I Hacked Azure With a Fake OAuth App | Wiz CTF Entra ID Challenge
Автор: CyberGuy
Загружено: 2026-01-20
Просмотров: 24
Описание:
What happens when you combine an illicit consent grant with a Conditional Access bypass?
Full Azure takeover.
In this Wiz Cloud Security Championship walkthrough, I show you step-by-step how I:
🔓 Deployed a malicious OAuth app into the victim's tenant
🚫 Bypassed Conditional Access using the admin consent endpoint trick
👥 Abused dynamic group membership rules
📧 Invited a guest user to gain automatic group access
📦 Retrieved the flag from Azure Storage using data-plane permissions
The scariest part? The guest user had ZERO visible RBAC roles - yet still had full blob access.
This is why understanding control-plane vs data-plane matters!
🔗 Resources:
• Full blog writeup: [LINK]
• Wiz CTF: https://cloudsecuritychampionship.com/
Like & Subscribe for more cloud security content! 🔔
#Azure #CloudHacking #WizCTF #EntraID #OAuthAttack
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: