A security researcher, known as Faav, discovered a significant vulnerability in Microsoft's internal analysis tool called Titan. This tool is used to manage and analyze large amounts of data. The flaw allowed Faav to access multiple databases containing more than 17,300 billion lines of data, though this number reflects the total volume of data stored, not the number of people affected. The vulnerability stemmed from a weakness in Titan's authentication system, which failed to verify the cryptographic signature of a JWT (JSON Web Token) used for access. This allowed Faav to create a fake token and impersonate an administrator, gaining access to the databases.
The web interface for Titan is only accessible to Microsoft employees who are connected to the company's internal network through a virtual private network (VPN). However, the API (Application Programming Interface), which allows programs to interact with the service, is accessible over the Internet. One of the API's functions allows users to send direct SQL queries to the databases, but it requires knowledge of the table names. Faav used the Wayback Machine, a website that archives historical versions of web pages, to find definitions of 56 tables from old versions of Titan dating back to 2023. This information helped him identify the necessary table names for his queries.
The API requires a connection token that includes user information and a cryptographic signature to verify the user's authenticity. Over ten days, Faav systematically modified the information in the token and observed the server's responses. He found that while Titan checked the content of the token, it never verified the cryptographic signature. This allowed Faav to create a token without a signature, which Titan still accepted. The final step was to provide a recognized username. After testing various email addresses without success, Faav tried "admin" during the night of September 5, and the system recognized him as the main administrator.
Faav accessed a database containing approximately 25,000 accounts, nearly 18,000 employee email addresses, and part of the company's organizational chart, along with data from Bing analysis. Microsoft confirmed the vulnerability and blocked access to the API on September 9. Faav received a $5,000 reward under Microsoft's bug bounty program and stated that he did not extract any data and saw no evidence that hackers had exploited the vulnerability.
Microsoft Internal Service Vulnerability Exposed by Security Researcher
AI-rewritten from original reportingHow it works
microsoftsecurity-vulnerabilitybug-bountydata-accessjwt-tokencybersecurity



