daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

azure-services-storage-blob.md (3311B)


      1 ---
      2 title: "Azure Services - Storage Blob"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/azure/azure-services-storage-blob.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-services-storage-blob.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # Azure Services - Storage Blob
     12 
     13 * Blobs - `*.blob.core.windows.net`
     14 * File Services - `*.file.core.windows.net`
     15 * Data Tables - `*.table.core.windows.net`
     16 * Queues - `*.queue.core.windows.net`
     17 
     18 ## Enumerate blobs
     19 
     20 ```powershell
     21 PS > . C:\Tools\MicroBurst\Misc\InvokeEnumerateAzureBlobs.ps1
     22 PS > Invoke-EnumerateAzureBlobs -Base <SHORT DOMAIN> -OutputFile azureblobs.txt
     23 Found Storage Account -  redacted.blob.core.windows.net
     24 ```
     25 
     26 ## List and download blobs
     27 
     28 Visiting `https://<storage-name>.blob.core.windows.net/<storage-container>?restype=container&comp=list` provides a JSON file containing a complete list of the Azure Blobs.
     29 
     30 ```xml
     31 <EnumerationResults ContainerName="https://<storage-name>.blob.core.windows.net/<storage-container>">
     32     <Blobs>
     33         <Blob>
     34             <Name>index.html</Name>
     35             <Url>https://<storage-name>.blob.core.windows.net/<storage-container>/index.html</Url>
     36             <Properties>
     37             <Last-Modified>Fri, 20 Oct 2023 20:08:20 GMT</Last-Modified>
     38             <Etag>0x8DBD1A84E6455C0</Etag>
     39             <Content-Length>782359</Content-Length>
     40             <Content-Type>text/html</Content-Type>
     41             <Content-Encoding/>
     42             <Content-Language/>
     43             <Content-MD5>JSe+sM+pXGAEFInxDgv4CA==</Content-MD5>
     44             <Cache-Control/>
     45             <BlobType>BlockBlob</BlobType>
     46             <LeaseStatus>unlocked</LeaseStatus>
     47             </Properties>
     48         </Blob>
     49 ```
     50 
     51 Browse deleted files.
     52 
     53 ```ps1
     54 $ curl -s -H "x-ms-version: 2019-12-12" 'https://<storage-name>.blob.core.windows.net/<storage-container>?restype=container&comp=list&include=versions' | xmllint --format - | grep Name
     55 
     56 <EnumerationResults ServiceEndpoint="https://<storage-name>.blob.core.windows.net/" ContainerName="<storage-container>">
     57       <Name>index.html</Name>
     58       <Name>scripts-transfer.zip</Name>
     59 ```
     60 
     61 ```powershell
     62 PS Az> Get-AzResource
     63 PS Az> Get-AzStorageAccount -name <NAME> -ResourceGroupName <NAME>
     64 PS Az> Get-AzStorageContainer -Context (Get-AzStorageAccount -name <NAME> -ResourceGroupName <NAME>).context
     65 PS Az> Get-AzStorageBlobContent -Container <NAME> -Context (Get-AzStorageAccount -name <NAME> -ResourceGroupName <NAME>).context -Blob
     66 ```
     67 
     68 Retrieve exposed containers with public access
     69 
     70 ```ps1
     71 PS Az> (Get-AzStorageAccount | Get-AzStorageContainer).cloudBlobContainer | select Uri,@{n='PublicAccess';e={$_.Properties.PublicAccess}}
     72 ```
     73 
     74 ## SAS URL
     75 
     76 * Use [Storage Explorer](https://azure.microsoft.com/en-us/features/storage-explorer/)
     77 * Click on **Open Connect Dialog** in the left menu.
     78 * Select **Blob container**.
     79 * On the **Select Authentication Method** page
     80     * Select **Shared access signature (SAS)** and click on Next
     81     * Copy the URL in **Blob container SAS URL** field.
     82 
     83 :warning: You can also use `subscription`(username/password) to access storage resources such as blobs and files.
     84 
     85 ## References
     86 
     87 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)