字号 ·· | 护眼
theregister

16岁研究员发现微软漏洞,获得对拥有17.3万亿行数据库的管理员访问权限16-year-old researcher found a Microsoft bug, got admin access to databases with 17.3 trillion rows

点「原文对照」整页切到原文,或双击某段只看那段的原文。

一名名为Faav的16岁安全研究员在微软的Titan分析服务中发现了一个认证漏洞,该漏洞使他能够获得管理员访问权限、在无有效凭证的情况下提交未经授权的SQL查询,并可能访问包含估计17.3万亿存储行的分析数据库。Titan是一个内部分析平台,微软通过其Web界面将访问权限限制为仅限微软员工。Faav在其自建的名为Antares的AI黑客机器人协助下发现,他可以通过Azure云服务主机访问Titan的API,因为Titan未检查令牌上的签名。

A 16-year-old security researcher named Faav found an authentication flaw in Microsoft’s Titan analytics service that allowed him to gain administrator access, submit unauthorized SQL queries with no valid credentials, and potentially reach analytics databases containing an estimated 17.3 trillion stored rows. Titan is an internal analytics platform, and Redmond restricts access via its web interface to Microsoft employees. Faav, with an assist from an AI hackbot he built called Antares, found that he could access Titan’s API through an Azure Cloud Services host because Titan didn’t check the signature on a token.

微软此后已锁定该API,并因其研究向Faav支付了5000美元的漏洞赏金。他表示,突破发生在经历了10天的认证错误后,周五完成学业作业后他重新投入研究,最终在周六凌晨1点后成功以Titan管理员身份执行了SQL。“当时是凌晨2点,”Faav在其关于发现的博客中写道。“我想大喊一声,或者至少说点什么,但父母都睡了。所以我只是坐在那里盯着17,333,335,124,315这个数字,反复核对计算。”

Microsoft has since locked down the API and paid Faav a $5,000 bug bounty for his research. He says the breakthrough came after 10 days of authentication errors, when he returned to the problem after finishing Friday’s schoolwork and finally managed to execute SQL as a Titan admin after 1 AM Saturday. “It was 2 AM,” Faav said in a blog about his findings. “I wanted to yell, or at least say something out loud, but my parents were asleep. So I just sat there staring at 17,333,335,124,315 and checked the math again.”

他还指出,应微软要求重写了博客文章,删减了部分章节和数字,并在发布前重述了影响范围。“我们感谢Faav报告的发现给我们提供的调查机会,”微软在提供给Faav博客的声明中表示。“他们的提交和协调漏洞披露帮助我们通过强化服务来更好地保护客户。我们重视并感谢在微软漏洞赏金计划条款下进行的安全研究,并期待未来继续与Faav合作。”一个男孩和他的机器人研究始于8月25日,当时Antares发现了Titan的公开API。

He also notes that he rewrote his blog post at Microsoft’s request, cut sections and numbers, and reworded the impact prior to publication. “We appreciate the opportunity to investigate the findings reported by Faav,” Microsoft said in a statement provided to Faav for his blog. “Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services. We value and appreciate safe security research under the terms of the Microsoft Bug Bounty Program and look forward to continuing to work with Faav in the future.”A boy and his bot The research began on August 25 when Antares found Titan’s public API.

在接下来的 10 天里,这名人类研究员和机器人测试了该服务的 JSON Web Token (JWT) 认证检查和采用电子邮件格式的用户主体名称 (UPN),最终发现了一个未签名的令牌,它能到达 Titan 的本地用户查找功能——但找不到 Titan 能识别的 UPN。9 月 5 日早些时候,Faav 将未签名令牌的 UPN 从采用电子邮件格式的身份改为了 admin。

For the next 10 days, the human and bot tested the service’s JSON Web Token (JWT) authentication checks and email-formatted user principal names (UPNs), eventually finding an unsigned token that could reach Titan’s local user lookup - but not a UPN that Titan recognized. Early on September 5, Faav changed the unsigned token’s UPN from an email-formatted identity to admin.

