Security/ security · microsoft · bug-bounty · hacking

Teen Hacker Exposes Microsoft Database Flaw for $5,000 Bounty

A 16-year-old researcher bypassed Microsoft's token checks to reach an internal database of trillions of rows, exposing a signature flaw Microsoft missed.

A 16-year-old bug hunter walked into an internal Microsoft database using a login token the system never bothered to verify.

Faav, who publishes under that handle, found that Microsoft's internal Titan analytics platform checked a JSON Web Token's tenant, audience, and application ID, but never checked the cryptographic signature meant to prove the token was real. After failed attempts using guessed email addresses, he swapped the token's user field for the plain string admin, which Titan resolved to a local admin account. That gave him access to an estimated 17.3 trillion stored rows and a metadata table listing roughly 25,000 accounts, reachable through an undocumented API endpoint that accepted raw SQL queries. He reported the bug on September 5, Microsoft patched it by September 9, and paid him $5,000 on September 17.

The real story isn't the eye-catching row count, which Microsoft calls a theoretical storage estimate rather than proof anyone's data was touched. It's that one unchecked signature made three other layers of access control pointless, the security equivalent of a hotel where every door has a working card reader but any card opens any room. It's also worth remembering Microsoft had editorial input on Faav's write-up before he published it, trimming details and reshaping how the impact was described.

This isn't Faav's first Microsoft disclosure, and he has separately found and reported bugs at Amazon, Google, and Adobe.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →