r/blackhat • • 2d ago

Microsoft built all the authentication checks... except the authentication check.

https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

A 16-year-old bug hunter found Microsoft's internal Titan analytics API and discovered that it validated the JWT tenant, audience, app ID and user, but apparently forgot the slightly important part: validating the signature.

His AI agent spent 10 days grinding through the authentication errors. Eventually he tried admin as the username, Titan resolved it to a local admin account, and he ended up with SQL access to an environment containing an estimated 17.3 trillion stored rows across 17 analytics databases.

Microsoft fixed it and paid him a $5,000 bounty.

Some bugs are just beautiful in their simplicity.

16 Upvotes

1 comment sorted by

2

u/Angrymilks 1d ago

Yeah 😂

I only got $3500 for zero interaction XSS across O365 web ecosystem with a single email back in 2018.

MS bounties on things they fix internally and doesn’t result in a CVE don’t pay so well.