A 16-year-old researcher named Faav hacked into Microsoft’s Titan analytics service, which holds 17 trillion rows of data. He found a flaw that let him act as an administrator. Microsoft fixed the issue on September 9 and gave him a $5,000 bounty on September 17 for his responsible reporting.

Faav, a savvy security researcher, discovered a significant vulnerability in Microsoft's Titan analytics platform that permitted unauthorized access. This flaw enabled him to masquerade as an administrator, executing SQL commands on extensive datasets. Upon notifying Microsoft, swift actions were taken to remedy the issue. For his responsible reporting, Faav was awarded a bounty of $5,000, highlighting the critical need for thorough security assessments within tech firms.

An internal Microsoft analytics service with more than 17 trillion rows of data was reportedly compromised by a 16-year-old security researcher who discovered a critical flaw that could have been exploited by attackers.

As reported by Help Net Security, the flaw was found in Microsoft's Titan service by the teenager, who goes by the name Faav. He reportedly discovered the vulnerability using an automated bug-hunting tool he built himself.

"Faav found that Titan did not verify the signature on login tokens. That let him pose as the service's administrator and run SQL queries against 17 connected databases holding an estimated 17.3 trillion rows," the report said.

During his research, Faav also gained access to a Bing analytics source containing search, identifier and location fields. The location values showed country- or state-level information derived from reverse IP lookups, he explained.

Because MUIDs, identifiers that Microsoft stores in users' browsers, appeared in more than one dataset, it was possible that user activity could have been correlated across services, Faav was quoted as saying.

Notably, Faav said he never accessed customer data or personally identifiable information (PII). He also did not use the two Bing samples to identify anyone, link records between datasets or build user profiles.

Microsoft respondsAfter the vulnerability came to light on September 5, Microsoft's Security Response Center (MSRC) asked Faav to stop testing and requested his IP address to confirm that there had been no activity beyond his research.

The endpoint was locked down on September 9, and Faav received a $5,000 bounty from Microsoft on September 17.

"We appreciate the opportunity to investigate the findings reported by Faav. Their submission and coordinated vulnerability disclosure helped us to better protect our customers by hardening our services. We value and appreciate safe security research under the terms of the Microsoft Bug Bounty Program and look forward to continuing to work with Faav in the future," Microsoft said in a statement.