All talks

BSidesLV 2023 · 2023/08

All You Need is Guest: Beyond Enumeration

Loading presentation…

Read the abstract and transcript

Abstract

Azure AD guest accounts are widely used to grant external parties limited access to enterprise resources, with the assumption that these accounts pose little security risk. As you’re about to see, this assumption is dangerously wrong.

In this talk, we will show how guests can leverage undocumented APIs to bypass limitations and gain unauthorized access to sensitive business data and capabilities including corporate SQL servers, SharePoint sites, and KeyVault secrets. Furthermore, we will reveal how guests can create and control internal business applications to move laterally within the organization. All capabilities presented in the talk work will be demonstrated with the default Office 365 and Azure AD configuration.

Next, we will drop PowerGuest, a powerful tool designed to uncover the true scope of guest access in your tenant. PowerGuest can automate limitation bypass, enumerate and dump all accessible data, and allow for interactive non-read actions by the researcher.

Finally, we will make up for shattering the illusion of guests having limited access by sharing concrete steps to harden your Azure AD and Office 365 configurations to prevent such attacks and suggest detection logic to catch them if a change in configuration is not possible.

Official conference abstract

Transcript

AI generated from recording.

Opening the Door: Guest Accounts and the Power of Collaboration

00:01 Presenter: Does it work? Can you hear me? All right. So, first of all, thank you for staying with me. I know it’s kind of late in the day. And because this is, I mean, it’s late in the day for all of us, so I think we can make it like a more, more chill kind of talk. So if you have questions, if you have comments, if you want to say that I’m wrong somewhere, just, just shout out during the talk. Okay? Don’t, don’t wait for the end.

00:30 Presenter: we’re going to, you know, before I explain anything,

00:33 Presenter: let me do a quick slide-based demo, okay?

00:37 Presenter: So, say you have access to an Azure Active Directory guest account.

00:43 Presenter: We’ve all received these emails

00:47 Presenter: where you get invited to somebody else’s tenant,

00:49 Presenter: and that’s, so it could happen because you work with them,

00:54 Presenter: you’re a contractor or something.

00:55 Presenter: Well, all right.

00:58 Presenter: When you actually log in to to this guest account and you go to their tenant by default

01:05 Presenter: By default you’ll you’ll actually

01:08 Presenter: Find nothing there because guests don’t have access to anything

01:12 Presenter: Unless unless that somebody actively gives them the access right and so

01:17 Presenter: What we’re going to show today is this is that this is definitely not true

01:20 Presenter: The tool that I’m going to release in this talk is going to produce for you with a guest account

01:27 Presenter: SQL servers, Azure resources.

01:29 Presenter: I’m not talking about enumeration here.

01:31 Presenter: I’m talking about full dumps of all of the data

01:34 Presenter: behind all of these resources.

01:36 Presenter: This is a true example.

01:37 Presenter: You’ll understand what’s going on here

01:39 Presenter: at the end of this talk.

01:41 Presenter: And so now that I hopefully,

01:44 Presenter: and yeah, there’s also a dump.

01:47 Presenter: And so now that I hopefully have your attention,

01:51 Presenter: hi, my name is Michael.

01:53 Presenter: I am focused on security for low code, no code apps,

01:57 Presenter: which is the kind of applications

01:58 Presenter: that business users are building.

01:59 Presenter: I’ve been doing that for about four years now.

02:01 Presenter: There’s a bunch of research I put out there.

02:04 Presenter: So if you’re interested about, on this topic,

02:07 Presenter: please reach out afterwards.

02:08 Presenter: And we’re looking for more smart people

02:11 Presenter: to kind of focus on this area, so reach out to me.

02:17 Presenter: All right.

02:19 Presenter: So before we understand kind of what’s,

02:22 Presenter: what’s going on here, we need to spend a brief moment

02:27 Presenter: what the guests are, what this mechanism actually is.

02:30 Presenter: So if you, the scenario is that,

02:34 Presenter: well, you wanna be able to share with someone.

02:38 Presenter: I work for a small company, like a 25 people startup,

02:42 Presenter: and we work with very large enterprises.

02:44 Presenter: And so in most of the cases,

02:47 Presenter: we need to find a way to collaborate on files, right?

02:50 Presenter: You need to share decks, you need to share legal docs.

02:54 Presenter: And so there are multiple ways in which you can share those those dogs around one thing you can do

03:00 Presenter: Which is pretty obvious

03:02 Presenter: You can just share those files of email right?

03:06 Presenter: It’s kind of funny, but we’ve all done that and so this is one one thing that you can absolutely do you can always you can also just

03:13 Presenter: Trust a random website on the internet, which is also something that we’ve all that we’ve all done

03:19 Presenter: I’ve found out that you can also do this in real life.

03:23 Presenter: So there are USB ports all around the world.

03:24 Presenter: You can just plug in your computer and drop whatever you’d like.

03:28 Presenter: So you can do that as well.

03:31 Presenter: That’s a real thing.

03:34 Presenter: Check out the website. It’s really cool.

03:35 Presenter: So what you can also do is you can invite those guests into your tenant.

03:42 Presenter: And that’s actually what Azure AD guests is all about.

03:46 Presenter: Basically the idea is that you bring people into your tenants and then two things happen

03:52 Presenter: One is that they can bring their own identities

03:54 Presenter: Which means you don’t have to worry about how they authenticate and two you are still in control and those are two

04:01 Presenter: Significant promises to try and hold together so let’s try and figure out

04:05 Presenter: What exactly does that mean in order for this mechanism to actually walk two things need to be need to hold one is that?

04:13 Presenter: This needs to be very easy to onboard every vendor every contractor. They use a different thing

04:17 Presenter: They need to be able to get on your your tenant quickly and the second thing it of course needs to be

04:24 Presenter: Easy to control right because otherwise you’ve just invited a guest into your tenant. I mean what could happen?

04:30 Presenter: And so let’s try and figure out these two things so the first thing

04:39 Presenter: Yeah

04:49 Presenter: Does that help in any way?

04:54 Presenter: All right.

04:57 Presenter: So the first thing I need to prove to you is that

05:01 Presenter: like getting a guest account is very easy.

