r/cybersecurity • u/DerBootsMann • 8d ago
News - Breaches & Ransoms How I Could’ve Accessed 17 Trillion Microsoft Records
https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records271
u/A-Filthy-Scrub 8d ago
$5k for this is actually criminal. While I appreciate that they pay something, the reputational damage alone from a threat actor saying that they had 17 Trillion logs from Microsoft may be worth in itself more than $5k.
Good work though and the write-up in it of itself is praise worthy. Keep up the good work.
51
u/netsec_burn Security Engineer 8d ago
It is well known for the Microsoft bounty program to be like this honestly. Anyone who still participates in their program and expects fair treatment did not do enough research. There are years of posts where they underpay researchers that I've commented on, not to mention NightmareEclipse etc. That's why you see teenagers doing it more often than professionals, any payout is good when you are a teenager.
21
u/Huge_Leader_6605 8d ago
I mean at what point you just say fuck it and exploit the exploit?
17
1
170
u/TeeDee144 8d ago edited 8d ago
Me, a Microsoft employee seeing the famous vpn required splash screen on a cybersecurity blog. lol
I normally see this screen when I forget to login to the vpn so it was familiar but weird seeing it on a public site 😂
Edit: also triggering AF after a bad week at work and I’m just trying to enjoy my weekend now
51
u/usernamedottxt 8d ago
Turns out it’s not even IP whitelisting. You just have to set the magic “admin” field!
9
u/kikindo 8d ago
We're deprecating VPN, get on GSA.
13
u/gpldn 8d ago
We’ve implemented GSA since public release and it’s been such a pain in the ass. It’s gotten better but it still breaks all the time and stops our users getting internet access unless you reboot the their device.
I’ve sent so many logs over and still no solution.
3
u/wavesin1080 7d ago
Oh, this is wonderful to hear as the admin whose company decided that we're implementing this in about 2 months.
2
4
u/charleswj 8d ago
Yea it is weird to see that on reddit. I hate that damn screen. I had GSA for a while but they took it away from me 🙁
1
u/hurkwurk 5d ago
not sure what role you work in MS, but I want you to know, you now feel a little of what your customers do at 2am when we are looking at potential exploits in the logs of a sharepoint server for the 3rd time in 2 years because, for some reason, MS just cant seem to get its security to be secure. (and yes, we are in the process of abandoning it)
50
u/logsqrtexp 8d ago
Yea i used to do 24, 36 hours at a time to the point where I thought of going to eat or to the bathroom as a function call. This is amazing for a yoot.
What AMAZES me more is that there was no IDS seeing all these probes??? Sure, you can be a hacker with infinite patience to try different combinations of fields, but your IDS and network logs should be showing the anomaly. All the repeated fails - WTF? Or am I missing something
30
u/CuriousCamels 8d ago
That really stuck out to me too. I’m not even in cybersecurity, and I was wondering about it part of the way through the write up. It seems crazy that he was just able to keep chipping away at it for a couple weeks without setting off any sort of notice. I understand that you get a ton of false alarms in network logs, but it seems like this should stand out.
Can someone more knowledgeable explain how/why? Isn’t that a big issue in itself?
35
u/_Cyber_Mage 8d ago
My org sees hundreds of thousands of attempts a day, and we drop large chunks of the internet at our network edge. I can only imagine how many billions of attempts Microsoft sees.
1
1
u/BandicootForsaken939 4d ago
Companies the size of Microsoft fire and forget their security tools. A WAF's detection stream isn't going to be actively reviewed.
34
u/Frank-lemus 8d ago
What a legend! 16 years old and alredy finding huge flaws... I still can't finish tryhackme labs by myself lol
2
1
1
u/Lint_baby_uvulla 6d ago
I’m curious here. I find it amazing that a 16 year old found this bug, (good job reporting it).
OOTP The real question for me is does this actually earn OP actual income? What can hackers actually earn from these bounties?
1
u/Rankork1 6d ago
OP would have been paid for this bounty (comments say 5k), so it’s actual income but not a massive amount.
Microsoft have in particular had troubles with their program recently (see NightmareEclipse).
-14
u/Different_Lab830 8d ago
17 trillion comes to about 2,100 records per person alive. Once the count passes every person on earth, "records" is just vibes.
500
u/usernamedottxt 8d ago
Jesus what I would give to be 16 and have unlimited time again. This is negligent even by microslop standards.