• Email Us: [email protected]
  • Contact Us: +1 718 874 1545
  • Skip to main content
  • Skip to primary sidebar

Medical Market Report

  • Home
  • All Reports
  • About Us
  • Contact Us

An email ‘autodiscover’ bug is helping to leak thousands of Windows passwords

September 22, 2021 by David Barret Leave a Comment

Shipping companies, power plants, and investment banks don’t often share much in common, but new research shows they are all inadvertently leaking thousands of email passwords of their own employees, thanks in part to a design flaw in a widely used email protocol.

Autodiscover is a feature in Microsoft Exchange, a popular email software for companies to host their own email servers, to set up apps on a phone or a computer using just an employee’s email address and password. It’s meant to make it easier to set up an email or calendar app, for example, by offloading the hard work to the server than configuring the app by hand.

Most apps will look for the configuration file in places on the company’s domain where it knows to look. Each time it looks somewhere and can’t find it, the app will “fail up” and somewhere else on the same domain. And if it can’t find the file, then users are left with the inconvenience.

But some apps will inadvertently fail up one step further before hitting a wall. That’s a problem because behind the scenes the app is trying to communicate with a domain name that’s outside of the company’s control but within the same top-level domain — so company.com would end up looking for the configuration file on autodiscover.com. Anyone who owns that domain name can “listen” to the email addresses and passwords as they are sent across the internet

Researchers have for years warned that email apps are vulnerable to this kind of data leakage and can put a company’s credentials at risk. Several apps were fixed at the time, but it’s clearly a problem that hasn’t gone away.

In April, Guardicore Labs acquired the autodiscover domains for some of the most user top-level domains — autodiscover.uk, autodiscover.fr, and so on — and set them to “listen” to leaky requests as they arrive.

In four months, Guardicore identified 340,000 exposed Exchange mailbox credentials hitting those domains. Some companies allow those same credentials to be used to log onto that domain, posing a risk if misused by a malicious hacker. Guardicore said the credentials were sent over the internet in plaintext and could be read at the other end.

Another 96,000 Exchange credentials were sent using protocols that are far stronger and cannot be decrypted, but could be tricked into sending the same credentials over the wire in the clear.

Amit Serper, Guardicore’s security research lead for North America and the author of the research, developed an attack that bounced back the encrypted credentials with a request to the app to use a weaker level of security to send the email address and password again, prompting the app to re-send the credentials in cleartext.

Serper named the attack, perhaps fittingly, “The ol’ switcheroo.”

The domains also saw exposed credentials from real estate companies, food manufacturers, and publicly traded companies in China, Serper said.

For the average user, the leak is practically invisible. Guardicore is not immediately naming the apps that are the biggest culprits of leaked credentials, since many of the app makers are still working on rolling out fixes. Serper told TechCrunch that once the apps are fixed, the domains will be sinkholed but will remain under Guardicore’s control to prevent them from falling into the hands of malicious actors.

It’s not an exhaustive list of domains under Guardicore’s control, but companies and users can take their own precautions by blocking autodiscover domains at the top-level, Serper said. App makers can also not let their apps fail upwards outside of a company’s domain.

Read more:

  • Hackers are stealing years of call records from hacked cell networks
  • A security researcher commandeered a country’s expired top-level domain to save it from hackers
  • FBI launches operation to remove backdoors from hacked Microsoft Exchange servers
  • The sinkhole that saved the internet

Source Link An email ‘autodiscover’ bug is helping to leak thousands of Windows passwords

David Barret
David Barret

Related posts:

  1. Motor racing-Hamilton and Verstappen collide and crash at Monza
  2. Tennis-Russia’s Medvedev beats Djokovic in U.S. Open final
  3. Indonesia-based Rey Assurance launches its holistic approach to insurance with $1M in funding
  4. Marketmind: September setback

Filed Under: News

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

  • Inhaling “Laughing Gas” Could Treat Severe Depression, Live Seven-Arm Octopus Spotted In The Deep Sea, And Much More This Week
  • People Are Surprised To Learn That The Closest Planet To Neptune Turns Out To Be Mercury
  • The Age-Old “Grandmother Rule” Of Washing Is Backed By Science
  • How Hero Of Alexandria Used Ancient Science To Make “Magical Acts Of The Gods” 2,000 Years Ago
  • This 120-Million-Year-Old Bird Choked To Death On Over 800 Stones. Why? Nobody Knows
  • Radiation Fog: A 643-Kilometer Belt Of Mist Lingers Over California’s Central Valley
  • New Images Of Comet 3I/ATLAS From 4 Different Missions Reveal A Peculiar Little World
  • Neanderthals Used Reindeer Bones To Skin Animals And Make Leather Clothes
  • Why Do Power Lines Have Those Big Colorful Balls On Them?
  • Rare Peek Inside An Egg Sac Reveals An Adorable Developing Leopard Shark
  • What Is A Superhabitable Planet And Have We Found Any?
  • The Moon Will Travel Across The Sky With A Friend On Sunday. Here’s What To Know
  • How Fast Does Sound Travel Across The Worlds Of The Solar System?
  • A Wonky-Necked Giraffe In California Lived To 21 Against The Odds
  • Seal Finger: What Is This Horrible Infection That Makes Your Hand Swell Like A Balloon?
  • “They Usually Aren’t Second Tier”: When Wolves Adopt Pups From Rival Packs
  • The Road To New Physics Beyond Our Knowledge Might Pass Through Neutrinos
  • Flu Season Is Revving Up – What Are The Symptoms To Look Out For?
  • Asteroid Bennu Was Missing Just One Ingredient Needed To Kickstart Life – We just Found It
  • Rare Core Samples Provide “Once In A Lifetime” Opportunity To Study The Giant Line That Slices Through Scotland
  • Business
  • Health
  • News
  • Science
  • Technology
  • +1 718 874 1545
  • +91 78878 22626
  • [email protected]
Office Address
Prudour Pvt. Ltd. 420 Lexington Avenue Suite 300 New York City, NY 10170.

Powered by Prudour Network

Copyrights © 2025 · Medical Market Report. All Rights Reserved.

Go to mobile version