Uploaded June 2023 | Updated September 2026, 2 weeks ago
Every year Google celebrates the best security issues found in Google Cloud. This year we take a look at the 7 winners to see if we could have found these issues too. Will I regret not having hacked Google last year?
This video is sponsored by Google VRP:
Follow GoogleVRP Twitter: twitter.com/GoogleVRP
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Join the Hextree Discord: discord.gg/xgQpCQCpvy
The GCP Prize Winners of 2022:
security.googleblog.com/2023/06/google-cloud-awards-313337-in-2022-vrp.html
1. Prize - $133,337: Yuval Avrahami unit42.paloaltonetworks.com/gke-autopilot-vulnerabilities
2. Prize - $73,331: Sivanesh Ashok and Sreeram KL blog.stazot.com/ssh-key-injection-google-cloud
3. Prize - $31,337: Sivanesh Ashok and Sreeram KL blog.stazot.com/auth-bypass-in-google-cloud-workstations
4. Prize - $31,311: Sreeram KL and Sivanesh Ashok blog.geekycat.in/client-side-ssrf-to-google-cloud-project-takeover
5. Prize - $17,311: Yuval Avrahami and Shaul Ben Hai paloaltonetworks.com/resources/whitepapers/kubernetes-privilege-escalation-excessive-permissions-in-popular-platforms Talk: youtube.com/watch?v=PGsJ4QTlKlQ
6. Prize - $13,373: Obmi obmiblog.blogspot.com/2022/12/gcp-2022-few-bugs-in-google-cloud-shell.html
7. Prize - $13,337: Bugra Eskici https://bugra.ninja/posts/cloudshell-command-injection/
Previous Winners:
GCP Prize 2019: youtube.com/watch?v=J2icGMocQds
GCP Prize 2020: youtube.com/watch?v=g-JgA1hvJzA
GCP Prize 2021: youtube.com/watch?v=GvO2Xtx8p9w
CHAPTERS
00:00 - Intro
01:28 - Python Command Injection (Prize 7)
03:01 - XSS, CSRF and NEL Backdoor (Prize 6)
07:04 - Excessive Permissions in k8s DaemonSets (Prize 5)
09:13 - SSRF auth Authorization Token (Prize 4)
10:46 - OAuth Issue (Prize 3)
12:07 - SSH authorized_key Injection (Prize 2)
14:45 - Kubernetes Engine Privilege Escalation (Prize 1)
18:11 - Discussing the Winner
19:25 - What did I learn from the GCP 2022?
20:51 - Outro
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#GoogleCloud #WebSecurity #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Every year Google celebrates the best security issues found in Google Cloud. This year we take a look at the 7 winners to see if we could have found these issues too. Will I regret not having hacked Google last year?
This video is sponsored by Google VRP:
Follow GoogleVRP Twitter: twitter.com/GoogleVRP
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Join the Hextree Discord: discord.gg/xgQpCQCpvy
The GCP Prize Winners of 2022:
security.googleblog.com/2023/06/google-cloud-awards-313337-in-2022-vrp.html
1. Prize - $133,337: Yuval Avrahami unit42.paloaltonetworks.com/gke-autopilot-vulnerabilities
2. Prize - $73,331: Sivanesh Ashok and Sreeram KL blog.stazot.com/ssh-key-injection-google-cloud
3. Prize - $31,337: Sivanesh Ashok and Sreeram KL blog.stazot.com/auth-bypass-in-google-cloud-workstations
4. Prize - $31,311: Sreeram KL and Sivanesh Ashok blog.geekycat.in/client-side-ssrf-to-google-cloud-project-takeover
5. Prize - $17,311: Yuval Avrahami and Shaul Ben Hai paloaltonetworks.com/resources/whitepapers/kubernetes-privilege-escalation-excessive-permissions-in-popular-platforms Talk: youtube.com/watch?v=PGsJ4QTlKlQ
6. Prize - $13,373: Obmi obmiblog.blogspot.com/2022/12/gcp-2022-few-bugs-in-google-cloud-shell.html
7. Prize - $13,337: Bugra Eskici https://bugra.ninja/posts/cloudshell-command-injection/
Previous Winners:
GCP Prize 2019: youtube.com/watch?v=J2icGMocQds
GCP Prize 2020: youtube.com/watch?v=g-JgA1hvJzA
GCP Prize 2021: youtube.com/watch?v=GvO2Xtx8p9w
CHAPTERS
00:00 - Intro
01:28 - Python Command Injection (Prize 7)
03:01 - XSS, CSRF and NEL Backdoor (Prize 6)
07:04 - Excessive Permissions in k8s DaemonSets (Prize 5)
09:13 - SSRF auth Authorization Token (Prize 4)
10:46 - OAuth Issue (Prize 3)
12:07 - SSH authorized_key Injection (Prize 2)
14:45 - Kubernetes Engine Privilege Escalation (Prize 1)
18:11 - Discussing the Winner
19:25 - What did I learn from the GCP 2022?
20:51 - Outro
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#GoogleCloud #WebSecurity #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.

![Why Pick sudo as Research Target? | Ep. 01
A serious sudo vulnerability had just been announced, but how do researchers find bugs like it? This first episode explains why sudo is an interesting target, prepares a reproducible research environment, and begins an AFL fuzzing strategy that immediately runs into practical problems.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: https://www.hextree.io/
Watch this video and more on Hextree: https://app.hextree.io/courses/yt-sudoedit/sudoedit-introduction
Join the Hextree Discord: https://discord.gg/xgQpCQCpvy
RESOURCES
Text version: https://liveoverflow.com/why-pick-sudo-research-target-part-1/
Episode files: https://github.com/LiveOverflow/pwnedit/tree/main/episode01
Full playlist: https://www.youtube.com/playlist?list=PLhixgUqwRTjy0gMuT4C3bmjeZjuNQyqdx
CHAPTERS
00:00 - Intro
01:48 - Prepare the System
03:57 - How to Pick a Research Target?
05:57 - Choose the Strategy: Fuzzing
09:27 - Fuzzing argv[] With AFL
13:00 - Running Into the Next AFL Problem
14:51 - Outro
SUPPORT
Per video: https://www.patreon.com/join/liveoverflow
Per month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): https://shop.liveoverflow.com/
WATCH, FOLLOW & READ
Second channel: https://www.youtube.com/LiveUnderflow
Twitch: https://twitch.tv/LiveOverflow/
Twitter: https://twitter.com/LiveOverflow/
Instagram: https://instagram.com/LiveOverflow/
TikTok: https://www.tiktok.com/@liveoverflow_
LiveOverflow blog: https://liveoverflow.com/
Hextree blog (ad): https://www.hextree.io/blog
#BinaryExploitation #LinuxSecurity #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement. Why Pick sudo as Research Target? | Ep. 01](https://i.ytimg.com/vi/uj1FTiczJSE/mqdefault.jpg)








