SoylentNews
SoylentNews is people
https://soylentnews.org/

Title    In Major Gaffe, Hacked Microsoft Test Account Was Assigned Admin Privileges
Date    Monday January 29 2024, @04:35AM
Author    hubie
Topic   
from the dept.
https://soylentnews.org/article.pl?sid=24/01/28/0657210

upstart writes:

How does a legacy test account grant access to read every Office 365 account?

The hackers who recently broke into Microsoft's network and monitored top executives' email for two months did so by gaining access to an aging test account with administrative privileges, a major gaffe on the company's part, a researcher said.

The new detail was provided in vaguely worded language included in a post Microsoft published on Thursday. It expanded on a disclosure Microsoft published late last Friday. Russia-state hackers, Microsoft said, used a technique known as password spraying to exploit a weak credential for logging into a "legacy non-production test tenant account" that wasn't protected by multifactor authentication. From there, they somehow acquired the ability to access email accounts that belonged to senior executives and employees working in security and legal teams. A "pretty big config error"

In Thursday's post updating customers on findings from its ongoing investigation, Microsoft provided more details on how the hackers achieved this monumental escalation of access. The hackers, part of a group Microsoft tracks as Midnight Blizzard, gained persistent access to the privileged email accounts by abusing the OAuth authorization protcol, which is used industry-wide to allow an array of apps to access resources on a network. After compromising the test tenant, Midnight Blizzard used it to create a malicious app and assign it rights to access every email address on Microsoft's Office 365 email service.

[...] Kevin Beaumont—a researcher and security professional with decades of experience, including a stint working for Microsoft—pointed out on Mastodon that the only way for an account to assign the all-powerful full_access_as_app role to an OAuth app is for the account to have administrator privileges. "Somebody," he said, "made a pretty big config error in production."


Original Submission

Links

  1. "upstart" - https://soylentnews.org/~upstart/
  2. "How does a legacy test account grant access to read every Office 365 account" - https://arstechnica.com/security/2024/01/in-major-gaffe-hacked-microsoft-test-account-was-assigned-admin-privileges/
  3. "published late last Friday" - https://arstechnica.com/security/2024/01/microsoft-network-breached-through-password-spraying-by-russian-state-hackers/
  4. "Thursday's post" - https://www.microsoft.com/en-us/security/blog/2024/01/25/midnight-blizzard-guidance-for-responders-on-nation-state-attack/
  5. "pointed out on Mastodon" - https://cyberplace.social/@GossiTheDog/111823778988979816
  6. "Original Submission" - https://soylentnews.org/submit.pl?op=viewsub&subid=61965

© Copyright 2024 - SoylentNews, All Rights Reserved

printed from SoylentNews, In Major Gaffe, Hacked Microsoft Test Account Was Assigned Admin Privileges on 2024-11-05 22:34:19