Microsoft has a subdomain hijacking problem
#1
Quote:A security researcher has pointed out today that Microsoft has a problem in managing its thousands of subdomains, many of which can be hijacked and used for attacks against users, its employees, or for showing spammy content.
The issue has been brought up today by Michel Gaschet, a security researcher and a developer for NIC.gp.
In an interview with ZDNet, Gaschet said that during the past three years, he's been reporting subdomains with misconfigured DNS records to Microsoft, but the company has either been ignoring reports or silently securing some subdomains, but not all.
RESEARCHER: ONLY 5%-10% GOT FIXEDGaschet says he reported 21 msn.com subdomains that were vulnerable to hijacks to Microsoft in 2017 [12], and then another 142 misconfigured microsoft.com subdomains in 2019 [12].
Further, the researcher also privately shared with ZDNet another list of 117 microsoft.com subdomains that he also reported to Microsoft last year.
 Of all the reported misconfigured subdomains, Gaschet told ZDNet that Microsoft only addressed a few. The researcher puts the number at somewhere between 5% and 10% of all the subdomains he reported.
BLAME DNS MISCONFIGURATIONSGaschet told ZDNet the OS maker usually fixes big subdomains, like cloud.microsoft.com and account.dpedge.microsoft.com, but leaves the other subdomains exposed to hijacks.
The researcher said that most of the Microsoft subdomains are vulnerable to basic misconfigurations in their respective DNS entries. The researcher says this 2014 blog postfrom Detectify explains the problem in depth.
"The root cause/mistake is a forgotten DNS entry pointing to something that doesn't exist anymore, or never existed, like a typo in the DNS entry content," Gaschet told ZDNet.
SUBDOMAIN HIJACKS LEAD TO SPAM ON MICROSOFT.COMBut until now, these misconfigurations have never caused Microsoft any problems or headaches, despite being an attractive attack surface.



Source
[-] The following 1 user says Thank You to ttyx for this post:
  • harlan4096
Reply


Messages In This Thread
Microsoft has a subdomain hijacking problem - by ttyx - 19 February 20, 02:07

Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Ibotta Referral Code [ZVFTJQW]: Get an $...
By using the exclusi...Jini777 — 20:17
Working Ibotta Promo Code [ZVFTJQW]: Get...
If you are in the US...Jini777 — 20:15
Surfshark VPN : Award-winning VPN servi...
How can generative...jasonX — 09:58
Surfshark VPN : Award-winning VPN servi...
What is post-quant...jasonX — 09:50
Adobe Acrobat Reader DC 2026.001.21411
Adobe Acrobat Read...harlan4096 — 09:47

[-]
Birthdays
Today's Birthdays
No birthdays today.
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (38)RobertUtelt

[-]
Online Staff
There are no staff members currently online.

>