• Email Us: [email protected]
  • Contact Us: +1 718 874 1545
  • Skip to main content
  • Skip to primary sidebar

Medical Market Report

  • Home
  • All Reports
  • About Us
  • Contact Us

An email ‘autodiscover’ bug is helping to leak thousands of Windows passwords

September 22, 2021 by David Barret Leave a Comment

Shipping companies, power plants, and investment banks don’t often share much in common, but new research shows they are all inadvertently leaking thousands of email passwords of their own employees, thanks in part to a design flaw in a widely used email protocol.

Autodiscover is a feature in Microsoft Exchange, a popular email software for companies to host their own email servers, to set up apps on a phone or a computer using just an employee’s email address and password. It’s meant to make it easier to set up an email or calendar app, for example, by offloading the hard work to the server than configuring the app by hand.

Most apps will look for the configuration file in places on the company’s domain where it knows to look. Each time it looks somewhere and can’t find it, the app will “fail up” and somewhere else on the same domain. And if it can’t find the file, then users are left with the inconvenience.

But some apps will inadvertently fail up one step further before hitting a wall. That’s a problem because behind the scenes the app is trying to communicate with a domain name that’s outside of the company’s control but within the same top-level domain — so company.com would end up looking for the configuration file on autodiscover.com. Anyone who owns that domain name can “listen” to the email addresses and passwords as they are sent across the internet

Researchers have for years warned that email apps are vulnerable to this kind of data leakage and can put a company’s credentials at risk. Several apps were fixed at the time, but it’s clearly a problem that hasn’t gone away.

In April, Guardicore Labs acquired the autodiscover domains for some of the most user top-level domains — autodiscover.uk, autodiscover.fr, and so on — and set them to “listen” to leaky requests as they arrive.

In four months, Guardicore identified 340,000 exposed Exchange mailbox credentials hitting those domains. Some companies allow those same credentials to be used to log onto that domain, posing a risk if misused by a malicious hacker. Guardicore said the credentials were sent over the internet in plaintext and could be read at the other end.

Another 96,000 Exchange credentials were sent using protocols that are far stronger and cannot be decrypted, but could be tricked into sending the same credentials over the wire in the clear.

Amit Serper, Guardicore’s security research lead for North America and the author of the research, developed an attack that bounced back the encrypted credentials with a request to the app to use a weaker level of security to send the email address and password again, prompting the app to re-send the credentials in cleartext.

Serper named the attack, perhaps fittingly, “The ol’ switcheroo.”

The domains also saw exposed credentials from real estate companies, food manufacturers, and publicly traded companies in China, Serper said.

For the average user, the leak is practically invisible. Guardicore is not immediately naming the apps that are the biggest culprits of leaked credentials, since many of the app makers are still working on rolling out fixes. Serper told TechCrunch that once the apps are fixed, the domains will be sinkholed but will remain under Guardicore’s control to prevent them from falling into the hands of malicious actors.

It’s not an exhaustive list of domains under Guardicore’s control, but companies and users can take their own precautions by blocking autodiscover domains at the top-level, Serper said. App makers can also not let their apps fail upwards outside of a company’s domain.

Read more:

  • Hackers are stealing years of call records from hacked cell networks
  • A security researcher commandeered a country’s expired top-level domain to save it from hackers
  • FBI launches operation to remove backdoors from hacked Microsoft Exchange servers
  • The sinkhole that saved the internet

Source Link An email ‘autodiscover’ bug is helping to leak thousands of Windows passwords

David Barret
David Barret

Related posts:

  1. Motor racing-Hamilton and Verstappen collide and crash at Monza
  2. Tennis-Russia’s Medvedev beats Djokovic in U.S. Open final
  3. Indonesia-based Rey Assurance launches its holistic approach to insurance with $1M in funding
  4. Marketmind: September setback

Filed Under: News

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

  • US Just Killed NASA’s Mars Sample Return Mission – So What Happens Now?
  • Art Sleuths May Have Recovered Traces Of Da Vinci’s DNA From One Of His Drawings
  • Countries With The Most Narcissists Identified By 45,000-Person Study, And The Results Might Surprise You
  • World’s Oldest Poison Arrows Were Used By Hunters 60,000 Years Ago
  • The Real Reason You Shouldn’t Eat (Most) Raw Cookie Dough
  • Antarctic Scientists Have Just Moved The South Pole – Literally
  • “What We Have Is A Very Good Candidate”: Has The Ancestor Of Homo Sapiens Finally Been Found In Africa?
  • Europe’s Missing Ceratopsian Dinosaurs Have Been Found And They’re Quite Diverse
  • Why Don’t Snorers Wake Themselves Up?
  • Endangered “Northern Native Cat” Captured On Camera For The First Time In 80 Years At Australian Sanctuary
  • Watch 25 Years Of A Supernova Expanding Into Space Squeezed Into This 40-Second NASA Video
  • “Diet Stacking” Trend Could Be Seriously Bad For Your Health
  • Meet The Psychedelic Earth Tiger, A Funky Addition To “10 Species To Watch” In 2026
  • The Weird Mystery Of The “Einstein Desert” In The Hunt For Rogue Planets
  • NASA Astronaut Charles Duke Left A Touching Photograph And Message On The Moon In 1972
  • How Multilingual Are You? This New Language Calculator Lets You Find Out In A Minute
  • Europa’s Seabed Might Be Too Quiet For Life: “The Energy Just Doesn’t Seem To Be There”
  • Amoebae: The Microscopic Health Threat Lurking In Our Water Supplies. Are We Taking Them Seriously?
  • The Last Dogs In Antarctica Were Kicked Out In April 1994 By An International Treaty
  • Interstellar Comet 3I/ATLAS Snapped By NASA’s Europa Mission: “We’re Still Scratching Our Heads About Some Of The Things We’re Seeing”
  • Business
  • Health
  • News
  • Science
  • Technology
  • +1 718 874 1545
  • +91 78878 22626
  • [email protected]
Office Address
Prudour Pvt. Ltd. 420 Lexington Avenue Suite 300 New York City, NY 10170.

Powered by Prudour Network

Copyrights © 2026 · Medical Market Report. All Rights Reserved.

Go to mobile version