Live data from Hacker News

Microsoft subdomain takeover

cseo-coherence.microsoft.com

21–30 of 71 posts

Re: Microsoft subdomain takeover

#22
I read 2 examples of the links provided in the archive.today. Is this attack possible because the sub domain is provided by a CDN/S3 (or public cloud in general)? What if it doesn't use any CDN? just plain web server serving the site but no longer available or the web server is down.

Re: Microsoft subdomain takeover

#23

Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?

> is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?

Well, previously I'd never heard of Truffle Security, but now I have. So ... maybe?

Re: Microsoft subdomain takeover

#26

Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?

> is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?

Microsoft has Safe Harbor.

Re: Microsoft subdomain takeover

#27

Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?

> [...] the risk of having Microsoft’s army of lawyers throw CFAA at you [...]

Especially now that this has been on Hacker News, I don't think even Microsoft is stupid enough to go on the offensive over something like this. The bad press would be so much greater than anything they have to gain.

Re: Microsoft subdomain takeover

#28
Security vulnerabilities due to resource reuse (subdomain takeover is just one example of this) are rampant and readily exploitable for tons of major companies, especially as cloud providers and SaaS often overlook these as being client responsibilities.

Shameless plug, I’ve worked on identifying/characterizing these issues on cloud providers: https://arxiv.org/pdf/2204.05122.pdf

It’s only a matter of time before adversaries become more sophisticated at identifying and exploiting these in bulk.

Re: Microsoft subdomain takeover

#29

Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?

> [...] the risk of having Microsoft’s army of lawyers throw CFAA at you [...] Especially now that this has been on Hacker News, I don't think even Microsoft is stupid enough to go on the offensive over something like this. The bad press would be so much greater than anything they have to gain.

Exactly, most PR professionals know about the damaging effect of the Streisand effect. There are better ways to ensure this isolated incident doesn't make it to the press, and deal with the independent researchers accordingly for not going through the proper channels.
Post reply on HN