Home / Series / Chaos Communication Congress / Aired Order / Season 38 / Episode 195

From Simulation to Tenant Takeover

All I wanted was for Microsoft to deliver my phishing simulation. This journey took me from discovering trivial vulnerabilities in Microsoft's Attack Simulation platform, to a Chinese company to which Microsoft outsourced its support department that wanted all my access tokens. I finally ended up hijacking remote PowerShell sessions and obtaining all data from random Microsoft 365 tenants, all the while reeling in bug bounties along the way.

English
  • Originally Aired December 30, 2024
  • Runtime 40 minutes
  • Production Code 281
  • Created January 2, 2025 by
    r4m3u5
  • Modified January 2, 2025 by
    r4m3u5