Translated ['', 'src/pentesting-cloud/azure-security/az-services/az-stor

This commit is contained in:
Translator
2026-01-18 15:04:46 +00:00
parent 5a13fa6488
commit 4b6f4a380a
@@ -4,114 +4,129 @@
## 기본 정보
Azure Storage Accounts는 blobs (binary large objects), 파일, 큐, 테이블 등 다양한 데이터 유형에 대해 확장 가능하고 안전하며 고가용성의 클라우드 **스토리지를 제공하는** Microsoft Azure의 기본 서비스입니다. 이들은 단일 네임스페이스 아래에서 이러한 서로 다른 스토리지 서비스를 그룹화하여 관리하기 쉽게 하는 컨테이너 역할을 합니다.
Azure Storage Accounts는 Microsoft Azure에서 다양한 데이터 유형(예: blobs (binary large objects), 파일, 큐, 테이블)에 대해 확장 가능하고 안전하며 고가용성의 클라우드 **스토리지**를 제공하는 기본 서비스입니다. 이들은 이러한 다양한 스토리지 서비스를 단일 네임스페이스 아래에 그룹화하여 관리하기 쉽게 하는 컨테이너 역할을 합니다.
**주요 구성 옵션**:
- 모든 storage account는 **Azure 전에서 유한 이름**을 가져야 합니다.
- 각 storage account는 **리전(region)** 또는 Azure 확장 에 배포됩니다.
- 더 나은 성능을 위해 storage account**premium** 버전을 선택할 수 있습니다.
- 랙, 드라이브 및 데이터센터 **장애(failures)**로부터 보호하기 위해 **4가지 중복 유형** 중에서 선택할 수 있습니다.
- 모든 스토리지 계정은 **Azure 전에서 유한 이름**을 가져야 합니다.
- 모든 스토리지 계정은 **지역(region)** 또는 Azure 확장 영역에 배포됩니다.
- 더 나은 성능을 위해 스토리지 계정**premium** 버전을 선택할 수 있습니다.
- 랙, 드라이브 및 데이터센터 **장애**로부터 보호하기 위해 **4가지 중복 유형** 중에서 선택할 수 있습니다.
**보안 구성 옵션**:
- **Require secure transfer for REST API operations**: 스토리지와의 모든 통신에서 TLS를 요구합니다.
- **Allows enabling anonymous access on individual containers**: 설정되어 있지 않다면 향후 개별 컨테이너에 익명 접근을 활성화할 수 없습니다.
- **Allows enabling anonymous access on individual containers**: 비활성화되어 있으면 향후 개별 컨테이너에 익명 액세스를 활성화할 수 없습니다.
- **Enable storage account key access**: 비활성화하면 Shared Keys로의 접근이 금지됩니다.
- **Minimum TLS version**
- **Permitted scope for copy operations**: 모든 storage account로부터, 같은 Entra tenant의 storage account로부터, 또는 동일 가상 네트워크의 private endpoints를 가진 storage account로부터 허용할 수 있습니다.
- **Permitted scope for copy operations**: 모든 스토리지 계정에서 허용, 동일한 Entra tenant의 모든 스토리지 계정에서 허용, 또는 동일 가상 네트워크의 private endpoints가 있는 스토리지 계정에서 허용.
**Blob Storage 옵션**:
- **Allow cross-tenant replication**
- **Access tier**: Hot (자주 접근하는 데이터), Cool 및 Cold (드물게 접근하는 데이터)
- **Access tier**: Hot(자주 접근하는 데이터), Cool 및 Cold(드물게 접근하는 데이터)
**네트워킹 옵션**:
- **Network access**:
- 모든 네트워크에서 허용
- 선택한 가상 네트워크 및 IP 주소에서 허용
- 공개 액세스를 비활성화하고 프라이빗 액세스 사용
- **Private endpoints**: 가상 네트워크에서 storage account로 프라이빗 연결을 허용합니다.
- 모든 네트워크에서 허용
- 선택한 가상 네트워크 및 IP 주소에서 허용
- 퍼블릭 액세스를 비활성화하고 private 액세스 사용
- **Private endpoints**: 가상 네트워크에서 스토리지 계정으로의 프라이빗 연결을 허용합니다.
