Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Google now pays $250,000 for KVM zero-day vulnerabilities

n1njaxn1njax Member
edited July 2024 in General

Google has announced a new bug bounty program, named kvmCTF, to help find vulnerabilities in the Kernel-based Virtual Machine or KVM hypervisor.

https://www.securityweek.com/google-offering-250000-for-full-vm-escape-in-new-kvm-bug-bounty-program/.

Thanked by 1emgh

Comments

  • Nice. I don't have much good to say about Google but that's the sort of bounty that should hoover up 0days before they end up on the open market

  • ehabehab Member
    edited July 2024

    @FlorinMarian now is your chance to get that villa up the road you always dreamed of.

  • ChuckChuck Member

    @ehab said:
    @FlorinMarian now is your chance to get that villa up the road you always dreamed of.

    today $250,000 would get you some bricks and paint.

  • VoidVoid Member

    Tagging @vitobotta, our in-house bug hunter.

    Thanked by 3ehab sh97 vitobotta
  • BruhGamer12BruhGamer12 Member
    edited July 2024

    @CloudHopper said:
    Nice. I don't have much good to say about Google but that's the sort of bounty that should hoover up 0days before they end up on the open market

    Is it? I know full zero click takeovers of IOS or Graphene OS can pay 2-3M with stock android not being too far behind. I'm not saying anything bad about google for this as what they are doing is still helpful no doubt but do black markets pay more for a full VM escape ? Seems like a pretty powerful exploit if combined with 1-2 other exploits.

    Thanked by 2tentor emgh
  • emghemgh Member, Megathread Squad
    edited July 2024

    @BruhGamer12 said:

    @CloudHopper said:
    Nice. I don't have much good to say about Google but that's the sort of bounty that should hoover up 0days before they end up on the open market

    Is it? I know full zero click takeovers of IOS or Graphene OS can pay 2-3M with stock android not being too far behind. I'm not saying anything bad about google for this as what they are doing is still helpful no doubt but do black markets pay more for a full VM escape ? Seems like a pretty powerful exploit if combined with 1-2 other exploits.

    Yes.

    It’s a good thing, but the sum is a piss in the ocean for them. It’s like 1/3rd of a house in a bigger city in Sweden.

    Considering it’s a technology they use, a bump couldn’t hurt.

  • coldcold Member
    edited July 2024

    @ehab said:
    @FlorinMarian now is your chance to get that villa up the road you always dreamed of.

    mean ! @ehab u sexy hater !
    250K are barely enuff for the new CEO car he needs

    Thanked by 2Chuck ehab
  • ehabehab Member

    if only @Not_Oles turns on Evil mode for some time he will screw CTF twice.

    Thanked by 1yoursunny
  • @vitobotta it's your time to shine

  • JoshRJoshR Member, Patron Provider

    Google has always had a bug bounty program and from what I've heard this is on a lower end.

  • VoidVoid Member

    @BruhGamer12 said:

    Graphene OS can pay 2-3M

    Damn, Micay is that rich I see.

  • @Void said:
    Tagging @vitobotta, our in-house bug hunter.

    @COLBYLICIOUS said:
    @vitobotta it's your time to shine

    Nice, given the prize I definitely need to explore this :D I have more experience with web apps but this looks like an interesting area. I have worked with KVM and other stuff when I used to work for OnApp years ago but not recently. Time to rediscover it :D

    Thanked by 1Void
  • emghemgh Member, Megathread Squad

    @vitobotta said:

    @Void said:
    Tagging @vitobotta, our in-house bug hunter.

    @COLBYLICIOUS said:
    @vitobotta it's your time to shine

    Nice, given the prize I definitely need to explore this :D I have more experience with web apps but this looks like an interesting area. I have worked with KVM and other stuff when I used to work for OnApp years ago but not recently. Time to rediscover it :D

    If you get the money, can I get an idler?

  • Not going to be easy money i fear. Unless there's some kind of blatant design error most bugs allowing to break out of the VM will likely be side channel stuff and researching this isn't for faint.

  • rattlecattlerattlecattle Member
    edited July 2024

    Completely different from pentesting web apps for clients which are more or less closed source. KVM being open source will be an order of magnitude tougher to discover a exploit. But probably bugs these days are initially found by fuzzers like AFL and not through manual source code review. Like for example fuzz the guest-host communication channel like virtio-vsock with AFL by building a suitable harness around the to be tested code. A crash found by AFL may not necessarily be vulnerable and that is where manual analysis of the crashes begins.

    Thanked by 1totally_not_banned
  • @rattlecattle said:
    Completely different from pentesting web apps for clients which are more or less closed source. KVM being open source will be an order of magnitude tougher to discover a exploit. But probably bugs these days are initially found by fuzzers like AFL and not through manual source code review. Like for example fuzz the guest-host communication channel like virtio-vsock with AFL by building a suitable harness around the to be tested code. A crash found by AFL may not necessarily be vulnerable and that is where manual analysis of the crashes begins.

    Good point. Forgot about virtio and friends. Getting those to crash might obviously also pave the path to freedom. Still certainly no easy money there.

    Thanked by 1rattlecattle
  • vitobottavitobotta Member
    edited July 2024

    Definitely. This stuff is A LOT more complex than regular web apps.

    @emgh said:

    @vitobotta said:

    @Void said:
    Tagging @vitobotta, our in-house bug hunter.

    @COLBYLICIOUS said:
    @vitobotta it's your time to shine

    Nice, given the prize I definitely need to explore this :D I have more experience with web apps but this looks like an interesting area. I have worked with KVM and other stuff when I used to work for OnApp years ago but not recently. Time to rediscover it :D

    If you get the money, can I get an idler?

    If I manage to get that sort of prize I will give you 100 idlers :D

    Thanked by 1emgh
  • MoopahMoopah Member

    @vitobotta said:
    Definitely. This stuff is A LOT more complex than regular web apps.

    @emgh said:

    @vitobotta said:

    @Void said:
    Tagging @vitobotta, our in-house bug hunter.

    @COLBYLICIOUS said:
    @vitobotta it's your time to shine

    Nice, given the prize I definitely need to explore this :D I have more experience with web apps but this looks like an interesting area. I have worked with KVM and other stuff when I used to work for OnApp years ago but not recently. Time to rediscover it :D

    If you get the money, can I get an idler?

    If I manage to get that sort of prize I will give you 100 idlers :D

    LET Giveaway sponsored by @vitobotta

    Thanked by 1emgh
  • BTW, speaking of bug bounties, yesterday I pocketed another $7K for 3 hours work :D (I haven't received the payment yet but it's confirmed)

    There is some sanitization against XSS in this app but I found I could bypass it and potentially execute javascript with an object tag.

    The "problem" is that this app restricts CSP to script tags to "self" so I cannot use inline scripts and I cannot load a js file from a domain I control even though with the aforementioned object tag I can render a script tag bypassing the sanitization.

    Did I stop there? Of course not 🤪

    The CSP also allows youtube as origin for embedding of videos.

    Here's a trick I used and that you may not be aware of. So I give you a free bug bounty hunting tip :D

    YouTube allows requests with URLs in the format

    https://www.youtube.com/oembed?url=http://www.youtube.com/watch?v=dQw4w9WgXcQ&format=json&callback=alert(1)
    

    Note the callback parameter. This request returns a JSONP response that allows me to execute code, like in the example a simple alert. So I used that URL in my PoC and got code execution (XSS) even though I can't load scripts from my domains and I cannot use inline script tags or tags with attributes with event handlers.

    Thanks YouTube! 🤣

    Thanked by 4emgh Void Kevinf100 ehab
  • emghemgh Member, Megathread Squad
    edited July 2024

    @vitobotta said:
    Definitely. This stuff is A LOT more complex than regular web apps.

    @emgh said:

    @vitobotta said:

    @Void said:
    Tagging @vitobotta, our in-house bug hunter.

    @COLBYLICIOUS said:
    @vitobotta it's your time to shine

    Nice, given the prize I definitely need to explore this :D I have more experience with web apps but this looks like an interesting area. I have worked with KVM and other stuff when I used to work for OnApp years ago but not recently. Time to rediscover it :D

    If you get the money, can I get an idler?

    If I manage to get that sort of prize I will give you 100 idlers :D

    Thanks! <3

    And good luck

  • VoidVoid Member

    @vitobotta said:

    If I manage to get that sort of prize I will give you 100 idlers :D

    Can I get one too since I tagged you first ? 😁

  • VoidVoid Member

    @vitobotta said:
    BTW, speaking of bug bounties, yesterday I pocketed another $7K for 3 hours work :D (I haven't received the payment yet but it's confirmed)

    There is some sanitization against XSS in this app but I found I could bypass it and potentially execute javascript with an object tag.

    The "problem" is that this app restricts CSP to script tags to "self" so I cannot use inline scripts and I cannot load a js file from a domain I control even though with the aforementioned object tag I can render a script tag bypassing the sanitization.

    Did I stop there? Of course not 🤪

    The CSP also allows youtube as origin for embedding of videos.

    Here's a trick I used and that you may not be aware of. So I give you a free bug bounty hunting tip :D

    YouTube allows requests with URLs in the format

    https://www.youtube.com/oembed?url=http://www.youtube.com/watch?v=dQw4w9WgXcQ&format=json&callback=alert(1)
    

    Note the callback parameter. This request returns a JSONP response that allows me to execute code, like in the example a simple alert. So I used that URL in my PoC and got code execution (XSS) even though I can't load scripts from my domains and I cannot use inline script tags or tags with attributes with event handlers.

    Thanks YouTube! 🤣

    MOOOAAR Tips

  • @Void said:

    @vitobotta said:

    If I manage to get that sort of prize I will give you 100 idlers :D

    Can I get one too since I tagged you first ? 😁

    I'll buy an idler for everyone if I get 250K with a bounty 🤣

    @Void said:

    @vitobotta said:
    BTW, speaking of bug bounties, yesterday I pocketed another $7K for 3 hours work :D (I haven't received the payment yet but it's confirmed)

    There is some sanitization against XSS in this app but I found I could bypass it and potentially execute javascript with an object tag.

