From ca0d89b0a9be142bc707f669e43838133eaa7b56 Mon Sep 17 00:00:00 2001 From: Translator Date: Thu, 9 Jul 2026 16:57:47 +0000 Subject: [PATCH] Translated ['', 'src/pentesting-cloud/azure-security/az-services/az-stor --- .../azure-security/az-services/az-storage.md | 139 +++++++++--------- 1 file changed, 70 insertions(+), 69 deletions(-) diff --git a/src/pentesting-cloud/azure-security/az-services/az-storage.md b/src/pentesting-cloud/azure-security/az-services/az-storage.md index 8283f3aef..1961d48f1 100644 --- a/src/pentesting-cloud/azure-security/az-services/az-storage.md +++ b/src/pentesting-cloud/azure-security/az-services/az-storage.md @@ -4,22 +4,22 @@ ## Basic Information -Azure Storage Accounts Microsoft Azure में मौलिक services हैं जो scalable, secure, और highly available cloud **storage for various data types** प्रदान करती हैं, including blobs (binary large objects), files, queues, and tables. ये containers की तरह काम करती हैं जो इन अलग-अलग storage services को आसान management के लिए एक single namespace के तहत group करती हैं। +Azure Storage Accounts Microsoft Azure की fundamental services हैं जो scalable, secure, और highly available cloud **storage for various data types** प्रदान करती हैं, जिसमें blobs (binary large objects), files, queues, और tables शामिल हैं। ये containers की तरह काम करती हैं जो इन अलग-अलग storage services को आसान management के लिए single namespace के तहत group करती हैं। **Main configuration options**: -- हर storage account का नाम **uniq** होना चाहिए across all Azure. -- हर storage account एक **region** में या Azure extended zone में deployed होता है -- बेहतर performance के लिए storage account का **premium** version चुनना संभव है -- rack, drive और datacenter **failures** से protection के लिए **4 types of redundancy** में से चुनना संभव है। +- Every storage account must have a **uniq name across all Azure**. +- Every storage account is deployed in a **region** or in an Azure extended zone +- It's possible to select the **premium** version of the storage account for better performance +- It's possible to select among **4 types of redundancy to protect** against rack, drive and datacenter **failures**. **Security configuration options**: -- **Require secure transfer for REST API operations**: storage के साथ किसी भी communication में TLS की आवश्यकता -- **Allows enabling anonymous access on individual containers**: अगर नहीं, तो भविष्य में anonymous access enable करना संभव नहीं होगा -- **Enable storage account key access**: अगर नहीं, तो Shared Keys के साथ access forbidden होगा +- **Require secure transfer for REST API operations**: Storage के साथ किसी भी communication में TLS की आवश्यकता +- **Allows enabling anonymous access on individual containers**: If not, it won't be possible to enable anonymous access in the future +- **Enable storage account key access**: If not, access with Shared Keys will be forbidden - **Minimum TLS version** -- **Permitted scope for copy operations**: किसी भी storage account से अनुमति दें, same Entra tenant के किसी भी storage account से, या same virtual network में private endpoints वाले storage account से अनुमति दें। +- **Permitted scope for copy operations**: किसी भी storage account से allow करें, same Entra tenant के किसी भी storage account से, या same virtual network में private endpoints वाले storage account से। **Blob Storage options**: @@ -29,26 +29,26 @@ Azure Storage Accounts Microsoft Azure में मौलिक services है **Networking options**: - **Network access**: -- All networks से अनुमति दें -- Selected virtual networks और IP addresses से अनुमति दें -- Public access disable करें और private access use करें +- Allow from all networks +- Allow from selected virtual networks and IP addresses +- Disable public access and use private access - **Private endpoints**: यह virtual network से storage account तक private