**데이터 보호 옵션**:
- **Point-in-time restore for containers**: 컨테이너를 이전 상태로 복원할 수 있니다.
- 기능은 versioning, change feed, 및 blob soft delete 활성화되어 있어야 합니다.
- **Enable soft delete for blobs**: 삭제된 blobs(덮어쓰여진 경우 포함)에 대해 일 단위 보존 기간을 설정할 수 있습니다.
- **Enable soft delete for containers**: 삭제된 컨테이너에 대해 일 단위 보존 기간을 설정할 수 있습니다.
- **Enable soft delete for file shares**: 삭제된 파일 공유에 대해 일 단위 보존 기간을 설정할 수 있습니다.
- **Enable versioning for blobs**: blob의 이전 버전을 보관합니다.
- **Enable blob change feed**: blob의 생성, 수정, 삭제 변경 사항을 로그로 보관합니다.
- **Enable version-level immutability support**: 계정 수준에서 모든 blob 버전에 적용되는 시간 기반 보존 정책을 설정할 수 있니다.
- **Point-in-time restore for containers**: 컨테이너를 이전 상태로 복원할 수 있게 합니다.
-를 위해 versioning, change feed, 및 blob soft delete 활성화야 합니다.
- **Enable soft delete for blobs**: 삭제된 블롭(덮어쓴 경우 포함)에 대해 일 단위 보존 기간을 설정니다.
- **Enable soft delete for containers**: 삭제된 컨테이너에 대해 일 단위 보존 기간을 설정니다.
- **Enable soft delete for file shares**: 삭제된 파일 공유에 대해 일 단위 보존 기간을 설정니다.
- **Enable versioning for blobs**: 블롭의 이전 버전을 유지합니다.
- **Enable blob change feed**: 블롭의 생성, 수정 삭제 변경 사항을 로그로 보관합니다.
- **Enable version-level immutability support**: 계정 수준에서 모든 블롭 버전에 적용되는 시간 기반 보존 정책을 설정할 수 있게 합니다.
- Version-level immutability support와 point-in-time restore for containers는 동시에 활성화할 수 없습니다.
**암호화 구성 옵션**:
- **Encryption type**: Microsoft-managed keys (MMK) 또는 Customer-managed keys (CMK)를 사용할 수 있습니다.
- **Enable infrastructure encryption**: 데이터를 "추가 보안"을 위해 이중 암호화할 수 있니다.
- **Enable infrastructure encryption**: 데이터를 "더 안전하게" 이중 암호화할 수 있게 합니다.
### 스토리지 엔드포인트
### Storage endpoints
<table data-header-hidden><thead><tr><th width="197">Storage Service</th><th>Endpoint</th></tr></thead><tbody><tr><td><strong>Blob storage</strong></td><td><code>https://<storage-account>.blob.core.windows.net</code><br><br><code>https://<stg-acc>.blob.core.windows.net/<container-name>?restype=container&comp=list</code></td></tr><tr><td><strong>Data Lake Storage</strong></td><td><code>https://<storage-account>.dfs.core.windows.net</code></td></tr><tr><td><strong>Azure Files</strong></td><td><code>https://<storage-account>.file.core.windows.net</code></td></tr><tr><td><strong>Queue storage</strong></td><td><code>https://<storage-account>.queue.core.windows.net</code></td></tr><tr><td><strong>Table storage</strong></td><td><code>https://<storage-account>.table.core.windows.net</code></td></tr></tbody></table>
### 공개 노출
만약 "Allow Blob public access"가 **활성화되어 있으면**(기본적으로 비활성화), 컨테이너 생성 시 다음을 할 수 있습니다:
"Allow Blob public access"가 **활성화**되어 있는 경우(기본값은 비활성화), 컨테이너 생성할 때 다음이 가능합니다:
- blob을 읽을 수 있는 **공개 접근 권한 부여**(이름을 알야 함).
- 컨테이너의 blobs를 **목록 조회**하고 **읽기**.
- 완전히 **비공개(private)**로 설정.
