Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.
Getting the transcript
Reading the captions from YouTube. A video nobody has opened here before takes 10 to 30 seconds; this page fills in on its own.

Critical Thinking - Bug Bounty Podcast · @criticalthinkingpodcast
Words
18,607
Runtime
1:23:57
Speaking pace
222wpm
Reading time
78min
222 words per minute, above the 201 75th percentile of 349 measured videos. That distribution comes from the 349-video hook study.
Opening (first 30 seconds)
like in three months it got like okay so I wrote the title of this blog post is is hacking Google for 500k but it's actually 670k right now oh my god in basically three four months oh my gosh from just running this that's crazy best part of backing when you can just you know critical thing right Yeah, dude. I literally have done the exact same thing you did in this blog post and I did it for like 3 weeks and I had and it was extremely structured. It was like you know consider all the types of O consider all the types of requests consider all the
111 words, the words spoken in the first 30 seconds at 222 words per minute.
Free, no signup. See how the first 30 seconds hold attention, with rewrites.
Sentence shape
| Measure | This transcript |
|---|---|
| Sentences | 1,225 |
| Average words per sentence | 15.2 |
| Longest sentence | 250 words |
| Questions asked | 157 |
| Sentences containing a number | 60 |
Most used terms
Filler phrases
1,349 in total: like 808 · you know 107 · um 101 · right? 88 · uh 76 · actually 51 · kind of 30 · I mean 28 · sort of 28 · basically 17 · literally 15.
A literal whole-word count of the same phrase list the Prepublish browser extension uses, so a phrase inside another word is not counted and a phrase used in its ordinary sense still is. It is a count and not a judgement.
What this transcript is
Every word below is the caption track YouTube publishes for this video, pulled from the video itself and reproduced unchanged. It is not Prepublish's writing, not a summary, and not a re-transcription: it is the video's own published captions. English captions, published by the channel, in the video’s original language. Source: the video on YouTube. A channel that would rather this page did not exist can ask for its removal through the contact page, and it is removed.
No Script X-ray for this video: YouTube shows a Most replayed graph only once a video has enough views.
like in three months it got like okay so I wrote the title of this blog post is is hacking Google for 500k but it's actually 670k right now oh my god in basically three four months oh my gosh from just running this that's crazy best part of backing when you can just you know critical thing right Yeah, dude. I literally have done the exact same thing you did in this blog post and I did it for like 3 weeks and I had and it was extremely structured.
It was like you know consider all the types of O consider all the types of requests consider all the types you know uh like all the different API keys we have you know like the 800 API keys we have like let's test everything comprehensively from end to from top to bottom with all the discovery docs that we've had access to or that we've leaked through bug bugs or gadgets using every form of O and every API key and like I found some bugs but I mean I'm talking on the order of probably like 10% of what you found right like I think I probably made like 50k across all those bugs so I mean this is definitely downstream.
I don't think that we should write this off as like you just using AI. Well, this is downstream of your expertise by a mile. Oh, yeah. I think and and taking that and then taking the leads from the AI and exploiting them further manually, I'm sure. Right. You got you would say that that's true, correct, Brutecat? Yeah, exactly. So, I think like a lot of the leads I get, I don't just leave it at that. I try to like push the impact as much as possible.
But I would also say in terms of the AI hunting, right? See, you don't want to give too much to the AI because if the AI has like access to do like anything it wants, it's not going to like for I try to explain this in a simple way, but pretty much the authentication itself. I've kind of like ab extracted that out of the AI completely. So the AI doesn't even think of that. It just focuses on this one task of testing the API, right?
And another thing is there's so much noise when it comes to like these these hack bots or whatever. You have to find a way to filter that out. So for me that was like building this thing where I could sort of see the request and response and and I could like and there's no way the AI could fake that because it's like every request AI does I tie it to like an operation right and that operation is then like associated with like the requested response so I can just see what it did if if there's like a PII leak I can see the PI there's no [ __ ] right wow yeah so you're you're getting a really one you're abstracting away a lot of the complicated parts of hacking on Google and then you're you're not giving the AI room to do much besid decides exactly what you need it for, which is sort of filling in these pieces of information and correlating them across uh you know, different Google APIs.
That's that's pretty sick, man. That's pretty sick. Um all right. Well, okay, hold on. We you know, we we got we got rolling there. Um we're back with part two uh of Brutecat's saga here. Um, and today we're going to talk about uh AI and how he has made over $500,000 hacking on Google um using AI uh over the past, it's not even like a year, it's like eight months at this point maybe. Um, so dude, I'm so excited for this.
I think before we get into the all the AI stuff, um, we also wanted to kind of go back and do a refresher on some of the discovery doc stuff. Um, so let's let's do a refresher on that and then we'll jump right into the AI uh component. So Arvin, you built a basically a system for this specifically, right? Yeah. So pretty much I built this whole thing where I can take a discovery document, right? I can parse it out and have this whole UI where I can see each method and tap on it and inspect it, right?
So instead of doing an approach where converting to swagger and trying to look at it that way, I have this one UI. I took a lot of inspiration from Google's. So, you know, do you know how every Google API that's a public API, they have this like try it like explorer or whatever. So, I really love that because you can you can just see the methods and test it like right away. So, I actually I took super like a lot of inspiration from that.
So, it was it seemed to be open source at one point, but I guess they just made it not open source anymore, but it's fine. Like I made my own version of it. So, like my own version has like all the auth and everything all configured. So, you just have to all you have to do is just upload your document, tap on the endpoint, you can start testing right away. You don't even need burp because it has like a burp inside of it, right?
So I just focus my time on testing it. So this is not this is just for like testing the leads in my AI reports, right? So I can just test it directly. Yeah, dude. It's beautiful to have tools like that that reduce the friction so much uh that that you can just you know that's when you know that your your your methodology is really streamlined when you have these super custom tools for this stuff. Yeah, exactly. Um, so, okay, so we've got the discovery docs, we've got the um, you know, sort of built-in burp or Kaido or whatever, you know, replayer for these, uh, specific calls.
How are you tying the AI into this and uh, and getting it to give you these leads uh, from the discovery doc structure that you've built out? So, let me let me back up a bit into explaining how I even got to this in the first place. Okay, so there was like this bug spot in Mexico last year, right? So the whole bug swat I wasn't actually hacking. I was just I was just thinking about like how because I was looking at the source code like googers they let you see the source code to any app you want or anything.
So I was completely fully abusing this. But that also got kind of got me interested back in the hacking, right? So for this like around this time I was I've been using cloud for like around a year. So even my like recctor protool was completely written by cloud like back in the old days of cloud. So I would I would like write it in the the web chat and then copy it and paste it and then take the health with that. So yeah, I was doing all that but but I had an idea like why couldn't I use clot or like whatever AI and why can't I test the discovery documents because you see the thing about discovery documents and testing the end points it's just tedious right yeah if you're looking for access controls I don't think it's like too technically complicated it's just more of like I do you have the time to like look through every single API right considering how many APIs there are it's like it's just too much right you have to you have to settle in your scope or whatever but in this case if I can use AI to look through everything it'll be so much faster So I I had this idea and I was selling Shri Ram and everybody but like and they they were they were listening to me but I don't think they they understood like what I I meant like I was I was fully like engrossed in this.
So this is the only thing in my mind like oh I could use AI to do this. So right after Buffalo ended like I was on a flight back I like one week later I had a whole MV working. So I had a I had this like web UI where I could sort of import like a discovery document and it would like show all the methods on the side show everything and so Google has this O like called first party O V2 right? So they actually ended up so this is something funny right they actually ended up leaking the source code or whatever like the client sites like the typescript source of this first party O in some random like u Google site because they had like source maps enabled so you can you can get like the whole specification of this first party off from there so from there I realized that first party O is not as simple as I originally thought like there's there's like this build like stack overflow post that's like documenting this a right but there's a bit of extra like fields you can have for like getting the full thing so sorry what did you say there was what did you say there was about the O blog post.
There's like these extra fields that you can have in the first party O authorization header. It's not just a sappy sappis hash. I mean there is it's a sav hash but the way you compute it. So this this is required for many APIs like drive front endpool ap the normal one. You have to use this one. So I was able to figure out all this from that and and and actually yeah so this was this was super useful. I combined this with the the discovery docs and like the whole like discovery do thing where I had a UI and in the end I could just go to my website click on any method it would have the whole like burp thing set up for me.
I could just copy the request or or play it in the thing itself with authentication everything handled. So the only thing I had to do is like change the request parameters. So I built up this whole thing first right this whole UI. But then the next step was once I had this UI, I I need to get API keys, right? You have to test APIs, you can't just you can't just use the API. You need keys. So I had those like humble collection of like like 100 keys or whatever, but that's way more than that.
So I did this effort with Michael Delton. He's another researcher. I spent like so long like trying to find as many sources of keys as I could. So this meant like I was trying like I took every single APK that Google has ever published. like I scraped all that 60,000 APKs. I like went through all of them like extracted out as many keys as I could from that. Even for IPAs, we like decrypted it and we took all all the keys from that.
We set up like a like this Chrome extension with Google like debugger API and we were able to sort of like look at every single request automatically and capture keys, right? Then we went through every single Google like domain and we were using as much functionality as possible and trying to get keys that way. So in total, right, this whole thing like ended up with like a few thousand keys from just this whole effort.
