TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Weirdest Bug Bounty – Getting PII from Office365

28 pointsby mbayeabout 5 years ago

2 comments

ipythonabout 5 years ago
I'm confused about the ntlm hashes - so it sounds like there is some service that contacts the auto-generated guid domain and sends legit SMB traffic to it? That seems really odd? I'd be curious to hear more about that.
maalloocabout 5 years ago
Wow. That’s textbook bad engineering. Could’ve done guid.nonexistanttld but they just had to do guid.com!
评论 #22728431 未加载