news.volyx.in

The unexpected Google wide domain check bypass (bugs.xdavidhu.me)

644 points by notRobot · 2404 days ago · 114 comments on HN

Article summary

A security researcher discovered a bug in Google's URL parsing library, which allowed them to bypass domain validation and potentially steal API keys or OAuth Client IDs. The bug was caused by a flawed assumption in a regular expression used for domain validation. The researcher found that the bug was not only present in the initial application they were testing, but also in many other Google products. The bug was reported to Google and fixed, with the researcher receiving a $6,000 bounty.

Main themes

  • URL parsing vulnerabilities
  • bug bounty programs
  • security research
  • regular expression flaws
  • domain validation
  • API key security

What commenters say

  • The bug bounty payout of $6,000 was considered low by some, given the potential impact of the vulnerability.
  • Others argued that the payout was reasonable, given the type of bug and the fact that it was not a critical vulnerability like a drive-by RCE.
  • Some commenters noted that the bug highlights the importance of careful string parsing and validation in security-critical code.
  • There was disagreement about whether the bug was primarily a client-side or server-side issue, with some arguing that the distinction is not always clear-cut.
  • Some commenters suggested that the vulnerability could be used by attackers to gain access to sensitive information or systems, potentially including Google's internal networks.
  • Others pointed out that the vulnerability may not be unique to Google and that other companies may also be affected by similar bugs in their URL parsing libraries.