Twelve Dollars for Google.com — Python Bug Hunt
Modelled on google.com being bought through Google Domains in September 2015.
- Language: Python
- Layer: Backend
- Difficulty: Easy
- Concepts: Validation, Parsing
- Modelled on: Google Domains · 2015
- Visible tests: unregistered is available, a plain registration is not; a locked domain is not available
- Reward: 50 XP for a complete fix
Briefing
Modelled on google.com being bought through Google Domains in September 2015. Sanmay Ved, a former Google employee, found google.com listed as available in Google Domains and bought it for $12; the purchase went through, and he briefly received the domain's webmaster messages before Google cancelled the order about a minute later and rewarded him through its bug bounty programme. Google did not publish the root cause.
This reconstruction plants one plausible mechanism — not Google's actual code: the availability check reads the registry record's EPP statuses and treats a domain as taken only when it carries the ok status. A heavily protected domain carries lock statuses instead of ok, so it shows as available.
Fix is_available so any registered domain is reported as taken.
Bug report
BUG-GDOMAINS · Priority: Critical · Reported by: registrar review
is_available(name, registry):
- the name is normalised first: surrounding whitespace stripped, lowercased, one trailing "." removed; the registry is queried with the normalised name
- True ONLY when registry.lookup(...) returns None (no record)
- any record means the domain is registered and NOT available, whatever its statuses: "ok", lock statuses such as "clientTransferProhibited", "pendingDelete", or an empty list
Observed: google.com (statuses clientDeleteProhibited, clientTransferProhibited, clientUpdateProhibited, serverDeleteProhibited, serverTransferProhibited, serverUpdateProhibited) was offered for $12.
Logs
[search] google.com statuses=[clientDeleteProhibited, clientTransferProhibited, ...] -> available
[cart] google.com added, price=12.00 USD
[order] completedThe code as shipped
src/registrar/availability.py (editable)
def normalise(name):
name = name.strip().lower()
if name.endswith("."):
name = name[:-1]
return name
def is_available(name, registry):
record = registry.lookup(normalise(name))
if record is None:
return True
return "ok" not in record["statuses"]
Read-only context: src/registrar/registry.py.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.