Translated ['', 'src/pentesting-cloud/azure-security/az-services/az-sql.

This commit is contained in:
Translator
2026-07-17 06:09:49 +00:00
parent 5221306157
commit 9b8b7d73ff
2 changed files with 146 additions and 146 deletions
@@ -4,47 +4,47 @@
## Azure SQL
Azure SQL 是一托管、安全的、智能的产品,它们使用 **Azure cloud 中的 SQL Server database engine**。这意味着你不必担心服务器的物理管理,可以专注于管理你的数据。
Azure SQL 是一系列托管、安全智能的产品,使用 **Azure cloud 中的 SQL Server database engine**。这意味着你无需担心服务器的物理管理,可以专注于管理数据。
Azure SQL 由四个主要服务组成
Azure SQL 包含四种主要产品
1. **Azure SQL Server**:部署和管理 SQL Server databases 需要一个 server。
2. **Azure SQL Database**:这是一**fully-managed database service**,可让你在 Azure cloud 中托管单个 databases。
3. **Azure SQL Managed Instance**用于更大规模、整个 SQL Server instance 级别的部署。
4. **Azure SQL Server on Azure VMs**:最适合你希望 **control over the operating system** 和 SQL Server instance 的架构。
1. **Azure SQL Server**:部署和管理 SQL Server databases 需要使用 server。
2. **Azure SQL Database**:这是一项**完全托管的 database service**,允许你在 Azure cloud 中托管独立的 databases。
3. **Azure SQL Managed Instance**:用于更大规模的、完整 SQL Server instance-scoped 部署。
4. **Azure SQL Server on Azure VMs**:最适合需要**控制 operating system **和 SQL Server instance 的架构。
### SQL Server Security Features
**Network access:**
**Network access**
- Public endpoint(可限制特定 networks 的访问)。
- Public endpoint(可以将访问限制特定 networks)。
- Private endpoints。
- 也可以根据 domain names 限制连接
- 也可以允许 Azure services 访问它(例如 portal 中使用 Query editor,或允许 Azure VM 连接)。
- 如果某个 SQL Server 将 *Allow Azure services and resources to access this server* 设置为 "Enabled"Azure 自动创建一条隐藏的 firewall rule,允许所有来自 Azure 的 network traffic 连接到 SQL Server —— 包括来自任何 tenant 的 resources。
- 这意味着如果你获得有效的 SQL credentials可以从自己 attackercontrolled tenant 的 Azure VM 连接到受害者的 Azure SQL Server。[MS docs 解释了这一点](https://learn.microsoft.com/en-us/azure/azure-sql/database/network-access-controls-overview?view=azuresql#allow-azure-services)
- 也可以根据 domain names 限制 connections
- 也可以允许 Azure services 访问它(例如使用 portal 中 Query editor,或允许 Azure VM 进行连接)。
- 如果 SQL Server 将 *Allow Azure services and resources to access this server* 设置为 "Enabled"Azure 自动创建一条隐藏的 firewall rule,允许自 Azure 的所有 network traffic 连接到 SQL Server包括来自任何 tenant 的 resources。
- 这意味着如果你获得有效的 SQL credentials可以从自己控制的 attacker tenant 的 Azure VM 连接到受害者的 Azure SQL Server。[The MS docs explains this](https://learn.microsoft.com/en-us/azure/azure-sql/database/network-access-controls-overview?view=azuresql#allow-azure-services)
**Authentication Methods:**
**Authentication Methods**
- Microsoft **Entra-only** authentication需要指定可以访问该 service 的 Entra principals。
- **Both SQL and Microsoft Entra** authentication传统的 SQL authentication,使用 username 和 password,并同时支持 Microsoft Entra
- **Only SQL** authentication:仅允许通过 database users 访问。
- Microsoft **Entra-only** authentication:需要指定可以访问该 service 的 Entra principals。
- **Both SQL and Microsoft Entra** authentication在 Microsoft Entra 之外,同时使用带有 username 和 password 的传统 SQL authentication
- **Only SQL** authentication:仅允许通过 database users 进行访问。
注意,如果允许任何 SQL auth需要指定一个 admin userusername + password);如果选择 Entra ID auth需要至少指定一个具有 admin 访问权限的 principal。
注意,如果允许任何 SQL auth需要指定一个 admin userusername + password);如果选择 Entra ID auth则还需要至少指定一个具有 admin access 的 principal。
**Encryption:**
**Encryption**
- 称为 “Transparent data encryption”,会对静态的 databases、backups 和 logs 进行加密
- 一如既往,默认使用 Azure managed key,但也可以使用 customer managed encryption key (CMEK)。
**Managed Identities:**
- 称为“Transparent data encryption”,用于加密静态存储的 databases、backups 和 logs。
- 与往常一样,默认使用 Azure managed key,但也可以使用 customer managed encryption key (CMEK)。
**Managed Identities**
- 可以分配 system 和 user managed MIs。
- 用于访问 encryption key(如果使用 CMEK)以及数据库中的其他 services。
- 有关可从 database 访问的 Azure services 示例,请查看 [this page of the docs](https://learn.microsoft.com/en-us/sql/t-sql/statements/create-external-data-source-transact-sql)
- 如果分配了多个 UMI,可以指定默认使用的那个
- 可以配置 federated client identity 以实现 cross-tenant access。
- 用于访问 encryption key(如果使用 CMEK)以及从 databases 访问其他 services。
- 有关可从 database 访问的 Azure services 示例,请查看 [this page of the docs](https://learn.microsoft.com/en-us/sql/t-sql/statements/create-external-data-source-transact-sql)
- 如果分配了多个 UMI可以指定使用的默认 UMI
- 可以配置 federated client identity以实现 cross-tenant access。
Some commands to access info inside a blob storage from a SQL database:
从 SQL database 访问 blob storage 中信息的一些 commands
```sql
-- Create a credential for the managed identity
CREATE DATABASE SCOPED CREDENTIAL [ManagedIdentityCredential]
@@ -69,62 +69,62 @@ SINGLE_CLOB
) AS DataFile;
GO
```
**Microsoft Defender:**
**Microsoft Defender**
- 于“缓解潜在数据库漏洞,以及检测异常活动”很有用
- 我们在单独的课程中讲解 Defender(它可以在其他个 Azure 服务中启用)
- 于“缓解潜在数据库漏洞检测异常活动”
- 我们在单独的课程中讨论 Defender(它可以在其他个 Azure 服务中启用)
**Backups:**
- Backup 频率由 retention policies 管理。
**备份:**
- 备份频率由保留策略管理。
**Deleted databases:**
- 可以从现有 backups 中恢复已删除的 DBs
**已删除的数据库:**
- 可以从现有备份中还原已删除的 DB。
## Azure SQL Database
**Azure SQL Database** 是一个**fully managed database platform as a service (PaaS)**,提供可扩展且安全的关系数据库解决方案。它基于最新的 SQL Server technologies 构建,并消除了基础设施管理的需要,因此成为云应用的热门选择。
**Azure SQL Database** 是一个**完全托管的数据库平台即服务(PaaS**,提供可扩展且安全的关系数据库解决方案。它基于最新的 SQL Server 技术构建,无需管理基础设施,因此成为云应用的热门选择。
要创建一个 SQL database,需要指定它将托管在哪个 SQL server
要创建 SQL 数据库,需要指定其托管位置所在的 SQL server。
### SQL Database Security Features
### SQL Database 安全功能
- **Always Up-to-Date**: 运行最新稳定版 SQL Server,并自动接收新功能和补丁。
- **Inherited SQL Server security features:**
- Authentication (SQL and/or Entra ID)
- **始终保持最新**运行最新稳定版 SQL Server,并自动接收新功能和补丁。
- **继承的 SQL Server 安全功能:**
- 身份验证(SQL 和/或 Entra ID
- Assigned Managed Identities
- Network restrictions
- Encryption
- Backups
- 网络限制
- 加密
- 备份
-
- **Data redundancy:** 选项包括 local、zone、Geo 或 Geo-Zone redundant
- **Ledger:** 它会通过加密方式验证数据完整性,确保任何篡改都能被检测到。对金融、医疗以及任何管理敏感数据的组织都很有用。
- **数据冗余:**可选择本地、区域、Geo 或 Geo-Zone 冗余
- **Ledger**通过加密方式验证数据完整性,确保能够检测到任何篡改。对金融、医疗以及任何管理敏感数据的组织都很有用。
A SQL database 可以是 **elastic Pool** 的一部分。Elastic pools 是一种高性价比方案,通过在多个数据库之间共享可配置的 compute (eDTUs) 和 storage resources 来管理它们,且定价仅基于分配的 resources,而不是数据库数量。
SQL 数据库可以属于一个 **Elastic Pool**。Elastic pools 通过在多个数据库之间共享可配置的计算资源(eDTUs)和存储资源,为管理多个数据库提供了一种经济高效的解决方案;其定价仅基于分配的资源,而不是数据库数量。
