Microsoft subdomain takeover
31–40 of 71 posts
Re: Microsoft subdomain takeover
#32Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?
> [...] the risk of having Microsoft’s army of lawyers throw CFAA at you [...] Especially now that this has been on Hacker News, I don't think even Microsoft is stupid enough to go on the offensive over something like this. The bad press would be so much greater than anything they have to gain.
Re: Microsoft subdomain takeover
#33These vulnerabilities are adding so much more fear to.life.
I just got done neutralizing lastpass. And that took a while. I started that back in September.
Re: Microsoft subdomain takeover
#34Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?
> [...] the risk of having Microsoft’s army of lawyers throw CFAA at you [...] Especially now that this has been on Hacker News, I don't think even Microsoft is stupid enough to go on the offensive over something like this. The bad press would be so much greater than anything they have to gain.
Re: Microsoft subdomain takeover
#35I read 2 examples of the links provided in the archive.today. Is this attack possible because the sub domain is provided by a CDN/S3 (or public cloud in general)? What if it doesn't use any CDN? just plain web server serving the site but no longer available or the web server is down.
Also possible with A/AAAA records, if the IP becomes controlled by someone else, that's less likely if you're self hosted with IPs you were assigned directly by an IP registry, than if you're borrowing IPs from a service provider.
Re: Microsoft subdomain takeover
#36Re: Microsoft subdomain takeover
#37Wonder if there are any cookies that would be able to access..
By default cookies are scoped to the subdomain only, so while not impossible some other domain would have to go out if it’s way to screw that up
Re: Microsoft subdomain takeover
#38Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?
Re: Microsoft subdomain takeover
#39Earlier quoted context omitted.
By default cookies are scoped to the subdomain only, so while not impossible some other domain would have to go out if it’s way to screw that up
If any cookie is scoped to `microsoft.com` - wouldn't this subdomain be able to access them?
Re: Microsoft subdomain takeover
#40Earlier quoted context omitted.
> [...] the risk of having Microsoft’s army of lawyers throw CFAA at you [...] Especially now that this has been on Hacker News, I don't think even Microsoft is stupid enough to go on the offensive over something like this. The bad press would be so much greater than anything they have to gain.
Exactly, most PR professionals know about the damaging effect of the Streisand effect. There are better ways to ensure this isolated incident doesn't make it to the press, and deal with the independent researchers accordingly for not going through the proper channels.