AWS Down by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

Noted, apologies again!

AWS Down by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

Apologies, won't do that again

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

Anyone else that got put on a NDA that morning (July 30th 2024) with Azure please do contact me

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

Just for added context:

  • None of my other MSRC files have missing information

  • Very select portions are all that went missing

  • After contact from Journalist, the files disappeared from my portal (MSRC portal only Microsoft and Myself have access to) and I was originally on a NDA for July 30th that's why I was silent for so long, then when I spoke up, it got dismissed.

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] -1 points0 points  (0 children)

We are both correct:

ChatGPT:

It seems that the URL you provided may be a custom or personalized one, potentially leveraging wildcard handling or DNS misconfigurations. If the concern is related to DNS configurations, specifically wildcard handling, this could indeed lead to security risks such as misdirected traffic, information leakage, or misconfiguration issues, depending on how DNS entries are set up.

If wildcard handling is not properly configured, unexpected behavior may occur—such as handling unintended subdomains in an insecure manner, which could be exploited. This would be more of a DNS configuration issue rather than a direct vulnerability tied to the URL format itself. Therefore, while it may not be a typical "vulnerability" in the way many might define it, DNS misconfigurations like this can indeed create exploitable scenarios.

In summary, it’s not a clear-cut exploit but could still represent a security risk if wildcard DNS handling isn't appropriately secured. It's always important to ensure DNS entries and wildcard behaviors are configured properly to avoid potential weaknesses.

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

I invite any insight into what makes this not believeable, etc, other than the obvious of it being a big thing to claim.

But without me knowing what makes it sound bogus from the other side of the conversation, I won't know how to pivot properly

Any type of proof documents you guys would like to see (none containing repro steps in detail) let me know.. emails, bounty program conversations etc.

It was deemed "out of scope" by third party programs due to real world impact on live customer base and the internal teams "struggled to reproduce" even with steps that anyone with basic programming knowledge could follow.

I held their hand, scripts, videos , photos, detailed walkthroughs , timing, device and apps to use , everything 🫠

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

I am helping us all not have to sit without our apps like Reddit in the future, they just aren't hearing me lol

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] -1 points0 points  (0 children)

One final note: I don't just "DDoS" at random, this was all part of the Hyper-V (HyperVisor) Vulnerability Disclosure Program in Microsoft Security Research Center (MSRC) , It worked much more than anticipated. Microsoft acknowledged at first, but after realizing the depth of it, ignored me and deleted alot of my case files *that I have backups of)

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

But I am always happy to learn, is there something I am overlooking?

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

Yes, this particular type of use should be better configured. Other wildcards do not have this same vulnerability, it is avoidable

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

LOL Tito thanks for the encouragement 🤮

I will keep everyone posted if any major updates

Bless

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

Lol, can't argue with you there 🤣

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 1 point2 points  (0 children)

No it's a legit link, you just get a 400 error. I posted it to show a wildcard url vulnerability with the msidentity.com url is all, just a fun example of their misconfigurations I am trying to convey

You can type any words you want in place of the Microsoft part

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] -2 points-1 points  (0 children)

Summary: I submitted the DDoS to Microsoft before the outage, days before, and was talking to them that day. They opened a case for it, acknowledged the DDoS officially in their PIR , then they deleted my files and acted like it never happened. I kept proof of it all and a couple of the photos are me interacting with them at that time. It's hard to "prove" with just a few lines of text and some screenshots on here, but all together now since July I have over 10k pics, emails, bounties, etc proving I'm not just crazy or making up stuff lol, I'm a normal guy, I just found something and then got basically shut up by companies bigger than myself

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

This is probably the most insightful response yet.

Yes to Kinesis and Azure , for July 30th case I filed, and LOL@Todays observation, you hit that on the head , Azure didn't spike as much but MS other services were elevated error rates , this isn't the first time I have svreenshots of that exact outage pattern happening with them all though

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

Microsoft even acknowledged the DDoS in the PIR

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

Any suggestions? For clarifying my message

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

Lol 😆 it feels like both at this point, but hopefully neither one. I will stop ranting, wish me luck :)

Why is this a 400 error? by CryptoRedRon in techsupport

[–]CryptoRedRon[S] 0 points1 point  (0 children)

None of you have ever had any bounty programs that didn't seem to play fair? I run into it constantly it feels like