#### Azure SQL Column Level Security (Masking) & Row Level Security
#### Azure SQL 列级安全(Masking)与行级安全
**Azure SQL's dynamic** data masking 是一项帮助**通过隐藏敏感信息来保护**的功能,防止未授权用户查看。它不会改实际数据,而是动态地对显示的数据进行 masking,确保信用卡号等敏感细节被遮蔽
**Azure SQL 的动态**数据掩码是一项通过**隐藏敏感信息来保护其安全**的功能,防止未授权用户查看这些信息。它不会改实际数据,而是动态掩码显示的数据,从而确保信用卡号等敏感细节被隐藏
**Dynamic Data Masking** 会影响除未被 masked 的用户(这些用户需要被指明)以及 administrators 之外的所有用户。它有一个配置选项用于指定哪些 SQL users 不受 dynamic data masking 影响,且 **administrators 始终被排除在外**
**Dynamic Data Masking** 会影响所有用户,但未被掩码的用户和管理员除外(需要指定这些用户)。其配置选项用于指定哪些 SQL 用户可免受动态数据掩码的影响,**管理员始终被排除在外**。
**Azure SQL Row Level Security (RLS)** 是一项**控制用户可以查看或修改哪些 rows** 的功能,确保每个用户只看到与自己相关的数据。通过创建带有 filter 或 block predicates 的 security policies,组织可以在 database 级别实施细粒度访问控制。
**Azure SQL Row Level Security (RLS)** 是一项**控制用户可以查看或修改哪些**的功能,确保每个用户只看到与相关的数据。通过使用筛选谓词或阻止谓词创建安全策略,组织可以在数据库级别实施细粒度访问控制。
### Azure SQL Managed Instance
**Azure SQL Managed Instances** 适用于更大规模、整个 SQL Server instance-scoped 的部署。它提供与最新的 SQL Server on-premises (Enterprise Edition) Database Engine 几乎 100% 的兼容性,并提供原生 virtual network (VNet) 实现,解决常见的安全问题,同时商业模式也更适合 on-premises SQL Server 客户。
**Azure SQL Managed Instances** 面向更大规模的、完整 SQL Server 实例范围的部署。它与最新的本地部署 SQL ServerEnterprise Edition)数据库引擎具有近 100% 的兼容性,并提供原生虚拟网络(VNet实现,解决常见的安全问题,同时采用有利于本地 SQL Server 客户的商业模式
### Azure SQL Virtual Machines
**Azure SQL Virtual Machines** 允许**控制 operating system** 和 SQL Server instance,因为会在 VM service 中启动一台运行 SQL server 的 VM。
**Azure SQL Virtual Machines** 允许**控制操作系统**和 SQL Server 实例,因为系统会在 VM 服务中生成一个运行 SQL server 的 VM。
创建 SQL Virtual Machine 时,可以**选择 VM 的所有设置**(如 VM 课程中所示),该 VM 将承载 SQL server。
- 这意味着 VM 将访问某些 VNet(s),可能附加 **Managed Identities**,可能挂载了 file shares……这使得从 SQL VM **pivoting** 非常有趣。
- 此外,还可以配置 app id 和 secret **SQL 访问特定的 key vault**,其中可能包含敏感信息。
创建 SQL Virtual Machine 时,可以**选择 VM 的所有设置**(如 VM 课程中所示),该 VM 将托管 SQL server。
- 这意味着 VM 将访问某些 VNet,可能附加 **Managed Identities**可能挂载了文件共享……这使得从 SQL VM 进行 **pivoting** 非常有趣。
- 此外,还可以配置 app id 和 secret使 **SQL 能够访问特定的 key vault**,其中可能包含敏感信息。
可以配置诸如 **automatic SQL updates**、**automatic backups**、**Entra ID authentication** 以及其他 SQL services 中的大多数功能。
可以配置诸如 **automatic SQL updates**、**automatic backups**、**Entra ID authentication** 以及其他 SQL 服务的大多数功能。
## Enumeration
## 枚举
{{#tabs}}
{{#tab name="az cli"}}
@@ -261,7 +261,7 @@ Get-AzSqlVM
{{#endtab}}
{{#endtabs}}
此外,如果你想枚举数据库中 Dynamic Data Masking 和 Row Level policies可以查询:
此外,如果你希望在数据库中枚举 Dynamic Data Masking 和 Row Level policies,可以查询:
```sql
--Enumerates the masked columns
SELECT
@@ -288,7 +288,7 @@ ON sp.object_id = sp2.object_id;
```
### 连接并运行 SQL 查询
你可以从示例 [enumerating an Az WebApp](az-app-services.md) 中找到一个连接字符串(包含凭):
你可以从示例[枚举 Az WebApp](az-app-services.md)中找到一个 connection string(包含凭):
```bash
function invoke-sql{
param($query)
@@ -307,11 +307,11 @@ $Connection.Close()
invoke-sql 'Select Distinct TABLE_NAME From information_schema.TABLES;'
```
You can also use sqlcmd to access the database. 了解服务器是否允许 public connections `az sql server show --name <server-name> --resource-group <resource-group>` 很重要,同时也要确认 firewall rule 是否允许我们的 IP 访问:
你也可以使用 sqlcmd 访问数据库。需要确认服务器是否允许公开连接 `az sql server show --name <server-name> --resource-group <resource-group>`,以及防火墙规则是否允许我们的 IP 访问:
```bash
sqlcmd -S <sql-server>.database.windows.net -U <server-user> -P <server-passworkd> -d <database>
```