But the problem was it wasn't it wasn't over yet. See many of these keys, they might be customer keys. They wouldn't be like Google's keys, right? And I want to keep the scope to just Google. I don't want to attack customers, right? So for this reason, I found a super interesting endpoint like I don't I don't remember where I came across it, but it's in cloud marketplace some endpoint where you can pass in a project number and it tells you which domain it's from.
So you can get a project number from any key from just going to like say protos.g of googlei.com. If I go to discovery document, I try a key there. This this key this key is not this API for the project for this key is not enabled for this this API. So it tells you oh this it gives some error and it leaks the project number in that error. So you can then use that project number and check which domain key is from essentially.
So I was able to filter up all non Google ones. Yeah. Very cool. So this allows you to filter it down. Yeah. Exactly. So there's also another way to get keys. Okay, so I wouldn't I wouldn't say I Okay, I'm not going to say here publicly whether I got keys from this or not, but if you're if you're smart, you can figure out there's like Z handlers in Google, right? There's like these debug handlers. Sometimes they're leaked, right?
And if you go to like certain debug handlers like flag Z, right? You can you can find keys inside there, right? Or proxy is like an LFI as a service, right? You can just use any LFI you want and and and read any file you want. So, and this is on the board class, right? You can just dump like the classes of running processes and stuff. Oh my gosh. and get the keys from those. Dude, that's that is a crazy thing. I've I've not heard of that.
That that's got to produce some crazy powerful keys. So, okay, for on the topic of C handlers, something super funny like this. This was quite recently, but Google accidentally leaked some random binary. Okay. So, okay, first of all, these the handlers are like you're supposed to be the corporate network. You to access them, you have to be like connected to like the internet or whatever, otherwise you won't see them.
They're like on www.google.com/roxy, right? But Google leaked some binary, right? And inside there, they bundled all the Z handlers with it. So I had Z handlers running locally. Really? Wow. Yeah, it was super cool. So I could see all the Z handlers and inside there I found this one Z handler. Like I was just for fun, I was just looking at reflected XSS like is there some like XSS and this like because it's on the main domain like www.google.com whatever or any any domain has the handlers for it.
So I saw this like this one like path. I I could just like put like a super simple access payload and it would pop an alert. And I sent I sent it to Ezekiel. I was like, "Hey, can you check this out?" And it popped an alert for him, dude. Oh my gosh. On on www. Yeah. Oh my gosh, dude. Like the amount of crap I went through to get an XSS on www and you just find this Z handler with a simple Dang it, dude. Uh yeah. Yeah, but this was okay.
This only works for Googlers, but I could argue that like that's where the most impact is like you can sort of Yeah, once you have access, you can start fetching all the internal stuff and Yeah. So, this is pretty funny. But this this binary also had like the full stubby like implementation, the server side implementation, the client side implementation. So, I've reverse engineered like all of this like I have a working like stubby client that I can just play around with.
Wow. I mean, wow, dude. That's that's amazing. So, you can get all this from Z handlers essentially. But yeah, so but the story doesn't end there cuz every API key has their own like restrictions to it. So like there's like web API keys but there's like there's a web restrictions or like Android restrictions or iOS restrictions. So depending on the restriction you have to supply certain headers in order to make it work.
So for web that's refer header or like for Android there's like some special like header you have to supply. So so you have to like brute force the valics for all of these right? If you don't have the valics for these it's basically useless. You can't really use the key right? So I spent a whole effort like individually looking at each each key and trying to brute force the values and storing that in my database. So I had a whole database all the keys and all the the values for each key.
So this was super useful. I think I had like around 3.6,000 keys from from all this 3.6 keys that K keys that are Google's. Yeah. Oh my gosh, dude. That is way bigger than my collection. I thought I was doing good with like 800. He's got 3.6k keys. Wow. So yeah, that that was like see because you think if you think about it, right, keys are the only thing that's preventing you from using the API, right? So this for AI scanning Google like keys are the most critical thing.
You have to get as many keys as you want if you want to access all the APIs or else you're just limited to whatever APIs that your keys can have, right? So then I had a I brute force like a list of all the Google API. So something interesting is if you send a get request to any Google API and look at the server header, it tells you like if if you see some server header there, you could tell it's like a valid Google API or not.
So you can like kind of brute force and find all these like various Google APIs. Then you can use the like you can use various tricks to leak the discovery document of this API. So then I had this whole like collection of discovery documents for all the APIs, right? And then I put all this together, right? So I built this AI tool which okay so or even before that okay I had to find which keys are enabled for each API.
I had to write like a script that goes through each method tries to get first party off working there like and then it tries to brute force like each key until it finds the keys working for each API. Then I had that whole thing in a database, right? So then I could go to any API. So my front end would look like this. Now I could go to any API. I had all the keys there. I could select which key I wanted. I could play all the keys because some keys have different responses.
So I click play all and everything works in the UI and I can see the responses and play around with parameters. I had all this going on, right? So then the next step was to actually use AI to scan everything, right? Because now I can just do this manually, but I don't have time for all that. So I I implemented like a basically like rap like wiggle loop. So this was back in the day like there was no there's no concept of like this control plane of bash right so nowadays we're all using cloud code which has like access to bash but back then this wasn't really like a widely thing like MCP was just pretty new I guess and so I just use like AI SDK and I was like writing some like simple thing with that where I had like MCP tools for each thing right so I had like these these three like I had like okay I had like a few MCP tools first was like probe API tool where I could like probe an API the second one was report vulnerability and the third one was complete testing So if you if you okay this pro API at first right I wasn't it wasn't optimized at all like I was sending so much extra stuff which wasn't needed like in this pro API body right maybe you want to show the document I could like sort of yeah yeah I'll share it right now um oh actually it's going to be a little bit challenging because they've got this behind you've got this behind O currently right because the article that should be hopefully will be released in conjunction with this episode we got we'll see pending approvals and stuff like that but um the currently it's behind a So, let me go ahead and see if I can share it.
Um, yeah, here we go. I think just go to the simplifying probe API section. Okay. Simplifying probe API. There it is right here. Yep. Okay. Yeah. So, it looks super ugly at first. Like I was sending all this like method ID and like path and or like all this stuff. I mean, okay, path is needed, but there's a bunch of stuff like host wasn't needed. Like why does the AI need to send this every single time? And the AI is constructing this MCP itself.
So it has to think of this and and writing. So I wanted to abstract as much as possible away from the AI. I want the AI to just focus on testing itself. So I simplified this a lot. So it's just now I just splice the endpoint the path because sometimes you have to supply path parameters, right? And for the accounts right it I just gave it like include credits. So it can use include credits supply the GIA id of the account it wants to use and it doesn't have to worry about all itself.
It just thinks of this. Okay. Right. So this is a perfect example of how you're you're abstracting away things from the AI to make it simpler for it to test as well. Exactly. Because if you if you were to like let it control all itself, right, it's going to hallucinate more or like have issues with that. So I just want I want a just focus on creating request bodies to test it, right? Because that's the hard part. That's the part of AI to think about, right?
How do you like in the applications context, how do you create like a right request body or something to test this API? M now I did want to push on something here. You said that you got all this hooked up via MCPs and I know that you were architecting a lot of this in like you know 2024 2025 that sort of thing but the the best practice that we've seen nowadays in the industry is to be using skills for these sort of things.
Um are you thinking about rearchitecting or do you think you're going to stick with your MCP structure? Well, I would I would say I would say in this case for what he's doing here, actually, I would I would think that the key point is actually the CLI piece, right? The skill might tell it how to use it like the same way I'm sure he told it how to use this MCP because there's always MCP docs as well. But the way that I would think about like doing this simplified uh thing he did here would actually be like, you know, a skill plus a command line utility, which is passing in, you know, a few of these parameters.
Yeah, that's kind of what I mean by skill precisely. Mhm. Yeah. So that's that's actually the way I do it right now. I'm not doing like this was back in the day like in maybe 2025 or whatever when it wasn't too like we weren't using bash that much, right? But nowadays my system is all like a CLI. I just have a CLI and I I don't use the skill. I just tell it like the prompt or whatever the system instructions. I tell it how to use this CLI and yeah like that that works very well for me.
So I'm not actually like using MCP at all. Okay. So essentially so now nowadays it is essentially a skill. It's just not in a skill. It's just in the the system prompt how you how to use your your CLI tool. Exactly. Okay. Yeah. So then the other issue I had was you remember how I mentioned that different keys could have different responses. So I had like a play all functionality, right? But how do I like give this to the AI?
So sure I could I could like do every single request and then give it like every single response back but it's like wasting responses because a lot of the time it's going to be the same response. So instead of doing that I kind of like group them together. So I basically made this like this like mapping where I I have like a hash or whatever off the response body and then I I can like map it together and the AI just sees like each result and it sees like okay like response body hash is response one and then it can look at response one to see what response one is.
So it doesn't have to send the same response every single time. So I'm just reducing the amount of like tokens it's like being wasted in and random stuff like this. That's a really good solution though because like you know like you said you don't want it to have to look at every single one for like 100 keys and I'm sure on a lot of these services it's enabled on like hundreds of keys right and so this basically condenses down all the ones that don't have data in them and then you know gives you unique responses for the ones that do have data so then the other thing is I had to apply my knowledge of Google APIs.
