mirror of
https://github.com/HackTricks-wiki/hacktricks-cloud.git
synced 2026-07-28 22:51:09 -07:00
Translated ['', 'src/pentesting-cloud/azure-security/az-services/az-stor
This commit is contained in:
@@ -2,54 +2,54 @@
|
||||
|
||||
{{#include ../../../banners/hacktricks-training.md}}
|
||||
|
||||
## Maelezo ya Msingi
|
||||
## Taarifa za Msingi
|
||||
|
||||
Azure Storage Accounts ni huduma za msingi katika Microsoft Azure zinazotoa cloud **storage kwa aina mbalimbali za data**, zenye scalability, secure, na highly available, ikijumuisha blobs (binary large objects), files, queues, na tables. Hufanya kazi kama containers zinazokusanya huduma hizi tofauti za storage pamoja chini ya namespace moja kwa urahisi wa usimamizi.
|
||||
Azure Storage Accounts ni huduma za msingi katika Microsoft Azure zinazotoa cloud **storage inayoweza kupanuka, salama, na yenye upatikanaji wa juu kwa aina mbalimbali za data**, ikijumuisha blobs (binary large objects), files, queues, na tables. Hufanya kazi kama containers zinazokusanya huduma hizi tofauti za storage pamoja chini ya namespace moja kwa usimamizi rahisi.
|
||||
|
||||
**Main configuration options**:
|
||||
|
||||
- Kila storage account lazima iwe na **uniq name across all Azure**.
|
||||
- Kila storage account hu-deployiwa katika **region** au katika Azure extended zone
|
||||
- Kila storage account huwekwa kwenye **region** au kwenye Azure extended zone
|
||||
- Inawezekana kuchagua toleo la **premium** la storage account kwa performance bora
|
||||
- Inawezekana kuchagua kati ya **4 types of redundancy to protect** dhidi ya rack, drive na datacenter **failures**.
|
||||
|
||||
**Security configuration options**:
|
||||
|
||||
- **Require secure transfer for REST API operations**: Require TLS in any communication with the storage
|
||||
- **Allows enabling anonymous access on individual containers**: Ikiwa sivyo, haitakuwa possible kuwezesha anonymous access baadaye
|
||||
- **Enable storage account key access**: Ikiwa sivyo, access kwa kutumia Shared Keys itakatazwa
|
||||
- **Require secure transfer for REST API operations**: Hitaji TLS katika mawasiliano yoyote na storage
|
||||
- **Allows enabling anonymous access on individual containers**: La sivyo, haitakuwa possible kuwezesha anonymous access baadaye
|
||||
- **Enable storage account key access**: La sivyo, access kwa kutumia Shared Keys itakuwa marufuku
|
||||
- **Minimum TLS version**
|
||||
- **Permitted scope for copy operations**: Ruhusu kutoka storage account yoyote, kutoka storage account yoyote ile iliyo kwenye Entra tenant moja, au kutoka storage account yenye private endpoints katika virtual network moja.
|
||||
- **Permitted scope for copy operations**: Ruhusu kutoka kwa storage account yoyote, kutoka kwa storage account yoyote iliyo kwenye Entra tenant moja au kutoka kwa storage account yenye private endpoints ndani ya virtual network moja.
|
||||
|
||||
**Blob Storage options**:
|
||||
|
||||
- **Allow cross-tenant replication**
|
||||
- **Access tier**: Hot (frequently access data), Cool and Cold (rarely accessed data)
|
||||
- **Access tier**: Hot (data inayofikiwa mara kwa mara), Cool na Cold (data inayofikiwa mara chache)
|
||||
|
||||
**Networking options**:
|
||||
|
||||
- **Network access**:
|
||||
- Ruhusu kutoka networks zote
|
||||
- Ruhusu kutoka virtual networks na IP addresses zilizochaguliwa
|
||||
- Ruhusu kutoka kwa networks zote
|
||||
- Ruhusu kutoka kwa virtual networks na IP addresses zilizochaguliwa
|
||||
- Zima public access na tumia private access
|
||||
- **Private endpoints**: Inaruhusu private connection kwenda storage account kutoka virtual network
|
||||
- **Private endpoints**: Inaruhusu connection ya private kwenda storage account kutoka kwenye virtual network
|
||||
|
||||
**Data protection options**:
|
||||
|
||||
- **Point-in-time restore for containers**: Inaruhusu kurejesha containers hadi state ya awali
|
||||
- **Point-in-time restore for containers**: Huruhusu kurejesha containers kwenda hali ya awali
|
||||
- Inahitaji versioning, change feed, na blob soft delete ziwe zimewezeshwa.
|
||||
- **Enable soft delete for blobs**: Inawezesha retention period kwa siku kwa blobs zilizofutwa (hata zile zilizowekwa juu)
|
||||
- **Enable soft delete for blobs**: Inawezesha retention period kwa siku kwa blobs zilizofutwa (hata zile zilizowekewa overwrite)
|
||||
- **Enable soft delete for containers**: Inawezesha retention period kwa siku kwa containers zilizofutwa
|
||||
- **Enable soft delete for file shares**: Inawezesha retention period kwa siku kwa file shared zilizofutwa
|
||||
- **Enable versioning for blobs**: Dumisha previous versions za blobs zako
|
||||
- **Enable versioning for blobs**: Dumisha versions za awali za blobs zako
|
||||
- **Enable blob change feed**: Hifadhi logs za create, modification, na delete changes kwa blobs
|
||||
- **Enable version-level immutability support**: Inakuruhusu kuweka time-based retention policy katika account-level ambayo itatumika kwa blob versions zote.
|
||||
- Version-level immutability support na point-in-time restore for containers haziwezi kuwezeshwa kwa pamoja.
|
||||
- **Enable version-level immutability support**: Hukuruhusu kuweka time-based retention policy kwenye account-level ambayo itatumika kwa blob versions zote.
|
||||
- Version-level immutability support na point-in-time restore for containers haziwezi kuwezeshwa kwa wakati mmoja.
|
||||
|
||||
**Encryption configuration options**:
|
||||
|
||||
- **Encryption type**: Inawezekana kutumia Microsoft-managed keys (MMK) au Customer-managed keys (CMK)
|
||||
- **Enable infrastructure encryption**: Inaruhusu double encrypt data "for more security"
|
||||
- **Enable infrastructure encryption**: Huruhusu double encrypt the data "for more security"
|
||||
|
||||
### Storage endpoints
|
||||
|
||||
@@ -64,18 +64,18 @@ Azure Storage Accounts ni huduma za msingi katika Microsoft Azure zinazotoa clou
|
||||
|
||||
### Public Exposure
|
||||
|
||||
Ikiwa "Allow Blob public access" imewezeshwa (**enabled**) (imezimwa kwa chaguo-msingi), wakati wa kuunda container inawezekana:
|
||||
Kama "Allow Blob public access" imewashwa (**enabled**; imezimwa kwa default), wakati wa kuunda container inawezekana:
|
||||
|
||||
- Kutoa **public access to read blobs** (unahitaji kujua jina).
|
||||
- **List container blobs** na **read** hizo.
|
||||
- Kuifanya iwe kabisa **private**
|
||||
- **List container blobs** na **read** them.
|
||||
- Kuuweka kuwa **private** kabisa
|
||||
|
||||
<figure><img src="https://lh7-rt.googleusercontent.com/slidesz/AGV_vUfoetUnYBPWQpRrWNnnlbqWpl8Rdoaeg5uBrCVlvcNDlnKwQHjZe8nUb2SfPspBgbu-lCZLmUei-hFi_Jl2eKbaxUtBGTjdUSDmkrcwr90VZkmuMjk9tyh92p75btfyzGiUTa0-=s2048?key=m8TV59TrCFPlkiNnmhYx3aZt" alt=""><figcaption></figcaption></figure>
|
||||
|
||||
### Static website (`$web`) exposure & leaked secrets
|
||||
|
||||
- **Static websites** zinahudumiwa kutoka container maalum ya `$web` kupitia region-specific endpoint kama `https://<account>.z13.web.core.windows.net/`.
|
||||
- Container ya `$web` inaweza kuripoti `publicAccess: null` kupitia blob API, lakini files bado zinaweza kufikiwa kupitia static site endpoint, hivyo kuweka config/IaC artifacts humo kunaweza leak secrets.
|
||||
- **Static websites** hutolewa kutoka kwa special `$web` container kupitia region-specific endpoint kama `https://<account>.z13.web.core.windows.net/`.
|
||||
- `$web` container inaweza kuripoti `publicAccess: null` kupitia blob API, lakini files bado zinaweza kufikiwa kupitia static site endpoint, hivyo kuweka config/IaC artifacts hapo kunaweza leak secrets.
|
||||
- Quick audit workflow:
|
||||
```bash
|
||||
# Identify storage accounts with static website hosting enabled
|
||||
@@ -87,21 +87,21 @@ az storage blob list --container-name '$web' --account-name <acc-name> --auth-mo
|
||||
# Pull suspicious files directly (e.g., IaC tfvars containing secrets/SAS)
|
||||
az storage blob download -c '$web' --name iac/terraform.tfvars --file /dev/stdout --account-name <acc-name> --auth-mode login
|
||||
```
|
||||
### Kukagua anonymous blob exposure
|
||||
### Kukagua ufichuzi wa anonymous blob
|
||||
|
||||
- **Tafuta storage accounts** zinazoweza kufichua data: `az storage account list | jq -r '.[] | select(.properties.allowBlobPublicAccess==true) | .name'`. Ikiwa `allowBlobPublicAccess` ni `false` huwezi kufanya containers ziwe public.
|
||||
- **Kagua accounts zenye hatari** ili kuthibitisha flag na settings nyingine dhaifu: `az storage account show --name <acc> --query '{allow:properties.allowBlobPublicAccess, minTls:properties.minimumTlsVersion}'`.
|
||||
- **Orodhesha container-level exposure** ambapo flag imewezeshwa:
|
||||
- **Tafuta storage accounts** ambazo zinaweza kufichua data: `az storage account list | jq -r '.[] | select(.properties.allowBlobPublicAccess==true) | .name'`. Ikiwa `allowBlobPublicAccess` ni `false` huwezi kufanya containers ziwe public.
|
||||
- **Kagua accounts hatarishi** ili kuthibitisha flag na settings nyingine dhaifu: `az storage account show --name <acc> --query '{allow:properties.allowBlobPublicAccess, minTls:properties.minimumTlsVersion}'`.
|
||||
- **Hesabu container-level exposure** ambapo flag imewezeshwa:
|
||||
```bash
|
||||
az storage container list --account-name <acc> \
|
||||
--query '[].{name:name, access:properties.publicAccess}'
|
||||
```
|
||||
- `"Blob"`: anonymous reads zinaruhusiwa **only when blob name is known** (hakuna listing).
|
||||
- `"Blob"`: anonima kusoma kunaruhusiwa **tu wakati jina la blob linajulikana** (hakuna listing).
|
||||
- `"Container"`: anonymous **list + read** ya kila blob.
|
||||
- `null`: private; authentication required.
|
||||
- **Prove access** bila credentials:
|
||||
- Ikiwa `publicAccess` ni `Container`, anonymous listing inafanya kazi: `curl "https://<acc>.blob.core.windows.net/<container>?restype=container&comp=list"`.
|
||||
- Kwa `Blob` na `Container` zote mbili, anonymous blob download inafanya kazi jina linapojulikana:
|
||||
- `null`: private; authentication inahitajika.
|
||||
- **Thibitisha access** bila credentials:
|
||||
- Iwapo `publicAccess` ni `Container`, anonymous listing inafanya kazi: `curl "https://<acc>.blob.core.windows.net/<container>?restype=container&comp=list"`.