connection allow करता है **Data protection options**: -- **Point-in-time restore for containers**: containers को earlier state में restore करने की अनुमति देता है -- इसके लिए versioning, change feed, और blob soft delete enabled होना required है। -- **Enable soft delete for blobs**: deleted blobs (overwritten भी) के लिए days में retention period enable करता है -- **Enable soft delete for containers**: deleted containers के लिए days में retention period enable करता है -- **Enable soft delete for file shares**: deleted file shared के लिए days में retention period enable करता है -- **Enable versioning for blobs**: आपके blobs के previous versions maintain करता है +- **Point-in-time restore for containers**: containers को पहले की state में restore करने की अनुमति देता है +- It requires versioning, change feed, and blob soft delete to be enabled. +- **Enable soft delete for blobs**: deleted blobs (even overwritten) के लिए दिनों में retention period enable करता है +- **Enable soft delete for containers**: deleted containers के लिए दिनों में retention period enable करता है +- **Enable soft delete for file shares**: deleted file shared के लिए दिनों में retention period enable करता है +- **Enable versioning for blobs**: अपने blobs के previous versions बनाए रखता है - **Enable blob change feed**: blobs में create, modification, और delete changes के logs रखता है -- **Enable version-level immutability support**: आपको account-level पर time-based retention policy set करने की अनुमति देता है जो सभी blob versions पर apply होगी। -- Version-level immutability support और point-in-time restore for containers को एक साथ enabled नहीं किया जा सकता। +- **Enable version-level immutability support**: आपको account-level पर time-based retention policy set करने देता है जो सभी blob versions पर apply होगी। +- Version-level immutability support and point-in-time restore for containers cannot be enabled simultaneously. **Encryption configuration options**: -- **Encryption type**: Microsoft-managed keys (MMK) या Customer-managed keys (CMK) use करना संभव है +- **Encryption type**: Microsoft-managed keys (MMK) या Customer-managed keys (CMK) का उपयोग करना possible है - **Enable infrastructure encryption**: data को "for more security" double encrypt करने की अनुमति देता है ### Storage endpoints @@ -64,18 +64,18 @@ Azure Storage Accounts Microsoft Azure में मौलिक services है ### Public Exposure -अगर "Allow Blob public access" **enabled** है (by default disabled), तो container बनाते समय यह संभव है कि: +If "Allow Blob public access" is **enabled** (disabled by default), when creating a container it's possible to: -- blobs को पढ़ने के लिए **public access** दें (आपको name जानना होगा). -- container blobs को **List** करें और उन्हें **read** करें। -- इसे पूरी तरह **private** बनाएं +- Give **public access to read blobs** (you need to know the name). +- **List container blobs** and **read** them. +- Make it fully **private**
### Static website (`$web`) exposure & leaked secrets -- **Static websites** special `$web` container से region-specific endpoint जैसे `https://.z13.web.core.windows.net/` के through served होते हैं। -- `$web` container blob API के जरिए `publicAccess: null` report कर सकता है, लेकिन files अभी भी static site endpoint के through reachable रहती हैं, इसलिए वहाँ config/IaC artifacts डालने से secrets leak हो सकते हैं। +- **Static websites** are served from the special `$web` container over a region-specific endpoint such as `https://.z13.web.core.windows.net/`. +- The `$web` container may report `publicAccess: null` via the blob API, but files are still reachable through the static site endpoint, so dropping config/IaC artifacts there can leak secrets. - Quick audit workflow: ```bash # Identify storage accounts with static website hosting enabled @@ -87,7 +87,7 @@ az storage blob list --container-name '$web' --account-name --auth-mo # Pull suspicious files directly (e.g., IaC tfvars containing secrets/SAS) az storage blob download -c '$web' --name iac/terraform.tfvars --file /dev/stdout --account-name --auth-mode login ``` -### anonymous blob exposure का Auditing +### गुमनाम blob exposure का auditing - **storage accounts को locate करें** जो data expose कर सकते हैं: `az storage account list | jq -r '.