Security Audit

Our Web Application Pentest ( WAP) attempts to address the Owasp top 10 & SANS top 20 web application vulnerabilities and other exploitable loopholes of your web application . Along with it our WAP team also test web applications for Business logic flaws that can directly or indirectly effect the functioning of application.

Trainings

We are here to help you solve your biggest query- where and how to start? CDI has brought various courses in Ethical Hacking in Chandigarh where all you technology lovers will be given the much needed push to move forward and create a niche for yourself in the field. From Beginner to Expert level we have many kinds of training patterns.

By Exploiting This Office 365 Flaw, Attackers Can Send You Malicious Emails

 

 

Every windows user is also using Office 365 to maintain his business records and daily work. A major security vulnerability in Office 365 has been discovered by a Turkish security researcher, which is allowing attackers to send spoofed malicious emails from a fake “Microsoft.com” address. The name of this Turkish security researcher is “Utku Sen”. He is a cyber-security enthusiast and giving his best to protect the cyberspace from hackers. Utku Sen is known for his “Hidden Tear” named ransomware, which he had released for educational purposes.

 

What is the Exact Security Issue?

Utku said that he was testing spam filters of various email platform including Gmail, Outlook 365 and Yandex. He was using SEES (Social Engineering Email Sender) tool to conduct these tests. Utku was sending phishing emails from SEES tool and he noticed that Yandex was showing some of them as valid emails. Yandex was performing a DKIM (DomainKeys Identified Mail) verification process and after that, it was marking those phishing emails with a green signal. This green signal has been used by Yandex email filters to identify legit emails.

 

Confused? Let Us Explain It.

Actually, Utku was using a spoofed “Microsoft.com” domain based email address to send those phishing emails. Email filters of Yandex were marking them as legit emails due to the use of “Microsoft.com” domain. These emails were forwarded by Utku through Outlook 365 to Yandex. He performed the same tests on Gmail also. Utku sent some phishing emails from spoofed “microsoft.com” outlook account to a Gmail account and it was also marking those malicious emails as legit emails. Then he used some other spoofed domain names instead of “Microsoft.com” and the emails were going directly into spam folders.

 

Utku was also not understanding this issue. Then a “ptmb” named Reddit user explained the whole security issue. In actual, Outlook was signing all the redirected messages with its own DKIM keys. When spam filters of Outlook, Yandex and Gmail were verifying DKIM keys of phishing emails, they were marking it as legit because all the DKIM keys were legit outlook DKIM keys. Outlook was blindly signing all those emails which contain a fake Microsoft.com type saying in it’s from field. It means user will get an email from a redirector instead of a sender.

 

Update Your Office 365 ASAP

After discovering this major security issue, Utku immediately reported it to Microsoft. After testing, Microsoft found it right and they released an update in last week of October to fix it. If you are using an old version of Office 365, then update is as soon as possible. Some phishing cases have been noticed by security experts related to this vulnerability.  

 

Other Hot Hacking News:

Official Website of “Eastern India Regional Council” Hacked, 17000 User Accounts Exposed

Adobe Has to Pay $1 Million As Fine For Major 2013 Data Breach 

The Public Wi-Fi Network of Whole “Israeli City” Hacked By This Hacker

See more of Cyber Intelligence by logging in.
Connect with cyber security experts,Discover job opportunities,Online Training, Information Security Advisory and lot more.