Google invites google.com hack

By
Follow google news

Up to US$3,337 reward.

Google's security team have invited researchers to try their hand at demonstrating an attack on almost any of its web properties, including google.com, youtube.com, blogger.com and orkut.com

Google invites google.com hack

"Any Google web properties which display or manage highly sensitive authenticated user data or accounts may be in scope," its security team explained

The program extends a previous campaign that rewarded researchers for discovering security flaws in its Chrome browser. 

Like that vulnerability program, Google is offering payment to researchers who find a bug, however it almost doubled the upper limit for finding "unusually clever" bugs. 

The base offer, as for Chrome, is US$500 while the new top reward is US$3,133, two thousand more than under Chrome. 

Bugs in scope include cross-site scripting flaws, bypassing its authorisation controls and "server side ... command injection".

Not surprisingly, Google's said its own corporate infrastructure was "definitively excluded".

Other attacks it didn't want researchers to launch against it included denial of service bugs, attacks on web properties hosted by third parties, and recently acquired technologies. 

Also out of scope were its client applications such as Android, Picasa and Google Desktop. 

Add iTnews as your trusted source

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:

Most Read Articles

Hundreds of old, vulnerable Exchange servers remain in Australia

Hundreds of old, vulnerable Exchange servers remain in Australia

ASD warns Aussie Adobe Commerce and Magento stores under attack

ASD warns Aussie Adobe Commerce and Magento stores under attack

Apple overhauls security with iOS and macOS 27

Apple overhauls security with iOS and macOS 27

OpenAI rogue agent activity wider-ranging than disclosed

OpenAI rogue agent activity wider-ranging than disclosed

Log In

  |  Forgot your password?