面向 Web 应用渗透测试人员的 Azure SAS Tokens
netspi.com | 博客 | #cloud | #azure | #misconfiguration | #web-pentest | #sas-tokens | #storage-accounts
摘要
介绍如何利用 Web 应用渗透测试技术滥用 Azure SAS tokens 的常见错误配置。
- 发布时间
- 收录时间
相关内容
博客 ·
netspi.com
Anonymously Enumerating Azure File Resources
NetSPI 介绍匿名枚举 Azure 存储资源的方法:Storage Account 的 Blob 容器若配置了 Container/Blob 公开访问策略,任何人都能列举和读取文件。文章讲解权限模型并发布自动化脚本,用于发现暴露的配置文件、备份甚至凭据。
博客 ·
netspi.com
Overcome Cloud Security Challenges with Purpose-Built Cloud Penetration Testing
云安全支出预计超 2000 亿美元/年,文章梳理影子 IT、攻防资源不对等、一处配置错误即可酿成灾难等五大云安全挑战,主张以专为云设计的渗透测试弥补传统手段不足。
博客 ·
netspi.com
Your Cloud Assets are Probably Not as Secure as You Think They Are
Gartner 估算高达 95% 的云安全事件源于人为配置错误:许多云服务默认未启用 MFA、云与本地网络通过联邦认证打通扩大横向移动风险、GitHub 等公开仓库频现凭据泄露;建议从环境隔离与最小权限做起,并开展常态化渗透测试。
博客 ·
netspi.com
Get-AzurePasswords: Exporting Azure RunAs Certificates for Persistence
NetSPI Azure Automation 系列首篇:拥有 runbook 权限的攻击者可创建自动化任务导出 RunAs 证书与 Automation 凭据,进而以高权限持续访问 Azure 订阅。文中解释了 Automation Account、Runbook 与密码/证书两类凭据的机制。
博客 ·
netspi.com
Running PowerShell on Azure VMs at Scale
NetSPI 演示在 Azure 中规模化执行命令的手法:拥有 Contributor 权限的账户可调用 Invoke-AzureRmVMRunCommand,以 NT AUTHORITY\SYSTEM 身份在订阅内任意 VM 上运行 PowerShell 脚本,无需开放 RDP 或防火墙端口。
博客 ·
netspi.com
Anonymously Enumerating Azure Services
NetSPI 发布匿名枚举 Azure 服务的脚本:通过 DNS 爆破 azurewebsites.net、blob.core.windows.net、database.windows.net 等常见域名的排列组合变体,无需凭据即可发现目标组织暴露在公网的 App Services、存储账户等 Azure 资源。
Skip to content