Get all your news in one place.
100's of premium titles.
One app.
Start reading
The Economic Times
The Economic Times

How a 16-year-old researcher hacked into Microsoft analytics service holding 17 trillion rows of data

An internal Microsoft analytics service with more than 17 trillion rows of data was reportedly compromised by a 16-year-old security researcher who discovered a critical flaw that could have been exploited by attackers.

As reported by Help Net Security, the flaw was found in Microsoft's Titan service by the teenager, who goes by the name Faav. He reportedly discovered the vulnerability using an automated bug-hunting tool he built himself.

“Faav found that Titan did not verify the signature on login tokens. That let him pose as the service’s administrator and run SQL queries against 17 connected databases holding an estimated 17.3 trillion rows,” the report said.

During his research, Faav also gained access to a Bing analytics source containing search, identifier and location fields. The location values showed country- or state-level information derived from reverse IP lookups, he explained.

Because MUIDs, identifiers that Microsoft stores in users’ browsers, appeared in more than one dataset, it was possible that user activity could have been correlated across services, Faav was quoted as saying.

Notably, Faav said he never accessed customer data or personally identifiable information (PII). He also did not use the two Bing samples to identify anyone, link records between datasets or build user profiles.

Microsoft responds

After the vulnerability came to light on September 5, Microsoft's Security Response Center (MSRC) asked Faav to stop testing and requested his IP address to confirm that there had been no activity beyond his research.

The endpoint was locked down on September 9, and Faav received a $5,000 bounty from Microsoft on September 17.

“We appreciate the opportunity to investigate the findings reported by Faav. Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services. We value and appreciate safe security research under the terms of the Microsoft Bug Bounty Program and look forward to continuing to work with Faav in the future,” Microsoft said in a statement.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.