    The "problem" is that this app restricts CSP to script tags to "self" so I cannot use inline scripts and I cannot load a js file from a domain I control even though with the aforementioned object tag I can render a script tag bypassing the sanitization.

    Did I stop there? Of course not 🤪

    The CSP also allows youtube as origin for embedding of videos.

    Here's a trick I used and that you may not be aware of. So I give you a free bug bounty hunting tip :D

    YouTube allows requests with URLs in the format

    https://www.youtube.com/oembed?url=http://www.youtube.com/watch?v=dQw4w9WgXcQ&format=json&callback=alert(1)
    

    Note the callback parameter. This request returns a JSONP response that allows me to execute code, like in the example a simple alert. So I used that URL in my PoC and got code execution (XSS) even though I can't load scripts from my domains and I cannot use inline script tags or tags with attributes with event handlers.

    Thanks YouTube! 🤣

    MOOOAAR Tips

    If people are interested I can start a thread and update it every now and then with some tips and case I come across.

  • @vitobotta said:

    @Void said:

    @vitobotta said:

    If I manage to get that sort of prize I will give you 100 idlers :D

    Can I get one too since I tagged you first ? 😁

    I'll buy an idler for everyone if I get 250K with a bounty 🤣

    Are the idlers powered by KVM? :P

  • @TheOnlyDK said:

    @vitobotta said:

    @Void said:

    @vitobotta said:

    If I manage to get that sort of prize I will give you 100 idlers :D

    Can I get one too since I tagged you first ? 😁

    I'll buy an idler for everyone if I get 250K with a bounty 🤣

    Are the idlers powered by KVM? :P

    Obviously

    Thanked by 1TheOnlyDK
  • Just saying, if I was a nation-state looking to looking to break into, say, a hosting provider for a military contractor, I would pay a lot more the 250k.

  • VoidVoid Member

    @vitobotta said:

    @Void said:

    @vitobotta said:

    If I manage to get that sort of prize I will give you 100 idlers :D

    Can I get one too since I tagged you first ? 😁

    I'll buy an idler for everyone if I get 250K with a bounty 🤣

    @Void said:

    @vitobotta said:
    BTW, speaking of bug bounties, yesterday I pocketed another $7K for 3 hours work :D (I haven't received the payment yet but it's confirmed)

    There is some sanitization against XSS in this app but I found I could bypass it and potentially execute javascript with an object tag.

    The "problem" is that this app restricts CSP to script tags to "self" so I cannot use inline scripts and I cannot load a js file from a domain I control even though with the aforementioned object tag I can render a script tag bypassing the sanitization.

    Did I stop there? Of course not 🤪

    The CSP also allows youtube as origin for embedding of videos.

    Here's a trick I used and that you may not be aware of. So I give you a free bug bounty hunting tip :D

    YouTube allows requests with URLs in the format

    https://www.youtube.com/oembed?url=http://www.youtube.com/watch?v=dQw4w9WgXcQ&format=json&callback=alert(1)
    

    Note the callback parameter. This request returns a JSONP response that allows me to execute code, like in the example a simple alert. So I used that URL in my PoC and got code execution (XSS) even though I can't load scripts from my domains and I cannot use inline script tags or tags with attributes with event handlers.

    Thanks YouTube! 🤣

    MOOOAAR Tips

    If people are interested I can start a thread and update it every now and then with some tips and case I come across.

    I’m definitely interested

  • @Void said:

    @vitobotta said:

    @Void said:

    @vitobotta said:

    If I manage to get that sort of prize I will give you 100 idlers :D

    Can I get one too since I tagged you first ? 😁

    I'll buy an idler for everyone if I get 250K with a bounty 🤣

    @Void said:

    @vitobotta said:
    BTW, speaking of bug bounties, yesterday I pocketed another $7K for 3 hours work :D (I haven't received the payment yet but it's confirmed)

    There is some sanitization against XSS in this app but I found I could bypass it and potentially execute javascript with an object tag.

    The "problem" is that this app restricts CSP to script tags to "self" so I cannot use inline scripts and I cannot load a js file from a domain I control even though with the aforementioned object tag I can render a script tag bypassing the sanitization.

    Did I stop there? Of course not 🤪

    The CSP also allows youtube as origin for embedding of videos.

    Here's a trick I used and that you may not be aware of. So I give you a free bug bounty hunting tip :D

    YouTube allows requests with URLs in the format

    https://www.youtube.com/oembed?url=http://www.youtube.com/watch?v=dQw4w9WgXcQ&format=json&callback=alert(1)
    

    Note the callback parameter. This request returns a JSONP response that allows me to execute code, like in the example a simple alert. So I used that URL in my PoC and got code execution (XSS) even though I can't load scripts from my domains and I cannot use inline script tags or tags with attributes with event handlers.

    Thanks YouTube! 🤣

    MOOOAAR Tips

    If people are interested I can start a thread and update it every now and then with some tips and case I come across.

    I’m definitely interested

    I can see if I remember.

Sign In or Register to comment.