Earlier quoted context omitted.
The researchers did go through the proper channels, and were ignored.
Would you feel the same way if it was your computer? Maybe you didn't believe the reported issue was real.
Microsoft subdomain takeover
61–70 of 71 posts
Re: Microsoft subdomain takeover
#62Re: Microsoft subdomain takeover
#63Security vulnerabilities due to resource reuse (subdomain takeover is just one example of this) are rampant and readily exploitable for tons of major companies, especially as cloud providers and SaaS often overlook these as being client responsibilities. Shameless plug, I’ve worked on identifying/characterizing these issues on cloud providers: https://arxiv.org/pdf/2204.05122.pdf It’s only a matter of time before adv…
When your paper came out some media articles made it sound like you invented the method, as you didn't bother to cite the original finder.
I know, academics don't like to cite "gray literature". But that's really not ok.
Re: Microsoft subdomain takeover
#64Re: Microsoft subdomain takeover
#65Security vulnerabilities due to resource reuse (subdomain takeover is just one example of this) are rampant and readily exploitable for tons of major companies, especially as cloud providers and SaaS often overlook these as being client responsibilities. Shameless plug, I’ve worked on identifying/characterizing these issues on cloud providers: https://arxiv.org/pdf/2204.05122.pdf It’s only a matter of time before adv…
As you plug this paper, I should point out that it's really bad behavior to not cite prior work. The original idea of subdomain takeover was by Frans Rosén: https://labs.detectify.com/2014/10/21/hostile-subdomain-take... When your paper came out some media articles made it sound like you invented the method, as you didn't bother to cite the original finder. I know, academics don't like to cite "gray literature". But…
Re: Microsoft subdomain takeover
#66Earlier quoted context omitted.
The researchers did go through the proper channels, and were ignored.
Would you feel the same way if it was your computer? Maybe you didn't believe the reported issue was real.
Then you should still check to make sure the issue isn't there.
Re: Microsoft subdomain takeover
#67Congrats to https://trufflesecurity.com/ The email rejection's tone is weird.
If it hadn't taken them almost a year and actual subdomain takeover to fix it, I might be inclined to believe them.
Re: Microsoft subdomain takeover
#68I want to click the red button. so bad.
It plays the song Turn Down for What and the whole page starts shaking lol
Re: Microsoft subdomain takeover
#69Earlier quoted context omitted.
It is harmless fun.
what a missed rick-roll opportunity