## References
## 参考资料
- [https://learn.microsoft.com/en-us/azure/azure-sql/azure-sql-iaas-vs-paas-what-is-overview?view=azuresql](https://learn.microsoft.com/en-us/azure/azure-sql/azure-sql-iaas-vs-paas-what-is-overview?view=azuresql)
- [https://learn.microsoft.com/en-us/azure/azure-sql/database/single-database-overview?view=azuresql](https://learn.microsoft.com/en-us/azure/azure-sql/database/single-database-overview?view=azuresql)
@@ -324,13 +324,13 @@ sqlcmd -S <sql-server>.database.windows.net -U <server-user> -P <server-passwork
../az-privilege-escalation/az-sql-privesc.md
{{#endref}}
## 后渗透
## Post Exploitation
{{#ref}}
../az-post-exploitation/az-sql-post-exploitation.md
{{#endref}}
### 持久化
### Persistence
{{#ref}}
../az-persistence/az-sql-persistence.md
@@ -4,22 +4,22 @@
## 基本信息
Azure Storage Accounts 是 Microsoft Azure 中的基础服务,提供可扩展、安全且高可用的云端 **storage for various data types**,包括 blobs (binary large objects)、files、queues 和 tables。它们作为容器,将这些不同的 storage services 组合在单一 namespace 下,便于管理。
Azure Storage Accounts 是 Microsoft Azure 中的基础服务,可为各种**数据类型提供可扩展、安全且高可用的云端存储**,包括 blobs(二进制大型对象)、文件、队列和表。它们充当容器,将这些不同的存储服务归集到单一命名空间下,以便进行管理。
**主要配置选项**
- 每个 storage account 在整个 Azure 中必须有一个 **uniq name**
- 每个 storage account 都部署在一个 **region** 或 Azure extended zone 中
- 可以选择 storage account 的 **premium** 版本以获得更好的性能
- 可以 **4 种冗余类型** 中进行选择,以防护 rack、drive 和 datacenter **failures**
- 每个 storage account 必须拥有一个**在所有 Azure 中唯一的名称**。
- 每个 storage account 都部署在某个**区域**或 Azure 扩展区域中。
- 可以选择 storage account 的 **premium** 版本以获得更好的性能
- 可以 **4 种冗余类型**中进行选择,以防护机架、驱动器和数据中心**故障**
**安全配置选项**
- **Require secure transfer for REST API operations**:要求与 storage 的任何通信使用 TLS
- **Allows enabling anonymous access on individual containers**如果不启用,未来也无法再开启匿名访问
- **Enable storage account key access**:如果不启用,将禁止使用 Shared Keys 访问
- **Require secure transfer for REST API operations**:要求所有与存储的通信使用 TLS
- **Allows enabling anonymous access on individual containers**允许在单个容器上启用匿名访问。如果不启用,将来无法启用匿名访问
- **Enable storage account key access**:如果不启用,将禁止使用 Shared Keys 进行访问
- **Minimum TLS version**
- **Permitted scope for copy operations**:允许来自任何 storage account、来自同一 Entra tenant 的任 storage account,或来自同一 virtual network 中带有 private endpoints 的 storage account。
- **Permitted scope for copy operations**:允许从任意 storage account、同一 Entra tenant 的任 storage account,或同一 virtual network 中带有 private endpoints 的 storage account 进行复制
**Blob Storage 选项**
@@ -29,27 +29,27 @@ Azure Storage Accounts 是 Microsoft Azure 中的基础服务,提供可扩展
**网络选项**
- **Network access**
- 允许来自所有网络
- 允许来自选定 virtual networks 和 IP addresses
- 允许来自所有网络的访问
- 允许来自选定 virtual networks 和 IP 地址的访问
- 禁用 public access 并使用 private access
- **Private endpoints**:允许从 virtual network storage account private connection
- **Private endpoints**:允许从 virtual network storage account 建立 private connection
**数据保护选项**
- **Point-in-time restore for containers**:允许将 containers 恢复到较早状态
- 要求启用 versioning、change feed 和 blob soft delete。
- **Enable soft delete for blobs**:为删除的 blobs(即使被覆盖)启用按天计算的 retention period
- **Enable soft delete for containers**:为删除的 containers 启用按天计算的 retention period
- **Enable soft delete for file shares**:为删除的 file shared 启用按天计算的 retention period
- **Enable versioning for blobs**保留 blobs 的先前版本
