Главная
Study mode:
on
1
Intro
2
WHAT'S AN AZURE
3
AZURE PERMISSIONS OVERVIEW - PRINCIPALS
4
AZURE PERMISSIONS OVERVIEW - ROLES
5
MANUAL CREDENTIAL ACCESS
6
AUTOMATING CREDENTIAL ACCESS
7
DUMPING PASSWORDS FROM KEY VAULTS
8
DUMPING PASSWORDS FROM APP SERVICES
9
DUMPING PASSWORDS FROM AUTOMATION ACCOUNTS
10
DUMPING PASSWORDS FROM STORAGE ACCOUNTS
11
DUMPING PASSWORDS FROM AZURE CONTAINER REGISTRIES
12
DUMPING PASSWORDS FROM CONTAINER REGISTRIES
13
DUMPING PASSWORDS FROM AZURE KUBERNETES SERVICES
14
PRIVILEGE ESCALATION IN AZURE
Description:
Explore the intricacies of extracting passwords from Microsoft Azure cloud environments in this 45-minute conference talk from Ekoparty 2021's Red Zone Space. Delve into the challenges faced by penetration testers when dealing with Azure's expanding attack surfaces. Learn about the MicroBurst toolkit, designed to automate common Azure escalation tasks, with a focus on its password extraction capabilities. Discover various hiding spots for passwords within Azure and techniques for manual extraction. Gain insights into using the Get-AzPasswords function for automated credential extraction from Azure tenants. Examine a case study highlighting a critical issue in Azure's permissions model that led to a Microsoft fix. Benefit from speaker Karl Fosaaen's expertise as Practice Director at NetSPI, with over a decade of computer security consulting experience and significant contributions to Azure security research.

Extracting All the Azure Passwords - Karl Fosaaen - Ekoparty 2021: Red Zone Space

Ekoparty Security Conference
Add to list