Azure Goat
Azure Goat
#BHUSA @BlackHatEvents
About US
Jeswin Mathai
• Chief Architect, Lab Platform @ INE
• Published Research at Black Hat US/Asia Arsenal, DEF CON USA/China Demolabs
• Gave research talk at DEF CON China and Rootcon Philippines
• Co-Trainer in Training:
- Black Hat Asia
- HITB AMS, GSEC
- NZ OWASP day
- Rootcon 13
#BHUSA @BlackHatEvents
Information Classification: General
About US
Nishant Sharma
• Director, Lab Platform @ INE
• Firmware developer, Enterprise WiFi APs and WIPS Sensors, Mojo Networks (Acquired
by Arista Networks)
• Masters degree in Infosec
• Published research at Blackhat US/Asia, DEF CON USA/China, HITB Amsterdam and
other venues
• Conducted trainings in HITB, OWASP NZ day and for multiple private clients
#BHUSA @BlackHatEvents
Information Classification: General
About US
Sherin Stephen
• Cloud Developer @ INE
• Presented his work at BlackHat Asia Arsenal 2022
• Experienced in Building and maintaining reusable code and robust cloud services
Rachana Umaraniya
• Cloud Developer @ INE
• Master's Degree in Computer Science
• Two years of experience in software development and specializes in Java Frameworks
#BHUSA @BlackHatEvents
Information Classification: General
#BHUSA @BlackHatEvents
Information Classification: General
#BHUSA @BlackHatEvents
Information Classification: General
Threatscape
#BHUSA @BlackHatEvents
Information Classification: General
Threatscape
#BHUSA @BlackHatEvents
Information Classification: General
Motivation
• Training Needs
#BHUSA @BlackHatEvents
Information Classification: General
Introducing AzureGoat
#BHUSA @BlackHatEvents
Information Classification: General
AzureGoat : A Damn Vulnerable Azure Infrastructure
#BHUSA @BlackHatEvents
Information Classification: General
OWASP Top 10
#BHUSA @BlackHatEvents
Information Classification: General
AzureGoat : Module 1 (Blog Application)
• A01: Broken Access Control
• A03: Injection
#BHUSA @BlackHatEvents
Information Classification: General
AzureGoat : Module 1 (Blog Application)
#BHUSA @BlackHatEvents
Information Classification: General
Building Realistic Insecure Application : Challenges
• Fast-paced development
#BHUSA @BlackHatEvents
Information Classification: General
Project Family
#BHUSA @BlackHatEvents
Information Classification: General
Installation
• Repository: https://github.com/ine-labs/AzureGoat
• Requirements
- AZ Utility
- Terraform
- Python
- Git
• Commands
- az login
- git clone https://github.com/ine-labs/AzureGoat
- terraform init
- terraform apply
#BHUSA @BlackHatEvents
Information Classification: General
Installation
#BHUSA @BlackHatEvents
Information Classification: General
Attacking the Application
• Reflected XSS
• SQL Injection
• Insecure Direct Object Reference
• Server Side Request Forgery Click
Clickto
toadd
add
DALL-E
• Sensitive Data Exposure text
text
DALL-E
• Password Reset
• S3 Misconfiguration
• IAM Privilege Escalation
#BHUSA @BlackHatEvents
Information Classification: General
Exploitation
#BHUSA @BlackHatEvents
Information Classification: General
Server Side Request Forgery
• Reading the source code of the application
#BHUSA @BlackHatEvents
Information Classification: General
Hunting Storage Accounts and Containers
• Globally unique
#BHUSA @BlackHatEvents
Information Classification: General
Privilege Escalation
#BHUSA @BlackHatEvents
Information Classification: General
Future Plans: Multiple Applications across Multiple Tenants
Click DALL-E
to add
DALL-E
text
• IaC Misconfigurations
#BHUSA @BlackHatEvents
Information Classification: General
Thanks
Click
Clickto
toadd
add
DALL-E
text
text
DALL-E
#BHUSA @BlackHatEvents
Information Classification: General