Teenager hacks open Microsoft database with 17 trillion total rows and 25,000 user accounts
Teenager cracks open Microsoft database with 17 trillion total rows and 25,000 user accounts — lack of JWT token validation yields a fruitful trove
In a recent hacking incident, a bored teenager named Faav managed to breach a Microsoft database containing trillions of records and 25,000 user accounts. The story began when Faav, who had been hacking Microsoft and other tech giants intermittently throughout the year, discovered a flaw in Microsoft's Titan analytics platform user validation.
Using his AI-powered bot, Antares, Faav scanned for vulnerabilities in the platform's endpoint URL and found one that required a VPN. Intrigued, he had Antares search for subdomains, eventually discovering a Swagger/OpenAPI file listing four routes. One of these routes, /v2/Query, accepted raw SQL queries without requiring authentication.
After learning about the database schema through a 2023 login page and the Azure Active Directory, Faav used Antares to test the server's response, which suggested that digital signature checks were not being performed on access tokens. With this insight, Faav assumed the role of an administrator and gained access to the database.
Within minutes, he accessed 25,000 employee records, organizational data, dashboards, and charts. Further exploration revealed a data source for Bing analytics, and after tallying rows across tables, Faav realized he had access to 17 trillion records. He promptly reported the breach to Microsoft's bug bounty program and received a $5,000 reward for his efforts.
In his blog post, Faav credited AI and human intuition for the success of his hack, highlighting how Antares' persistent efforts combined with a human hunch led to this significant discovery.
Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.