Microsoft Subdomains Have A Massive Security Loophole, Leading To Cyber Attacks!

Microsoft subdomains are being sued for broadcasting spammy content, attacks and various other cyber attacks as pointed out by a researcher. What's more concerning that despite notifying the company multipole times, vulnerability is fixed only in 5% - 10% subdomains .

Must Read

Apple Store In India: More Of Disappointment Than Excitement?

Apple has started making moves to strengthen its presence in India. With the launch of Apple online...

Windfall! Online Grocery Market In India Looks Set For Purple Patch Ahead

Silver linings are clearly in short supply in the pandemic fuelled world that we have come to...

Facebook’s Chasm Of Distrust: An Ever-Deepening Divide

Facebook, the world's most popular social media platform has failed measurably as it is voted as the...

A security researcher has pointed out the fact that Microsoft’s thousands of subdomains are prone to many vulnerabilities which can be taken advantage of. These subdomains can be hijacked and used for attacks against their own employees, users or for showing them spammy content according to him.

Michel Gaschet, the security researchers, is also a developer for NIC.gp brought this issue to light. Whilst in an interview with ZDNet, he mentioned that he has been reporting these subdomains to Microsoft for the past three years. However, either most of his reporting has been repeatedly been ignored or Microsoft has been fixing some of them silently. He believes that these subdomains have misconfigured DNS records.

Advertisements

Gaschet also privately shared a list of 117 microsoft.com subdomains, he reported to Microsoft last year, with ZDNet. The security researcher said he reported 21 msn.com subdomains that were vulnerable to hijacks to Microsoft in 2017 and then another 142 misconfigured microsoft.com subdomains in 2019.

Source: ZDnet

However, only 5-10% of all the subdomains he collectively reported were addressed and fixed by Microsoft whereas the others still remain misconfigured. It was noticed by him that subdomains such as cloud.microsoft.com and account.dpedge.microsft are more prioritised over the others as they are big. Hence, the other subdomains remain exposed to hijacking vulnerabilities.

These subdomains which are vulnerable to potential hijacks are because of basic misconfigurations in their respective DNS entries. A 2014 blog post from Detecify in 2014 explained the same in-depth.

“The root cause/mistake is a forgotten DNS entry pointing to something that doesn’t exist anymore, or never existed, like a typo in the DNS entry content,” Gaschet told ZDNet.

These misconfigured subdomains stayed the same because Microsoft never had to deal with any problems even though they were very much a sweet spot for attacking. In a hypothetical situation, an overly malicious attacker could have possibly taken over one of these subdomains whilst prompting Microsoft users to log in through a phishing page and collect their login credentials. Luckily enough Microsoft, no such malicious and dangerous attacker or group noticed this loophole but on the other hand, there are some who figured it out.

Source: ZDNet

It was reportedly pointed out on Twitter by Gaschet that one spam group figured out that they could hijack Microsoft’s subdomains and therefore, boost their spammy content by hosting it on a reputable domain.

Advertisements

Several ads for Indonesian poker casinos on at least four legitimate Microsoft subdomains were spotted which included portal.ds.microsoft.com, perfect10.microsoft.com, ies.global.microsoft.com, and blog-ambassadors.microsoft.com. Gaschet says these spammy advertisements are still very much active.

Microsoft has been reached out to for a comment regarding the same but we are still to be heard back from.

Microsoft’s Take On These Security Loopholes

One of the possible reasons as guessed by Gaschet that Microsoft is still not prioritizing these subdomain fixes could be because of the fact that the company’s bug bounty program doesn’t yet include these ‘subdomain’ takeovers’.

Therefore, the reporting of such issues get lined up way down in their priority list despite these issues being very severe. Microsoft, the multinational tech behemoth has been asked to revamp how it manages its DNS records, wherein lies the source of most of these misconfigurations by Gaschet.

It’s high time that Microsoft takes notice of this problem as it is easier to get rid of it while alarms are still going off and not after the situation has worsened.

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest News

Windfall! Online Grocery Market In India Looks Set For Purple Patch Ahead

Silver linings are clearly in short supply in the pandemic fuelled world that we have come to...

$4.6 Billion Incentive For Companies To Push Electric Vehicle Adoption In India

The Electric Vehicle (EV) market in India is at a nascent stage. So far, the sales of EVs have been encouraging, albeit...

Amazon Luna Is Here To Eat Into The Cloud Gaming Market, Dominated By Google And Microsoft

The cloud gaming space has been one of the key interest areas of Amazon for quite some time. Today, the eCommerce giant...

Facebook’s Chasm Of Distrust: An Ever-Deepening Divide

Facebook, the world's most popular social media platform has failed measurably as it is voted as the least trusted social media platform...

With 9.8 Million Users Coursera Observes Boom Of Online Education In India

The global outbreak of Covid-19 has changed the lifestyle of people and almost every industry has resorted to online in a bid...

TikTok Oracle Deal: An Eyewash Or Mockery?

On Saturday, within few hours of US Department of Commerce announcing the ban on TikTok that would prevent users to download TikTok...

In-Depth: Dprime

Will ‘TikTok By Microsoft’ Be A Winner?

For the last two years, TikTok has been in the public eye for all sorts of reasons. First, it was the exploded...

Facebook Subscription Model: Looking Beyond Ad Dollars?

Seldom do job listings create a stir this gripping. However, when the job listing in question is a stealth post from Twitter,...

Will The Online Food Delivery Market in India End Up Becoming A Two-Horse Race?

It's pretty much evident that the food delivery space in India is all set to get riled up soon enough as one...

More Articles Like This