利用人工智能攻击 Google 赚取 50 万美元
brutecat.com | 博客 | #ai-security | #bug-bounty | #fuzzing | #reconnaissance | #api-security | #google
摘要
作者利用 Claude 对 Google 内部 API 进行大规模自动化模糊测试:基于 discovery 文档枚举端点,通过解析 6 万多个 Android APK、访问 2800 余个网页域名和解密 iOS 应用批量收集 API 密钥,最终在 Google VRP 中获得 50 万美元赏金。
- 发布时间
- 收录时间
Skip to content