Web Hack List

Later archive addition

Into the Borg: SSRF inside Google production network

A Google Caja server-side script fetcher accepted Google-hosted URLs but executed inside Google's production network. Hosting a script on App Engine exposed the internal source address, after which direct private-IP requests returned internal content, producing an SSRF into the Borg environment.

Record

Published by
OpnSec
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of OpnSec, first published at the original source. Preserved copies are kept so the citation survives its host.