Web Hack List

Collected research

Unauthorized Google Maps API Key Usage Cases

Unauthorized Google Maps API Key Usage Cases, and Why You Need to Care

Explains what an unrestricted Google Maps API key left in client-side code allows: anyone can bill the owner's quota through the Maps endpoints, or exhaust a capped budget to deny the service, and careless referrer wildcards can be side-stepped with lookalike domains. Includes a scanner that tests every Maps endpoint for a supplied key.

Record

Document
Unauthorized Google Maps API Key Usage Cases, and Why You Need to Care
Researcher
Ozgur Alp and @ozgur_bbh
Published by
Medium
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Ozgur Alp and @ozgur_bbh, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .