Beware of the GIF: Account Takeover Vulnerability in Microsoft Teams
cyberark.com
cyberark.com
At the peril of being downvoted, I am going to rant, but rant I shall.
Last year they tried to move all Skype users to Teams, which failed miserably. Today, they have tried doing the same, but to my much chagrin, the issue from last year still persists. We are not able to share screen with Skype users. One user just got irritated and left.
A few weeks ago they forgot to renew their SSL certificate, which is unacceptable for a corporation like Microsoft.
And now this. It makes me loathe Teams even more.
At my last company, Teams was introduced as a tool besides skype - and everyone was encouraged to move meetings etc. whenever possible over to Teams. It worked out pretty well, after a few months skype meetings became the exception, almost everything, especially if only techies were included, was happening on Teams.
I recommend to give it a serious try, some of it features do suck (notification settings etc. are absolutely horrendous and seem to not properly work half the time) but overall it improved the ways people communicated a lot compared to skype. At least that was my experience :)
Yeah, it's amazing that such an aborted thing ever seen the day of life. Skype looks like a windows program. Team looks like an Android game.
About corporate: Skype can do a 250 people meeting, Teams can do only 100.
It is like in the old M$ joke: How wonderful it's gonna be when they will get it.
> At my last company, Teams was introduced as a tool besides skype - and everyone was encouraged to move meetings etc. whenever possible over to Teams. It worked out pretty well, after a few months skype meetings became the exception, almost everything, especially if only techies were included, was happening on Teams.
In my company people preffer Skype.
> I recommend to give it a serious try, some of it features do suck (notification settings etc. are absolutely horrendous and seem to not properly work half the time) but overall it improved the ways people communicated a lot compared to skype. At least that was my experience :)
It is a piece of crap. The only "feature" above skype is that it has these groups. From an UI point of view is a piece of crap. Who was the idiot that conceived such a crappy interface ? When i start a new chat i want a new chat not to see my last chat with someone else.
- Want to paste some code? Hope you like smileys everywhere! (This one alone blows my mind. How is this still a thing?)
- Want to send something longer than two twitter messages? Nope, can't have that! Please chunk it into separate messages.
- You receive an image. Why does it take three clicks before you can actually see it?
- How many Skype apps would you like? There's Skype for Business, Skype (the normal windows program), Skype (the Windows app)... Knowing the nonsense that is Microsoft's account system, you probably can't even communicate between them.
- Small hiccup in your connection? Video call now stays at crappy resolution. Solution? Switch to "show full video". Or back from it (cropped). Or fiddle with other unrelated stuff and pray. It's completely erratic.
- You chose "show full video"? Enjoy doing that again in 5 minutes when Skype decides it would really rather crop that person on the side of the frame.
- Trying to edit the middle of a message before sending? Enjoy our state-of-the-art "run spell check on the main thread after every character". Now you can type your message and then watch it appear on the screen in slow-mo over the next five seconds! (Not sure if this is 100% Skype's fault, but I haven't seen it elsewhere.)
That's all I can think of on the spot.
However, I do expect a little bit more than that in 2020 to be honest - I wanna be able to paste code snippets or the like without having to fear that skype introduces some weird special characters when copying it out of skype again (which caused super weird issues more than once).
I want to talk asynchronously: Skype (at least in the for-business variant that I know) is very intrusive; if someone messages you you get a window in the face, and if you click it away you have to do some seriously weird digging to see the message again.
Similarly, I want chat persistence that is not an absolute pain in the butt: If I wanna check what a colleague sent me three days ago in a chat, this has to be like one or two clicks away, not scrolling through stuff.
I want to talk to multiple people at once regularly (a team, a workgroup, you name it) without having to set up the group every single time.
I want to share GIFs and pictures, not just links.
... hope that gives you a bit of an idea on why I'm not particularly fond of skype :)
The auto reformatting is annoying though. Outlook does even worse, always replacing dash with long unicode dash.
https://microsoftteams.uservoice.com/forums/555103-public/su... https://microsoftteams.uservoice.com/forums/555103-public/su...
It supports neither MacOS or Windows native notifications! On Mac this means all Teams notifications end up behind the native notifications.
On the other hand, native Mac notifications are nowhere as feature rich as the custom Teams implementation.
When I get a notification all I want to do is be able to click it or dismiss it. But teams loves to appear on the wrong screen, behind windows, or just not show up at all. That combined with the questionable design choices of the UI, I have missed calls because I heard the sound but couldn't find the alert for it.
Sadly this is likely never to change since Microsoft does the exact same thing for Outlook, which is why I refuse to use it and just stick with native apps for work.
Yet, feature-wise, nothing comes even remotely close. Nothing Cisco offers (Webex is a trash dumpster fire), Skype for consumers is garbage, Skype for Business marginally better, and the FOSS crowd... Mattermost is a decent Slack alternative but no video calls, Jitsi is flattened against the video call capabilities of Teams and Asterisk can't even get a multi-party video call done. Zoom is video calls only, and appear.in/whereby too (plus Whereby tops out at 12 participants).
Hate to admit it but MS Teams is so far away the others might just call it quits, the only thing it would need to completely ditch Webex and S4B at my employer would be an easy way to invite totally random guests to video conferences and support for dial-in via telephone as fallback.
I don't think any of them can be designated the best collab tool because they all (Skype, Zoom, Teams, Slack) have their strengths and weaknesses. I think Teams handles calls and video conferencing better than Slack, but Slack has a more intuitive and feature-rich experience for text-based communication and water-cooler style casual channels. Teams performs better on my machine. Slack has a much more reliable mobile tier. Zoom (not taking privacy issues into consideration) is unbeatable IMO for video reliability, I've used it for years across two major corporations now and it's yet to fail. I think Microsoft is aiming to make Teams unify the best of all these worlds.
> First, the attacker needs to issue a certificate for the compromised sub-domains.
Certbot uses ones ability to present a resource (aka acme-challenge) on the domain for issuing certs (either via http or dns txt record).
More info: https://certbot.eff.org/docs/using.html#changing-a-certifica...
Teams is 1000x better than skype in my experience.
Outlook calendar automatically deletes the entire series when you try removing past events. I had a manager that left recently and therefore they cancelled a series. Rather than keep the previous events so that I could go back and see what I was doing on a particular day, it just removed the entire past series from everyone's calendar like they never attended.
At the risk of posting an insubstantial comment, holy shit.
1. Domain like "abcde.teams.microsoft.com" has a CNAME that points to a domain like "abcde.microsoft-teams.com", but "microsoft-teams.com" is no longer registered to or controlled by Microsoft.
2. Hacker registers microsoft-teams.com, gets a LetsEncrypt SSL for it.
3. Send a message to someone with a GIF that was uploaded to "abcde.teams.microsoft.com". Teams thinks it's legit because it's a subdomain of "teams.microsoft.com", and SSL checks out, so it sends the user's auth token along with the HTTP request for the GIF. Problem is, it's sending it to the attacker controlled "abcde.microsoft-teams.com".
4. Since the hacker controls "abcde.microsoft-teams.com", they now have your auth token, which they can use to impersonate you.
Et voila, account takeover.
I'd bet that plenty of whitehats and blackhats have bots automatically crawling domains belonging to tech companies searching for subdomain takeover opportunities.
Can you elaborate a bit on this? I get that these are example domains, but why would "abcde.teams.microsoft.com" (which is presumably controlled by Microsoft) point to a domain "microsoft-teams.com" that is not controlled by Microsoft? Was that a mistake on Microsoft's part, or did the attackers do something clever to gain control of that domain/point a Microsoft-owned subdomain to the attacker's domain?
Microsoft has a lot of these, just random Microsoft-ish domains that were used at one point or another. It's a problem because it makes it harder to look at the domain name as a sanity check against phishing.
It is likely there is a detailed change approval process for updating a *.microsoft.com DNS record. Or that only certain depts can make changes, and only for certain reasons. Someone involved with Teams avoided that by using a separate domain and a cname record, then they could update their separate domain records more easily. Later someone forgot to register this domain, and/or forgot to update the DNS to somewhere that is over their control, or forgot to put in sufficient checks to prevent tokens being shared with unauthorized servers.
Since you control the DNS for microsoft-teams.com, you can point it to your server. Now both domains point at your server and you get all requests to abcde.teams.microsoft.com. That's how they get cookies.
You can get an SSL certificate because you can serve anything for abcde.teams.microsoft.com. That includes abcde.teams.microsoft.com/.well-known/acme-challenge/* and the .gif (or other) resource you use to steal cookies.
Either abcde.microsoft-teams.com is a typo or you seem to think CNAMEs work like an HTTP redirect, which they don't.
If Microsoft had one of these, they could've caught this before it was exploited.
TLDR; Authorization cookie for an important Account API is sent to *.teams.microsoft.com and they got control of a subdomain of that somehow.
A somewhat deep dive into the format https://enthusiasms.org/post/16976438906
All that said, and please excuse my ignorance here, but how common is it for subdomain not to be under the control of its owner?
2019: You replace blahblahblah and shut it down on Heroku
2020: An attacker creates blahblahblah.heroku.com. and can now read and write cookies for *.microsoft.com.
Replace Heroku with any off-domain hosting service that lets you register a vanity or predictable hostname rather than assigning a GUID.
This is how FreeDNS works: There's lots of domains which are donated to the project, and people can register subdomains of those domains and have them point to their own systems, with software to ensure the DNS records stay up-to-date even in the face of dynamic IP addresses.
it's subdomain takeover
"leveraging a subdomain takeover vulnerability"
I have to say, these headlines immediately made me think of this long ago fixed bug: https://www.cvedetails.com/cve/CVE-2008-2160/