05:03 Presenter: And while I talk, you can see that I’m inviting myself

05:06 Presenter: to a guest with a bunch of different ways to do that

05:09 Presenter: through Microsoft.

05:10 Presenter: Notice that all of these options to invite guests are embedded into productivity apps

05:15 Presenter: So you own a team’s channel or you own a SharePoint site

05:19 Presenter: You just want to collaborate with someone so you plug in their email and it invites them as a guest

05:24 Presenter: This is a decision that the business user makes no decision that the admin makes right and so this is very

05:31 Presenter: Easy to achieve and actually when you look at the ad tenant for any large enterprise

05:36 Presenter: most of them you’ll find lots of guests.

05:38 Presenter: You can go down the very strict round

05:40 Presenter: of kind of cutting this and not using this feature,

05:44 Presenter: but then, well, how do you share files?

05:46 Presenter: We’ve seen the other options.

05:48 Presenter: And so it’s very easy to get guests.

05:51 Presenter: In some cases, it might even be too easy.

05:54 Presenter: So again, this is the email that you receive as a guest.

05:59 Presenter: Actually, in a talk last year,

From Invitation to Access: Understanding Azure AD Guest Mechanics

06:02 Presenter: here, Dirkian showed that you can hijack guest accounts.

06:06 Presenter: I talked about Black Hat last year.

06:07 Presenter: He showed that you can hijack guest accounts, guest

06:09 Presenter: invites that were not redeemed, and then redeem them

06:13 Presenter: yourself with any email address that you’d like.

06:15 Presenter: This was actually fixed, but this was a pretty cool thing

06:20 Presenter: because any user in the organization could just query

06:23 Presenter: open tickets and then just grab them.

06:26 Presenter: And so it’s very easy to get guests.

06:29 Presenter: I think that’s kind of really pretty established the second thing that I need to prove to you is that it’s

06:35 Presenter: Still easy to control it’s easy for IT and security to control

06:38 Presenter: And so let’s see that part and so in order to do that

06:42 Presenter: We need to understand how does Azure Active Directory guest actually work and so on the vendor side partner side

06:48 Presenter: You could be using any any any type of identity provider you could be using another

06:52 Presenter: AAD account, but you can just you can use a Google suite or

06:55 Presenter: or Okta, whatever you’d like.

06:57 Presenter: And so the way it works is that it creates a link

06:59 Presenter: between those two directories.

07:01 Presenter: And so you get authenticated with your home tenant

07:03 Presenter: and your guest tenant just trust that authentication.

07:07 Presenter: And the cool thing about it is that because it’s done this

07:11 Presenter: way, all of the security controls that Microsoft

07:14 Presenter: provides for you apply.

07:15 Presenter: So if you have conditional access, MFA enforced,

07:19 Presenter: whatever you’d like, this all get enforced automatically

07:22 Presenter: on guests, which is awesome, right?

07:26 Presenter: And so one thing that we need to understand, though,

07:29 Presenter: is that, well, in order to give somebody guest access,

07:33 Presenter: we want security controls, right?

07:36 Presenter: Because otherwise you’ve just invited somebody into your tenant

07:39 Presenter: and they can do whatever they like.

07:40 Presenter: In order to get security controls,

07:42 Presenter: we need to have an AID account

07:45 Presenter: because otherwise we can’t apply the security mechanisms

07:48 Presenter: that we already have as an enterprise.

07:50 Presenter: And so in order to have that account,

07:55 Presenter: the ID which actually grants full access to your tenant.

07:58 Presenter: So what’s, what’s actually happening here?

08:01 Presenter: So the crucial piece is that you don’t get full access.

08:06 Presenter: You get access that’s denied by default.

08:08 Presenter: You get access that gives you access to nothing, basically.

08:11 Presenter: So if I invited you through Teams, you’ll only, you’ll only get access to that specific

08:15 Presenter: team channel.

08:17 Presenter: Or at least that’s what it should, that’s what should happen.

08:22 Presenter: So a quick recap here.

08:25 Presenter: all very very very easy to guess we should we should assume that a compromise in a guest

08:29 Presenter: account within our tenant is easy. AAD controls apply, security controls apply which is great

08:35 Presenter: and access should be denied by default and now when I’ve talked so much good things about

08:39 Presenter: this mechanism let’s see what happens in practice because in practice as we know things are

08:45 Presenter: a bit a bit more a bit dirtier and so first of all there are so okay so let’s start by

08:52 Presenter: kind of just inviting some, a guest around. And every time you see this icon on the bottom

08:58 Presenter: right corner, that’s kind of the, the user, the legitimate user that’s, that’s doing something.

09:03 Presenter: And you’ll see in a, in a moment an icon, a different icon for, for a hacker. Just because

09:07 Presenter: I’m gonna move between users a lot. And so, I’m, I’m in teams. I’m going to kind of just

09:14 Presenter: say, invite somebody. I’m going to invite a hacker in because why not? That’s my hacker

09:19 Presenter: account here. And then once I invite that guest, I click on that and that guest is invited

09:25 Presenter: and they will get that email that we saw earlier. From the hacker perspective, and you can see

09:32 Presenter: the hacker icon here, I just log into my account and then I need to allow this tenant to get

09:39 Presenter: access to basic information about my profile and I’ll do that. Zenity demo is kind of the

09:46 Presenter: the, the thing that I’m hacking.

09:48 Presenter: And again, I get to this, to this portal which is empty

09:52 Presenter: because it’s showing me all of the apps that I have access

09:55 Presenter: to which is actually none, okay?

09:57 Presenter: And so there’s, there are two things that we already know

10:01 Presenter: how to do, and if you’ve Googled it before,

10:03 Presenter: you would have found it before this talk.

10:05 Presenter: One is phishing through teams.

10:07 Presenter: Once you get invited into, into a guest, into a tenant

10:11 Presenter: as a guest, then you can do phishing through the internal

10:14 Presenter: teams of that organization, which is actually pretty nice, because it adds some believability

10:20 Presenter: into your phishing attempt. The other thing that you can do is recon on the directory.

