Collected research
$36k Google App Engine RCE - Ezequiel Pereira
$36k Google App Engine RCE
From inside a Google App Engine app the author reached the runtime's internal RPC endpoint and an undocumented gRPC service, then recovered hidden API names from the Java launcher's arguments and leaked proto files. In non-production environments this allowed calling stubby.Send to reach arbitrary internal Google services and app_config_service to grant his own app privileged settings.
Record
- Document
- $36k Google App Engine RCE
- Researcher
- Ezequiel Pereira
- Published by
- Blogger
- Date
- Topic
- Server
In the archive
Related sources
Tags
This page is the archive's own catalogue record. The research is the work of Ezequiel Pereira, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .