Toyota Tsusho Insurance Broker India (TTIBI), an Indo-Japanese joint insurance venture, operated a misconfigured server that exposed more than 650,000 Microsoft-hosted email messages to customers, a security researcher has found. The issue may not be entirely fixed. When the researcher disclosed the vulnerability on Wednesday – five months after private disclosure – the firm still had not changed the password of the affected account. Eaton Zveare, a security researcher at Traceable AI, published an account of how he discovered the issue by examining an Android app created by Eicher Motors, an India-based automotive firm that has a subdomain (eicher.ttibi.co.in) for its car insurance premium calculator on the TTIBI website. The Android app, My Eicher, offers various vehicle-related services like predictive uptime, fuel management, and fleet monitoring. And, as Zveare discovered, it includes an API interface Java class that contains a GET request to the premium calculator page. Zveare then examined the calculator web page on the TTIBI website and saw that it included a client-side function that created a request to send email using a server-side API. "This caught my eye because this was a client-side email sending mechanism," he wrote in a post describing his findings. "If it worked, I could send [an] email with any subject & body to anyone, and it would come from a genuine Eicher email address." Zveare wasn't expecting much because the request code included a Bearer Authorizat...
Insurance website's buggy API leaked Office 365 password and a giant email trove
The Register
·Thomas Claburn
·Published Jan 18, 2024
·Updated
Affected Software
1 affected component
Microsoft Office 365