Web Hack List

Other nomination

Unauthorized Google Maps API Key Usage Cases

Explains what an unrestricted Google Maps API key left in client-side code allows: anyone can bill the owner's quota through the Maps endpoints, or exhaust a capped budget to deny the service, and careless referrer wildcards can be side-stepped with lookalike domains. Includes a scanner that tests every Maps endpoint for a supplied key.

Record

Researcher
Ozgur Alp and @ozgur_bbh
Published by
Medium
Date

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ozgur Alp and @ozgur_bbh, first published at the original source. Preserved copies are kept so the citation survives its host.