Главная
Study mode:
on
1
Intro
2
Wiz Research Team
3
Motivation
4
Research Mindset
5
Bug #1 - Jupyter Notebook LPE
6
Bug #2 - Unrestricted Network Access
7
Network Recon - IMDS
8
Network Recon - WireServer
9
WireServer 101 - Goal State
10
WireServer 101 - Extension Configuration
11
WireServer 101 - Certificate Endpoint
12
Decoding CertificatesBondPackage
13
Recon - Cluster Endpoint - Manifest
14
Listing Running Applications in Cluster
15
Recap - The Full Exploit
16
Disclosure Timeline
17
Account Service Takeover
Description:
Dive into a detailed exploration of ChaosDB, a critical cross-tenant vulnerability discovered in Azure Cosmos DB. Learn how the Wiz Research Team uncovered this unprecedented cloud vulnerability that allowed any Azure user to gain full admin access to thousands of customers' databases without authorization. Understand the technical aspects of the exploit, including Jupyter Notebook LPE, unrestricted network access, and the intricacies of WireServer. Follow the step-by-step process of the full exploit, from initial reconnaissance to account service takeover. Gain insights into the disclosure timeline and the far-reaching implications of this security breach for organizations using Azure's flagship managed database solution.

ChaosDB - How We Hacked Databases of Thousands of Azure Customers

Black Hat
Add to list