So Google APIs they they tend to give like super weird responses. For example, if you get a response saying method not found it doesn't mean the method isn't found. It just means like you don't have the visibility label on your key when you're trying to fetch this method, right? So the AI is not how's the AI supposed to know this, right? So the AI only knows so much in this context menu. So I basically simplify this down.
So for all this generic error messages, I basically convert it into like the sort of standard error. So it just says like standard error missing required visibility label or standard error like invalid argument no details, right? So instead of providing the whole thing for each you baked in your knowledge into an error for your local for the model you're running that is that is really good this is the correct way of implementing AI tools.
Yeah. No the way I would have done this which is incorrect is put in the skill if you see param not found that means missing required visibility label but now it's having to like do this like extra leap of logic every time it sees that whereas you just baked it straight into your tool. So cool. You know what? You know what's so beautiful about this too is this is very much how humans work as well, right? Like as as little friction as you can have when testing these things, the better.
And you know, and obviously in our brains we know, you know, okay, if it it's 404, then it means I'm missing the visibility label and it's there and you know, eventually it just becomes like, you know, you don't really think about it. But honestly, as as little friction as you can possibly have uh you know between what you see and and inhibiting your thought processes, right? That's better for testing, which is why you built out that whole environment in the front end, right?
Where you're parsing discovery docs, you just press play and go. And you're also applying that to the AI agent here in a really really effective way. That's that's freaking sick, dude. And not only did I provide like the standard error type, I would also provide like an explanation. So if you scroll down a bit right you can see standard error explanation. This request was rejected by the application due to invalid arguments but no details are provided.
So it kind of explains this error to it if it doesn't understand what error is. So it doesn't have like really the past knowledge. It just sees it right here. So wow this worked out really well for me. So in terms of the AI figuring out like these errors because otherwise it would just keep reporting like these these leads that were nonsense like or like it would it would just think something wrong and like not attack something more when in reality that something could be done more here.
So that that that's pretty much like worked for this. But the the problem was still validation. So I had this whole thing going and it was running and it was producing so much noise though like I would say like 90% of what I sent was like complete noise. It was just nonsense report right. So and I had to go through each one and validate them and it was super tiring for me. So I wanted to find a way how can I cut down this this 90% jump, right?
How can I make it like super like like I I want like super high signal. So in this case I figured out it's like a solution where I could have like an operation ID. So every time the the AI makes a tool call right I tie it to some sort of ID and when it makes a lead it has to reference this ids that it made. So it knows it knows which ID it knows which operation ID it did. So it just has to reference that ID inside the report and I'll reject the report if it doesn't have any ids.
So it can't make a false report. And the other thing was like a lot of the times in Google there's a lot of things that like you would think might look like a bug but it's not really a bug. So I had I like fixed the system problem a lot and I I basically had like testing rules where like oh if you ID enumeration like sure that's that's cool but it's not a bug. Okay I mean sure it's like interesting you can use this for testing but if you can tell that ID1 exists and ID2 doesn't exist like I don't I don't really care about that.
I don't want to report this to VB. So like and also give it like ideas for maybe like testing idle like you can use use a few values. If you notice there like if you scroll down a bit you see don't know a parameter value use use one test me default. I wonder if that's how I found like the client ID default. I mean or it could it could have been another way because yeah but should should we also add a dash there because I feel like you've mentioned seeing dash in some fields too. point if you add what's sorry I was going to say should we add a dash there for the don't know a pram value because I feel like sometimes in paths the the project ID will be just be dash oh yeah yeah definitely definitely yeah 100% yeah so I built up this whole like sort of this this whole thing and it wrote there like even severity level so I can have like like a debug means okay it's like internal debug info that's leaked that's not like leaking some random Google type right or like a suspected IOR but you have no way to like prove it.
So that's another that's like info or medium is like these few like things like a guy ID to email but a critical or high would be like an IR that's leaking people's PII, right? So and so I built up this whole thing and the signal was super high. Like I would say like most reports I I got were all valid and they're all like they're all really well released. So at this point I I ran this across the whole Google like all 14,000 APIs on Google.
I had like a whole session. Oh yeah, and not just this, I will also have to group it together in groups because you see a discovery document is quite big. If I just have a whole testing session just for one discovery document, it's it's going to like focus on one part and leave out another part. So instead of doing that, I sort of made them like I I had like this whole uh process beforehand where I would like group these end points into like front groups, I guess you could say, and it would test each group for one one whole session for each group.
So that way like everything is having attention give to it. It's not like just going to focus on one area and ignore everything else. And I guess if you're doing that, there needs to be decent documentation so that you can compare notes cross groups though, right? Like if one primitive from one group needs to be used in another, you know, group is that something you've implemented or Yes, I did. So I made some like sort of summary thing where it like sum at the very end of a testing session, it summarizes everything it learned from that and it passes that on to the context of the next testing group.
Nice. Yeah, that's really good. Um, you just uh I need I need to audit that file. Can you hand me that file that gets passed from from Yeah, we're going to need those just to, you know, for journalistic purposes. Uh, no, that that's great. I actually can't believe that you like are you sure you want to leak this whole this part of the system prompt here? Like, yeah, sure. Everything is public. Oh my gosh. I'm happy to give all this.
You're so generous. Yeah, I I am um very very blown away. Justin, you've got two weeks. Yeah, seriously, I'm glad we have two week heads up on this. This is crazy. Um, you just casually mentioned 14K APIs. That's a lot of APIs, dude. I think I've got somewhere to the tune of 2K. Um, you mentioned some technique before for brute forcing and then being able to tell off of the server header. Is that anything you care to elaborate on there or?
Yeah. So that's pretty much how you can I mean you can find APIs throughout many races, right? You can you can see from like APKs or from the JS files, right? There's actually this super cool trick you can do in JS files where you can like Okay, I don't remember exactly what it was, but you know you know how JS files have like module system. Yeah. Right. So you can you can actually dump the full JS file without like just those modules like with everything.
So you can change like D equals to one or D equals to zero something like that and you can dump the whole JS file. So that's kind of how you can you can get more like keys or more host names from there. So I collected hostings for all these various parts, right? And then I used those various tricks to leak discovery document even though they tried blocking it, right? So maybe you can hit it through like gRPC or something and it'll leak the discovery document.
So there's a lot of like tricks you can do with this. So that's in total I have like 14,000 discovery documents like almost every single discovery document in Google. 14,000 discovery documents. Holy wow, dude. That is crazy. I didn't I I thought you were saying you had 14K APIs, not 14K discovery documents. That's insane, dude. Yeah, I had all that. So, I I had this whole gold mine. I just need to like extract it now.
So, I have everything set up. It's time to roll. So, I basically I've ran it across the whole Google. It found so many bugs. Like in three months it got like Okay, so I wrote the title of this blog post is is hacking Google for 500K, but it's actually 670K right now. Oh my gosh. And basically three forms. Oh my gosh. From just running this. That's crazy. Well, we have our clip for the start of the episode. Yeah, seriously.
What the heck, dude? Um, that is insane. Uh, so really a couple comments here. One, I can clearly see your OS int background coming in strong here, right? like you you are really thinking about this almost like a big data project, right? Where you are, you know, doing a ton of recon, grabbing all this data from all sorts of areas, cross-correlating it, getting primitives, getting, you know, abstracting away things into modules, right?
This is like classic OS in behavior here. Um, and then you're tying it all together and then AI is the glue between all these different pieces that is helping fill in the blanks. Um, that's sick for one. Um, for two, I wanted to ask specifically, you've done a lot of work getting different O methods for Google. You mentioned first-party off. Uh, you've also done some really excellent work on Android related off. Um, there's also some references in here to iOS related off.
Um, in your experience, what is the most do you have off of vibes the o method that is producing most access to the things that you want? Like first party off like that has so much access to almost all APIs as long as the API has a host name of client6.goole.com. So you have to take note of this. So not all APIs have this alias. Only some APIs have internet exposed client 6. Google.com and if it does like 90% of the time you can use first party O for it, right?
But there's many % of the time doesn't work. Yeah, I'll say that. Oh, dude, I'm doing something wrong then. That's that is uh that is very high. Okay. Interesting. Yeah. So, so pretty much it's super good, but I also implemented like a bearer token. So, I have a bunch of like these Android clients and and even web clients. So, they that's a whole different thing that I did. I don't think it's covered in this article, but I basically implemented all of this.
So, when you send a request, the play all thing, it's doing all of this. It's it's not just the keys with first point. It's doing bar off. It's doing Android all doing iOS off everything. And and have you found that sometimes you will I I I saw you know you do multiple requests with multiple different keys there and give the response back you know in in long form. Um have you found that if you actually if you're using the same API key but a different O method that sometimes you will get different results or is it mostly tied to the API key?
So API keys only like a web concept if you use you can't you don't really use API keys with a bearer token because a beer token usually contains like the authorization of a GCP product. Okay. itself. What about what about um the situations? I guess there there are some situations where you got first party O just got an API key, you know, that sort of thing, right? Have you found, you know, a lot of I guess or maybe you've got a bearer token, right, that has a specific scope to it and then you've also is there never an overlap where you've got first-party O and it works with the Android O or whatever?
