BingBang: Hacking Bing.com (and much more) with Azure Active Directory

  Рет қаралды 4,318

Black Hat

Black Hat

Күн бұрын

In cloud-managed environments, exposing one of your most sensitive assets to external attackers can be as simple as clicking a checkbox. This was the case for Bing.com with their Azure Active Directory (AAD) integration, where a single misconfiguration enabled us to bypass authentication, alter search results, and launch XSS attacks on its users stealing their Office 365 tokens. However, Bing was not an isolated case. By inventing a new scanning technique to remotely map AAD misconfigurations, we identified thousands of exposed applications across the internet.
In this talk, we will present our novel technique for hunting misconfigurations on Azure AD, one of the most common Identity Providers on the internet....
By: Hillai Ben-Sasson
Full Abstract and Presentation Materials: www.blackhat.c...

Пікірлер
Something Rotten in the State of Data Centers
40:27
Black Hat
Рет қаралды 9 М.
An Unknown Ending💪
00:49
ISSEI / いっせい
Рет қаралды 57 МЛН
🍉😋 #shorts
00:24
Денис Кукояка
Рет қаралды 3,6 МЛН
Will A Guitar Boat Hold My Weight?
00:20
MrBeast
Рет қаралды 261 МЛН
Hacking with Bloodhound: Map Your Environment
39:25
John Hammond
Рет қаралды 68 М.
Breaking Bitlocker - Bypassing the Windows Disk Encryption
9:11
stacksmashing
Рет қаралды 969 М.
Phishing 2.0 - Detecting Evilginx, EvilnoVNC, Muraena and Modlishka
46:05
How to Listen to Phone Calls in Wireshark
7:30
Plaintext Packets
Рет қаралды 154 М.
Compromising LLMs: The Advent of AI Malware
36:29
Black Hat
Рет қаралды 7 М.
Three New Attacks Against JSON Web Tokens
40:18
Black Hat
Рет қаралды 6 М.
An Unknown Ending💪
00:49
ISSEI / いっせい
Рет қаралды 57 МЛН