Regulation

Teenager exploits Microsoft Titan database flaw, accessing 17 trillion rows and 25,000 employee records

A security researcher known as Faav discovered a critical validation bypass in Microsoft's internal analytics platform, gaining unauthorized access to massive datasets through a missing JWT token check.

2 min read
Teenager hacks open Microsoft database with 17 trillion total rows and 25,000 user accounts

A young hacker identified as Faav uncovered a significant vulnerability within Microsoft's Titan analytics platform, an internal system containing 17 trillion total rows of data and employee records belonging to 25,000 accounts. The breach stemmed from inadequate user validation mechanisms, specifically the failure to properly check JSON Web Token authentication.

Faav described his approach to finding vulnerabilities across major technology firms, stating that he has "spent the year hacking Microsoft off and on around school," while also investigating security gaps at Amazon, Google, Adobe, and other companies. His methodology relies on custom tools, including an AI orchestrator bot named Antares that he developed to automate security scanning and reduce manual work.

The discovery began when Antares identified an endpoint URL within Titan that displayed an error message indicating VPN access was required. This prompted Faav to direct Antares to search for related subdomains, which led to locating an Azure Cloud host and its corresponding Swagger/OpenAPI specification file. The specification documented four API routes, though only one—labeled /v2/Query—lacked Azure Active Directory authentication requirements.

The /v2/Query endpoint presented a particularly severe issue: it accepted raw SQL queries directly. To understand the database structure, Faav consulted the Wayback Machine and retrieved a 2023 version of the login page, which contained an Apache Superset configuration file detailing 56 table definitions across the database schema.

Although the endpoint initially rejected Faav's queries due to missing JWT authentication, he observed that the server's response patterns suggested the token's digital signature was not being validated. Rather than attempting to forge a legitimate token, he constructed an access token claiming administrator privileges. The server accepted it without verification, granting him entry to the system.

Once inside, Faav accessed 25,000 employee records alongside organizational data, dashboards, and visualizations. Further exploration revealed a data source dedicated to Bing analytics. After calculating the total row count across all accessible tables, he determined the database contained 17 trillion records in total—a figure he verified multiple times before nearly alerting his household at 2 a.m.

Faav reported the vulnerability to Microsoft's bug bounty program and received a $5,000 reward. In documenting his findings, he emphasized the collaborative role of automation and human reasoning: "AI and human intuition compounded here. Antares did ten days of work I didn't have to [...] Its persistence, plus one human hunch, is what made this find possible."

Source: Tom's Hardware · Reporting supplemented by The Silicon Ledger staff.