// Hacking NEWS // How a Hacker Hijacked the Windows Tiles

in #news5 years ago

Microsoft forgot to remove DNS redirection from an old web service. A stupid mistake that allowed to redirect his domain name to another content, potentially malicious.

140717-193471-193469_rc.jpg
Windows tiles are under influence - Hanno Böck / Martin Wolf

The info

The hacker Hanno Böck has successfully hacked Windows Live Tiles, a technology that Microsoft introduced with Windows 8 that allows websites to display notifications in Start menu tiles using XML tags.

These feeds could be created through a Microsoft web service that is no longer active but whose domain (notifications.buildmypinnedsite.com) still exists and could be hijacked to other potentially malicious content. The hacker took the opportunity to display skulls.

This technique is usually known as "subdomain takeover," an important attack vector that can usually be found in the way most online services allow their users to run web apps or blogs with a custom domain name.

"We have informed about this problem but have not received it yet," Böck said. "Once we cancel the subdomain a bad actor could register it and abuse it for malicious attacks."

What does this entail

This domain hijacking is possible because Microsoft has created a DNS delegation of notifications.buildmypinnedsite.com to azure.com, where the web service was actually hosted. But after closing his service, the publisher forgot to remove this delegation that anyone could use on his behalf.

It was enough to create another web service on azure.com and associate it with notifications.buildmypinnedsite.com, because the Microsoft cloud service does not offer any verification procedure. According to Hacker News, this delegation has since been removed.

The context

This diversion type is a classic. It is even on the rise because the websites integrate more and more third-party services like forum or online store, which only rely on a DNS delegation. But the day publishers remove these services, they no longer think about this redirection.

You wanna try?

Sources: Golem.de and Hacker News

Stay Informed, Stay Safe

DQmdpsoEfLe5nRg4Q1oKWHNjLdMnAucCYfRou1yF5Yiwrzs.png

DQmNuF3L71zzxAyJB7Lk37yBqjBRo2uafTAudFDLzsoRV5L.gif

Sort:  

Gracias por esta valiosa información

Coin Marketplace

STEEM 0.17
TRX 0.15
JST 0.028
BTC 61940.19
ETH 2433.78
USDT 1.00
SBD 2.50