Oh, yeah. like many many times it works for both but but I would say like yeah but most of the time like if you want like the thing that works for most places it's going to be first party o it's going to be first party o okay gotcha all right man wow well that is pretty sick um I've got a lot of stuff to go back and review on my own uh infrastructure I will say you know Joseph and I both have a similar system like Joseph said last week's episode we have a similar system to this we have um you know gadgets that we're tying together to cross correlate you know these API keys um you know correlate project names correlate all of this stuff uh but we have done it much less successfully and it's still it's still been good for me I I've enjoyed it you know I've found some good bounties out of it but like not 670k worth of bounties no um I think it's mostly the off thing I don't think that I have really solved first party O had like connected it to the client 6 APIs in the way you did Brata yeah I I definitely did and I still didn't have that uh piece.
I think the area where he's crushing it right now after reading through his article is actually enumeration of the referer and origin header which is massive right so can you talk a little bit to how that uh integrates with first party off um here yeah so if you want to use an API key right like I mentioned they have they all have like different restrictions right you can have like Android header restrictions or iOS header restrictions if you're just skipping past this and like not doing it properly right you're going to skip so many keys that could otherwise work.
Oh, and another thing I want to mention, right? So, all these APIs, they have an origin whitelist. So, with first party author, you can't just use any origin you want. You have to use a specific like whitelist origin. If you don't use a white list origin, it's going to give you some like error that just says session token like invalid or something. Session cookie invalid, but it's it's a it's a fake error. Like it's it actually just means the origin is all white listed.
So, you can brute force all the origins like a bunch of lists of like Google domains and find the working origin. And in fact, the key to this is right, if you find any like like many Google APIs only work on corp origins, that's a huge red flag. I found so many bugs on ones that just only work in corp like origins. So you can you can just use corp origins there. And in fact, the origin doesn't even have to be like.google.com.
It could be like with google.com even though like the cookies obviously doesn't make sense for it to be there, but it it'll work. Wow, that's very interesting. I I need to get a wider scope of these domains cataloged for my brute force, I think, because I I mean, I've got a ton of APIs that I have working API keys for, but not a referer that's correctly um scoped. So, I bet that's where I bet that's one of the keys that I'm kind of falling off on here and missing access to a lot of off.
It feels like there's so many secret API versions um in the path and also so many different secret labels as well. Yeah, you really got to get all of these pieces together, man. And I, you know, I bet I bet Brcat has decent coverage, but not probably perfect coverage. So, I I wonder what's going to happen next. The next time Brutecat like figures out some little thing and then applies it across the scale of the whole system, how many more APIs and stuff he's going to get access to.
Let well actually that's a good question. Do you know what the percentage of APIs that you have where you you don't have access to like either the correct origin or a key to to access it or do do you know any of those numbers? Okay. So one thing I will say is that like I mentioned before how I had most of my success with corresponding authoring but like to be honest right there's a whole untapped surface of using like the bearer off like better cuz like my my system for the bearer off is just kind of like like taped together.
It's it's not that good. Like my focus is mostly first party off. If you use beer o and try to find all these different various clients and find ways or even even doesn't have to be a client that way. It could be like let's say I'm hacking GCP and I I managed to get an access token of like a tenant project maybe that has access to some APIs that otherwise you wouldn't be able to access and if it's an internal API probably has some bugs in it.
So that's that whole area is completely untapped and I haven't I haven't even extracted that again. Oh my gosh, dude. Uh, don't. Why are you saying that on the podcast? Oh my gosh, dude. That is uh Yeah, people. Dude, well, you know, that's another thing that'd be interesting is I got to get you to like give me a uh an API endpoint or something that I can hit and like just tell me whether you've got like a certain API key.
Like I give you an API key and you like yes or no, I don't know about this. Right? because it'd be pretty fun if if like if uh you know we could just do this game of like can I give Boot Cat an API key that he doesn't have and will it unlock access to any scope for him? Uh that would be pretty cool. Well, the same way I feel like people reach out to you for like, oh, I have this CSPT. Can you help me turn it into a bug or whatever?
I and like people do that to me with like prompt injection or Q parameter injection or whatever. Like Brutecat needs an endpoint where people can be like, "Hey, I have this functionality. I've got this primitive. Is this a bug or like can we can we chain this to other things to get a bug? Like we need like a brute cat escalation endpoint. Yeah, dude. Oh my gosh. He's going to start running like the freaking Google primitive black market over here.
Yeah, that's amazing. Um that sounds like a good idea. I could have like an endpoint where you can put your key there and or like your project number there or not. It'll tell you if I have the key or not. And then if I don't have the key, maybe you could add it to this and it be the bounty. Yeah, exactly. That would be pretty funny. Exactly, man. Ship it, dude. Ship it. we'll we'll put it on the pod and people can just throw API keys at you and you can like check it and see if it's like a Google API key or whatever, right?
Um yeah, that would be pretty sick. Um okay, so man, we've covered so much here. Um I'm trying to think about I guess I will try bugs to highlight. Yeah, I will try to do a little bit of a summary here. So as far as all of this goes, the key components are one identifying your um API target. This could be a Google API.com or it could be a client 6. There could be an alias between the two, but there isn't always. Um, then you need to get off to this thing, which you said largely is going to be done via firstparty off um, which requires an API key.
Um, the uh, what is it? Uh, sappy SID um, cookie for you to create that hash uh, that needs to go in the O bearer and then your cookies and a correct origin and refer. Is that correct? Yeah, and there's also the extra component I mentioned for the computing the authorization header. I actually provided the leaked like TS file or whatever which I got from the source map. So, it's in this blog. So, you can you can just use that.
Okay. To compute the whole thing. Gotcha. Yeah. And there's also some like goated Stack Overflow like uh article that that had some code for that too. That's what I used for my implementation. But yeah, actually using the actual TSX um from Google's implementation is way better. Um, and there are, correct me if I'm wrong here, but there there are individual error messages that can tell us whether we are missing an origin header or a referral header or it doesn't support this specific type of O and that sort of thing.
And you have to be able to understand, you know, what is the situation for this given API key, an API pair. Exactly. And so, so the errors are all documented in this blog post. And not only that, I've also had a section in this where I show like each layer of where things are checked, right? So for example, for brewing keys, right, in the okay, the past, right? You could like finding valid keys, you have to get like you have to get first party off first working and then you have to like get the referers all working.
You get what I mean? Like there's different like layers to this. You you have to get like authentication first and only then you can start like rooting the keys. So you if you want to build your program for like booting the keys for each API, you should like take note of all these different things. I even had a section here where they showed each layer essentially. So you can feed that to your plot or whatever and build this.
Interesting. Okay. So I think I'm doing this the other way around. I think I am trying to determine if the API key gains access. Oh, you know the I I'm doing this wrong because what I'm doing is I'm only using the API key to determine whether I can hit the discovery docs or not. Right. So, but there's actually what you're saying is that I should be using Okay. So, let me ask you this. How do you determine how do you determine whether first party o is working for a given API without having an API endpoint to hit on that API?
You mean like a doc? You need I mean you need a you need an API method in order to be able to check if you can do first party author, right? You just need one API method and API methods. You don't have to necessarily have a doc to test API methods, right? Why can't I why can't I test a API method that's like leaked in some JavaScript file or something? So you for so you can use that and sort of like test it that way.
So you don't have to test it through a discovery document and a lot of times discovery document goes down but you have an older discovery document. So you still want to test a use the methods to test it. Does that make sense? Yeah. Okay. Okay. So we do need a method. So we need a method and we need a host and then we can using that we can check whether it supports firstparty off even if we don't have an API key that's compatible with that host.
Is that correct or or not? Okay. You know, I think I I think I misspoke earlier. You need to you need to have a Okay, so you need to have like a valid API key first in order to even start like in this API if you want to check first party author, right? So that that key check happens first and then after that it checks for restrictions of the key. So does this like key have like the right head for header or does have the right iOS header, right?
So that whole thing happens and and then at that point I think the the first party a like origin check happens. So it checks whether you have the right origin for your first party author. If you have everything sorted so far, it checks the visibility label. Does your key have the or GCP product project to your key have the label that's needed for this end point? If it doesn't, return method not found, which is like that [ __ ] okay, like response.
But if it if it does, it is you true. Then it checks, oh, does is this method blocked for this like GCP project or some key or something like certain keys have like certain like methods like blocked for them. So you have to get through this whole thing and only then you can get your request processed. Wow. And this is why it's so hard to test Google APIs. Goodness. Yeah. And this is why Brute says like actually, you know, once you get through the security by obscurity, it's not that hardened of a target, right?
Because nobody can get through the security by obscurity here, which is crazy. Um, okay. So, we've we go through we go through all of that whole flow. We get an API. We get a method. We hit we hit the we correlate the API key. Then we determine first party O. We make sure that we have our refer and our origin header that work with that for us to be able to generate that first party O. We establish an authenticated you know primitive to access the specific API.
Then from there we utilize some tricks or whatever to either you know get the discovery doc from um you know slashdiscovery or we call methods that we found inside of JS files related to the specific host which you have documented in your correlation which I assume came from your Chrome extension that you're using to yeah or or the big data research that you've done that essentially correlates where you got that specific API key or host.
Is that accurate? Yeah. Okay. Yeah. And then and then you feed all of that into the AI. Then the AI tries to take that structure, you know, either with the discovery docs or with the JS files or whatever and then construct a valid proto JSON request body and then send that to the uh API and then it will respond or not respond, you know, until you and you tweak it, tweak it, tweak it, tweak it until you hit something you're not supposed to be hitting.
Is that is that a good Key here is yeah but you should like I think the key here is that everything's abstracted away that the AI is not thinking of this right the tooling is all doing this like the AI just thinks about the body what's it send like all this happens behind the scenes in the the tool itself like all this this research into which API has first party auth what what keys we have or this these are all like background tooling that I've done and the AI itself is just testing the specific body the body for the endoint yeah that's essential that's essential is is you're you're you're perfectly exemplifying what you know, we should not use AI for things that you can do without AI, right?
Like if you can brute force all these things, correlate all of this, establish your O primitives, uh, you know, enumerate these specific endpoints or whatever. If you can do all of that outside of AI, then don't use AI for that. Only use AI for the very little tiny bit of um, you know, intellectual magic that you need to correlate and construct these request bodies. Is that accurate? Yeah, nice dude. Dang, that is pretty.
You know, it's starting to make sense, man. It's starting to make sense, you know, why why uh your um your method is producing such uh such fruitful results. Um okay, so you you mentioned in here just kind of going into that AI implementation about the Ralph the Ralph Wigum loop and stuff like that. Are you still using that? Are you using, you know, the sloop primitives now? um what how do how do you train your AI on when to give up and be done testing an API versus when to keep pushing?
Okay, so in this case, so the the whole thing I mentioned where I did was SDK and I had like MCB tools set up. So that's all scrapped now. Instead, I have like a whole container or whatever like I have where cloud codes running in the container. I think it's similar setup to what you have, but in in this Yeah. So I have a like I feed I feed the AI whatever like whatever it needs to do this and in fact the discovery documents I'm not even providing it as a context in the past I used to provide as a context but that's a horrible method the better method is you can convert this to like markdown files and and the AI can read that right so the AI reads all of this and then according that to that it tests whatever it wants in terms of giving up I would say that okay so this loop I have this like thing where it doesn't end until it like finishes testing everything like if it tries ending and it hasn't tested everything I'm not going to let it end.
I'm going to poke poke it again and say, "Oh, you have not finished testing these endpoints." Yeah. So that that's kind of a way I can ensure it doesn't just quit early and it ensures it test everything. Do you mean literally via code? Like if it hasn't seen like if your like op codes don't show that it's hit every single endpoint for coverage, then it then it keeps going. Precisely. Oh my gosh, dude. He's baked in like literally every hackbot type uh trick in the book just naturally.
Yeah, that's that is uh that is amazing. Um yeah, I'm I'm my brain is kind of spinning with that now because yeah, of course you can check what request this thing has sent, right? Uh through you can just take a site map and be like if you haven't hit every API key or every API path, then you're not allowed to be done. Yeah, absolutely. Um that's that's really cool, man. Uh codifying all of that is definitely got to be what's what's pushing this to the next level.
Well, I mean, obviously including, you know, your your in-depth understanding of of the Google APIs and all of that structure, but I think, you know, you you're using AI better than I've seen almost anybody use AI to this point, and I think this is a really key component of that. Um, awesome, man. All right. Well, let's let's uh let's go from there and let's go a little bit further down in the uh write up and then talk about some of the pwning Google um stories that you have from this result.
Um does that does that sound good or do you have any other comments to put in that whole uh infrastructure section? Okay, I think that sounds good. Yeah, we can we can cover a few of these. This is the most fun part. Like so you can completely port like there's so many different bugs here. It's it's so cool. And these are just a few of them by the I couldn't fit all of them in the write up because like I had to get Sam to like vet all of these right and see which one but these are the ones that finalized right but like the product team had to like give feedback for like each of them so but yeah that all ended up happening but yeah I wish I could have included more to be honest there's a lot of more cooler ones I I could have got like 15 you know atto's atto at this ridiculous dude okay all right hit us okay so the first one was a Google voice so this is super this is super funny.
This is literally like a you don't even need O for this endpoint like this G fiber voice PA you can just you just hit this endpoint with like an unobiscated guy id keep in mind these are like incremental basically you can like increment this and it dumps like the the Google account phone number the Google voice number like the email the pin like everything okay and it just dumps everything and it it didn't even end there so there was there was this endpoint in this where you can assign a number so I can add a phone number to your Google account and it would be like it literally if you're going to buy account Google / phone.
You'll see it there. Oh my god, that was pretty funny. That That is I can't believe this had no off. Oh my god. Yeah, it was You just needed a key. Like I guess nobody found the key, so that's why nobody found it. Do Do you know the top your head where this key came from? Like what strategy you used to get this key? Okay. Honestly, I have no tracking for that. I have legit no clue where the key came from. Probably one of the various sources I had.
I feel like that would be a really interesting piece though, dude, is to like know, okay, hey, 80% of my keys that I get vulnerabilities in come from like old APKs or something like that, right? Yeah. I tracked where I found all of mine, so I can like always ask it where it found it. Yeah. Yeah, that is. But I'm also not Brat, so Yeah. And I also only have like 700 keys or 800 keys versus like Yeah. Um, wow, dude. That is horrifying for one, and also very interesting scope.
I think the um I think you said in the write up that this was actually like some sort of provider uh API. Is that is that what happened? So, okay. I'm not too sure what this this this whole like API is honestly. It looks like some admin management API, but the more interesting part of this API is not only could you do all this Google account stuff. It seemed to be like some sort of like Google fiber stuff as well. So, if you look at the bottom right, there's like some sort of seemingly endpoint that you could do a SIM swap with.
Like I can just start a number port. I mean, I never I never got to testing this because I already reported it and I just didn't like go too much because I didn't want to like lose a bounty. But but yeah, I these are all these are all like super interesting end points. I wish I could have tested it. Dude, I'm I'm peeved right now because I'm I'm about to log into my um my freaking discovery tool that I use to track the I think I have this I think I have this key and this AP.
That is not what I wanted to see today. brood cat that is oh man that is so you miss this I don't know what I missed man because I actually you know what's interesting is I I have just personally I have Google and uh and I was like oh this is such an interesting you know uh attack surface because not very many people actually have Google as their phone provider right um so I found a bunch of bugs in Google Fi um and and worked on that scope a lot um and um Yeah.
Okay. All right. I'm gonna I'm gonna not I I I'm pretty sure I've seen this exact endpoint, which makes me very mad. Uh especially since there's no op, right? Like if it was if there was some crazy [ __ ] you were doing. Okay. Anyway, it's just a get URL. I can just do a get to this like just just a URL and you can see the phone number and everything. It's so stupid. And I think the maybe the reason you might have missed it is because it takes an unoffiscated guy ID.
So this is actually one trick I did is in my like I provided like a context of like all the different accounts has access to as well as like ids for each account. So like the unoffiscated ID the the like the focus office guy ID all these different like various things a project number project ID so it has like values to test if that makes sense. Yeah totally. Yeah that's def definitely necessary and I don't I don't have AI hooked up to mine so I just like I I had to manually test all of them.
Um so wow yeah this is a beautiful bug or you know I don't know when did you find this bug? Do you know when this was? Probably maybe like January this year of this year of 2026. Yeah. Damn it. Yeah. All of this is 2026. Oh, man. All of this is 26, man. Heck me, man. All right. Whatever. All right. What's the next one? This is Okay. So, okay. We can cover ad exchange or Okay. Another one is LDAR. Okay. That's kind of interesting.
So, LDAR is actually Okay. Elar. Corporate. Google.com. when you when you visit this is a corporate like domain but the for some reason the API wasn't like on the corp corp agency it was it was like exposed publicly so the API was public but the domain itself was all public so the front end I mean so this is kind of funny so essentially is this this thing I spoke to Eduardo do you know who Edward is yeah he works for Google yeah exactly so I was talking to him what about what LAR is exactly and it was quite interesting when you report like a bug right and they have to discuss with the product team in terms of like what is a bug and what's intended functionality This all goes through LDAR.
And not only that, it also has like Elder has like a bunch of like um if if say I'm doing okay, this is what I I'm pretty sure it works this way. If I'm doing some sort of like investigation, I want to get like access to certain accounts or like log files, I have to go through Elder. That's that's my understanding of this. So I mean if you're if you're a Googler so was pretty funny cuz like literally everything was exposed.
Like I can start reading every like assessment or like every everything like you can see like logs access requests and I even I even made like a little front end or something. You can you can see how the LDR like report looks like. Oh my god. I was able to get like some CSS elements. Oh. And the way I found out this I got this bug was cuz like my AI made an LDR report and it like shared it with my like email or some [ __ ] and I I I checked my email and I started seeing like all these emails from LDR like no reply at Google call like and had like G3 docs links everywhere and all these buganizer links.
So I already I already knew like I got some bug. Wow, dude. That's crazy. So, the AI submitted a report and then you got emails to your private Gmail account that was saying like, "Oh, linking to this Google 3 stuff." Oh my gosh. Yeah, I I did I will say I did have a similar thing the other day with my hackbot where I just I was hacking on something. I was writing a report actually and I look down at my phone and and I I see an email from this government target that I'm working on and it and it's like uh PC you know in the title and the subject line and I'm like oh okay and it just I mean it wasn't a crazy bug. just it had full like, you know, impersonation of this, you know, government entity or whatever.
But, uh, that's hilarious that it emailed you. Yeah, it from my account or whatever and like emailed me with it. Uh, which was pretty funny. So, yeah, dude. Wow. This is crazy. And, you know, this one I'm just looking at the off. It looks like you you used origin www.google.com and you were able to get in with first party off. Yeah. So, this one didn't have any like white or like the white list was a wild card for star or google.com.
So, you could just use anything star Google. Wow. Dang, that's crazy, dude. Look at this UI, dude. You're such a jerk. You made this UI. You're like, "Hey, I actually recreated Elder on the Oh my gosh. If you scroll through, you can see a bunch of like internal stuff." Oh my god. What is this? Yeah, I managed to get this approved through Google. How? I don't know how they Oh, you've got some stuff blocked out. That's Yeah.
Oh, yeah. I had to I had to bleep out the emails. That That was like the one thing I couldn't settle on. Wow, dude. That's Oh, dude, you've even got the like LLC thing at the bottom. That's hilarious, dude. I love I love it. Okay. And And this is the official LDL logo. Yeah. So, I have everything like I think Sam told me this looks pretty accurate to the real one. So, dude, if you don't let me ask you, how do you stay organized?
So, like even with my hack bot, like obviously it's hacking across a bunch of other companies and I feel like it it's still a lot of times kind of confusing to keep up with everything. And then when I'm doing these like full Google sweeps, like I basically, you know, attempted to do what you've done here um back before the live hacking event in Seoul. And I, you know, again, I had some success, but not nearly as much as you did.
But even just like thinking back on it, like I just cannot stay so organized. Like how do you manage all of this? I mean, look, when when I'm working on this one target, that's all I'm going to be working on. Like, that's all I'm thinking about. Like, whenever I do anything, I'm just like when I'm sleeping, I get dreams about this. Like, that's the level of like dedication I have for this. So, I'll just keep focusing on this.
So, everything is like in my head like whenever I find a gadget or I'll implement it like straight away or write code it like that moment. So, yeah. So, I that's why I'm just like focused on this one thing and do it as as well as possible because I think Google like pays the most, right? So, compared to other programs. So I just wanted to focus on this especially given my domain knowledge in this. Yeah. Yeah. You definitely I mean the domain knowledge you have is a massive advantage.
Um I before I got you know going back to the last bug the the fiber one I got a little you know freaked out there at the end but I do I do realize we we missed a little bit about the um the Z handlers there. So, oh yeah, are you are you catching Z handlers on Google API.com domains? Yeah. So, in fact, this one like I just noticed when they they patched it out cuz they they patched it like a P zero. They patched it super fast, but but they did some I don't know what they were doing cuz I saw some super sus like on proxy like error or something when I go to the main domain.
Then I was then I sent it to like Michael. I was showing him like look at this. And then like we ran like f like fff or like whatever. And we were able to find a bunch of parts. And then we checked and some of them worked. Like this is how a zander looks like. This is a slash ptcz handler. Wow. That's a dream. This is just like the type of I don't know why but this is like peak hacking for me. Like when I read this I'm like I'm going to find this on a Google API.
Yeah, dude. You you've got to experience this. So this is this is no off. Yeah. This is you could just use this. And in fact, right, if you're if you're smart, you would be scanning for this and all APIs and all domains. Yes, I'm doing that. They pop up randomly and they and you can get so much useful information from them, right? And that could be used for like later attacks as well. Wow. Wow, dude. Dang, that's crazy.
Okay, let's uh let's go to the ad exchange atto now. Okay, ad exchange. Okay, this was like some Okay, I'm not too sure what ad exchange is. I think it's just some like ad management platform, but this was kind of funny. So, first I was on the prod API, right? Okay, hold on. Pause pause. So, uh, ad exchange is extremely pivotal to Google's success as a company. Um, it just if you haven't, uh, heard of this this product, I I I would I would tell you go check out um, have you ever listened to the Acquired Pod podcast?
No. Dude, you you got to check this out. They they do a like a three-part series. They're like they do very very um indepth uh assessments of like very big successful companies. Um you should go listen to their three-part series on Google because uh it mentions this product a good bit and it's a good has a good bit to do with Google success if I recall correctly. Um so anyway I'm sorry continue. Yeah. Yeah. So this this okay I'm not too familiar with this product product but like as as you mentioned I'm pretty sure this is quite a important like critical product for them and it allows like like a publishers or whatever to like sell advertising space on their like website I guess.
So this so this was quite impactful but anyways at at the start right I found this like cookie matching accounts right it just started dumping like all the accounts but okay this by itself it was kind of interesting like it was it was showing like all the different like it was it was like literally one request and it was like a completely massive response and every single account that existed was on this right so I could see all the different like companies like the PTE or whatever like the private private limited all this kind of stuff but but I couldn't I couldn't actually do anything bored with this so I was kind of stuck here at first like so I have account IDs but what can I with that.
But turns out, right, for for whatever reason, they have Okay, this is actually kind of funny. So the staging environment of this like pointed to prod. So that there's like a test dash add exchange buyer API, right? Oh my. Yeah. So this endpoint had no access controls. You could freely do whatever you wanted and you can start referencing the prod identities and you can start seeing all the prod data. You're kidding. No way.
So I guess it just in the back end it had access to the prod database. Okay. So one thing in Google, right? This I don't think there's such a thing as staging. There's no such thing as staging. Like everything is production. So this this points to production. A lot of the times you might see some staging has like a different database. I mean that that could be it's possible, but for most of the time it just points to prod.
So this is actually a trick you can use to bypass it. So remember that LDR I was mentioning earlier. I actually bypassed the LDR initial fix by doing the same thing on auto push. Auto push is like another like staging environment and they they double the bounty. Wow. Because I could do it once again. Dang. Yeah, dude. There's got to be there's got to be so many things that I need to go back and test after this episode.
That's crazy. Oh, and yeah. So, I'm just reading through this. I mean, it's literally just first party off and then you just start. I mean, it's like stuff you would see on, you know, a 30,000, you know, crit max bounty, you know, program, like just these numeric IDs in the in the path and then you're just doing whatever the heck you want. Um, this is crazy, dude. Wow. All right. Um, man, I I'm just I'm kind of blown away like because there's so there's so Google is so s I felt like Google is such a difficult target, but when you put it together the pieces like this, you start to see it that yeah, there's there's a lot of things that you can access that you shouldn't be able to access if you master first party O and um you know, enumeration of all of the API keys.
Right. Very interesting. It's like an onion. If you peel away like the layers or whatever and then finally you reach the gold mine that's inside where nobody's touched the tech service. Yeah, dude. Frick. That's beautiful. And there's like 20 years of you 20 years plus of uh like data in there. It's crazy. All right. What is uh let's keep going. You want to do leaking YouTube videos or or what? Yeah. This is this is this kind of relates to like so the other thing I was mentioning.
So pretty much every every Google every YouTube channel that's a partner has like this whatever hidden CMS account a content manager. So content manager is like this tool. It's like a god mode for YouTube where you can strike any channel or like banning channels. So this is something for like big enterprises but but like YouTube partners have like a secret account that's like this the same thing but it's used for like content ID matching.
It's like some tool in YouTube. But yeah, the the interesting thing was that whenever a YouTuber uploaded a video, right, this was actually added as a content ID asset because that's how it does the content ID like copyright matching tool, right? So if it turns out, right, you like the the name of this asset is literally just like autogenerated asset dash to video ID. So if you search all assets for autogenerated asset dash like just dash and then you can you can start like leaking every single like unlisted video and stuff like that they thought was private.
Wait, wait. How? Wait, what do you mean search for this? You're not like Because there's a YouTube partner API. You can just search for all this. Wow. Okay. And And what? All you need to know is like this title or what? I think he's saying that the I think he's saying that these were originally like anyone who ever has ever found this API and tested it has just assumed probably that it was just like public assets because when you search it, it's like, oh yeah, these are just videos that exist on YouTube, right?
It's no big deal. But what he's saying is that all the private ones were still in there, but obviously people hadn't really noticed that. And the way you could find them is by searching for autogenerated asset dash. And then everything after that was like technically like the title of the private video. Wow. Is that accurate? The interesting thing about this Yeah. Did I say that right? Yeah. Yeah. Exactly. And you can use the filters, right?
So okay, it's theoretically possible like you I made a PC for this where I can have like a program that's running that's constantly getting new like video ids because I have like I can filter by time right so I keep keep fetching this like every few seconds and I keep like getting video ID so if I upload a video or any partner channel you you'll see pop up there so you can like capture like videos itself or you can look at historic you can scrape all the historic videos there's so so much stuff you can do here and and I think the impact for this is actually quite big because if you think about it right there's there's all this like poly market and these kind of predictions sites where like I could if let's say Google has like they upload like the Geminy model like video like they send as a premiere or something.
If you could just leak it through this you'll load the data it's going to be released and then you can sort of make a poly market bid on that. Oh my gosh, dude. Yeah, this is one and you got 12K for this. This is one of those bugs where if you were actually like a black hat, you could have just made so much more money off of it. Just like oh my gosh actually wait this this hitting me. Aren't some unlisted videos uh like capture the flags and like big CTFs?
