Live data from Hacker News

Microsoft subdomain takeover

cseo-coherence.microsoft.com

61–70 of 71 posts

Re: Microsoft subdomain takeover

#61
post #41

Earlier quoted context omitted.

The researchers did go through the proper channels, and were ignored.

Would you feel the same way if it was your computer? Maybe you didn't believe the reported issue was real.

What do you mean "your computer"? They didn’t do anything to Microsoft’s computer. Or am I misunderstanding something?

Re: Microsoft subdomain takeover

#63

Security vulnerabilities due to resource reuse (subdomain takeover is just one example of this) are rampant and readily exploitable for tons of major companies, especially as cloud providers and SaaS often overlook these as being client responsibilities. Shameless plug, I’ve worked on identifying/characterizing these issues on cloud providers: https://arxiv.org/pdf/2204.05122.pdf It’s only a matter of time before adv…

As you plug this paper, I should point out that it's really bad behavior to not cite prior work. The original idea of subdomain takeover was by Frans Rosén: https://labs.detectify.com/2014/10/21/hostile-subdomain-take...

When your paper came out some media articles made it sound like you invented the method, as you didn't bother to cite the original finder.

I know, academics don't like to cite "gray literature". But that's really not ok.

Re: Microsoft subdomain takeover

#65
post #63

Security vulnerabilities due to resource reuse (subdomain takeover is just one example of this) are rampant and readily exploitable for tons of major companies, especially as cloud providers and SaaS often overlook these as being client responsibilities. Shameless plug, I’ve worked on identifying/characterizing these issues on cloud providers: https://arxiv.org/pdf/2204.05122.pdf It’s only a matter of time before adv…

As you plug this paper, I should point out that it's really bad behavior to not cite prior work. The original idea of subdomain takeover was by Frans Rosén: https://labs.detectify.com/2014/10/21/hostile-subdomain-take... When your paper came out some media articles made it sound like you invented the method, as you didn't bother to cite the original finder. I know, academics don't like to cite "gray literature". But…

they have a page on background. Have you considered that there is no malintent?

Re: Microsoft subdomain takeover

#66
post #41

Earlier quoted context omitted.

The researchers did go through the proper channels, and were ignored.

Would you feel the same way if it was your computer? Maybe you didn't believe the reported issue was real.

> Maybe you didn't believe the reported issue was real

Then you should still check to make sure the issue isn't there.

Re: Microsoft subdomain takeover

#67

Congrats to https://trufflesecurity.com/ The email rejection's tone is weird.

What do you find weird in the tone? I find it succinct, confirming they were already aware of the issue and that they are already working on a (bulk) solution.

If it hadn't taken them almost a year and actual subdomain takeover to fix it, I might be inclined to believe them.

Re: Microsoft subdomain takeover

#68
post #4

I want to click the red button. so bad.

It plays the song Turn Down for What and the whole page starts shaking lol

While we were waiting for our friend in the ER (she's fine), one of us downloaded an app that was a giant red button like that one and that's all it played, TURN DOWN FOR WHAT! And you could press it a bunch so it's like "TTTT TTT TT URN URN DOWWN FFFOORR WHAT WHAT! The nurses enjoyed it

Re: Microsoft subdomain takeover

#69
post #10
post #8

Earlier quoted context omitted.

It is harmless fun.

what a missed rick-roll opportunity

It is possible that there can be divided in to 2 groups the people in this world: 1 who's first thought given this opportunity is to rick roll the eff outa the situation, and another group that for some reason wouldn't.
Post reply on HN