|
||||
- Kwa `Blob` na `Container` zote mbili, anonymous blob download inafanya kazi wakati jina linajulikana:
|
||||
```bash
|
||||
az storage blob download -c <container> -n <blob> --account-name <acc> --file /dev/stdout
|
||||
# or via raw HTTP
|
||||
@@ -115,25 +115,25 @@ If you find any **storage** you can connect to you could use the tool [**Microso
|
||||
|
||||
### RBAC
|
||||
|
||||
It's possible to use Entra ID principals with **RBAC roles** to access storage accounts and it's the recommended way.
|
||||
Ni inawezekana kutumia Entra ID principals na **RBAC roles** kufikia storage accounts na ndio njia inayopendekezwa.
|
||||
|
||||
### Access Keys
|
||||
|
||||
The storage accounts have access keys that can be used to access it. This provides f**ull access to the storage account.**
|
||||
The storage accounts have access keys that can be used to access it. Hii inatoa f**ull access to the storage account.**
|
||||
|
||||
<figure><img src="../../../images/image (5).png" alt=""><figcaption></figcaption></figure>
|
||||
|
||||
### **Shared Keys & Lite Shared Keys**
|
||||
|
||||
It's possible to [**generate Shared Keys**](https://learn.microsoft.com/en-us/rest/api/storageservices/authorize-with-shared-key) signed with the access keys to authorize access to certain resources via a signed URL.
|
||||
Ni inawezekana [**generate Shared Keys**](https://learn.microsoft.com/en-us/rest/api/storageservices/authorize-with-shared-key) zilizosainiwa kwa kutumia access keys ili ku-authorize access to certain resources kupitia signed URL.
|
||||
|
||||
> [!NOTE]
|
||||
> Note that the `CanonicalizedResource` part represents the storage services resource (URI). And if any part in the URL is encoded, it should also be encoded inside the `CanonicalizedResource`.
|
||||
> Kumbuka kuwa sehemu ya `CanonicalizedResource` inawakilisha storage services resource (URI). Na kama sehemu yoyote katika URL ime-encode, inapaswa pia ku-encode ndani ya `CanonicalizedResource`.
|
||||
|
||||
> [!NOTE]
|
||||
> This is **used by default by `az` cli** to authenticate requests. To make it use the Entra ID principal credentials indicate the param `--auth-mode login`.
|
||||
> Hii hutumiwa **kwa default na `az` cli** kuthibitisha requests. Ili ifanye kazi kwa kutumia Entra ID principal credentials onyesha param `--auth-mode login`.
|
||||
|
||||
- It's possible to generate a **shared key for blob, queue and file services** signing the following information:
|
||||
- Ni inawezekana generate **shared key for blob, queue and file services** kwa kusaini taarifa zifuatazo:
|
||||
```bash
|
||||
StringToSign = VERB + "\n" +
|
||||
Content-Encoding + "\n" +
|
||||
@@ -150,7 +150,7 @@ Range + "\n" +
|
||||
CanonicalizedHeaders +
|
||||
CanonicalizedResource;
|
||||
```
|
||||
- Inawezekana kutengeneza **shared key for table services** kwa kusaini taarifa ifuatayo:
|
||||
- Inawezekana kuzalisha **shared key for table services** kwa kusaini taarifa ifuatayo:
|
||||
```bash
|
||||
StringToSign = VERB + "\n" +
|
||||
Content-MD5 + "\n" +
|
||||
@@ -158,7 +158,7 @@ Content-Type + "\n" +
|
||||
Date + "\n" +
|
||||
CanonicalizedResource;
|
||||
```
|
||||
- Inawezekana kutengeneza **lite shared key for blob, queue and file services** kwa kusaini taarifa ifuatayo:
|
||||
- Inawezekana kuzalisha **lite shared key kwa blob, queue na file services** kwa kusaini taarifa zifuatazo:
|
||||
```bash
|
||||
StringToSign = VERB + "\n" +
|
||||
Content-MD5 + "\n" +
|
||||
@@ -167,7 +167,7 @@ Date + "\n" +
|
||||
CanonicalizedHeaders +
|
||||
CanonicalizedResource;
|
||||
```
|
||||
- Inawezekana kutengeneza **lite shared key for table services** kwa kusaini taarifa zifuatazo:
|
||||
- Inawezekana kuzalisha **lite shared key for table services** kwa kusaini taarifa ifuatayo:
|
||||
```bash
|
||||
StringToSign = Date + "\n"
|
||||
CanonicalizedResource
|
||||
@@ -186,56 +186,56 @@ Content-Length: 0
|
||||
```
|
||||
### **Shared Access Signature** (SAS)
|
||||
|
||||
Shared Access Signatures (SAS) ni URL salama, zenye muda maalum ambazo **hutoa ruhusa mahususi ya kufikia resource**s ndani ya Azure Storage account bila kufichua access keys za account. Wakati access keys zinatoa full administrative access kwa rasilimali zote, SAS huruhusu udhibiti wa granular kwa kubainisha permissions (kama read au write) na kuweka muda wa kuisha.
