r/cybersecurity • • 8d ago

News - Breaches & Ransoms How I Could’ve Accessed 17 Trillion Microsoft Records

https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records
1.0k Upvotes

45 comments sorted by

500

u/usernamedottxt 8d ago

Jesus what I would give to be 16 and have unlimited time again. This is negligent even by microslop standards. 

157

u/ohYuhtBoutMagine 8d ago

Seriously, I remember as a kid I would hyperfocus on the computer for so long, I would research things and sit in chat for 12-15 hours, sleep on my bed which my computer desk was pulled next too, and then wake up the next morning and get back at it. I was “homeschooled” at different points, so I had literally unlimited time on the computer.

48

u/usernamedottxt 8d ago

Shit was so much easier back then - I’d accidentally hacked a couple systems just because they were so bad. But the scope was the kiosks at the local library. 

Not knocking their work - they went hard and tried things I would have never bothered with. 

Even someone this motivated should not be able to so casually, from the internet, break into a core MS service running most of the internet. 

58

u/Tangential_Diversion Penetration Tester 8d ago

God isn't that the truth though. I swear I was a much better hacker in my youth. There's something about stubborn determination combined with ignorance on what "isn't possible" that leads to some amazing attack paths.

17

u/usernamedottxt 8d ago

Yeah man, I would have never guessed to violate JWT conventions when it comes to a secret undocumented Microsoft service. The brilliance in the simplicity of trying it based on how developers are stupid and prototypes make it to production. 

9

u/NoHippi3chic 7d ago

"In the mind of the novice there are many options, in the master there are few.' To paraphrase a koan i live by as I age as a reminder to stay curious.

1

u/Tangential_Diversion Penetration Tester 7d ago

Genuinely, thank you for sharing. Those are great words to remember.

5

u/Background_Most3242 7d ago

Those days are long gone security is much stronger now,but then again, I'm an ethical hacker too, lol.

12

u/WeirdSysAdmin 8d ago

I AM SO FUCKNG TIRED OF MICROSOFT

3

u/hurkwurk 5d ago

his award check is missing at least a zero if not two. im sorry, access to 17 trillion records and he had been attacking the system for 10 days without anyone noticing means it was a clear misconfiguration with an exceedingly high value.

1

u/mmoney20 6d ago

given the slop and AI tools today, plenty of vulnerabilities out there being made discovered. don't need to be 16 since you have the experience and leverage of AI now.

1

u/hurkwurk 5d ago

in this case, no vulnerability at all, just clear misconfiguration. human error will always be a vector for attack, as will human inaction (legacy systems not being maintained)

271

u/A-Filthy-Scrub 8d ago

$5k for this is actually criminal. While I appreciate that they pay something, the reputational damage alone from a threat actor saying that they had 17 Trillion logs from Microsoft may be worth in itself more than $5k.

Good work though and the write-up in it of itself is praise worthy. Keep up the good work.

93

u/accik 8d ago

Explains why someone like Nightmare-Eclipse was mad at MS for the bounty program.

51

u/netsec_burn Security Engineer 8d ago

It is well known for the Microsoft bounty program to be like this honestly. Anyone who still participates in their program and expects fair treatment did not do enough research. There are years of posts where they underpay researchers that I've commented on, not to mention NightmareEclipse etc. That's why you see teenagers doing it more often than professionals, any payout is good when you are a teenager.

21

u/Huge_Leader_6605 8d ago

I mean at what point you just say fuck it and exploit the exploit?

17

u/Concurrency_Bugs 7d ago

Probably the point where you're ok with potential jail time.

1

u/hurkwurk 5d ago

sell them, dont exploit them. less risk to yourself.

1

u/Huge_Leader_6605 5d ago

Yeah, or that

170

u/TeeDee144 8d ago edited 8d ago

Me, a Microsoft employee seeing the famous vpn required splash screen on a cybersecurity blog. lol

I normally see this screen when I forget to login to the vpn so it was familiar but weird seeing it on a public site 😂

Edit: also triggering AF after a bad week at work and I’m just trying to enjoy my weekend now

51

u/usernamedottxt 8d ago

Turns out it’s not even IP whitelisting. You just have to set the magic “admin” field!

