Self-Service Password Reset (SSPR) Abuse in Azure Ad
obsidiansecurity.com
obsidiansecurity.com
What a lie. What a self-serving baldfaced lie. I have a record of my report to GitLab on August 12, 2021 regarding the same SSPR vulnerabilities. Hey Obsidian: email account takeovers work just like a SIM swap. I can name at least two more sites that are vulnerable. I've disclosed to the site owners, so I'm just politely waiting out the 90 days or so before going public.
Prior discussion right here from yours truly: https://news.ycombinator.com/item?id=36726414
https://www.cloudflare.com/learning/security/glossary/attack...
An "attack vector" is not necessarily a TTP used by threat actors, it is a way in. Whether it is used or unused, an attack vector is an attack vector.
Yes, they've documented threat actors actively using it. And SSPR used against several other services before this one. But the claim is in the lede sentence: "novel attack vector".