Titan 将其识别为本地用户名,将其解析为持有管理员角色的本地用户 ID 1,并允许他运行 SQL。根据 Faav 的说法,教训是:Titan 验证了 JWT 的内容(租户、受众、应用 ID、用户),但从未验证签名,而这是任何认证检查中最重要的部分。这些认证检查就像一家酒店,每扇门都装有工作正常的刷卡器,但任何一张门卡都能打开任何房间。

Titan recognized it as a local username, resolved it to local user ID 1, which held an admin role, and allowed him to run SQL. The takeaway, according to Faav: Titan validated the contents of the JWT (tenant, audience, app ID, user) but never verified the signature, the most important part of any authentication check. The authentication checks felt like a hotel where every door had a working keycard reader, but any keycard unlocked any room.

尽管应用中存在所有访问控制逻辑,但缺少的这一环让一切都变得毫无意义。如果你是正在阅读此文的开发者(或编码代理),从这篇文章中得到的最重要的教训是:在构建认证系统时,务必首先确保验证签名。

Despite all the access-control logic existing in the app, the one missing piece made it all pointless. If you’re a developer (or coding agent) reading this, the most important takeaway from this post is to make sure you verify signatures above all else when building auth.

这使 Faav 获得了对 Titan 平台元数据库的访问权限,从那里他可以直接查询应用表。元数据包含:约 25,000 条账户和电子邮件记录。17,990 条员工电子邮件记录。15,001 条员工组织记录。355 个数据库配置。20,979 个虚拟数据集 SQL 定义。

24,569 个仪表板、425,891 个图表和 27,347 个数据集定义。

This gave Faav access to Titan’s platform metadata database, and from there he could query application tables directly. The metadata contained: About 25,000 account and email records. 17,990 employee email records. 15,001 employee organization records. 355 database configurations. 20,979 virtual-dataset SQL definitions. 24,569 dashboards, 425,891 charts, and 27,347 dataset definitions.

Titan 的用户和使用目录暴露了员工职位、部门和管理层级,研究人员指出这可能对社会工程学攻击有用——“尽管我从未测试或演示过这一点,”他补充道。他还发现了一个必应分析样本,并测试了包含搜索信息、标识符和高级位置信息(如国家或州级详细信息)的两行数据。Faav 表示,这些位置值不包含精确的用户位置。

Titan’s user and usage directory exposed employee job titles, departments, and management hierarchy, which the researcher notes could be useful for social-engineering attacks - “though I never tested or demonstrated that,” he added. He also found a Bing analytics sample and tested two rows that contained search info, identifiers, and high-level location information, such as country- or state-level details. Faav said the location values did not contain precise user locations. 17.3 trillion data rows Then he hit the jackpot, testing 56 routing values from an archived configuration and discovering 30 were still active.

17.3万亿行数据 随后他中了大奖,从一份归档配置中测试了56个路由值,发现其中30个仍处于活跃状态。“每个路由值指向一个后端配置,而每个配置包含一个或多个数据库,因此这30个活跃值通过24个配置解析到17个连接的分析数据库,涵盖9,863个唯一表名,”这位漏洞猎人写道。总计约17.3万亿行,Faav表示这是基于元数据得出的存储估算,可能包含历史、重复和衍生数据。

“Each routing value pointed to a backend configuration, and each configuration contained one or more databases, so the 30 live values resolved through 24 configurations to 17 connected analytics databases spanning 9,863 unique table names,” the bug hunter wrote. The total comes to about 17.3 trillion rows, which Faav says is a storage estimate derived from metadata and likely includes historical, duplicated, and derived data.

“但无论如何这是一个相当高的数字。” 9月6日至9月8日期间,微软要求这名少年停止测试,并索要其IP地址,以确认除漏洞赏金研究外无其他恶意活动。一天后,微软锁定了该端点,并告知Faav“该报告促使立即展开调查和修复,以解决剩余的暴露问题。” 9月17日,微软因其工作奖励了该漏洞猎人5000美元。®

“But quite the high number nonetheless.”Between September 6 and September 8, Microsoft asked the teen to stop testing and requested his IP address to confirm no nefarious activity beyond the bug bounty research. A day later, Redmond locked down the endpoint and told Faav the “report prompted immediate investigation and remediation to address the remaining exposure.”Microsoft awarded the bug hunter $5,000 for his work on September 17.®