Teenager finds open Microsoft database with 17 trillion rows
A hacker known as Faav discovered an unsecured /v2/Query endpoint in Microsoft's internal Titan analytics platform: the server failed to verify JWT signatures, exposing 25,000 employee records and 17 trillion rows of data, including Bing analytics. Microsoft awarded $5,000 through its bug bounty program.
- The /v2/Query endpoint required no Azure AD authentication and accepted raw SQL queries
- The server did not validate JWT signatures, allowing admin impersonation
- The database held 25,000 employee records and 17 trillion rows, including Bing data
- Microsoft paid $5,000 via its bug bounty program
Read next
Software