11 ms·
Microsoft Live Account Credentials Leaking from Windows 8 and Above
- Kenji 10y agotl;dr: Simply accessing a website with Edge leaks the user name and password hash to the attacker site. They mention that this is also default behaviour in Spartan, Internet Explorer, Outlook (though I do not know how effectively it can be delivered to something like Outlook). Works on up to date Windows 10 and Edge (there is an online test if you're vulnerable). If you don't use the listed software, you're probably completely safe (maybe there is other Microsoft software that does this, though?). If you don't use your Microsoft Live Account as a Windows account, you're safe (someone then just finds out the hash of your local password). EDIT: Interestingly, Edge on the Xbox One is not vulnerable. It seems like the behaviour on the console is different.
- cocotino 10y agoPassword hash? Do they mean an auth token?
- dalbin 10y agoNo I think they mean the NTLMv2 hash of the password.
- deviate_X 10y agoI'd be interested to know, how easy is it to actually break the hash of the password-code
- zaroth 10y agoWhen it's NTLM, extremely easy. I know NTLMv1 cracks at around 25 billion attempts per second on a high-end GPU, which is MD4 based. NTMLv2 is MD5 based with a longer key, so it's slower, I'm not sure how much slower, but I'll guess 1 order of magnitude. Still, far too fast for a password hash. [1] - http://thepasswordproject.com/oclhashcat_benchmarking http://thepasswordproject.com/oclhashcat_benchmarking
- voltagex_ 10y agohttps://hashcat.net/hashcat/ https://hashcat.net/hashcat/ should do it, although NTLMv2 isn't explicitly mentioned. If your password is common (see something like https://github.com/danielmiessler/SecLists/tree/master/Passwords https://github.com/danielmiessler/SecLists/tree/master/Passw...) or <10 ASCII characters, it shouldn't take too long.
- pdkl95 10y agoGiven that far too many passwords can be found with a dictionary attack, it probably only takes seconds for an attacker with "several modern video cards"[1] of hashing power. [1] https://www.youtube.com/watch?v=7U-RbOKanYs https://www.youtube.com/watch?v=7U-RbOKanYs
- marcosdumay 10y agoWhy would you need to? The hash is enough to give you access to any NTLM service.
- dagaci 10y agoWhat NTLM service would you be able to access for example?
- marcosdumay 10y agoWait, what? NTLM is a generic authentication layer. You use it to get single sign-on for your web APIs.
- youdontknowtho 10y agoOther people are reporting that Edge isn't vulnerable.
- overlordalex 10y agoThe articles recommends that you "strengthen your Microsoft Live account password", but if I understand the vulnerability it is only exposing the hash of your password? If it's only exposing the hash, why should you make your password stronger?
- cylo 10y agoTo make the password hash harder to crack. There's a big difference in time to crack the hash for "Passw0rd" vs "$)63hjbbdhs23".
- yAnonymous 10y ago>$)63hjbbdhs23 Great, I'll just store this in my password manag... oh, wait.
- Sylos 10y agoThe hash for "Passw0rd" would almost certainly also be in some Rainbow table, so effectively no computation time in that case...
- cm2187 10y agoMy uneducated understanding is that it is an MD5 hash, quite easily brute forceable if that's the case. https://en.wikipedia.org/wiki/NT_LAN_Manager#NTLMv2 https://en.wikipedia.org/wiki/NT_LAN_Manager#NTLMv2
- KMag 10y ago
- JBiserkov 10y agoMicrosoft should fix this ASAP. You should enable Two-factor Authentication (2FA) on your account. https://support.microsoft.com/en-us/help/12408/microsoft-account-about-two-step-verification https://support.microsoft.com/en-us/help/12408/microsoft-acc...
- el_duderino 10y agoThe permissions their Android 2FA app requires seems a bit much for its purpose. The app has access to: - Identity - Contacts - SMS - Camera - Device ID & call information - Other https://play.google.com/store/apps/details?id=com.microsoft.msa.authenticator https://play.google.com/store/apps/details?id=com.microsoft.... Am I the only one who thinks that?
- aroch 10y agoI can understand Identity, SMS, Camera, and Device ID/Call info. Identity: Find or manage any Live/O365/MS account on your device SMS: Read enrollment text message or backup texts (e.g. no network) for pushing auth requests Camera: Enrollment via QR code Device ID / Call info: Needed to reliably push notifications / send SMS + get phone number for verification texts whatever Android's permission system is sort of obtuse
- Maarten88 10y agoYou can use several other 2FA apps such as Google Authenticator if you do not trust the Microsoft one, they are compatible. That said, personally I do like the Microsoft Authenticator app very much, it's just a single tap on the phone to confirm the 2FA login, which is much more convenient than retyping a code. Disadvantage is that the Android version of the Microsoft Authenticator app can only have one account, I could not connect a second 2FA service (LastPass) to it.
