A 16-year-old security researcher used a personal AI tool, Antares, to find and exploit an internal Microsoft analytics service called Titan. The service exposed a /v2/Query endpoint that accepted raw SQL and performed claim checks on JWTs but never verified signatures. By crafting an unsigned JWT (alg: none) and setting the upn claim to "admin," the researcher was treated as Titan’s administrator and could run SQL against connected backends. Limited, careful testing returned application metadata (about 25,000 account records, ~17,990 employee emails, org records, dashboards, dataset definitions) and two one-row samples from a Bing analytics partition; no efforts were made to identify individuals or exfiltrate PII. The finding was reported through coordinated disclosure and Microsoft acknowledged the report and hardened its services.
The accessible surface mapped to 30 live routing values resolving to 24 configurations, 17 ClickHouse databases and 9,863 unique table names; metadata queries produced an estimated 17.3 trillion stored rows (a storage estimate likely including historical and derived data). The core root cause was missing JWT signature verification, which rendered all other access-control checks ineffective. The researcher credits Antares for enumeration and error-chaining while a human hunch (recognizing upn mapped to a local username) triggered the full exploit, underscoring that automated tools plus human intuition found a critical auth flaw.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.