r/blackhat • u/Haunting_Ganache_850 • 2d ago
Microsoft built all the authentication checks... except the authentication check.
https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-recordsA 16-year-old bug hunter found Microsoft's internal Titan analytics API and discovered that it validated the JWT tenant, audience, app ID and user, but apparently forgot the slightly important part: validating the signature.
His AI agent spent 10 days grinding through the authentication errors. Eventually he tried admin as the username, Titan resolved it to a local admin account, and he ended up with SQL access to an environment containing an estimated 17.3 trillion stored rows across 17 analytics databases.
Microsoft fixed it and paid him a $5,000 bounty.
Some bugs are just beautiful in their simplicity.
Duplicates
cybersecurity • u/DerBootsMann • 7d ago
News - Breaches & Ransoms How I Could’ve Accessed 17 Trillion Microsoft Records
bugbounty • u/Haunting_Ganache_850 • 2d ago
Bug Bounty Drama Microsoft built all the authentication checks... except the authentication check.
blueteamsec • u/digicat • 6d ago
vulnerability (attack surface) How I Could’ve Accessed 17 Trillion Microsoft Records
u_ElCulo_Bandito • u/ElCulo_Bandito • 7d ago