- Sami_Lehtinen 10y agoMS 2FA fails, you can still use IMAP to fetch email and stuff, without 2FA. So it's only partial implementation. Of course it prevents "completely taking over the account", but even if it's enabled you can still do a lot without providing 2FA code.
- pjc50 10y agoAnd people wonder why some of us haven't upgraded from Windows 7. Win10 tries really hard to make you log into your desktop with your Live Account credentials - you can't use the store without this. Whereas if it were just leaking a local login it would be much less critical.
- scholia 10y agoBut if you upgrade to Windows 10 from Windows 7, your existing log-on (which has no Live account connection) continues exactly as before.... It's not really a surprise if an app store needs an account. Are there any that don't?
- pjc50 10y ago.. until you try to install an app, at which point you're prompted to switch over your local account. Apparently you can get round this, but it's not the obvious or default path.
- scholia 10y agoYes. Also, if you start to use Cortana (which is off by default), Microsoft pushes you into converting your local PC account into a Microsoft Account (ie link your PC to your MSA email address).
- jhasse 10y agoF-Droid for Android: https://f-droid.org/ https://f-droid.org/ Also nearly any Linux package manager ;) (if they count as an "app store" for you)
- zokier 10y agoI think the definition of "store" generally implies the ability to buy things, which neither F-Droid or package managers enable.
- 10y ago
- option_greek 10y agoI thought they started fresh with Edge browser by keeping it away from windows/OS specific stuff. Apparently not.
- philjohn 10y agoNope. The started with the IE 11 source code and ripped a whole load of stuff dealing with compatibility, and previous rendering engines, out. Once they had completed this step they started adding new features in, but it's still got the legacy of Internet Explorer code in it.
- Sylos 10y agoI still don't understand how this myth that they wrote Edge from scratch even came to be. You don't just quickly write a browser from scratch in this day and age. And if you did, it would be so much better than Edge or the other contemporary browsers, because you could start out with a much better architecture...
- aurhum 10y ago> I still don't understand how this myth that they wrote Edge from scratch even came to be. Because people confuse Microsoft marketing fluff with reality? "Microsoft Edge is built from the ground up to improve productivity, to be more secure, and to correctly, quickly and reliably render Web pages. While Microsoft Edge is the default browser for Windows 10 and is the best fit for most users, some enterprise customers have line-of-business applications built specifically for older Web technologies, which require Internet Explorer 11." [0] "We designed Microsoft Edge from the ground up to prioritize power efficiency and deliver more battery life" [1] "Microsoft Edge is designed from the ground up to provide a modern, interoperable, and secure browsing experience"[2] [0] https://blogs.microsoft.com/firehose/2016/05/19/improvements-in-windows-10-anniversary-update-help-make-microsoft-edge-and-internet-explorer-11-work-better-together/ https://blogs.microsoft.com/firehose/2016/05/19/improvements... [1] https://blogs.windows.com/windowsexperience/2016/06/20/more-battery-with-edge/ https://blogs.windows.com/windowsexperience/2016/06/20/more-... [2] https://blogs.windows.com/msedgedev/2016/06/07/edge-enterprise-policies-anniversary-update/ https://blogs.windows.com/msedgedev/2016/06/07/edge-enterpri...
- jason46 10y agoIs signed into Cortana and the Windows store synonymous?
- wangchow 10y agoAnyone know if this affects Windows phone 10? It also uses all of the mentioned software.
- ValdikSS 10y agoDoes not affect Windows Phone 8.
- Nokinside 10y agoAs a Linux user I have kept Windows 7 & 8 partitions in my laptop and workstation disks for years because there used to be time where you needed Windows in the work for some programs to work and some documents to open. Windows 10 upgrade push made me to realize that that time passed a long time ago. Last time I booted to Windows for other reason than playing a game was seven years ago. LibreOffice works well with MS documents and you can always use them from Google drive. Windows has lost it's grip for good.
- kemiller2002 10y agoThis is most likely true, and I believe that this is the reason you see MS trying to migrate to being an online provider and moving the .NET framework (and SQL Server for that matter) to work on other platforms.
- bsilvereagle 10y ago> Windows has lost it's grip for good. For your listed use case of gaming & document creation. There are a lot of niche applications that are Windows only. All major CAD platforms, a decent chunk of FEA packages, hardware vendor software, etc. At the professional level, Windows still has quite the grip.
- _RPM 10y agoIf you're a windows shop. My shop doesn't use windows at all.
- criddell 10y agoI think for the kinds of applications that the poster was talking about (CAD, FEA, etc...), there's no concept of the department or business being a Windows shop or a macOS shop any more than it being an Intel shop or an AMD shop. The OS is just infrastructure and not that interesting. It's the applications that are key and if some application requires a Windows machine, that's what they buy.