[] | select(.properties.allowBlobPublicAccess==true) | .name'`. अगर `allowBlobPublicAccess` `false` है, तो आप containers को public नहीं बना सकते। - **risky accounts का inspect करें** ताकि flag और अन्य weak settings confirm हों: `az storage account show --name --query '{allow:properties.allowBlobPublicAccess, minTls:properties.minimumTlsVersion}'`. @@ -96,44 +96,44 @@ az storage blob download -c '$web' --name iac/terraform.tfvars --file /dev/stdou az storage container list --account-name \ --query '[].{name:name, access:properties.publicAccess}' ``` -- `"Blob"`: anonymous reads allowed **केवल तब जब blob name ज्ञात हो** (कोई listing नहीं)। -- `"Container"`: anonymous **list + read** हर blob का। +- `"Blob"`: anonymous reads allowed **only when blob name is known** (no listing). +- `"Container"`: anonymous **list + read** of every blob. - `null`: private; authentication required. -- **बिना credentials access साबित करें**: -- यदि `publicAccess` `Container` है, तो anonymous listing काम करती है: `curl "https://.blob.core.windows.net/?restype=container&comp=list"`. -- `Blob` और `Container` दोनों के लिए, जब name ज्ञात हो, anonymous blob download काम करता है: +- **Prove access** without credentials: +- If `publicAccess` is `Container`, anonymous listing works: `curl "https://.blob.core.windows.net/?restype=container&comp=list"`. +- For both `Blob` and `Container`, anonymous blob download works when the name is known: ```bash az storage blob download -c -n --account-name --file /dev/stdout # or via raw HTTP curl "https://.blob.core.windows.net//" ``` -### Connect to Storage +### Storage से Connect करें -अगर आप कोई **storage** पाते हैं जिससे आप connect कर सकते हैं, तो आप ऐसा करने के लिए [**Microsoft Azure Storage Explorer**](https://azure.microsoft.com/es-es/products/storage/storage-explorer/) tool का उपयोग कर सकते हैं। +अगर आपको कोई **storage** मिलता है जिससे आप connect कर सकते हैं, तो आप ऐसा करने के लिए [**Microsoft Azure Storage Explorer**](https://azure.microsoft.com/es-es/products/storage/storage-explorer/) tool का उपयोग कर सकते हैं। -## Access to Storage +## Storage तक Access ### RBAC -storage accounts तक पहुंचने के लिए **RBAC roles** के साथ Entra ID principals का उपयोग करना संभव है, और यही recommended तरीका है। +Storage accounts तक access के लिए **RBAC roles** के साथ Entra ID principals का उपयोग किया जा सकता है, और यही recommended तरीका है। ### Access Keys -storage accounts के पास access keys होती हैं जिनका उपयोग उन्हें access करने के लिए किया जा सकता है। इससे storage account पर f**ull access** मिलता है। +Storage accounts में access keys होती हैं जिनका उपयोग करके उन्हें access किया जा सकता है। यह storage account तक f**ull access** प्रदान करता है।
### **Shared Keys & Lite Shared Keys** -किसी signed URL के माध्यम से कुछ resources तक access authorize करने के लिए access keys से signed **Shared Keys** [**generate**](https://learn.microsoft.com/en-us/rest/api/storageservices/authorize-with-shared-key) करना संभव है। +Signed URL के जरिए कुछ resources तक access authorize करने के लिए access keys के साथ signed [**Shared Keys**](https://learn.microsoft.com/en-us/rest/api/storageservices/authorize-with-shared-key) generate करना संभव है। > [!NOTE] -> ध्यान दें कि `CanonicalizedResource` भाग storage services resource (URI) को दर्शाता है। और अगर URL का कोई भी भाग encoded है, तो उसे `CanonicalizedResource` के अंदर भी encoded होना चाहिए। +> ध्यान दें कि `CanonicalizedResource` part storage services resource (URI) को दर्शाता है। और अगर URL का कोई भी भाग encoded है, तो उसे `CanonicalizedResource` के अंदर भी encoded होना चाहिए। > [!NOTE] -> यह requests authenticate करने के लिए डिफ़ॉल्ट रूप से **`az` cli द्वारा उपयोग किया जाता है**। इसे Entra ID principal credentials उपयोग करने के लिए `--auth-mode login` param निर्दिष्ट करें। +> यह requests को authenticate करने के लिए by default **`az` cli** द्वारा उपयोग किया जाता है। इसे Entra ID principal credentials का उपयोग करवाने के लिए `--auth-mode login` param बताएं। -- निम्न जानकारी को sign करके **blob, queue और file services** के लिए एक **shared key** generate करना संभव है: +- निम्न जानकारी को sign करके blob, queue और file services के लिए **shared key** generate करना संभव है: ```bash StringToSign = VERB + "\n" + Content-Encoding + "\n" + @@ -150,7 +150,7 @@ Range + "\n" + CanonicalizedHeaders + CanonicalizedResource; ``` -- निम्नलिखित जानकारी पर हस्ताक्षर करके **table services के लिए shared key** जनरेट करना संभव है: +- निम्नलिखित जानकारी को sign करके **table services के लिए एक shared key** generate करना संभव है: ```bash StringToSign = VERB + "\n" + Content-MD5 + "\n" + @@ -158,7 +158,7 @@ Content-Type + "\n" + Date + "\n" + CanonicalizedResource; ``` -- निम्नलिखित जानकारी पर हस्ताक्षर करके **blob, queue और file services** के लिए एक **lite shared key** जनरेट करना संभव है: +- blob, queue और file services के लिए **lite shared key** जनरेट करना संभव है, निम्न जानकारी पर sign करके: ```bash StringToSign = VERB + "\n" + Content-MD5 + "\n" + @@ -167,12 +167,12 @@ Date + "\n" + CanonicalizedHeaders + CanonicalizedResource; ``` -- निम्नलिखित जानकारी को sign करके **lite shared key for table services** generate करना संभव है: +- निम्नलिखित जानकारी पर sign करके **table services** के लिए एक **lite shared key** generate करना संभव है: ```bash StringToSign = Date + "\n" CanonicalizedResource ``` -फिर, key का उपयोग करने के लिए, इसे Authorization header में निम्न syntax का पालन करते हुए किया जा सकता है: +फिर, key का उपयोग करने के लिए, इसे Authorization header में निम्न syntax के अनुसार किया जा सकता है: ```bash Authorization="[SharedKey|SharedKeyLite] :" #e.g. @@ -186,68 +186,68 @@ Content-Length: 0 ``` ### **Shared Access Signature** (SAS) -Shared Access Signatures (SAS) ऐसे secure, time-limited URLs हैं जो Azure Storage account में resource**s** तक access के लिए specific permissions **grant करते हैं** बिना account's access keys को expose किए। जबकि access keys सभी resources पर full administrative access देते हैं, SAS permissions (जैसे read या write) specify करके और expiration time define करके granular control देता है। +Shared Access Signatures (SAS) हैं secure, time-limited URLs जो Azure Storage account में resource**s** तक access देने के लिए विशिष्ट permissions **grant** करते हैं, बिना account's access keys को expose किए। जबकि access keys सभी resources तक full administrative access देते हैं, SAS permissions (जैसे read या write) specify करके और expiration time define करके granular control allow करता है। #### SAS Types -- **User delegation SAS**: यह एक **Entra ID principal** से बनाया जाता है जो SAS को sign करेगा और permissions को user से SAS तक delegate करेगा। इसे केवल **blob and data lake storage** के साथ उपयोग किया जा सकता है ([docs](https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas)). सभी generated user delegated SAS को **revoke** करना possible है। -- भले ही delegation SAS को user के पास मौजूद permissions से "ज्यादा" permissions के साथ generate करना possible हो। हालांकि, अगर principal के पास वे permissions नहीं हैं, तो यह work नहीं करेगा (no privesc)। -- **Service SAS**: यह storage account **access keys** में से एक का उपयोग करके sign किया जाता है। इसे single storage service में specific resources तक access grant करने के लिए उपयोग किया जा सकता है। अगर key renew की जाती है, तो SAS काम करना बंद कर देगा। -- **Account