Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.
Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.

Critical Thinking - Bug Bounty Podcast · @criticalthinkingpodcast
Words
20,524
Runtime
1:25:28
Speaking pace
240wpm
Reading time
86min
240 words per minute, above the 201 75th percentile of 349 measured videos. That distribution comes from the 349-video hook study.
Opening (first 30 seconds)
I I don't know. I can't remember any dates or whatever, but I can remember I can remember that weird header. Or that password. I can remember the password of my first domain admin that I popped, you know, like but I can't I can't remember >> remember my I don't remember my own mom's birthday, but I remember I remember this one. >> [music] >> Best part about hacking when you can just, you know, critical thing, right? >> [music] [laughter] [gasps] >> Hey, what's up guys? Before we get into the show, I wanted to mention something super quick from our friends at ThreatLocker and I actually think you all are going to think it's pretty awesome because
120 words, the words spoken in the first 30 seconds at 240 words per minute.
Free, no signup. See how the first 30 seconds hold attention, with rewrites.
Sentence shape
| Measure | This transcript |
|---|---|
| Sentences | 1,469 |
| Average words per sentence | 14.0 |
| Longest sentence | 104 words |
| Questions asked | 296 |
| Sentences containing a number | 72 |
Most used terms
Filler phrases
1,567 in total: like 974 · right? 179 · you know 110 · um 69 · uh 63 · kind of 62 · sort of 38 · actually 32 · I mean 20 · literally 11 · basically 9.
A literal whole-word count of the same phrase list the Prepublish browser extension uses, so a phrase inside another word is not counted and a phrase used in its ordinary sense still is. It is a count and not a judgement.
What this transcript is
Every word below is the caption track YouTube publishes for this video, pulled from the video itself and reproduced unchanged. It is not Prepublish's writing, not a summary, and not a re-transcription: it is the video's own published captions. English captions, generated automatically by YouTube, in the video’s original language. Source: the video on YouTube. A channel that would rather this page did not exist can ask for its removal through the contact page, and it is removed.
No Script X-ray for this video: YouTube shows a Most replayed graph only once a video has enough views.
I I don't know. I can't remember any dates or whatever, but I can remember I can remember that weird header. Or that password. I can remember the password of my first domain admin that I popped, you know, like but I can't I can't remember >> remember my I don't remember my own mom's birthday, but I remember I remember this one. >> [music] >> Best part about hacking when you can just, you know, critical thing, right? >> [music] [laughter] [gasps] >> Hey, what's up guys?
Before we get into the show, I wanted to mention something super quick from our friends at ThreatLocker and I actually think you all are going to think it's pretty awesome because so much of bug bounty is often, you know, kind of quoted as like, "Yeah, but hackers will never exploit that because they can just get in via fishing." Well, that's actually true, you know, most of the time whenever companies get breached, it's because of fishing or access to that user's account or, you know, they do something like do a whole bunch of push notification 2FA and eventually a user gets so much fatigue they approve it.
But they have a solution for this. ThreatLocker has a thing called zero trust cloud access, right? Which prevents access to cloud resources or SaaS resources based on the device you're logging in from. So, if a user gets fished, right? They put in their credentials they get fished or they get vished, they the attacker has the credentials, maybe they even have a way to get the MFA because they did some sort of SIM swap because they have a hookup at Verizon or AT&T or whatever, right?
So, they have the credentials, they have the MFA, they still can't get in because the zero trust cloud access like will basically straight up allow or deny people access to resources based on the device you're logging in from. So, if you're an enterprise or a company and you're concerned about the highest risk, which really is fishing, this is a way to add a another like basically impenetrable layer to preventing it and securing your network.
Um yeah, back to the show. All right, dude. Um I guess we'll cut right in. I don't know, man. If you want to release the episode, we'll release the episode, but this is some crazy [ __ ] you're about to talk about. So, um Brute, thanks for coming on, man. I really appreciate it. Um I obviously you've done a lot of To be honest, that one blog post that you put with the uh rect proto was like an a life-changing thing for me uh when hacking Google.
So, you have nothing to prove, but the tradition is the tradition, so let's go ahead and start off with a bug before we get into your uh introduction. >> So, thanks so much for having me in the pod. So, yeah, the first the first bug I'll cover here is remote code execution in Borg, right? So, Google's top production. So, this bug is actually a super interesting. Like it's my it's my first RCE or well, it's two RCEs, but the way I found it was So, I had this whole AI scanning like set up, right?
So, my AI scanner would scan like all the APIs and then dark the dark Google and it would let me know if like any of them have a potential bug, right? So, this scanner actually notified me about few endpoints in this Etsy API. So, Cloud CRM IP frontend pa.googleapis.com. It's a mouthful, but yeah, this it was super interesting because the first endpoint I found was like this this endpoint it took in like a a Gaia ID and it would return an email.
So, this kind of like reminded me of like my old research or whatever. So, this by itself was kind of cool, but I looked through the the other endpoints in this API, right? And I saw some really weird endpoint. There was like this endpoint where it was like called get proto definition. So, in Google, right? Everything is protobuf, right? Literally literally everything. So, even the request that you send, it's it's just protobuf.
This is a protobuf message, right? So, if you can leak the type of this protobuf message, you can then use this get proto definition endpoint and it would just dump the whole protobuf there. So, So, that that was super useful. If I I wanted to scrape this, but but I asked >> [laughter] >> I wanted to I asked Sam and they're like, "Nope, you're you're not allowed." So, I had Yeah, I I got stuck there, but I would have loved to have to archive this for the whole Google. >> Yeah.
Oh my gosh, dude. I I that I have chills just thinking about that. Like, now every every cuz like, to be honest, man, one of the hardest things about hacking on Google is literally just dealing with the proto JSON proto buff nonsense that they kick out all the time. There's so much obscurity in there that you know, it's just it's horrible. So, and man, having the keys to the kingdom like that, that must have felt great. >> So, exactly.
And I think that mostly Google is People think it's a hard target, but I think it's just security by obscurity for a lot of it because How do you How do you know which endpoints to hit or whatever? It's It's not a like a traditional target in the sense that most other like apps or whatever. In this target, it's super weird. You have to just Reconnaissance is like the probably the most important thing in Google, right?
So, that's why That's why I published the the Recon proto research, which is essentially this this tool where you can hit any endpoint and use this like JSON plus proto buff. It's It's like this GSPB. It's like a super weird content type. But, for some reason, Google's back end would like leak a bunch of error messages so you can like probe it with with like random payloads and it will start dumping like everything that wants proto buff.
So, you can you can use this and like build out the whole request proto buff with this, right? So, this is super useful for a lot of my research. But, the the only problem is that it only works for APIs that have this specific content type enabled, right? Which a lot of APIs don't. So, this would have allowed for like dumping the proto buffs for those. And or even batch execute or these kind of like weird APIs. They're all They're all proto buff, but how are you supposed to know like what each parameter is?
It's just super confusing. But, yeah, with this you could have done that. So, I mean, I did I did use it a fair bit for here and there for like some of the research I'm working on to to kind of like see what each of them are, but I couldn't I couldn't touch too much on it. Yeah, but anyways, I I looked more into this this API, right? Cuz it was super interesting. And I saw that there was like this weird endpoint that's called like list quota queue.
So, it was taking in like a filter parameter. So, in in Google, right? The most annoying error that I keep getting is like invalid argument. So, for hacking like server-side, you just use It's like super generic error. It doesn't It doesn't tell you anything. If you hit the same error in like like intranet inside Google, right, you'll actually dump the full stack trace, but they don't They don't give us that. So, we're we're kind of screwed. >> That's interesting. >> like I was looking at like the the parameters that I could supply to the CPI.
And And one of them was like a filter parameter, right? And filter usually means like it's It's just It usually follows some sort of like AIP standard, right? So, I looked up this this standard of this filter. And I was I was trying a bunch of stuff. Like I tried like um various different things. And eventually I tried like client ID is greater than like 1 2 3 or something. And that that just worked. >> Oh my gosh. So, this is like a filter language that you're getting in here that you can inject.
Okay. >> Yeah, it's it's like some sort of I'm not too sure how it looks like in the back end, but I assume it's just some implementation of this this AIP, right? So, because everything in the AIP seemed to work here. So, yeah, I tried this, but >> like this. Yeah, okay. Interesting. AIP >> So, yeah, I tried that, but the the problem was it would say some error like oh this we can't we can't convert the response to JSON cuz I'm guessing they didn't like they didn't set up like a JSON like conversion thing for this.
They didn't They didn't have like a protobuf or something for this. So, yeah, that that was a that was a problem. So, I didn't I didn't know how to get past that, of course. Then I kind of realized that yeah, I could just use like all equals to proto, right? But even that had its problems because you can't just supply protobuf in like a JSON or like a Okay, so this is endpoint is just client 6 at google.com, right? And client 6 at google.com is like an alias to google APIs at google.com.
But the the difference is you can use cookies with it, right? That's what's kind of useful about But the problem is you can't use protobuf like direct You can't put a protobuf responses directly into client 6 at google.com cuz Google like freaks out about it. Like I'm not too sure why. I'm assuming some sort of like uh like XSS prevention. I don't I don't know. But they don't they don't allow you to just >> There's some like Like When you say protobuf responses, you mean like like binary Protobuf, not the proto JSON. >> Yeah, exactly. >> Okay. >> So, they they they just freak out.
But, so I remember this one trick, right? So, I'm sure you Do you guys know who Ismael Pereira is? >> Yeah. Oh, yeah. >> Yes. >> [laughter] >> Okay, so I I love this guy's content. So, I like I He had like some random video uploaded like I think one of his talks in in Box War, right? So, I literally went through every single second of that whole talk and like took down notes and everything. Everything he says is the gospel.
So, I was taking notes like constantly. And one of those notes in one of the second of his like hour-long video was this this header: X-Goog-Encoded-Response-If-Executable-Base64. >> Wow, dude. Okay. Okay, so now you've got this header that allows you to mutate the Protobuf that's coming out of the back end. >> Yeah, exactly. So, it converts it to base64, which is allowed for the front end or whatever. So, all right, it's allowed for client-side in Google Chrome.
So, once I had this, I could I could then dump like the response in in base64. It was It was massive, by the way. It was like super big. I think like the server took like 10 seconds to to even respond back. And then I just used like uh the protoc uh command line tool, and I just like dumped everything. I mean, I was able to also use the same Remember the get proto definition? I could just use that to just kind of find the proto definition for this, and then and I was able to decode it back. >> Wow.