10:25 Presenter: So you can actually find, there’s some sophisticated ways in which you can find a list of users

10:30 Presenter: within that organization, even though you are not allowed to directly enumerate the

10:35 Presenter: users. If you want to look at it, there’s a nice link there that it will share everything

10:41 Presenter: about it. And so this is the state of the art for

10:44 Presenter: guest exploitation, but of course we want more.

10:47 Presenter: Right? We want access to resources. And so this is the

10:50 Presenter: point in the talk where I’m basically suggesting that if

10:55 Presenter: you don’t want to have a responsibility when you go back

10:59 Presenter: to work, then, then this is the time to live.

11:01 Presenter: Because right now I’m going to show how this is completely,

11:06 Presenter: how, how the reality differs from, from your expectations.

11:13 Presenter: All right, so what I’m going to do right now is just virtually click on that link

11:20 Presenter: So when I click on that link I get invited to something I get it into something called power-ups

11:24 Presenter: Which is the local local platform for for Microsoft which is built into office

11:29 Presenter: And the first thing that you’ll see here is that

11:32 Presenter: Well, I get I get some sort of an L

11:35 Presenter: Which is telling me basically you’re trying to reach an environment which does not belong to your tenant

11:41 Presenter: I’ve set earlier is in the guest tenant, right? Not my home tenant. And so I click on this

11:47 Presenter: go to home page and I get to my home page and now I’m in power, in power ups but you

The Hidden Risks: Business Users Sharing Credentials

11:52 Presenter: can see here that I’m in my own tenant, Pontoso, which is the hacker’s tenant. And so now I

11:59 Presenter: need to be able to switch to the guest tenant. That’s pretty easy. You just kind of, you

12:04 Presenter: go to switch directory and now I’m in the right, I’m going to move to the right tenant,

12:08 Presenter: So you can move to any one of the tenants

12:11 Presenter: that you have access to.

12:12 Presenter: Again, when you get access as a guest

12:16 Presenter: to somebody else’s corporate,

12:17 Presenter: this is just waiting for you.

12:19 Presenter: All right?

12:20 Presenter: And so once you do that,

12:22 Presenter: then you get to where I actually sent you

12:25 Presenter: with this link,

12:26 Presenter: which is a screen called Connections.

12:28 Presenter: And you can see that these connections

12:30 Presenter: have Azure connections,

12:32 Presenter: connections for SQL servers.

12:33 Presenter: You can see their names.

12:35 Presenter: And for some reason, as a guest,

12:39 Presenter: And so let’s try and figure out what the hell is this?

12:44 Presenter: Why does this exist and why do we have access into it?

12:48 Presenter: And so let’s examine one of them.

12:50 Presenter: This is an Azure file storage,

12:52 Presenter: and it’s called something like Jamie Redding customer data.

12:57 Presenter: All right.

12:58 Presenter: So first of all, you can see this little menu here,

13:01 Presenter: two interesting things.

13:02 Presenter: So one is details.

13:03 Presenter: Well, we’ll see that in a moment.

13:05 Presenter: But the other is share.

13:07 Presenter: So there’s a share button here.

13:08 Presenter: on a connection to Azure file storage.

13:11 Presenter: Let’s look at that share button.

13:13 Presenter: All right.

13:15 Presenter: So this file storage connection

13:19 Presenter: is apparently shared with three different entities.

13:22 Presenter: The first thing is shared with org.

13:24 Presenter: The second thing is shared with Jamie.

13:27 Presenter: This is probably the Jamie that created this connection.

13:29 Presenter: And the third thing here is Jamie,

13:31 Presenter: and you can almost barely see that this is an Outlook account,

13:36 Presenter: a personal account.

13:38 Presenter: that each of them have. And so this is the root cause issue of

13:43 Presenter: why we’re seeing this connection right now. Okay? So Jamie has,

13:47 Presenter: has created this connection and has shared this with everyone.

13:51 Presenter: And actually what’s going on here is that this connection is

13:56 Presenter: a wrapper around credentials. It can be an OAuth token,

13:59 Presenter: a refresh token, or so Jamie’s own refresh token,

14:02 Presenter: her own identity. Or it could be like a username

14:04 Presenter: password or a client secret or whatever you’d like.

14:06 Presenter: And then you could just take this up and share it with everyone everyone means your entire ad guest your retire ad tenant

14:13 Presenter: You can also share this with the groups with specific individuals with your own outlook account whatever just just kind of be productive

14:21 Presenter: And so this this works in this kind of this is pretty cool

14:26 Presenter: Let’s try and figure out what this connection actually is why does this exist and so going back to details and now

14:32 Presenter: I can see a bunch of information about this connection. I can see that indeed it was created

14:37 Presenter: It is owned by Jamie reading and trying to figure out who Jamie is

14:41 Presenter: I can see that Jamie is a customer service representative that works in in sales ops so Jamie is a business user

14:47 Presenter: So Jamie made made the decision which was a bad decision to share this connection around and we’ll see in a moment that this is

14:56 Presenter: This is a common mistake to make because it that the platform just make it very easy for you to

15:02 Presenter: do it so before we move forward with this talk I’m not sure how many of you

15:08 Presenter: are familiar with low-code no-code and so I need to explain to you why is this

15:12 Presenter: happening why does why is it believable that somebody from the business would

15:16 Presenter: create a connection to Azure and share it with the dialogue so here’s the

15:20 Presenter: reason yeah okay so you won’t get the video but here’s the reason basically

15:32 Presenter: NoCode is putting power in the hands of business users

15:36 Presenter: to build their own applications and automations

15:38 Presenter: on top of business data.

15:39 Presenter: What this video actually shows is that right now

15:42 Presenter: they’ve integrated ChatGPT into their platform.

15:46 Presenter: So you can just kind of ask ChatGPT to create an app for you.

15:50 Presenter: And it would create a table on a database

15:52 Presenter: and share it with everyone and create the columns

15:56 Presenter: and create the actual app.

15:57 Presenter: And so this is something that business users are actually

16:00 Presenter: using to solve their own business problems and when they do it they do them on business data of course and

16:06 Presenter: So as a business user you mostly don’t have access to service accounts, right?

16:11 Presenter: You do have access to your own credentials

16:12 Presenter: So why not wrap them around with a thing called connections and share them share your refresh tokens with whoever wants it?

