利用 Azure WireServer 解密虚拟机扩展设置
netspi.com | 博客 | #cloud | #red-team | #azure | #credentials | #wireserver | #vm-extensions | #decryption
摘要
Azure WireServer 服务为 Azure 虚拟机提供配置数据。本文将逐步演示如何解密这些数据以查找敏感信息。
- 发布时间
- 收录时间
相关内容
博客 ·
netspi.com
Get-AzurePasswords: Exporting Azure RunAs Certificates for Persistence
NetSPI Azure Automation 系列首篇:拥有 runbook 权限的攻击者可创建自动化任务导出 RunAs 证书与 Automation 凭据,进而以高权限持续访问 Azure 订阅。文中解释了 Automation Account、Runbook 与密码/证书两类凭据的机制。
博客 ·
netspi.com
Get-AzurePasswords: A Tool for Dumping Credentials from Azure Subscriptions
NetSPI 发布 MicroBurst 组件 Get-AzurePasswords:该 PowerShell 脚本自动化导出 Azure 订阅中的凭据,覆盖 Key Vaults 密钥/机密/证书、App Services 配置及 Automation Accounts 凭据,帮助测试者快速收集云环境敏感信息用于横向移动。
博客 ·
netspi.com
Azure 密码收集新手指南
MicroBurst 的 Get-AzPasswords(原 Get-AzurePasswords)使用入门:逐项讲解如何从 Azure Key Vault、App Services、自动化账户、存储账户与容器注册表批量提取凭据,并提醒误操作风险。
博客 ·
netspi.com
Attacking Azure Container Registries with Compromised Credentials
拿到 Azure 容器注册表(ACR)Admin 凭据后的攻击路径:用 docker login 认证,通过 _catalog 与 tags API 枚举镜像,再拉取镜像挖掘源码与密钥实现进一步提权;MicroBurst 新增 Get-AzACR 函数自动化全流程。
博客 ·
netspi.com
Decrypting Azure VM Extension Settings with Get-AzureVMExtensionSettings
MicroBurst 新增 Get-AzureVMExtensionSettings 脚本:Azure VM 扩展的 .settings 配置虽经加密仍存于本地磁盘,本地管理员可解密还原,可能泄露敏感命令参数、存储账户密钥乃至本地管理员用户名与密码。
博客 ·
netspi.com
Attacking Azure with Custom Script Extensions
Azure Custom Script Extension 与 Run Command 的攻防两面:拥有 Virtual Machine Contributor 角色即可在任意可达 VM 上以 LocalSystem 身份执行任意脚本,RDP/SSH 端口关闭也不受影响,可用于建立立足点、持久化与提权。
Skip to content