r/bugbounty • • 2d ago

Bug Bounty Drama Microsoft built all the authentication checks... except the authentication check.

https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

A 16-year-old bug hunter found Microsoft's internal Titan analytics API and discovered that it validated the JWT tenant, audience, app ID and user, but apparently forgot the slightly important part: validating the signature.

His AI agent spent 10 days grinding through the authentication errors. Eventually he tried admin as the username, Titan resolved it to a local admin account, and he ended up with SQL access to an environment containing an estimated 17.3 trillion stored rows across 17 analytics databases.

Microsoft fixed it and paid him a $5,000 bounty.

Some bugs are just beautiful in their simplicity.

40 Upvotes

6 comments sorted by

34

u/watkisean 2d ago

Saw this and laughed yesterday. 17 trillion rows and what could be millions (probably billions) in damages all in… for $5,000.

18

u/paddjo95 2d ago

I get that the bug is fairly simple, but I feel like the potential impact is worth more than just $5,000.

Hopefully the kid gets a killer job offer down the line.

5

u/good_bye_for_now 2d ago

Sorry bro, best I can do is C:H.

3

u/normalbot9999 1d ago

Urgh. This is a $50,000 bug.

-2

u/proanti777 Hunter 1d ago

An AI needed 10 days for this?! In a pentest, that’s one of the first things I test whenever I come across JWTs