I Hacked The Cloud: Azure Managed Identities

Поделиться
HTML-код
  • Опубликовано: 24 ноя 2024

Комментарии • 61

  • @DePhoegonIsle
    @DePhoegonIsle 7 месяцев назад +10

    If this isn't a complete course on why you should disable code or execution of things on an entire directory, or ya know disable direct access to user uploades using an set to call the files in a sanitized way, as clean text only.
    I have to admit it's cool to see some of these things, but alot of these vulnerablities come off more as Pebuac sorts of the one who setup that web service, and less in 'it's in the cloud'.

  • @darshannaik1676
    @darshannaik1676 7 месяцев назад +13

    I regulary Watch Your Video , But today i wanna say thank you to you man,.. You are doing great job. You Motivate me to work in the cyber security field in interesting way.
    Thank You John Sir !!🙏🏻🙏🏻

    • @RajuSingh-pr8ec
      @RajuSingh-pr8ec 7 месяцев назад

      Pjuup the
      :⁠-⁠[8⁠-:⁠'⁠(😮

  • @diabilliq
    @diabilliq 7 месяцев назад +2

    very cool writeup! this is something that will get mitigated once CAE (continuous access evaluation) support managed identities.

  • @fredrikzels2637
    @fredrikzels2637 7 месяцев назад +1

    This was great. I understood most of it. Started out with PS and now i'm learning linux OS to understand the basics before I go to networks and further.

  • @Sleeping_Aizawa
    @Sleeping_Aizawa 7 месяцев назад +3

    😊 love how your skills have evolved into beautiful public resources for knowledge, understanding, and wisdom. Thank you for all you time and teachings

  • @antifreeze44
    @antifreeze44 7 месяцев назад +2

    John's the best there is. These are so Insighful.

  • @logiciananimal
    @logiciananimal 7 месяцев назад +1

    If one needs a name, the initial access of the managed identity endpoint is effectively a case of SSRF - server side request forgery.

  • @xCheddarB0b42x
    @xCheddarB0b42x 7 месяцев назад +2

    Rad stuff. I guess one way to learn Azure AD I mean Entra ID is to learn some attack chains.

  • @zanidd
    @zanidd 7 месяцев назад +2

    I actually wanted to get a blue team cert after the CBBH, but this looks too tempting

  • @HitemAriania
    @HitemAriania 7 месяцев назад +6

    Sir, its Entra ID sir

  • @IvanStamenkovicSeemsIndie
    @IvanStamenkovicSeemsIndie 7 месяцев назад +1

    I am literally right now deploying AKS cluster, and also using Managed Identities for internal stuff. Damn, have to watch this :D

  • @malikgenius4u
    @malikgenius4u 7 месяцев назад

    great demo ... i didnt know it could escalate this far... secure sites are the key to protect cloud env.

  • @MsDuketown
    @MsDuketown 7 месяцев назад +5

    Great uses of SAAS tools! These git-flows all lead back home, and with resources beyond 09-01-2017... So working with URI's is similar to working with URL's, but without the universal curl commandeer? Awesome! Who could of think of that?
    Next up Amazon AWS? Cloudfare? Some other CDN, like fonts for Google?

  • @annorome
    @annorome 7 месяцев назад +1

    Ah, I see John on the quick side of things. >:D The whole Azure *Tree* with all the Kubernetes Cluster Setups and Managements is beautifully riddled with ... holes. :D

  • @Hybrid_Netowrks
    @Hybrid_Netowrks 7 месяцев назад

    As always John the king of security

  • @youtonew
    @youtonew 7 месяцев назад +1

    if we know that there is the page after uploads and we know page name (like you you create your own sheell and there you spesify the C and then you modify the url c=whoami and its executed if we dont upload this kind of shell) then how we execute commands in url

  • @PracticalAIinstitute
    @PracticalAIinstitute 7 месяцев назад +2

    NICE!! well done and thanks for theat

  • @BillAnt
    @BillAnt 7 месяцев назад +1

    Boom, another vuln got Hammonded! :D

  • @xx-be2uz
    @xx-be2uz 7 месяцев назад +1

    I do not understand in 06:31 where did you gather the api-version from

  • @CesSanchez
    @CesSanchez 7 месяцев назад +1

    Shoulnd't it be Entra ID, instead of Azure AD, in the cert?

  • @ambroserapose5082
    @ambroserapose5082 7 месяцев назад +1

    Hey John, I am a victim of someone hacking my multiple accounts gmail microsoft Facebook twitter etc maybe through my phone or somehow they got access to my Google password manager, Is there any safety steps I can take other than changing password and adding 2 factor authenticator app? Any help is appreciated.

  • @starlox0
    @starlox0 7 месяцев назад +1

    Really awesome video 🎉.....i also learning cloud security 😀

  • @KyAreTR
    @KyAreTR 7 месяцев назад +4

    Isnt all of your attack possible because of the website and code uploaded to the i guess webapp? And not because of Azure, WebApps, Functions or other PaaS in Azure?
    The Title seems very Clickbaity. Please educate me

    • @ryandawson1220
      @ryandawson1220 7 месяцев назад

      I agree on this one. When an RCE happens on your server, they will always have access to secrets in one form or fashion. We are pulling our secrets in via Azure Keyvault at runtime with a managed identity, so this particular video interested me. This makes it super easy for the attacker to get access to the Keyvault to pull secrets. However if they are already on the server, they could dump memory and get them this one.
      I think the one take away is to make sure your managed identities are properly scoped. Don't use one managed identity for all applications.

    • @KyAreTR
      @KyAreTR 7 месяцев назад

      Agree. Use system managed identity and use IAM to grant access to needed ressources and thats it. And i really do hope that people do not have VMs with PublicIPs available in azure...use a loadbalancer at least infront of it.

    • @rnts08
      @rnts08 7 месяцев назад

      110% clickbait. The vulnerability is SSI, which has been known for 20+ years surfacing again due to clueless DevOps managing infrastructure.

  • @hazembenmadhi9500
    @hazembenmadhi9500 6 месяцев назад

    does there is any ctf challenge for demo this attack or something similar to it like azure active directory attacks?

  • @simbad3311
    @simbad3311 7 месяцев назад +1

    Really cool mate👍

  • @gvoden
    @gvoden 7 месяцев назад

    another great video!

  • @55mga
    @55mga 7 месяцев назад +1

    Your videos are great. Keep it up, it really helps us all learn. But I admit the conditions for this hack were staged for the hacking adventure, but it shows how multiple vulnerabilities can be used. Thank you.

  • @papidulzuratravel8715
    @papidulzuratravel8715 7 месяцев назад

    Amazing thanks!

  • @alone_rider_988
    @alone_rider_988 7 месяцев назад +2

    Bro do you know how does someone exploited all the data of boat company

  • @basavarajtippannavar3092
    @basavarajtippannavar3092 7 месяцев назад

    Bro where is the XZ back door proof of concept video

  • @ancipital
    @ancipital 7 месяцев назад

    Interesting stuff - thanks!

  • @david3199
    @david3199 7 месяцев назад +1

    HI John

  • @peaktheweak
    @peaktheweak 7 месяцев назад

    is it just me or did he look at the eclipse a little too long? eyes r a lil red lookin

  • @JohnSmith-jc7dk
    @JohnSmith-jc7dk 7 месяцев назад

    You cant get away with this.

  • @courageousmelon5654
    @courageousmelon5654 7 месяцев назад +2

    Azure Active Directory? Don't you mean Entra ID? 🤮

  • @velo1337
    @velo1337 7 месяцев назад

    funny that windows defender detects this as a trojan

  • @shakibbro2
    @shakibbro2 7 месяцев назад

    please 1 video how to hacked gmail password please please new video
    🙏🙏🙏🙏🙏🙏

  • @joelanzo
    @joelanzo 7 месяцев назад

    Serious

  • @carsonjamesiv2512
    @carsonjamesiv2512 7 месяцев назад

    COOL!

  • @User-o5l2w
    @User-o5l2w 7 месяцев назад

    Is bro still at the hotel that he leaked the address to in his last video? 😭 be safe bro

  • @Slim-d7q
    @Slim-d7q 7 месяцев назад

    Old hackers descend ppl from sky to earth sow y will never reach them😂😂😂

  • @jmanuelng
    @jmanuelng 7 месяцев назад

    😱

  • @VonVillagracia
    @VonVillagracia 7 месяцев назад

    Hack my company if you can HOHOHOHO 👹👺👺

  • @jwspock1690
    @jwspock1690 7 месяцев назад

    top

  • @lachine1
    @lachine1 7 месяцев назад

    early gang

  • @TheCypherious
    @TheCypherious 7 месяцев назад +2

    Security is only as good as the person who sets it up.

  • @greob
    @greob 7 месяцев назад +1

    Very nice demonstration!

  • @fredrikzels2637
    @fredrikzels2637 7 месяцев назад

    This was great. I understood most of it. Started out with PS and now i'm learning linux OS to understand the basics before I go to networks and further.