16-Year-Old Discovers Microsoft API Vulnerability Using AI
A 16-year-old security researcher has identified a critical vulnerability in Microsoft's internal Titan analysis platform. The discovery granted access to vast amounts of data and earned the researcher a $5,000 bounty.
A 16-year-old security researcher, known online as Faav, has detailed how he discovered a significant vulnerability within Microsoft's internal Titan data analysis platform. The flaw could have allowed unauthorized access to extensive internal company data, including employee records.
Faav's discovery led to a $5,000 reward through Microsoft's bug bounty program. He utilized an AI-powered robot named Antares to identify a public API endpoint for the Titan platform. Faav found that a specific API route, "/v2/Query," lacked proper authentication and permitted direct SQL queries.
Using archived web pages from the Wayback Machine, Faav was able to discern the database structure. He ultimately bypassed the required JWT authentication by presenting a forged token, gaining access to a database containing metadata such as employee email addresses and organizational details.
Based on his findings, Faav estimated that the accessible data comprised over 17 trillion rows, including information related to Bing analytics. He reported the vulnerability to Microsoft, which subsequently patched the issue. Microsoft acknowledged Faav's contribution to enhancing their security.