Another blog post could be written titled "I wrote my own teams client where I'm allowed to edit messages locally", would that be a security issue?
In other words there is not really anything of note, if I read the post correctly.
Another blog post could be written titled "I wrote my own teams client where I'm allowed to edit messages locally", would that be a security issue?
In other words there is not really anything of note, if I read the post correctly.
Bug bounty programs and flashy brand name vulnerabilities have created this ecosystem where lots of security "researchers" publish long blog posts about so called "vulerabilities" they have discovered, hyping them up to be way more than they are. In hopes of getting bug bounties or hired as contractors I assume.
I had to unsubscribe from reddit's r/netsec and r/blackhat due to the number of borderline false posts like this.
There's like this intense pressure of people in security to network it seems. In the rare times I would post on netsec/blackhat to correct a misconception I'd get reached out to to connect on linkedin and whatnot.
Of course there is still some tremendous security researchers out there, like those at Google ProjectZero, but this industry seems to also attract a lot of borderline grifters.
This is akin to saying fakeroot gives you root capabilities, or claiming to get root by doing "export PS1='# '"
I never said P0 is my threshold, I just used them as an example of good security researchers. I don't doubt there are plenty of randos doing good work. I'm just finding the signal to noise ratio is getting worse.
> While I was working with the previous version (v0.4.4) of AADInternals Teams functions I noticed an interesting thing: I was able to edit and delete chat messages using AADInternals as a guest even when it was not allowed.
I agree however that the rest of the article doesn't really make any attempts to show a server-side issue.
In the unlikely event that someone reading this doesn't understand why server-side sanitation of any user input is always required, xkcd.com/327 provides an amusing take.
The real issue would have been if the user did these actions and there was no backend validations on them. The video does not cover this.
Neither the article nor the video prove that it does anything more than limit the display options client-side though. The source of truth is still the server and nothing here speaks to that...
https://twitter.com/NestoriSyynimaa/status/13211346867149537...
(But hasn't offered any evidence to back this up)
If it does change server data, yea - significant news. But that doesn't seem to be implied, except by omission of a claim that it does not.