Hacking G Suite: The Power of Dark Apps Script Magic

Presented at DEF CON 29 (2021), Aug. 7, 2021, 3 p.m. (45 minutes)

You've seen plenty of talks on exploiting, escalating, and exfiltrating the magical world of Google Cloud (GCP), but what about its buttoned-down sibling? This talk delves into the dark art of utilizing Apps Script to exploit G Suite (AKA Google Workspace). As a studious sorcerer, you'll discover how to pierce even the most fortified G Suite enterprises. You'll learn to conjure Apps Script payloads to bypass powerful protective enchantments such as U2F, OAuth app allowlisting, and locked-down enterprise Chromebooks. Our incantations don't stop at the perimeter, we will also discover novel spells to escalate our internal privileges and bring more G Suite accounts under our control. Once we've obtained the access we seek, we'll learn various curses to persist ourselves whilst keeping a low profile so as to not risk an unwelcome exorcism. You don't need divination to see that this knowledge just might rival alchemy in value. REFERENCES: No real academic references, this is all original research gleaned from real-world testing and reading documentation.

Presenters:

  • Matthew Bryant - Red Team @ Snapchat
    mandatory (Mathew Bryant) is a passionate hacker currently leading the red team effort at Snapchat. In his personal time he's published a variety of tools such as XSS Hunter, CursedChrome, and tarnish. His security research has been recognized in publications such as Forbes, The Washington Post, CBS News, Techcrunch, and The Huffington Post. He has previously presented at Blackhat, RSA, Kiwicon, Derbycon, and Grrcon. Previous gigs include Google, Uber, and Bishop Fox. @IAmMandatory https://thehackerblog.com

Links:

Similar Presentations: