Abstract
EntraID guest accounts are widely used to grant external parties access to enterprise resources, with the assumption that these pose little security risk. This assumption is dangerously wrong. This session will show how guests can bypass limitations and gain unauthorized access to corporate Azure resources and SQL servers and share concrete steps to harden configuration to prevent such attacks.
Transcript
AI generated from recording.
Opening Remarks and Session Overview; Introducing Guest Access in Microsoft Entra ID; Why Guest Access Exists and Its Intended Use Cases
00:00 Presenter: All right. Thank you, everyone. Good morning. We are going to start by having some fun. I’ll probably start the conference for all of us. We’re going to have time at the end, but actually, if you have interesting questions while I go through things, feel free to raise your hand.
00:28 Presenter: We’ll go through the disclaimer.
00:29 Presenter: Actually, before we get to that, hi.
00:32 Presenter: My name is Michael.
00:35 Presenter: I’m the CTO and co-founder of a company called Zenity.
00:39 Presenter: I’ve been focused on security for low-code, no-code apps, citizen development, recently
00:45 Presenter: Gen.AI for the last five years.
00:49 Presenter: I also run the OWASP low-code, no-code top 10.
00:51 Presenter: So this comes at kind of multiple angles.
00:56 Presenter: I’m part security researcher, a gun kind of entrepreneur.
01:01 Presenter: This talk is going to be focused on guest access within Entry ID and trying to figure out the real boundaries of what these guests can do.
01:15 Presenter: We’re going to start by figuring out why this mechanism even exists.
01:18 Presenter: So why is there a mechanism for people to invite guests into their tenant?
01:24 Presenter: Next, we will uncover the true surface that guests bring, the risk surface, the attack
01:33 Presenter: surface that guests bring into your enterprise.
01:38 Presenter: There would be, we will look at the difference between the promise of guests and the actual
01:43 Presenter: reality.
01:44 Presenter: we’re going to look at three different things
01:47 Presenter: teams
01:48 Presenter: teams based phishing, we’re going to look at
01:50 Presenter: enumeration and then we’re going to look at
01:52 Presenter: PowerPoint which is actually my part of the
01:53 Presenter: my contribution here in terms of research
01:56 Presenter: and we’re going to finish with
01:58 Presenter: a few comments on
02:00 Presenter: how we can protect your organization
02:02 Presenter: when you get back home
02:03 Presenter: next week
02:05 Presenter: this section
02:07 Presenter: we can also continue to kind of go
02:10 Presenter: through it in the Q&A, in the last year
02:12 Presenter: or so I’ve been working with multiple
02:14 Presenter: enterprises to try and figure out how to create a better guest strategy following these findings.
02:20 Presenter: So please feel free to interject.
02:23 Presenter: All right, let’s get started.
02:26 Presenter: So why invite guests in?
02:29 Presenter: Why does this mechanism even exist?
02:31 Presenter: So let me start with a story.
02:34 Presenter: I work for, so my company is very small.
02:38 Presenter: We have like 40 employees and we work with large enterprises.
02:42 Presenter: So the first thing you have, the first problem you need to go through when you want to start
02:47 Presenter: to collaborate is how do you share files?
02:49 Presenter: There are plenty of things you want to share.
02:52 Presenter: How do you do it?
02:54 Presenter: This is a problem that you need to solve from the get-go.
02:57 Presenter: Now, there are plenty of ways for you to try and do that.
03:01 Presenter: One thing you can do is just share those files over email.
03:05 Presenter: Of course, none of us have ever done that, right?
03:08 Presenter: Shared sensitive files over email.
03:10 Presenter: that’s not a good way to do it.
03:12 Presenter: You could also, like back in the old days,
Threat Landscape: Guest Access Risks and Attack Vectors
03:15 Presenter: you could get somebody with a USB or something.
03:18 Presenter: That too is probably not the right way to go.
03:21 Presenter: So in order for this thing to actually,
03:28 Presenter: I mean, there needs to be a better solution.
03:32 Presenter: The better solution for that from Microsoft
03:37 Presenter: is the guest mechanism.
03:39 Presenter: Now, there are also other things that are kind of enterprise file sharing, but guests give you more.
03:44 Presenter: Guests allow you to actually get access to multiple resources within your enterprise.
03:51 Presenter: In order for guest access to be successful, two things need to happen.
03:57 Presenter: One, it needs to be very easy for vendors to onboard.
04:01 Presenter: It needs to be very easy for every vendor to plug in their own identity,
04:06 Presenter: whether they’re using Microsoft, they’re using Okta, whatever they’re using, and they need to be able to log in to your enterprise.
04:14 Presenter: The second thing is that it needs to be very easy for IT and security to control, because otherwise you’ve just invited somebody into your home, right?
04:21 Presenter: So let’s look at the two of those.
04:25 Presenter: For the first one, getting guest access into Active Directory or into Entry ID under default
04:36 Presenter: configuration is very easy.
04:40 Presenter: The choice is left to business users, not to admins.
04:44 Presenter: So you’re seeing a bunch of ways here where through Teams, through SharePoint, people
04:50 Presenter: that are not administrative, they are just like normal business users, they can plug in
04:55 Presenter: an email for somebody else that’s outside of your enterprise. It could be a Gmail account,
05:00 Presenter: it could be your competitor, whatever it is, and they are invited into the tenant. Now,
05:05 Presenter: they are invited as guests. They are provision-specific access. We’ll get into that in a moment.
05:11 Presenter: But the mechanism allows… The reason why this exists is collaboration, ease of collaboration.
05:17 Presenter: So, AMSO 65 is a collaboration platform and you want to collaborate with other folks across
05:24 Presenter: the industry, you need a way to have that conversation with them.
05:27 Presenter: So again, this first point I just covered, that happens.
05:31 Presenter: So, it is very easy to get guest access.
05:36 Presenter: Actually, before I go to that, there’s also more than the fact that there’s guests that
05:46 Presenter: everybody can provision access for those guests.
05:49 Presenter: There’s also research in the recent years
Teams‑Based Phishing and Credential Exposure
05:52 Presenter: into different parts of, different problems that can occur here
05:56 Presenter: and there are ways for hackers to actually steal
06:00 Presenter: or there were ways and grab away
06:05 Presenter: unredempted tokens, unredempted invites
06:08 Presenter: and grab them for themselves. If you’re interested, there’s a link at the end of the presentation.
06:12 Presenter: The second thing is that it needs to be easy for IT and security to control.
06:19 Presenter: Now, the way that this works is that on one side, on the left side, you have the identity
06:26 Presenter: provider for your guest and on the right side here you have the identity provider for your
06:30 Presenter: organization.
06:31 Presenter: The cool thing about the guest mechanism is that once this link is established, all of
06:38 Presenter: the security controls, the entire Microsoft Security Suite applies to that guest. You
06:43 Presenter: can apply conditional access policies, you can apply kind of MFA requirements. This is
06:48 Presenter: why this is a cool mechanism. This is the crux of why this mechanism is good. So it’s
06:56 Presenter: easy for IT and security to control because you already have your existing controls. But
07:02 Presenter: So there seems to be a problem here.
07:05 Presenter: So we need to provision guest access.
07:09 Presenter: And that guest access requires, in order to do that, we need security controls, right?
07:14 Presenter: So in order to have those security controls, we invite the guest into our tenant, right?
07:20 Presenter: Because that’s the way to apply those controls.
07:22 Presenter: But now that we’ve invited the guest into the tenant, they have full access, that sounds
07:28 Presenter: weird, right?
07:29 Presenter: That shouldn’t be the case.
07:32 Presenter: That is not the case that we are trying to make here.
07:38 Presenter: What’s actually going on is that you should not have full access.
07:42 Presenter: You should not be just any user.
07:44 Presenter: You should have a special kind of access, which means everything is denied by default.
07:49 Presenter: You only have access to the things that you were explicitly granted access to.
