Episode Details

Back to Episodes
How a 19-Year-Old Hacked the NEWS Without Breaking In

How a 19-Year-Old Hacked the NEWS Without Breaking In

Published 1 week ago
Description

Your Outlook account recovery will accept an authenticator code on its own. No password, no inbox, no phone number. 
Anyone holding that TOTP secret owns the account, and the second factor you bought to survive credential theft becomes the only thing in the way.

Koen Kandelaars found one sitting in a PDF on a public help page at the NOS, the largest news organization in the Netherlands. He scanned a QR code out of an onboarding manual and had a real employee's second factor on his phone. 

Rob Maas, Field CTO at ON2IT, walks the full chain with the attacker himself: eleven vulnerabilities in the first responsible disclosure, a twelfth Koen estimates at 1 to 5 million euros, and the recovery flow nobody tested.

Timestamps

  • (00:00) - MFA was on. He got in anyway.
  • (02:04) - Why the biggest news organization became the target
  • (03:24) - Mapping the attack surface before touching anything
  • (04:54) - Eleven findings in the first responsible disclosure
  • (08:50) - The Media Cloud help page and the live TOTP QR code
  • (11:19) - How the password reset removes your second factor
  • (14:29) - The 1 to 5 million euro estimate, and what to fix

Key Topics Covered

  • Attack surface discovery against a large public broadcaster
  • Responsible disclosure done well: response time, remediation, and recognition
  • Where the next generation of defenders comes from, and how they choose a side

Related ON2IT Content & Referenced Resources:

Threat Talks: https://threat-talks.com/
ON2IT (Zero Trust as a Service): https://on2it.net/
AMS-IX: https://www.ams-ix.net/ams


Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us