• rootsecdev Profile Picture

    rootsecdev @rootsecdev

    3 years ago

    This is going to be fun for bypassing MFA Microsoft Teams stores auth tokens as cleartext in Windows, Linux, Macs bleepingcomputer.com/news/security/…

    33 493 1K 0 213
  • FrankMcG Profile Picture

    Frank McGovern - INACTIVE @FrankMcG

    3 years ago

    @rootsecdev @cxstephens More info:

    FrankMcG Profile Picture

    Frank McGovern - INACTIVE @FrankMcG

    3 years ago

    @rootsecdev @cxstephens More info:

    0 5 17 0 1

    0 0 10 0 0
  • rwxrob Profile Picture

    𝚁𝚘𝚋 𝙼𝚞𝚑𝚕𝚎𝚜𝚝𝚎𝚒𝚗 🔮 Здравствуй. @rwxrob

    3 years ago

    @rootsecdev While this is bad, it's not that much worse than compromising any user's client-side browser data, no? Once you compromise the system enough to read these Electron files, you have free reign on every token and other file on the system.

    1 0 5 0 0
  • james1052 Profile Picture

    James Gallagher @james1052

    3 years ago

    @rootsecdev Deleted my previous reply. I still think it's meh. Low sev. Because there is always going to be a way for an attacker with existing access to get the token. They can just become SYSTEM if necessary.

    0 0 4 0 0
  • joetomasone Profile Picture

    Joe Tomasone @joetomasone

    3 years ago

    @rootsecdev Was Teams coded by the old IE devs?

    3 0 3 0 0
  • MyyLawn Profile Picture

    MIL (THE GREATEST HATER OF ALL TIME) @MyyLawn

    3 years ago

    @rootsecdev Omg Microsoft programs just like me

    0 0 3 0 0
  • dadamnmayne Profile Picture

    Unknown Artists - Cyber Threat Division @dadamnmayne

    3 years ago

    @rootsecdev I agree with the 'so what' from so many of the comments. Even if it was encrypted, that's just more fun to go find out how to break it. After all, it would have to decrypt at some point and in a manner that would not disrupt the user's experience.

    1 0 2 0 0
  • tom_fkr Profile Picture

    Tomski @tom_fkr

    3 years ago

    @rootsecdev "An attacker with local access on a system" sounds like you are already in deep 💩💩💩

    0 0 1 0 0
  • diceroll123 Profile Picture

    Dice @diceroll123

    3 years ago

    @rootsecdev Sensationalism tbh. Access to a computer means you can steal browser cookies, sniff/make web requests on behalf of someone else, hell, if you want a Discord login token you can just check the "authorization" header for any outgoing request in the network console. 😴

    0 0 1 0 0
  • pips_ai Profile Picture

    pips @pips_ai

    3 years ago

    @rootsecdev Low severity..

    0 0 1 0 0
  • pe0sat Profile Picture

    Jan | PE0SAT ☮️ @pe0sat

    3 years ago

    @rootsecdev What could possibly go wrong .....

    0 0 1 0 0
  • FrankieForOne Profile Picture

    Frankie @FrankieForOne

    3 years ago

    @rootsecdev What is the big deal? You need admin access to computer to use this and if you are admin then you can do this and so much more anyway. Even elevate yourself to SYSTEM account and dance on your grave.

    0 0 1 0 0
  • Lachlan_Mc Profile Picture

    Lachie 888 🌴 @Lachlan_Mc

    3 years ago

    @rootsecdev for fuck sake

    0 0 0 0 0
  • rimt07 Profile Picture

    IvanMT🛡⏩🕵️‍♂️ @rimt07

    3 years ago

    @rootsecdev @SaveToNotion #Thread

    1 0 0 0 0
  • Patrickcm13 Profile Picture

    Patrick cm @Patrickcm13

    3 years ago

    @rootsecdev

    0 0 0 0 0
    Download Gif
  • HickMessiah Profile Picture

    HickMessiah @HickMessiah

    3 years ago

    @rootsecdev @_JohnHammond oh no. Oh no. Oh no no no.

