Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
15 Indlæg 15 Posters 0 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.socialG This user is from outside of this forum
    gossithedog@cyberplace.social
    wrote sidst redigeret af
    #1

    A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

    They paid him $5000 and told nobody about it.

    https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

    rtificial@infosec.exchangeR nigel@unsociable.lowkey.partyN spartan_1986@infosec.exchangeS generalx@freeradical.zoneG donhawkins@mastodon.socialD 13 Replies Last reply
    1
    0
    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

      A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

      They paid him $5000 and told nobody about it.

      https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

      rtificial@infosec.exchangeR This user is from outside of this forum
      rtificial@infosec.exchangeR This user is from outside of this forum
      rtificial@infosec.exchange
      wrote sidst redigeret af
      #2

      @GossiTheDog they are some real scum bags with their bug bounty program. Trying to give him the run around with that finding and some chump change

      1 Reply Last reply
      0
      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

        A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

        They paid him $5000 and told nobody about it.

        https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

        nigel@unsociable.lowkey.partyN This user is from outside of this forum
        nigel@unsociable.lowkey.partyN This user is from outside of this forum
        nigel@unsociable.lowkey.party
        wrote sidst redigeret af
        #3

        @GossiTheDog sounds like the dark web would pay better.

        1 Reply Last reply
        0
        • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

          A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

          They paid him $5000 and told nobody about it.

          https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

          spartan_1986@infosec.exchangeS This user is from outside of this forum
          spartan_1986@infosec.exchangeS This user is from outside of this forum
          spartan_1986@infosec.exchange
          wrote sidst redigeret af
          #4

          @GossiTheDog Irresponsible non disclosure.

          justinderrick@mstdn.caJ 1 Reply Last reply
          0
          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

            A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

            They paid him $5000 and told nobody about it.

            https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

            generalx@freeradical.zoneG This user is from outside of this forum
            generalx@freeradical.zoneG This user is from outside of this forum
            generalx@freeradical.zone
            wrote sidst redigeret af
            #5

            @GossiTheDog
            And the most egregious error:

            The frontend had a scary "VPN REQUIRED" page to keep out the hackers.

            Seems it was only a recommendation.

            1 Reply Last reply
            0
            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

              A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

              They paid him $5000 and told nobody about it.

              https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

              donhawkins@mastodon.socialD This user is from outside of this forum
              donhawkins@mastodon.socialD This user is from outside of this forum
              donhawkins@mastodon.social
              wrote sidst redigeret af
              #6

              @GossiTheDog @gooser3000 Isn’t that “special”.

              1 Reply Last reply
              0
              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

                They paid him $5000 and told nobody about it.

                https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

                S This user is from outside of this forum
                S This user is from outside of this forum
                spacelifeform@infosec.exchange
                wrote sidst redigeret af
                #7

                @GossiTheDog

                Copilot should have found this. /s

                1 Reply Last reply
                0
                • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                  A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

                  They paid him $5000 and told nobody about it.

                  https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

                  gaoadriaan@social.vivaldi.netG This user is from outside of this forum
                  gaoadriaan@social.vivaldi.netG This user is from outside of this forum
                  gaoadriaan@social.vivaldi.net
                  wrote sidst redigeret af
                  #8

                  @GossiTheDog

                  1 Reply Last reply
                  0
                  • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                    A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

                    They paid him $5000 and told nobody about it.

                    https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

                    chx@chx.contactC This user is from outside of this forum
                    chx@chx.contactC This user is from outside of this forum
                    chx@chx.contact
                    wrote sidst redigeret af
                    #9

                    @GossiTheDog good thing they didn't give him a mcdonalds voucher

                    1 Reply Last reply
                    0
                    • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                      A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

                      They paid him $5000 and told nobody about it.

                      https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

                      djl@mastodon.mit.eduD This user is from outside of this forum
                      djl@mastodon.mit.eduD This user is from outside of this forum
                      djl@mastodon.mit.edu
                      wrote sidst redigeret af
                      #10

                      @GossiTheDog

                      I'd guess that _all_ the "AI agent hacks computer system" instances were exactly and only incompetent security on the part of the hacked system.

                      When "Internet of things" was a thing, I was terrified, because you can't make and sell an internet-connected thing at a price such that you can afford to implement decent security in it.

                      1 Reply Last reply
                      0
                      • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                        A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

                        They paid him $5000 and told nobody about it.

                        https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

                        pouakai@mastodon.socialP This user is from outside of this forum
                        pouakai@mastodon.socialP This user is from outside of this forum
                        pouakai@mastodon.social
                        wrote sidst redigeret af
                        #11

                        @GossiTheDog
                        This clever hacker also leverage Codex and Claude during hacking, orchestrated by a customised AI Antares.
                        if this guy call LLM #aislop and refused to use, the good thing probably won't happen

                        1 Reply Last reply
                        0
                        • spartan_1986@infosec.exchangeS spartan_1986@infosec.exchange

                          @GossiTheDog Irresponsible non disclosure.

                          justinderrick@mstdn.caJ This user is from outside of this forum
                          justinderrick@mstdn.caJ This user is from outside of this forum
                          justinderrick@mstdn.ca
                          wrote sidst redigeret af
                          #12

                          @Spartan_1986 @GossiTheDog Paying next months rent vs. Paying next year’s rent.

                          1 Reply Last reply
                          0
                          • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                            A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

                            They paid him $5000 and told nobody about it.

                            https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

                            luna@mastodon.worldL This user is from outside of this forum
                            luna@mastodon.worldL This user is from outside of this forum
                            luna@mastodon.world
                            wrote sidst redigeret af
                            #13

                            @GossiTheDog Why do they need to.keep 17 trillion records?

                            1 Reply Last reply
                            0
                            • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                              A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

                              They paid him $5000 and told nobody about it.

                              https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

                              bassrck5000@mstdn.socialB This user is from outside of this forum
                              bassrck5000@mstdn.socialB This user is from outside of this forum
                              bassrck5000@mstdn.social
                              wrote sidst redigeret af
                              #14

                              @GossiTheDog

                              1 Reply Last reply
                              0
                              • gossithedog@cyberplace.socialG gossithedog@cyberplace.social

                                A 16 year old boy hacked an internal Microsoft system called TITAN with 17 trillion records as it didn’t validate JWT signatures at all, accepted ‘admin’ as authentication without a password and was internet facing.

                                They paid him $5000 and told nobody about it.

                                https://blog.faav.net/how-i-couldve-accessed-17-trillion-microsoft-records

                                xs4me2@mastodon.socialX This user is from outside of this forum
                                xs4me2@mastodon.socialX This user is from outside of this forum
                                xs4me2@mastodon.social
                                wrote sidst redigeret af
                                #15

                                @GossiTheDog

                                “Shall we play a game?”

                                1 Reply Last reply
                                0
                                • pelle@veganism.socialP pelle@veganism.social shared this topic
                                Svar
                                • Svar som emne
                                Login for at svare
                                • Ældste til nyeste
                                • Nyeste til ældste
                                • Most Votes


                                • Log ind

                                • Login or register to search.
                                Powered by NodeBB Contributors
                                Graciously hosted by data.coop
                                • First post
                                  Last post
                                0
                                • Hjem
                                • Seneste
                                • Etiketter
                                • Populære
                                • Verden
                                • Bruger
                                • Grupper