Teen researcher accessed Microsoft Titan data through a platform flaw
The route reached employee records and Bing analytics data, putting stored company information at risk.
Teenage researcher Faav found a route into Microsoft's Titan analytics platform that accepted raw SQL, exposing a serious risk to data stored there. The server's responses suggested it was not checking JWT signatures; Faav then supplied a token identifying him as an administrator and gained entry. The database held 25,000 employee records, organizational information, dashboards and charts, while Bing analytics tables added up to 17 trillion records. Microsoft paid Faav a $5,000 bug bounty after he reported the vulnerability.
Why it matters
For employees represented in Titan, the incident showed that data held there could be reached by someone presenting an administrator token the server appeared not to verify. Microsoft paid Faav for reporting the flaw, but the verified facts do not say whether the route was closed.
Signal or noise?
Does this story matter, or is it hype? Decide before you see what everyone else thinks.
Sources
- Tom's Hardware