Breaking Managed Identity Barriers In Azure Services

  Рет қаралды 1,108

Black Hat

Black Hat

Күн бұрын

Identity management and authentication mechanisms together with authorization policies play a crucial role in systems security, especially when it comes to complex interdependent systems such as cloud services. One such service in Azure is Managed Identities. Managed Identities provide a universal interface for helping users to avoid storing credentials in code. Additionally, Managed Identities is used with various other Azure services. Hence, such services require special attention when it comes to service hardening while maintaining the same level of security. This also creates a need for stronger identity management to ensure secure access.
In this session, we present our findings from two Azure services, highlighting how we successfully bypassed the security mechanisms of Managed Identities. Attendees will gain insights into two novel approaches for maintaining persistence in Azure Functions and Azure Machine Learning service. Our investigation uncovered security gaps and design oversights within these services. These flaws allow attackers to impersonate assigned managed identities and allows for stealthy persistence in scenarios following a compromise. We managed to extract Managed Identity Entra ID token off the Azure resources to which these identities were allocated, undermining the fundamental principle of managed identities. Furthermore, the generated logs couldn't be used to differentiate between malicious and legitimate requests, rendering the stealthy persistence in Azure Machine Learning service undetectable.
By:
Nitesh Surana | Senior Threat Researcher, Trend Micro
David Fiser | Senior Threat Researcher, Trend Micro
Full Abstract & Presentation Materials:
www.blackhat.c...

Пікірлер
Bad Randomness: Protecting Against Cryptography's Perfect Crime
39:00
REAL or FAKE? #beatbox #tiktok
01:03
BeatboxJCOP
Рет қаралды 18 МЛН
Beat Ronaldo, Win $1,000,000
22:45
MrBeast
Рет қаралды 158 МЛН
When you have a very capricious child 😂😘👍
00:16
Like Asiya
Рет қаралды 18 МЛН
IAM The One Who Knocks
40:58
Black Hat
Рет қаралды 8 М.
The Dream That Turn Into a Nightmare
1:03:18
JSTalks
Рет қаралды 65
Microsoft Azure Managed Identity Deep Dive
48:40
John Savill's Technical Training
Рет қаралды 94 М.
Compromising Confidential Compute, One Bug at a Time
35:32
State of GPT | BRK216HFS
42:40
Microsoft Developer
Рет қаралды 695 М.
System Assigned vs User Assigned Managed Identity Explained
12:03
Meet Kamal Today - Cloud Mastery
Рет қаралды 10 М.
REAL or FAKE? #beatbox #tiktok
01:03
BeatboxJCOP
Рет қаралды 18 МЛН