|
||||
Shared Access Signatures (SAS) ni secure, time-limited URLs ambazo **grant specific permissions to access resource**s katika Azure Storage account bila kufichua account's access keys. Wakati access keys zinatoa full administrative access kwa resources zote, SAS huruhusu granular control kwa kubainisha permissions (kama read au write) na kufafanua expiration time.
|
||||
|
||||
#### SAS Types
|
||||
|
||||
- **User delegation SAS**: Hii huundwa kutoka kwa **Entra ID principal** ambayo ita-sign SAS na ku-delegate permissions kutoka kwa user kwenda kwenye SAS. Inaweza kutumika tu na **blob and data lake storage** ([docs](https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas)). Inawezekana **kufuta** user delegated SAS zote zilizotengenezwa.
|
||||
- Hata kama inawezekana kutengeneza delegation SAS yenye permissions "zaidi" kuliko zile user alizonazo. Hata hivyo, ikiwa principal hana hizo permissions, haitafanya kazi (no privesc).
|
||||
- **Service SAS**: Hii hu-signiwa kwa kutumia moja ya storage account **access keys**. Inaweza kutumika kutoa access kwa specific resources ndani ya single storage service. Ikiwa key itafanyiwa renewal, SAS itaacha kufanya kazi.
|
||||
- **Account SAS**: Hii pia hu-signiwa kwa kutumia moja ya storage account **access keys**. Hutoa access kwa resources katika storage account services (Blob, Queue, Table, File) na inaweza kujumuisha service-level operations.
|
||||
- **User delegation SAS**: Hii inatengenezwa kutoka kwa **Entra ID principal** ambayo itasaini SAS na ku-delegate permissions kutoka kwa user kwenda kwa SAS. Inaweza kutumika tu na **blob and data lake storage** ([docs](https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas)). Inawezekana **revoke** zote generated user delegated SAS.
|
||||
- Hata kama inawezekana kutengeneza delegation SAS yenye permissions “zaidi” kuliko zile ambazo user anazo. Hata hivyo, ikiwa principal hana hizo permissions, haitafanya kazi (no privesc).
|
||||
- **Service SAS**: Hii inasainiwa kwa kutumia moja ya storage account **access keys**. Inaweza kutumika kutoa access kwa specific resources katika single storage service. Ikiwa key itanyweshwa upya, SAS itaacha kufanya kazi.
|
||||
- **Account SAS**: Pia inasainiwa na moja ya storage account **access keys**. Inatoa access kwa resources katika storage account services (Blob, Queue, Table, File) na inaweza kujumuisha service-level operations.
