I, Too, Stole a Microsoft 365 Account. Here's How. (Stealing Access Tokens from Office Desktop Apps)

  Рет қаралды 7,606

HuskyHacks

HuskyHacks

Күн бұрын

Attacking & Defending Azure & M365 - Xintra Training: training.xintr...
mrd0x original writeup: mrd0x.com/stea...
TokenFinder: github.com/dor...
I also reimplemented TokenFinder in C#: github.com/Hus...

Пікірлер: 19
@T4tly
@T4tly 10 ай бұрын
Come for the content, but I stay for Cosmo. Top notch stuff as always Matt
@TheRikkieg
@TheRikkieg 5 ай бұрын
Thanks! The information about the jwt token helped me find a big vulnerability
@mrashco
@mrashco 10 ай бұрын
Love your teaching mate! Keep up the great content.
@HAMETE
@HAMETE 10 ай бұрын
Interesting. It's not clear to me what the remediation would be in that case, what kind of protections could be used other than low permissions?
@huskyhacks
@huskyhacks 10 ай бұрын
So it turns out that Microsoft ended up publishing a blog on token theft security last year and they include detection and mitigation guidance for this kind of attack: www.microsoft.com/en-us/security/blog/2022/11/16/token-tactics-how-to-prevent-detect-and-respond-to-cloud-token-theft/ Mitigation is the easier part of the problem and basically boils down to implementing conditional access policies for user logins and revoking refresh tokens if you suspect a user has been compromised. The blog goes into detail on this. Detection is a harder problem to approach and the blog calls out that Entra Identity Protection and Defender for Cloud Apps *should* both catch a token replay attack like this and they can flag it as an anomalous sign-in, but I'm skeptical.
@HAMETE
@HAMETE 10 ай бұрын
@@huskyhacks I will review the article. Thank you very much Husky! 👍
@TAPCybersec
@TAPCybersec 10 ай бұрын
Nice work!
@luckbeforeleap
@luckbeforeleap 5 ай бұрын
Dumping the access tokens is nice but dumping the refresh tokens would be cooler :)
@queenhannah8007
@queenhannah8007 2 ай бұрын
What if we have the access token
@xBXVx97
@xBXVx97 10 ай бұрын
Looking good husky 👍
@huskyhacks
@huskyhacks 10 ай бұрын
tyty king
@whitecyberduck
@whitecyberduck 10 ай бұрын
Very cool!
@PetranEVO
@PetranEVO 10 ай бұрын
Great Video! Thanks for sharing!
@cyberus15
@cyberus15 9 ай бұрын
Doesn't work. even with renewed token it errors out: {"error":{"code":"InvalidAuthenticationToken","message":"Access token validation failure. Invalid audience.","innerError....
@huskyhacks
@huskyhacks 9 ай бұрын
What's the audience for that token and which resource are you trying to access?
@cyberus15
@cyberus15 9 ай бұрын
Not sure about the audience, but the token is for outlook for sure.
@huskyhacks
@huskyhacks 9 ай бұрын
@@cyberus15 Unfortunately, the Outlook API was deprecated sometime last year learn.microsoft.com/en-us/previous-versions/office/office-365-api/api/version-2.0/use-outlook-rest-api You might be able to get lucky and find an older on-prem Exchange server that still uses the API but I haven't tested that. Your best bet is to hunt for Graph API tokens and use those
How hackers are breaking into MFA enabled Microsoft 365 accounts
6:00
7 HIDDEN Apps in Microsoft 365 that will EXPLODE Productivity
28:35
Jonathan Edwards
Рет қаралды 282 М.
VAMPIRE DESTROYED GIRL???? 😱
00:56
INO
Рет қаралды 6 МЛН
Session Vs JWT: The Differences You May Not Know!
7:00
ByteByteGo
Рет қаралды 192 М.
I Took Over a Microsoft Cloud Account. Again.
25:40
John Hammond
Рет қаралды 106 М.
A Boss Reveals Everything Your Company Can Monitor in Microsoft
11:55
Pragmatic Works
Рет қаралды 255 М.
Deep Dive on Microsoft Entra Private Access
1:01:08
John Savill's Technical Training
Рет қаралды 41 М.
Action Required! Major Outlook Security Changes for Personal Accounts
9:01
Why is JWT popular?
5:14
ByteByteGo
Рет қаралды 324 М.
Is Microsoft 365 Email Security Good Enough to Prevent a Cyber Attack?
9:06
Azure Active Directory (AD, AAD) Tutorial | Identity and Access Management Service
30:57
Adam Marczak - Azure for Everyone
Рет қаралды 713 М.
Single and multi-tenant applications in Microsoft Entra ID
1:18:25
Tech Mind Factory
Рет қаралды 15 М.
How 126,000,000 Minecraft Accounts Got Hacked
14:10
Beluga
Рет қаралды 8 МЛН