6g4a! |
GitHub - secureworks/family-of-client-ids-research: Research into Undocumented Behavior of Azure AD Refresh Tokens
https://github.com/secureworks/family-of-client-ids-research
Saved on 2023-08-09 [19578 edays] via github.com
Modified 2023-08-09 [19578 edays]
azure cybersecurity
https://github.com/secureworks/family-of-client-ids-research
Saved on 2023-08-09 [19578 edays] via github.com
Modified 2023-08-09 [19578 edays]
azure cybersecurity
Undocumented functionality in Azure Active Directory allows a group of Microsoft OAuth client applications to obtain special “family refresh tokens,” which can be redeemed for bearer tokens as any other client in the family. We will discuss how this functionality was uncovered, the mechanism behind it, and various attack paths to obtain family refresh tokens. We will demonstrate how this functionality can be abused to access sensitive data. Lastly, we will share relevant information to mitigate the theft of family refresh tokens.