|
||||
|
||||
SAS URL iliyosainiwa kwa kutumia **access key** inaonekana kama hii:
|
||||
A SAS URL signed by an **access key** looks like this:
|
||||
|
||||
- `https://<container_name>.blob.core.windows.net/newcontainer?sp=r&st=2021-09-26T18:15:21Z&se=2021-10-27T02:14:21Z&spr=https&sv=2021-07-08&sr=c&sig=7S%2BZySOgy4aA3Dk0V1cJyTSIf1cW%2Fu3WFkhHV32%2B4PE%3D`
|
||||
|
||||
SAS URL iliyosainiwa kama **user delegation** inaonekana kama hii:
|
||||
A SAS URL signed as a **user delegation** looks like this:
|
||||
|
||||
- `https://<container_name>.blob.core.windows.net/testing-container?sp=r&st=2024-11-22T15:07:40Z&se=2024-11-22T23:07:40Z&skoid=d77c71a1-96e7-483d-bd51-bd753aa66e62&sktid=fdd066e1-ee37-49bc-b08f-d0e152119b04&skt=2024-11-22T15:07:40Z&ske=2024-11-22T23:07:40Z&sks=b&skv=2022-11-02&spr=https&sv=2022-11-02&sr=c&sig=7s5dJyeE6klUNRulUj9TNL0tMj2K7mtxyRc97xbYDqs%3D`
|
||||
|
||||
Tambua baadhi ya **http params**:
|
||||
Note some **http params**:
|
||||
|
||||
- Param **`se`** inaonyesha **tarehe ya kuisha** ya SAS
|
||||
- Param **`sp`** inaonyesha **permissions** za SAS
|
||||
- **`sig`** ni **signature** inayothibitisha SAS
|
||||
- The **`se`** param indicates the **expiration date** of the SAS
|
||||
- The **`sp`** param indicates the **permissions** of the SAS
|
||||
- The **`sig`** is the **signature** validating the SAS
|
||||
|
||||
#### SAS permissions
|
||||
|
||||
Wakati wa kutengeneza SAS ni lazima kuonyesha permissions ambazo inapaswa kutoa. Kutegemea objet ambayo SAS inatengenezwa juu yake, permissions tofauti zinaweza kujumuishwa. Kwa mfano:
|
||||
When generating a SAS it's needed to indicate the permissions that it should be granting. Depending on the objet the SAS is being generated over different permissions might be included. For example:
|
||||
|
||||
- (a)dd, (c)reate, (d)elete, (e)xecute, (f)ilter_by_tags, (i)set_immutability_policy, (l)ist, (m)ove, (r)ead, (t)ag, (w)rite, (x)delete_previous_version, (y)permanent_delete
|
||||
|
||||
## SFTP Support for Azure Blob Storage
|
||||
|
||||
Azure Blob Storage sasa inasaidia SSH File Transfer Protocol (SFTP), ikiwezesha secure file transfer na management moja kwa moja kwenda Blob Storage bila kuhitaji custom solutions au third-party products.
|
||||
Azure Blob Storage sasa inasaidia SSH File Transfer Protocol (SFTP), ikiruhusu secure file transfer na management moja kwa moja kwenda Blob Storage bila kuhitaji custom solutions au third-party products.
|
||||
|
||||
### Key Features
|
||||
|
||||
- Protocol Support: SFTP inafanya kazi na Blob Storage accounts zilizosanidiwa na hierarchical namespace (HNS). Hii hupanga blobs katika directories na subdirectories kwa urahisi wa navigation.
|
||||
- Security: SFTP hutumia local user identities kwa authentication na haiunganishwi na RBAC au ABAC. Kila local user anaweza kufanya authenticate kupitia:
|
||||
- Protocol Support: SFTP inafanya kazi na Blob Storage accounts zilizo configured with hierarchical namespace (HNS). Hii hupanga blobs ndani ya directories na subdirectories kwa urahisi wa navigation.