- **블롭을 읽을 수 있는 공개 액세스 부여**(이름을 알고 있어야 함).
- 컨테이너 블롭 **목록화****읽기**.
- 완전히 **비공개**로 설정.
<figure><img src="https://lh7-rt.googleusercontent.com/slidesz/AGV_vUfoetUnYBPWQpRrWNnnlbqWpl8Rdoaeg5uBrCVlvcNDlnKwQHjZe8nUb2SfPspBgbu-lCZLmUei-hFi_Jl2eKbaxUtBGTjdUSDmkrcwr90VZkmuMjk9tyh92p75btfyzGiUTa0-=s2048?key=m8TV59TrCFPlkiNnmhYx3aZt" alt=""><figcaption></figcaption></figure>
#### 익명 blob 노출 감사
### Static website (`$web`) 노출 & leaked secrets
- **데이터를 노출할 수 있는 storage account 찾기**: `az storage account list | jq -r '.[] | select(.properties.allowBlobPublicAccess==true) | .name'`. 만약 `allowBlobPublicAccess``false`이면 컨테이너를 공개로 전환할 수 없습니다.
- **위험한 계정 검사**: 플래그와 기타 취약한 설정을 확인: `az storage account show --name <acc> --query '{allow:properties.allowBlobPublicAccess, minTls:properties.minimumTlsVersion}'`.
- **플래그가 활성화된 경우 컨테이너 수준 노출 열거**:
- **Static websites**는 지역별 엔드포인트(예: `https://<account>.z13.web.core.windows.net/`)를 통해 특별한 `$web` 컨테이너에서 제공됩니다.
- `$web` 컨테이너는 blob API를 통해 `publicAccess: null`을 보고할 수 있지만, 파일은 여전히 static site 엔드포인트를 통해 접근 가능하므로 구성/IaC 아티팩트를 해당 위치에 두면 secrets가 leak될 수 있습니다.
- 간단한 감사 워크플로:
```bash
# Identify storage accounts with static website hosting enabled
az storage blob service-properties show --account-name <acc-name> --auth-mode login
# Enumerate containers (including $web) and their public flags
az storage container list --account-name <acc-name> --auth-mode login
# List files served by the static site even when publicAccess is null
az storage blob list --container-name '$web' --account-name <acc-name> --auth-mode login
# Pull suspicious files directly (e.g., IaC tfvars containing secrets/SAS)
az storage blob download -c '$web' --name iac/terraform.tfvars --file /dev/stdout --account-name <acc-name> --auth-mode login
```
### 익명 blob 노출 감사
- **데이터를 노출할 수 있는 스토리지 계정 찾기**: `az storage account list | jq -r '.[] | select(.properties.allowBlobPublicAccess==true) | .name'`. `allowBlobPublicAccess``false`이면 컨테이너를 public으로 전환할 수 없습니다.
- **위험한 계정 검사**하여 플래그 및 기타 약한 설정 확인: `az storage account show --name <acc> --query '{allow:properties.allowBlobPublicAccess, minTls:properties.minimumTlsVersion}'`.
- **플래그가 활성화된 경우 컨테이너 수준의 노출 열거**:
```bash
az storage container list --account-name <acc> \
--query '[].{name:name, access:properties.publicAccess}'
```
- `"Blob"`: 익명 읽기 허용 **blob 이름이 알려진 경우에만** (목록 불가).
- `"Container"`: 익명으로 모든 blob에 대해 **list + read**.
- `"Blob"`: 익명 읽기 허용 **오직 blob 이름이 알려진 경우에만** (목록 불가).
- `"Container"`: 익명 **목록 + 읽기** (모든 blob).
- `null`: 비공개; 인증 필요.
- **접근 증명** 자격 증명 없이:
- If `publicAccess` is `Container`, 익명 목록 조회가 작동합니다: `curl "https://<acc>.blob.core.windows.net/<container>?restype=container&comp=list"`.
- For both `Blob` and `Container`, 익명 blob 다운로드는 이름이 알려진 경우 작동합니다:
- If `publicAccess` is `Container`, anonymous listing works: `curl "https://<acc>.blob.core.windows.net/<container>?restype=container&comp=list"`.
