Web Hack List

Collected research

Azure B2C Crypto Misuse and Account Compromise

Technical Advisory - Azure B2C - Crypto Misuse and Account Compromise

Azure AD B2C custom policies follow Microsoft's own tutorial in encrypting OAuth refresh tokens under an RSA key, but RSA encrypts with the public half, which is not a secret. An attacker who recovers that public key can mint a refresh token carrying any claims for any user and redeem it for a session, taking over accounts without credentials; the researchers demonstrated it against Microsoft's own MSRC researcher portal to read other people's vulnerability reports.

Record

Document
Technical Advisory - Azure B2C - Crypto Misuse and Account Compromise
Researcher
Justin Copeland and @praetorianlabs
Published by
Praetorian
Date
Topic
Crypto

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Justin Copeland and @praetorianlabs, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .