• Email Us: [email protected]
  • Contact Us: +1 718 874 1545
  • Skip to main content
  • Skip to primary sidebar

Medical Market Report

  • Home
  • All Reports
  • About Us
  • Contact Us

An email ‘autodiscover’ bug is helping to leak thousands of Windows passwords

September 22, 2021 by David Barret Leave a Comment

Shipping companies, power plants, and investment banks don’t often share much in common, but new research shows they are all inadvertently leaking thousands of email passwords of their own employees, thanks in part to a design flaw in a widely used email protocol.

Autodiscover is a feature in Microsoft Exchange, a popular email software for companies to host their own email servers, to set up apps on a phone or a computer using just an employee’s email address and password. It’s meant to make it easier to set up an email or calendar app, for example, by offloading the hard work to the server than configuring the app by hand.

Most apps will look for the configuration file in places on the company’s domain where it knows to look. Each time it looks somewhere and can’t find it, the app will “fail up” and somewhere else on the same domain. And if it can’t find the file, then users are left with the inconvenience.

But some apps will inadvertently fail up one step further before hitting a wall. That’s a problem because behind the scenes the app is trying to communicate with a domain name that’s outside of the company’s control but within the same top-level domain — so company.com would end up looking for the configuration file on autodiscover.com. Anyone who owns that domain name can “listen” to the email addresses and passwords as they are sent across the internet

Researchers have for years warned that email apps are vulnerable to this kind of data leakage and can put a company’s credentials at risk. Several apps were fixed at the time, but it’s clearly a problem that hasn’t gone away.

In April, Guardicore Labs acquired the autodiscover domains for some of the most user top-level domains — autodiscover.uk, autodiscover.fr, and so on — and set them to “listen” to leaky requests as they arrive.

In four months, Guardicore identified 340,000 exposed Exchange mailbox credentials hitting those domains. Some companies allow those same credentials to be used to log onto that domain, posing a risk if misused by a malicious hacker. Guardicore said the credentials were sent over the internet in plaintext and could be read at the other end.

Another 96,000 Exchange credentials were sent using protocols that are far stronger and cannot be decrypted, but could be tricked into sending the same credentials over the wire in the clear.

Amit Serper, Guardicore’s security research lead for North America and the author of the research, developed an attack that bounced back the encrypted credentials with a request to the app to use a weaker level of security to send the email address and password again, prompting the app to re-send the credentials in cleartext.

Serper named the attack, perhaps fittingly, “The ol’ switcheroo.”

The domains also saw exposed credentials from real estate companies, food manufacturers, and publicly traded companies in China, Serper said.

For the average user, the leak is practically invisible. Guardicore is not immediately naming the apps that are the biggest culprits of leaked credentials, since many of the app makers are still working on rolling out fixes. Serper told TechCrunch that once the apps are fixed, the domains will be sinkholed but will remain under Guardicore’s control to prevent them from falling into the hands of malicious actors.

It’s not an exhaustive list of domains under Guardicore’s control, but companies and users can take their own precautions by blocking autodiscover domains at the top-level, Serper said. App makers can also not let their apps fail upwards outside of a company’s domain.

Read more:

  • Hackers are stealing years of call records from hacked cell networks
  • A security researcher commandeered a country’s expired top-level domain to save it from hackers
  • FBI launches operation to remove backdoors from hacked Microsoft Exchange servers
  • The sinkhole that saved the internet

Source Link An email ‘autodiscover’ bug is helping to leak thousands of Windows passwords

David Barret
David Barret

Related posts:

  1. Motor racing-Hamilton and Verstappen collide and crash at Monza
  2. Tennis-Russia’s Medvedev beats Djokovic in U.S. Open final
  3. Indonesia-based Rey Assurance launches its holistic approach to insurance with $1M in funding
  4. Marketmind: September setback

Filed Under: News

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

  • Clouded Leopard Caught On Camera With A Slow Loris Snack For First Time
  • “Octopus Maps” Promote Conspiratorial Thinking Even When It Is Unintended
  • YouTuber Creates “World’s Strongest Handheld Laser”. It’s Capable Of Punching Through Titanium.
  • “Razor Blade Throat” And A Traveling “Nimbus”: What’s Up With The NB.1.8.1 COVID-19 Variant?
  • Fast, Ferocious, and Fearsome: Meet The Sun Spiders Of The Solifugae
  • “Juvenile Bigfoot”, Evolved Monkeys, Or Just Good Marketing? Meet The Albatwitch Of Pennsylvania Folklore
  • The Strange Science Behind Time Feeling Faster As You Age
  • Hundreds Of New Giant Viruses Discovered Throughout The World’s Oceans
  • Scientists Dropped Gophers On Mount St. Helens For 24 Hours. Four Decades Later, The Impact Is Astonishing
  • We Finally Know The Route Of Neanderthals’ Massive Migration Across Eurasia
  • Why Earth’s Orbit Around The Sun Isn’t What You Think
  • Why Do We Say “Eleven” and “Twelve” Instead Of “Oneteen” And “Twoteen”?
  • Ice Age Puppies, Preserved In Permafrost For 14,000 Years, Turn Out To Be Wolves
  • “The Wood Frog Comes Back To Life”: Meet The Real-Life Frogsicle That Can Survive Freezing
  • Meet The Dragon Prince, A New Dinosaur That’s Rewriting What We Know About Tyrannosaur Evolution
  • Incredible Laser Tool Can Read Tiny Text From Over A Kilometer Away, Perfect For The Spy Of Tomorrow
  • How Vantablack – The Blackest Paint On Earth – Could Save Astronomy
  • Fish Suffer “10 Minutes Of Intense Pain” Before Dying In Commercial Fishing Operations
  • China Reveals First Deep-Sea “Testing Site”, Adding To Vast Network Of Marine Bases
  • The “Spiritual Bliss Attractor”: Something Weird Happens When You Leave Two AIs Talking To Each Other
  • Business
  • Health
  • News
  • Science
  • Technology
  • +1 718 874 1545
  • +91 78878 22626
  • [email protected]
Office Address
Prudour Pvt. Ltd. 420 Lexington Avenue Suite 300 New York City, NY 10170.

Powered by Prudour Network

Copyrights © 2025 · Medical Market Report. All Rights Reserved.

Go to mobile version