07:53 Presenter: That’s why the guest mechanism works.
07:56 Presenter: works. That’s the
07:59 Presenter: crucial piece that we need
Enumeration of Tenant Resources by Guests
08:00 Presenter: to examine to make sure that
08:02 Presenter: this mechanism does what it’s supposed
08:04 Presenter: to do. Otherwise, you’ve just invited
08:07 Presenter: another employee into your
08:08 Presenter: tenant, like
08:11 Presenter: another guest into your tenant, which
08:12 Presenter: has the same access as an employee.
08:16 Presenter: Alright.
08:17 Presenter: As a recap,
08:18 Presenter: it’s very easy to get a guest account.
08:21 Presenter: Your threat model should include
08:24 Presenter: threat actors
08:26 Presenter: just get a guest account.
08:28 Presenter: It’s just so easy.
08:30 Presenter: There are also sign up portals.
08:32 Presenter: There’s plenty of ways to get that.
08:34 Presenter: Not to mention just somebody compromising one of your vendors.
08:38 Presenter: The second piece is that entry ID security controls apply.
08:42 Presenter: This is how you try to bring structure
08:44 Presenter: into what these guests are doing.
08:46 Presenter: And this all lies on the assumption
08:49 Presenter: or the proposition that access is denied by default.
08:55 Presenter: Now let’s look into that.
08:57 Presenter: Let’s look into what, that was the promise.
09:00 Presenter: Now we’re gonna look at reality.
09:01 Presenter: And we’re gonna see some key differences.
09:05 Presenter: The first thing I wanna,
09:08 Presenter: so let’s start with kind of getting guest access.
09:13 Presenter: So here I am in Teams.
09:15 Presenter: You can see the little icon on the right button side.
Exploiting Power Apps: Credential Sharing and API Abuse
09:18 Presenter: This is the user icon.
09:23 Presenter: In a few slides, I’ll switch to the hacker side and then you’ll have a different icon
09:29 Presenter: that will help you understand which account is logged in.
09:33 Presenter: So this is just a user, a normal user in your organization.
09:36 Presenter: They go into teams.
09:38 Presenter: They want to invite somebody into a specific team.
09:41 Presenter: So they’re going to invite a hacker.
09:44 Presenter: Why not?
09:44 Presenter: This is just a hacker email.
09:46 Presenter: Once I plug this email there, you can see this little
09:52 Presenter: banner pops up, add a hacker as a guest.
09:55 Presenter: Sounds great, I’m just gonna click on it.
09:57 Presenter: That’s it.
09:59 Presenter: That’s it.
10:00 Presenter: Alright?
10:01 Presenter: That’s what, that is all, that is the only thing that’s
10:04 Presenter: required to get those guests in.
10:06 Presenter: Once the guest is in, now as a hacker, you can see the
10:10 Presenter: hacker icon, I log in to my hacker tenant, of course, this
10:16 Presenter: my tenant now, I have the password, right?
10:19 Presenter: I log in, I need to consent to be invited into this tenant
10:24 Presenter: and once I’m in, I go to my apps and it’s empty
10:29 Presenter: because it’s denied by default, right?
10:31 Presenter: So everything works and we can stop the presentation
10:35 Presenter: right now and go wrong, right?
10:39 Presenter: Yeah, let’s start with the first thing,
10:42 Presenter: teams-based phishing.
10:46 Presenter: So, Teams is now the way enterprises communicate.
10:51 Presenter: One of the problems with Teams is that on one side, it’s an enterprise platform.
10:57 Presenter: On the other side, it’s a collaboration platform.
10:59 Presenter: These things sometimes don’t mix well.
11:01 Presenter: And so, one feature that Teams has is that any user under default settings, any user in one tenant can send a message to a user in another tenant.
11:13 Presenter: All right, so somebody from another company reaches out to you by team.
11:18 Presenter: Now we are all used to defect the teams is internal.
11:22 Presenter: This confusion is being used by hackers.
