Collected research
Azure B2C Crypto Misuse and Account Compromise
Technical Advisory - Azure B2C - Crypto Misuse and Account Compromise
Azure AD B2C custom policies follow Microsoft's own tutorial in encrypting OAuth refresh tokens under an RSA key, but RSA encrypts with the public half, which is not a secret. An attacker who recovers that public key can mint a refresh token carrying any claims for any user and redeem it for a session, taking over accounts without credentials; the researchers demonstrated it against Microsoft's own MSRC researcher portal to read other people's vulnerability reports.
Record
- Document
- Technical Advisory - Azure B2C - Crypto Misuse and Account Compromise
- Researcher
- Justin Copeland and @praetorianlabs
- Published by
- Praetorian
- Date
- Topic
- Crypto
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Justin Copeland and @praetorianlabs, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .