<!--DEBUG:--><!--DEBUG:dc3-united-states-it-in-english-pdf-2--><!--DEBUG:--><!--DEBUG:dc3-united-states-it-in-english-pdf-2--><!--DEBUG-spv-->{"id":1553845,"date":"2020-04-30T12:56:00","date_gmt":"2020-04-30T10:56:00","guid":{"rendered":"http:\/\/nhub.news\/?p=1553845"},"modified":"2020-04-30T17:08:10","modified_gmt":"2020-04-30T15:08:10","slug":"how-viewing-a-gif-could-have-compromised-your-account-in-microsoft-teams","status":"publish","type":"post","link":"http:\/\/nhub.news\/ru\/2020\/04\/how-viewing-a-gif-could-have-compromised-your-account-in-microsoft-teams\/","title":{"rendered":"How Viewing a GIF Could Have Compromised Your Account In Microsoft Teams"},"content":{"rendered":"<p style=\"text-align: justify;\"><b>Microsoft Teams, just like other video conferencing apps, has seen a growth in users owing to the coronavirus pandemic. Now, a new vulnerability surfaced that could have allowed hackers to take over an entire Teams roster.<\/b><br \/>\nMicrosoft Teams is among the popular video conferencing services and has seen a rise in users owing to the coronavirus pandemic. But, with the increase in user base, comes an increased security risk. A new analysis of Microsoft Teams by information security company CyberArk found that user accounts were vulnerable to takeovers just by sharing a malicious GIF. This vulnerability is associated to the temporary access token created by Microsoft Teams at various points and can affect both the Teams desktop or web browser versions. However, Microsoft said it has addressed the issue and taken steps to keep its customers safe.<br \/>The vulnerability was spotted by CyberArk when it analysed how Microsoft Teams works. During the research, it was found that every time Teams is opened, the client creates a new temporary token or access token. Just like the initial access token, there are other tokens that are created as well for say for SharePoint, Outlook and other services. These tokens are then used to allow a user to see images or GIFs shared with them or by them. As these images are stored on Microsoft&#8217;s servers, a token called \u201cskype token\u201d is created and can also be seen as a cookie called \u201cskypetoken_asm.\u201d<br \/>The researchers noted that Teams makes sure that users will be able to see the content by establishing two cookies called \u201cauthtoken\u201d and \u201cskypetoken_asm.\u201d Thus, if someone gets access to the authtoken, they can create a skype token. Stating that two of the sub-domains under Microsoft Teams namely, \u2018aadsync-test.teams.microsoft.com&#8217; and \u2018data-dev.teams.microsoft.com&#8217;, were vulnerable to a subdomain takeover, CyberArk said that if an attacker can \u201cforce a user to visit the sub-domains\u201d, the victim&#8217;s browser will send a cookie to the attacker&#8217;s server, which will allow the attacker to create a skype token. This will then give the attacker access to the victim&#8217;s Teams account data.<br \/>By leveraging this vulnerability in Microsoft Teams, CyberArk stated that attackers could have used a malicious GIF to \u201cscrape user&#8217;s data and ultimately take over an organization&#8217;s entire roster of Teams accounts.\u201d It was noted that vulnerabilities like this have the ability to spread automatically and would affect every user who uses the Teams desktop or web browser version.<br \/>The analysis also pointed out that after working with Microsoft Security Research Center, the issue was fixed. According to ZDNet, Microsoft said, \u201cWe addressed the issue discussed in this blog and worked with the researcher under Coordinated Vulnerability Disclosure. While we have not seen any use of this technique in the wild, we have taken steps to keep our customers safe.&#187;<\/p>\n<script>jQuery(function(){jQuery(\".vc_icon_element-icon\").css(\"top\", \"0px\");});<\/script><script>jQuery(function(){jQuery(\"#td_post_ranks\").css(\"height\", \"10px\");});<\/script><script>jQuery(function(){jQuery(\".td-post-content\").find(\"p\").find(\"img\").hide();});<\/script>","protected":false},"excerpt":{"rendered":"<p>Microsoft Teams, just like other video conferencing apps, has seen a growth in users owing to the coronavirus pandemic. Now, a new vulnerability surfaced that could have allowed hackers to take over an entire Teams roster. Microsoft Teams is among the popular video conferencing services and has seen a rise in users owing to the [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1553844,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[90],"tags":[],"_links":{"self":[{"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/posts\/1553845"}],"collection":[{"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/comments?post=1553845"}],"version-history":[{"count":1,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/posts\/1553845\/revisions"}],"predecessor-version":[{"id":1553846,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/posts\/1553845\/revisions\/1553846"}],"wp:featuredmedia":[{"embeddable":true,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/media\/1553844"}],"wp:attachment":[{"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/media?parent=1553845"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/categories?post=1553845"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/nhub.news\/ru\/wp-json\/wp\/v2\/tags?post=1553845"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}