- **Enable blob change feed**:保留 blobs 的创建、修改和删除变更日志
- **Enable version-level immutability support**:允许在 account-level 设置基于时间的 retention policy,并将其应用于所有 blob versions
- **Point-in-time restore for containers**:允许将容器恢复到较早状态
- 此功能要求启用 versioning、change feed 和 blob soft delete。
- **Enable soft delete for blobs**:为删除的 blobs 设置以天为单位的保留期限(包括被覆盖的 blobs)。
- **Enable soft delete for containers**:为删除的容器设置以天为单位的保留期限。
- **Enable soft delete for file shares**:为删除的 file shares 设置以天为单位的保留期限。
- **Enable versioning for blobs**维护 blobs 的历史版本
- **Enable blob change feed**:保留 blobs 的创建、修改和删除变更日志
- **Enable version-level immutability support**:允许在 account-level 设置基于时间的保留策略,并将其应用于所有 blob 版本
- Version-level immutability support 和 point-in-time restore for containers 不能同时启用。
**加密配置选项**
- **Encryption type**:可以使用 Microsoft-managed keys (MMK) 或 Customer-managed keys (CMK)
- **Enable infrastructure encryption**:允许对数据进行双重加密,“for more security”
- **Encryption type**:可以使用 Microsoft-managed keysMMK或 Customer-managed keysCMK)。
- **Enable infrastructure encryption**:允许对数据进行双重加密,以实现“更高的安全性”。
### Storage endpoints
@@ -64,19 +64,19 @@ Azure Storage Accounts 是 Microsoft Azure 中的基础服务,提供可扩展
### Public Exposure
如果启用了 "Allow Blob public access"(默认禁用),创建 container 时可以:
如果启用了 **Allow Blob public access**(默认禁用),创建容器时可以:
- 赋予 **public access to read blobs**(你需要知道名称)。
- **List container blobs** 并读取它们。
- 设为完全 **private**
- 授予**公开读取 blobs 的权限**(需要知道名称)。
- **列出容器中的 blobs**并读取它们。
- 将其设置为完全**私有**
<figure><img src="https://lh7-rt.googleusercontent.com/slidesz/AGV_vUfoetUnYBPWQpRrWNnnlbqWpl8Rdoaeg5uBrCVlvcNDlnKwQHjZe8nUb2SfPspBgbu-lCZLmUei-hFi_Jl2eKbaxUtBGTjdUSDmkrcwr90VZkmuMjk9tyh92p75btfyzGiUTa0-=s2048?key=m8TV59TrCFPlkiNnmhYx3aZt" alt=""><figcaption></figcaption></figure>
### Static website (`$web`) exposure & leaked secrets
### Static website`$web`)暴露与泄露的 secrets
- **Static websites** are served from the special `$web` container over a region-specific endpoint such as `https://<account>.z13.web.core.windows.net/`.
- The `$web` container may report `publicAccess: null` via the blob API, but files are still reachable through the static site endpoint, so dropping config/IaC artifacts there can leak secrets.
- Quick audit workflow:
- **Static websites** 通过特殊的 `$web` 容器提供服务,其 endpoint 类似于 `https://<account>.z13.web.core.windows.net/`,并且与区域相关。
- `$web` 容器通过 blob API 可能会报告 `publicAccess: null`,但文件仍可通过 static site endpoint 访问,因此将 config/IaC artifacts 放置在那里可能会 leak secrets
- 快速审计流程:
```bash
# Identify storage accounts with static website hosting enabled
az storage blob service-properties show --account-name <acc-name> --auth-mode login
@@ -89,51 +89,51 @@ az storage blob download -c '$web' --name iac/terraform.tfvars --file /dev/stdou
```
### 审计 anonymous blob 暴露
- **Locate storage accounts** that can expose data: `az storage account list | jq -r '.[] | select(.properties.allowBlobPublicAccess==true) | .name'`. If `allowBlobPublicAccess` is `false` you cannot turn containers public.
- **Inspect risky accounts** to confirm the flag and other weak settings: `az storage account show --name <acc> --query '{allow:properties.allowBlobPublicAccess, minTls:properties.minimumTlsVersion}'`.
