HT TECH wants to start sending you push notifications. Click allow to subscribe

Indian hackers win $22000 Google bug bounty for uncovering major vulnerabilities

Two Indian hackers have won a cash prize of more than $22000 in bug bounty after they found major flaws in Google Cloud Program (GCP) projects.

By: HT TECH
Updated on: Jan 20 2023, 21:48 IST
Google bug bounty worth $22000 won by Indian hacker duo. (AFP)
Google bug bounty worth $22000 won by Indian hacker duo. (AFP)

Two Indian hackers have won a total cash reward of more than $22000 as bug bounty from Google. Bug bounties are rewards, usually cash prizes, given by major tech companies to individuals who identify an error or vulnerability in their computer program or system. These particular bug bounties were awarded by Google to the Indian hacker duo for finding major security vulnerabilities in its Google Cloud Program (GCP) projects. Among them, the biggest bounty was a server-side request forgery (SSRF) bug and subsequent patch bypass which earned them a cool $5000.

The two Indians who won the bounties are Sreeram KL and Sivanesh Ashok who are both part of Google Vulnerability Rewards Program (VRP). Sivanesh also posted a blog detailing the bugs and how they came across them. Posting about it on Twitter, he said, “A write-up about how

You may be interested in

Mobiles Tablets Laptops
23% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹115,999₹149,999
Buy now
24% OFF
Google Pixel 128GB
  • Black
  • 4 GB RAM
  • 128 GB Storage
₹64,990₹84,999
Buy now
36% OFF
Google Pixel 2 128GB
  • Kinda Blue
  • 4 GB RAM
  • 128 GB Storage
₹63,990₹99,999
Buy now
Samsung Galaxy S23 5G
  • Green
  • 8 GB RAM
  • 128 GB Storage
₹57,999
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
39% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,490₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,790₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

@kl_sree and I found a bug in Google Cloud that allowed us to takeover a victim's compute engine VM”.

Also read: Looking for a smartphone? To check mobile finder click here.

Indian hacker duo find vulnerabilities in Google

The SSRF bug is especially a dangerous vulnerability to have. By abusing this vulnerability, hackers could trick victims into opening malicious links and take control of their GCP projects remotely.

Sivanesh pointed out in his blog, “Since there was no random token or CSRF protection, anyone could craft a link and send it to a Compute Engine user to create a new user in their instance…making a victim open a malicious link would add the attacker's username and SSH key into their computer”.

However, people do not need to worry about it as after the security risk was flagged, Google has released a patch that takes care of the issue. Alongside, the two Indians also uncovered a bunch of more vulnerabilities.

Speaking with Daily Swig, Sreeram said, “While finding this issue, we gained insight into the workings of managed GCP products, which helped us find other bugs in GCP”.

What is Google VRP

Google Vulnerability Reward Program (VRP) is a formal process to reward the contributions from external security researchers towards finding out security risks and providing patches for them. As long as a security researcher follows the guidelines of Google, anyone can participate and flag a vulnerability and get a reward from Google.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 20 Jan, 21:47 IST

Sale

Mobiles Tablets Laptops
5% OFF
Google Pixel 7A
  • Charcoal
  • 8 GB RAM
  • 128 GB Storage
₹41,990₹43,999
Buy now
44% OFF
Samsung Galaxy S23 FE
  • Mint
  • 8 GB RAM
  • 128 GB Storage
₹44,999₹79,999
Buy now
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
33% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,999₹39,999
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
24% OFF
Samsung Galaxy Tab A7 Lite
  • Silver
  • 3 GB RAM
  • 32 GB Storage
₹9,710₹12,700
Buy now
18% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹93,648₹113,798
Buy now
23% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹22,990₹29,990
Buy now
28% OFF
Asus ROG Zephyrus G14 GA402NU N2023WS Laptop
  • Eclipse Gray
  • 16 GB RAM
  • 1 TB SSD
₹144,990₹201,990
Buy now
29% OFF
Asus VivoBook Pro 15 OLED M6500IH L1701WS Laptop
  • Quiet Blue
  • 16 GB RAM
  • 512 GB SSD
₹58,990₹82,990
Buy now
22% OFF
Asus ROG Strix G15 G512LV AZ225T Laptop
  • Glacier Blue
  • 16 GB RAM
  • 1 TB SSD
₹70,990₹90,990
Buy now
NEXT ARTICLE BEGINS