Did you So So, did you get to this stop like point where you needed that header, and then you went and did the research to find it? Or did you already have that research like saved off, and then you just like when you were kind of scrambling, then you found it? >> I mean, it just came to me cuz I I remembered it I remembered everything cuz I took down all the notes, right? >> Yeah, basically you just had You had it up in the noggin.
There's no AI there. Just he had it. >> That's the classic That's the classic like, you know, hyperfocus hacker mentality is like I I I don't know. I can't remember any dates or whatever, but I can remember I can remember that weird header. >> Yes. >> password. I can remember the password of my first domain admin that I popped, you know, like but I can't I can't remember >> I don't remember my I don't remember my own mom's birthday, but I remember I remember this stuff. >> Exactly, exactly, dude.
It's that hyper hyper hacker focus. Um that's a great tip though when converting if you're getting raw protobuf out of a you know, client6.google, right? Then or else you won't be. But you can get this out with this, which is pretty cool. And and so let me ask one clarifying question here though because um you said Google APIs, right? That's of course Google APIs and client6.google.com have a you know, relationship there.
If were you saying that googleapis.com you can get the raw proto out? Uh but you can't do it on client6.google.com. >> you can't use first-party you can't use first-party authentications. This whole endpoint was working with first-party auth, which is a cookie auth, right? So you can't you can't use it with Google APIs. That's the problem. >> Mm. Okay. So so if you tried to hit the same endpoint on Google APIs it it wouldn't work because first-party auth doesn't work there.
So you had to do it through client6. Mm. >> Exactly. Yeah. >> Wow, very interesting, man. You you know a lot of these little these little quirks of Google. This is Once again, I can't believe you're sharing this, but thank you so much. We really we this is very helpful. So all right, what you you finally get the response out base64, you proto C to get the actual raw data out, and what do you see? >> So inside there it was a bunch of like random stuff like random like workflow internal workflows.
So I was looking at what what exactly is this? It seemed to be some sort of like task. So a Googler can configure a task, right? And then this is the execution log of the task, right? So I'll see some weird like spanner syncing to Salesforce. The spanner's like Google's like internal database. I mean, they have a the cloud product for it as well, but they use this everywhere. So it was it was really quite interesting.
So okay, at this point I I already like reported it cuz like I don't want to touch too much. Like I've I've have experience in the past where like I went through far whatever. I don't want to risk anything. So I just reported then I keep looking after that, right? So I sent I sent the report but then I wanted to see like even deeper because see they're they're executing tasks here. So can I execute my own task? Because that was that would be pretty interesting.
So I looked at the discovery document, right? So I was I was going through the whole document and I noticed like one thing that was super interesting. Generic stubby type task V2. >> Mhm. >> So this instantly set off like red flags for me because so if you know anything about Google, right? So stubby is their internal RPC format. So okay, just just a like a refresher or whatever. If you if you send any request to a Google API, right?
It's it's actually just sending it to some sort of RPC. So some of these RPCs are like exposed or some of them are internal, right? So this So let's say let's say I send a request to like compute.google.apis.com or whatever. So that server that's handling that that borg that borg task or whatever, it can also fetch like other RPCs to fetch whatever it needs and then it returns it back to you, right? So it does this through stubby using a production account.
So something like whatever.atprod.google.com, right? So if you can somehow like execute arbitrary stubby queries, you can reach all these like internal RPCs that that would otherwise not be exposed publicly, right? So it's a massive risk breach. So it's it's kind [clears throat] of >> like an SSRF at Google cuz I know they've they've famously told me like oh we don't really have SSRF but being able to make arbitrary stubby RPC calls is basically the equivalent of an SSRF at Google, right? >> Yeah, exactly.
And in fact I would say like an RCE in Google most people like think of RCE as like oh I have I have shell access to the server, right? But in Google it doesn't really work that way. Like even if you have remote code execution on a borg task, which is like if you if you manage to like any sort of Google application if you get code execution, it's on a borg task. But what is the real impact there? Sure, you can see what's being processed locally but that's still like a sandbox environment.
The the real impact here is the stubby access, which is why they pay so much for for stubby, right? >> Mhm. Okay, guys. So we really need to take away from this here that if anytime you see stubby, you need to be very interested, which is very interesting because I actually um one of my bugs that I've had I submitted recently to Google. It It utilized a stubby endpoint and I was like, I don't like I don't know why this works, but it works.
And uh so anyway, we'll have to compare notes on that afterwards cuz I haven't gotten any uh disclosure permission on that. Maybe you can do something with that that I couldn't. Um but that that is really interesting, man. So, just to clarify, you know, traditional architecture for RCE is, you know, you get a shell, you take over the server, whatever. Google uh you know, infrastructure architecture is a little different.
All of these APIs are being mapped back to a central RPC sort of environment. And uh you know, typically it's taking an API endpoint and mapping that to an RPC call. But there might be some scenarios where you can take a API call and map it to an arbitrary RPC call, right? and that is where you get RCE really impactful RCE on Google. Is that Is my understanding that correctly? >> Yeah, if they have some weird proxy thing which just like proxy stubby queries exactly like like this kind of sounds like it would do. >> Wow.
Generic stubby type task. >> Sounds like you I can just send anything I want, right? So, it it was pretty interesting. Yeah, so I I was looking forward to this and I was trying to see, okay, is there a way I can like configure this task or whatever, right? So, I tried I tried like creating a task and at first I wasn't able to. It's like I had to fill in like this whole like payload or whatever. I had the discovery document, but you see like you still don't know what to like put in there, right?
So, you can have the comments can kind of hint you hint at you of what to put in there, but but still you still have to guess the parameter just half the time. So, I was trying a bunch, but I wasn't able to do it, but I noticed like I was I was constantly getting invalid argument, which is a generic error. >> Word. >> I looked at the workflow execution log that I leaked earlier and I saw like there was like some client ID default there.
Like I'm not sure what that means. So, I just copied that and pasted it and it just worked. So, I was able to create this this workflow. >> Wow. Nice. >> so once I had the workflow, I mean, I was I was trying to okay, can I just run this workflow now? But it wasn't all that easy. When I tried to run it, it tells me, "Oh, no, you have to publish it first." Right? And when I try to publish it, it tells me, "Oh, sorry, you you the pu- the publisher can't be the same as the last editor." So, this kind of stopped me cuz I thought that Oh, it it was even saying something like, "Oh, you have to raise a request for approval." Like, what does that mean?
Do I have to like send it to some Googler and have them approve it? They're not going to approve it for me. So, yeah, I I I kind of hit a roadblock there. I was trying a bunch of different stuff to kind of bypass that, but I I was I was pretty stuck here. So, I was stuck here for maybe like a month, right? Literally like a month. And and because of that original report that I did, right? When I initially just leaked the workflow workflow's execution logs, so they're already like starting to patch out all these endpoints.
So, that that was like a big problem for me. But, any- anyways, like I was in some random like Discord chat, like just out of nowhere, right? I just happened to ask like another like researcher in the same Discord group that like, "Hey, do you need do you need any protobufs or anything?" Cuz I have like an endpoint I can just get any protobuf for you cuz they didn't like fully patch it yet. Right. And then it turns out this guy had the exact same thing.
Like, I was like, "What?" And then what are the what are the odds of that? Like, some random guy in a chat has the exact same endpoint. And then we start DMing. I was like, "Is it is it the Cloud CRM API?" "Yeah, yeah, it's the it's the same API." And then and and we realized we were stuck at like two different points. Okay, so he was kind of looking at it a whole different aspect. I didn't even like think of this. So, he realized that this API, right, is very similar to this product called application integration, which is like the public GCP product, right?
It's like the internal version of it. And he was looking into this application integration a lot. So, he found these same endpoints from the JS files of that product. Does that make sense? >> Yeah. Yeah, where where did you find this guy, dude? >> Like Bro, I I I just introduced him like not that long ago in some by some friends. >> Nice, dude. That's crazy. >> happens to be >> Not even like in my There's There's a lot There's a lot of subcommunities, Justin.
A lot of little sub hacker groups, you know? >> Yeah. >> And I And Burp Cat, you acted like that was kind of an anomalous like thing that you all had found the same thing, but literally every time I mess you with something you're like, oh yeah, I already know that. I've already seen that. >> [laughter] >> Yeah, same. Same. So, it's like yeah. >> I'm I'm I'm pretty sure that's not that uncommon that there's an intersection there finding the same thing. >> Yeah, but you know, but it's different if it when it's us to Brute Cat versus Brute Cat to other people.
You know what I'm saying? Like you got to got to got to give give credit where credit's due here. Um okay, so this is the internal version of the public um service for running these uh you know, application integration tasks. >> Yeah, exactly. So, I was looking I was looking more into it. So, he was able to but he couldn't figure out how to create the workflow because he didn't know that client ID default thing, right?
Cuz he wasn't able to leak the whole workflow execution log or whatever that I was able to do. He was he was trying to like different parameters. He he he he he just never created the workflow. It kept saying invalid argument. But I knew how to create the workflow. But he knew how to kind of get past that [clears throat] because he was super like he knew this whole product like in the back of his hand. Like he like he completely knew application integration.
But I didn't know anything about it. So, he I sent him like we compared notes. I sent him exactly how to create the task, right? And then we worked together. So, okay, so at this point we had a we had a bit of a problem. So, while I could create the task before, but I can't actually do that anymore cuz they they patched the endpoint, right? It just it just returned permission denied cuz for cuz of the patches of the initial bug that I reported.
So, we were trying to see like what ways we can do around it. So, for some weird reason this this API is is kind of weird. I've never seen this before, but they have like duplicate endpoints. So, they have like the they have like let's say get workflow definition. And then they that one's blocked, but workflow support get workflow definition that that one it works. >> What? What? >> [laughter] >> And all these were in the discovery doc? >> Yeah, all of them.
They're all they're all in the discovery doc. >> Wow. >> So, yeah, so I I found that, but the problem was the only endpoint that didn't have a counterpart was the the create workflow one. So, we were screwed. Yeah, so we were we were literally stuck here. But then I then I sent the thing to like Shrock cuz he was like messing around with it. And somehow he created the workflow. I was like, "What? Like it doesn't work for me.
How does it work for you?" So, then we realized that like the the fix wasn't like rolled out to all the Google servers. So, like he was from Canada, right? So, it worked for him, but not for me, cuz I'm from Singapore, right? So, that that was super interesting. So, he was able like like reproduce it super easily. He's able to create the the task. Then then we realized that okay, he sent me like So, Google has like this this their DNS system is kind of interesting.
