Document validated Azure high-impact permission abuse - #375
Open
carlospolop wants to merge 13 commits into
Open
Conversation
…ion-risk-evidence-20260907
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Documentation structure
Existing Entra ID, Conditional Access, API Management, Automation, Batch, Container Apps, Container Registry, Functions, Key Vault, Service Bus, Static Web Apps, Storage, and VM pages are extended in place. Services that had no privilege-escalation page receive narrowly scoped ARM Deployment, App Configuration, Communication Services, Data Factory, Event Grid, Event Hubs, IoT Hub, Kubernetes, Log Analytics, Notification Hubs, Redis, Relay, and SignalR/Web PubSub pages, all registered in
SUMMARY.md. There is no catch-all high-impact-permissions page.Live validation
Validated in an authorized Azure subscription with disposable entities/resources:
readonlykeys/actionand GET-backedreadonlykeys/readreturned account-wide read-only master keys that read a seeded document; a write attempt with the key was rejectedpipelines/createRun/actionstarted a stored pipeline, which invoked the signed Logic workflow and returned its canaryprovisioningserviceownercredentials; each credential created a disposable enrollment through the data planestart/actionexecuted an overridden image and shell command without changing the stored Job; Job and Dapr-component list-secret actions returned exact seeded inline-secret canariesbeginGetAccessactions each issued a read SAS that recovered an exact seeded byte range from the raw VHD; every SAS was revokedfunctions/masterkey/readreturned a master key and invoked a protected function when the app used file-backed secret storage;functions/token/readreturned a short-lived admin JWT that listed a function key, invoked the protected function, accessed host status, and performed an administrative function invocationslots/config/list/actiondisclosed a seeded secret and a reusable Storage connection string whose account key independently uploaded and downloaded the blob canary;slots/publishxml/actionreturned slot publishing credentials that deployed and invoked a canary through Kudu when SCM basic authentication was enabled, while the same credentials correctly failed with HTTP 401 when it was disabledgetFullUrl/actionvariants returned complete signed Logic App endpoints; every recovered URL invoked the workflow and returned its distinct seeded canaryregistries/runs/listLogSasUrl/actionreturned a signed run-log URL that downloaded the exact ACR Tasks build-log canary without task creation or scheduling rightsresetapikey/actionand Web Appnewpassword/actionreturned no credential; Logic access-key routes were deprecated; App Insights token candidates and Function host-runtime master routes did not resolve; App Service connection-string candidate routes returned HTTP 405; Web PubSub data-token testing could not be authorized; DPS enrollment write via Entra authentication, restore-pointretrieveSasUris, ordinary managed-disk write SAS, and Job-start secret-reference injection did not produce standalone validated attacksAll disposable applications, service principals, users, grants, policies, role artifacts, resources, canary data, resource groups, SDK directories, and local test files were removed and re-queried after cleanup.
Validation
mdbook build41 passed, 83 subtests passed1 passed306 passed, 1 skipped, 168 subtests passedAdditional live-validated credential surfaces (2026-09-08)
listKeysandlistStorageAccountKeysrecovered a linked Storage key and downloaded a protected blob; workspace datastore and connection secrets independently accessed their seeded Storage/Language targets.listsecretsactions each returned a reusable Cognitive Services key that successfully called the connected Language endpoint.listsecretsexplicitly failed and is documented as configuration-dependent.listCallbackUrlsupplied a wildcard signature that invoked a known trigger path.listSecrets, portal settings, preview client applications, API-connection keys, Health Bot delegated data actions, Maps UAMI SAS, and Logic agreementlistSecretsremain excluded.listKeys/listSecrets-looking Azure operations are no longer automatically Critical. They remain Medium until exact reuse or secret impact is validated; known proven rules retain explicit High/Critical tiers.Latest validation:
343 passed, 1 skipped, 200 subtests passed;mdbook buildsucceeded. A real macOS/zsh AzurePEASS run against the authorized subscription completed using the Azure CLI session. Cleanup was re-queried: the resource group, Entra app/SP, soft-deleted Key Vault/Cognitive resources, temporary artifacts, test-only extensions/image, and test-only provider registrations are absent.Additional live validation (second 2026-09-08 pass)
Additional live validation (third 2026-09-08 pass)
Additional live validation (fourth 2026-09-08 pass)
regeneratekeys/actionreturned a replacement primary key that listed jobs, created a job, and read it back; the old primary failed and the untouched secondary remained valid.listkeys/actionvariants returned alias connection strings. The Service Bus key sent and recovered the exact queue canary; the Event Hubs key published through the alias with HTTP 201.listkeys/actionbypassed the managed-resource-group key boundary and used the returned connection string to inject a canary into the protectedatlas_hookEvent Hub. Receive access was not claimed because the system epoch receiver rejected the competing client.listSecretsrecovered an exact Entra client secret that obtained a token; tenantlistSecretssigned a direct-management request that returned HTTP 200; gatewaygenerateTokenauthenticated the official self-hosted gateway image and synchronized assigned configuration containing the exact backend credential.listCredentialsauthenticated to the registry/v2/endpoint with HTTP 200. Container AppslistSecretsrecovered that exact stored ACR password from a scale-to-zero app and independently authenticated with HTTP 200.listKeysvalues were rejected by the official container; model-provider credential operations return metadata rather than values; Web API ConnectionlistConnectionKeysreturnedOperationNotAllowed; API Center credential retrieval could not be authorized without the missing data-plane role; and the undocumented Inference Service preview resource rejected creation.mdbook buildsucceeded.Unregisteringstate at the final audit.Additional live validation (fifth 2026-09-08 pass)
databaseAccounts/listConnectionStrings/actionreturned a primary SQL connection string. A fresh Cosmos SDK client created only from that string read the exact protected canary item, so the standalone action is Critical.registries/generateCredentials/actionindependently rotated an existing token password withouttokens/write. The generated credential listed a protected tag and deleted its canary manifest, so the standalone action is Critical and the old two-permission combination was corrected.localusers/regeneratePassword/actionreturned a new local-user password that authenticated over SFTP and downloaded a protected blob with an exact hash match. It is now aligned as Critical in the direct classifier and configured attack catalog.pnsCredentials/actionreturned the exact seeded Firebase/GCM API key while ordinary hub GET output redacted it. This configuration-dependent external credential disclosure is High.Components/ApiKeys/Actionminted aReadTelemetrykey; using only that key against the data-plane query API recovered the exact seeded custom event. This sensitive-telemetry path is High.listwithsecretsreturned null secrets across current API versions; Storage local-userlistKeysdid not authenticate to Azure Files; Logic workflow access-key output was not independently converted into an accepted SAS; and Compute restore-pointretrieveSasUrisreturnedOperationNotAllowedbecause the endpoint is unsupported.mdbook buildsucceeded.