I Could've Accessed 17T Microsoft Records
a day ago
- A 16-year-old bug bounty hunter discovered a critical vulnerability in Microsoft's internal Titan service.
- The /v2/Query endpoint accepted SQL queries without verifying JWT signatures, allowing unauthorized access.
- By crafting an unsigned JWT with 'alg':'none' and setting the 'upn' claim to 'admin', the researcher gained administrator privileges.
- This provided access to 30 live routing targets and 17 connected analytics databases, totaling an estimated 17.3 trillion rows.
- Data exposed included employee records (25,000 accounts) and Bing search analytics samples.
- The vulnerability was reported to MSRC and fixed; the researcher received a $5,000 bounty.