- For both `Blob` and `Container`, anonymous blob download works when the name is known:
```bash
az storage blob download -c <container> -n <blob> --account-name <acc> --file /dev/stdout
# or via raw HTTP
curl "https://<acc>.blob.core.windows.net/<container>/<blob>"
```
### 스토리지에 연결
### Connect to Storage
연결할 수 있는 **스토리지**를 찾으면 [**Microsoft Azure Storage Explorer**](https://azure.microsoft.com/es-es/products/storage/storage-explorer/) 도구를 사용할 수 있습니다.
If you find any **storage** you can connect to you could use the tool [**Microsoft Azure Storage Explorer**](https://azure.microsoft.com/es-es/products/storage/storage-explorer/) to do so.
## 스토리지 접근 <a href="#about-blob-storage" id="about-blob-storage"></a>
## Access to Storage <a href="#about-blob-storage" id="about-blob-storage"></a>
### RBAC
Entra ID principals **RBAC roles**와 함께 사용해 스토리지 계정에 접근할 수 있으며, 권장되는 방법입니다.
It's possible to use Entra ID principals with **RBAC roles** to access storage accounts and it's the recommended way.
### 액세스 키
### Access Keys
스토리지 계정에는 접근에 사용할 수 있는 액세스 키가 있습니다. 이는 스토리지 계정에 대한 **완전한 액세스 권한**을 제공합니다.
The storage accounts have access keys that can be used to access it. This provides **스토리지 계정에 대한 전체 액세스 권한을 제공합니다.**
<figure><img src="../../../images/image (5).png" alt=""><figcaption></figcaption></figure>
### **Shared Keys & Lite Shared Keys**
액세스 키로 서명된 [**generate Shared Keys**](https://learn.microsoft.com/en-us/rest/api/storageservices/authorize-with-shared-key)를 생성하여 서명된 URL을 통해 특정 리소스에 대한 접근을 허가할 수 있습니다.
It's possible to [**generate Shared Keys**](https://learn.microsoft.com/en-us/rest/api/storageservices/authorize-with-shared-key) signed with the access keys to authorize access to certain resources via a signed URL.
> [!NOTE]
> `CanonicalizedResource` 부분은 스토리지 서비스 리소스(URI)를 나타냅니다. URL의 어떤 부분이 인코딩되어 있다면, 그 부분은 `CanonicalizedResource` 내부에서도 인코딩되어야 합니다.
> 참고로 `CanonicalizedResource` 부분은 스토리지 서비스 리소스(URI)를 나타냅니다. URL의 어떤 부분이 인코딩되어 있다면, `CanonicalizedResource` 에서도 동일하게 인코딩되어야 합니다.
> [!NOTE]
> 것은 요청을 인증하기 위해 **기본적으로 `az` cli에서 사용됩니다**. Entra ID principal 자격 증명을 사용하도록 하려면 `--auth-mode login` 파라미터를 지정하세요.
> 요청을 인증하는 데 기본적으로 **`az` cli**에서 사용됩니다. Entra ID principal 자격 증명을 사용하도록 하려면 파라미터 `--auth-mode login` 지정하세요.
- 다음 정보를 서명하여 **shared key for blob, queue and file services**를 생성할 수 있습니다:
- It's possible to generate a **shared key for blob, queue and file services** signing the following information:
```bash
StringToSign = VERB + "\n" +
Content-Encoding + "\n" +
@@ -150,7 +165,7 @@ CanonicalizedResource;
StringToSign = Date + "\n"
CanonicalizedResource
```
그런 다음 키를 사용하려면 다음 형식으로 Authorization 헤더에 지정하면 됩니다:
그런 다음 키를 사용하려면 다음 구문을 따라 Authorization header에 넣으면 됩니다:
```bash
Authorization="[SharedKey|SharedKeyLite] <AccountName>:<Signature>"
#e.g.
@@ -162,72 +177,72 @@ x-ms-date: Fri, 26 Jun 2015 23:39:12 GMT
Authorization: SharedKey myaccount:ctzMq410TV3wS7upTBcunJTDLEJwMAZuFPfr0mrrA08=
Content-Length: 0
```
### **Shared Access Signature** (SAS)
### **공유 액세스 서명** (SAS)
Shared Access Signatures (SAS)는 계정의 액세스 키를 노출하지 않고 Azure Storage 계정 리소스에 접근할 수 있는 **리소스에 대한 특정 권한을 부여**하는 보안·시간제한 URL입니다. 액세스 키 모든 리소스에 대한 전체 관리자 권한을 제공하는 반면, SAS는 권한(예: 읽기 또는 쓰기)을 지정하고 만료 시간을 정의 세분화된 제어를 제공합니다.
Shared Access Signatures (SAS)는 계정의 액세스 키를 노출하지 않고 Azure Storage 계정 리소스에 접근하기 위해 특정 권한을 부여하는 보안적이고 시간 제한 URL입니다. 액세스 키 모든 리소스에 대한 전체 관리자 액세스를 제공하는 반면, SAS는 읽기나 쓰기 같은 권한을 지정하고 만료 시간을 정의하여 세분화된 제어를 가능하게 합니다.
#### SAS Types
#### SAS 유형
- **User delegation SAS**: 이 **Entra ID principal**에서 생성되며 해당 principal이 SAS에 서명하고 사용자로부터 권한을 SAS로 위임합니다. **blob and data lake storage**에서만 사용할 수 있습니다 ([docs](https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas)). 생성된 모든 사용자 위임 SAS를 **해지**할 수 있습니다.
- 사용자가 가 권한보다 "더 많은" 권한으로 delegation SAS를 생성하는 것이 가능하더라도, principal이 해당 권한을 가지고 있지 않동하지 않습니다(권한 상승 불가, no privesc).
- **Service SAS**: 이는 storage account**access keys** 중 하나로 서명됩니다. 단일 storage service의 특정 리소스에 대한 접근을 부여하는 데 사용 수 있습니다. 키가 갱신되면 SAS는 동을 멈춥니다.
- **Account SAS**: 마찬가지로 storage account**access keys** 중 하나로 서명됩니다. Blob, Queue, Table, File 스토리지 계정 서비스 전반에 걸쳐 리소스 접근을 부여하며 서비스 수준 작업을 포함할 수 있습니다.
- **User delegation SAS**: 이것은 **Entra ID principal**로부터 생성되며, 해당 principal이 SAS에 서명하고 사용자로부터 SAS로 권한을 위임합니다. **blob and data lake storage**에서만 사용할 수 있습니다 ([docs](https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas)). 생성된 모든 user delegated SAS를 **폐기(revoke)**할 수 있습니다.
- 사용자가 가지고 있는 권한보다 "더 많은" 권한으로 delegation SAS를 생성할 수 있는 경우가 있습니다. 그러나 principal이 해당 권한을 실제로 가지고 있지 않면 동하지 않습니다(권한 상승 없음 — no privesc).
- **Service SAS**: 이것은 스토리지 계정의 하나의 **액세스 키(access keys)**로 서명됩니다. 단일 스토리지 서비스 내의 특정 리소스에 대한 접근을 부여하는 데 사용 수 있습니다. 키가 갱신되면 SAS는 동을 멈춥니다.
- **Account SAS**: 이것도 스토리지 계정의 하나의 **액세스 키(access keys)**로 서명됩니다. Blob, Queue, Table, File과 같은 스토리지 계정 서비스 전반 리소스 접근을 부여하며 서비스 수준 작업을 포함할 수 있습니다.
