Bug bounty hunter Sahad Nk recently uncovered a series of vulnerabilities that left Microsoft users’ accounts — from your Office documents to your Outlook emails — susceptible to hacking.
While working as a security researcher with cybersecurity site SafetyDetective,The Intern - A Summer of Lust Nk discovered that he was able to take over the Microsoft subdomain, http://success.office.com, because it wasn’t properly configured. This allowed the bug hunter to set up an Azure web app that pointed to the domain’s CNAME record, which maps domain aliases and subdomains to the main domain. By doing this, Nk not only takes control of the subdomain, but also receives any and all data sent to it.
This is where the second major vulnerability comes into play.
Microsoft Office, Outlook, Store, and Sway apps send authenticated login tokens to the http://success.office.comsubdomain. When a user logs in to Microsoft Live, login.live.com, the login token would leak over to the server controlled by Nk. He would then just have to send over an email to the user asking them to click a link, which would provide Nk with a valid session token — a way to log in to the user’s account without even needing their username or password. And, because Nk has access on Microsoft’s side, that link would come in the form of a login.live.com URL, bypassing phishing detection and even the savviest of internet users.
According to SafetyDetective, the issues were reported to Microsoft in June. They were fixed just last month, in November.
Topics Cybersecurity Microsoft
(Editor: {typename type="name"/})
NYT mini crossword answers for May 12, 2025
Netflix's relaxing 'Fireplace for Your Home' isn't just for the holidays
'Fortnite' rocket launch event is over, but you can see all the videos
'Top Gun 2' casts Miles Teller as Goose's son
AMD Radeon RX 550 + Intel Pentium G4560
Planet formation around distant star captured by astronomers
This story about two random people *maybe* falling in love on a plane is too perfect
Bran Stark has a sweet message for all of us, after what happened to Hodor
Exceptionally rare radio sources detected in the distant universe
Makeup artist unveils new Beyoncé
Whale Vomit Episode 5: Startup Monarchy
British teens had the funniest reactions to their nightmarish maths exam
接受PR>=1、BR>=1,流量相当,内容相关类链接。