Web Hack List

Collected research

$36k Google App Engine RCE - Ezequiel Pereira

$36k Google App Engine RCE

From inside a Google App Engine app the author reached the runtime's internal RPC endpoint and an undocumented gRPC service, then recovered hidden API names from the Java launcher's arguments and leaked proto files. In non-production environments this allowed calling stubby.Send to reach arbitrary internal Google services and app_config_service to grant his own app privileged settings.

Record

Document
$36k Google App Engine RCE
Researcher
Ezequiel Pereira
Published by
Blogger
Date
Topic
Server

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ezequiel Pereira, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .