IT manager gets certificate for Microsoft domain, tries to report it but gets in trouble

He tried to alert the company in January, but the company never got his emails, and later suspended his Microsoft account

Oversight allowed researcher to register live.fi administrative email addresses.

Oversight allowed researcher to register live.fi administrative email addresses.

After a security enthusiast discovered a loophole that allowed him to register a valid SSL certificate for Microsoft's live.fi domain, he tried to responsibly disclose the issue. But instead of thanks he got locked out of his email, phone, Xbox and online storage accounts.

The issue was discovered by a Finnish man who works as an IT manager for a company in the industrial sector. He talked to the IDG News Service, but requested anonymity.

Microsoft's Outlook.com email service allows users to have multiple email addresses called aliases under a single account. At the moment, the service only allows aliases to be created on the @outlook.com domain, but several months ago more domains were available.

Around six months ago the Finnish IT manager, who already had a @live.fi and @live.com address, got the idea to check if he could register any privileged usernames as his additional aliases.

Privileged usernames like admin@, administrator@, postmaster@, hostmaster@ and webmaster@ are typically reserved for use by domain name owners for administrative purposes, but the IT manager managed to register hostmaster@live.fi, security@live.fi and hostmaster@hotmail.fi as his aliases because Microsoft did not block them.

Initially he thought that he might receive potentially sensitive email messages intended for the domain owner and that he would then report the issue, but as time passed, no email came for those addresses. Then, in January he got the idea to try to obtain an SSL certificate using one of the addresses.

He chose a certificate authority called Comodo because the company offers certificates for free that are valid for 90 days and because it accepts domain ownership verification through admin-type email addresses.

According to the IT manager, he obtained the certificate late on January 26 and the whole process took around 10 minutes which made him believe that it was fully automated. The following day he reported the issue to CERT-FI, which is part of the National Cyber Security Centre Finland.

He also claims that he reported the issue to an email address listed as contact for the live.fi domain on Jan. 31 and to security@microsoft.com on Feb. 24, but he received no response from either address. It's worth noting that the proper contact email at Microsoft for reporting vulnerabilities is secure@microsoft.com, not security@microsoft.com. However, according to a Microsoft blog post from 2006, there should be an automatic response from security@microsoft.com with information about the proper contact.

Microsoft issued an update Monday to blacklist the improperly issued certificate, but not before suspending the IT manager's account on March 12. This locked him out not only from his email, but also OneDrive, Xbox Live, Lumia phone and other Microsoft services. Microsoft finally unlocked his account today.

"Of course, not all the decisions I made were smart, but I tried my best," he said, referring to how he handled the investigation and reporting of the issue.

"Through our own investigations, independent from the researcher, we identified and have fixed the misconfiguration that was allowing people to create accounts reserved for Microsoft's use," a Microsoft representative said via email Wednesday.

The Microsoft representative added that it is "standard practice" for the company to disable accounts where there may be a violation of Microsoft's terms of service or where a security risk could be present, and to guide account holders on how to recover access the next time they try to log in. "Through this process, we contacted the researcher and are working with him to restore his account," the representative said.

The IT manager confirmed after Microsoft sent its statement that he regained access to his account.

Administrative email addresses need to be reserved from the start, so that nobody can use them maliciously, said Frans Rosén, co-founder of Web security firm Detectify, via email. Some certificate issuers manually verify domain ownership, but such email addresses, along with those listed in domain whois records, are often accepted for verification by default, making their hijacking really dangerous, he said.

Rosén expressed surprise that Microsoft failed to protect those usernames, saying that this is a fairly commonly known problem for services that allow user-generated email addresses.

Researchers at Detectify recently investigated how forgotten subdomains can be abused by attackers, possibly to obtain SSL certificates which could then be used in man-in-the-middle attacks.

Join the newsletter!

Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection

Tags securityMicrosoftencryptiononline safetypkiExploits / vulnerabilities

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Lucian Constantin

IDG News Service
Show Comments

Cool Tech

SanDisk MicroSDXC™ for Nintendo® Switch™

Learn more >

Breitling Superocean Heritage Chronographe 44

Learn more >

Toys for Boys

Family Friendly

Panasonic 4K UHD Blu-Ray Player and Full HD Recorder with Netflix - UBT1GL-K

Learn more >

Stocking Stuffer

Razer DeathAdder Expert Ergonomic Gaming Mouse

Learn more >

Christmas Gift Guide

Click for more ›

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Ratchada Dunn

Sharp PN-40TC1 Huddle Board

The Huddle Board’s built in program; Sharp Touch Viewing software allows us to easily manipulate and edit our documents (jpegs and PDFs) all at the same time on the dashboard.

George Khoury

Sharp PN-40TC1 Huddle Board

The biggest perks for me would be that it comes with easy to use and comprehensive programs that make the collaboration process a whole lot more intuitive and organic

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?