16:20 Presenter: and so this is the way that this typically works and

16:23 Presenter: One of the things that is important for you to understand that this is a big issue is just

16:30 Presenter: And so here’s what I did here

16:39 Presenter: Okay, this is a slide showing

16:43 Presenter: Right now a single number five million. That’s the number of

16:48 Presenter: Of developers using dotnet today according to Microsoft all right a

16:53 Presenter: Pretty big number how many developers do you think are using this like business developers are using this local no code tool?

17:00 Presenter: in order to build their own applications.

17:02 Presenter: Just have a number in your head, something that fits

17:05 Presenter: with your model of the world, where if you look at where we

17:08 Presenter: focus most of our attention, it’s on applications that

17:11 Presenter: those people are building, right?

17:14 Presenter: People that are building it with code.

Exploiting the Connections: From Phishing to Data Dump

17:16 Presenter: And so I actually went through Microsoft

17:18 Presenter: earning reports for the few years back, and they

17:24 Presenter: mentioned the numbers here and there.

17:26 Presenter: So here are the here are the numbers from the from the from the reports according to the

17:32 Presenter: Small kind of linear regression I did here. There are about 8 million developers today

17:37 Presenter: And so I’m sure that most of the people in this room have

17:42 Presenter: Either never heard of this before or didn’t dedicate a lot of their career to try and solve this problem

17:48 Presenter: This is actually kind of becoming huge huge within the top organizations in the world

17:54 Presenter: So we need to start dedicating our time here and so

17:59 Presenter: Now that we understand that this thing is happening is happening in every major org really every major org out there because just show me

18:06 Presenter: My an ent a large enterprise. That’s not a microsoft shop

18:10 Presenter: Let’s figure out. How do we get from those connections to actually doing something with them?

18:15 Presenter: And so in this in this part right now

18:18 Presenter: I’m just gonna take you through the rabbit hole of how do we get to these so we were able to see this connection

18:24 Presenter: that’s fine. But now we want to automate things, we want to dump the data behind this, we want

18:29 Presenter: to make this into something that we can use as hackers. And so let’s try to figure out

18:33 Presenter: how that works.

18:34 Presenter: Just before we get into the next phase here. We do a thing called outrageous

18:47 Presenter: speaker requests here at B-Sides every year. When someone submits a talk, there’s a field

18:52 Presenter: right at the very end that says any outrageous requests,

18:54 Presenter: and a lot of times they throw something in there

18:56 Presenter: at two in the morning and forget about it.

18:58 Presenter: The request that we have from you

19:00 Presenter: was to help you find more hacker friends,

19:02 Presenter: I think is the actual thing.

19:04 Presenter: So first off, I want to make sure, is this you?

19:07 Presenter: Yeah.

19:07 Presenter: Okay, so I’m going to ask everybody in the audience,

19:11 Presenter: if you can, if you are on Twitter,

19:14 Presenter: and this one’s you as well?

19:16 Presenter: Yep.

19:16 Presenter: Okay, so I’m going to

19:18 Presenter: at MBRG0,

19:21 Presenter: and I’m going to follow him,

19:24 Presenter: and I’m going to go to LinkedIn,

19:30 Presenter: where we have…

19:33 Presenter: And I’m sorry, how do you pronounce your last name?

19:35 Presenter: Bargari.

19:36 Presenter: Bargari, okay.

19:37 Presenter: Michael Bargari, and I’m going to add him,

19:39 Presenter: and I encourage everyone here,

19:40 Presenter: pull out your phones,

19:41 Presenter: and do the same thing right now.

19:44 Presenter: Help me fill this outrageous speaker request.

19:47 Presenter: Cheers.

19:48 Presenter: Have a good day.

19:50 Presenter: Thank you.

19:55 Presenter: Actually, there are so many avenues for research here,

19:59 Presenter: and we are so little,

20:02 Presenter: the group of people that is focused on this area

20:04 Presenter: is so small.

20:05 Presenter: If you’re interested in like an interesting challenge

20:08 Presenter: and just banging your heads against the world with this,

20:12 Presenter: just reach out to me.

20:13 Presenter: There are plenty of things we can collaborate on.

20:15 Presenter: All right, so now let’s do some hacking first of all I

20:21 Presenter: And again, I’m authenticated as the guest here and I’m looking at the specific connection

20:25 Presenter: Let’s try to figure out what information lies behind this Azure file storage thing and so

20:31 Presenter: I’m going through the there’s a tab here called applications that use this connection and so let’s just try to

20:37 Presenter: Look log into that application customer insight something all right

20:43 Presenter: This takes me to a page which gives me some information about this app, and then there’s

20:47 Presenter: this link.

20:48 Presenter: And by the way, you’ll notice that this link is a Microsoft link inside of the Microsoft

20:52 Presenter: own domain.

20:53 Presenter: And in DefCon last year, what I showed was that you can create a phishing app that would

20:58 Presenter: be hosted by Microsoft in this link and supports SSO, and everything is kind of nice and believable.

21:03 Presenter: So check that out if you’re interested.

21:06 Presenter: And so when I click on this app, I get this kind of thing that’s stopping me.

21:12 Presenter: me to actually view this app. And if you look, kind of open this up, and if you look closely,

21:19 Presenter: this is telling me that I don’t have a license. And so this makes sense, right? I’m a guest.

21:25 Presenter: I don’t have a, by default, I don’t, I’m not supposed to be able to do anything. And so

21:30 Presenter: the clue to understand how do we circumvent this is the sentence above here. So I’ll read it out.

21:36 Presenter: You don’t have the correct plan to access this app ask your admin for one or ask the admin at your at the organization in which you’re a guest

21:45 Presenter: Can you guess what I’m what I’m gonna do to bypass this

21:49 Presenter: So I need a license. I don’t have a license in the guest tenant

21:53 Presenter: What would happen if I have a license in my own tenant now that that that shouldn’t work, right?

