| the craziest part is that he didn't even need real admin credentials. Microsoft's internal API never verified JWT signatures, letting him forge an authentication token. After getting past its other checks, changing the username field to "admin" gave him administrator-level access lmao. to be clear, the 17.3 trillion figure refers to estimated rows potentially accessible across 17 analytics databases, not records he downloaded. He reported the vulnerability to Microsoft, and the reward? just $5,000. holy crap, how does something like this make it into production tho? [link] [comments] |
from hacking: security in practice https://ift.tt/xqoXtmF
Comments
Post a Comment