TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Microsoft subdomain takeover

271 点作者 kailanb超过 2 年前

19 条评论

ericpauley超过 2 年前
Security vulnerabilities due to resource reuse (subdomain takeover is just one example of this) are rampant and readily exploitable for tons of major companies, especially as cloud providers and SaaS often overlook these as being client responsibilities.<p>Shameless plug, I’ve worked on identifying&#x2F;characterizing these issues on cloud providers: <a href="https:&#x2F;&#x2F;arxiv.org&#x2F;pdf&#x2F;2204.05122.pdf" rel="nofollow">https:&#x2F;&#x2F;arxiv.org&#x2F;pdf&#x2F;2204.05122.pdf</a><p>It’s only a matter of time before adversaries become more sophisticated at identifying and exploiting these in bulk.
评论 #34307592 未加载
评论 #34305910 未加载
npteljes超过 2 年前
Archive, because it has already been fixed by MS:<p><a href="https:&#x2F;&#x2F;archive.ph&#x2F;DEzVW" rel="nofollow">https:&#x2F;&#x2F;archive.ph&#x2F;DEzVW</a>
评论 #34305802 未加载
simlevesque超过 2 年前
Congrats to <a href="https:&#x2F;&#x2F;trufflesecurity.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;trufflesecurity.com&#x2F;</a><p>The email rejection&#x27;s tone is weird.
评论 #34308473 未加载
评论 #34306632 未加载
jiggawatts超过 2 年前
The shameful thing about this is that I get &quot;subdomain takeover&quot; warning emails from Azure on a regular basis. Microsoft has a ton of automation around this for their customers already.
0xfffafaCrash超过 2 年前
Isn’t Truffle Security opening themselves up to litigation from this? It’s harmless, but is the risk of having Microsoft’s army of lawyers throw CFAA at you really worth this?
评论 #34304844 未加载
评论 #34304135 未加载
评论 #34303941 未加载
评论 #34304131 未加载
评论 #34305743 未加载
metadat超过 2 年前
Is this an example of the attack in the wild? Or what did I just view?
评论 #34303492 未加载
评论 #34296251 未加载
nashashmi超过 2 年前
I need to start thinking more critically about my passwords being stored on ms edge. Now!<p>These vulnerabilities are adding so much more fear to.life.<p>I just got done neutralizing lastpass. And that took a while. I started that back in September.
评论 #34305645 未加载
eyelidlessness超过 2 年前
I got to see it in the wild, and it was magnificent. Glad they fixed it, for users I hope it was as holistic as they claimed it would be.
smileybarry超过 2 年前
Now it&#x27;s a different kind of broken as HTTP redirects to HTTPS and refuses to connect due to HSTS mismatch.
breakingcups超过 2 年前
Wonder if there are any cookies that would be able to access..
评论 #34304111 未加载
AviationAtom超过 2 年前
Looks like th subdomain hadn&#x27;t been used in about two years:<p><a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20190501000000*&#x2F;http:&#x2F;&#x2F;cseo-coherence.microsoft.com" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20190501000000*&#x2F;http:&#x2F;&#x2F;cseo-cohe...</a>
_trampeltier超过 2 年前
Again?!? Here an article from 2020.<p><a href="https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;microsoft-has-a-subdomain-hijacking-problem&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;microsoft-has-a-subdomain-hija...</a><p>2019: Microsoft loses control over Windows Tiles subdomain<p><a href="https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;microsoft-loses-control-over-windows-tiles-subdomain&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.zdnet.com&#x2F;article&#x2F;microsoft-loses-control-over-w...</a>
评论 #34306298 未加载
zakki超过 2 年前
I read 2 examples of the links provided in the archive.today. Is this attack possible because the sub domain is provided by a CDN&#x2F;S3 (or public cloud in general)? What if it doesn&#x27;t use any CDN? just plain web server serving the site but no longer available or the web server is down.
评论 #34304463 未加载
chollida1超过 2 年前
Can someone explain this? The link just 404&#x27;s
评论 #34306207 未加载
mehrzad超过 2 年前
Windows Store individual links don&#x27;t seem to work for me. I have to search them up in the home page.
hoseja超过 2 年前
Airtight hatchway guys!
lukew3超过 2 年前
Looks like it&#x27;s been fixed. Here&#x27;s the archived page: <a href="https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20230107222311&#x2F;http:&#x2F;&#x2F;cseo-coherence.microsoft.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;web.archive.org&#x2F;web&#x2F;20230107222311&#x2F;http:&#x2F;&#x2F;cseo-coher...</a>
评论 #34303835 未加载
评论 #34304183 未加载
demarq超过 2 年前
I want to click the red button.<p>so bad.
评论 #34304121 未加载
评论 #34303500 未加载
评论 #34303507 未加载
评论 #34303499 未加载
评论 #34303681 未加载
jmull超过 2 年前
Don&#x27;t click that red button... ;)
评论 #34303698 未加载
评论 #34303666 未加载