从 Azure Batch 服务提取敏感信息
netspi.com | 博客 | #cloud | #cloud-security | #penetration-testing | #azure | #managed-identity | #azure-batch | #sas-token
摘要
NetSPI 剖析 Azure Batch 服务的安全风险:拥有 Reader 权限的攻击者可读取作业输出与存储账户 SAS 令牌,Contributor 权限则可运行作业、生成 Managed Identity 令牌并收集 Batch 密钥实现持久化。
- 发布时间
- 收录时间
Skip to content