Bing vulnerability made it possible to alter search results

产品中心 2024-09-23 04:32:45 646

A major security exploit that let researchers change Bing search results was revealed this week.

The vulnerability was discovered in January by cybersecurity research company Wiz and reported to the Microsoft Security Response Center (MSRC).

In a Twitter thread, Wiz researcher Hillai Ben-Sasson explained how he was able to hack into Bing's content management system (CMS). By logging into Microsoft's cloud computing platform Azure, he discovered that he could grant all users access to internal Microsoft apps. He then accessed a database of Bing's search results. From there, Ben-Sasson figured out that he could actually modify what showed up in the results.

Wiz researchers also discovered that Bing was vulnerable to a Cross-Site Scripting (XSS) attack and discovered they had access to sensitive Office 365 data including Outlook emails, Calendar information, and Teams messages. MSRC detailed security updates and shared recommendations for Azure AD admins and developers in its blog post.

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!
SEE ALSO:Protect your privacy with the best free VPN

The purpose of the researchers' experiment was to show that it was possible and share its findings with Microsoft. But it shows how malicious hackers could have wreaked havoc for Bing.


Related Stories
  • Oh great, Microsoft's Bing AI chatbot is getting more ads
  • Microsoft threatens to cut-off rival AI chatbots from Bing data
  • Bing vs. Bard: The ultimate AI chatbot showdown
  • Meet Copilot, Microsoft's AI tool for work and productivity
  • The ChatGPT bug exposed more private data than previously thought, OpenAI confirms

"A malicious actor with the same access could’ve hijacked the most popular search results with the same payload and leak sensitive data from millions of users," said the Wiz blog post. Luckily it was caught before any major damage was done.

Microsoft confirmed that it has been fixed as of March 29. Wiz received a $40,000 "bug bounty" for reporting the vulnerability, which it it plans to donate to an unspecified recipient.

本文地址:http://x.zzzogryeb.bond/html/31d399804.html
版权声明

本文仅代表作者观点,不代表本站立场。
本文系作者授权发表,未经许可,不得转载。

全站热门

“大体老师”的故事:以生命点亮生命

提升公众风险防范能力 优化人民币流通环境

“2024 创享未来”创友年会暨2023年度雅安市“创业明星”颁奖仪式举行

交通银行青岛分行发行青岛市首张社保卡“居民服务一卡通”

The Astounding World of Automata

发券促销 喜购年货

我市加强出版物市场监管营造安全良好节日氛围

开展春运志愿服务 展现城市文明水平

友情链接