Like wasn't that like the solution to Mr. Beast CTF? And not just that. Not just that, there even like PC's if I if I upload like a P or something for exploit like that's going to be here. Oh my gosh, dude. It was it was a massive leap. Yeah. Yeah. See, you know, and 12K for this. Were they considering this abuse? Because is this 10K plus one? But this is not abuse. Okay. Actually, you know, they they tried doing this as abuse first, but I got it out of abuse, but but it's still like a Yeah, I don't know.
They just gave it 12k. I'm not sure, but I think that the impact is much more in my opinion. Yeah, dude. Me too, man. Me, too. Um, okay. We've got time for maybe one more of these uh of your writeups and then I want to hit this cloud console, GraphQL stuff. Um, which one do you think we should go with? Okay, so PLX is very interesting. So, maybe we can check that. So PLX if you know if you know anything about Google right PLX is their like it's internal like dashboard thing.
So yeah if we know anything about Google then you know that right res. Yeah of course exactly I was I was like yeah of course PLX. Yeah of course. Yeah just hides Google bug hunter shirt underneath the hands. Okay tell us about plx which of course I know about already. Okay. It's it's this tables thing where you can you can create like a table and you can put like data inside. Right. So most any Googler you ask will know what PLX is because they use it every day.
So this is very interesting. Anyways, it like they this is so this is so stupid. They had this API like the data hub like the client 6 Google comp. So this this was like data hub is kind of this this API that's meant for like access controls for PLX, right? So one of the endpoints this was the very very beginning like you could you could just use like suggest and then you can start suggesting like tables and stuff. So this started like leaking a bunch of like tables and stuff but and you could see like like data is like need to know employee data or something but yeah that was kind of interesting but like this is just a table names I wanted to get more than this right so at first I was stuck here but then it turns out right the staging environment for this you could just set an AM policy and then add yourself as the admin of the table then you take over the whole table.
Oh my gosh look at this no way. And then he dumped it and he was and he was so stoked because his O center was like I just got all the information. Yeah. Right. Yeah. So if you if you scroll down you can see some of the the the tables and stuff like I gave a bunch of like internal information here but if you scroll down you can see like they're pentabytes in size like a lot of them. But the problem was you could holy this is like a lot but the issue here was you couldn't directly query the table stuff. you have the ACL endpoint like you can you have the access control but I have no way to query it right but so okay something funny I don't think I wrote it here but just like like a maybe a month later like I was I was working with strugg again and and basically found he found this like that same application integration had like this one query you could do like a run uh I forgot what it was called I think like some some sort of like query you could do like some sort of task you could do and it was like even after all the RC patches this still worked and you could like query this these tables itself with that.
So yeah, that that was pretty funny. I just want to read this real quick. This is one of the descriptions of one of the I guess functions in here. Generate a dump of the YPP corpus of lower tier channels for purposes of capitalized conqueror. What the heck? It's like, oh man, I want I want to use all of these things. I want to play with all these things. Goodness, this is crazy, dude. Wow. Um and 12K 12K for that. Wait, this one PLX has 12K too.
Yeah. Um, come on. Yeah. Yeah. I mean, it's it's whatever, I guess. Yeah. Wow. Um, dude, this is really this is really crazy research. And I think that it's really impressive how you pivot around staging and you you and and this other guy I think shrugged is his name from the first one that uh you know you guys do multi-step exploits like uh adding yourself as an IM user and then going back and you know hitting these uh tables right and I I think you know correct me if I'm wrong probably AI isn't putting together these chains for you it's giving it's giving you primitives and then you are putting it together yourself 100% like this is all non AI like AI just finds the initial like lead or something but the rest of the post exploitation is mostly just like doing it manually I don't I don't think the AI is like good enough to com combine like different like primitives together and think of stuff like that right now maybe in the future but but yeah this part of it is completely manual wow it definitely can on like stuff that is more regular but I think you're definitely right on programs like this where it's requiring so much like contextual knowledge that you have about Google that it just doesn't have.
Totally. Yeah, man. So, I definitely want to go and move over to this GraphQL stuff, but as soon as I clicked on this link, I see data batch execute. So, maybe maybe it'll all pull together, but I also really wanted to get your expertise on that because I see that everywhere and it's very opaque and I wish that there was some primitive that I could use to get more information out of these uh batch execute requests. Do you have anything that you care to share on that?
Okay, so the only thing is there's like this known method where in the JavaScript call, the RBC ID, you can kind of like find the real RBC, not the offiscated ID. But that's like the only real trick you have. Apart from that, like I'm not aware of any other trick. You have to just use the JavaScript files and maybe your AI can like figure out what's happening there for the JavaScript file and then sort of piece together that.
But yeah, I I built up this whole like catalog of all the RPC IDs I could and like brute force them on all the different domains and stuff like I have this tooling where I can sort of test that. But I haven't I haven't found like too many bugs from batch execute directly. But I'm sure there's bugs here because this is just security by obscurity. Like I feel like Google if you're listening maybe have some grant or something where you give us all the like the protool types and everything for all of these batch.
I have begged them for that because that would be I mean there's so many bugs there. I'm positive. Yeah. Yeah. Exactly. It's just it's just hidden away. Like I'm not sure that's what they really want. Like do you really want security about security? Yeah. Yeah. Wow. Okay. So tell me about this uh Google Cloud um console GraphQL stuff that you have here which apparently starts with Google Classroom in some way. Okay. No.
So, so essentially I was just explaining in this right where like Google Google cluster is a good example of like where you have a batch execute endpoint but the reality is behind the batch execute it's just a Google API right but you have to reach through this batch execute because it's not publicly the RPC is not publicly exposed so you have to go through this weird proxy and then you can hit the actual Google API behind the scenes so in this case this this like batch execute which is this RBC ID is actually this home room data services like whatever API right so and the classroom PI API But you can't really I don't think you can actually hit this directly.
So this is a way you can get more attack surface right through all these various proxies. But one of the most interesting proxies was this cloud console. So cloud console as you know it uses GraphQL. So if you browse around cloud console you'll see this like request for like cloud console PA or whatever. And it's all like GraphQL requests. It looks giant. It looks intimidating but the reality of it is it's it's actually quite funny.
So whenever you send a request it's just using Google APIs in the back end. And they screwed up big time. They the staging endpoint for this was like allowed you to like introspect everything because they didn't validate the signature on staging. Wow. So yeah, basically my my AI actually reported this as a lead. So it's saying like oh you can you can just introspect this and and I didn't realize it at first and then I looked at it more.
I was like wait a second like this opens up a whole new world of attack surface because like I wouldn't have been able to reach this from Google API directly. You know what I mean? Yeah totally. Wow. That must have been Yeah, dude. That's a game changer. Wow. So, a lot of this this part of this write up is just talking about like how we basically Okay, this was I was working with Michael Delton, right? Because he's he's really familiar with GraphQL.
So, he was he was handling most of the like porting the AI tool or whatever for scanning this bugs, sorry, this GraphQL stuff instead, right? So, we we use a lot of various uh tricks in this sort of because you see if you look at this whole like get resource building info like some of these like mapped to RPCs, right? It's it's kind of complicated because some of these are yeah some of these are mapped to RBC. It's hard to tell.
So we have to kind of assume that some of them are RPCs and and in fact they had comments as well. So that was very interesting. We had to package this all together and give it to the AI and we started testing like the whole thing. Oh yeah, another point I I want to raise is that you have to okay this is one thing you have to be a bit careful of because if you're testing GCP you need like a free trial account or you're not going to be able to reach most of the attack surface.
But if you give it access to like GraphQL or whatever, it can activate the free trial. So you have to be super careful here because if you sorry if you you can activate the full billing. So if you accidentally enable billing and it starts like costing a lot of money. You're you're going to you're going to get bleeded like dry or something. Yeah. I literally got charged 3K. I literally got charged 3K like two weeks ago and was was only and was only able to do a um a refund for like 2k of it.
I ended up eating the other $1,000. Um yeah. Yeah. And it's but because like and the the model was literally like, "Oh, I was able to enable 15 free seats on this service." It's like, "No, it's not free. They charge you after the fact. They you you know, you spin it up and then they charge you later." Oh my gosh. But also, it's so useful, right? Because like I was talking to another Google hacker. I know you know them, Brcat named Pedro.
And Pedro is like really smart and wrote like that fireblazer tool which I mean he's also just like Brcat willing to share so much with the community when really if he had just used it only himself, he would have made way more money probably. and um and he doesn't use any billing accounts for any of his testing. And so even though he's a super talented Google hacker who's like, you know, made a lot of money and like is not willing to use a billing account and I'm sure there's so many bugs behind that because there's probably lots of people like him, you know, or people who are just like hesitant or scared.
And so for me, I feel like I have to keep leaning into using things that are behind the billing account, but it's also like this huge risk at the same time. So totally. Okay. So the way I solve this problem actually is okay, I realized that I could create the free trial or whatever. So I could create a free trial on one GIA. Then I have a different Gaia which is the actual testing one the testing account that AI has access to.