- **Enumerate container-level exposure** where the flag is enabled:
- **定位可能暴露数据的 storage accounts**`az storage account list | jq -r '.[] | select(.properties.allowBlobPublicAccess==true) | .name'`。如果 `allowBlobPublicAccess` `false`,则无法将 containers 设置为 public
- **检查存在风险的帐户**,确认该标志及其他较弱的设置:`az storage account show --name <acc> --query '{allow:properties.allowBlobPublicAccess, minTls:properties.minimumTlsVersion}'`
- **枚举已启用该标志的 container 级暴露**
```bash
az storage container list --account-name <acc> \
--query '[].{name:name, access:properties.publicAccess}'
```
- `"Blob"`: 匿名读取仅在 **已知 blob 名称** 时允许(不允许列)。
- `"Container"`: 匿名 **列出 + 读取** 每个 blob。
- `null`: 私有;需要证。
- **在没有凭据的情况下证明访问**
- 如果 `publicAccess` `Container`,匿名列表可用`curl "https://<acc>.blob.core.windows.net/<container>?restype=container&comp=list"`
- 对于 `Blob``Container`,当已知名称时,匿名 blob 下载可用
- `"Blob"`:仅当已知 blob 名称时允许匿名读取(不允许列)。
- `"Container"`:允许匿名**列出 + 读取**每个 blob。
- `null`私有;需要身份验证。
- **在凭据的情况下证明访问权限**
- 如果 `publicAccess` `Container`匿名列出有效`curl "https://<acc>.blob.core.windows.net/<container>?restype=container&comp=list"`
- 对于 `Blob``Container`,当已知名称时,匿名 blob 下载均有效
```bash
az storage blob download -c <container> -n <blob> --account-name <acc> --file /dev/stdout
# or via raw HTTP
curl "https://<acc>.blob.core.windows.net/<container>/<blob>"
```
### Connect to Storage
### 连接到 Storage
If you find any **storage** you can connect to you could use the tool [**Microsoft Azure Storage Explorer**](https://azure.microsoft.com/es-es/products/storage/storage-explorer/) to do so.
如果你发现任何可以连接的 **storage**,可以使用工具 [**Microsoft Azure Storage Explorer**](https://azure.microsoft.com/es-es/products/storage/storage-explorer/) 进行连接。
## Access to Storage <a href="#about-blob-storage" id="about-blob-storage"></a>
## 访问 Storage <a href="#about-blob-storage" id="about-blob-storage"></a>
### RBAC
可以使用 Entra ID principals 配合 **RBAC roles** 访问 storage accounts,这是推荐方式。
可以使用带有 **RBAC roles** 的 Entra ID principals 访问 storage accounts,这是推荐方式。
### Access Keys
storage accounts 有可用于访问的 access keys。这会提供对 storage account 的 f**ull access.**
storage accounts 有可用于访问的 access keys。这会提供对 storage account 的全**部访问权限**
<figure><img src="../../../images/image (5).png" alt=""><figcaption></figcaption></figure>
### **Shared Keys & Lite Shared Keys**
可以通过使用 access keys 签名生成 [**Shared Keys**](https://learn.microsoft.com/en-us/rest/api/storageservices/authorize-with-shared-key)借助 signed URL 授权访问某些资源。
可以使用 access keys [**generate Shared Keys**](https://learn.microsoft.com/en-us/rest/api/storageservices/authorize-with-shared-key)通过 signed URL 对其进行签名,从而授权访问特定资源。
> [!NOTE]
> 请注意,`CanonicalizedResource` 部分表示 storage services resource (URI)。如果 URL 中任何部分编码,那么它也应该在 `CanonicalizedResource` 中编码。
> 请注意,`CanonicalizedResource` 部分表示 storage services resourceURI。如果 URL 中任何部分经过编码,那么在 `CanonicalizedResource` 中也应进行编码。
> [!NOTE]
> 这是 **`az` cli 默认用于** 认证请求的方式。要让它使用 Entra ID principal credentials,请指定参数 `--auth-mode login`。
> 这是 **az cli** 默认用于对 requests 进行身份验证的方式。若要使其使用 Entra ID principal credentials,请指定参数 `--auth-mode login`。
- 可以通过对以下信息签名,生成一个用于 blobqueue file services **shared key**
- 可以通过对以下信息进行签名,**blob, queue and file services** 生成 **shared key**
```bash
StringToSign = VERB + "\n" +
Content-Encoding + "\n" +
@@ -150,7 +150,7 @@ Range + "\n" +
CanonicalizedHeaders +
CanonicalizedResource;
```
- 可以通过签名以下信息来生成一个 **shared key for table services**
- 可以通过以下信息进行签名来生成用于 table services 的 **shared key**
```bash
StringToSign = VERB + "\n" +
Content-MD5 + "\n" +
@@ -158,7 +158,7 @@ Content-Type + "\n" +
Date + "\n" +
CanonicalizedResource;
```
- 可以 blobqueue file services 生成一个 **lite shared key**,签名以下信息
- 可以通过对以下信息进行签名,生成 **lite shared key for blob, queue and file services**
```bash