So, depending on like which IP address you resolve www.googleapapis.com, it like returns like so like a different IP address, right? And this IP address is linked to like a they call it like a 1e100.net domain. So, it's like something.1e.100.net. So, basically he sent me his 1e100.net domain and I I put it into my like Burp or whatever in the target. And I was able to to do it easily. So, then we were like figuring out like this whole this whole like thing to create this this task. >> way you can sort of pin what what host is dealing with your request.
So, you >> Okay, it's not as direct as that. It's it's kind of like you can pin it to a specific country, I would say. It's not like a specific server. >> Right. >> Yeah. Okay. >> So, yeah, anyways, we we were trying to figure out like like how can we like publish this now? So, he realized that we could like add like a different Gaia >> Mhm. >> to to some add ACL endpoint. I got I didn't even notice this. I don't know I don't know why, but he he could like add a different Gaia there.
Then you could use that Gaia to approve your own integration or your own like workflow whatever. And then you could like publish it. And then we ran the workflow and it actually executed. >> gosh, dude. That's that You must have been so like hyped when that happened. >> rush was crazy. >> I I'm sure. You just at that point you just like flip your desk and you're like, "Oh my gosh." So, what's crazy to me though is that he knew you know, how how to change that um access control or that ACL.
Um and I'm trying to find it. I've got this, you know, the write-up open here, Uh but it it was like a pretty obscure key that he needed for that. So, I'm I'm very curious how he came up with that key. Um but I guess that's a little part of the >> he's he's just guessing. >> Yeah. Wow. >> Yeah, we're just we're just playing around, right? Trying to see what works. >> Wow. Yeah, and and I guess there's probably maybe these set of strings as well in the um in the application integration app in Google Cloud.
So, maybe he's kind of taking some of the the stuff from there and then trying it on this you know, internal version. >> Exactly, right? And And actually another thing is the for this stubby task, right? We had we had to fill up the parameters for it. So, it wasn't as easy as just like executing the task. Like, what do I put inside this task? It doesn't There's no documentation I can refer to for the parameters. So, the we actually figured out that the application the public application integration, if you tried to configure a task there, it wouldn't work, but it would like leak this like the parameters.
It would tell you, "Oh, you need this this like uh server spec or you need this method parameter." >> Mhm. >> So, using using that, we were able to slowly piece out exactly what we needed for the request. Then then we also figured out like we looked through like random discovery documents and we were able to find like some random GSLB address like GSLB alkaline base. That's the one we used. Then and like so is equal Pereira, remember I I mentioned him.
He had this like RC from Super Longo. So, we we looked at the write-up for that and we just like took some random like stubby method. I think I think we used like a server status on get services, right? So, we took that and we tried it. And that's how we managed to get the whole thing working. >> Dude. Wow. >> Yeah. Wasn't there some other bug or something, Justin, at one of the live hacking events we were at or someone used a GSLB address and they had to like also find it or >> Dude, I don't know.
To be honest, that that is so far over my head with some of this stuff. I I don't think I even remember it. So, uh that is really impressive that you guys were able to piece that together. I guess I need to go back and review some of this guy's uh you know YouTube videos or talks and stuff like that because there's gold there if you if you know where to look apparently. So. >> For the For those of you that don't understand, like GSLB is Google service load balancer.
It's like their internal like DNS sort of thing where you can sort of reach to a specific host. So, Alkali base is is like this Okay, so Alkali is Google's internal framework for like creating APIs. So, these APIs tend to be super insecure. It's like this It's like a easy way for a Googler to spin up an API. >> a dev thing. >> So, historically they've had like so many bugs. But yeah, we just happened to find this this one address.
I mean, you could have worked with different ones. But But yeah, so we we had this working, but like and we we sent in the report to to like Google, but they they like told it like just 1 hour after we sent the report. So, we realized that like everything stopped working cuz the the fix is fully rolled out. So, if we had done this like 1 hour later, we wouldn't have been able to prove anything. >> No way, dude. >> super clutch. >> That is >> Yeah, first off, like this, I can't help but think in some in some of the stuff we're going to talk about later today with like the reports you put in.
Like some some of the write-ups you have are like, you know, three reports covered this and paid out a total of, you know, $30,000 or whatever. How How do you decide kind of where I like on Google specifically where to draw the line with like why like why would you throw it all in one report versus why would you kind of break it up? Cuz like this one like I'm curious like once you all got that stubby that stubby RPC call working, did you just throw it on the report you already had or did you all submit another report?
You know, I'm just really curious how your mind thinks about like when to combine them versus when to report them separately for Google's program specifically. >> So, that's actually a really good question. So, you have to be kind of careful here. So, generally Okay, I would say in this specific case, if I tried making a different report, they would kind of like lump it all together because it's the same API, right? So, there's no there's no point of making a different report so they can do like the previous report so they can do for something or the new one might get duped.
So, the if it's the same API and if the API is pretty small, like it's just a couple of methods here, like I would like I would like to think that you should probably just do it in the same report, but if it's a pretty big API, like maybe like 100 plus methods, I would split it up into different reports. And everything it it really it's really nuanced. It's hard to like tell straight away. You could You could be losing out on bounties.
Like in this case, like that initial bug I reported, I don't think they paid for that. They just like the RCE like overrode it and everything. >> Mhm. >> So, you have to be a bit careful there. >> Wow. >> [snorts] >> Yeah, dude. It It's a little tricky, man. I'm running into this a little bit with Google, too, is like they they actually do pretty decent due due diligence when you submit your report sometimes, you know, and they'll fix stuff that's adjacent and and you know, same similar root cause stuff.
Um so, a lot of that stuff will end up getting duped back. But, I I but I also feel like just as a critique of the Google program, I feel like that is not incentivized as well for you to like prove full impact across multiple different environments, right? So, if you've got, you know, eight different things that are vulnerable here, you're not really they don't incentivize you outlining that in your report very well, you know? >> Exactly.
That That's super well said. Yeah. >> Yeah, so so I would like to for them to I would like to see either a multiplier, you know, they they do multipliers for their report quality, which I think is a super important thing to to to do. Um and they do multipliers for other stuff, but then I think they're sort of um on the fly uh you know, at will uh extra bonus they they can add for things like, you know, having multiple instances that are vulnerable uh is very limited, uh you know, a grand or two.
So, I I definitely think a multiplier would be there so it would be better there so that it it kind of encompasses the impact that you can have if you've got a massively, you know, critical vulnerability that spans multiple different, you know, API endpoints or services. >> So, generally in such cases, right, what I actually do if if I find like two different bugs and like let's say I find the first one I reported, but the second one doesn't help me get any additional impact.
Like it's just another different issue. So I'll actually just not report the second one. I'll wait till they fix the first one. Then I'll report the second one. And and that always works out. >> Yeah. Yeah. And and I think if anybody's listening and thinks that that's like weird or offensive, this is like exactly like you want to create a system, like we should all work towards creating systems that like encourage the most ethical behavior, you know?
And so like, you know, I would tell Google or or and I know people that do this same exact thing on HackerOne programs and bug crowd programs. This isn't exclusive to Google. Like hackers are obviously going to try to provide the most for their family that they can, you know? And so that's the way the system should be set up. And so, you know, what should actually happen there is you should be able to report both of those and they treat them independently or whatever, you know?
Especially if they're separate fixes, which they obviously were because you just proved that by waiting, right? So >> Yeah. And and you give them the opportunity to realize that hey, maybe the due diligence isn't always done as well as it should be, right? So so you know, you shouldn't always scoop these back, right? >> [laughter] >> Uh because look, now I've just reported another adjacent service and that that is, you know, not fixed, right?
And and so um yeah, I think that that pokes holes a little bit in the like we're going to do our root cause analysis uh sort of situation. And and you know, in my in my experience, I've done that and I've been you know, I've gotten another bounty for it and I've also gotten burned by it, you know? Like I've I've submitted a bug and they fixed all of the adjacent ones as well, you know? And and I was like, okay, well, they did do their due diligence this time.
Uh but then I've also, you know, reported it another one later and then they haven't fixed it. So it is a little bit of a roll of the dice, but I think it's the best way to show exactly whether the root cause analysis that they're doing is is um producing the results that it should, right? >> I know this this doesn't always work, but for the most part what you should try to do, at least for Google, is I mean at least for now until they change this, but you should try to find as much impact as possible, right?
So like even that means like sitting on it for like a day or two. Yeah. Just try to find as much impact as possible. Report the most impactful thing and that's it, right? So, then then you can like wait and report those like like less impactful stuff if they don't patch it. So, that way you kind of like save yourself. >> Yeah, I I totally agree. So, that is So, you know, calling that service list uh on on the prod probably got to be such a crazy moment.
You must have been so hyped. Um but that's not the end of the story here. So, tell me how this continues to get another crazy bug out of Google. >> Okay, so when we when we first tried When I first saw this RCE, I was super tempted to like play around with it and stuff like, "Oh, can I can I like do stuff?" But yeah, I was quickly told that no, I should just like stop touching this. But yeah, so I had to leave it there.
So, I was kind of sad cuz I I really wanted to try all these like internal like RPCs or whatever. I've I've collected them over like like I guess like the year or whatever that I've been hunting Google. So, I wanted to play around with them, but no, I couldn't. But anyways, it's fine. I I was like working on a bunch of other stuff, right? And like maybe like 3 months later, I was like improving my scanner and I was targeting Google Cloud at this point.
So, I was on Google Cloud APIs. And for some reason, this integrations application integration like popped up again. So, my scanner figured out like there was this problem across the whole application integration API. So, you could like sell you could like put {slash} project {slash} like your project number, but reference someone else's UUID and it just works. It's like some super dumb ID. And this works like for all the APIs in this whole like all the points in this whole integrations API, right?
But the problem is how do you get this ID? Because this ID is like a UUID, right? So, I was going to screw you. So, I tried because if you just report this by itself, it's not going to be too impactful, I'll say, cuz there's no way to prove to Google that UUID. So, they're going to downgrade it a lot. So, I was saying, "Okay, is there any way I can sort of leak this UUID?" Right? So, I was looking through like the whole application integration and this is where I was like really playing around with it.
So, I saw there's like this this feature called like test cases. So, you can create a test case for your integration. So, like just for anyone doesn't understand, uh application integration is kind of like like no code like automation workflow. So, you can like drag and drop stuff and like connect it together. So, let's say I take something from like one place and and send it to another place. So, that's kind of how this application integration works.
So, they have a test case feature where you can create a test case for a specific integration. So, I can test just this one part of this integration like this this is like a send email task board. So, I create a test for that and and like test that. But, this test case thing was super weird. So, when I created my test case, I looked at like how it was listing the test cases. So, it was like some RPC list test cases. But, but I decoded like the protobuf cuz it was sending in protobuf.