A SAS URL signed by an **access key** looks like this:
액세스 키로 서명된 SAS URL 예시는 다음과 같습니다:
- `https://<container_name>.blob.core.windows.net/newcontainer?sp=r&st=2021-09-26T18:15:21Z&se=2021-10-27T02:14:21Z&spr=https&sv=2021-07-08&sr=c&sig=7S%2BZySOgy4aA3Dk0V1cJyTSIf1cW%2Fu3WFkhHV32%2B4PE%3D`
A SAS URL signed as a **user delegation** looks like this:
User delegation으로 서명된 SAS URL 예시는 다음과 같습니다:
- `https://<container_name>.blob.core.windows.net/testing-container?sp=r&st=2024-11-22T15:07:40Z&se=2024-11-22T23:07:40Z&skoid=d77c71a1-96e7-483d-bd51-bd753aa66e62&sktid=fdd066e1-ee37-49bc-b08f-d0e152119b04&skt=2024-11-22T15:07:40Z&ske=2024-11-22T23:07:40Z&sks=b&skv=2022-11-02&spr=https&sv=2022-11-02&sr=c&sig=7s5dJyeE6klUNRulUj9TNL0tMj2K7mtxyRc97xbYDqs%3D`
Note some **http params**:
몇 가지 **HTTP 파라미터**에 주목하세요:
- The **`se`** param indicates the **만료 날짜** of the SAS
- The **`sp`** param indicates the **권한** of the SAS
- The **`sig`** is the **서명** validating the SAS
- `se` 파라미터는 SAS의 만료 날짜를 나타냅니다.
- `sp` 파라미터는 SAS의 권한(permissions)을 나타냅니다.
- `sig`는 SAS를 검증하는 서명(signature)입니다.
#### SAS permissions
#### SAS 권한
SAS를 생성할 때 부여할 권한을 명시해야 합니다. 어떤 객체에 대해 SAS를 생성하느냐에 따라 포함될 수 있는 권한이 달라집니다. 예를 들어:
SAS를 생성할 때 부여할 권한을 지정해야 합니다. 대상 객체에 따라 포함될 수 있는 권한이 달라집니다. 예를 들어:
- (a)dd, (c)reate, (d)elete, (e)xecute, (f)ilter_by_tags, (i)set_immutability_policy, (l)ist, (m)ove, (r)ead, (t)ag, (w)rite, (x)delete_previous_version, (y)permanent_delete
## SFTP Support for Azure Blob Storage
## Azure Blob Storage용 SFTP 지원
Azure Blob Storage는 이제 SSH File Transfer Protocol (SFTP)을 지원하여, 맞춤형 솔루션이나 타사 제품 없이 Blob Storage로 직접 안전한 파일 전송 및 관리를 할 수 있습니다.
Azure Blob Storage는 이제 SSH File Transfer Protocol (SFTP)을 지원하여, 커스텀 솔루션이나 서드파티 제품 없이 직접 Blob Storage로 안전한 파일 전송 및 관리를 가능하게 합니다.
### Key Features
### 주요 기능
- Protocol Support: SFTP는 hierarchical namespace (HNS)로 구성된 Blob Storage 계정에서 작동합니다. 이는 blob을 디렉터리와 하위 디렉터리로 구성하여 탐색을 용이하게 합니다.
- Security: SFTP는 로컬 사용자 ID를 인증에 사용하며 RBAC 또는 ABAC와 통합되지 않습니다. 각 로컬 사용자는 다음 방법으로 인증할 수 있습니다:
- Azure에서 생성 비밀번호
- 공개-개인 SSH 키 쌍
- Granular Permissions: Read, Write, Delete, List와 같은 권한을 로컬 사용자에게 최대 100개 컨테이너에 대해 할당할 수 있습니다.
- Networking Considerations: SFTP 연결은 포트 22를 통해 이루어집니다. Azure는 방화벽, private endpoints 또는 virtual networks와 같은 네트워크 구성을 지원하여 SFTP 트래픽을 보호니다.
- Security: SFTP는 인증을 위해 로컬 사용자 ID를 사용하며 RBAC 또는 ABAC와 통합되지 않습니다. 각 로컬 사용자는 다음 방법으로 인증할 수 있습니다:
- Azure에서 생성 비밀번호
- 공개/개인 SSH 키 쌍
- Granular Permissions: Read, Write, Delete, List와 같은 권한을 로컬 사용자에게 최대 100개 컨테이너에 대해 할당할 수 있습니다.
- Networking Considerations: SFTP 연결은 포트 22를 통해 이루어집니다. Azure는 방화벽, private endpoints, virtual networks와 같은 네트워크 구성을 지원하여 SFTP 트래픽을 보호할 수 있습니다.
