3 ms·
you can find both disclosure dates and versions in the report. As for when it was fixed - I have no idea, as they never told me, one day it just was.
by oskarsv 6y ago
you can find both disclosure dates and versions in the report.
As for when it was fixed - I have no idea, as they never told me, one day it just was.
- GekkePrutser 6y agoThank you for reporting it and not selling it on the black market! I agree the categorisation is very bad. I hope raising this here will help you getting rewarded properly.
- driverdan 6y ago> Thank you for reporting it and not selling it on the black market! I disagree. If MS is going to treat major issues like this then researchers should be selling them to the highest bidder. Maybe that way they'll actually treat disclosures properly.
- Zenbit_UX 6y agoPretty bold to advocate for blackhat behavior on one of the most schoolboy vanilla places on the internet, but I can't say I necessarily disagree with your sentiment, big tech needs a lesson but is this really the vulnerability we want? 115 million DAU on teams... The amount of damage the NSA or some other state sponsored actor could do with this... It would be very bad to say the least. How bad depends on which state acquires it. If a script kiddy got it they would likely do a mass randomware infection, hospitals would get hit, people would die. Millions in crypto would be lost to unencrypted wallets found on the vulnerable machines (yes people do that..), this could cause some to lose their life savings... People have commit suicide for less. My point is its important to look past FAANG being cheap and look at 2nd and 3rd order effects from something this powerful and widespread.
- mistrial9 6y ago> look at 2nd and 3rd order effects .. which FOSS engineers have spent their lives on, while FAANG acumulates patent and SSL money across international borders? forcing TEAMS kool-aid with surveillance built-in, down your desktop with the help of C-Suite and their attorneys?
- woodruffw 6y agoGovernments around the world already regularly trade in exploits that are as or more severe than this one. That isn’t to advocate for brokering to a government, just to say that the market already exists and contains comparable exploits. It’s only a matter of time until we see the next EternalBlue to WannaCry lifecycle.
- corty 6y agoThe ethical thing to do is immediate full disclosure, not selling it and not this (ir)responsible disclosure crap.
- mwcampbell 6y ago> researchers should be selling them to the highest bidder But what about all of the innocent people who would be harmed by such a callous approach? I'm glad some researchers have a conscience.
- iforgotpassword 6y ago> But what about all of the innocent people who would be harmed by such a callous approach? They should then think again about their choice of using teams. Why should Microsoft rake in money from a shabby product while volunteers have to fix their shit? Assigning a ridiculously low score to significantly lower the bounty as a billion dollar company is disgusting.
- untog 6y ago> They should then think again about their choice of using teams. What percentage of Teams users do you think have a choice in their use of Teams?
- the8472 6y agoIf it's on their work machines then it primarily endangers their employer's data, much less their own.
- airstrike 6y agoAnd then when the company loses business from the disruption, do you think employees walk away scot-free?
- the8472 6y agoI consider that inherent risk. Not getting a raise because the company made business decisions that turned out suboptimal (such as gaining short-term profits by not investing IT security) is a risk that any employee faces. If you want a more stable environment you go for a more risk-averse employer, perhaps even public sector jobs.
- MrDresden 6y agoWhile I get your sentiment, I must disagree. Profiting from the very likely unethical use of the exploit would be unethical. Instead this mishandling by M$ should rather cause researchers to publicly announce the vulnerabilities which would hopefully cause M$ to change their ways in future dealings. It is ofcourse easy for me to say this, not being a researcher who lives off of the discoveries made.
- krageon 6y agoParticipating in a system that exploits researchers for free labour using societal guilt-tripping is the unethical move here. That means you.
- MrDresden 6y agoI see you completely missed my point. My point is that in the case of M$ the defects could be publicly announced to all parties at once as a way of making M$ realize that how bad their handling is/was. In all likelyhood this shouldn't have to happen for too long before they would realize their mistake. Many other corporations do indeed value the discoveries of researchers and do pay accordingly for being notified. Never did I suggest that this should become the industry norm (i.e not paying for private disclosures). Now what ever your personal feelings on that idea is, it does not change the fact that selling exploits to other parties would be unethical. Furthermore, participating in a system that promotes assumptions and flawed reading comprehension is not conductive to a good discourse. That means you.
