Google != Evil

Remember back in May?
I announced this post: Google AdWords XSS'es.

I turned out that I had been in contact with the wrong Google staff.

The Google AdWords support didn't know enough about security related issues, therefor I didn't get any reward.

One thing lead to another, and I announced the post with two 0-days.

However! Just minutes after, a certain employee at the Google Security staff contacted Jelmer - who in turn contacted me.
We had a nice conversation and exchanged all information needed to both exploit and to patch the vulnerability.

The information provided was enough to qualify me for the Google Vulnerability Reward Program.

I would just want to thank the Security Staff at Google.
The VRP do work.

So no hard feelings! I managed to get on the Google Hall of Fame and received an award of $500 USD.

Google HoF

Google HoF

Thanks Google <3

Hey, I'm Fredrik. I'm from Sweden, born 1990, and I got a huge interest for information technology and information security. So far, I've been studying for three years at the Internation IT College of Sweden and one year at the Royal Institute of Technology (Kista, Sweden). I'm one of the Co-Founders of Detectify. I'm working closely together with the swedish firm Young & Skilled. ...Not to forget, I'm the previous founder of Arctic Security. If you wish to contact me, please email me at h@ackack.net or follow me on twitter @Almroot.

6 Comments

  1. Henrik Kentsson says:

    Awesome, that's a good achievement :)
    Too bad you didn't get a link to this blog...

  2. нα¢кєя says:

    Hey That name saying

    нα¢кєя Himanshu Sharma Is me in the screenshot :) Right above your name sir haha xD i got $500 reward from google too :)

  3. Fredrik Nordberg Almroth says:

    Haha awesome! So we're both part of the same club now :D
    Nice to meet you!

  4. НΑ¢КЄЯ says:

    Nice to meet you too :D if you ever need me you can contact me at 007@fbi.al :P

  5. Curious says:

    And if they did not put you in Hall of Fame and did not pay you, they would be evil?

  6. Fredrik Nordberg Almroth says:

    In my opinion yes. It was after all a web based vulnerability - and if Google would break their own policy (the Google vulnerability reward program); I would see it as unfair.
    I can't really call them evil no matter the context tough.

Leave a Comment