7 ms·
Microsoft mishandling example.com
- godzillabrennus 8mo agoThis is the same company that mishandled the Office brand (abandoned it) and is mishandling the Xbox brand (what even is an Xbox anymore?). Are we surprised?
- deleted 8mo ago[deleted]
- rurban 8mo agoNSA probably. Gives them plausible deniability. Maybe some of their targets did use example.com for some probing, and the NSA had a hand in Sumitomo Electric Industries' mail server.
- whizzter 8mo agoReading the article, there is a huge flaw in the autodiscover protocol by Microsoft. https://www.akamai.com/blog/security/autodiscovering-the-great-leak https://www.akamai.com/blog/security/autodiscovering-the-gre... According to it, it seems that if someone registers autodiscover.com then example.com lacking autodiscover.example.com will make Outlook try checking if autodiscover.com has an entry. It's just a braindead system.
- deleted 8mo ago[deleted]
- irusensei 8mo agoNot surprised. They used to have training material incentivizing professionals to use .local as TLD for Active Directory realms. Thats a reserved domain for Multicast DNS. Working on Linux automation systems we would need to make sure to disable anything related to Avahi in our images otherwise name resolution would fail for some customers.
- szszrk 8mo agoMy company used .local for EVERYTHING. I took it as normal at the time, until I got into problems with VMWARE products. Support patiently explained .local is reserved for something else and kindly provided Wikipedia links. They never responded why they used .local in their docs, trainings, webinars they provided, though :)
- irusensei 8mo agoMy impression is that Ballmer IE6 era Microsoft didn't gave a shit about standards.
- jve 8mo agoIs standard you are talking about is Multicast DNS https://www.rfc-editor.org/rfc/rfc6762 https://www.rfc-editor.org/rfc/rfc6762 from year 2013?
- PcChip 8mo agoI’ve worked with hundreds of customers that use .local internal domains and vmware, what issues are you describing?
- EvanAnderson 8mo agoThings from docs making it into production is insidious. There were some early Sun docs that referenced a 129.9.0.0/16 network. Some helpful contractor in my locality, specializing in local government work, configured several police, fire, and city governments with that subnet internally back in the 90s. A few of them are still running that way today. I remember running into some oddball behavior with the Teredo adapter in Windows 7 that I traced back to it behaving differently because the PC's IP address didn't fall into RFC1918 space.
- somat 8mo agoMakes me remember the 192.1 addresses that were all over at one place I worked. "Um you know that is a valid internet address right?" "Yeah, but the guy who originally set the systems up was confused about the private address space, used the wrong one and we don't want to break anything so are not going to change it" Good times.
- hu3 8mo agoThis is why I never use these IANA-reserved domains like .test, .example, .invalid, .localhost. I always make up some impossible domains like domain.tmptest Otherwise you're one DNS "misconfiguration" away from sending dev logs and auth tokens to some random server. > Since at least February 2020, Microsoft's Autodiscover service has incorrectly routed the IANA-reserved example.com to Sumitomo Electric Industries' mail servers at sei.co.jp, potentially sending test credentials there.
- whizzter 8mo ago.example is probably far safer than example.com. https://www.akamai.com/blog/security/autodiscovering-the-great-leak https://www.akamai.com/blog/security/autodiscovering-the-gre... According to it, it seems that if someone registers autodiscover.com then example.com lacking autodiscover.example.com will make Outlook try checking if autodiscover.com has an entry. It's just a braindead system.
- jsheard 8mo agoIt's all fun and games until Donuts buys .tmptest for some reason.
- wongarsu 8mo agobrb, just filing paperwork to apply for the .tmptest gTLD /s
- lagniappe 8mo agoI suspect you'd download a car.
- ThePowerOfFuet 8mo ago$100K
- thequux 8mo ago$227k just to apply, and another few hundred thousand in legal, compliance, and contracting to reach delegation. Source: I'm on the board of dotMeow and wrote the financial plan
- andreldm 8mo agoThat’s why example.com states “Avoid use in operations”, not only that could create unnecessary traffic for them as well as leak information as in situations like this.
