Uploaded March 2021 | Updated September 2026, 2 weeks ago
This video tells the story of how Ezequiel Pereira found a critical Google Cloud vulnerability and earned $164,674 in rewards. It explores Google internals including Deployment Manager, SSRF, Google's Global Software Load Balancer (GSLB), BNS addresses, gRPC, and Protocol Buffers.
This video was sponsored by the Google Vulnerability Rewards Program:
security.googleblog.com/2021/03/announcing-winners-of-2020-gcp-vrp-prize.html
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-websecurity/server-side-request-forgery-ssrf
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Ezequiel's own Writeup: https://www.ezequiel.tech/2020/05/rce-in-cloud-dm.html
SRE Book: https://sre.google/books/
GCP Prize 2020: youtube.com/watch?v=J2icGMocQds
CHAPTERS
00:00 - Intro
00:33 - Meet Ezequiel Pereira
00:58 - The Impact Of The Bug
02:41 - Winning The $133,337 Prize!
04:03 - How To Find a Product To Research?
06:05 - How To Approach Google Products?
07:16 - The BEST Tip For Bug Hunters!
08:08 - What Does Deployment Manager Do?
09:00 - Type Providers: First Research Into Deployment Manager
11:03 - Using Type Providers for SSRF?
13:00 - Going Deeper - Finding A Hidden Version
15:01 - The Google Dogfood Version
15:52 - Discovering Internal Google Options - GSLB
17:34 - The Google SRE Book - Explaining Googles Software Load Balancer
19:34 - Exploiting GSLB?
21:58 - Failing to Exploit GSLB
22:28 - Abusing Protobuf To Find Hidden Enums
25:34 - Google API GRPC/Protobuf Tricks
29:11 - SUCCESS! Attacking Google's Network via GSLB SSRF!
30:34 - Summary
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#GoogleCloud #BugBounty #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
This video tells the story of how Ezequiel Pereira found a critical Google Cloud vulnerability and earned $164,674 in rewards. It explores Google internals including Deployment Manager, SSRF, Google's Global Software Load Balancer (GSLB), BNS addresses, gRPC, and Protocol Buffers.
This video was sponsored by the Google Vulnerability Rewards Program:
security.googleblog.com/2021/03/announcing-winners-of-2020-gcp-vrp-prize.html
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-websecurity/server-side-request-forgery-ssrf
Join the Hextree Discord: discord.gg/xgQpCQCpvy
Ezequiel's own Writeup: https://www.ezequiel.tech/2020/05/rce-in-cloud-dm.html
SRE Book: https://sre.google/books/
GCP Prize 2020: youtube.com/watch?v=J2icGMocQds
CHAPTERS
00:00 - Intro
00:33 - Meet Ezequiel Pereira
00:58 - The Impact Of The Bug
02:41 - Winning The $133,337 Prize!
04:03 - How To Find a Product To Research?
06:05 - How To Approach Google Products?
07:16 - The BEST Tip For Bug Hunters!
08:08 - What Does Deployment Manager Do?
09:00 - Type Providers: First Research Into Deployment Manager
11:03 - Using Type Providers for SSRF?
13:00 - Going Deeper - Finding A Hidden Version
15:01 - The Google Dogfood Version
15:52 - Discovering Internal Google Options - GSLB
17:34 - The Google SRE Book - Explaining Googles Software Load Balancer
19:34 - Exploiting GSLB?
21:58 - Failing to Exploit GSLB
22:28 - Abusing Protobuf To Find Hidden Enums
25:34 - Google API GRPC/Protobuf Tricks
29:11 - SUCCESS! Attacking Google's Network via GSLB SSRF!
30:34 - Summary
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#GoogleCloud #BugBounty #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.