- rndgermandude 6y agoThing is, we don't know if this was found before by malicious actors and sold and/or abused. This thing sounds like it is mostly pretty straight forward to find once you start looking - "you" being somebody experienced in this field of research, that is. At least you don't have to construct fancy weird machines (with type confusion, heap spraying and all those shenanigans). It comes down to finding something that can perform code execution in their internal API (here: "electronSafeIpc") and then finding a way to get there (here: angular escape bypass/not-properly-sanitized user provided data) and you can do both in javascript and don't have to read tons of machine code. Given that Teams is a great target because of it's large and often corporate user base, I'd be surprised if none of the usual industrial espionage suspects (e.g. China, NSA, etc) had a look at Teams before. And I'd think the chance of them having found the same bug, or a related bug, once they looked is pretty good too. From what I am hearing even the (US) military uses Teams sometimes... If that isn't incentive to look at this thing for "interested parties", then I don't know.
- oskarsv 6y agoplease check out how much code MS Teams actually has, before statements like this :) (it’s more than 30MB of compressed JS)
- rndgermandude 6y agoI didn't want to belittle your work, if you think that was the case. It's still outstanding to find things like that on your own, and a lot of work goes into it. Sorry if I gave the wrong impression. I have analyzed foreign code bases of similar dimensions in the past myself and found critical bugs. The size doesn't say much, it comes down to identifying the "interesting" bits (like the electronSafeRpc in this case), which can be hard and tedious, but greatly reduces the code you have to look at in detail. My assertion is that if your name is e.g. China then you will not be turned off by that.
- oskarsv 6y agothat electronSafeIpc API is actually not that interesting and a completely standard way to do things for ElectronJS apps. No, I do agree - from my perspective C/C++ class bugs are more difficult. Maybe they see this as magic as well. Still, it was painstaking work and in either case CountryX will easily surpass those difficulties.
- SkyPuncher 6y ago"Locks can be picked so everyone should break into homes to proved a point" Lol, no.
- the8472 6y agoThat most locks are pickable is common knowledge and that is why high-risk targets invest in additional security beyond locks. That crufty electron apps are a security risk is not. So yes, you do need someone to run out into the streets and yell that the emperor has no clothes. Otherwise common knowledge will not be established.
- Wowfunhappy 6y agoAside from the harm this could inflict on innocent users, I’m not actually convinced it would cause vendors to change their behavior. From a business perspective, the reason exploits are bad for companies is because they generate bad press, right? Well, it's not obvious to me that an exploit which was being used in the wild gets significantly worse press than one which was not. There's also the possibility the buyer will reserve an exploit for super-targeted attacks, and the public won't find out at all until year later.
- coldtea 6y agoYeah, that will show 'em... Then people will move to some understuffed FOSS alternative with 5 people working part-time on it, with as severe bugs that nobody notices (remember Heartbleed and countless others?)...
- higerordermap 6y agoImagine thinking people move to FOSS alternatives. Imagine thinking PHBs at most companies even care about security.
- stjohnswarts 6y agoyou could be a grey hat if you averaged out one exploit turned in to the proper group to one exploit sold to the highest bidder. Flip a coin to be a real greyhat
- mNovak 6y agoIf the bounty money borders on insignificant, there's always public shaming. Demo the exploit in a controlled environment, and let the media cycle go.
- rasz 6y agowhy controlled? Last time some dude got frustrated and started dropping zero days pretty much weekly Microsoft finally hired him to make it stop.
- 314 6y agoSo the people / companies who would be hacked and have their data / systems destroyed are what? Acceptable collateral damage?
- krageon 6y agoNot selling this is the real crime here. Microsoft's conduct in this case deserves much worse than just that. Hoping for a reward now is obviously not going to happen - the best you can hope for as a response to an act like this is legal action. In a vindictive way, you can definitely hope they will get significantly damaged by this and in that way learn their lesson, but I doubt it.
- csnover 6y agoSorry if I am just obtuse but I don’t see a timeline in the linked report on GitHub. All I can see is that you tested against a version of Teams from 2020-08-31. Being able to see the complete timeline of communication with MS from discovery to public disclosure is not necessary but would give a more complete picture of how this went down, and I’d like to see it too if it’s not such a hassle.
- oskarsv 6y agoThere is no timeline besides when I reported it and now minus 2wks. They never told me when the fix was deployed. There is little value in going through the email chains to note each date:(. Final decision was made 2020-11-19
- politelemon 6y agoCould you put that in the README, is what we're asking, as vague as it may be. At the moment the 'has been fixed' is the only clue to this in terms of resolution, and it's tucked away; without it it looks like most of the README is attempting to capitalize on the shock/outrage factor. Edit: Thanks, author has added some dates. https://github.com/oskarsve/ms-teams-rce/commit/35eac619fdef8015b70d8a7119965538daed8e05 https://github.com/oskarsve/ms-teams-rce/commit/35eac619fdef...