Google Pays High School Student $10,000 for Reporting Security Flaw

Advertisement
By Gadgets 360 Staff | Updated: 11 August 2017 17:18 IST
Highlights
  • A high-school student spotted a vulnerability on Google's website
  • He reported the vulnerability to Google
  • Google thanked him and paid him $10,000

A high-school student from Uruguay has been rewarded with $10,000 (roughly Rs. 6.5 lakh) after he discovered and reported a vulnerability to Google.

The student, Ezequiel Pereira, says he chanced upon the vulnerability after a bout of boredom last month when he was poking around Google services using Burp Suite, a popular Web security testing tool.

After a few failed attempts, Pereira says he came across yaqs.googleplex.com, an internal webpage which didn't have username or password check in place. Googleplex.com hosts several Google App Engine apps.

Advertisement

"The website's homepage redirected me to "/eng", and that page was pretty interesting, it had many links to different sections about Google services and infrastructure, but before I visited any section, I read something in the footer: "Google Confidential".

Advertisement

"At that point I stopped poking at the website and reported the issue right away, without even thinking of a better way to show the vulnerability than with Burp," Pereira wrote.

Sharing screenshots of the email exchanges, Pereira said he received multiple response from Google's security team the same day, who confirmed that the bug he had reported was indeed effective.

Advertisement

Bug Bounty Hunters Say They Aren't Welcome in India

With little to no hope of any rewards, Pereira says he was surprised when a month later Google team informed him that he would be paid $10,000 for his work, and that he could share the nature of the vulnerability with the world.

Advertisement

Google has since resolved the vulnerability. "The bug has been fixed now, and, according to Google, the large reward was because they found a few variants that would have allowed an attacker access sensitive data," Pereira wrote.

The transparency and willing to reward independent security researchers is one of the things several Silicon Valley companies have been working on. Google, Microsoft and Apple are increasingly offering bug bounty reward programs where they encourage people to report any security or privacy flaws they spot in any of their services.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Google, Security, Web, Internet, Bug Bounty, Facebook
Advertisement

Related Stories

Popular Mobile Brands
  1. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  2. Saiyaara is All Set to Stream on This OTT Platform in September
  3. India's Indigenous Vikram Microprocessor Showcased at Semicon India 2025
  4. Apple Hebbal: First-Ever Apple Store in Bengaluru is Now Open
  5. Realme 15T 5G India Launch Today: All You Need to Know
  6. OpenAI Could Soon Build This Massive AI Infrastructure in India
  7. Total Lunar Eclipse 2025: When and Where to Watch the Blood Moon Safely
  8. WhatsApp Will Now Let You Generate Any Video Call Background Using AI
  9. OnePlus Pad 3 Price in India, Offers Announced Ahead of September 5 Debut
  10. Google Debunks Gmail Security Warning Reports, Calls It Entirely False
  1. Vivo X300 Series to Use Samsung’s New 200-Megapixel ISOCELL HPB Sensor for Stills, Portrait Photography
  2. Apple Reportedly Pushes Supply Chain Partners to Ramp Up Automation Upgrades
  3. Total Lunar Eclipse 2025: When and Where to Watch the Blood Moon Safely
  4. Apple Hebbal: First-Ever Apple Store in Bengaluru is Now Open
  5. Oppo Find X9 Design Spotted in Leaked Render; Performance Revealed via Geekbench
  6. Google Debunks Gmail Security Warning Reports, Calls It Entirely False
  7. Realme 15T Launched in India With 7,000mAh Battery, 50-Megapixel Selfie Camera: Price, Specifications
  8. Bitcoin Conspiracy Thriller Killing Satoshi Starring Casey Affleck, Pete Davidson Expected to Release in 2026
  9. 007 First Light Is Getting a Gameplay Deep Dive at Sony's State of Play This Week
  10. OnePlus 15 Will Reportedly Arrive With Company's New, Propreitary Camera Engine
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.