And I saw it was sending like workflow ID equals to and then my workflow ID like as like some filter. But, why is that client-side? That should be like server-side, right? So, that was super weird. Then I was like, "Okay, so surely if I like remove this filter, it's not going to dump everybody's things, right?" So, I just removed the whole filter and it just dumped like the test cases for everybody in the whole GC. Who is this product? >> dude.
That response size on that must have been massive. >> Okay, so yeah, it was it was pretty massive. Like but I it was like some I think there was like a page size or something. So, I had it set as like 1,000. But, yeah, I got a super big response and I I instantly know like something is wrong. And I could see all these like I googled like google.com cuz it's like all these Googlers that make like their own integrations. >> Oh, no.
That's crazy, dude. Oh my gosh. I I I would definitely have just submitted it there. It's really It's really funny to me that you're like, "No, I need to get this UUID out." >> [laughter] >> Oh, yeah. I'm not going to like I I don't want to stop there cuz it's not going to be a a good bounty, right? I want to escalate the impact as much as possible, right? Until it before I report. So, I was trying to see, "Okay, can I get the UUID from this?" Cuz now I deleted all the test cases, right?
It should be in the path, but for some reason there's like a dash there like where my like UUID the UUID is supposed to be. It wasn't showing it. So, I was I was kind of stumped here. Like cuz I I thought I could stop it and and get it working, but no. So, I was trying to see, okay, what what way can I have around this? All right. So, right now, what I can do is I can list all the test cases. I can execute the test cases using the test case ID with the same dash as the integration UUID.
But, I can't actually like I can't actually get the whole integration cuz I can't get the integration UUID, if that makes sense. So, I was trying to see how I can leak that. Cuz But, then I realized, wait, can't I just use the same filter parameter as earlier and then just do like a binary search on that? So, I can fix it to a known test case. Then, I can just use binary search and like keep trying all the different stuff until I can leak out the whole UUID of that like of the guy who owns the test case.
Does that make sense? >> Yeah, that makes sense. Freak, I love that, man. I love those filter injection, you know, filter-based binary search things. Those are amazing. It feels so good when you pull that off, man. Oh my gosh. I love it. >> No, literally. So, I had like I had the claw like write up the the whole script. And it just did like first try. I could see like the little animation of it like slowly brute it. It was it was awesome. >> Yeah, like Oh my gosh.
Dude, I haven't had one of those since Cloud has been around. But, I I do remember the last time I coded one up manually. And I finally The last time I did it, you know, it required a bunch of weird, you know, statements in there with like different parentheses to get the order of operations correct. And it was like when it finally, you know, you could tweak one variable and it would, you know, show yes or no. I was like, "Oh my gosh, yes." So, it's amazing. >> I would have I would have never thought to use this on a UUID for some reason.
Like, I just wouldn't think of it as being something that could be binary searched with like greater than less than, but clearly it can. >> No, cuz it's the same it's the same filter AIP thing, right? It's It's all the same thing. >> Yeah. >> So, you can use the same logic there and and do the binary search. I mean, I was stuck here for a bit. I It took me like maybe like a day to figure out this this whole binary search thing.
I don't think even Cloud figured it out. Like, I I Cloud like working on this like, can you can you try to escalate this impact? Can you try to like see if there's any way we can leak it? But but no. But but I had to manually figure this out. But yeah, so once I once I had this working, I got the UID. I was able to then do IDORs across this whole thing. So I could I could just take over some guy's integration. I could like view all their integrations.
I can I can do all this kind of stuff. But see, remember earlier like those test cases had like at google.com or something. So I was thinking what if what if like those like these internal integrations or whatever, but they're not they're using this application integration. But they're using some sort of internal task time, right? Can I like somehow like use that and like steal their integration and execute that task time?
So I was trying to see open that angle, right? But I have to be a bit careful as well cuz I you you have to draw a line, right? I can't I can't like I can't like get to read your customer data cuz they're going to like they're not going to accept the report. So I had to send everything I had so far and just and like and just tell them to look for it. But like I wasn't satisfied in that. Like I don't I don't want to them to look for it.
I wanted to find it myself. So I was looking deeper. So what is exactly be stopping me from creating my own integration? If I try to create an integration with like the same stubby type task, is it what is stopping me from from doing that? So I tried it out and I was actually able to create the integration. But when I tried to execute this this integration, it would just like time out. Like it would just say oh like this this thing has timed out after like 120 seconds and it doesn't say anything else.
So it's kind of vague. But I looked at the same test case feature. What if I create a test case for my stubby integration and then execute that test case? So okay, at first I was playing around with all the different internal test sets. I wasn't even playing around with stubby. I was I was doing some weird Python task or something. So I was I was trying the Python task. Then I got some like super like So when I when I when I when I pressed play button for the thing the test test case I just made, I got some super suspicious like error like like insufficient like disk space or something.
Like it's it looked like some like Linux error like a standard Linux error when you ran out of like space in your your box. So I was like what is going on here? There was something weird here. So yeah, I was then I was looking at like Okay, so this probably reaching some sort of like execution back end, right? Yeah, I think that's the error here. No no space left on the device. >> Gosh, dude. What? No space left We had Java IO exception, no space left on the This is the sketchiest thing ever.
Wow. >> And it was showing the UI as well, like a big big red like notice Oh, like no space left on the device. So So yeah, then I was like, okay, can I can I try to stubby one? But the stubby one would just give me some like super generic error like an unknown error. And that that's it. Like doesn't tell tell me anything else. But I figured out right I could look at the workflow execution logs and that had like a stack trace.
So I fetched I fetched the whole stack trace and I got some some super suspicious error like it was like Uber mint verification failed. So like it would it would have an RPC security policy error and it had a bunch of stuff like that. So this error in Google usually means that like the product owner you're trying to reach doesn't have like a RPC security policy defined for the RPC you're trying to hit. So like it's not whitelisted for the RPC or something.
So because I was I was it's a different product account than the other one, right? This is like a completely different product account. So I'm guessing this one didn't have access to Alkali base or whatever I was trying to hit. So this was this already told me that it's definitely hitting like stubby. So I checked with like Sam if I could like escalate this any more, like if I could try to keep testing this, right? And they they like they checked it and apparently it was fully exploitable.
So I I had to stop everything here. >> Wow, dude. Look at that. Execute stubby call. Oh my gosh. That is beautiful. And and they they said, all right, back off. We'll We'll take it from here. Dude. Wow. >> You have to be super careful. Like if you I've heard of this like this is a rumor going on around like whatever whatever. Some guy like took his RC too far and then they they like they voided the whole thing. So I I don't want to I don't play too much.
I better just report this and and let them deal with it. So but I was also looking at like the stack trace. You could kind of see like how the source code looks cuz like it leaks out everything in the stack trace. So, I kind of like figured out like how it's like setting these different parameters and stuff. So, yeah. I I reported this. I didn't hear back for like almost a month. So, I was at this point I was like wondering like did they like why is it taking so long?
Cuz the other one like was rewarded in just a few days. But, it turns out, right? This this one got 75,000. So, there's like the three different tiers in in Google's like VRP rewards. So, 50,000 is for like an sort of unprivileged production user, right? But, but if you get 75,000, that means it's a highly privileged like production user. And 100K would be like complete like admin in in Google's app, right? And see, in many cases, in my opinion, right?
Even if you have a unprivileged user or whatever, you can you can usually like privilege escalate to like different like RPCs and stuff, but they won't let you test that, obviously, but it's it's definitely probably possible. So, they just look at like I guess the permissions of the product account. But, in this case, like I was speaking to Cote right, like they would be they're super big about this. They they won't tell me more about this even though I keep like pressing them on this.
But, apparently, there's some sort of like escalation that even I didn't show here that you could do and and you can get even more impact. So, that that's why they they rewarded the 75K tier. >> Mhm. Wow, dude. Very very cool. That is uh quite a story and I think probably this is the longest intro bug that we've ever had [laughter] in the history of Critical Thinking. >> But, totally worth it. But, completely totally worth it. >> Totally worth it, man.
Um absolutely inspiring. Um >> A double RC on Google. >> Yeah. Dang. That's insane. So, I did take some notes and I do have some some questions to go back to on this. Um but, before we do that, I do want to give you the proper introduction. Um as we mentioned, guys, this is Brute Cat. You can get his uh his on his blog at brutecat.com. Um it's on on Twitter, it's just @BruteCat, right? >> Yeah. >> Yeah. Um and you're also doing some consulting now, right?
Tell us a little bit about that. >> Yeah. I mean, I've just recently started like doing a bunch of Yes, I set up my own company, Brute Cat Security. So, you can you can just go to brutecat.com/hunt if you want me to pentest your stuff. I have a whole like AI thing, the same AI that I used for pentesting Google, right? I've I've kind of like worked that out for pentesting other companies as well. And I've had I've had tons of success with that.
So, if you want me to run it on your your company, just feel free to reach out. >> Nice, dude. That's awesome. Um And yeah, I mean this guy is the pinnacle of Google hacker. Like like just I've read all of his blogs multiple times. Um, so dude, really excited to have you on the pod. Um >> Let me let me blow everybody's mind real quick. Literally out here, I was telling my wife that we were coming to interview you, and I was like, yeah, this guy's amazing.
He's been hacking Google for forever. He's like one of the goats. And then I see it that in our in our doc, how I got into Google mid 2014 and 2024. >> heck? >> Mid to late 2024. No, in my head, for some reason, you're like this like always epic Google hacker that's been around for 10 years. And I'm like, wait a second, he started hacking Google 2 years ago. What am I doing with my life? >> Exactly, dude. Exactly. That's how I feel, too.
And and yeah, well, it's funny you mentioned your wife cuz I said it I said the same thing to my wife, and she knew who he was cuz I talked about his research before >> [laughter] >> to her. I was like, yeah, man, this guy, Brute Cat, he came up with this crazy way to like let me access Google APIs a little bit better. Um so, that's pretty funny, man. Um, go going back to the write-up. Um so, I wanted to ask you a couple things.
One, um you mentioned that you were using your AI to guess the the parameters for these requests, right? So, what sort of additional information have you given Claude to enable it to um, you know, do these guesses correctly? And how do you get it normalized to your account? Like where you have different objects created and that sort of thing. >> Okay, I can touch on this now, but probably probably be better if I talk on this later because I have a whole >> You want to talk about the whole thing in that section? >> Yeah, yeah, we should probably cover it then. >> Okay, let let's do that then.
