this 16 yo kid gained access to 17 trillion microsoft users records, by using "admin" as username

this 16 yo kid gained access to 17 trillion microsoft users records, by using "admin" as username

the craziest part is that he didn't even need real admin credentials. Microsoft's internal API never verified JWT signatures, letting him forge an authentication token. After getting past its other checks, changing the username field to "admin" gave him administrator-level access lmao.

to be clear, the 17.3 trillion figure refers to estimated rows potentially accessible across 17 analytics databases, not records he downloaded. He reported the vulnerability to Microsoft, and the reward? just $5,000.

holy crap, how does something like this make it into production tho?

submitted by /u/jeheskielsunloy
[link] [comments]


from hacking: security in practice https://ift.tt/xqoXtmF

Comments