21:58 Presenter: Okay, let’s try

22:00 Presenter: Here’s like a developer plan. I can get for free, but for Microsoft

22:04 Presenter: I’ll just say hey can I get a license for this hacker account and they’ll say yeah of course here’s a license

22:11 Presenter: And now of course I’m in because why not if you have a license in one tenant then it applies to another tenant

22:17 Presenter: That’s great and

22:20 Presenter: Now after this thing loads

22:22 Presenter: Then I get to this screen which is telling me something very weird that this app is not compliant with the latest data

22:29 Presenter: prevention policies all right

22:31 Presenter: And you can see here something about a policy name, deny Azure file storage, DLP inside of this power-ups thing, inside of this low-code thing.

22:42 Presenter: That’s kind of weird.

22:44 Presenter: And so let’s try and, so I was able to circumvent the license issue, but now I’m blocked by DLP.

22:52 Presenter: And so Microsoft has actually integrated something they call DLP data loss policies inside inside of this

23:00 Presenter: Power up thing inside of this local no good thing which is great right we have business users. They are building applications

23:05 Presenter: We are worried about data moving out of our tenant. Let’s have a DLP built in this is a great idea

Bypassing Licenses and DLP: The Hacker’s Toolkit

23:11 Presenter: So let’s use this great idea again. I’m logged in as the as the

23:15 Presenter: As the user that’s kind of the trusted user that uses that’s fine

23:18 Presenter: And I’m going to create a DLP policy to find social security numbers within my tenant. It’s gonna be awesome. I’m going to choose

23:27 Presenter: Connectors all right, so I need to choose a connector. I’m gonna choose the SharePoint connector something about it not being blockable

23:36 Presenter: I’m kind of stuck. I’m not not really sure. I’m not sure if you kind of what would you do next in this screen like

23:42 Presenter: How do I move forward with applying this DLP policy?

23:47 Presenter: So actually the thing here is that this is not DLP

23:52 Presenter: This is not DLP in the sense that you think about DLP. This is a an allow list denialist for connectors

23:59 Presenter: connectors mean

24:01 Presenter: connector to SharePoint like SharePoint as a whole

24:05 Presenter: Everybody’s SharePoint every site every tenant whatever you’d like every one drive for business some connectors are not blockable at all

24:13 Presenter: SharePoint, but you can block, I don’t know,

24:15 Presenter: SQL Server, for example. This is definitely

24:17 Presenter: not DLP in the sense that

24:19 Presenter: we think about as security people.

24:21 Presenter: So it needs to be kind of

24:23 Presenter: clear here. And the second thing that’s interesting

24:25 Presenter: is that this DLP is

24:27 Presenter: actually full of holes, and one of my

24:29 Presenter: hobbies is to try and

24:31 Presenter: figure out all of the different holes

24:33 Presenter: within this DLP. Currently, I know

24:35 Presenter: of five, and so

24:37 Presenter: here’s one of them, and

24:39 Presenter: another one, and another one, and another one, and another one.

24:42 Presenter: There’s ways in which you, you create a sophisticated DLP policy that bypasses itself.

24:48 Presenter: This is all completely public.

24:51 Presenter: Admittedly, there are some advanced features in this DLP policy.

24:55 Presenter: You can do kind of endpoint filtering, but it also only works in, in compile mode rather

25:01 Presenter: than run time.

25:01 Presenter: So, not a security, not a security mechanism.

25:05 Presenter: This would, this might prevent users from making mistakes.

25:08 Presenter: This would definitely not prevent a hacker from doing something within your org

25:12 Presenter: But having said all of that. I mean we are still blocked right?

25:17 Presenter: We are still blocked by this thing right now, and we need to circumvent that and

25:23 Presenter: I’m gonna be honest with you

25:25 Presenter: I I have a way to I have a way forward but unfortunately I won’t be able to actually share

25:31 Presenter: That that that beat right now because Microsoft asked me not to and so they’re gonna

25:37 Presenter: They’re gonna they’re gonna fix it which is great and so after they fix it

25:41 Presenter: I’m gonna put the information there in the link but until then let’s just kind of let’s forget about it

25:49 Presenter: All right, so forget about it. I cannot I was not able to

25:53 Presenter: To actually get something from Azure file storage. Let’s just take another connection here. Here’s a sequel storage

25:59 Presenter: Called Enterprise customers sounds nice. So again going to details applications using these connections

26:07 Presenter: applications. I click on one of those applications. And this time I actually got into the app.

26:12 Presenter: And the first thing that I see when I go into the app is this screen that is telling me,

26:17 Presenter: hey, I’m going to use this SQL connection in this app. By the way, again, think about

26:22 Presenter: like regular applications. You tend to see like an O of consent form, something like

26:27 Presenter: that. This is not it. This is, I’m going to use this connection which somebody else

26:32 Presenter: Is already shared with you and I’m going to use it in this app and it’s not limited by permissions because it’s whatever you gave the

26:38 Presenter: Token initially all right, so I’m gonna gonna go to this app and now I can actually

26:44 Presenter: Finally see data. This is the sequel server data behind this connection that this app is actually fetching so you can see information about

26:52 Presenter: Customers right this is just like a list of users

26:55 Presenter: And then for each one of those users I can click on a user and I can see information about that user including

27:02 Presenter: This is all generated by chit by chgpt. So thank you open AI for that

27:06 Presenter: And now we want to understand how we can kind of fetch this data in a more

27:11 Presenter: I don’t know robust way and so

27:14 Presenter: Just looking at the requests that this thing is actually sending you can see that all of this information is being fetched

27:20 Presenter: through this request and

27:22 Presenter: Looking at the and at that request. I can see two things so one

27:27 Presenter: I’m sure if that’s gonna work so right here. I’m going to something called as you a PIM

27:32 Presenter: We’ll see that in a moment and here inside of this request URL

27:35 Presenter: You can see this long URL which has something with the enterprise customers table

27:41 Presenter: All right, we’ll try to figure out figure out what that means in a moment, but just to

27:47 Presenter: show you that

27:49 Presenter: Yeah, all right, so

27:52 Presenter: Again, what I’m going to do is just copy this this

27:57 Presenter: Requests and then just replay it and I get all of the all of the information right and so this is just what the app is doing

28:04 Presenter: This is not the entire data behind behind this SQL server, so let’s try and figure out what’s actually going on here

28:11 Presenter: this is

28:12 Presenter: Power up is actually using this endpoint as way a p a p.m. Net to fetch the

