

Subdomain Takeover: Microsoft loses control over Windows Tiles
source link: https://www.tuicool.com/articles/hit/e6B7bmr
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.

The Tiles service Microsoft introduced with Windows 8 has never been particularly successful. Microsoft has disabled a web service for the system but forgot to delete nameserver entries. This made the host vulnerable for a subdomain takeover attack - allowing us to control the contents. By doing so we were able to show arbitrary pictures and text within the tiles of other web pages.
The tiles can fullfil a number of functions. They allow web pages to display news on the tiles with a special meta tag. This function is called Windows Live Tiles. Web pages which support this service can be pinned as a tile.
Microsoft service converts RSS feed to Tiles
With a special XML-based file format, web pages can control the content of the tiles; for example, they can show the latest news. To make it easier for web pages to provide this function, Microsoft ran a service that automatically converted RSS feeds into that special XML format.
The web page that allows creating the corresponding meta tags is still online , although the service no longer works. The host that should deliver the XML files - notifications.buildmypinnedsite.com - only showed an error message from Microsoft's cloud service Azure.
The abandoned host was vulnerable for a so-called subdomain takeover attack . The host was redirected to a subdomain of Azure. However this subdomain wasn't registered with Azure.
Azure subdomain could be re-registered
The takeover works via a so-called CNAME nameserver entry. It redirects all requests for the host to the unregistered Azure subdomain. With an ordinary Azure account, we were able to register that subdomain and add the corresponding host name. Thus we were able to control which content is served on that host.
Web pages using the defunct service from Microsoft included the Russian mail provider Mail.ru, Engadget, and German news sites Heise Online and Giga. Web pages that include these meta tags should remove them or, if they want to keep the functionality, create the corresponding XML files themselves.
Microsoft does not answer
We have informed Microsoft about this problem but haven't received a reply yet. We won't keep the host registered permanently. There's a decent amount of traffic reaching this host and running up costs to hold the domain and block the corresponding subdomain even if we stop the web service and don't provide any content. Once we cancel the subdomain a bad actor could register it and abuse it for malicious attacks.
Windows Tiles were introduced on the start screen of Windows 8 and moved to the start menu in Windows 10. They have never been particularly popular. The web page Windowscentral speculated in January that the Tiles may be deprecated soon. The upcoming Windows Lite is rumored to come without Tiles already.
Recommend
-
76
subjack Subjack is a Subdomain Takeover tool written in Go designed to scan a list of subdomains concurrently and identify ones that are able to be hijacked. With Go's speed and efficiency, this tool really stands out when it comes to mas...
-
243
README.md SubOver Subover is a Hostile Subdomain Takeover tool originally written in python but rewritten from scratch in Golang. Since it's redesign, it has been aimed with speed and efficienc...
-
170
README.md Subzy Subdomain takeover tool which works based on matching response fingerprings from
-
12
Create card visualizations 05/05/2020 2 minutes to read In this article APPLIES TO:
-
9
How-To How to avoid subdomain takeover in Azure environments Active but unused subdomains in Microsoft Azure give attackers the opportunity to use them for...
-
10
Subdomain Takeover: Ignore This Vulnerability at Your PerilThe Domain Name System (DNS) is often described as the address book of the Internet; A and AAAA records map a human-frie...
-
8
DNSTake A fast tool to check missing hosted DNS zones that can lead to subdomain takeover. What is a DNS takeover? DNS takeover vulnerabilities occur when a subdomain (subdomain.example.com) or domain has its au...
-
6
Debunked: Is a subdomain takeover ‘game over’ for companies? October 29, 2021 When was the last time you checked DNS c...
-
6
Twitter Loses Three More Execs as Musk Takeover Drama Continues Published May 17, 2022 By
-
5
Twitter loses 3 million monthly UK visitors after Musk takeover Users switch to rival platforms amid c...
About Joyk
Aggregate valuable and interesting links.
Joyk means Joy of geeK