BingBang: Hacking Bing.com (and much more) with Azure Active Directory

  Рет қаралды 3,965

Black Hat

Black Hat

Күн бұрын

In cloud-managed environments, exposing one of your most sensitive assets to external attackers can be as simple as clicking a checkbox. This was the case for Bing.com with their Azure Active Directory (AAD) integration, where a single misconfiguration enabled us to bypass authentication, alter search results, and launch XSS attacks on its users stealing their Office 365 tokens. However, Bing was not an isolated case. By inventing a new scanning technique to remotely map AAD misconfigurations, we identified thousands of exposed applications across the internet.
In this talk, we will present our novel technique for hunting misconfigurations on Azure AD, one of the most common Identity Providers on the internet....
By: Hillai Ben-Sasson
Full Abstract and Presentation Materials: www.blackhat.com/us-23/briefi...

Пікірлер
Off The Record - Weaponizing DHCP DNS Dynamic Updates
39:50
Black Hat
Рет қаралды 1,8 М.
когда повзрослела // EVA mash
00:40
EVA mash
Рет қаралды 3,7 МЛН
Three New Attacks Against JSON Web Tokens
40:18
Black Hat
Рет қаралды 5 М.
A Hacker Shares His Biggest Fears | Informer
6:19
VICE
Рет қаралды 3,1 МЛН
The Black Hat Europe Network Operations Center (NOC) Report
38:03
Breaking Managed Data Services in the Cloud
39:34
Black Hat
Рет қаралды 2,1 М.
7 HIDDEN Apps in Microsoft 365 that will EXPLODE Productivity
28:35
Jonathan Edwards
Рет қаралды 156 М.
mTLS: When Certificate Authentication is Done Wrong
22:14
Black Hat
Рет қаралды 1,3 М.