In the name of Allah the beneficent the Merciful.
Few months ago I found vulnerability in Microsoft's Onedrive where i could have get the editable link for documents in one drive from "view only" link.
Proof of concept Steps:
1) Login as victim in browser A and go to onedrive.live.com
2) Upload any document or file and then open the document like this
https://onedrive.live.com/ view.aspx?cid= 0cf9bc876832caee&page=view& resid=CF9BC876832CAEE!106& parId=CF9BC876832CAEE!103&app= Word
3) Now open share and then create two links
a) edit link
b) View only link
4) After that shorten the links using "Shorten link" hyperlink beside
the edit link and view only link.
5) Then you can see a shortened link in this format
View only :
http://1drv.ms/1pFlbbq
Edit :
http://1drv.ms/1pFl93x
6) Notice that in above urls the only difference is last 3 characters.
7) Now give the view only link to attacker .
8) Attacker will use the view only link and he can predict the last 3
characters .
Hence it was possible to escalate the privilege and finally attacker
will get editable link for document.
Note : characters in (http://1drv.ms/1pFlbbq) were combination of a-z
, A-Z and 0-9 only)
So, it was not difficult for attacker to predict them.
Microsoft accepted the bug as valid and fixed the issue by completely removing shortened links . Now you can't do shorten the onedrive links . Microsoft also acknowledge me for Reporting the bug as security researcher.
Iam very happy to safe the privacy of microsoft users data.
Thanks for Reading
Jai Hind :)
Contact info :
facebook : facebook.com/haji.mohd871
twitter : @mohdhaji24
linkedin : linkedin.com/in/mohd-haji-490960a0
facebook : facebook.com/haji.mohd871
twitter : @mohdhaji24
linkedin : linkedin.com/in/mohd-haji-490960a0