11:26 Presenter: So here’s an example, this is from a Microsoft blog.
11:29 Presenter: There’s a security tool called Team Fisher.
11:32 Presenter: And Team Fisher allows you to extend phishing operations to teams.
11:39 Presenter: Now, the cool thing that the Team Fisher does is that not only uses the fact that you can
11:45 Presenter: converse with somebody on somebody else, that you can send a message to somebody else in another
11:50 Presenter: tenant, it also bypasses security mechanisms put by Microsoft and allows that guest to send an
11:56 Presenter: attachment. That should not be possible, but it’s still possible with Team Fisher. You can try it
12:01 Presenter: out, it’s an open source tool. So with Team Fisher, somebody else from outside of your tenant, from
12:09 Presenter: tenant let’s say a hacker control tenant can send a message to one of your
12:13 Presenter: employees with an attachment that could have malware in it all right that’s the
12:18 Presenter: that’s the way that this is this breaks in now this is not a hypothetical you can
12:24 Presenter: see you can see a title here from MSR former Microsoft threat logs you
12:31 Presenter: probably identify the the APT involved here this is the they are persistent at
12:40 Presenter: Microsoft enlarge Microsoft chops.
12:44 Presenter: This is how this looks like.
12:46 Presenter: So you are inside of Teams and you get this message.
12:51 Presenter: And its message, so can you spot the fact
12:54 Presenter: that this user is external?
12:59 Presenter: So like trying to help you here.
13:04 Presenter: Can you see this?
13:05 Presenter: All right, this is your protection mechanism.
13:10 Presenter: So you have somebody external, they log in, there’s an attachment.
13:17 Presenter: This is something that has been exploited by multiple APTs.
13:21 Presenter: Actually, other APTs are using it not just to send out malware, but also to bypass MFA protection.
13:30 Presenter: so you get a message from somebody in Teams
13:34 Presenter: and this is their name.
13:36 Presenter: You can see it here.
13:38 Presenter: Microsoft Identity Protection
13:39 Presenter: and you can see the domain here.
13:41 Presenter: If you spot it just right,
13:42 Presenter: you’ll see that this is not the right domain.
13:44 Presenter: But APTs are using it to reach out to you
13:46 Presenter: and say, hey, you just received an MFA code.
13:49 Presenter: Please give it to me.
13:51 Presenter: So one thing that you can do as a guest
13:54 Presenter: is the fact that you abuse the fact
13:58 Presenter: that Teams is a collaboration platform
14:01 Presenter: take phishing out of email into Teams.
14:05 Presenter: Just to kind of make sure we’re all on the same page here,
14:08 Presenter: this is the same problem.
14:09 Presenter: There’s the same problem with Slack, right?
14:12 Presenter: This is about collaboration platforms
14:14 Presenter: and what happens when you try to have both enterprise
14:19 Presenter: and collaboration at the same time.
14:21 Presenter: Let me show you another thing.
14:23 Presenter: Guests are not supposed to be able to enumerate your tenant, right?
14:26 Presenter: You invite guests in, they are not supposed to be able to see
14:32 Presenter: Okay, so as a guest, you try to log into entry ID.
14:35 Presenter: Indeed, you don’t have access.
14:37 Presenter: But if you use a tool called the internals,
14:40 Presenter: then you do get like a full access, a full list,
14:43 Presenter: or not a full list, but a large list of users in that tenant.
14:47 Presenter: Now, the way that this works is pretty neat,
14:50 Presenter: pretty sophisticated.
14:51 Presenter: This is not the focus of the talk,
14:52 Presenter: so I’m not gonna go deep into it.
14:53 Presenter: But basically, as a guest, you can enumerate every group
14:57 Presenter: you are a part of.
14:59 Presenter: Now you are a part of the guest group by default,
15:02 Presenter: and then from there you can enumerate the guest group
15:05 Presenter: and then enumerate the groups for every user
15:08 Presenter: that you’ve already seen, and this is a recursive process,
15:11 Presenter: and then you get a loud list.
15:12 Presenter: So check out AAD Internals, it’s out there.
15:15 Presenter: It’s a really cool and powerful tool.
15:19 Presenter: What we’ve seen up until now is actually not enough
15:25 Presenter: because hackers need more.
15:26 Presenter: They are looking for ways to actually access company data, to delete that data, maybe to actually perform operations on that data.
15:36 Presenter: All right, so now let’s switch gears and go to the main part of the talk.
15:45 Presenter: This is the moment in the talk where you get a choice.
15:49 Presenter: Because in the next slide, I’m going to ruin your next week.
15:53 Presenter: And so it’s perfectly okay to go have an early lunch, go have a drink, whatever you, that’s fine.
16:02 Presenter: This is your chance.
16:04 Presenter: No takers?
16:07 Presenter: All right.
16:09 Presenter: As a guest, when I click on this link, it takes me to something you can see here, something called Power Apps.
16:17 Presenter: It’s part of the Power Platform ecosystem.
16:20 Presenter: And the first thing that I get is this hello screen.
16:24 Presenter: And then I get the disconnect.
16:27 Presenter: This is basically saying, hey, you are not part of this tenant.
16:32 Presenter: So it logs me into my home tenant.
16:35 Presenter: You can see here that I’m logged into something called Pontoso.
16:38 Presenter: This is the hacker website.
16:40 Presenter: This is a gift.
16:42 Presenter: The name is a gift to Microsoft.
Defensive Measures and Shared Responsibility
16:46 Presenter: I can click on Pontoso and then I switch the directory.
16:49 Presenter: You can see that I have kind of all of the different tenants that I belong to as the hacker.
16:53 Presenter: switch to the guest tenant. Once I switch to the guest tenant, I’m not sure where I am
17:00 Presenter: right now, but let’s understand what we’re seeing. We are seeing a list of something
17:06 Presenter: called connections. Each of these connections have these icons that can help you understand
17:12 Presenter: what they are. So SQL Server, Azure Resources, Blob Storage. You can see the different names
17:19 Presenter: that are indicated here.
17:22 Presenter: Enterprise financials, sounds interesting.
17:24 Presenter: Customer data, sounds interesting.
17:28 Presenter: So this is already weird.
17:31 Presenter: A guest should not have access to a list of credentials
17:34 Presenter: sitting somewhere in Office 365.
17:37 Presenter: Let’s try to figure out what we are looking at.
17:39 Presenter: So checking out the first thing, like Azure Blob Storage.
17:42 Presenter: So you can see that there is a nice little menu here.
17:47 Presenter: and I have a few different things I can do on these credentials.
17:53 Presenter: One of them is share.
17:55 Presenter: Now a share button on a credential should raise your eyebrows.
18:01 Presenter: That’s the original thing right there.
18:04 Presenter: So if I click on share, I can see that this specific credential
18:09 Presenter: to file storage, you can see the storage right here,
18:13 Presenter: is shared with three different entities.
18:16 Presenter: org, which actually means everyone.
18:19 Presenter: Everyone in your tenant.
18:21 Presenter: Everyone including guests.
18:22 Presenter: Everyone.
18:24 Presenter: It’s shared with Jamie.
18:26 Presenter: And you can see the address right here.
18:29 Presenter: This is the actual tenant that we’re breaking into.
18:31 Presenter: And the last thing is Jamie’s Outlook account.
18:34 Presenter: Personal Outlook account.
18:35 Presenter: Because why not?
18:38 Presenter: This is the problem.
18:40 Presenter: Alright?
18:41 Presenter: This is why we are seeing this credential.
18:44 Presenter: So now let’s try and figure out, well, what’s behind this.
18:48 Presenter: So I look at details, and then I get a bunch of information about this connection.
18:52 Presenter: I can see that the owner is Jamie Redding.
18:55 Presenter: This is the same Jamie that we saw earlier.
18:58 Presenter: And now using Teams, I can try and figure out who Jamie is.
19:01 Presenter: Jamie is a customer success representative.