And then, um, the other thing that I had here, we already covered GSLB, um, but the Google SRE handbook is quoted multiple times in this, uh, you know, in this write-up. I mean, have you just read this whole thing cover to cover? Uh, like >> Yeah, I've read it like five times. I mean, [laughter] the first time I read it, I didn't know anything. Like, but I kept reading it again and again. And not just this. So, I read a bunch of stuff.
Like, I would read like Beyond Prod and their whole documentation there. Like, there's a they document so much stuff. I've even read about like as much stuff as I can, all different papers about like cuz Google releases a lot of these papers, and it's it's about their whole internal infrastructure. If you can like read that and learn it and bring those tips into the hunting, it's actually super beneficial. >> Mm. Mm.
Yeah, if there's just so much to figure out with Google cuz it is architected very much, you know, different from any other company that I've seen. Um, okay. So, the Google SRE handbook, you mentioned something called Beyond Prod, and then do you have any other resources that you really gained, you know, got a lot out of, uh, when prepping for, I guess, hacking Google, uh, infrastructure? >> I would say that Okay, they they do have like some papers on like Chubby or these kind of like internal stuff, but mostly just these two resources that you mentioned.
Those are the If you if you just want to get started, you should be reading this. This is like the minimum requirement. >> Okay. Nice. Well, I'm going to go get those. Go go read through those cuz I have referenced the Google SRE handbook a couple times, but I haven't actually like read it cover to cover. So, I think I'll have to go back and and do that. Um, sweet, man. Uh, well, that was a whirlwind. So, just a couple of takeaways from that write-up.
Uh if you're using client six and first-party off and you're getting a protobuf response, you know, or you're not getting a protobuf response out and you think you should be, then you can use the uh Google encoded response if executable header to get it out as base 64. Um you've got the whole request proto. Um we we did sort of a uh head nod to that, you know, cuz you found request proto as a service there. But, um there's this whole primitive, essentially, uh gadget that you've outlined on your blog about how to do an error-based oracle to leak the the JSON um uh the proto JSON request uh structure.
Um uh for these a Google APIs uh requests. Um and we should be on the lookout for anything related to stubby. No matter if you see stubby, you need to like lock in uh because there could be some really impactful stuff there. >> Um and it should be said it should be said that we're at request a proto is also uh a project on his GitHub. >> Yeah. Oh, for sure. Yeah. Beautiful beautiful project. Um anything else that you think we should have as takeaway from from that that write-up? >> I think it's pretty well said.
And like you mentioned, if you see any sort of stubby, right? You should try to find a way to reach that. Like there's so there's so many like potential RCs. In fact, right? If you look at all the discovery documents, if you try to grep for stubby, you'll you'll find a bunch of like stuff like that. And you can look at you can grep for like GSLB, grep for these kind of keywords and see if there's anything referencing that cuz that could potentially be a way you can you can get access to this, right?
And they have so many like webhooks, like random stubby webhooks, I'm guessing the Google has made it to make their life easier, but the same thing can be used for for us hackers, right? So, you want to try to find as many as those as possible. And in fact, it may not even be in the discovery document directly. It could be like embedded in some some inside some service. Let's say you like let's say you're hacking on some GCP product, right?
And maybe you've got access to like the tenant project or something and you have a shell or something. If you If you see anything inside there that's referencing something, that could be another thing, right? It doesn't have to be in the discovery doc. >> Cuz they've got to tape this They've got to tape everything back together with these RPC calls, right? So, if you've got any sort of primitive, you know, inside of, you know, the the shell in your own org in that product and that and that thing can do anything, right?
You know, then it needs to tie back out to RPC calls at the end of the day. And if they don't do that in a secure way, then you could get arbitrary RPC call execution. Very interesting. Um and then the last the last call out that I had here that I did forget in my notes was take a look at the AIP-160 filtering um spec and just realize that that is something that is used pretty widely across Google because you can run into these bugs where you can create these, you know, filter binary searches or at least, you know, be able to notice when there is a filter being used and you might be able to use that to access other people's information.
Um >> What One thing One takeaway I had which I um always associated with like old Yahoo stuff is just the is is the whole load balancer thing. Like uh you know, I don't think that people should intentionally try everything like from different regions or 100 times or whatever, but I do think if you ever try something and it works and then you're you know, later on you're trying to reproduce it and it doesn't work, you can think about the fact that oh, maybe it's cuz I was connected to a VPN or maybe, you know, Well, if it's if it's working for a buddy and not for you, you know, it may be due to the fact that it's going through like a different load balancer. >> Yeah, I need to send this request like >> Yes, the way the way >> [laughter] >> The way Yeah, no, exactly.
See, the the way Google does their request, right? It's like the minute they do a fix, let's say you report a bug and they fix it. Like their fixes roll out gradually. It's not like an instant roll out for many cases, right? So, if you can you can use this trick usually and find like some hosts or something that you can use to route the request through and and reach a server that hasn't had that fixed rolled out yet.
So, this is like a way to kind of bypass it temporarily. >> Very nice, man. Very nice. >> Cool. >> All right. So, let's jump into how you got into Google VRP and it starts with a obsession with YouTube, it looks like, which I think many people can relate to. So, give us give us that story. >> Okay, so it wasn't necessarily obsession with YouTube, but that was pretty related. But, it was mostly obsession with like OSINT stuff.
So, I was Okay, I was a complete noob, by the way. Like I I didn't know like anything was going on. Like I just wanted to I thought it was super interesting that these like OSINT tools existed where you can sort of like find out information of any guy you wanted, right? So, I wanted to see like Google was pretty interesting because if you can everyone has a Google account pretty much, right? Like I don't think there's a single person that doesn't have a Gmail, right?
So, if you can somehow like leak information off the Gmail, like maybe they have a Maps review or like a Play review or something, that'll be pretty It's pretty fun, right? So, I was I was looking into this, right? And I saw this like this random website, like Okay, I think it was called like OSINT Industries or something, but this website was pretty funny because you could input an email and it would find the YouTube channel tied to the email.
So, I was like, "How does that that work?" because I'm I'm like I could you dox me from that. I have >> You're like, "That's a bug." You're like, "I know, that's a bug, right?" >> [laughter] >> Yeah. Yeah. So, so yeah, like a lot of these OSINT stuff like relates to actual bugs, but but yeah, I I was like kind of I was super interested in this. I was like super obsessed with it. I was trying to figure it out. Then eventually I I think I went to some like super ancient like Discord server for for this guy and I saw some screenshot that he he like sent and it said there there's like a path of his like his like home directory or something.
He had some terminal open and you could see the path there. And it said something about profile card. So, I was like, "Okay, this has to be related to this." cuz he was talking about that that whole YouTube thing like right before this. So, then I was like, "Okay, what is a profile card?" I I looked through everything to try to find a profile card references. And turns out profile card is like some super weird like YouTube feature.
So, if you have like a Okay, this person is only for mobile. If you went to like like YouTube any sort of YouTube video in the comment section, and you tap on the profile there, it would like load this kind of like mini card, and you could like see subscribe or whatever, right? So, this is called a profile card. So, it didn't exist in the web yet, but I was curious how it worked. So, I set up like a whole like I read some like tutorials or something, and I set up a whole like on my iOS phone, I could like sniff the traffic, right?
Through like Burp. And then I was like looking through all the different requests, and it was in protobuf, so I I couldn't read it, but I noticed the ID there looked a lot like a Gaia ID, which is like a Google account identifier. So, I was like, "So, I can just pass in any Gaia ID here, and it's just going to return the YouTube channel." And then And then it worked. But, I was also thinking, "If it's able to do that, how is it getting the Gaia ID, right?" Cuz surely it's getting it from somewhere.
And then I looked more into it, and it turns out whenever you load the comments of any like channel page or whatever, it had the Gaia ID of every single user like tied to that. >> Oh my god. >> See, the thing is, Google, they have two different types of Gaia IDs. They have an obfuscated focus Gaia ID, right? So, it's called focus obfuscated ID, foggy, that's what they call it. But, they also have an unobfuscated Gaia ID, right?
So, like the raw Gaia ID. But, the thing is, you see, the many teams The teams across Google, they think that they can just safely release this obfuscated one, but the truth is that you can many times convert this obfuscated one to an email, or like convert this obfuscated one to to fetch like some other information. So, it's it's like a It's an issue with across the teams at Google, cuz Google's so big, right? They they don't realize that one team thinks it's it's like it's not safe, the other team thinks it's perfectly fine.
So, they they did a massive screw up here. Like, if I could probably go to Wayback Machine and look through that, I bet you would find a Gaia ID stuff like so many channels there. So, so yeah, this this was interesting. But, so I had I had this for a while, I built it to my little little little tool or whatever, I could like sort of do that. But, I didn't even think of it as a bug. Like, I wasn't I wasn't even trying to find bugs, to be honest.
Like, like hacking Google in particular. But, I was just trying to find these little simple stuff. But, then I noticed they they rolled out this fix to like they like they Okay, so they First of all, they rolled out like this feature to the web. So, it's in the web you can tap on it. And a ton of people found the same thing cuz it's super easy to like see the request of web as compared to iOS, right? So, then they I saw they started rolling out the patches for this.
Like, instead of they stopped they stopped like supplying the guy ID. They started like doing some like channel ID or something instead. Like, the reason why it was a guy ID to begin with is because this comments back end in YouTube is is like from G+ days. So, back in the day like they didn't they didn't want to lose those comments that were made in G+ days. So, they it's like it's still a guy ID back in. Like, your comments are tied to your Google account.
It's also tied to your YouTube channel. So, if you move your YouTube channel to a different guy account, it's going to lose all the comments cuz it's all tied to this. >> Interesting. >> So, yeah, I was I was looking at that and then I was able to Yeah, so, but they they stopped they stopped patching the whole thing. And then I was like kind of stuck. Like, I wanted to find like another way to do it. So, I was looking through like every all the APIs like with a friend and we're trying to see like is there any other way we can like leak these guy IDs?
And we we figured out like there was this one this one like endpoint if you had a live chat and you like tap the three dots on like a side of like a live chat and on a live chat viewer, let's say they write a message, you tap the three dots there. It like opens this context menu like you can block the guy or report the guy or something. And this block functionality, like how does the block work there? Cuz like how does it What does a block mean?
If I block a guy here, is it blocked across all of Google? Because then it's tied to the guy ID. So, cuz if you like if you block the guy and then you look at your list of blocked people through the people API, it just lists lists the guy ID there. So, you just have another way to do it. >> Dude, that is such a good trick and I've used that multiple times. I I think I actually shouted it out on the pod a couple couple weeks ago.
