By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
DIGITAL TRENDDIGITAL TREND
  • Tech Updates
  • Featured
  • Course
  • Tutorial
  • News
  • Technology
  • Mobiles
  • Spotrs
Search
© 2023 digitaltrend.in Company. All Rights Reserved.
Reading: Bing had a flaw that allowed changing the search results and seeing data from Microsoft 365 users – DIGITALTREND
Share
Notification Show More
Latest News
Samsung launches line of TVs for 2023 with new QLED 8K and OLED debut – DIGITALTREND
07/06/2023
Galaxy A34 5G 128 GB is for almost half the original price – DIGITALTREND
07/06/2023
iPhone 13 of 128 GB is with more than R$ 2 thousand of discount in relation to the Apple store – DIGITALTREND
06/06/2023
Apple Watch SE 44 mm has more than 35% off and lowest price of the year on offer on Amazon – DIGITALTREND
06/06/2023
iPad 10th generation 64 GB has almost R$ 1 thousand off on offer – DIGITALTREND
06/06/2023
Aa
DIGITAL TRENDDIGITAL TREND
Aa
  • Tech Updates
  • Mobiles
  • Programming
  • Hacking
  • Featured
  • Technology
  • Tools
  • About Us
  • Contact Us
  • Terms And Conditions
Search
  • Tech Updates
  • Mobiles
  • Programming
  • Hacking
  • Featured
  • Technology
  • Tools
  • About Us
  • Contact Us
  • Terms And Conditions
© 2022 digitaltrend.in Company. All Rights Reserved.
Join Whatsapp Group To get Daily Update.
DIGITAL TREND > Blog > Artificial intelligence > Bing had a flaw that allowed changing the search results and seeing data from Microsoft 365 users – DIGITALTREND
Artificial intelligence

Bing had a flaw that allowed changing the search results and seeing data from Microsoft 365 users – DIGITALTREND

SUPERMAN♥
SUPERMAN♥ 31/03/2023
Updated 2023/03/31 at 12:25 AM
Share
3 Min Read
SHARE


To the best deals,
no tail stuck

Due to a flaw in Microsoft’s application configuration, anyone could access and modify Bing’s search results. “Could”, as the problem was discovered on January 31, 2023, but was fixed by the company on March 28. One of the proofs of the defect was the change in the list of “Best soundtracks”, which changed the film Dune per Hackers: Computer Hackers.

Bing (Image: Unsplash / Rubaitul Azad)
Bing (Image: Unsplash/Rubaitul Azad)

The discovery was made by the team of analysts from Wiz Research, a group of professionals that aims to detect threats to the cloud and build mechanisms to protect it. They realized that when building an app on Azure App Services and Azure Functions, the software could be misconfigured to allow users access to the app.

Next, analysts discovered a program called “Bing Trivia” that was misconfigured and allowed anyone to log in and access the app’s Content Management System. However, it didn’t take long for the team to notice that Bing.com was directly linked to the app. That is, it was possible to enter the Microsoft search engine and modify it.

As a test, they successfully tried to change the search result on “Best Soundtracks”. The professionals changed the first title to appear on the list, from its name to its representation image. The team at Wiz Research even managed to add a link and generic text.

XSS attack on Bing was also possible

Analysts decided to try injecting a payload through the same loophole they found in the “Bing Trivia” app. They soon realized that they managed to execute an XSS (Cross-Site Scripting) attack, which would place malicious code on Bing.com, turning it into a trap for users.

Testing by the Wiz Research team proved that it was possible to compromise the security of Microsoft 365 as soon as a user saw the carousel on the search results page. This would give cybercriminals full access to personal information such as email, Teams messages, and OneDrive files.

Once they were certain of their findings, the professionals shared the data with Microsoft.

Redmond’s company claimed that the flaw only affected a small portion of internal apps, but that fixes were immediately implemented. It also reported that it has introduced security improvements to prevent configuration errors in Microsoft Azure from becoming issues in the future.

Finally, the company said announcement released on Wednesday (29), that “this type of functionality has been disabled in 99% of applications for consumers”.

With information: Bleeping Computer.

BingMicrosoftMicrosoft 365

You Might Also Like

Samsung launches line of TVs for 2023 with new QLED 8K and OLED debut – DIGITALTREND

Galaxy A34 5G 128 GB is for almost half the original price – DIGITALTREND

iPhone 13 of 128 GB is with more than R$ 2 thousand of discount in relation to the Apple store – DIGITALTREND

Apple Watch SE 44 mm has more than 35% off and lowest price of the year on offer on Amazon – DIGITALTREND

iPad 10th generation 64 GB has almost R$ 1 thousand off on offer – DIGITALTREND

TAGGED: allowed, Bing, changing, data, DIGITALTREND, flaw, Microsoft, results, search, users

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
[mc4wp_form]
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
SUPERMAN♥ 31/03/2023
Share this Article
Facebook TwitterEmail Print
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Samsung 55″ QLED 4K TV has a discount of more than R$ 1 thousand in this offer – DIGITALTREND
Next Article Sky should expand internet via fiber to more than 40 cities after new partnership with neutral network – DIGITALTREND

Stay Connected

235.3k Followers Like
69.1k Followers Follow
11.6k Followers Pin
56.4k Followers Follow
136k Subscribers Subscribe
4.4k Followers Follow

Latest News

Samsung launches line of TVs for 2023 with new QLED 8K and OLED debut – DIGITALTREND
Apps And Software 07/06/2023
Galaxy A34 5G 128 GB is for almost half the original price – DIGITALTREND
Artificial intelligence 07/06/2023
iPhone 13 of 128 GB is with more than R$ 2 thousand of discount in relation to the Apple store – DIGITALTREND
Artificial intelligence 06/06/2023
Apple Watch SE 44 mm has more than 35% off and lowest price of the year on offer on Amazon – DIGITALTREND
Artificial intelligence 06/06/2023

You Might also Like

Apps And Software

Samsung launches line of TVs for 2023 with new QLED 8K and OLED debut – DIGITALTREND

07/06/2023
Artificial intelligence

Galaxy A34 5G 128 GB is for almost half the original price – DIGITALTREND

07/06/2023
Artificial intelligence

iPhone 13 of 128 GB is with more than R$ 2 thousand of discount in relation to the Apple store – DIGITALTREND

06/06/2023
Artificial intelligence

Apple Watch SE 44 mm has more than 35% off and lowest price of the year on offer on Amazon – DIGITALTREND

06/06/2023
//

We influence 20 million users and is the number one business and technology news network on the planet

DIGITAL TRENDDIGITAL TREND

© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.

Removed from reading list

Undo
AdBlock Detected
Our site is an advertising supported site. Please whitelist to support our site.
Okay, I'll Whitelist
Welcome Back!

Sign in to your account

Lost your password?