HT TECH wants to start sending you push notifications. Click allow to subscribe

Autodiscover email bug leaks thousands of Windows passwords

In a big development that has affected a huge number of people, it has been revealed that companies all around the world are leaking passwords due to the Autodiscover email bug. In fact, thousands of Windows passwords have been leaked.

By: HT TECH
Updated on: Sep 23 2021, 14:21 IST
Autodiscover email bug that leaked Windows passwords was found by cybersecurity experts who then managed to collect over 3,40,000 Exchange account credentials earlier this year. (Pixabay)

Cybersecurity researchers have discovered an Autodiscover email bug in Microsoft Exchange software that is used by many companies. The email bug allegedly involves a feature called Autodiscover which is part of the email service, and it has leaked thousands of employees' Windows passwords, which can be collected by hackers. The email bug has affected food companies, real estate firms and companies in China as well, according to a new report.

The Autodiscover system, which is part of Microsoft Exchange, can quickly configure a users laptop, PC or smartphone along with email using just the employee’s credentials. It can ease the hassle faced by computer administrators and technical support by ‘auto-configuring” the client using the worker’s username and password – however, to do this, the requests are sometimes sent to other domains (outside the company’s network) such as autodiscover.com which provides the necessary configuration details.

You may be interested in

Mobiles Tablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
23% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
₹115,999₹149,999
Buy now
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
₹106,998
Check details
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹87,900
Check details
21% OFF
Acer Swift Go SFG14 41 NX KG3SI 002 Laptop
  • Pure Silver
  • 8 GB RAM
  • 512 GB SSD
₹58,990₹74,999
Buy now
39% OFF
Acer Aspire 5 A515 57G Laptop
  • Gray
  • 16 GB RAM
  • 512 GB SSD
₹54,949₹89,999
Buy now
22% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹33,499₹42,999
Buy now
39% OFF
Asus VivoBook 15 X515JA BQ322WS Laptop
  • Transparent Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,490₹51,990
Buy now
34% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,299₹39,999
Buy now
55% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹47,000
Buy now
32% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹19,790₹28,999
Buy now
Honor Pad X9
  • Gray
  • 4 GB RAM
  • 128 GB Storage
₹14,999
Check details

Also read: Looking for a smartphone? Check Mobile Finder here.

According to researchers from Guardicore Labs, the Autodiscover feature can be used to collect and leak passwords -- in April, they bought the domains such as autodiscover.uk and autodiscover.fr and configured them to collect these usernames and passwords – over 3,40,000 Exchange account credentials were spotted, TechCrunch reports. What is worse, according to the researchers, due to the email bug, these credentials were sent in plaintext (human-readable, non-encrypted), which is how they were collected.

The researchers found that 96,000 of the credentials for Exchange email were encrypted, but if they “bounced” them back requesting weak security, the credentials would be sent via plaintext again, which meant lower security like the rest of the credentials sent in an unencrypted manner. These can also be easily read by humans and is not protected by any encryption.

The researchers say that companies should disable their Autodiscover domain at the top According to the researchers, users cannot see or detect the leak, while app developers are working on fixes, which is why the full list of apps has not been revealed. They also plan to retain control of the domain names listed above after the issues are resolved, to ensure they cannot be misused by unscrupulous elements.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on ,Twitter, Facebook, , and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 23 Sep, 14:21 IST

Sale

Mobiles Tablets Laptops
4% OFF
Samsung Galaxy S24 Ultra
  • Titanium Black
  • 12 GB RAM
  • 256 GB Storage
₹129,999₹134,999
Buy now
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
₹148,900₹159,900
Buy now
13% OFF
Xiaomi 14
  • Matte Black
  • 12 GB RAM
  • 512 GB Storage
₹69,999₹79,999
Buy now
10% OFF
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage
₹80,590₹89,900
Buy now
33% OFF
Xiaomi Pad 6
  • Mist Blue
  • 6 GB RAM
  • 128 GB Storage
₹26,999₹39,999
Buy now
38% OFF
Lenovo Tab M10 5G
  • Abyss Blue
  • 6 GB RAM
  • 128 GB Storage
₹20,999₹34,000
Buy now
28% OFF
Realme Pad 2
  • Imagination Grey
  • 6 GB RAM
  • 128 GB Storage
₹17,999₹24,999
Buy now
11% OFF
Samsung Galaxy Tab S9 5G 256GB
  • Graphite
  • 8 GB RAM
  • 256 GB Storage
₹96,999₹108,699
Buy now
29% OFF
Acer Aspire 3 A315 24 NX KDESI 004 Laptop
  • Silver
  • 8 GB RAM
  • 512 GB SSD
₹31,990₹44,999
Buy now
27% OFF
Infinix INBook X1 Neo XL22 Laptop Intel Celeron Quad Core 8 GB 256 GB SSD Windows 11
  • Blue
  • 4 GB RAM
  • 128 GB SSD
₹21,990₹29,990
Buy now
26% OFF
Asus ROG Strix G15 G512LV AZ161T Laptop
  • Blue
  • 16 GB RAM
  • 1 TB SSD
₹86,990₹117,990
Buy now
34% OFF
Asus VivoBook Go 15 OLED E1504GA LK323WS Laptop
  • Green Grey
  • 8 GB RAM
  • 512 GB SSD
₹33,740₹50,990
Buy now
NEXT ARTICLE BEGINS