azure-services-storage-blob.md (3311B)
1 --- 2 title: "Azure Services - Storage Blob" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/azure/azure-services-storage-blob.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/azure/azure-services-storage-blob.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # Azure Services - Storage Blob 12 13 * Blobs - `*.blob.core.windows.net` 14 * File Services - `*.file.core.windows.net` 15 * Data Tables - `*.table.core.windows.net` 16 * Queues - `*.queue.core.windows.net` 17 18 ## Enumerate blobs 19 20 ```powershell 21 PS > . C:\Tools\MicroBurst\Misc\InvokeEnumerateAzureBlobs.ps1 22 PS > Invoke-EnumerateAzureBlobs -Base <SHORT DOMAIN> -OutputFile azureblobs.txt 23 Found Storage Account - redacted.blob.core.windows.net 24 ``` 25 26 ## List and download blobs 27 28 Visiting `https://<storage-name>.blob.core.windows.net/<storage-container>?restype=container&comp=list` provides a JSON file containing a complete list of the Azure Blobs. 29 30 ```xml 31 <EnumerationResults ContainerName="https://<storage-name>.blob.core.windows.net/<storage-container>"> 32 <Blobs> 33 <Blob> 34 <Name>index.html</Name> 35 <Url>https://<storage-name>.blob.core.windows.net/<storage-container>/index.html</Url> 36 <Properties> 37 <Last-Modified>Fri, 20 Oct 2023 20:08:20 GMT</Last-Modified> 38 <Etag>0x8DBD1A84E6455C0</Etag> 39 <Content-Length>782359</Content-Length> 40 <Content-Type>text/html</Content-Type> 41 <Content-Encoding/> 42 <Content-Language/> 43 <Content-MD5>JSe+sM+pXGAEFInxDgv4CA==</Content-MD5> 44 <Cache-Control/> 45 <BlobType>BlockBlob</BlobType> 46 <LeaseStatus>unlocked</LeaseStatus> 47 </Properties> 48 </Blob> 49 ``` 50 51 Browse deleted files. 52 53 ```ps1 54 $ curl -s -H "x-ms-version: 2019-12-12" 'https://<storage-name>.blob.core.windows.net/<storage-container>?restype=container&comp=list&include=versions' | xmllint --format - | grep Name 55 56 <EnumerationResults ServiceEndpoint="https://<storage-name>.blob.core.windows.net/" ContainerName="<storage-container>"> 57 <Name>index.html</Name> 58 <Name>scripts-transfer.zip</Name> 59 ``` 60 61 ```powershell 62 PS Az> Get-AzResource 63 PS Az> Get-AzStorageAccount -name <NAME> -ResourceGroupName <NAME> 64 PS Az> Get-AzStorageContainer -Context (Get-AzStorageAccount -name <NAME> -ResourceGroupName <NAME>).context 65 PS Az> Get-AzStorageBlobContent -Container <NAME> -Context (Get-AzStorageAccount -name <NAME> -ResourceGroupName <NAME>).context -Blob 66 ``` 67 68 Retrieve exposed containers with public access 69 70 ```ps1 71 PS Az> (Get-AzStorageAccount | Get-AzStorageContainer).cloudBlobContainer | select Uri,@{n='PublicAccess';e={$_.Properties.PublicAccess}} 72 ``` 73 74 ## SAS URL 75 76 * Use [Storage Explorer](https://azure.microsoft.com/en-us/features/storage-explorer/) 77 * Click on **Open Connect Dialog** in the left menu. 78 * Select **Blob container**. 79 * On the **Select Authentication Method** page 80 * Select **Shared access signature (SAS)** and click on Next 81 * Copy the URL in **Blob container SAS URL** field. 82 83 :warning: You can also use `subscription`(username/password) to access storage resources such as blobs and files. 84 85 ## References 86 87 * [Training - Attacking and Defending Azure Lab - Altered Security](https://www.alteredsecurity.com/azureadlab)