- charles_f 8mo agoYeah, it feels more like a safety net than something you should purposefully use
- binaryturtle 8mo agoWhy do you need to send a password when using their Autodiscover API? Would Outlook send the respective passwords for each email account to Microsoft?
- philipwhiuk 8mo agoI suspect they try to login and reverse engineer the IMAP config.
- Neil44 8mo agocurl -u just requires the field to be there, I suspect. No authentication takes place. You can send any password and the output doesn't change.
- GranPC 8mo ago> Microsoft's Autodiscover service misconfiguration can be confirmed via curl -v -u "email@example.com:password" "https://prod.autodetect.outlook.cloud.microsoft/autodetect/detect?app=outlookdesktopBasic https://prod.autodetect.outlook.cloud.microsoft/autodetect/d..." Wait, does their autodetect send email and password to their servers, instead of just domain???
- deleted 8mo ago[deleted]
- stronglikedan 8mo agoSee replies to a similar question here (in case you haven't already): https://news.ycombinator.com/item?id=46732623 https://news.ycombinator.com/item?id=46732623
- technion 8mo agoAutodiscover has always been an interesting security problem. I wrote this years ago: https://lolware.net/blog/2020-09-02-autodiscover-circus/ https://lolware.net/blog/2020-09-02-autodiscover-circus/
- gruez 8mo ago>Microsoft's Autodiscover service misconfiguration can be confirmed via curl -v -u "email@example.com:password" "https://prod.autodetect.outlook.cloud.microsoft/autodetect/detect?app=outlookdesktopBasic https://prod.autodetect.outlook.cloud.microsoft/autodetect/d...": Hold up, does this mean outlook sends your full credentials to Microsoft when you try to set up an outlook account? I'm sure they pinky promise they keep your credentials secure, but this feels like it breaks all sorts of security/privacy expectations.
- thedanbob 8mo agoIt's more common than you might think. I know of at least one popular email client that stores your credentials on their servers to enable features like multi-account sync and scheduled sending.
- spiffyk 8mo agoI would expect such a feature to use end-to-end encryption for the data, so that only the user can see the credentials. It does, right? Right?
- gruez 8mo ago>>multi-account sync and scheduled sending >I would expect such a feature to use end-to-end encryption for the data How would "end-to-end encryption" when such features by definition require the server to have access to the credentials to perform the required operations? If by "end to end" you actually mean it's encrypted all the way to the server, that's just "encryption in transit".
- treyd 8mo ago> If by "end to end" you actually mean it's encrypted all the way to the server, that's just "encryption in transit". This is what Zoom claimed was e2ee for a little while before getting in trouble for it.
- Thaxll 8mo agoWhere does sei.co.jp comes from? Why Microsoft would use that domain in the first place?
- irusensei 8mo agoIt's not really the domain but the registration in the MS Office Cloud. If you query who owns example.com mail you get that company.
- Daviey 8mo agoI'm willing to bet they were the first user to try and add example.com to their Outlook account, and MS then just assigned it to them without verifying they own the domain.
- onionisafruit 8mo agoI gather this has little to do with “example.com” and more to do with any domain that doesn’t have an autodiscover subdomain.
- butz 8mo agoNice to see tinyapps.org is still alive.
- emmelaich 8mo ago> The domain has a null MX record (indicating it doesn't accept email) Not quite true, SMTP will use the A record if there is no MX.
- dpifke 8mo agoIn this case, "null MX record" means MX exists, but does not specify a valid server: $ host -t mx example.com example.com mail is handled by 0 . Senders should not fall back on the A record in this case.
- philo23 8mo agoJust a guess but why do I get the feeling it’s because someone who setup sei.co.jp in Azure Entra (aka Azure AD) some how managed to add/claim the domain “example.com” against their companies tenant. It’s clearly not using the DNS records for discovery because they don’t exist, the only other option I can see is some weird fall through or hard coded value and it seems like an odd one to pick.
- 1vuio0pswjnm7 8mo agoNow that example.com is hidden behind Cloudflare, how does the public know who is controlling the origin servers The IPv4 for example.com used to be 93.184.216.34 Was there an announcement somewhere
- 1vuio0pswjnm7 8mo agoThe old nameservers for example.com still have not updated their zone files dq a example.com 199.43.135.53