Bug bounty hunter Sahad Nk recently uncovered a series of vulnerabilities that left Microsoft users’ accounts — from your Office documents to your Outlook emails — susceptible to hacking.
While working as a security researcher with cybersecurity site SafetyDetective,lesbian sex tumblr video Nk discovered that he was able to take over the Microsoft subdomain, http://success.office.com, because it wasn’t properly configured. This allowed the bug hunter to set up an Azure web app that pointed to the domain’s CNAME record, which maps domain aliases and subdomains to the main domain. By doing this, Nk not only takes control of the subdomain, but also receives any and all data sent to it.
This is where the second major vulnerability comes into play.
Microsoft Office, Outlook, Store, and Sway apps send authenticated login tokens to the http://success.office.comsubdomain. When a user logs in to Microsoft Live, login.live.com, the login token would leak over to the server controlled by Nk. He would then just have to send over an email to the user asking them to click a link, which would provide Nk with a valid session token — a way to log in to the user’s account without even needing their username or password. And, because Nk has access on Microsoft’s side, that link would come in the form of a login.live.com URL, bypassing phishing detection and even the savviest of internet users.
According to SafetyDetective, the issues were reported to Microsoft in June. They were fixed just last month, in November.
Topics Cybersecurity Microsoft
(Editor: {typename type="name"/})
Best Apple iPad Mini deal: Save $100 at Best Buy
PlayStation Classic is Sony's new throwback games console
People are sharing the meanest backhanded compliments they've received
Notre Dame vs. Georgia football livestreams: kickoff time, streaming deals, and more
Construction worker creates life
Birkenstock will pull its shoes from Amazon over counterfeit sellers
1 moment in the new 'Captain Marvel' trailer really has people confused
Waymo stopped Los Angeles man from stealing a driverless car
Apple's messy Ireland situation has ended with a €14 billion payout
接受PR>=1、BR>=1,流量相当,内容相关类链接。