- zokier 10y ago
- pvdebbe 10y agoIs the NTLMv2 hash even salted?
- zaroth 10y agoNTLM is designed to do authentication over an unencrypted channel with a shared secret (password). It's also important to appreciate there is no initialization protocol for a new user, it's just "please login user x with y". As such, the protocol exchanges everything you would need in order to crack the password in the messages themselves. Adding a salt, unless you stipulate a way to share that salt across machines ahead of time, would not prevent cracking a password by intercepting the messages, because the salt would have to be in the message exchange as well. What a public / visible salt in the message exchange does do is eliminate rainbow table (instant) cracking based on intercepting the message. To answer your question: NTLM is unsalted, and NTLMv2 adds a salt, which is exchanged in the messaging. In this case the salt is applied a bit differently -- MD5(MD5(password), salt) -- because the salt is randomly generated each time, and what's stored in the authentication database is just MD5(password). The salt is only in the challenge-response protocol, so you can still bulk-crack all the passwords in the database if you can steal it. So, you can think of NTLMv2 as "half-salted" and when you tell people that, you'll have a great story to tell (for values of "great" which include crypto-inclined audiences). EDIT: I think KMag has it right. The message has the username, domain, salt, and: MD5(MD5(MD4(password), username || domain), salt) The nesting is because of their attempts at shoe-horning this in their legacy codebase and trying to remain backward compatible. A more secure way to hash the same data, but not backward compatible, is; HMAC(salt, username || domain || password)
- NKCSS 10y agoThis is fun to write for yourself; small SMB client to couple a unique file request to the credentials and website showing the info retrieved via SMB; I think I found my weekend project :)
- ValdikSS 10y agohttps://github.com/SpiderLabs/Responder https://github.com/SpiderLabs/Responder
- besselheim 10y agoUntil a fix is released, this can be mitigated by blocking outbound TCP connections on ports 139 and 445. Individual users can do this using by setting up suitable outbound rules in the Windows Firewall with Advanced Security snap-in (wf.msc).
- Lagged2Death 10y agoOr by using a browser that doesn't silently and promiscuously attempt to connect to remote network shares. Like, any other browser. Good grief.
- besselheim 10y agoOr both. Defense in depth.
- billpg 10y agoHave Microsoft confirmed the issue or planned to roll out a fix?
- batrat 10y agoDid the test with edge and it doesn't work. I'm on stable build. Also it needs edge/ie to be able to do the test...
- KMag 10y agoDoes your ISP block SMB/CIFS ports?
- be5invis 10y agoTested using Edge on r14393, and the demo returns “Not vulnerable”. There is a SEC7111 error in the console.
- anc84 10y agoHuh, their evile 31337 haxx0r background looks like a blatant copyright violation. It's artwork based on a video game cover. Previously also "stolen" by the BBC: http://www.gamesradar.com/wait-did-bbc-use-thief-art-illustrate-story-about-hacker/ http://www.gamesradar.com/wait-did-bbc-use-thief-art-illustr... (since then apparently replaced, http://www.bbc.com/news/technology-33442419 http://www.bbc.com/news/technology-33442419 ) Also available for illegitimate at http://www.shutterstock.com/pic-389962378/stock-photo-hacker-and-computer-virus-concept.html http://www.shutterstock.com/pic-389962378/stock-photo-hacker... or http://www.shutterstock.com/pic-345906527/stock-photo-dangerous-hacker-stealing-data-concept.html http://www.shutterstock.com/pic-345906527/stock-photo-danger...
- drzaiusapelord 10y ago>Edge, Spartan, Internet Explorer (just saying..) Why does he keep repeating "Spartan?" That was Edge's codename. Now its just Edge. Is he's referring to the engine that can be embedded into other applications? If so, its called EdgeHTML.
- oneplane 10y agoSomehow I'm not surprised, neither by the way it's broken nor the neglect on Microsofts part on this issue... Pretty much every non-standard Microsoft-only approach to things seem to be broken one way or another, only to be fixed after someone threatens to expose and exploit it. I know it's gotten better in recent years, but the fact that it's still something that seems to be pushing from the outside in, instead of being part of the manufacturer's culture is shining through rather harshly.
- chocolatebunny 10y agoDoes this affect Microsoft software on macs? We use Outlook on our macbooks at work and I'm wondering if a single mass email can get everyone's Exchange password, or at least the md5sum of their passwords.
- robododo 10y agoJust to clarify the article a bit: Your password hash is not sent over the wire. What is sent over the wire is the NTLMv2 response message. This, simplified, is: HMAC_MD5(Hash | challenge). If you want the gory details, check out MS-NLMP. That said, a dictionary-attackable password + attacker with fast GPUs can still brute-forcing the HMAC, then attack the password hash (MD4). It's a bit harder than just banging on a simple hash, though not terrifically difficult.