But like going through that like abuse uh report functionality to deanonymize people is super clean and it works almost every time I've ever tried it. Um that's a that's a big, you know, sort of conceptual takeaway that spans multiple targets, I think. >> So, I was I was I was looking at like how this thing worked in the request wise, right? And turns out you don't even need to block the guy. Like if you just open the three dots, it's like it preloads the guy ID of the of the guy.
And it was even worse cuz you don't even need a live chat message. You can just change the channel ID to whatever channel ID and it just returns the guy ID, right? So, >> Oh, wow. >> Yeah, at this point I had the guy ID, but like how could I get more in fact? Like sure, you can you can list like the maps reviews or like the play reviews or whatever, but I want to get the email of this guy. >> a second. Wait a second.
Just clarifying. You said you he doesn't even need to comment. You can just change the channel ID and it drops the guy ID of every viewer? >> So, okay, if you just change the channel ID to the channel ID of the nation. >> Yeah. >> Say Say it again. >> I said, what do you mean by change the channel ID, Broca? >> Okay, so pretty much in the in the three dots, right? You can just tap on that. It loads this context menu for that user, right?
So, you can just change the user ID to any user in the whole YouTube. It'll just load the three dots for that user. Does that make sense? >> Oh, he's saying that in the request that in the request that gets sent when you hit the three dots, if in that request you just change it to the channel ID, aka the user ID of any user, then it will just immediately respond with the guy ID. >> I see. I see. Okay, got you. That makes sense.
Continue. >> There's always so much assumed knowledge whenever you're interviewing experts. Like when you say channel ID, to me I'm thinking like channels that people publish from, but you know everyone on YouTube has their own channel ID because like and so anyways, yeah. >> Exactly. Right. Right. Exactly. >> Yeah. So, yeah, I had this I had this like primitive or whatever. I could get I could get the guy ID, but I wanted to see how I can escalate this further.
So, I was I was looking through like all these different like all the different like apps in Google cuz there's there's so many weird apps. They've had so many leaks before like in the past, right? You could just you could open like a This is back when Google Hangouts existed. You could open a Hangouts chat with somebody and it takes in a guy ID and it just returns it just opens a chat with their email, if that makes sense.
So, there's probably some leak out there. So, I was looking through all of this super old apps. Like I found this app like Pixel Recorder. Okay, it was like this niche app where if you have a Pixel phone, you can like have recordings and sync it to the cloud. So, I had this app and I synced it to the cloud and I went to this this like recorder.google.com or something. And at this point, like there was like a share functionality.
So, I just tested it out. Can I Can I share What if I share this recording? And it took in the obfuscated guy ID and it returned the the email. Like it cuz it matched the guy ID and then you get this is the people added and it has email there. So, now I had a full chain cuz I could just I could just leak the guy ID, then leak the email and now I have the email of any YouTube channel I would or any YouTube user for that matter. >> Wow, dude.
That That's intense. So, channel to Gaia, Gaia to email, right? So, you get that chain and then you leak the email out. Wow. >> That chain is like something that a seasoned bug bounty expert would report and it's just his first Google bug. >> Yeah, I know, right? Yeah, like that's such a such a crazy thing, dude. Very good work. Yeah, I think the OSINT background really That's a great That's a great tran- transition, right?
Because you're so focused You're focused very literally on like leaking data that is useful, you know? Um so, you don't get as many reports where you're like, "Oh, I can leak this, you know, completely unrelated thing." You're like, "Oh, okay. Email. Yep, that's useful for sure." So, um that's a great >> Leak- leaking leaking into top bug hunters seems to be such a a clear route. Like there's obviously all the game leakers that have done the exact same thing on like uh Epic or Fortnite and stuff. >> For sure.
So, then you just kind of after this, looking at the doc, it kind of seems like you just went ham on YouTube, right? >> Okay, so okay, I'm not done with the story yet. So, it wasn't it wasn't complete yet because See, the problem with this Pixel Recorder was when I shared the the recording or something, it sent this this a super long email, "Oh, this guy has shared a like recording with you." So, it's it's it's super like messy.
Like I don't want that the victim seeing that. If the victim sees that, then it lowers the impact so much, right? Like and my OSINT tools like there's like this general rule in OSINT where like if you have something that works, it shouldn't notify the guy. If it's If it notifies the guy, it's like a red light. So, I was trying to see, okay, is there a way I can like stop this notification? I So, I tried to see like Okay, like the parameters, there's no parameters like not like uncheck like the notify, but I I thought about it.
Like, what exactly is in the notification email, right? There's the title of the recording in the title of the subject of the email, and there's like the recording like whatever description or something. But, if the title title probably has some sort of limit, right? If If you reach the limit, it just probably won't send the email cuz it's it's very So, I just I just like wrote like a 1.2 million character like title, and I created the the pixel recording.
Then I shared it, and there was no email. >> I I don't want you building OSINT tools for anyone, okay? Stick to bug bounty, buddy, because that If If there are OSINT uh builders who are out there who are smart as you, they're going to be able to pull off some crazy stuff. >> Yeah. Wow. That That is a good I love how the solution could be that simple sometimes. You're just like, yeah, what if the email was really really really freaking big?
You know? >> [laughter] >> This is making me regret so much. I feel like there's so many like sensitive actions that you can take on behalf of other users that are often like mitigated by basically notification emails. Now I want to go back and retest all of those. >> Totally. Totally. >> Uh That was so smart. >> Wow. Great Great finding, dude. >> So, at this point, I was like, okay, this is surely like a VRP like level bug.
Like, I I should probably report this to Google. Like, I I don't think I should be happy with this. It looks too broken. So, yeah, I I I looked into like like how do you like open like a security report or something. So, I sent in the the report. It was like a super like messy report. I I didn't I didn't even know what I was doing. So, I just wrote out like all the steps of the how to get this working, and I sent it off, right?
So, then eventually So, they they took like quite a while to get back. I think it was like around like November and December of like 2024 or something like that. I I don't I don't know the exact timeline, but something like that. So, there was It took It took quite a while cuz it it was like the holiday period, I guess. But, eventually they they they got a nice catch. I I to like debug with the triager. Like, I think there was like some weird like case where the treasure wasn't able to actually test it and it didn't work for him because he was trying to get the tree dots working for his own channel, which doesn't work because like you can't open the you can't block yourself, if you hear me.
You can only block other people. So that just didn't work, but yeah, in the end we sorted it out and he got like a nice catch. So this was my very first like Google bug, right? So this kind of got me into this whole this whole thing. Like and I think it was worth in the end like 10k or something, right? It was it was like pretty big money. I mean so I was I was looking I was looking at more into this thing. I was still looking at I was still focused on I wasn't I didn't actually care about like VRB hacking internally.
So I was looking at like how I can I had this like database or whatever. I was like scraping a bunch of YouTube data cuz it was quite interesting to me getting all this big data stuff. Like can I list all the comments of some guy, right? cuz if you if I like if I like scrape all the comments, can I like list all the comments from this community channel or this user? So I was like doing that and across from doing that I learned so much about Google APIs, right?
So I think that that knowledge was super valuable. So first of all, I I figured out like what like protobuf and GRPC was. Like I could hit requests directly with GRPC. Like all this wasn't documented properly. Like I had to find some like I found some how to RPC like markdown page that like Google released, but even that didn't explain GRPC too well. Like there's a difference between proto over HTTP and GRPC. I was using GRPC itself cuz I wanted this to be as fast as possible cuz if you're doing it at the scale of like YouTube, you have to it has to be fast.
Then I figured out like oh there's like this header X-Google-Field-Mask. So I can like I can just reduce it to exactly what fields I want, right? Like the comment text or whatever. Then this is where I learned the 1e100.net trick where you can load balance across like all different all YouTube or all different hosts in Google. So that way you're not like just hammering this one host. And and Google also had like rate limits, but at this point I figured out like I'll do I'll do more research and I realized that you can use IPV6, right?
To bypass this whole rate limits because rate limits are normally per IP address for unauthenticated requests, right? But they didn't consider the fact that an IPV6 like IPs are super cheap. You can just get like a /64 or something has so many IPs, like billions of IPs. And you can just use that and rotate between each IP and then they can't they can't stop you. Unless they do like a subnet ban, but at this point that didn't exist.
So, you could just kind of do that and bypass any and all the rate limits. >> Wow, dude. Yeah, I remember back in the day when I was in the recon game, you know, there was this problem where you couldn't Google dork very effectively, you know, in an automated way. And the solution that we had to that back in the day was get a /64, you know, IPv6 and then use that to hit Google and and do your do your search until it you know, blocks you and then just rotate the IP.
But I guess I guess they probably fixed that now with subnet bans. >> Oh, yeah. So, the the fix they have now is they do I think it's a it's like a layered approach. So, if you try to use a /64, they'll ban the /64. Then if you try to use a /48, like it only increases the subnet size of the ban. So, that I think it's a smart approach. But I mean, it's still possible to get like a you can still rent out like a super big like ISP level like range or something.
Or if you if you have a shared range with other customers, like that could also be another way. Like it's super hard to block this. I don't think IPs are a really good way to >> Yeah, I mean, you could just buy like proxy rotation, right? Through like some of those like more shady services and it will just rotate every every request through a bunch of different residential IPs and you'll just never be blocked. >> Yeah, that's true. >> Yeah, exactly.
So, yeah, that that was that was kind of what I was working on, but through this this this whole process of trying to like how I can get as much information as possible from a YouTube channel. I was looking through all the APIs. So, at this point I found this repto proto thing. Like it's like this tool where I can I can just probe I can use this JSON proto buff and I can just probe like like 1 2 3 4 5. Like I just send that in like an array and send that to the server.
It starts leaking a bunch of error messages, which tell me the whole proto buff message, right? So, I can reconstruct the whole proto buff that the request has. So, this leak this leaks so many like internal things that would otherwise not be seen anywhere, right? So, I went to I was looking through all the channel endpoints and I found this this one endpoint like the get creator channel. So, if you go to your YouTube channel and you like I think click on the earn tab or one of the tabs, it like fetches information about your own channel, right?
So, it uses this get creator channels like endpoint. But, you can also use this to fetch other people's channels, but for restricted fields. Like, you can supply like specific like fields that you want to fetch and it would only be like the public fields. So, I was thinking, is there any sort of like parameter I can like use here? So, I leaked I ripped the proto and I leaked all the parameters and I saw some like include suspended is true.