    0 0 0 0 0
  • seism0saurus Profile Picture

    seism0saurus @seism0saurus

    3 years ago

    @rootsecdev @robmay70 That's terrible @Microsoft Your products have an "interesting" architecture.

    0 0 0 0 0
  • dadamnmayne Profile Picture

    Unknown Artists - Cyber Threat Division @dadamnmayne

    3 years ago

    @rootsecdev Only possible solution is maybe using virtualization-based security with the tokens like credential guard.

    0 0 0 0 0
  • MathHewitt Profile Picture

    sam @MathHewitt

    3 years ago

    @rootsecdev Is this a bigger issue for guests/ federated networks??

    0 0 0 0 0
  • Alias_duel_zone Profile Picture

    Alias duel zone ⚖️ ⛓️‍💥 @Alias_duel_zone

    3 years ago

    @rootsecdev Lesson to remember forever: MFA implemented by BS editor or incompetents in basic security is plain BS! False security summit. That's all folks!

    0 0 0 0 0
  • TheBigBearUK Profile Picture

    The BigBear UK @TheBigBearUK

    3 years ago

    @rootsecdev What applications would / could one use to monitor for the listed directories or file access? Under the various platforms? Does it need different apps and setups on each is? Or is there a cross-platform solution?

    0 0 0 0 0
  • ThisIsRollo Profile Picture

    Igwe Rollo 👑 @ThisIsRollo

    3 years ago

    @rootsecdev Is there a POC for this yet?

    0 0 0 0 0
  • vxremalware Profile Picture

    TOUHAMI KA @vxremalware

    3 years ago

    @rootsecdev That's really crazy because i found these tokens on my laptop when feel bored and look for security vulnerabilities, I'm didn't expect it will be valuable as this.

    0 0 0 0 0
  • RvLeshrac Profile Picture

    RvLeshrac @RvLeshrac

    3 years ago

    @rootsecdev There's no session validation server-side? At all? Anywhere?

    1 0 0 0 0
  • Ivanratchev1 Profile Picture

    Ivanratchev @Ivanratchev1

    3 years ago

    @rootsecdev 😲

    0 0 0 0 0
  • dcc0928 Profile Picture

    dcc0928 @dcc0928

    3 years ago

    @rootsecdev 👀

    0 0 0 0 0
  • Deweyoxberg Profile Picture

    Deweyoxberg @Deweyoxberg

    3 years ago

    @rootsecdev Offs.

    0 0 0 0 0
  • LeeMWilson Profile Picture

    Lee Wilson @LeeMWilson

    3 years ago

    @rootsecdev Teams is garbage.

    0 0 0 0 0
  • acz0x1 Profile Picture

    Acz @acz0x1

    3 years ago

    @rootsecdev 🤦

    0 0 0 0 0
  • Download Image
    • Privacy
    • Term and Conditions
    • About
    • Contact Us
    • TwStalker is not affiliated with X™. All Rights Reserved. 2024 www.instalker.org

    twitter web viewer x profile viewer bayigram.com instagram takipçi satın al instagram takipçi hilesi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al sosyalgram takipçi satın al instagram ücretsiz takipçi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al metin2 metin2 wiki metin2 ep metin2 dragon coins metin2 forum metin2 board popigram instagram takipçi satın al takipçi hilesi twitter takipçi satın al tiktok takipçi satın al tiktok beğeni satın al tiktok izlenme satın al beğeni satın al instagram beğeni satın al youtube abone satın al youtube izlenme satın al buyfans buy instagram followers buy instagram likes buy instagram views buy tiktok followers buy tiktok likes buy tiktok views buy twitter followers buy telegram members Buy Youtube Subscribers Buy Youtube Views Buy Youtube Likes forstalk postegro web postegro x profile viewer