28:19 Presenter: Information behind that connection actually any any

28:23 Presenter: Operation that this app would like to do with this connection it will do through this as well p.m. Instance

28:28 Presenter: Okay, so let’s let’s try to figure out this URL it starts with as right apm. That’s just an actual

28:35 Presenter: API gateway that’s hosted in Azure

28:37 Presenter: And all right after that it goes to sequel and then an ID for for this specific connection

28:43 Presenter: If you use the same thing in your power apps instance, then you’ll get the same URL

28:49 Presenter: But just in a different ID you’ll probably not be in Europe, but well and then after the sequel I get I

28:57 Presenter: I need to choose choose the data set

28:59 Presenter: This is because if you authenticate to sequel with your all of token that you have actually access to multiple sequel

29:05 Presenter: SQL servers because this is using your own kind of Azure manager identity and so you can see that I’m

29:12 Presenter: choosing the customer inside database

29:14 Presenter: and the specific enterprise customers data database,

29:18 Presenter: so that’s a server and a database.

29:20 Presenter: And then there’s a request here to tables,

29:24 Presenter: and let me just fix the URL here.

29:26 Presenter: So tables, the name of the table, items.

29:29 Presenter: All right, so this is actually just an interface

29:32 Presenter: to query the SQL server.

29:37 Presenter: So let’s back up for a moment,

29:40 Presenter: and now I need to tell you what the hell is this thing.

Unveiling the API Hub: Token Exchange and Automation

29:44 Presenter: The way that power-ups work, but actually,

29:48 Presenter: this is kind of Microsoft-focused,

29:50 Presenter: but most local local platforms work this way

29:53 Presenter: because they need to be able to impersonate business users

29:56 Presenter: because business users need to be able to create apps

29:58 Presenter: with their own credentials.

30:00 Presenter: And so here’s how it works.

30:01 Presenter: On the left side, you have the app,

30:03 Presenter: and on the right side, you have the API

30:04 Presenter: that it would like to call.

30:06 Presenter: And now there’s this Azure API management thing

30:09 Presenter: that the app will go up to Azure API.

30:14 Presenter: have your credentials it it has the ID for that app and it goes out out to

30:20 Presenter: Azure API management and it says hey on this app please provide me access to to

30:26 Presenter: that specific request through that API and now note that as a user you can

30:33 Presenter: share your credentials with other users you can also share your credentials with

30:37 Presenter: an app all right or an automation the plans of the back on the background

30:41 Presenter: Without without you actually being there all right so what actually happens here is that they have built a token storage

30:48 Presenter: that is

30:49 Presenter: managed inside of this azure API management instance and the tokens get injected every time you

30:56 Presenter: You you reach out with a request, and then they cleaned it up them out on the way back

30:59 Presenter: All right, so this is how it works, and it works like that in with with most with most of the platforms

31:07 Presenter: And so let’s try and take a look

31:09 Presenter: And so again this this this thing is going to allow us we’ve seen I mean we’ve seen one request

31:15 Presenter: But this thing is going to allow us much more than that so

31:20 Presenter: What we have up until now is the ability to well we we went to the UI we copied the request now

31:27 Presenter: We can replay that request that’s fine

31:29 Presenter: But can we actually generate the request without going through the manual processes?

31:35 Presenter: thing. In order to do that,

31:37 Presenter: we need to be able to

31:39 Presenter: make this request. In order to

31:41 Presenter: make this request, we need the token.

31:43 Presenter: Let’s figure out what this token

31:44 Presenter: actually grants us.

31:47 Presenter: Opening out the Jot token

31:48 Presenter: shows that I get an audience

31:51 Presenter: of API hub, azure.com.

31:53 Presenter: This is actually an internal thing

31:55 Presenter: Microsoft created on top of API management

31:56 Presenter: that does this entire

31:58 Presenter: token exchange thing.

32:00 Presenter: What I need is a token

32:02 Presenter: with the right permissions

32:05 Presenter: query this API and the question and that’s that’s the next question we need to answer and so in

32:12 Presenter: order to do that

32:15 Presenter: First remember that I can generate tokens right this is my user. It’s not that’s not that’s not the problem

32:19 Presenter: I need to generate the token with the right resource with the right client

32:23 Presenter: I did to actually allow me to fetch information from this internal API and so

32:29 Presenter: I’m going to use this snippet which is just like using a common Python libraries to generate this token and

32:35 Presenter: I just need to find the right client idea it would allow me to get this resource if I try to use a built-in client app a

32:42 Presenter: Public client app again. This needs to be in the in the guest tenant right so I cannot just

32:47 Presenter: Create an app there so if I if I try to use a public client app

32:50 Presenter: It doesn’t work because the app needs to be pre consented to have that to have permissions to that resource

32:58 Presenter: If I try to use my own app in the in the home tenant and make it a multi tenant app

33:05 Presenter: work because I can’t even ask for that permission.

33:08 Presenter: So if you go to the app and you try to ask for the right

33:10 Presenter: API permissions to query API hub, you won’t find it there

33:14 Presenter: because it’s an internal API.

33:15 Presenter: They didn’t expose it to everybody.

33:18 Presenter: And so we’re kind of stuck.

33:21 Presenter: We were able to copy and then replay that request through

33:27 Presenter: the browser, but that means we can do manual things.

33:31 Presenter: That’s fine.

33:32 Presenter: that’s not like a wide-scale exfiltration thing.

33:37 Presenter: And so let’s try and figure out

33:38 Presenter: how do we get to that token.

33:40 Presenter: And before that, I’m going to do a very quick recap.

33:42 Presenter: So we get access to an account

33:44 Presenter: which is outside of our corporate.

33:48 Presenter: We get a guest account.

33:50 Presenter: We find a bunch of credentials

33:52 Presenter: on this thing called power-ups

33:54 Presenter: which business users are building

33:55 Presenter: and then sharing those connections with everybody.

33:59 Presenter: We try to get access.

34:00 Presenter: We are blocked by license.

34:02 Presenter: so we just got a license

34:04 Presenter: we were blocked by DLP and

34:07 Presenter: then I did a bunch of hand waving and we’ll move forward and

34:12 Presenter: We were blocked by a programmatic by being able to program get programmatic access to API hub

34:17 Presenter: And that’s the last thing that’s stopping us from getting access to those credentials

34:22 Presenter: And so we need an AID app that is able to do a few things one

34:26 Presenter: It needs to be owned by default because this needs to be already available in the guest tenant which I cannot change

34:32 Presenter: It needs to be pre-approved to query this API hub thing.

34:35 Presenter: And it needs to be a public client because I need to be able to generate tokens.

34:38 Presenter: If it’s a confidential client that I need a certificate in order to generate tokens,

34:43 Presenter: then I won’t have that certificate.

34:46 Presenter: And so let’s try to get that.

34:49 Presenter: We already know of one app that is able to generate those tokens,

34:53 Presenter: and that’s, of course, PowerAppsPortal, right?

Building the PowerPoint Tool: Automating Data Exfiltration

34:55 Presenter: Because that’s where we found this token.

34:58 Presenter: And so this is on by default.

34:59 Presenter: Every tenant will have PowerApps.

35:02 Presenter: to query API hub, but unfortunately it’s a,

35:05 Presenter: it’s not a public client application.

35:06 Presenter: They’ve done their job well here,

35:07 Presenter: so it’s a confidential app.

35:09 Presenter: You can’t just generate tokens on its behalf.

35:11 Presenter: And so what can we do in order to circumvent this thing?

35:16 Presenter: We can use this very clever piece of research.

35:19 Presenter: I’m not sure how many of you are aware.

35:21 Presenter: If not, I really recommend you go out and read this.

35:25 Presenter: Basically, think about what happens

35:27 Presenter: when you log into one Microsoft app, like Teams,

35:32 Presenter: to another Microsoft apps like Outlook,

35:34 Presenter: and you don’t get re-authenticated.

35:36 Presenter: Something happens there.

35:38 Presenter: These are different apps in different domains,

35:40 Presenter: different tokens.

35:41 Presenter: If you look at the tokens, you’ll see different tokens.

35:43 Presenter: So the way that this works

35:45 Presenter: is that there’s undocumented behavior

35:47 Presenter: on the AAD side

35:48 Presenter: that allows you to exchange one refresh token

35:51 Presenter: with one client ID and one resource permission

35:53 Presenter: with another refresh token,

35:55 Presenter: with another client ID

35:58 Presenter: and another refresh token

35:59 Presenter: and another resource.

36:02 Presenter: entire the entire Microsoft suite of products so there are I think we’ll see

36:07 Presenter: in a moment a list but something like 20 different client IDs which you can just

36:13 Presenter: exchange the tokens between them seemingly without without seamlessly

36:17 Presenter: without the user knowing so if you get a refresh token to one of them you

36:20 Presenter: actually get all of them this also allows you in some cases to buy first

36:24 Presenter: things like MFA but check out this research it’s really cool and so this is

36:28 Presenter: going to help us because if we look at those client IDs, this is the list of the client

36:33 Presenter: IDs that are currently public that we all, that we’ve already identified as a community.

36:38 Presenter: You’ll find two things that are really helpful here. One is power-ups, which is actually

36:43 Presenter: helpful, right? This is what we need. And the other is the Microsoft Azure CLI, which

36:47 Presenter: is of course something I can very easily generate tokens for, all right? So now you can see

36:52 Presenter: the solution, right? I’m gonna, I’m gonna authenticate to Azure CLI with permissions

36:58 Presenter: with Azure CLI, just query the Azure graph,

37:01 Presenter: the Microsoft graph or something,

37:03 Presenter: and then I’m just gonna exchange that token

37:05 Presenter: for an API hub token.

37:07 Presenter: Because power-ups can, can get access

37:09 Presenter: to this API hub token.

37:11 Presenter: And so this is exactly what, what I’m going to do,

37:13 Presenter: and this is how this screenshot actually shows

37:16 Presenter: how it looks like to use the tool

37:18 Presenter: that I’m gonna drop in a second,

37:20 Presenter: which allows you to, again, this is, this is,

37:23 Presenter: this is what you, what you,

37:25 Presenter: the permissions that you need to provide, right?

37:29 Presenter: Microsoft Azure CLI and then you have you get a whole bunch of goodies from

37:32 Presenter: Kind of you get different tokens that in specifically here. I’m I’m looking for the API hub token

37:39 Presenter: Alright, so now that we’ve solved this problem. Let me show you what I can do with it

37:45 Presenter: This entire thing is just gonna be a demo of PowerPoint PowerPoint is a tool that I’m releasing today

37:51 Presenter: You can find it in github already. It’s actually a kind of a the next version of something. I put in I

37:58 Presenter: Defcon last year and PowerPoint is going to allow you to do everything I explained so far and actually much more

38:06 Presenter: So PowerPoint has different modules

38:10 Presenter: The dump module which we’re gonna talk about right now

38:13 Presenter: There are also three models. I’m not gonna talk about

38:16 Presenter: Creating a backdoor which is actually a backdoor that persists through even if you delete the user

38:22 Presenter: phishing campaigns inside of an org no code malware which is a reference to kind of a

38:28 Presenter: Less at the Defcon last year check this out. This is a kind of just people are doing really really cool things with this already and so

38:38 Presenter: We’re gonna focus on this part and so what I’m going to do is just run a powerpoint dump and I’m gonna

38:43 Presenter: And this is the ID for the guest tenants

38:46 Presenter: And then it’s gonna wait a kind of think for a second. It’s gonna acquire a token first of all to power ups

38:53 Presenter: And with that token to power ups

38:55 Presenter: I’m going to go to device login of course you can use the token that you get from somewhere else

39:02 Presenter: Whatever you’d like

39:04 Presenter: I’m going to authenticate why them authenticated as the hacker user

39:10 Presenter: Okay, and now it’s going to first of all enumerate all of the different resources that they have access to

39:17 Presenter: I showed you connections credentials, but actually I have access to much more. We’ll see that in a moment

39:22 Presenter: And so I started with the token to power-ups

39:25 Presenter: Through the token to power-offs, I was able to identify six applications that are available for me as a guest to use and also nine credentials

39:35 Presenter: And now I’m going to exchange this token for an API hub token and I’m going to use this API hub token

39:42 Presenter: To actually go through each one of those credentials and dump and dump that credential

39:48 Presenter: And I’m fetching some API specs for that you’ll see that in a moment and so and by the time this is finished

39:55 Presenter: Now the dump is already on your drive.

39:57 Presenter: You can see a few things here.

39:59 Presenter: So one is that these are all of the types of connections

40:02 Presenter: where I found that were, that I found that were,

40:05 Presenter: that were shared.

40:06 Presenter: And I’m actually generating a,

40:08 Presenter: well you said it in a moment.

40:10 Presenter: There’s actually the data behind those connections.

40:12 Presenter: So here’s for example the SQL server that we saw earlier.

40:15 Presenter: You can see the different tables that exist

Mitigations and the Shared Responsibility Model

40:17 Presenter: in the SQL server.

40:18 Presenter: And if I look into any one of them,

40:21 Presenter: then I see a full dump of that table.

40:24 Presenter: I also have a nice little GUI for you to just kind of use.

40:29 Presenter: And this GUI shows all of the different things that I was able to find in this tenant.

40:33 Presenter: You can see that there are credentials, automations, and applications.

40:36 Presenter: Applications you can, you can go into those applications and see what they have.

40:40 Presenter: Automations you can, you can actually run those automations.

40:44 Presenter: Okay, you can, you can, and then those automations can do a whole bunch of different things.

40:48 Presenter: Clicking on credentials would show you the credentials we saw earlier in this talk.

40:53 Presenter: So these are available here.

40:54 Presenter: And so the first thing you can do is go to dump.

40:56 Presenter: You go to dump.

40:57 Presenter: You see all of the tables.

40:59 Presenter: Here’s the data for this entire SQL server

41:01 Presenter: with the generated social security numbers.

41:06 Presenter: You can also kind of look at other queries here.

41:11 Presenter: And the other thing that’s interesting here

41:13 Presenter: is that there’s a playground

41:15 Presenter: where we are actually generating a Swagger UI

41:17 Presenter: for each one of those connections.

41:19 Presenter: So you can actually dynamically use these things

41:23 Presenter: to push whatever you’d like through these connections,

41:26 Presenter: specifically with SQL, note SQL pass through native query.

41:29 Presenter: This allows you to just run whatever you’d like on the server,

41:33 Presenter: which is kind of awesome.

41:35 Presenter: So, and you can use the Swagger API to do that.

41:38 Presenter: That’s great.

41:41 Presenter: Check out the tool.

41:42 Presenter: There’s plenty of more things you can do with it.

41:44 Presenter: And we’re gonna give a few demos at Arsenal

41:47 Presenter: that cover what I’ve covered today,

41:49 Presenter: but also other scenarios you can do with the same tool.

41:55 Presenter: All right, so in the like four minutes or three minutes I have left

42:00 Presenter: Okay, I need to I need to give you something

42:04 Presenter: All right, so here’s what first of all I’m gonna say this has been like we’ve strongly collaborated with Microsoft

42:13 Presenter: Throughout this entire thing they are aware of it. They’re trying to fix what they can fix

42:17 Presenter: They are trying to make defaults better

42:19 Presenter: We have some of the mitigations that I’m just that I’m going to share with you right now. We’ve actually collaborated on

42:25 Presenter: creating them

42:27 Presenter: There are no in this stock what you’ve seen right now. There are no kind of vulnerabilities

42:32 Presenter: There’s just like I don’t creative reading of the docs and so

42:36 Presenter: I’m just gonna show I’m gonna brief very very briefly here

42:40 Presenter: I think the number one thing that we are missing is that if we think about the shared responsibility model for for example serverless

42:49 Presenter: right? But with low code, with the things that business users are building, we think,

42:53 Presenter: hey, that’s probably secure. The vendor is in charge of everything. That’s, of course,

42:58 Presenter: not true. I mean, you don’t own the code, fine, but you own the business logic because

43:02 Presenter: they are using these tools to create business logic which doesn’t make sense. For example,

43:07 Presenter: an app that impersonates its own users. If you’re interested in that part, I’m going

43:12 Presenter: to explain a lot more about it in a talk tomorrow called something like show that business users

43:20 Presenter: what could go wrong.

43:22 Presenter: And so, again,

43:24 Presenter: the shared responsibility

43:25 Presenter: model applies here as well.

43:27 Presenter: The platforms themselves need to own their part

43:29 Presenter: and if you’re looking

43:31 Presenter: at news, just last week,

43:33 Presenter: Tenable found a crucial

43:35 Presenter: multi-tenant vulnerabilities in this specific

43:37 Presenter: organization, in this specific platform

43:39 Presenter: that allowed them to basically replace

43:41 Presenter: your code with somebody else’s code

43:43 Presenter: and do whatever they like,

43:46 Presenter: unauthenticated. But you as a

43:49 Presenter: to own your part. If you help, if you are, if you work for a

43:53 Presenter: large Microsoft shop or you help a large Microsoft shop, can

43:57 Presenter: you answer those questions? Like, what are your business

44:00 Presenter: users are building? Who are they sharing with? What is the

44:03 Presenter: data that they are actually using? I think the answer is

44:07 Presenter: probably no. This needs to be part of AppSec. And so we need

44:12 Presenter: to start carrying our own. And so now, in order to protect

44:19 Presenter: I’m gonna just send out, send you out in a few different directions.

44:23 Presenter: All of the links are gonna be there, okay?

44:27 Presenter: One minute?

44:29 Presenter: Okay.

44:30 Presenter: So very quickly, don’t overshare credentials.

44:33 Presenter: That’s kind of obvious, right?

44:35 Presenter: This is for developers.

44:37 Presenter: There’s also a project called the OWASP Low Code, No Code Top 10, which would illustrate

44:42 Presenter: all of the different things that could go wrong when business users create applications,

44:45 Presenter: and this is actually speaking in a language

44:47 Presenter: that business users can understand.

44:49 Presenter: So you can just send them to those links

44:51 Presenter: and they’ll hopefully understand

44:53 Presenter: what they need to do better.

44:55 Presenter: You can harden your environment.

44:57 Presenter: There’s secure configuration you can apply.