Other nomination
Unauthorized Google Maps API Key Usage Cases
Explains what an unrestricted Google Maps API key left in client-side code allows: anyone can bill the owner's quota through the Maps endpoints, or exhaust a capped budget to deny the service, and careless referrer wildcards can be side-stepped with lookalike domains. Includes a scanner that tests every Maps endpoint for a supplied key.
Record
- Researcher
- Ozgur Alp and @ozgur_bbh
- Published by
- Medium
- Date
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Ozgur Alp and @ozgur_bbh, first published at the original source. Preserved copies are kept so the citation survives its host.