5 ms·
I'm confused as to how they do the sub domain takeover.
by abluecloud 6y ago
I'm confused as to how they do the sub domain takeover.
- zaroth 6y agoCame here to ask the exact same question. TLDR; Authorization cookie for an important Account API is sent to *.teams.microsoft.com and they got control of a subdomain of that somehow.
- cotillion 6y agoThose records probably pointed to an ip or a CNAME which was not registered or not under microsoft control. But some more information on that mistake would have been nice.
- munchbunny 6y agoI had to read up on it, the gist of it is (these are example domain names I made up for illustration): 1. Domain like "abcde.teams.microsoft.com" has a CNAME that points to a domain like "abcde.microsoft-teams.com", but "microsoft-teams.com" is no longer registered to or controlled by Microsoft. 2. Hacker registers microsoft-teams.com, gets a LetsEncrypt SSL for it. 3. Send a message to someone with a GIF that was uploaded to "abcde.teams.microsoft.com". Teams thinks it's legit because it's a subdomain of "teams.microsoft.com", and SSL checks out, so it sends the user's auth token along with the HTTP request for the GIF. Problem is, it's sending it to the attacker controlled "abcde.microsoft-teams.com". 4. Since the hacker controls "abcde.microsoft-teams.com", they now have your auth token, which they can use to impersonate you. Et voila, account takeover. I'd bet that plenty of whitehats and blackhats have bots automatically crawling domains belonging to tech companies searching for subdomain takeover opportunities.
- tidepod12 6y ago>Domain like "abcde.teams.microsoft.com" has a CNAME that points to a domain like "abcde.microsoft-teams.com", but "microsoft-teams.com" is no longer registered to or controlled by Microsoft. Can you elaborate a bit on this? I get that these are example domains, but why would "abcde.teams.microsoft.com" (which is presumably controlled by Microsoft) point to a domain "microsoft-teams.com" that is not controlled by Microsoft? Was that a mistake on Microsoft's part, or did the attackers do something clever to gain control of that domain/point a Microsoft-owned subdomain to the attacker's domain?
- munchbunny 6y agoYup, in my hypothetical example, at some point "microsoft-teams.com" was registered by Microsoft. At that time, some engineer deployed something that involved the CNAME. Over time, "microsoft-teams.com" was moved elsewhere and the domain became unregistered, but the engineer maybe forgot or left the team, and nobody remembered that there's this out of date "abcde.teams.microsoft.com" DNS record just sitting there. Microsoft has a lot of these, just random Microsoft-ish domains that were used at one point or another. It's a problem because it makes it harder to look at the domain name as a sanity check against phishing.
- gnopgnip 6y agoMicrosoft and other large companies are made up of many smaller groups, and to make this work there are a lot of extra rules. For the most part those rules serve a purpose and the benefit outweighs the cost. Sometimes these rules create extra problems, because of how people actually make choices and use the resulting system. It is likely there is a detailed change approval process for updating a *.microsoft.com DNS record. Or that only certain depts can make changes, and only for certain reasons. Someone involved with Teams avoided that by using a separate domain and a cname record, then they could update their separate domain records more easily. Later someone forgot to register this domain, and/or forgot to update the DNS to somewhere that is over their control, or forgot to put in sufficient checks to prevent tokens being shared with unauthorized servers.
- deleted 6y ago[deleted]
- staticvar 6y agoAha! Thank you munchbunny. Another title for this article could be "How some major tech companies DNS record management practices left your organization vulnerable to attack". This is a great lesson for all of us. Leaving old records in DNS is so easy to do.
- donmcronald 6y agoI don't think you got it quite right. No one would ever see microsoft-teams.com and you wouldn't need an SSL cert for it. The CNAME affects the DNS lookup, so if you ask "where's abcde.teams.microsoft.com", the server replies "it's at the same IP as "microsoft-teams.com, so go look there". Since you control the DNS for microsoft-teams.com, you can point it to your server. Now both domains point at your server and you get all requests to abcde.teams.microsoft.com. That's how they get cookies. You can get an SSL certificate because you can serve anything for abcde.teams.microsoft.com. That includes abcde.teams.microsoft.com/.well-known/acme-challenge/* and the .gif (or other) resource you use to steal cookies. Either abcde.microsoft-teams.com is a typo or you seem to think CNAMEs work like an HTTP redirect, which they don't.
- aaron_m04 6y ago> I'd bet that plenty of whitehats and blackhats have bots automatically crawling domains belonging to tech companies searching for subdomain takeover opportunities. If Microsoft had one of these, they could've caught this before it was exploited.