$7.5k Google services mix-up (2018)
sites.google.com
sites.google.com
It seems fairly safe to assume someone has already snapped this guy up. I can't recall the last time I felt so impressed reading some security writeup
https://opnsec.com/2018/07/into-the-borg-ssrf-inside-google-...
Source: Also a 19 y/o Googler.
I chose this over university - I get paid and am working towards a CS degree as part of the work. Granted, am not an intern (I'm something different) but I understand they are well paid at FAANG companies and the experience is the same.
If the work you do is valuable then it deserves a comp that matches a full time workers rate.
Also, we work in computer science and a for a vast majority of developers it's business as usual. So I wouldn't say that it's particularly generous or lucky.
Before this current job I hadn't worked as a professional (outside of minor freelance work in my home town) so I see this as bootstrapping a career with zero student debt, plus there's perks like travel opportunities and accelerated career growth which I couldn't easily get elsewhere.
> Also, we work in computer science and a for a vast majority of developers it's business as usual. So I wouldn't say that it's particularly generous or lucky.
I was lucky enough to be born into a good family, where I could learn the skills to be where I am today, no?
Right but I meant that Google offering a job or keeping you on payroll shouldn't feel like luck but like the default, expected behaviour in our field.
And that is almost surely only a tiny subset of what could be done via the the whole run with arbitrary permissions thing. Most of the other don't jump out as me as much as that one does, but I may just not recognize the significance of some of the permissions.
It is interesting that he could only make it work in the non-production environment, but I'm not sure if that would actually limit the capabilities meaningfully.
And the date should be (2019)
https://web.archive.org/web/20180215070105/https://sites.goo...
I'd guess that by messing with this stuff, it probably broke some internal systems that ended up firing alerts to engineers internally. Those engineers then 'discovered' the bug, and started fixing it.
Most systems at scale are designed to reject bad input, log it, but nobody takes any action.
A few systems have to process every record in order. For example, the billing system might go through every entry in a database table and add them to bills. If just one entry is malformed in some way and can't be added to the bill, it is retried. If there isn't success after a few retries, the whole process fails, and an engineer is paged to sort the problem.
I saw this kind of thing multiple times... You think you have fully sanitized every input, but someone always finds a way to add a 30 gigabyte surname to the addressbook, choose a profile image with negative dimensions, have a million devices share the same mac address, etc.
So impressive! This is great work.