Live data from Hacker News

Microsoft subdomain takeover

cseo-coherence.microsoft.com

31–40 of 71 posts

Re: Microsoft subdomain takeover

#32

Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?

> [...] the risk of having Microsoft’s army of lawyers throw CFAA at you [...] Especially now that this has been on Hacker News, I don't think even Microsoft is stupid enough to go on the offensive over something like this. The bad press would be so much greater than anything they have to gain.

[deleted]

Re: Microsoft subdomain takeover

#33
I need to start thinking more critically about my passwords being stored on ms edge. Now!

These vulnerabilities are adding so much more fear to.life.

I just got done neutralizing lastpass. And that took a while. I started that back in September.

Re: Microsoft subdomain takeover

#34

Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?

> [...] the risk of having Microsoft’s army of lawyers throw CFAA at you [...] Especially now that this has been on Hacker News, I don't think even Microsoft is stupid enough to go on the offensive over something like this. The bad press would be so much greater than anything they have to gain.

Oracle enters the room...

Re: Microsoft subdomain takeover

#35
post #22

I read 2 examples of the links provided in the archive.today. Is this attack possible because the sub domain is provided by a CDN/S3 (or public cloud in general)? What if it doesn't use any CDN? just plain web server serving the site but no longer available or the web server is down.

Without a shared service like this one, you can also have this happen if you CNAME or NS to a different domain and that domain becomes controlled by someone else (for example, if it expires and is registered by a new person).

Also possible with A/AAAA records, if the IP becomes controlled by someone else, that's less likely if you're self hosted with IPs you were assigned directly by an IP registry, than if you're borrowing IPs from a service provider.

Re: Microsoft subdomain takeover

#37

Wonder if there are any cookies that would be able to access..

By default cookies are scoped to the subdomain only, so while not impossible some other domain would have to go out if it’s way to screw that up

If any cookie is scoped to `microsoft.com` - wouldn't this subdomain be able to access them?

Re: Microsoft subdomain takeover

#38

Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?

These takeovers are often just a case of finding stale DNS entries that are pointed at resources which can be re-allocated by third parties, i.e. elastic IP addresses on AWS. So it's very likely that the person had legit access to that IP, not their fault MS pointed a DNS entry at it when they did not control it.

Re: Microsoft subdomain takeover

#39

Earlier quoted context omitted.

By default cookies are scoped to the subdomain only, so while not impossible some other domain would have to go out if it’s way to screw that up

If any cookie is scoped to `microsoft.com` - wouldn't this subdomain be able to access them?

yes, if the domain parameter of the cookie is explicitly set.

Re: Microsoft subdomain takeover

#40

Earlier quoted context omitted.

> [...] the risk of having Microsoft’s army of lawyers throw CFAA at you [...] Especially now that this has been on Hacker News, I don't think even Microsoft is stupid enough to go on the offensive over something like this. The bad press would be so much greater than anything they have to gain.

Exactly, most PR professionals know about the damaging effect of the Streisand effect. There are better ways to ensure this isolated incident doesn't make it to the press, and deal with the independent researchers accordingly for not going through the proper channels.

The researchers did go through the proper channels, and were ignored.
Post reply on HN