In a blog post published on his personal website, Faav described spending the year hacking Microsoft off and on around school, also digging up bugs on platforms from Amazon, Google, Adobe, and others. He developed an AI orchestrator bot called Antares to scan for vulnerabilities and automate security legwork.
The hack began when Antares found an endpoint URL in Titan that displayed an error message stating a VPN was required. Faav instructed the tool to search for subdomains around that endpoint, leading to one hosted on Azure Cloud along with a Swagger/OpenAPI file outlining four API routes. While three of those routes required Azure Active Directory authentication, the fourth, named /v2/Query, did not. This endpoint also accepted raw SQL queries.
Using the Wayback Machine, Faav found a 2023 version of the login page that contained an Apache Superset configuration file detailing the database schema, including 56 table definitions. Initially, the endpoint refused queries due to a missing JSON Web Token (JWT). After 10 days of automated attempts by Antares, Faav realized the server was not verifying the token's digital signature. By forging an administrator's token, he gained access.
Once inside, he executed a "SHOW DATABASES" command and accessed 25,000 employee records, along with organization records, dashboards, and charts. Further exploration of a Bing analytics data source revealed access to 17 trillion rows across multiple tables. Faav said he had to double-check the number to avoid waking his parents at 2 am.
After reporting the issue to Microsoft's bug bounty program, he received $5,000. In his post, Faav emphasized that "AI and human intuition compounded here. Antares did ten days of work I didn't have to ... Its persistence, plus one human hunch, is what made this find possible."