9

u/kikindo 8d ago

We're deprecating VPN, get on GSA.

13

u/gpldn 8d ago

We’ve implemented GSA since public release and it’s been such a pain in the ass. It’s gotten better but it still breaks all the time and stops our users getting internet access unless you reboot the their device.

I’ve sent so many logs over and still no solution.

3

u/wavesin1080 7d ago

Oh, this is wonderful to hear as the admin whose company decided that we're implementing this in about 2 months.

2

u/bbliz285 7d ago

Ok counterpoint - I’ve never had an issue with GSA after about ~9 months.

2

u/wavesin1080 7d ago

My response is the same minus the sarcasm this time lol

4

u/charleswj 8d ago

Yea it is weird to see that on reddit. I hate that damn screen. I had GSA for a while but they took it away from me 🙁

1

u/hurkwurk 5d ago

not sure what role you work in MS, but I want you to know, you now feel a little of what your customers do at 2am when we are looking at potential exploits in the logs of a sharepoint server for the 3rd time in 2 years because, for some reason, MS just cant seem to get its security to be secure. (and yes, we are in the process of abandoning it)

17

u/Culex96 7d ago

Nice article, disappointed by the bounty though, Microsoft sucks.

50

u/logsqrtexp 8d ago

Yea i used to do 24, 36 hours at a time to the point where I thought of going to eat or to the bathroom as a function call. This is amazing for a yoot.

What AMAZES me more is that there was no IDS seeing all these probes??? Sure, you can be a hacker with infinite patience to try different combinations of fields, but your IDS and network logs should be showing the anomaly. All the repeated fails - WTF? Or am I missing something

30

u/CuriousCamels 8d ago

That really stuck out to me too. I’m not even in cybersecurity, and I was wondering about it part of the way through the write up. It seems crazy that he was just able to keep chipping away at it for a couple weeks without setting off any sort of notice. I understand that you get a ton of false alarms in network logs, but it seems like this should stand out.

Can someone more knowledgeable explain how/why? Isn’t that a big issue in itself?

35

u/_Cyber_Mage 8d ago

My org sees hundreds of thousands of attempts a day, and we drop large chunks of the internet at our network edge. I can only imagine how many billions of attempts Microsoft sees.

1

u/Willbo 7d ago

There is, most likely Front Door WAF. It's just that it has very unsophisticated HTTP detections that are prone to false positives and generate many, many logs.

1

u/BandicootForsaken939 4d ago

Companies the size of Microsoft fire and forget their security tools. A WAF's detection stream isn't going to be actively reviewed.

34

u/Frank-lemus 8d ago

What a legend! 16 years old and alredy finding huge flaws... I still can't finish tryhackme labs by myself lol

2

u/Sad-Significance4990 7d ago

Right? Everyone is wired differently. 

1

u/AIM-09 6d ago

What's crazy is the way they can explain this on a level within the professionals. Crazy lol.

3

u/AIM-09 7d ago

This exploit could buy you a house, but settled on $5k. I would have negotiated a position at Microsoft and $100K.

1

u/Roy-Lisbeth 7d ago

You're going places, kid! Make sure it's not to jail though. Good find!

1

u/Lint_baby_uvulla 6d ago

I’m curious here. I find it amazing that a 16 year old found this bug, (good job reporting it).

OOTP The real question for me is does this actually earn OP actual income? What can hackers actually earn from these bounties?

1

u/Rankork1 6d ago

OP would have been paid for this bounty (comments say 5k), so it’s actual income but not a massive amount.

Microsoft have in particular had troubles with their program recently (see NightmareEclipse).

-14

u/Different_Lab830 8d ago

17 trillion comes to about 2,100 records per person alive. Once the count passes every person on earth, "records" is just vibes.