news.volyx.in

How to contact Google SRE by dropping a shell in Cloud SQL (offensi.com)

639 points by fanf2 · 2233 days ago · 98 comments on HN

Article summary

The article describes a vulnerability in Google Cloud SQL that allowed researchers to gain access to the underlying host machine. The vulnerability was exploited by using SQL injection and argument injection to execute a malicious plugin, which spawned a reverse shell. The researchers were then able to escape the container and gain access to the host machine by spoofing a response from the metadata server. The vulnerability has since been patched by Google.

Main themes

  • Cloud Security
  • Vulnerability Exploitation
  • Google Cloud SQL
  • Support Models
  • Cloud Infrastructure
  • Security Measures
  • Cloud Provider Accountability

What commenters say

  • Some commenters believe that the vulnerability was due to basic mistakes, such as SQL and command injection, and that Google should have caught it earlier.
  • Others argue that the vulnerability was not a surprise, given the complexity of the system and the potential for human error.
  • There is a disagreement about whether Google Cloud's support model is adequate, with some arguing that it is reasonable to expect support only with a paid subscription, while others believe that it is unreasonable to require an additional fee for support.
  • Some commenters note that the vulnerability highlights the importance of proper security measures, such as using secure protocols like TLS, and that the lack of such measures in this case made the exploit possible.
  • The discussion also touches on the topic of cloud infrastructure and the potential risks and benefits of using cloud services, including the trade-offs between security, convenience, and cost.
  • Some commenters express concern about the potential for similar vulnerabilities to exist in other cloud services, and the need for greater transparency and accountability from cloud providers.
  • Others argue that the vulnerability was an isolated incident and that Google's response to it was adequate, given the circumstances.