flâneur — a map of the web's best reading

How We Impersonated Cloud Code by Google Cloud and Took Over GCP Accounts - Upwind | Cloud Security Happens at Runtime

upwind.io · 1,962 words · saved by 1 readers

The Upwind security research team is constantly examining threat landscapes and potential attack paths. In one of our recent searches, we discovered an anomaly in the authentication behavior of Google Developer tools that security practitioners should be aware of. We discovered this threat landscape by running scans on GCP Cloud Code, during which we found exposed OAuth client IDs and secrets, along with the source code for a VS Code extension included as a CSV file. To check this further, we crafted and tested a malicious VS Code extension, which allowed us to successfully extract user tokens and transfer them to remote buckets. Once we discovered that this threat landscape existed, we quickly compiled an advisory and submitted it to Google. However, much to our surprise, our submission did not meet their bug bounty policy criteria, and we received a response from Google explaining that this functionality was intentionally designed. Google’s response was as follows: “Client-side devel

How We Impersonated Cloud Code by Google Cloud and Took Over GCP Accounts - Upwind Skip to main content Skip to footer Home > Feed > How We Impersonated Cloud Code by Google Cloud and Took Over GCP Accounts Research How We Impersonated Cloud Code by Google Cloud and Took Over GCP Accounts Warning : Undefined variable $photo in /nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval()'d code on line 24 Warning : Trying to access array offset on value of type null in /nas/content/live/landing173/wp-content/themes/bricks/includes/elements/code.php(236) : eval(

Explore this link on the map →

related reading