So, that sounds like you would think it means the channels are banned, but that that's not what it was. It just it just appended some random content owner association. I I don't know what what this was. So, I was trying to figure that out. Like, it it added some content owner association with some ID, right? So, I started looking into this. Like, what is a content owner? And I I went through this whole rabbit hole. So, turns out like content owners are like this so CMS accounts on YouTube.
It's like this god mode account. They give it to a few enterprises and they essentially can they can strike anyone they want. They can like monetize any channel they want. They can claim your content. It's a super sensitive tool. So, this this this tool or whatever can link channels to it, right? And this would leak the association with that tool. So, and the way like these rights management tools work a lot is they have like you can like if I'm a if I'm like a big like company or whatever and I want to contact another company, I have a I need to like find your email or something to contact you, right?
So, they have this endpoint like some some endpoint to sort of uh like get the email of the other company, but it's just a constant it's like a notification email. And you set this as a public email. It's not like some sort of account email. You can put it as whatever like at your company.com, right? So, it's just internal functionality, but so, this required a CMS account to do in the first place. But, then I looked deeper into YouTube, right?
And I realized that, you know the copyright match tool that a lot of YouTube channels have? So, you can see like other people claiming your content. Like, how does that work? It's probably just content ID in the backend, right? So, is it making a secret CMS account in the backend? And it it sure was. So, it was it made some like weird CMS account back end. It's like some like I guess they had to do that in order to make this hack work to get the the content ID working for that.
So, then I realized that I could leak the ID of that, right? And what is the content the the notification email set for that account? Is it like cuz you can't set that anywhere, right? And it turns out it it goes to the account email of the YouTube channel. >> Oh. Nice, dude. >> So, I was able to do this whole chain. I could like I could sort of leak this this initial ID. Then I could discover this ID and leak the normal conflict notification email, which would be the channel's email.
And then I had the I had the the email for basically any YouTube partner I wanted to. >> Wow, dude. Yeah, that is a good chain. So, there's that there's that aspect there of like how does this value get populated when the account is created automatically? I like that. So, so that's just try I'm always trying to take these principles and kind of bring them up to a a higher level, I guess. So, even in those situations where you can create, you know, let's say an email that's adjacent to to the one associated with your specific account.
If you can figure out a way for that to access it in its default state, right? Before the user has set it, then that might be, you know, associated with the main account. That's very good. That is an awesome principle. >> Exactly. Yeah, so that that worked out here. So, I think this one even higher bounty than the other one. I don't know. It's kind of confusing cuz you know, they're they're abuse VRP like caps out. The first one got rewarded as abuse, but this one got rewarded as like the the normal VRP.
So, it got like 20K. But the other one was 10K. I mean, I don't know, man. Like I feel like they should increase the rewards for the abuse. >> Yeah, dude. I don't abuse That is one of the things that we've we've we've kind of bumped up against with them often. I'll share this situation that I had where um you know, I I was able to enumerate the phone number for any Google account. And uh but it was through essentially a a What is the word I'm looking for?
A not magnified, but like a brute force that is powerful across multiple requests, right? Like I can send, you know, 10,000 in one request. And so, you know, it was it was pretty low traffic. It was like, you know, 60 to 100,000 requests to leak a full a full, you know, 10 10-character phone number. Um but somehow that got put in abuse even because of it if it's like brute forcing some I'm like, but this at the end of the day it still leaks the same phone number.
Like if there's an API that just responded with this phone number, then you would say it's Google VRP all day. But if I have to send, you know, 60,000 requests to leak it, you know, then it then it's abuse. I don't I don't understand. It's it's a little bit of a weird setup they have there. >> But even if if they wanted to do this, in my opinion, they should let the match up the abuse rewards to be like equal to this because you can have an abuse bug abuse bug whatever a super high impact, right?
As you mentioned. So, it doesn't make sense that the rewards are capped at like 13k or 10k or something. But the the VRP of the other side like Google VRP is is not capped like that. >> Yeah. Yeah. >> Yeah, I I hate that like the which maybe this is only the GenAI stuff, but the API keys they gave internal access to internal AI models historically were treated as like abuse API leaks and they paid 500 bucks for them.
I will say the ones this year did pay better, but still for the type of impact there again, I think that in Google VRP it would have paid a lot more. Like if you could just like take over a Google account that had access to those same models, they would pay you like 50k, right? But because it's like an abuse bug, then it's like capped at like nine or 10 or something. >> we've had the Google team on here to talk about that in the past and they were like, "Guys, abuse is for when, you know, Google VRP isn't going to pay you at all." And I'm like, "See, I don't think that's true." Like, you know, cuz I don't think that you would not pay me to be able to link the phone number of any arbitrary Google account, right?
Like, that doesn't make any sense. So, uh I don't know. There's definitely some some some tweaking that that needs to be done there. And I'll say, you know, I've said it on the pod, I'll say it again, I often, almost every bug, to be honest, push it back to Google, you know? And and I would say a lot of time they do adjust the bounty at the end of the day after more rationale. But, I it is frustrating to me that I have to push it back every time and be like, "No, this is this tier.
No, this is this data sensitivity. No, this is not abuse. This is, you know." And it it takes time, man. It's not a insubstantial amount of time that that it takes to do these debates. So. >> Yeah, it's super tiring as well cuz like you report a bug and you think that it's just going to be just really but no, you have to you have to keep like fighting against appeal it and talk back and forth. It's just super annoying.
Like, you can't just report it and be happy. I think other like programs, I'm not too sure but I'm pretty sure other programs would report the same report the same thing as you mentioned as like a normal tier. It wouldn't be like abuse and then some lower PR. >> Yeah, it's odd. It's odd. >> Dude, Justin, you were just talking about how you leak phone numbers and then I scroll down here in the doc and literally Brute Cat has found the same thing back in early 2025. >> Okay, [laughter] all right, yeah. >> But but he didn't have to do it via some convoluted abuse way.
He did it in a railway. >> know this there's an IPv6 bypass there. He might be brute forcing stuff, too. What do you what do >> Dude, is it is it is it brute force as well? It's the same [laughter] thing. But but when did you when did you find it? >> I found it I found it it must have been it must have actually been late 2025. But mine was on >> Oh, wow. >> So, uh Richard Richard >> know about that. No, but that's like that's like >> Yeah, well yes.
Mute that, too, please, Richard. But, yeah. >> [laughter] >> Yeah, so >> No, I do want that. I just didn't report it cuz I I didn't want to like because it was part of my OSINT thing right and I kind of like get that. >> You burned his OSINT tool, Justin. What are you doing? >> Well, I don't I don't even Who knows if they even fixed it cuz it's abuse, you know, but whatever. Um so, anyway, hit it hit us with what you got for this phone leak. >> Okay, yeah.
So, anyways, so this this phone leak is for like the account recovery number right. So, you could basically everyone has a set pretty much. So, I was looking through like the the JavaScript like like I noticed the Google pages right. For some reason some of them worked without JavaScript which is kind of odd to me cuz like in the modern web right you don't really see many things that work without JavaScript. Right. So, I was just playing around with it.
I I wasn't expecting anything. So, I went to the login page. The login page didn't work, but for some reason this forget password like the the forget password page or something it it just worked, right? And I'm sorry, it wasn't forget password. It's like forget username or something. Yeah, so this page just worked. And the forget username functionality is super interesting. So, you can enter like a full name, right? And then you can enter like a phone number and it tells you if it matches together.
So, is there an account which has this full name and this phone number? And it worked without JavaScript. So, this was like a huge exploit because if you think about it, JavaScript is how Okay, so do you know what Bot Bot Guard is? Have you heard of him? >> Yeah. Yeah, I heard of Bot Guard. >> So, it's like it's like Google's like obfuscated proof of work, right? So, they use this everywhere they want to stop like botting because the the idea with it is like by the time you spend all this time to reverse it like the chance is a new challenge already.
And it's it takes So, it takes super hard to reverse it and you have to it's a proof of work as well. So, it takes a lot of compute power if you want to generate this token, right? So, this is how they they prevent it, but they can't do this without JavaScript. They need JavaScript to load the challenge, but everything seemed to work without JavaScript. So, that was super sus. And I knew a bunch of like like these weird like login pages that work without without JavaScript as well.
Like youtube.com/tv for the longest time you could do a login without JavaScript, but they they patched that, but this one wasn't patched, right? So, I was looking at it and and I was looking Okay, so can I just like brute force this? So, Okay, this is this is something super interesting. The number maybe realize this, but many services like PayPal, they they leak like so many digits of your phone number. So, if I go to paypal.com and if I do a password reset of your email, they'll like show me, "Oh, do you want to text this number?
Like +165" and then it's just just four digits censored. Everything else is revealed. >> I've never thought about how that this is probably some super useful bit of information for OSINTers. >> Yeah, totally. >> But yes, of course we know exactly what you're talking about. >> If you think about it, if you chain enough services, you can probably just leak the whole phone number. >> Yeah. >> Cuz [laughter] they Yeah. >> But even if not, if you're doing some sort of like um node-based mapping of people, right?
Because like that's obviously a big problem is like linking profiles and stuff. Even those three digits might be useful enough to like link like 60% of profiles or something in like an OSINT database, which is kind of interesting. >> Yeah, so I was I was looking at how this works. So, I had I could take the I only need I only need to brute four digits or something for the PayPal one. So, and that's what I did. It's super easy to do.
So, I wrote out some like script or something, and I was able to I was able to get it. So, it it worked. But then I wanted to see, "Okay, can I take it steps further? Can I just brute force the entire phone number?" Right? But at this point, there was Okay, there's a bunch of issues. Okay, so first of all, how do I know which country code your phone number is? Cuz there's so many formats, right? It could be like +1, it could be +65 for Singapore.
But turns out, if you look at like the password reset, like the it is like some form that they write the phone number in, like a bunch of dots a dots and a space and something like that. You can use that and reverse engineer it and figure out which country it's from. So, then you know which like plus code it is. So, that's the first link. And you can get the the last two digits from the the like password reset or whatever.
It shows like the last two digits of Google, right? Then the other the other problem was how do I get the full name? Cuz if I'm going to brute force this, I need to have a full name to fix on and then to brute force it, right? But I didn't know where to get a full name. So, but after I looked through like a bunch of weird services Okay, so this person's OSINT thing, right? Google was has has been has been like trying to get rid of all this full full name leaks for the longest time.
So, they've been stopping as many of these as possible. So, this was like a big thing that they tried doing in like I don't remember exactly when. I think it was like like April of like 2024. Like they tried like leaking all the different leaks, but I found for some reason you could like share like a Looker Studio report with somebody and then it like leaks their their full name or something if you if you share ownership. >> Doesn't doesn't remember his mom's birthday, but remembers the date that he they stopped doing the full name leaks on Google's thing. >> [laughter] >> So, the reason this worked is because like the if you think about it in Google, right?