And in that I so I temporarily give it give the project access the testing guya to the free trial account one. I link the free trial to that one. Then I like remove it from the account or whatever. So the it can never actually activate the free trial. Does that make sense? The the billing account is different from the project owner. Interesting. Okay. So, you're using Google's own privilege system there to prevent I and but guys, I bet we could also just go in there and put billing limits, couldn't we?
I don't think that's false. No, you you you set a billing limit, but it doesn't actually limit how much they charge you. It just it like they don't have anything for that. They just notify you. Yeah. Yeah. Exactly. It's it's it's [ __ ] Like they'll just tell you, "Oh, you just lost like $5,000." Yeah. No. And and Justin No, he's not wrong. And there's literally no way to like uh disable a lot of these services without reaching out to support and then you're waiting days.
That's exactly what happened to me as soon as I saw the charge. I immediately contacted support and I immediately told AI like, "Hey, go cancel this." And it like it destroyed all the services. It even disabled the APIs at the API level, but they kept charging me because like the only way to turn on and off like Vert.Ex for enterprise or something is like buy support. And so Brutecrat is exactly right. There you literally cannot get out of getting charged in those cases.
And I kept emailing them every day and was like, "Hey, I just received another $800 charge. Please go turn it off. I'm bleeding money." And then same thing there. You you apparently can close the billing account, but I have like real services for my real apps running on the same billing account. Yeah, we can't do that. We got to we got to create separate accounts for that. Oh my gosh. Exactly. Like never link them together.
And you have to have a different if you use a trick I mentioned where you have a different like two different gas one that owns the free trial and the other one that that doesn't have access to it but it's the project owner like this has worked so far but keep in mind it will also the AI will also it's like a it's like a monkey machine gun it's going to bleed out the whole like use the whole $300 in like 10 seconds like so you have to keep having new free trials so I have like I have like 10 free trials so far like all the different like using my mom's card my my dad's card every card I can get.
Hey, Mom. I'm gonna give your your credit card to my AI and Yeah, great. It It has a habit of spending too much money. Sorry about that. Yeah. Yeah. Exactly. Oh, you just got charged 10K. Yeah. My bad. My bad. Um Wow, man. That's awesome. So, you were able to also, you know, kind of hit some GraphQL stuff in combination with Google's RPC stuff um across the scope. So, I I I think that is for me. I mean, I think GraphQL stuff is a little bit more approachable than a lot of this like Google RPC protojson nonsense, but um yeah, that is that is impressive that you were able to bridge that gap.
Um yeah, I I think we've got about five more minutes left. There's like so much to cover in this uh you know, blog post. So really listeners, you have to go and read this, you know, blog post like it's gospel really. Um, so we'll we'll link the the blog post in the description or or just don't just just listen to the audio and go give Brutecat a follow and hires pin test, but don't apply any of these learnings to your hacking.
Maybe don't. Yeah, you know, that would be great. That's what I would recommend personally for my own benefit. Um, that's right. No. Um, did you have anything else that you wanted to add in here and shout out that you feel like the people really need to know from these last couple sections? Okay. Yeah, maybe one thing I can mention is the vertex assistance. So this is a 30k bounty, but it's very interesting. So the way this one worked is it's actually a feature that wasn't even rolled out yet.
So we were able to enable the experiment. Okay, so first the AI found it from the introspection and it found it. But we we couldn't even find the functionality of this like we were looking through the whole UI, it just didn't exist, right? But by by using like various tricks and like like we're changing the JavaScript or whatever like and using the console and setting a deb like debug point and a break point and stuff like that we were able to like set the flag to enable it and then we could see the UI.
So in this case I think they they paid for it because they spoke to the product team and they decided that like while normally they don't pay for such things in this case it was probably going to be released. So yeah but they may not they may not do this in the future. So, but I think that there's a lot of attack service in terms of like experimental features that you may want to look at. Yeah, 100%. Man, I've had a lot of success with this.
Actually, this is one of my top Google hacking tips is pay attention to the feature flags because Google's, you know, especially now with AI, the the release cycle is so rapid, they've got this stuff pushed to prod way before it it, you know, it gets released. um tons of tons of vulnerabilities and if not vulnerabilities, extra functionality that you could you you know you can be testing and chaining um behind those feature flags.
That's a great shout out. Maybe one last thing I can mention just quickly talk about the App Engine one because it's pretty funny. Like this this was so this was so interesting. So for whatever reason this you know that the App Engine dashboard if you go to just search app engine and like GCP and go to there it's probably one of the most like trafficked like GCP products. I I'm pretty sure it's used everywhere, but the the same dashboard loading endpoint was it just worked unauthenticated and you could just supply any project ID there.
It just stops all the like stats and stuff. You're joking. Yeah, the stats contained like the paths and stuff. So, if you had like a password reset link, it would just be shown here. So, those Oh my gosh, dude. Oh, okay. So, hey, also I noticed here you've got the key in the query parameter versus in the the request body. Um, have you noticed any variance between passing the key in via the X-API key header versus the key in the query parameter?
No, there's no difference. If you use XQ API keys, it's the exact same thing. Okay. Yeah. So, there's not really any difference. Just with J's preference, I guess. Wow, dude. That's crazy. No, but in this case, see, a lot of Google products, they just run on App Engine itself. Like the bug hunter site was vulnerable to this. Mhm. So, if you go to any bug hunter's URL and then I could I could just query this and see which URL you went to.
So, that was pretty funny. Oh my gosh, dude. That that is nuts. The logs for all of this. Wow. Um very very good uh writeups here on all of this. Thank you so much for sharing all of this, dude. This is uh very inspiring and also very informative. Uh the combination of of both of them. Um I'm definitely itching to go back to this API scope now. Um, so hopefully, you know, I don't know. I I'm a little bit on one hand I'm like itching.
On the other hand, I'm like, man, Brutecat is so far ahead on this, you know, it's like, uh, do I even give it a shot? But my my my experienced bug hunter within me says, absolutely. You know, there's everyone's put everything here. Yeah. All the all the different gadgets and everything I could think of, I put it all in this one post. So if you if you want to get started in Google server side hacking like you should you should just read this and and understand every single like primitive and all the gadgets and stuff and apply all of that and build out all the tooling we discussed here because you're going to you're definitely going to find bugs.
I have no doubt about it. I I did not get everything. There's no way, right? Like I definitely missed it all. Wow. Inspiring man. I'm I'm sure even based on all those leads and and findings that it's reported to you. I mean at 670K and bounties like you had to have overlooked or not found lots of stuff down a lot of those paths, right? Each lead it gives you is like a rabbit a rabbit trail that you went down and I'm sure you went like you probably haven't seen some of those trails and then some of them you went down and then stopped and got stuck and then other ones you turned into a ton of bounties, right?
Yeah. No, definitely like there's probably there's probably some stuff in there that I haven't even reviewed it because it just got like washed away or something and the new leads came up and I never got through it. But so I still think there's probably the probably still like bugs lying around especially the the thing I mentioned earlier where use a bear token cuz I I was using this whole research was all these bounties were mostly from the first party off but I do not even use like bear bear off that much but I think that you can probably use that and and especially if you get access some sort of like tenant account that's under like a google.com GCP project project that you can use that and it'll have access to like tons of more APIs like in fact I know some APIs that have a stubby rc I could see it, but I can't I can't hit it because it doesn't work at first party off.
So, it's super annoying. It just pisses me off everything time I think about. Yeah, man. Yeah, I totally feel that. That's how I feel about like all of the APIs that I have access to as well. And you've got all these additional off methods. Um, wow. That's that's very inspiring, dude. Dude, um, Joseph, let's give him a little round of applause here, man. This is this is Yeah, seriously. This is some of the best research I I think I've ever seen on critical thinking.
Um, so thank you so much for gracing us with uh the opportunity to disseminate this to the people and for coming on here and talking about it at length. Um, I'm going to give this as much distribution as I possibly can because uh, you know, you'd be goated forever if it was just the wreck to proto uh, you know, tip that you gave out, but this on top of that is just legendary, man. So, thank you. Yeah, this is literally going to be the Google hacking bible going forward.
For sure. 100%. Thank you so much, man. Yeah, sure. No worries. I I think that more bug hunters should try to share research like this because I'll be honest, right? Like I met so many people from that initial research I shared that I've been doing collabs with them that I would have never been able to find like so many bounties without them. So I think that sharing knowledge to everybody is actually a good thing in the community.
Yeah. Wow. I'm very inspiring. Thank you so much. Um that's the pod y'all. Go hack Google. Peace. And that's a wrap on this episode of Critical Thinking. Thanks so much for watching to the end, y'all. If you want more critical thinking content, uh, or if you want to support the show, head over to ctbb.show/isord. You can hop in the community. There's lots of great highlevel hacking discussion happening there on top of master classes, hackalongs, exclusive content, and a full-time hunters guild if you're a full-time hunter.
It's a great time. Trust me. All right, I'll see you there.
The words are the caption track's own and nothing is reworded or re-transcribed. Paragraph breaks are placed between sentences so the text reads as prose.
Free tools for your own script. No signup, no login.
Paste your draft and see where viewers are likely to drop off, with a rewrite for each weak line.
Paste the first 30 seconds of your own draft for a hook score and rewrites.
Check your draft against YouTube's advertiser-friendly guidelines before you record it.
Read this channel's public videos and transcripts, and download a writing brief for it.