TE
TechEcho
Home
24h Top
Newest
Best
Ask
Show
Jobs
English
GitHub
Twitter
Home
Weirdest Bug Bounty – Getting PII from Office365
28 points
by
mbaye
about 5 years ago
2 comments
ipython
about 5 years ago
I'm confused about the ntlm hashes - so it sounds like there is some service that contacts the auto-generated guid domain and sends legit SMB traffic to it? That seems really odd? I'd be curious to hear more about that.
maallooc
about 5 years ago
Collapse
Wow. That’s textbook bad engineering. Could’ve done guid.nonexistanttld but they just had to do guid.com!
评论 #22728431 未加载