2x Google RCE with VRP Legend Brutecat (Ep. 177)

2x Google RCE with VRP Legend Brutecat (Ep. 177)

Source: YouTube · Critical Thinking - Bug Bounty Podcast · published Jun 4, 2026 · 1:25:27

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Security researcher Brute Cat details how he leveraged stubby RPC exploitation, protobuf manipulation, and IDOR chains to uncover critical vulnerabilities in Google’s infrastructure, resulting in significant bug bounty payouts.

Key Takeaways:
• Brute Cat utilized the X-Goog-Encoded-Response-If-Executable-Base64 header to bypass protobuf restrictions and dump internal workflow execution logs from the Cloud CRM API 10:20
• He identified a filter injection vulnerability in the list_quota_queue endpoint, enabling a binary search to leak UUIDs and establish an IDOR chain linking YouTube channels to account emails 15:45
• The researcher exploited "Generic stubby type task" endpoints to execute arbitrary RPC calls, achieving Remote Code Execution (RCE) by bypassing authentication via duplicate endpoints and ACL misconfigurations 20:10

Brute Cat’s methodology demonstrates that combining obscure header manipulation, filter-based binary searches, and internal RPC access allows for high-impact exploitation of Google’s complex microservices architecture.

Sources:

  • 10:20 Using special headers to dump protobuf responses
  • 15:45 Filter injection and binary search for UUID leakage
  • 20:10 Stubby RPC exploitation and RCE discovery

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

I I don't know. I can't remember any dates or whatever, but I can remember I can remember that weird header. Or that password. I can remember the password of my first domain admin that I popped, you know, like but I can't I can't remember >> remember my I don't remember my own mom's birthday, but I remember I remember this one. >> [music] >> Best part about hacking when you can just, you know, critical thing, right? >> [music] [laughter] [gasps] >> Hey, what's up guys? Before we get into the show, I wanted to mention something super quick from our friends at ThreatLocker and I actually think you all are going to think it's pretty awesome because so much of bug bounty is often, you know, kind of quoted as like, "Yeah, but hackers will never exploit that because they can just get in via fish…