
following rabbit holes through the tech stack

Arbitrary 1-click tenant take over via MS application

In this blog post I explain how reply URLs in Azure Applications can be used as a vector for phishing. The impact of this can range from data leaks to complete tenant takeover; just by luring a victim to clicking on a link.