TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Microsoft Live Account Credentials Leaking from Windows 8 and Above

233 pointsby aurhumalmost 9 years ago

19 comments

Nokinsidealmost 9 years ago
As a Linux user I have kept Windows 7 &amp; 8 partitions in my laptop and workstation disks for years because there used to be time where you needed Windows in the work for some programs to work and some documents to open.<p>Windows 10 upgrade push made me to realize that that time passed a long time ago. Last time I booted to Windows for other reason than playing a game was seven years ago. LibreOffice works well with MS documents and you can always use them from Google drive.<p>Windows has lost it&#x27;s grip for good.
评论 #12210813 未加载
评论 #12209461 未加载
评论 #12209868 未加载
评论 #12210371 未加载
评论 #12210546 未加载
评论 #12210592 未加载
评论 #12209458 未加载
评论 #12209708 未加载
评论 #12213903 未加载
pjc50almost 9 years ago
And people wonder why some of us haven&#x27;t upgraded from Windows 7.<p>Win10 tries <i>really hard</i> to make you log into your desktop with your Live Account credentials - you can&#x27;t use the store without this. Whereas if it were just leaking a local login it would be much less critical.
评论 #12209001 未加载
评论 #12209083 未加载
评论 #12208974 未加载
评论 #12210845 未加载
评论 #12209294 未加载
评论 #12208949 未加载
评论 #12208981 未加载
评论 #12209723 未加载
besselheimalmost 9 years ago
Until a fix is released, this can be mitigated by blocking outbound TCP connections on ports 139 and 445.<p>Individual users can do this using by setting up suitable outbound rules in the Windows Firewall with Advanced Security snap-in (wf.msc).
评论 #12209716 未加载
oneplanealmost 9 years ago
Somehow I&#x27;m not surprised, neither by the way it&#x27;s broken nor the neglect on Microsofts part on this issue...<p>Pretty much every non-standard Microsoft-only approach to things seem to be broken one way or another, only to be fixed after someone threatens to expose and exploit it. I know it&#x27;s gotten better in recent years, but the fact that it&#x27;s still something that seems to be pushing from the outside in, instead of being part of the manufacturer&#x27;s culture is shining through rather harshly.
JBiserkovalmost 9 years ago
Microsoft should fix this ASAP.<p>You should enable Two-factor Authentication (2FA) on your account.<p><a href="https:&#x2F;&#x2F;support.microsoft.com&#x2F;en-us&#x2F;help&#x2F;12408&#x2F;microsoft-account-about-two-step-verification" rel="nofollow">https:&#x2F;&#x2F;support.microsoft.com&#x2F;en-us&#x2F;help&#x2F;12408&#x2F;microsoft-acc...</a>
评论 #12209317 未加载
option_greekalmost 9 years ago
I thought they started fresh with Edge browser by keeping it away from windows&#x2F;OS specific stuff. Apparently not.
评论 #12209052 未加载
评论 #12218183 未加载
be5invisalmost 9 years ago
Tested using Edge on r14393, and the demo returns “Not vulnerable”. There is a SEC7111 error in the console.
Kenjialmost 9 years ago
tl;dr: Simply accessing a website with Edge leaks the user name and password hash to the attacker site. They mention that this is also default behaviour in Spartan, Internet Explorer, Outlook (though I do not know how effectively it can be delivered to something like Outlook).<p>Works on up to date Windows 10 and Edge (there is an online test if you&#x27;re vulnerable). If you don&#x27;t use the listed software, you&#x27;re probably completely safe (maybe there is other Microsoft software that does this, though?). If you don&#x27;t use your Microsoft Live Account as a Windows account, you&#x27;re safe (someone then just finds out the hash of your local password).<p>EDIT: Interestingly, Edge on the Xbox One is not vulnerable. It seems like the behaviour on the console is different.
评论 #12209301 未加载
评论 #12208851 未加载
评论 #12209870 未加载
drzaiusapelordalmost 9 years ago
&gt;Edge, Spartan, Internet Explorer (just saying..)<p>Why does he keep repeating &quot;Spartan?&quot; That was Edge&#x27;s codename. Now its just Edge. Is he&#x27;s referring to the engine that can be embedded into other applications? If so, its called EdgeHTML.
overlordalexalmost 9 years ago
The articles recommends that you &quot;strengthen your Microsoft Live account password&quot;, but if I understand the vulnerability it is only exposing the hash of your password?<p>If it&#x27;s only exposing the hash, why should you make your password stronger?
评论 #12208877 未加载
评论 #12209605 未加载
评论 #12208876 未加载
评论 #12210125 未加载
NKCSSalmost 9 years ago
This is fun to write for yourself; small SMB client to couple a unique file request to the credentials and website showing the info retrieved via SMB; I think I found my weekend project :)
评论 #12223716 未加载
robododoalmost 9 years ago
Just to clarify the article a bit:<p>Your password hash is not sent over the wire. What is sent over the wire is the NTLMv2 response message. This, simplified, is: HMAC_MD5(Hash | challenge). If you want the gory details, check out MS-NLMP.<p>That said, a dictionary-attackable password + attacker with fast GPUs can still brute-forcing the HMAC, then attack the password hash (MD4). It&#x27;s a bit harder than just banging on a simple hash, though not terrifically difficult.
batratalmost 9 years ago
Did the test with edge and it doesn&#x27;t work. I&#x27;m on stable build. Also it needs edge&#x2F;ie to be able to do the test...
评论 #12211053 未加载
pvdebbealmost 9 years ago
Is the NTLMv2 hash even salted?
评论 #12209504 未加载
chocolatebunnyalmost 9 years ago
Does this affect Microsoft software on macs? We use Outlook on our macbooks at work and I&#x27;m wondering if a single mass email can get everyone&#x27;s Exchange password, or at least the md5sum of their passwords.
billpgalmost 9 years ago
Have Microsoft confirmed the issue or planned to roll out a fix?
wangchowalmost 9 years ago
Anyone know if this affects Windows phone 10? It also uses all of the mentioned software.
评论 #12223720 未加载
jason46almost 9 years ago
Is signed into Cortana and the Windows store synonymous?
anc84almost 9 years ago
Huh, their evile 31337 haxx0r background looks like a blatant copyright violation. It&#x27;s artwork based on a video game cover. Previously also &quot;stolen&quot; by the BBC: <a href="http:&#x2F;&#x2F;www.gamesradar.com&#x2F;wait-did-bbc-use-thief-art-illustrate-story-about-hacker&#x2F;" rel="nofollow">http:&#x2F;&#x2F;www.gamesradar.com&#x2F;wait-did-bbc-use-thief-art-illustr...</a> (since then apparently replaced, <a href="http:&#x2F;&#x2F;www.bbc.com&#x2F;news&#x2F;technology-33442419" rel="nofollow">http:&#x2F;&#x2F;www.bbc.com&#x2F;news&#x2F;technology-33442419</a> )<p>Also available for illegitimate at <a href="http:&#x2F;&#x2F;www.shutterstock.com&#x2F;pic-389962378&#x2F;stock-photo-hacker-and-computer-virus-concept.html" rel="nofollow">http:&#x2F;&#x2F;www.shutterstock.com&#x2F;pic-389962378&#x2F;stock-photo-hacker...</a> or <a href="http:&#x2F;&#x2F;www.shutterstock.com&#x2F;pic-345906527&#x2F;stock-photo-dangerous-hacker-stealing-data-concept.html" rel="nofollow">http:&#x2F;&#x2F;www.shutterstock.com&#x2F;pic-345906527&#x2F;stock-photo-danger...</a>
评论 #12209720 未加载