Teen Security Researcher Finds Authentication Flaw in Microsoft Analytics Platform

A 16-year-old security researcher known as Faav discovered an authentication vulnerability in Microsoft's internal Titan analytics platform that potentially exposed access to databases containing an estimated 17 trillion rows of data, Bruno Ferreira reported for Tom's Hardware.
![A teenage security researcher known as Faav discovered an authentication vulnerability in Microsoft's internal Titan analytics platform and reported it through the company's bug-bounty program. [Photo: Microsoft X]](https://static.wixstatic.com/media/1c4fd3_67473056d564416aa7874d0c12bf3cb3~mv2.jpg/v1/fill/w_980,h_515,al_c,q_85,usm_0.66_1.00_0.01,enc_avif,quality_auto/1c4fd3_67473056d564416aa7874d0c12bf3cb3~mv2.jpg)
Faav said he had spent much of the year researching vulnerabilities in products and services operated by Microsoft and other technology companies.
He used a custom artificial-intelligence tool called Antares to automate parts of his security research.
According to reporting on his disclosure, Faav discovered an exposed application-programming interface (API) associated with Titan. The system had authentication controls, but one route did not properly validate the authenticity of the security token presented to it.
Faav eventually obtained administrator-level access by exploiting that authentication weakness.
The access allowed him to inspect information associated with Titan's analytics environment, including application-account and employee information.
Reporting indicates that he accessed approximately 25,000 application-account records and around 17,990 employee email records while testing the vulnerability. He also confirmed access to information associated with Bing analytics.
The figure of roughly 17 trillion rows refers to the estimated amount of data contained across connected analytics databases that could potentially have been reachable through the vulnerability.
It does not mean that Faav downloaded or extracted 17 trillion individual records. He limited his testing and reported the vulnerability to Microsoft's security-response program.
Microsoft subsequently fixed the vulnerability and awarded Faav a $5,000 bug bounty, according to reporting on the disclosure.
Faav said the discovery resulted from a combination of automated work by Antares and a human insight that allowed him to identify the authentication weakness.
![TFD [LOGO] (10).png](https://static.wixstatic.com/media/bea252_c1775b2fb69c4411abe5f0d27e15b130~mv2.png/v1/crop/x_150,y_143,w_1221,h_1193/fill/w_179,h_176,al_c,q_85,usm_0.66_1.00_0.01,enc_avif,quality_auto/TFD%20%5BLOGO%5D%20(10).png)










