ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough
1–10 of 35 posts
Re: ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough
#2 > August 17 2021 - MSRC awarded $40,000 bounty for the report.
I don't know much about the bug bounty industry, is this the typical payout from what it seems to be a pretty severe vulnerability?Re: ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough
#3> August 17 2021 - MSRC awarded $40,000 bounty for the report. I don't know much about the bug bounty industry, is this the typical payout from what it seems to be a pretty severe vulnerability?
Re: ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough
#4> August 17 2021 - MSRC awarded $40,000 bounty for the report. I don't know much about the bug bounty industry, is this the typical payout from what it seems to be a pretty severe vulnerability?
Re: ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough
#5Re: ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough
#6> August 17 2021 - MSRC awarded $40,000 bounty for the report. I don't know much about the bug bounty industry, is this the typical payout from what it seems to be a pretty severe vulnerability?
For example, person that reported the two major Microsoft Exchange vulnerability chains received no payout at all.
Ref: https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-ProxyL...
Re: ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough
#7> August 17 2021 - MSRC awarded $40,000 bounty for the report. I don't know much about the bug bounty industry, is this the typical payout from what it seems to be a pretty severe vulnerability?
The part that's contraversial about the MS bounties is that they stopped covering the majority of on-premise products. For example, person that reported the two major Microsoft Exchange vulnerability chains received no payout at all. Ref: https://i.blackhat.com/USA21/Wednesday-Handouts/us-21-ProxyL...
Re: ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough
#8> August 17 2021 - MSRC awarded $40,000 bounty for the report. I don't know much about the bug bounty industry, is this the typical payout from what it seems to be a pretty severe vulnerability?
Yes, quite large. Next HN will say how many billions they could afford to pay because of all the potential damage. If it's hard to make sense, the security guard at the bank doesn't get paid a % of the money if they stop a robbery and many other examples off payout being way less than potential damage caused.
Re: ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough
#9Given that much of attack is related to rhings not exclusive it CosmosDB, firewall, internal service and certificate, it’s likely that other services may be at risk as well.
Generally, because so many flaws are involved, this cannot be easy to fix.
Re: ChaosDB Explained: Azure's Cosmos DB Vulnerability Walkthrough
#10This vulnerability, and especially its handling by Microsoft, were the final nail in the coffin for us and we've put in the effort to migrate away.