我们知道你(在 Azure)去年夏天做了什么
摘要
NetSPI 在 DEF CON 33 的演讲揭示:支持 Entra ID 身份验证的 Azure 资源会暴露租户 ID,攻击者可借此大规模将云资源归因到特定组织。
- 发布时间
- 收录时间
相关内容
博客 ·
netspi.com
Anonymously Enumerating Azure Services
NetSPI 发布匿名枚举 Azure 服务的脚本:通过 DNS 爆破 azurewebsites.net、blob.core.windows.net、database.windows.net 等常见域名的排列组合变体,无需凭据即可发现目标组织暴露在公网的 App Services、存储账户等 Azure 资源。
博客 ·
netspi.com
Anonymously Enumerating Azure File Resources
NetSPI 介绍匿名枚举 Azure 存储资源的方法:Storage Account 的 Blob 容器若配置了 Container/Blob 公开访问策略,任何人都能列举和读取文件。文章讲解权限模型并发布自动化脚本,用于发现暴露的配置文件、备份甚至凭据。
博客 ·
netspi.com
DEF CON 33:NetSPI 的「Access Everywhere」体验
NetSPI 安全专家分享 DEF CON 33「Access Everywhere」主题的核心见解,从与黑客社区交流到通过演讲和工作坊拓展安全专长。
博客 ·
netspi.com
Get-AzurePasswords: Exporting Azure RunAs Certificates for Persistence
NetSPI Azure Automation 系列首篇:拥有 runbook 权限的攻击者可创建自动化任务导出 RunAs 证书与 Automation 凭据,进而以高权限持续访问 Azure 订阅。文中解释了 Automation Account、Runbook 与密码/证书两类凭据的机制。
博客 ·
netspi.com
Running PowerShell on Azure VMs at Scale
NetSPI 演示在 Azure 中规模化执行命令的手法:拥有 Contributor 权限的账户可调用 Invoke-AzureRmVMRunCommand,以 NT AUTHORITY\SYSTEM 身份在订阅内任意 VM 上运行 PowerShell 脚本,无需开放 RDP 或防火墙端口。
博客 ·
netspi.com
Get-AzurePasswords: A Tool for Dumping Credentials from Azure Subscriptions
NetSPI 发布 MicroBurst 组件 Get-AzurePasswords:该 PowerShell 脚本自动化导出 Azure 订阅中的凭据,覆盖 Key Vaults 密钥/机密/证书、App Services 配置及 Automation Accounts 凭据,帮助测试者快速收集云环境敏感信息用于横向移动。
Skip to content