MSRC bug ππ
A month ago I noticed people talking about devtunnels
I was so fascinated by the "new ngrok", after poking around for some time. I stumbled on this redirection which send the AAD token for oauth flow 1/nlearn.microsoft.com/en-us/azure/deβ¦
the url looked like this global.rel.tunnels.api.visualstudio[.]com/auth/postback?pb=url&scheme=aad where url is your private devtunnel url, the issue was your token can be sent to any devtunnel url, basically an open redirect to anything.uks1.devtunnels[.]ms 2/n
exploitation was easy, I made my devtunnel that forwards my local web server public using --anonymous 'devtunnel access list <devtunnel_id> --anonymous' then send the url from previous reply to victim 3/n
the token stolen gives full access to victim tunnels and other information 4/4
example of what I was able to steal
@threadreaderapp unroll
β’ β’ β’
Missing some Tweet in this thread? You can try to
force a refresh