Twelve Dollars for Google.com — Python Bug Hunt

Modelled on google.com being bought through Google Domains in September 2015.

  • Language: Python
  • Layer: Backend
  • Difficulty: Easy
  • Concepts: Validation, Parsing
  • Modelled on: Google Domains · 2015
  • Visible tests: unregistered is available, a plain registration is not; a locked domain is not available
  • Reward: 50 XP for a complete fix

Briefing

Modelled on google.com being bought through Google Domains in September 2015. Sanmay Ved, a former Google employee, found google.com listed as available in Google Domains and bought it for $12; the purchase went through, and he briefly received the domain's webmaster messages before Google cancelled the order about a minute later and rewarded him through its bug bounty programme. Google did not publish the root cause.

This reconstruction plants one plausible mechanism — not Google's actual code: the availability check reads the registry record's EPP statuses and treats a domain as taken only when it carries the ok status. A heavily protected domain carries lock statuses instead of ok, so it shows as available.

Fix is_available so any registered domain is reported as taken.

Bug report

BUG-GDOMAINS · Priority: Critical · Reported by: registrar review

is_available(name, registry):

  • the name is normalised first: surrounding whitespace stripped, lowercased, one trailing "." removed; the registry is queried with the normalised name
  • True ONLY when registry.lookup(...) returns None (no record)
  • any record means the domain is registered and NOT available, whatever its statuses: "ok", lock statuses such as "clientTransferProhibited", "pendingDelete", or an empty list

Observed: google.com (statuses clientDeleteProhibited, clientTransferProhibited, clientUpdateProhibited, serverDeleteProhibited, serverTransferProhibited, serverUpdateProhibited) was offered for $12.

Logs

[search] google.com statuses=[clientDeleteProhibited, clientTransferProhibited, ...] -> available
[cart] google.com added, price=12.00 USD
[order] completed

The code as shipped

src/registrar/availability.py (editable)

def normalise(name):
    name = name.strip().lower()
    if name.endswith("."):
        name = name[:-1]
    return name


def is_available(name, registry):
    record = registry.lookup(normalise(name))
    if record is None:
        return True
    return "ok" not in record["statuses"]

Read-only context: src/registrar/registry.py.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More Python bug hunts.