Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Protection

Misconfigured Database Exposed Microsoft Site to Attacks

A researcher discovered that a database connected to the mobile version of Microsoft’s careers website was not properly configured, potentially allowing malicious actors to abuse it for various purposes.

A researcher discovered that a database connected to the mobile version of Microsoft’s careers website was not properly configured, potentially allowing malicious actors to abuse it for various purposes.

According to Chris Vickery, a researcher who over the past months discovered hundreds of millions of records exposed online due to misconfigured databases, unauthenticated attackers could have accessed and modified the content of a MongoDB database maintained by mobile web development firm Punchkick Interactive for Microsoft’s careers site (m.careersatmicrosoft.com).

Vickery, who recently joined MacKeeper, found that the database contained the details of some Microsoft employees, including their name, email address, password hash and token.

Another problem was that since the database was not write-protected, an attacker could have inserted arbitrary HTML code. This could have been exploited to host a phishing page or to launch watering hole attacks against the site’s visitors.

The vulnerability was reported to Punchkick on February 5 and it was resolved within an hour, Vickery said. The web development firm told the expert that the misconfigured database is a separate service that is “consumed” by the mobile version of Microsoft’s careers website.

Contacted by SecurityWeek, Microsoft said it was made aware of the issue, and confirmed that it was addressed. However, Vickery believes the database was left unprotected for at least a few weeks.

“The lesson to learn here is that if you’re a big name player like Microsoft, it’s acceptable for third-parties to handle mundane operations like job posting webpages. But be aware that a hole in the third-party’s security can quickly become a hole in your security,” the researcher noted in a blog post.

Last month, Vickery warned that hackers can abuse misconfigured enterprise printers for storage. The expert’s analysis focused on HP printers, which are accessible over port 9100 and provide an anonymous FTP server to malicious actors.

Advertisement. Scroll to continue reading.

Related: Leaky Databases Expose 25 Million Accounts

Related: Second Database Exposing Voter Records Found Online

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.

Compliance

The three primary drivers for cyber regulations are voter privacy, the economy, and national security – with the complication that the first is often...

Data Protection

While quantum-based attacks are still in the future, organizations must think about how to defend data in transit when encryption no longer works.

Application Security

Virtualization technology giant VMware on Tuesday shipped urgent updates to fix a trio of security problems in multiple software products, including a virtual machine...

Application Security

Fortinet on Monday issued an emergency patch to cover a severe vulnerability in its FortiOS SSL-VPN product, warning that hackers have already exploited the...

Cybersecurity Funding

Los Gatos, Calif-based data protection and privacy firm Titaniam has raised $6 million seed funding from Refinery Ventures, with participation from Fusion Fund, Shasta...