5 ms·
That’s a scary vulnerability. There’s no mention of the bug bounty paid out for it but I hope it was substantial.
by stirlo 2y ago
That’s a scary vulnerability. There’s no mention of the bug bounty paid out for it but I hope it was substantial.
- belter 2y agoIt's a feature not a bug: "Azure’s Security Vulnerabilities Are Out of Control" - https://www.lastweekinaws.com/blog/azures_vulnerabilities_are_quack/ https://www.lastweekinaws.com/blog/azures_vulnerabilities_ar...
- SideburnsOfDoom 2y agoAt least this new one seems to have been fixed within two months: 6 Jan to Feb 20th.
- eitland 2y ago> Let’s start with some empathy, because let’s face it: Nobody sets out to build something insecure except maybe a cryptocurrency exchange. :-)
- belter 2y agoNobody sets out to build something insecure but if they go with Azure.... "Microsoft confirms partial loss of security log data on multiple platforms" - https://www.cybersecuritydive.com/news/microsoft-loss-security-log-data/730285/ https://www.cybersecuritydive.com/news/microsoft-loss-securi... "Microsoft called out for ‘blatantly negligent’ cybersecurity practices" - https://www.theverge.com/2023/8/3/23819237/microsoft-azure-breach-blatantly-negligent-cybersecurity-practices https://www.theverge.com/2023/8/3/23819237/microsoft-azure-b...
- Daedren 2y agoWell at the bottom of the article, they mention that Microsoft first closed the issue as invalid, and on the second attempt they closed it as "cannot be reproduced" (after fixing it). So from that I can imply there was no payment.
- eitland 2y agoI've reported a trivial way to infer details about passwords in Windows. (Ctrl-arrow in password fields in Windows 8 jumped by character group even when hidden so if a prefilled password was 123 abc.de it would stop after 3, after space (I think), after c, after dot and finally after e.) All I got was an email: that is interesting bye bye. But it was fixed in the next patch or the next after I think. So I didn't care to report the two bigger problems I found with Azure Information Protection [1][2] I thought about reporting them but decided against it. And I will continue to tell people that I don't care to do free work for MS when they won't even give me a t-shirt, a mug or even acknowledge it. Maybe if one is a security researcher it can be worth it but if you just find something interesting you'll probably be better rewarded by reddit or HN, yes, the upvotes are worthless but less so than a dismissive email. [1] one in the downloadable AIP tooling where you can easily smuggle clear text information with rock solid plausible deniability - I found it by accident after having implemented a part of a pipeline in the most obvious way I could think of. [2]: the second had to do with how one can configure SharePoint to automatically protect files with AIP on download, the only problem being if you logged in using another login sequence (sorry for the lack of details, this was before the pandemic and it was just a small part of what I was working on at the time) SharePoint would conveniently forget all about it despite all efforts by me, the security admin at the company and the expert that Microsoft sent to fix it.
- franktankbank 2y ago> the expert that Microsoft sent to fix it. Ha ... ha ... ha ... ha ... did they give you the run around for several months until you dropped the issue? It's actually pretty astounding that they don't get sued for this practice. If a company is paying for support and are given illiterate noobs then that is breach of contract I would think. I would never recommend entering a contract with MSFT, they produce trash products they can't support and are more invested in their Legal team than actual product.
- RajT88 2y agoI thought the same when a friend of mine reported something to Apple. I would guess it's SOP at this point across big tech, unless something is too big to ignore.
- IcyWindows 2y agoThe caller still needs at least the Reader role, so it was limited to accounts that were added to the Azure subscription as only Readers. I'm glad they fixed it, but this doesn't seem too scary??
- bradford 2y agoSuppose user U has read access to Subscription S, but doesn't have access to keyvault K. If user U can gain access to keyvault K via this exploit, it is scary. [Vendors/Contingent staff will often be granted read-level access to a subscription under the assumption that they won't have access to secrets, for example.] (I'm open to the possibility that I'm misunderstanding the exploit)
- hland 2y agoYour take is spot on, sir.
- p_ing 2y agoMy reading on this is that the Reader must have read access to the API Connection in order to drive the exploit [against a secure resource they lack appropriate access to]. But a user can have Reader rights on the Subscription which does cascade down to all objects, including API Connections.
- dh2022 2y agoBut also the API connection seems to have secret reader permissions as per screenshot in the article… Giving secret reader permission to another resource seems to be the weak link.
- p_ing 2y agoThe API Connection in a Logic App contains a secret in order to read/write (depending on permission) a resource. Could be a Key Vault secret, Azure App Service, Exchange Online mailbox, SharePoint Online site..., etc. The secret typically is a user account (OAuth token), but it could also be an App Id/Secret.