StringToSign = VERB + "\n" +
Content-MD5 + "\n" +
@@ -167,7 +167,7 @@ Date + "\n" +
CanonicalizedHeaders +
CanonicalizedResource;
```
- 可以通过签名以下信息来生成一个 **lite shared key for table services**
- 可以通过以下信息进行签名,生成 **table services 的 lite shared key**
```bash
StringToSign = Date + "\n"
CanonicalizedResource
@@ -186,20 +186,20 @@ Content-Length: 0
```
### **Shared Access Signature** (SAS)
Shared Access Signatures (SAS) 是安全的、限时的 URL,用于**授予访问 Azure Storage account 中资源的特定权限**,而不会暴露 account 的 access keys。虽然 access keys 提供对所有资源的完管理访问权限, SAS 通过指定权限(如 read 或 write)并定义过期时间来实现细粒度控制
Shared Access Signatures (SAS) 是一种安全、有时间限制的 URL,可在不暴露 account access keys 的情况下,**授予 Azure Storage account 中资源的特定访问权限**access keys 提供对所有资源的完管理权限, SAS 则可通过指定权限(如 read 或 write)并定义过期时间来实现 granular control
#### SAS Types
- **User delegation SAS**: 这是从一个 **Entra ID principal** 创建的,由它来签名 SAS,并将权限从 user 委派给 SAS。它只能用于 **blob and data lake storage** ([docs](https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas))。可以**revoke** 所有生成的 user delegated SAS。
- 即使可以生成权限“更多”的 delegation SAS也仍然如此。然而,如果 principal 本身没有这些权限,它也不会工作(no privesc)。
- **Service SAS**: 这是使用 storage account 的某个 **access key** 签名。它可用于授予对单个 storage service 中特定资源的访问权限。如果 key 被续订SAS 将停止工作。
- **Account SAS**: 这同样用 storage account 的某个 **access key** 签名。它授予对 storage account 各项 servicesBlob、Queue、Table、File)中资源访问权限,并且可以包含 service-level 操作
- **User delegation SAS**:此 SAS 由 **Entra ID principal** 创建,该 principal 将对 SAS 进行签名,并将权限从 user 委派给 SAS。它只能 **blob and data lake storage** 一起使用([docs](https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas)。可以 **revoke** 所有生成的 user delegated SAS。
- 即使可以生成权限“更多”的 delegation SAS使其超出 user 所拥有的权限,但如果 principal 没有这些权限,该 SAS 也无法工作(no privesc)。
- **Service SAS**使用 storage account 的 **access keys** 之一进行签名。它可用于授予对单个 storage service 中特定资源的访问权限。如果 key 被 renouvelSAS 将停止工作。
- **Account SAS**同样使用 storage account 的 **access keys** 之一进行签名。它授予对 storage account 各项 servicesBlob、Queue、Table、File)中资源访问权限,并包含 service-level operations
一个**access key** 签名的 SAS URL 看起来像这样
**access key** 签名的 SAS URL 如下
- `https://<container_name>.blob.core.windows.net/newcontainer?sp=r&st=2021-09-26T18:15:21Z&se=2021-10-27T02:14:21Z&spr=https&sv=2021-07-08&sr=c&sig=7S%2BZySOgy4aA3Dk0V1cJyTSIf1cW%2Fu3WFkhHV32%2B4PE%3D`
一个**user delegation** 方式签名的 SAS URL 看起来像这样
**user delegation** 方式签名的 SAS URL 如下
- `https://<container_name>.blob.core.windows.net/testing-container?sp=r&st=2024-11-22T15:07:40Z&se=2024-11-22T23:07:40Z&skoid=d77c71a1-96e7-483d-bd51-bd753aa66e62&sktid=fdd066e1-ee37-49bc-b08f-d0e152119b04&skt=2024-11-22T15:07:40Z&ske=2024-11-22T23:07:40Z&sks=b&skv=2022-11-02&spr=https&sv=2022-11-02&sr=c&sig=7s5dJyeE6klUNRulUj9TNL0tMj2K7mtxyRc97xbYDqs%3D`
@@ -207,47 +207,47 @@ Shared Access Signatures (SAS) 是安全的、限时的 URL,用于**授予访
- **`se`** param 表示 SAS 的 **expiration date**
- **`sp`** param 表示 SAS 的 **permissions**
- **`sig`** 是验证 SAS 的 **signature**
- **`sig`** 是用于验证 SAS 的 **signature**
#### SAS permissions
生成 SAS 时,需要指定它应授予的权限。根据生成 SAS 的对象不同,可包含的权限也不同。例如:
生成 SAS 时,需要指定它应授予的 permissions。根据 SAS 所针对的对象,可包含不同的 permissions。例如:
- (a)dd, (c)reate, (d)elete, (e)xecute, (f)ilter_by_tags, (i)set_immutability_policy, (l)ist, (m)ove, (r)ead, (t)ag, (w)rite, (x)delete_previous_version, (y)permanent_delete
- (a)dd(c)reate(d)elete(e)xecute(f)ilter_by_tags(i)set_immutability_policy(l)ist(m)ove(r)ead(t)ag(w)rite(x)delete_previous_version(y)permanent_delete
## SFTP Support for Azure Blob Storage
Azure Blob Storage 现在支持 SSH File Transfer Protocol (SFTP),可直接对 Blob Storage 进行安全的文件传输和管理,而无需自定义方案或第三方产品
Azure Blob Storage 现在支持 SSH File Transfer Protocol (SFTP),可直接对 Blob Storage 进行安全的文件传输和管理,而不需要 custom solutions 或 third-party products
