Главная
Study mode:
on
1
BingBang: Hacking Bing.com (and much more) with Azure Active Directory
Description:
Explore a groundbreaking Black Hat conference talk that unveils a novel technique for identifying Azure Active Directory (AAD) misconfigurations. Discover how a single checkbox led to bypassing authentication, altering search results, and launching XSS attacks on Bing.com users, compromising their Office 365 tokens. Learn about the innovative scanning method developed to remotely map AAD misconfigurations, revealing thousands of exposed applications across the internet. Gain insights into the potential vulnerabilities in cloud-managed environments and the far-reaching implications of seemingly minor configuration choices. Presented by Hillai Ben-Sasson, this 34-minute talk delves into the intricacies of cloud security, offering valuable lessons for cybersecurity professionals and organizations relying on Azure AD.

BingBang - Hacking Bing.com with Azure Active Directory

Black Hat
Add to list