• Email Us: [email protected]
  • Contact Us: +1 718 874 1545
  • Skip to main content
  • Skip to primary sidebar

Medical Market Report

  • Home
  • All Reports
  • About Us
  • Contact Us

An email ‘autodiscover’ bug is helping to leak thousands of Windows passwords

September 22, 2021 by David Barret Leave a Comment

Shipping companies, power plants, and investment banks don’t often share much in common, but new research shows they are all inadvertently leaking thousands of email passwords of their own employees, thanks in part to a design flaw in a widely used email protocol.

Autodiscover is a feature in Microsoft Exchange, a popular email software for companies to host their own email servers, to set up apps on a phone or a computer using just an employee’s email address and password. It’s meant to make it easier to set up an email or calendar app, for example, by offloading the hard work to the server than configuring the app by hand.

Most apps will look for the configuration file in places on the company’s domain where it knows to look. Each time it looks somewhere and can’t find it, the app will “fail up” and somewhere else on the same domain. And if it can’t find the file, then users are left with the inconvenience.

But some apps will inadvertently fail up one step further before hitting a wall. That’s a problem because behind the scenes the app is trying to communicate with a domain name that’s outside of the company’s control but within the same top-level domain — so company.com would end up looking for the configuration file on autodiscover.com. Anyone who owns that domain name can “listen” to the email addresses and passwords as they are sent across the internet

Researchers have for years warned that email apps are vulnerable to this kind of data leakage and can put a company’s credentials at risk. Several apps were fixed at the time, but it’s clearly a problem that hasn’t gone away.

In April, Guardicore Labs acquired the autodiscover domains for some of the most user top-level domains — autodiscover.uk, autodiscover.fr, and so on — and set them to “listen” to leaky requests as they arrive.

In four months, Guardicore identified 340,000 exposed Exchange mailbox credentials hitting those domains. Some companies allow those same credentials to be used to log onto that domain, posing a risk if misused by a malicious hacker. Guardicore said the credentials were sent over the internet in plaintext and could be read at the other end.

Another 96,000 Exchange credentials were sent using protocols that are far stronger and cannot be decrypted, but could be tricked into sending the same credentials over the wire in the clear.

Amit Serper, Guardicore’s security research lead for North America and the author of the research, developed an attack that bounced back the encrypted credentials with a request to the app to use a weaker level of security to send the email address and password again, prompting the app to re-send the credentials in cleartext.

Serper named the attack, perhaps fittingly, “The ol’ switcheroo.”

The domains also saw exposed credentials from real estate companies, food manufacturers, and publicly traded companies in China, Serper said.

For the average user, the leak is practically invisible. Guardicore is not immediately naming the apps that are the biggest culprits of leaked credentials, since many of the app makers are still working on rolling out fixes. Serper told TechCrunch that once the apps are fixed, the domains will be sinkholed but will remain under Guardicore’s control to prevent them from falling into the hands of malicious actors.

It’s not an exhaustive list of domains under Guardicore’s control, but companies and users can take their own precautions by blocking autodiscover domains at the top-level, Serper said. App makers can also not let their apps fail upwards outside of a company’s domain.

Read more:

  • Hackers are stealing years of call records from hacked cell networks
  • A security researcher commandeered a country’s expired top-level domain to save it from hackers
  • FBI launches operation to remove backdoors from hacked Microsoft Exchange servers
  • The sinkhole that saved the internet

Source Link An email ‘autodiscover’ bug is helping to leak thousands of Windows passwords

David Barret
David Barret

Related posts:

  1. Motor racing-Hamilton and Verstappen collide and crash at Monza
  2. Tennis-Russia’s Medvedev beats Djokovic in U.S. Open final
  3. Indonesia-based Rey Assurance launches its holistic approach to insurance with $1M in funding
  4. Marketmind: September setback

Filed Under: News

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

  • Pretty In Purple: Why Do Some Otters Have Purple Teeth And Bones? It’s All Down To Their Spiky Diets
  • The World’s Largest Carnivoran Is A 3,600-Kilogram Giant That Weighs More Than Your Car
  • Devastating “Rogue Waves” Finally Have An Explanation
  • Meet The “Masked Seducer”, A Unique Bat With A Never-Before-Seen Courtship Display
  • Alaska’s Salmon River Is Turning Orange – And It’s A Stark Warning
  • Meet The Heaviest Jelly In The Seas, Weighing Over Twice As Much As A Grand Piano
  • For The First Time, We’ve Found Evidence Climate Change Is Attracting Invasive Species To Canadian Arctic
  • What Are Microfiber Cloths, And How Do They Clean So Well?
  • Stowaway Rat That Hopped On A Flight From Miami Was A “Wake-Up Call” For Global Health
  • Andromeda, Solar Storms, And A 1 Billion Pixel Image Crowned Best Astrophotos Of The Year
  • New Island Emerges In Alaska As Glacier Rapidly Retreats, NASA Satellite Imagery Shows
  • With A New Drug Cocktail, Scientists May Have Finally Found Flu’s Universal Weak Spot
  • Battered Skull Confirms Roman Amphitheaters Were Beastly For Bears
  • Mine Spiders Bigger Than A Burger Patty Lurk Deep In Abandoned Caves
  • Blackout Zones: The Places On Earth Where Magnetic Compasses Don’t Work
  • What Is Actually Happening When You Get Blackout Drunk? An Ethically Dubious Experiment Found Out
  • Koalas Get A Shot At Survival As World-First Chlamydia Vaccine Gets Approval
  • We Could See A Black Hole Explode Within 10 Years – Unlocking The Secrets Of The Universe
  • Denisovan DNA May Make Some People Resistant To Malaria
  • Beware The Kellas Cat? This “Cryptid” Turned Out To Be Real, But It Wasn’t What People Thought
  • Business
  • Health
  • News
  • Science
  • Technology
  • +1 718 874 1545
  • +91 78878 22626
  • [email protected]
Office Address
Prudour Pvt. Ltd. 420 Lexington Avenue Suite 300 New York City, NY 10170.

Powered by Prudour Network

Copyrights © 2025 · Medical Market Report. All Rights Reserved.

Go to mobile version