### Key Features
- Protocol Support: SFTP 用于配置了 hierarchical namespace (HNS) 的 Blob Storage accounts。会将 blobs 组织 directories 和 subdirectories,便于导航。
- Security: SFTP 可以使用 local user identities,也支持基于 Microsoft Entra ID 的访问,并结合 Azure RBAC 进行授权。这意味着可以使用常的 Blob Storage data-plane roles 授予访问权限,而不必创建本地 SFTP users。Local users 可以通过以下方式认证
- Protocol SupportSFTP 用于配置了 hierarchical namespace (HNS) 的 Blob Storage accounts。该功能会将 blobs 组织 directories 和 subdirectories 中,以便更轻松地进行导航。
- SecuritySFTP 可以使用 local user identities同时也支持基于 Microsoft Entra ID 的 access,并使用 Azure RBAC 进行 authorization。这意味着可以使用常的 Blob Storage data-plane roles 授予 access,而不必创建 local SFTP users。Local users 可以通过以下方式进行 authenticate
- Azure-generated passwords
- Public-private SSH key pairs
- Granular Permissions: 可以为 local users 分配 Read、Write、Delete 和 List 等权限,最多可作用于 100 个 containers。
- Networking Considerations: SFTP connections 通过 port 22 建立。Azure 支持 firewall、private endpoints 或 virtual networks 等网络配置来保护 SFTP traffic。
- Granular Permissions可以为 local users 分配 Read、Write、Delete 和 List 等 permissions,最多支持 100 个 containers。
- Networking ConsiderationsSFTP connections 通过 port 22 建立。Azure 支持 firewalls、private endpoints 或 virtual networks 等 network configurations,以保护 SFTP traffic。
### Setup Requirements
- Hierarchical Namespace: 创建 storage account 时必须启用 HNS。
- Supported Encryption: 需要 Microsoft Security Development Lifecycle (SDL) 批准的 cryptographic algorithms(例如 rsa-sha2-256、ecdsa-sha2-nistp256)。
- SFTP Configuration:
- Hierarchical Namespace创建 storage account 时必须启用 HNS。
- Supported Encryption需要 Microsoft Security Development Lifecycle (SDL) 批准的 cryptographic algorithms(例如 rsa-sha2-256、ecdsa-sha2-nistp256)。
- SFTP Configuration
- 在 storage account 上启用 SFTP。
- 对于 local-user access,创建具有适当权限的 local user identities。
- 对于 local users,配置 home directories,以定义其在 container 的起始位置。
- 对于 local-user access,创建具有适当 permissions 的 local user identities。
- 对于 local users,配置 home directories,以定义其在 container 的起始位置。
### Permissions
| Permission | Symbol | Description |
| ---------------------- | ------ | ------------------------------------ |
| **Read** | `r` | 读取文件内容。 |
| **Write** | `w` | 上传文件并创建目录。 |
| **List** | `l` | 列出目录内容。 |
| **Delete** | `d` | 删除文件或目录。 |
| **Create** | `c` | 创建文件或目录。 |
| **Modify Ownership** | `o` | 更改所有者用户或组。 |
| **Modify Permissions** | `p` | 更改文件或目录上的 ACLs。 |
| **Read** | `r` | Read file content。 |
| **Write** | `w` | Upload files and create directories。 |
| **List** | `l` | List contents of directories。 |
| **Delete** | `d` | Delete files or directories。 |
| **Create** | `c` | Create files or directories。 |
| **Modify Ownership** | `o` | Change the owning user or group。 |
| **Modify Permissions** | `p` | Change ACLs on files or directories。 |
## Enumeration
@@ -255,7 +255,7 @@ Azure Blob Storage 现在支持 SSH File Transfer Protocol (SFTP),可以直接
{{#tab name="az cli" }}
<details>
<summary>az cli enumeration</summary>
<summary>az cli 枚举</summary>
```bash
# Get storage accounts
az storage account list #Get the account name from here
@@ -442,31 +442,31 @@ New-AzStorageBlobSASToken `
{{#endtab }}
{{#endtabs }}
### File Shares
### 文件共享
{{#ref}}
az-file-shares.md
{{#endref}}
## Privilege Escalation
## 权限提升
{{#ref}}
../az-privilege-escalation/az-storage-privesc.md
{{#endref}}
## Post Exploitation
## 后渗透
{{#ref}}
../az-post-exploitation/az-blob-storage-post-exploitation.md
{{#endref}}
## Persistence
## 持久化
{{#ref}}
../az-persistence/az-storage-persistence.md
{{#endref}}
## References
## 参考资料
- [https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blobs-introduction](https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blobs-introduction)
- [https://learn.microsoft.com/en-us/azure/storage/common/storage-sas-overview](https://learn.microsoft.com/en-us/azure/storage/common/storage-sas-overview)