and on success returns {}. no filename, no path. the file is right there, but invisible. what he did instead of giving up: โ†’ sent [/]etc[/]shadow instead. it FAILS, and the failure leaks the full destination path + filename format โ†’ wrapped the hidden copy in a /batch request, pinning everything to the same server โ†’ read the neighboring filenames from the failures โ€” consecutive worker IDs, one gap. that gap was his file โ†’ interpolated the timestamps, predicted the cycle counter, streamed 771,000 candidates the server confirmed the exact path. then he read it with his other bug ($60k one): root:x:0:0:root:/root:/bin/bash โšก Panel awards $37,604.40
๋” ๋ณด๊ธฐ