|
||||
- Security: SFTP inaweza kutumia local user identities, lakini pia inasaidia Microsoft Entra ID-based access with Azure RBAC kwa authorization. Hii ina maana access inaweza kutolewa kwa kawaida Blob Storage data-plane roles badala ya kuunda local SFTP users. Local users wanaweza authenticate kupitia:
|
||||
- Azure-generated passwords
|
||||
- Public-private SSH key pairs
|
||||
- Granular Permissions: Permissions kama Read, Write, Delete, na List zinaweza kupewa local users hadi containers 100.
|
||||
- Networking Considerations: SFTP connections hufanyika kupitia port 22. Azure inasaidia network configurations kama firewalls, private endpoints, au virtual networks ili kulinda SFTP traffic.
|
||||
- Granular Permissions: Permissions kama Read, Write, Delete, na List zinaweza kupewa local users kwa hadi containers 100.
|
||||
- Networking Considerations: SFTP connections hufanywa kupitia port 22. Azure inasaidia network configurations kama firewalls, private endpoints, au virtual networks ili kulinda SFTP traffic.
|
||||
|
||||
### Setup Requirements
|
||||
|
||||
- Hierarchical Namespace: HNS lazima iwe enabled wakati wa kuunda storage account.
|
||||
- Supported Encryption: Inahitaji Microsoft Security Development Lifecycle (SDL)-approved cryptographic algorithms (kwa mfano, rsa-sha2-256, ecdsa-sha2-nistp256).
|
||||
- Supported Encryption: Inahitaji Microsoft Security Development Lifecycle (SDL)-approved cryptographic algorithms (e.g., rsa-sha2-256, ecdsa-sha2-nistp256).
|
||||
- SFTP Configuration:
|
||||
- Enable SFTP kwenye storage account.
|
||||
- Create local user identities zenye permissions zinazofaa.
|
||||
- Configure home directories kwa users ili kufafanua starting location yao ndani ya container.
|
||||
- Enable SFTP on the storage account.
|
||||
- Kwa local-user access, create local user identities with appropriate permissions.
|
||||
- Kwa local users, configure home directories ili kufafanua starting location yao ndani ya container.
|
||||
|
||||
### Permissions
|
||||
|
||||
@@ -379,7 +379,7 @@ az storage account local-user list \
|
||||
{{#tab name="Az PowerShell" }}
|
||||
|
||||
<details>
|
||||
<summary>Uorodheshaji wa Az PowerShell</summary>
|
||||
<summary>Az PowerShell enumeration</summary>
|
||||
```powershell
|
||||
# Get storage accounts
|
||||
Get-AzStorageAccount | fl
|
||||
@@ -448,7 +448,7 @@ New-AzStorageBlobSASToken `
|
||||
az-file-shares.md
|
||||
{{#endref}}
|
||||
|
||||
## Privilege Escalation
|
||||
## Uongezaji wa Ruhusa
|
||||
|
||||
{{#ref}}
|
||||
../az-privilege-escalation/az-storage-privesc.md
|
||||
@@ -466,11 +466,12 @@ az-file-shares.md
|
||||
../az-persistence/az-storage-persistence.md
|
||||
{{#endref}}
|
||||
|
||||
## References
|
||||
## Marejeo
|
||||
|
||||
- [https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blobs-introduction](https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blobs-introduction)
|
||||
- [https://learn.microsoft.com/en-us/azure/storage/common/storage-sas-overview](https://learn.microsoft.com/en-us/azure/storage/common/storage-sas-overview)
|
||||
- [https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support](https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support)
|
||||
- [https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support-entra-id-based-access](https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support-entra-id-based-access)
|
||||
- [Holiday Hack Challenge 2025 – Spare Key (Azure static website SAS leak)](https://0xdf.gitlab.io/holidayhack2025/act1/spare-key)
|
||||
- [Holiday Hack Challenge 2025: Blob Storage (Storage Secrets)](https://0xdf.gitlab.io/holidayhack2025/act1/blob-storage)
|
||||
- [https://learn.microsoft.com/en-us/cli/azure/storage/account](https://learn.microsoft.com/en-us/cli/azure/storage/account)
|
||||
|
||||
Reference in New Issue
Block a user