3 ms·
A rooted phone would be enough to gain access without needing to brute force guess passwords. The rooted phone could just force a prompt for the user to supply
by dhx 3y ago
A rooted phone would be enough to gain access without needing to brute force guess passwords. The rooted phone could just force a prompt for the user to supply their password again for an application such as Teams, and this password could then be captured as well as the key used to derive new TOTP values.
Hence there is seemingly some other weakness allowing login to a corporate Microsoft e-mail account. For example, a method to enrol a second/additional TOTP generator by only knowing an account password and not needing to supply an existing TOTP code. Or a "lost my phone that generates TOTP codes" recovery process. Or for example, a Kerberos ticket accepted by Exchange can be obtained using a method that only needs a valid password and not a TOTP code?
- devbent 3y ago> Hence there is seemingly some other weakness allowing login to a corporate Microsoft e-mail account. Why the hence? Why not just root some MS employees not fully patched android phone while they cross a border? Or just bribe an intern.