News Score: Score the News, Sort the News, Rewrite the Headlines

Consent & Compromise: Abusing Entra OAuth for Fun and Access to Internal Microsoft Applications - Eye Research

This blog is about how I got access to over 22 internal Microsoft services and how you might be vulnerable too. After my last talk at the 38C3 conference in Hamburg, this was the top comment on YouTube. Well, this story definitely falls in the category “someone stumbling around finding horrifying vulnerabilities”. Although this time I was not even having issues, I was just distracted from a boring task. You see, I was writing some documentation the other day, when my Eye fell on one of those aka...

Read more at research.eye.security

© News Score  score the news, sort the news, rewrite the headlines