Microsoft subdomain takeover
21–30 of 71 posts
Re: Microsoft subdomain takeover
#22Re: Microsoft subdomain takeover
#23Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?
Well, previously I'd never heard of Truffle Security, but now I have. So ... maybe?
Re: Microsoft subdomain takeover
#24Wonder if there are any cookies that would be able to access..
Re: Microsoft subdomain takeover
#25I want to click the red button. so bad.
Re: Microsoft subdomain takeover
#26Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?
Microsoft has Safe Harbor.
Re: Microsoft subdomain takeover
#27Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?
Especially now that this has been on Hacker News, I don't think even Microsoft is stupid enough to go on the offensive over something like this. The bad press would be so much greater than anything they have to gain.
Re: Microsoft subdomain takeover
#28Shameless plug, I’ve worked on identifying/characterizing these issues on cloud providers: https://arxiv.org/pdf/2204.05122.pdf
It’s only a matter of time before adversaries become more sophisticated at identifying and exploiting these in bulk.
Re: Microsoft subdomain takeover
#29Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?
> [...] the risk of having Microsoft’s army of lawyers throw CFAA at you [...] Especially now that this has been on Hacker News, I don't think even Microsoft is stupid enough to go on the offensive over something like this. The bad press would be so much greater than anything they have to gain.
Re: Microsoft subdomain takeover
#30Looks like it's been fixed. Here's the archived page: https://web.archive.org/web/20230107222311/http://cseo-coher...
Now the CNAME is pointing to redirect-dns.msftdomains.com.