突破 Azure 服务中的托管身份壁垒.pdf

编号:615408 PDF 98页 19.38MB 下载积分:VIP专享
下载报告请您先登录!

突破 Azure 服务中的托管身份壁垒.pdf

1、#BHASIA BlackHatEventsBreaking Managed Iden-ty Breaking Managed Iden-ty Barriers in Azure ServicesBarriers in Azure ServicesDavid Fiser,Nitesh Surana#BHASIA BlackHatEvents From Sikkim,India Senior Threat Researcher(Cloud)Presented at Black Hat USA,HITB,HackInParis.VulnerabiliBes in cloud services vi

2、a Zero Day IniBaBve X:_niteshsurana|Web:#BHASIA BlackHatEvents#BHASIA BlackHatEventsThe ArtAzure FunctionsAzure Machine LearningManaged Identities#BHASIA BlackHatEventsThe Ar(sts#BHASIA BlackHatEventsEPISODE I:Azure Functions#BHASIA BlackHatEventsAzure Func(ons Serverless plaNorm User code inside CS

3、P#BHASIA BlackHatEventsAzure Functions Running user codeAny user code!?import azure.functions as funcimport osdef main(req:func.HttpRequest)-func.HttpResponse:val=req.params.get(msg)return check_output(echo 0.format(val),shell=True)#BHASIA BlackHatEventsAzure Functions AuthenBcaBon Triggers#BHASIA B

4、lackHatEventsResearch Simulation of compromise Analysis of environment Configuration changes#BHASIA BlackHatEventsAuthentication Tokens Client certificate Custom logic#BHASIA BlackHatEventsTriggers HTTP(s)request Events#BHASIA BlackHatEventsTimeouts4.5 m5 m#BHASIA BlackHatEventsEnvironment analysis

5、whoami mount,capsh env#BHASIA BlackHatEventsEnvironment variables Popular pracBce in DevOps OWen stores secrets References as a!VAULT!#BHASIA BlackHatEventsEnvironment variables Fundamentalsunless a new table passed as arguments#BHASIA BlackHatEvents#BHASIA BlackHatEventsIs this some debugger magic?

6、Environment variableshttps:/ BlackHatEventsAzureWebJobsStorageCONTAINER_ENCRYPTION_KEYCONTAINER_START_CONTEXT_SAS_URI#BHASIA BlackHatEventsAzureWebJobsStorageAzure FunctionStorage Accountsource code#BHASIA BlackHatEvents encryptedContext:Lk8nHZ/2m+6TGuK0pfhtNA=./cYdq+AnpWjICTECMSDgT5SsgFPGm6ouZFtlY7

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(突破 Azure 服务中的托管身份壁垒.pdf)为本站 (鲁大师) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