India

Google Rewards 2 Indian Hackers; Know Why

New York: New York: Google has rewarded two Indian hackers for reporting vulnerabilities in four Google Cloud Platform (GCP) projects.

Google gave Sreeram KL and Sivanesh Ashok $22,000 (around Rs 18 lakh) as bug bounty, which is given by tech giants to individuals who detect an error or vulnerability in their computer programme or system.

The hacker duo’s biggest bounty was machine learning training and deployment platform Vertex AI, which earned them a pair of $5,000 payouts for a server-side request forgery (SSRF) bug and patch bypass, The Daily Swig reported.

Sivanesh explained the bug and how they came across vulnerabilities in GCP in his personal blog ‘Geeky Cat’.

“A write-up about how Sreeram KL and I found a bug in Google Cloud that allowed us to take over a victim’s compute engine VM,” Sivanesh wrote on Twitter.

“The flaw resided in Vertex AI’s workbench feature, which enables the creation of Jupyter notebook-based development environments on the cloud,” Sreeram said in his blog.

What Is SSRF Bug?

SSRF is a web security vulnerability which allows an attacker to induce the server-side application make requests to an unintended location.

The attacker may cause the server to make a connection to internal-only services within the organisation’s infrastructure. The attacker may also be able to force the server to connect to arbitrary external systems, potentially leaking sensitive data such as authorization credentials.

OB Bureau
Share
Published by
OB Bureau

Recent Posts

Free Love Predictions, Unique Date Ideas: How To Make This Valentine’s Day Memorable

Bhubaneswar: As Valentine’s Day approaches, many apps are rolling out special offers. For instance, Astrotalk is… Read More

2 minutes ago

Hollywood Actor Anthony Mackie Wants Shah Rukh Khan To Be The Next Avenger

New Delhi: Bollywood Badshah Shah Rukh Khan has fans across the globe and one among… Read More

2 minutes ago

Odisha Focusses On Building Greenfield Paradip Airport, Puri SJIA

Bhubaneswar: In a significant move to strengthen aviation infrastructure in the state and align with… Read More

12 minutes ago

3-Tier Security Net For Budget Session Of Odisha Assembly Beginning Tomorrow

Bhubaneswar: With the budget session of Odisha Assembly slated to begin on Thursday, Director General… Read More

34 minutes ago

Elvish Yadav In Trouble Over His Racial Comments On ‘Bigg Boss 18’ Contestant Chum Darang

Itanagar: Social media influencer Elvish Yadav was in the line of fire for his racial… Read More

35 minutes ago

CBI Arrests Senior Statistical Officer For Accepting Bribe

Mumbai: The Central Bureau of Investigation (CBI) arrested a senior officer of the National Statistical… Read More

45 minutes ago