post-feature-image
HomeMicrosoft

Microsoft Closed XSS Vulnerability for Admin Access in Office 365 Edition

Microsoft closed cross-site scripting (XSS) vulnerability in its Office 365 edition, so the security researcher who discovered him to exp...

Microsoft Considered as an Essential Part of Our Life According to Forrester
Microsoft Rumored Upgrade Windows 8.1 Kernel Version
Surface Pro 2 Tablet Upgrated with a Faster Processor Thats Consumpting More Power
Microsoft closed cross-site scripting (XSS) vulnerability in its Office 365 edition, so the security researcher who discovered him to explain how it was done. Cogmotive-founder Alan Byrne details how the vulnerability can be exploited on their company blog as well as YouTube video demonstration.

This script loads up to two inline frames, each with a width and height values ​​set to 0 so that they are not really visible page. Script continue to use these two iframes to add a new user with administrative rights in the world and change the old user name back to normal . 

The vulnerability stems from Microsoft's failed to clear the input fields. The default implementation of Office 365, users can change their names. Since the content of this field is not checked, users can enter HTML code. Add a new user means a temporary password sent to them, to give them everything they need to connect and fully control the organization's Office 365 implementation, including original locking administrators out.
Name

Apple Apps E-Reader Facebook Games Google Internet Laptop Microsoft Phablet Smartphone Social Network Tablet Tech News
false
ltr
item
Gadgets Corner : Microsoft Closed XSS Vulnerability for Admin Access in Office 365 Edition
Microsoft Closed XSS Vulnerability for Admin Access in Office 365 Edition
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRbiELzu1k2LIa57u9ns9DzwAftNqdwW4SVc9NJY-NUPzAFPqE4i35iaGlab9tfbr6TK2gCcDXjiFvGfbsdyT3FrKQu4lOXoURAxVlACOFa_hlJCpJgtLCf7M-YUAW2u7nn7TEKFbeqNEE/s1600/office365.png
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRbiELzu1k2LIa57u9ns9DzwAftNqdwW4SVc9NJY-NUPzAFPqE4i35iaGlab9tfbr6TK2gCcDXjiFvGfbsdyT3FrKQu4lOXoURAxVlACOFa_hlJCpJgtLCf7M-YUAW2u7nn7TEKFbeqNEE/s72-c/office365.png
Gadgets Corner
https://cmdcorner.blogspot.com/2014/01/microsoft-closed-xss-vulnerability-for.html
https://cmdcorner.blogspot.com/
http://cmdcorner.blogspot.com/
http://cmdcorner.blogspot.com/2014/01/microsoft-closed-xss-vulnerability-for.html
true
2424653965478038045
UTF-8
Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago