HNHacker News
TopNewBestAskShowJobs

hland

44 karma · joined August 23, 2016

submissionscomments
hland··on Azure's Weakest Link – Five Full Cross-Tenant Compromises
API Connections allow anyone to fully compromise any other connection worldwide, giving full access to the connected backend.
hland··on Azure's Weakest Link – Full Cross-Tenant Compromise
API Connections allow anyone to fully compromise any other Connection worldwide, giving full access to the connected Backend. This includes cross-tenant compromise of Key Vaults and Azure SQL databases, as well as any other externally connected service, such as Jira or SalesForce.
hland··on Finding SSRFs in Azure DevOps – Part 2
Binary Security was previously rewarded for three Server-Side Request Forgery (SSRF) vulnerabilities in Azure DevOps, which you can read about here. Now we have found another SSRF vulnerability that we also reported to Microsoft. We then bypassed Microsoft’s fix of the vulnerability using DNS rebinding. If you read the previous blogpost, some of this may feel a bit like deja-vu. This blog post outlines how these new SSRFs were identified by analyzing the Azure DevOps source code.
hland··on Azure's Weakest Link? How API Connections Spill Secrets
Your take is spot on, sir.
hland··on Azure's Weakest Link? How API Connections Spill Secrets
Binary Security found the undocumented APIs for Azure API Connections. In this post we examine the inner workings of the Connections allowing us to escalate privileges and read secrets in backend resources for services ranging from Key Vaults, Storage Blobs, Defender ATP, to Enterprise Jira and SalesForce servers.