A VPN door, and an API window left open
A 16-year-old researcher, Faav, leveraged his automation tool, Antares, to uncover Titan, an internal Microsoft analytics service. This discovery exposed a critical architectural misstep: a corporate VPN secured Titan’s web interface, yet its cloud-hosted API and associated documentation remained publicly accessible. This boundary mismatch created an immediate vulnerability.
Crucially, one specific API route, /v2/Query, bypassed standard Entra ID authentication. Unlike other documented routes, /v2/Query reportedly accepted raw SQL queries directly, offering an unauthenticated access vector into Microsoft’s internal data infrastructure. This singular exposure represented a significant lapse in access control.
Faav exploited this open window, demonstrating how a publicly exposed API, coupled with a bypassed authentication mechanism, can undermine even robust perimeter defenses. This incident underscores the imperative for comprehensive security audits across all service interfaces, not just the front-end.
The JWT checked everything—except the signature
Faav’s next step involved understanding Titan’s internal architecture. Using a 2023 Wayback Machine snapshot, he recovered 56 table definitions, providing a critical blueprint of the service’s data structure. This reconnaissance revealed the precise data points available for querying.
Then came the authentication challenge. Titan utilized JSON Web Tokens (JWTs), and Faav observed a critical flaw: the service checked various token claims—such as tenant, audience, and app ID—but it entirely skipped cryptographic signature validation. This oversight rendered claim validation meaningless.
A token with "alg": "none" in its header and an empty signature payload could therefore pass all checks. Without a signature to verify the token’s integrity and origin, Titan accepted the forged credentials as legitimate. Claim validation alone cannot establish trust; it is the signature verification that authenticates the token’s sender and prevents tampering. Faav now had a pathway to bypass Titan’s security.
One word turned a broken token into admin access
Faav faced one final hurdle: user authentication. Email-style usernames for Titan consistently failed, despite the forged JWT. After persistent attempts, a simple, plain username—admin—succeeded, mapping to local UserID 1, which inherently carried an administrative role. This single word unlocked extensive access.
Admin privileges revealed a significant internal footprint. Faav gained visibility into 30 live routing targets and 17 analytics databases, including the critical Bing Analytics. The exposed metadata encompassed approximately 25,000 internal Microsoft accounts.
Headline figures, such as the estimated 17.3 trillion rows, represented the theoretical storage capacity of the accessible databases, not confirmed records accessed or exfiltrated. Faav maintained strict ethical boundaries, never touching customer data, and reported the vulnerability the same day. For additional context on this remarkable disclosure, read about the Open Microsoft Database With 17 Trillion Total Rows and 25,000 User Accounts Hacked by a Bored Teenager. Microsoft remediated the endpoint within four days and awarded a $5,000 bounty.
Enjoying this? Get one like it in your inbox each morning.
one email a day · unsubscribe in two clicks · no third-party tracking
A four-day fix—and a bigger security lesson
Faav practiced responsible disclosure, confirming he never accessed customer data. Microsoft responded swiftly, restricting the exposed endpoint and strengthening token checks within four days. This prompt action contained what could have been a catastrophic breach, given the 17.3 trillion rows of data Faav could reach.
The $5,000 bounty awarded to Faav sparked community debate. Many argued the payout was modest given the potential impact of admin access to 30 routing targets and 17 analytics databases, including Bing Analytics. The broader lesson, however, extends beyond the bounty.
This incident offers critical takeaways for cloud security teams. Ensure your systems verify JWT signatures and outright reject unsigned tokens, especially those leveraging the alg: "none" vulnerability. Furthermore, eliminate default privileged accounts like admin that map to predictable User IDs.
Finally, independent testing of backend API routes is paramount. A VPN-protected interface offers a false sense of security if unauthenticated public cloud endpoints remain exposed. Robust security demands vigilance across all layers, not just the front door.
Frequently Asked Questions
What was Microsoft Titan?
Titan was an internal Microsoft analytics service that provided access to routing targets and analytics databases.
How did Faav gain administrative access?
The API accepted a JWT without verifying its signature, and the username “admin” mapped to an account with administrative privileges.
Was data from 17.3 trillion rows stolen?
No confirmed customer-data theft was reported. The figure described a theoretical maximum storage volume, and Faav said he did not access customer data.
How did Microsoft respond?
Microsoft reportedly fixed the exposed endpoint within four days and awarded Faav a $5,000 bug bounty.

