
Jakub Domeracki
@j_domeracki
Followers
353
Following
140
Media
6
Statuses
44
Security Engineer @ Coder Google Cloud VRP ๐ฉ๏ธ
Joined April 2023
Another one of my reports got disclosed ๐. @GoogleVRP did a great job of nearly eliminating XSS-es from their core apps, but some are still to be found. A technical writeup, describing this and corresponding issues, should be published by end of month ๐ค.
bughunters.google.com
Found a security vulnerability? Discover our forms for reporting security issues to Google: for the standard VRP, Google Play, and Play Data Abuse.
6
38
214
Still can't quite believe that one of my reports won the most creative category award at recent @GoogleVRP bugSWAT LHE! ๐. Can't disclose the details yet but I'll surely cover the entire attack scenario in a dedicated writeup.
5
3
92
RT @terminatorLM: ๐ปThis is GerriScary: a vulnerability I discovered in Google's Gerrit that allowed to hack several projects and affected 1โฆ.
0
26
0
Sharing a writeup on Bucket Traversals, which in my opinion is an under researched vulnerability class:. It's based on a case study which ended being rewarded by OSS @GoogleVRP:. I hope you'll find it interesting!
1
24
79
@GoogleVRP None of the current guesses are close - it's a cloud specific scenario which was reported and written about in the past. I intend to stick with the standard 90 days post disclosure / 30 days post fix practice, so no details until then.
0
0
1
Well-known attack technique, still relevant. Will publish an educational writeup in a few weeks/months๐ค. @GoogleVRP
4
2
98
Rarely do I post but this is in my book a must watch by @snyff. Great insights and for me personally a much needed recalibration of expectations & approach.
1
6
14
RT @S1r1u5_: Imagine opening a Discord message and suddenly your computer is hacked. We discovered a bug that made this possible and earneโฆ.
0
178
0
RT @gregxsunday: Story of a Cloud Architecture Diagramming Tool gone wrong by @j_domeracki.#BBRENewsletter84 https:โฆ.
0
4
0
Sharing a technical writeup, which goes over an almost year long responsible disclosure process:. The severity of disclosed shortcomings, resulted in getting decommissioned ๐ง. Greatly appreciate the cooperation with @GoogleVRP! ๐.
jdomeracki.github.io
Table of Contents
0
30
126