Christian Bortone

16 posts

Christian Bortone banner
Christian Bortone

Christian Bortone

@xybytes

Prague, Czech Republic 参加日 Şubat 2019
108 フォロー中181 フォロワー
Christian Bortone
Christian Bortone@xybytes·
@ppetryszen Unfortunately, the only way to verify these roles is to review them one by one. The role names are misleading, and the documentation is not reliable here because Microsoft does not provide clear information for this case. There are likely many others like this...
English
0
0
1
34
Christian Bortone
Christian Bortone@xybytes·
Just published new research on Azure File Sync. I found that the built-in Azure File Sync Administrator role can grant more power than expected, opening a path to privilege escalation and sensitive file access. xybytes.com/azure/Abusing-…
English
1
18
33
3.1K
Christian Bortone
Christian Bortone@xybytes·
Weak ACLs in AD and misconfigured dynamic groups in Azure AD are not new vulnerabilities. But when they intersect in a hybrid environment, they create a powerful, and often overlooked, attack path. You can read here my article. 🫡 lnkd.in/d9AMzdj7
English
0
0
2
76
Christian Bortone
Christian Bortone@xybytes·
@G0ldenGunSec Excellent article. Just a quick note . The GPO abuse in Azure Arc (DPAPI + decoded secrets) was originally discovered by me about two years ago. I’d appreciate it if you could link to the original article for that specific section. xybytes.com/azure/Abusing-…
English
0
2
4
206
Dave Cossa
Dave Cossa@G0ldenGunSec·
Azure Arc is Microsoft's solution for managing on-premises systems in hybrid environments. My new blog covers how it can it be identified in an enterprise and misconfigurations that could allow it to be used for out-of-band execution and persistence. ibm.com/think/x-force/…
English
7
82
187
24.1K
Christian Bortone
Christian Bortone@xybytes·
I was at @BSidesZagreb last week. I gave a talk on Privilege Escalation in Azure Machine Learning. If you're interested, check out this article on the topic. Plus, there are two scripts in MicroBuster that you can use for enumeration. 🙂 xybytes.com/azure/Privileg…
Christian Bortone tweet media
English
0
0
0
94
Christian Bortone
Christian Bortone@xybytes·
In my latest research article, I take a close look at the weaknesses within Azure Application Proxy, demonstrating how impersonating the connector can enable traffic hijacking from outside the infrastructure. xybytes.com/azure/Azure-Ap…
Christian Bortone tweet media
English
0
6
13
816
Christian Bortone
Christian Bortone@xybytes·
During my exploration of Azure Arc, I noticed that the Azure Arc Management Tool can be used to coerce NTLM authentication. The interesting part is that all the other options require local administrator permissions—except for this one. 🤔 lnkd.in/degfdcQF
Christian Bortone tweet mediaChristian Bortone tweet media
English
0
9
27
4.4K
Fabian Bader
Fabian Bader@fabian_bader·
@kfosaaen I have to double check but to run a command you would need Microsoft.HybridCompute/machines/runCommands/write which is not available to this role.
English
6
0
1
278
Karl
Karl@kfosaaen·
Assuming I'm reading this one correctly, this one is a pretty big deal. Continuing my take on it in a thread, but read the blog from @xybytes here: xybytes.com/azure/Abusing-…
English
1
29
79
9K
Christian Bortone
Christian Bortone@xybytes·
@fabian_bader @kfosaaen While I'm not sure how common this is in real-world environments, it's possible, especially considering that many system administrators may not be very familiar with Azure Arc. Therefore, the impact depends on the RBAC assigned to that SP.
English
0
0
2
36
Christian Bortone
Christian Bortone@xybytes·
@fabian_bader @kfosaaen This situation highlights a scenario where a system administrator might use a single SP for all tasks, including managing Azure and onboarding new machines.
English
0
0
1
31
Christian Bortone
Christian Bortone@xybytes·
@fabian_bader @kfosaaen Yes, that’s correct. If you only have the onboarding role, you can only add new machines to Azure Arc. With the Azure Connected Machine Resource Administrator role, you have full control.
English
1
0
2
33
Christian Bortone がリツイート
🅾️sservaMy👁️☮️🌈👠
Praticamente è il motivo, oggi, su cui si fonda la "non cultura". Quanto mi manchi, quanto mi mancano le tue parole ♥️ #MichelaMurgia
Italiano
26
394
1.9K
70.7K
Christian Bortone
Christian Bortone@xybytes·
I am excited to announce that I will be presenting a new attack technique in Azure Arc that I discovered, at BSides Leeds. In this talk, I will discuss a recent security flaw that enables bad actors within a corporate environment to gain control over a service principal account.
Christian Bortone tweet media
English
0
0
3
257
Intigriti
Intigriti@intigriti·
What's the most underrated vulnerability?
English
53
8
107
47.8K
Christian Bortone
Christian Bortone@xybytes·
To all my fellow pen testing buddies out there, this meme is dedicated to the unlucky soul who started an engagement, only to face a server that took a 24-hour nap or developers who removed functionality from the web app to avoid being tested. It can be f…lnkd.in/er47BDZy
English
0
0
1
177