Web Hack List

Other nomination

$36k Google App Engine RCE - Ezequiel Pereira

From inside a Google App Engine app the author reached the runtime's internal RPC endpoint and an undocumented gRPC service, then recovered hidden API names from the Java launcher's arguments and leaked proto files. In non-production environments this allowed calling stubby.Send to reach arbitrary internal Google services and app_config_service to grant his own app privileged settings.

Record

Researcher
Ezequiel Pereira
Published by
Blogger
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ezequiel Pereira, first published at the original source. Preserved copies are kept so the citation survives its host.