If you you can always see the Drive owner's name, right? Like any sort of Google Drive. So, I think like they have this consensus where if somebody owns a document, they can they can you can see the name of that person. But, for some reason they didn't consider the fact that Looker Studio doesn't require the other guy to accept ownership. You can just transfer it and he's not the owner. You don't have to The guy doesn't have to prove it.
For Drive, the guy has to approve it first. So, this kind of allowed me to leak the full name of the person. Then I could chain it together. So, I could now I could now prove it first. But, so I had I had a whole working proof by PFC. I was like ready to report it. And then like I tried again, it just stopped working. I was They they they they fixed it. Like I was I was screwed here. Like I had everything ready and they they screwed it.
But, then I then I was like seeing, "Okay, is there any way I can like kind of salvage this? Like is there some like bypass or something I can do?" So, I was I was super disappointed. I was looking through like the JavaScript version of it and I saw they passed through like some botguard parameter. So, they passed through like a botguard real botguard token. So, I was like, "What if I do this on like the Node.js endpoint?
Like what like if I'm passing like a botguard there? Like what happens there?" So, I just tried it like for fun. And it seemed to just work. Like it just didn't have any sort of limit. Like you hit one botguard token, you could send infinite requests with that one token. >> Wow, that's crazy. >> So, I could compute it myself. Like I could do the proof of work once, then I could use the same token infinite times, then the whole thing worked again.
So, I could I could So, for any Google account, if you have a recovery phone number, which is everyone, you can just find a number, right? So, that was pretty interesting. And I actually demoed this to a bunch of journalists because they were super interested in this cuz this will impact you for SIM swapping. If you think about it, if you have a guy's phone number, that's probably the hardest part of the SIM swap, right?
You can just use a rogue like Telco provider or something and and then SIM swap a guy and steal their crypto or whatever. So, this is a the sim the phone number is the hardest part and this just gives you the phone number. So, a bunch of like journalists were interested in it and they ended up covering it, I think. There's a bunch of articles on this. If you get like any US number in like 1 hour. So, I did it live demo to them as well.
Like they sent me the email. I got the phone number and sent it back to them. >> That's great, dude. Oh, man. That I I love it when you get to do when you get to actually like exploit it and show it, you know? Um did did you report this one to Google as well or is this one you decided to just go the full disclosure route on or or both? >> Oh, no. I I reported it to Google. Like but like while it was like while the report was like they haven't fixed it yet, I I was able to do the demo to journalists, right?
But I didn't give them the info about the exploit itself. I just said they kind of did it on their email cuz they they could send it to you, right? So, they were So, I had this whole embargo and immediately we released the article and it's pretty it's pretty cool. But but yeah, this was rewarded under abuse. I think it was like 5K 5K bounty. >> Mhm. Yeah, dude. That See, that does that not just feel off to you? Like I feel like the value of a Goog you know, Google account to phone number mapping is like so much more valuable than that.
Uh for exactly the reason you said, like what a powerful exploitation tool for malicious actors. >> Exactly. I I don't know why they they did that. I guess it's cuz the abuse problem. But but oh well, I mean the same thing with Google VRP, right? It would be like it it would be like probably like a 30K or something like that, right? >> Wow, dude. Very good. Yeah, dude. I I got to go back and look at that report again from from before and be like and cuz I went back and forth with them like four or five times about it, but they didn't keep it at pull it out of abuse.
So, um all right, man. Uh, I think the last one or maybe we'll do in one more section before we we cut for this week, but um, I want to hear you talk about the discovery docs and your experiences with that because I just speaking personally, Google ran a a grant back I think end of 2024, I want to say, where uh, they gave a bunch of discovery docs, you know, to the to the hackers and the hackers, you know, were able to use these to attack and we found out that you can get these actually from hitting, you know, dollar sign discovery rest.
Uh, but then since then there has been a bunch of changes to that it after my eyes have were opened. Um, and you know, it's not quite as simple anymore. So, what kind of tips and tricks do you have for discovery docs? >> So, for this Okay, for discovery docs in general, I wasn't actually part of this grant, right? So, I didn't have access to the discovery docs or anything, but I found it through an entirely different approach.
Like, I was just looking through this old stuff and I was looking at the people API because this people API was super interesting. You could look up a guy ID or anything and see a bunch of stuff about it, right? You could look up a guy ID. So, I was also looking at that, but I couldn't figure out all the parameters from just guessing from the request, right? I had to get a doc. So, the doc the doc I'll learn everything had comments, everything.
So, this is kind of how I found discovery docs. Like, back in the day, you could just do it Wait, back in the day I mean like 2024, you could just do slash like dollar sign discovery slash rest and it would just give you a doc, but recently, I mean, uh, I think within the last year or so, they've like they've nuked all of this. So, you can't just because they had they had some like scandal or something and like it was related to like content warehouse API.
So, they accidentally released a bunch of protos and like they also started locking down discovery documents because of the end. Yeah, it was it was a big thing, but but if you're smart, there's a way around it. Okay, but I'm not going to I won't say it here, but if you can figure it out, it's possible. You can still get a discovery document from many APIs. >> Interesting. Okay. >> about think about the RBC app. I love it. >> Okay.
Hmm, I'm going to turn on that. I'm going to turn on that a bit. >> So, yeah, anyways, I was looking through the the discovery document and but the thing is you need a key to access them, right? You can't just access the discovery document by itself. They They all of them require API key. So, I spent this time like going through all the different like various sites. Like I was doing this manually at first, right? I would just go to all the different sites, capture all the keys I could get, and I had this like database.
It was It was like a a humble database of like 200 keys. >> [laughter] >> I was able to sort of like leak a bunch of documents, but and I That's when I published an article as well. Like I I wrote the whole like thing about the discovery documents. I didn't I didn't even utilize it that much. Like I should have In hindsight, I should have like done more stuff there with the hacking it, but I just kind of left it there and I I did other stuff.
So, that's that's kind of like the whole discovery document thing I did at first. And for YouTube, like the discovery document was interesting because you can't just do such discovery with /rest because they did a weird thing a weird rule where they blocked all like uh like get requests or something. Like you could you couldn't do any get get requests, but the get requests had to be done for the discovery document to work, right?
Cuz it's /discovery/rest. So, how did I get How did I get that working? So, uh it turns out you could use some like X-HTTP-Method-Override. So, you could send a post and then convert it to a get and it leaks the document. So, I had It was a super big document. In fact, this this is the biggest discovery document that exists in Google. It's the YouTube document. So, it had all kinds of APIs inside and I I was able to like trace back and find that YouTube exploit that I had where they did include suspended.
I saw it there. And I'm sure there's still tons of exploits you can find on YouTube if you still look at his documents. There's like hundreds of methods. It's super big. This There's even this whole like testing CPP in a YouTube API once. Like they're super suspicious. Like maybe you should look at that. >> Dude, that that There's so whenever you get one of those docs and you start parsing through it, it's like I just feel like a kid in a candy shop.
I'm like, "Oh, man. I can't wait to like, you know, work through all of the functionality of these things." When when you get a primitive like this, when you get a a way to get insight into these APIs uh on any target in a of fashion, that is such a high signal that you need to be paying very, very, very close attention there. >> Exactly. >> On Google specifically, it is a little overwhelming, though. >> Oh, for sure.
For sure. 100%. >> Um yeah, so I think the discovery docs they're in this proprietary format, but there's also conversions that you can do to um like Swagger and stuff like that. Have you had uh is that what you use or do you parse out the actual raw discovery doc itself and and put it into a format that's readable for you? >> So I wouldn't actually do that. I wouldn't actually convert it to Swagger because you're going to lose a lot of stuff. >> Exactly. >> Because the way the way these documents are formed, it's like protocol messages that are converted to like JSON, right?
If you it's not a standard like Swagger format cuz yeah, it's like it's super weird. It's a Google's like own format. If you do this, you're going to lose a lot of comments or like enums or something like that. Like you you don't want to lose it. You want to parse it exactly like it is. >> Mhm. Mhm. So yeah, that's something to keep in >> Do you have a Do you have like a preferred method of doing that or do you just have your custom solution? >> So I built a whole like front end for doing this.
Like I have I have a front end where I can uploading discovery document and then it shows like a whole thing. I'll explain more about that like later on, but but yeah, like that's kind of how I I parse it myself. I don't actually I mean, you can probably make some custom like tool or like command line tool or whatever, but front end was the easiest for me cuz I wanted to build a way I can sort of upload the discovery document, list all the methods, see which one I I want at first party off already enabled for it, copy it and immediately start testing. >> Great.
So I built this whole thing. >> Very nice, man. Yeah, I I definitely I definitely want to double click into that. Um let's let's say uh we've got one more thing left before I think we're going to cut for today. Um do you want to talk about Google API hacking at Bugswat Mexico uh in this in this one or should we push that to next week? >> Next next. >> Okay, let's do it. So all right, that's a wrap, dude. Thanks for coming on this episode.
We're going to we're going to tease uh next week's episode. Um you know, there's there's a lot of really really crazy [ __ ] that Brute Rat has been doing on Google and he's going to show how he uses his AI to hack the APIs that are associated with Google, take advantage of these discovery docs and API key correlations and put all that together to net over 500k in bounties. So, you know, we don't we try to avoid part one part two sort of situations on CTBB, but I think this time we're going to we're going to make exceptions.
So, um >> He basically did what me and Justin did, but way better. >> Yeah, but like, you know, five times better. >> way better, yeah. >> That's >> [laughter] >> that's amazing. Um, sweet. All right, well, we'll see you guys next week. Peace. And that's a wrap on this episode of Critical Thinking. Thanks so much for watching to the end, y'all. If you want more Critical Thinking content [music] or if you want to support the show, head over to ctbb.show/discord.
You can hop in the community. There's lots of great high-level [music] hacking discussion happening there on top of master classes, hack alongs, exclusive [music] content, and a full-time hunter's guild if you're a a full-time hunter. It's a great time, trust me. >> [music] >> All right, I'll see you there.
The words are the caption track's own and nothing is reworded or re-transcribed. Paragraph breaks are placed between sentences so the text reads as prose.
Free tools for your own script. No signup, no login.
Paste your draft and see where viewers are likely to drop off, with a rewrite for each weak line.
Paste the first 30 seconds of your own draft for a hook score and rewrites.
Check your draft against YouTube's advertiser-friendly guidelines before you record it.
Read this channel's public videos and transcripts, and download a writing brief for it.