SAS**: इसे भी storage account **access keys** में से एक के साथ sign किया जाता है। यह storage account services (Blob, Queue, Table, File) across resources तक access grant करता है और service-level operations शामिल कर सकता है। +- **User delegation SAS**: यह एक **Entra ID principal** से बनाया जाता है जो SAS को sign करेगा और user से SAS तक permissions delegate करेगा। इसे केवल **blob and data lake storage** के साथ उपयोग किया जा सकता है ([docs](https://learn.microsoft.com/en-us/rest/api/storageservices/create-user-delegation-sas))। सभी generated user delegated SAS को **revoke** करना possible है। +- भले ही "more" permissions के साथ delegation SAS generate करना possible हो, जो user के पास हैं उनसे ज़्यादा। हालांकि, अगर principal के पास वे permissions नहीं हैं, तो यह काम नहीं करेगा (no privesc)। +- **Service SAS**: यह storage account **access keys** में से किसी एक का उपयोग करके signed होता है। इसका उपयोग एक single storage service में specific resources तक access grant करने के लिए किया जा सकता है। अगर key renewed हो जाए, तो SAS काम करना बंद कर देगा। +- **Account SAS**: यह भी storage account **access keys** में से किसी एक के साथ signed होता है। यह storage account services (Blob, Queue, Table, File) के across resources तक access देता है और service-level operations शामिल कर सकता है। -एक **access key** से sign किया गया SAS URL कुछ ऐसा दिखता है: +एक **access key** द्वारा signed SAS URL कुछ इस तरह दिखता है: - `https://.blob.core.windows.net/newcontainer?sp=r&st=2021-09-26T18:15:21Z&se=2021-10-27T02:14:21Z&spr=https&sv=2021-07-08&sr=c&sig=7S%2BZySOgy4aA3Dk0V1cJyTSIf1cW%2Fu3WFkhHV32%2B4PE%3D` -एक **user delegation** के रूप में sign किया गया SAS URL कुछ ऐसा दिखता है: +एक **user delegation** के रूप में signed SAS URL कुछ इस तरह दिखता है: - `https://.blob.core.windows.net/testing-container?sp=r&st=2024-11-22T15:07:40Z&se=2024-11-22T23:07:40Z&skoid=d77c71a1-96e7-483d-bd51-bd753aa66e62&sktid=fdd066e1-ee37-49bc-b08f-d0e152119b04&skt=2024-11-22T15:07:40Z&ske=2024-11-22T23:07:40Z&sks=b&skv=2022-11-02&spr=https&sv=2022-11-02&sr=c&sig=7s5dJyeE6klUNRulUj9TNL0tMj2K7mtxyRc97xbYDqs%3D` -कुछ **http params** नोट करें: +कुछ **http params** ध्यान दें: - **`se`** param SAS की **expiration date** indicate करता है - **`sp`** param SAS की **permissions** indicate करता है -- **`sig`** SAS को validate करने वाला **signature** है +- **`sig`** SAS को validate करने वाली **signature** है #### SAS permissions -SAS generate करते समय यह indicate करना जरूरी है कि वह कौन-सी permissions grant करेगा। जिस object पर SAS generate किया जा रहा है, उसके आधार पर अलग-अलग permissions शामिल की जा सकती हैं। उदाहरण के लिए: +SAS generate करते समय यह indicate करना ज़रूरी है कि वह कौन-सी permissions grant करेगा। जिस objet पर SAS generate किया जा रहा है, उसके अनुसार अलग-अलग permissions शामिल हो सकती हैं। उदाहरण के लिए: - (a)dd, (c)reate, (d)elete, (e)xecute, (f)ilter_by_tags, (i)set_immutability_policy, (l)ist, (m)ove, (r)ead, (t)ag, (w)rite, (x)delete_previous_version, (y)permanent_delete ## SFTP Support for Azure Blob Storage -Azure Blob Storage अब SSH File Transfer Protocol (SFTP) को support करता है, जिससे custom solutions या third-party products की जरूरत बिना सीधे Blob Storage पर secure file transfer और management possible हो जाता है। +Azure Blob Storage अब SSH File Transfer Protocol (SFTP) support करता है, जिससे custom solutions या third-party products की आवश्यकता बिना सीधे Blob Storage पर secure file transfer और management संभव हो जाता है। ### Key Features - Protocol Support: SFTP, hierarchical namespace (HNS) के साथ configured Blob Storage accounts पर काम करता है। यह blobs को directories और subdirectories में organize करता है ताकि navigation आसान हो। -- Security: SFTP authentication के लिए local user identities का उपयोग करता है और RBAC या ABAC के साथ integrate नहीं करता। हर local user authenticate कर सकता है via: +- Security: