A security researcher has found a critical flaw with Microsoft’s Office 365 service that allowed users to access other users’ private documents. Kevin Beumont discovered that the search bar on the homepage of Docs.com, Microsoft’s Office 365 document sharing site, was showing files that were not intended for public sharing in its results.
Microsoft says that “with Docs.com, you can create an online portfolio of your expertise, discover, download, or bookmark works from other authors, and build your brand with built-in SEO, analytics, and email and social sharing.” However, it seems that documents that were meant to privately shared – such as within a company or organisation – were being indexed by the search function, making them potentially accessible by anyone.
Other researchers then started to test the Docs.com search function:
According to Ars Technica, the search function gave results of private documents that included:
Microsoft has now removed the search bar from Docs.com homepage, but is still visible on other pages of the website. Regardless, these documents have already been indexed by Google and Bing, making them publicly available, given the correct search criteria.
Electronic Arts (EA) announced today that its games were played for over 11 billion hours…
Steam's annual end-of-year recap, Steam Replay, provides fascinating insights into gamer habits by comparing individual…
GSC GameWorld released a major title update for STALKER 2 this seeking, bringing the game…
Without any formal announcement, Intel appears to have revealed its new Core 200H series processors…
Ubisoft is not having the best of times, but despite recent flops, the company still…
If you haven’t started playing STALKER 2: Heart of Chornobyl yet, now might be the…