Collected research
Google Maps XSS (by fiddling with Protobuf)
How I found a $5,000 Google Maps XSS (by fiddling with Protobuf)
Google Maps encodes its URL and AJAX parameters in an undocumented text form of Protobuf. Reverse-engineering it with a Chrome debugger script and a Qt request editor exposed a tile format served as Content-Type text/html with encryption and compression switchable off, so attacker-chosen marker text executed as script on www.google.com; base64 field encoding evaded browser XSS filters.
Record
- Document
- How I found a $5,000 Google Maps XSS (by fiddling with Protobuf)
- Researcher
- Marin Moulinier
- Published by
- Medium
- Date
- Topic
- XSS
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Marin Moulinier, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .