Chaos Communication Congress

Chaos Communication Congress

From Simulation to Tenant Takeover (38x195)


: 30, 2024

All I wanted was for Microsoft to deliver my phishing simulation. This journey took me from discovering trivial vulnerabilities in Microsoft's Attack Simulation platform, to a Chinese company to which Microsoft outsourced its support department that wanted all my access tokens. I finally ended up hijacking remote PowerShell sessions and obtaining all data from random Microsoft 365 tenants, all the while reeling in bug bounties along the way.

  • : 2011
  • : 1474
  • : 0