Teenager hacks Microsoft database with access to 17 trillion records

Security researcher Faav exploited a misconfigured API in Microsoft's Titan analytics platform, gaining access to 25,000 employee records and vast amounts of Bing analytics data.

By LineZotpaper
Published
Read Time2 min
A teenage security researcher, known as Faav, has detailed how he hacked into a Microsoft database containing 17 trillion rows of data and 25,000 employee records by exploiting a misconfigured API endpoint in the company's internal Titan analytics platform. The researcher, who used an AI orchestration tool named Antares to automate the tedious parts of the discovery, was awarded $5,000 through Microsoft's bug bounty program.

In a blog post published on his personal website, Faav described spending the year hacking Microsoft off and on around school, also digging up bugs on platforms from Amazon, Google, Adobe, and others. He developed an AI orchestrator bot called Antares to scan for vulnerabilities and automate security legwork.

The hack began when Antares found an endpoint URL in Titan that displayed an error message stating a VPN was required. Faav instructed the tool to search for subdomains around that endpoint, leading to one hosted on Azure Cloud along with a Swagger/OpenAPI file outlining four API routes. While three of those routes required Azure Active Directory authentication, the fourth, named /v2/Query, did not. This endpoint also accepted raw SQL queries.

Using the Wayback Machine, Faav found a 2023 version of the login page that contained an Apache Superset configuration file detailing the database schema, including 56 table definitions. Initially, the endpoint refused queries due to a missing JSON Web Token (JWT). After 10 days of automated attempts by Antares, Faav realized the server was not verifying the token's digital signature. By forging an administrator's token, he gained access.

Once inside, he executed a "SHOW DATABASES" command and accessed 25,000 employee records, along with organization records, dashboards, and charts. Further exploration of a Bing analytics data source revealed access to 17 trillion rows across multiple tables. Faav said he had to double-check the number to avoid waking his parents at 2 am.

After reporting the issue to Microsoft's bug bounty program, he received $5,000. In his post, Faav emphasized that "AI and human intuition compounded here. Antares did ten days of work I didn't have to ... Its persistence, plus one human hunch, is what made this find possible."

§

Analysis

Why This Matters

  • Demonstrates how a combination of AI automation and human intuition can uncover significant security flaws in major tech infrastructure.
  • Highlights the risks of misconfigured APIs and neglected authentication checks, which can expose trillions of records.
  • Shows the value of bug bounty programs in incentivizing ethical disclosure of vulnerabilities, though the $5,000 reward for such a massive breach may raise questions about compensation.

Background

Microsoft's Titan analytics platform is an internal tool used to process and analyze large datasets, including data from services like Bing. The exposed database contained not only employee information but also potentially sensitive analytics data. The vulnerability was discovered by Faav, a teenage security researcher who regularly finds bugs in major companies' systems and uses AI tools to assist in his work. Bug bounty programs like Microsoft's are designed to reward researchers for responsibly reporting vulnerabilities rather than exploiting them maliciously.

Key Perspectives

Faav (Security Researcher): He sees the hack as a collaborative success between his human intuition and automation, and he responsibly disclosed it through Microsoft's bug bounty program. Microsoft: The company has not publicly commented on this specific incident, but its bug bounty program accepted the report and issued a $5,000 reward, indicating it assesses the severity of findings. Security Critics: The $5,000 reward for access to 17 trillion records may be seen as insufficient for the severity of the breach, potentially discouraging some researchers from reporting serious flaws.

What to Watch

  • Whether Microsoft issues a public statement or patches the vulnerability following disclosure.
  • Potential changes to Microsoft's token verification processes to prevent similar JWT bypasses.
  • How other companies may adapt their bug bounty reward structures after seeing the scale of data exposed for a relatively modest payout.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.