Главная
Study mode:
on
1
Intro
2
Wiz Research Team
3
Motivation
4
Research Mindset
5
Bug #1 - Jupyter Notebook LPE
6
Bug #2 - Unrestricted Network Access
7
Network Recon - IMDS
8
Network Recon - WireServer
9
WireServer 101 - Extension Configuration
10
Wire Server 101 - Certificate Endpoint
11
Decoding CertificatesBondPackage
12
Listing Running Applications in Cluster
13
Recap - The Full Exploit
14
Disclosure Timeline
15
Account Service Takeover
Description:
Dive into a critical cybersecurity presentation from Black Hat that exposes ChaosDB, a severe cross-tenant vulnerability in Azure Cosmos DB. Discover how the Wiz Research Team uncovered this unprecedented cloud vulnerability that allowed unauthorized access to thousands of Azure customers' databases. Learn about the exploitation process, including Jupyter Notebook LPE, unrestricted network access, and account service takeover. Explore the research mindset, network reconnaissance techniques, and the full exploit chain. Gain insights into the disclosure timeline and the far-reaching implications of this security flaw for organizations worldwide.

ChaosDB - How We Hacked Databases of Thousands of Azure Customers

Black Hat
Add to list