SFTP local user identities का उपयोग कर सकता है, लेकिन authorization के लिए Azure RBAC के साथ Microsoft Entra ID-based access भी support करता है। इसका मतलब है कि local SFTP users बनाने के बजाय सामान्य Blob Storage data-plane roles से access grant किया जा सकता है। Local users authenticate कर सकते हैं via: - Azure-generated passwords - Public-private SSH key pairs - Granular Permissions: Read, Write, Delete, और List जैसी permissions local users को up to 100 containers के लिए assign की जा सकती हैं। -- Networking Considerations: SFTP connections port 22 के through बनाई जाती हैं। Azure network configurations जैसे firewalls, private endpoints, या virtual networks को support करता है ताकि SFTP traffic secure रहे। +- Networking Considerations: SFTP connections port 22 के through बनाई जाती हैं। Azure SFTP traffic को secure करने के लिए firewalls, private endpoints, या virtual networks जैसी network configurations support करता है। ### Setup Requirements - Hierarchical Namespace: storage account बनाते समय HNS enabled होना चाहिए। -- Supported Encryption: Microsoft Security Development Lifecycle (SDL)-approved cryptographic algorithms (e.g., rsa-sha2-256, ecdsa-sha2-nistp256) की जरूरत होती है। +- Supported Encryption: Microsoft Security Development Lifecycle (SDL)-approved cryptographic algorithms (e.g., rsa-sha2-256, ecdsa-sha2-nistp256) की आवश्यकता होती है। - SFTP Configuration: - storage account पर SFTP enable करें। -- उचित permissions के साथ local user identities बनाएं। -- users के लिए home directories configure करें ताकि container के भीतर उनकी starting location define हो सके। +- local-user access के लिए, उचित permissions के साथ local user identities create करें। +- local users के लिए, home directories configure करें ताकि container के भीतर उनकी starting location define हो सके। ### Permissions | Permission | Symbol | Description | | ---------------------- | ------ | ------------------------------------ | -| **Read** | `r` | File content पढ़ें। | -| **Write** | `w` | Files upload करें और directories बनाएं। | -| **List** | `l` | Directories की contents list करें। | -| **Delete** | `d` | Files या directories delete करें। | -| **Create** | `c` | Files या directories create करें। | -| **Modify Ownership** | `o` | Owning user या group बदलें। | -| **Modify Permissions** | `p` | Files या directories पर ACLs बदलें। | +| **Read** | `r` | Read file content. | +| **Write** | `w` | Upload files and create directories. | +| **List** | `l` | List contents of directories. | +| **Delete** | `d` | Delete files or directories. | +| **Create** | `c` | Create files or directories. | +| **Modify Ownership** | `o` | Change the owning user or group. | +| **Modify Permissions** | `p` | Change ACLs on files or directories. | ## Enumeration @@ -471,6 +471,7 @@ az-file-shares.md - [https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blobs-introduction](https://learn.microsoft.com/en-us/azure/storage/blobs/storage-blobs-introduction) - [https://learn.microsoft.com/en-us/azure/storage/common/storage-sas-overview](https://learn.microsoft.com/en-us/azure/storage/common/storage-sas-overview) - [https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support](https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support) +- [https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support-entra-id-based-access](https://learn.microsoft.com/en-us/azure/storage/blobs/secure-file-transfer-protocol-support-entra-id-based-access) - [Holiday Hack Challenge 2025 – Spare Key (Azure static website SAS leak)](https://0xdf.gitlab.io/holidayhack2025/act1/spare-key) - [Holiday Hack Challenge 2025: Blob Storage (Storage Secrets)](https://0xdf.gitlab.io/holidayhack2025/act1/blob-storage) - [https://learn.microsoft.com/en-us/cli/azure/storage/account](https://learn.microsoft.com/en-us/cli/azure/storage/account)