Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


Lias

5699 posts

Uber Geek
+1 received by user: 4019

ID Verified
Trusted
Lifetime subscriber

#300522 15-Sep-2022 12:56
Send private message

https://www.vectra.ai/blogpost/undermining-microsoft-teams-security-by-mining-tokens

 

TL;DR, Teams auth tokens are stored unencrypted and accessible by any user of a machine, even non privileged users.





I'm a geek, a gamer, a dad, a Quic user, and an IT Professional. I have a full rack home lab, size 15 feet, an epic beard and Asperger's. I'm a bit of a Cypherpunk, who believes information wants to be free and the Net interprets censorship as damage and routes around it. If you use my Quic signup you can also use the code R570394EKGIZ8 for free setup. Opinions are my own and not the views of my employer.


View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2
Dynamic
4081 posts

Uber Geek
+1 received by user: 1898

ID Verified
Trusted
Lifetime subscriber

  #2968611 15-Sep-2022 13:03
Send private message

Wow.  Thanks for posting this.





“Don't believe anything you read on the net. Except this. Well, including this, I suppose.” Douglas Adams




MikeB4
MikeB4
18956 posts

Uber Geek
+1 received by user: 13166

ID Verified
Trusted
Subscriber

  #2968619 15-Sep-2022 13:22
Send private message

Thanks heaps for that 





A world that has gone totally insane.


amanzi
Amanzi
1375 posts

Uber Geek
+1 received by user: 357

ID Verified
Trusted
Lifetime subscriber

  #2968620 15-Sep-2022 13:26
Send private message

"accessible by any user of a machine, even non privileged users" I don't believe this is true, but happy to be proved wrong. The token should be stored in the user profile and only that user would have access to it. An administrator on the machine would be able to get to it, but that's by design and is part of the trust model of having administrator rights. Perhaps encrypting the file would be a good idea, but there are lots of tokens stored in a user profile that contain sensitive data.




Beccara
1473 posts

Uber Geek
+1 received by user: 517

ID Verified

  #2968627 15-Sep-2022 13:45
Send private message

Until I see something else I agree with Amanzi, the folders they are telling you to monitor are within user profiles. You'd need local admin priv's to gain access without using another privesc vuln.

 

It's certainly could evolve into something that can be drive-by'ed but right now you'd need access and other vulns





Most problems are the result of previous solutions...

All comment's I make are my own personal opinion and do not in any way, shape or form reflect the views of current or former employers unless specifically stated 

gzt

gzt
19639 posts

Uber Geek
+1 received by user: 8749

Lifetime subscriber

  #2968661 15-Sep-2022 15:15
Send private message

Lias: PSA: Don't use Teams on shared devices. TL;DR, Teams auth tokens are stored unencrypted and accessible by any user of a machine, even non privileged users.

Microsoft announced some time ago they were dropping Electron. Based on previous statements from Microsoft I'm thinking the built in Windows 11 Teams does not use Electron at all.


gzt

gzt
19639 posts

Uber Geek
+1 received by user: 8749

Lifetime subscriber

  #2968668 15-Sep-2022 15:33
Send private message

There are a number of claims in that article. I skimmed. On a W10 system I examined "Session Storage" in the user profile is permissioned appropriately for a managed machine.

 
 
 
 

Shop now on Samsung phones, tablets, TVs and more (affiliate link).
Ruphus
472 posts

Ultimate Geek
+1 received by user: 182


  #2968675 15-Sep-2022 15:51
Send private message

TBH, if an attacker had local or remote access to the file system (which is required to get a hold of these tokens), there's other issues that need to be addressed first.


Beccara
1473 posts

Uber Geek
+1 received by user: 517

ID Verified

  #2968676 15-Sep-2022 15:55
Send private message

Yeah it's not a point of entry, could be used for lateral movement but so could a keylogger at that point.





Most problems are the result of previous solutions...

All comment's I make are my own personal opinion and do not in any way, shape or form reflect the views of current or former employers unless specifically stated 

plas
456 posts

Ultimate Geek
+1 received by user: 59


  #2968680 15-Sep-2022 16:03
Send private message

Beccara:

 

Yeah it's not a point of entry, could be used for lateral movement but so could a keylogger at that point.

 

 

 

 

Better option would be to grab the browser profiles.


Lias

5699 posts

Uber Geek
+1 received by user: 4019

ID Verified
Trusted
Lifetime subscriber

  #2968753 15-Sep-2022 18:18
Send private message

amanzi:

 

"accessible by any user of a machine, even non privileged users" I don't believe this is true, but happy to be proved wrong. The token should be stored in the user profile and only that user would have access to it. An administrator on the machine would be able to get to it, but that's by design and is part of the trust model of having administrator rights. Perhaps encrypting the file would be a good idea, but there are lots of tokens stored in a user profile that contain sensitive data.

 

 

"an attack path that enables malicious actors with file system access to steal credentials for any Microsoft Teams user who is signed in. Attackers do not require elevated permissions to read these files, which exposes this concern to any attack that provides malicious actors with local or remote system access"





I'm a geek, a gamer, a dad, a Quic user, and an IT Professional. I have a full rack home lab, size 15 feet, an epic beard and Asperger's. I'm a bit of a Cypherpunk, who believes information wants to be free and the Net interprets censorship as damage and routes around it. If you use my Quic signup you can also use the code R570394EKGIZ8 for free setup. Opinions are my own and not the views of my employer.


gzt

gzt
19639 posts

Uber Geek
+1 received by user: 8749

Lifetime subscriber

  #2968756 15-Sep-2022 18:33
Send private message

Lias:/Article: Attackers do not require elevated permissions to read these files

This part is not explained unless I missed it in the text. The article names browser cache and Teams/Electron appdata "session cookies" SQLite file. As standard in Win 10 both directories restrict access to the named user, admin user and system user.

 
 
 
 

Shop now on Samsung phones, tablets, TVs and more (affiliate link).
nztim
4147 posts

Uber Geek
+1 received by user: 2876

ID Verified
Trusted
TEAMnetwork
Subscriber

  #2968759 15-Sep-2022 18:48
Send private message

using the browser version inside incognito is okay other than that no no no and no





Any views expressed on these forums are my own and don't necessarily reflect those of my employer. 


mwh

mwh
43 posts

Geek
+1 received by user: 16


  #2968763 15-Sep-2022 19:17
Send private message

Lias:

 

"an attack path that enables malicious actors with file system access to steal credentials for any Microsoft Teams user who is signed in. Attackers do not require elevated permissions to read these files, which exposes this concern to any attack that provides malicious actors with local or remote system access"

 

i.e. attackers who have access to the running user account do not need to elevate permissions to read files owned by the running user account. There are certainly more-protected ways to store credentials, but this article is hyperbolic clickbait (and there's nothing to do with shared devices or multiple users even then).


amanzi
Amanzi
1375 posts

Uber Geek
+1 received by user: 357

ID Verified
Trusted
Lifetime subscriber

  #2968776 15-Sep-2022 19:56
Send private message

Lias:

 

"an attack path that enables malicious actors with file system access to steal credentials for any Microsoft Teams user who is signed in. Attackers do not require elevated permissions to read these files, which exposes this concern to any attack that provides malicious actors with local or remote system access"

 

 

As I and others have pointed out in this thread you're getting confused with the threat, and the inflammatory way this article is written is not helping. The tokens are only accessible by the user that created the token, or someone with administrator privileges to the computer. You started this thread with a title that said, "Don't use Teams on shared devices" and then you made a claim that these tokens are "accessible by any user of a machine, even non privileged users". But that is absolutely not true and can easily be verified by anyone who is using Teams by checking the file permissions of the files mentioned in the article. On a Windows machine these tokens are stored in the %APPDATA% directory which is only accessible by the logged-on user (and an administrator account). So a non-privileged user would not be able to access another user's token on a shared device. I haven't tested this on Linux or macOS so I can't say for sure, but I know the default behaviour on either of these operating systems is that anything inside the home directory is only accessible by that user.


gzt

gzt
19639 posts

Uber Geek
+1 received by user: 8749

Lifetime subscriber

  #2968823 15-Sep-2022 20:46
Send private message

Based on the file locations provided at the end of the article - "Attackers do not require elevated permissions to read these files" - the only thing that could make that statement true based only on the other information provided is creation of non-standard non-default user profile directories. I expect that sometimes occurs for administrative reasons relating to profile management.

 1 | 2
View this topic in a long page with up to 500 replies per page Create new topic









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.