Teenager Exposes Titan Flaw, Accesses 17 Trillion Rows of Microsoft Data
A 16-year-old security researcher discovered a flaw in Titan, an internal Microsoft analytics service, which could have allowed an attacker to access employee records and Bing search analytics.
The researcher, who goes by Faav, used an automated bug-hunting tool called Antares to identify the vulnerability. He found that Titan did not verify the signature on login tokens, allowing him to pose as the administrator and run SQL queries against 17 connected databases containing approximately 17.3 trillion rows of data.
Faav noted that this included a subset of Microsoft's workforce, which could have been used for targeted social engineering attempts. He also accessed Bing analytics source and pulled two one-row samples from its latest partition.
The researcher reported the vulnerability to Microsoft on September 5 and received a $5,000 bounty on September 17 after the endpoint was locked down on September 9. Faav emphasized that he never touched customer data or personally identifiable information (PII) during his research.