### Setup Requirements
### 설정 요구사항
- Hierarchical Namespace: HNS는 storage account 생성 시 활성화되어야 합니다.
- Supported Encryption: Microsoft Security Development Lifecycle (SDL)에서 승인 암호화 알고리즘(예: rsa-sha2-256, ecdsa-sha2-nistp256)을 요구합니다.
- Hierarchical Namespace: 스토리지 계정 생성 시 HNS가 활성화되어야 합니다.
- Supported Encryption: Microsoft Security Development Lifecycle (SDL) 승인 암호화 알고리즘(예: rsa-sha2-256, ecdsa-sha2-nistp256)을 요구합니다.
- SFTP Configuration:
- Enable SFTP on the storage account.
- Create local user identities with appropriate permissions.
- Configure home directories for users to define their starting location within the container.
- 스토리지 계정에서 SFTP를 활성화합니다.
- 적절한 권한을 가진 로컬 사용자 ID를 생성합니다.
- 사용자의 시작 위치를 정의하기 위해 홈 디렉터리를 구성합니다.
### Permissions
### 권한
| 권한 | 기호 | 설명 |
| ---------------------- | ------ | ------------------------------------- |
| **읽기 (Read)** | `r` | 파일 내용을 읽습니다. |
| **쓰기 (Write)** | `w` | 파일 업로드 및 디렉터리 생성. |
| **목록 (List)** | `l` | 디렉터리 내용 나열. |
| **삭제 (Delete)** | `d` | 파일 또는 디렉터리 삭제. |
| **생성 (Create)** | `c` | 파일 또는 디렉터리 생성. |
| **소유권 변경 (Modify Ownership)** | `o` | 소유 사용자 또는 그룹 변경. |
| **권한 변경 (Modify Permissions)** | `p` | 파일 또는 디렉터리의 ACL 변경. |
| Permission | Symbol | Description |
| ---------------------- | ------ | ------------------------------------ |
| **Read** | `r` | 파일 내용을 읽습니다. |
| **Write** | `w` | 파일 업로드 및 디렉터리 생성. |
| **List** | `l` | 디렉터리 내용 나열합니다. |
| **Delete** | `d` | 파일 또는 디렉터리 삭제합니다. |
| **Create** | `c` | 파일 또는 디렉터리 생성합니다. |
| **Modify Ownership** | `o` | 소유자 또는 그룹 변경합니다. |
| **Modify Permissions** | `p` | 파일 또는 디렉터리의 ACL 변경합니다. |
## Enumeration
## 열거
{{#tabs }}
{{#tab name="az cli" }}
@@ -426,29 +441,30 @@ New-AzStorageBlobSASToken `
az-file-shares.md
{{#endref}}
## 권한 상승
## Privilege Escalation
{{#ref}}
../az-privilege-escalation/az-storage-privesc.md
{{#endref}}
## 사후 악용
## Post Exploitation
{{#ref}}
../az-post-exploitation/az-blob-storage-post-exploitation.md
{{#endref}}
## 지속성
## Persistence
{{#ref}}
../az-persistence/az-storage-persistence.md
{{#endref}}
## 참
## 참고자료
- [https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blobs-introduction](https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blobs-introduction)
- [https://learn.microsoft.com/en-us/azure/storage/common/storage-sas-overview](https://learn.microsoft.com/en-us/azure/storage/common/storage-sas-overview)
- [https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support](https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support)
- [Holiday Hack Challenge 2025 Spare Key (Azure static website SAS leak)](https://0xdf.gitlab.io/holidayhack2025/act1/spare-key)
- [Holiday Hack Challenge 2025: Blob Storage (Storage Secrets)](https://0xdf.gitlab.io/holidayhack2025/act1/blob-storage)
- [https://learn.microsoft.com/en-us/cli/azure/storage/account](https://learn.microsoft.com/en-us/cli/azure/storage/account)
- [https://learn.microsoft.com/en-us/cli/azure/storage/container](https://learn.microsoft.com/en-us/cli/azure/storage/container)