19:04 Presenter: Jamie actually does not exist, but in this example,
19:07 Presenter: Jamie is a customer success representative.
19:09 Presenter: Jamie is a business user.
19:10 Presenter: So a business user creates a credential, creates a connection.
19:15 Presenter: We’ll see in a moment why.
19:17 Presenter: And they just share it.
19:19 Presenter: So why this is happening?
19:20 Presenter: Well, this is happening.
19:24 Presenter: Let’s check out Copilot for Power Apps.
19:27 Presenter: So to get started, what we’re going to do is we’re going to say,
19:28 Presenter: make me an app to track my Star Wars and Legos hoists.
19:31 Presenter: And then we’re going to say, create an app.
19:35 Presenter: There you can see it made us a table with a bunch of sample items
19:38 Presenter: and a bunch of columns, right?
19:40 Presenter: built force we didn’t do any of that?
19:42 Presenter: Wasn’t expecting the sound.
19:44 Presenter: But what you’re seeing here
19:45 Presenter: is actually that you can have a conversation
19:48 Presenter: with something that looks like ChGPT
19:50 Presenter: and on the background it generates
19:52 Presenter: an app for you. Imagine every
19:54 Presenter: conversation you had with ChGPT
19:56 Presenter: ends up with an app
19:58 Presenter: that everybody can use.
20:00 Presenter: Now this is just one way to build those apps.
20:03 Presenter: Actually business users are dragging
20:04 Presenter: and dropping ever since
20:06 Presenter: I think this came out in
20:10 Presenter: They are creating their own applications, their own automations.
20:12 Presenter: I’m working with organizations that have hundreds of thousands of these.
20:17 Presenter: So of course they are going to make mistakes.
20:19 Presenter: These are business users.
20:20 Presenter: They have no idea about security implications.
20:24 Presenter: Nor should they, right?
20:25 Presenter: They are not security experts.
20:29 Presenter: If you try to, like one thing you can do right now to try and
20:33 Presenter: get yourself off the hook and think that this is not your problem,
20:37 Presenter: is to say, hey, no, we don’t have citizen development.
20:40 Presenter: is going to do it in my organization.
20:41 Presenter: We’re a financial service.
20:43 Presenter: I’ve heard this.
20:44 Presenter: Let me try to convince you that you’re not in a position to say that.
20:50 Presenter: According to Microsoft, this is from last year,
20:53 Presenter: according to Microsoft, there were 5 million C-sharp developers,
20:57 Presenter: .NET developers, last year.
20:59 Presenter: How many citizen developers do you think there were?
21:03 Presenter: So according to Microsoft earning reports that I went through one by one,
21:07 Presenter: about 8 million.
21:10 Presenter: last year all right so way more citizen development than C sharp development how
Q&A and Closing Remarks — Part 1
21:15 Presenter: much security effort are we investing in those social developers versus the
21:19 Presenter: citizen developers right so of course we’re gonna problem of course we’re gonna
21:24 Presenter: pick it because we are not holding any part any of our part in the shared
21:28 Presenter: responsibility model so these numbers they so they don’t work for Microsoft
21:34 Presenter: they work for you those people right now I just to get it straight this is
21:40 Presenter: like they are getting productive,
21:42 Presenter: they are moving your business forward,
21:43 Presenter: but they need guardrails.
21:45 Presenter: And so this is why you get these overshared credentials,
21:49 Presenter: where somebody shared it with the entire org
21:51 Presenter: or some of the Outlook.
21:52 Presenter: Because they are making choices they are quick to make.
21:55 Presenter: Okay, now let’s look at what we can do with it.
21:59 Presenter: So, back to this specific connection,
22:03 Presenter: you can see two different tabs here,
22:06 Presenter: apps that are using these connections and flows,
22:08 Presenter: these are automations using these connections looking into apps there’s an
22:11 Presenter: application called customer customer is inside here let’s login okay so I get
22:17 Presenter: this this kind of bunch of information about this application and a link okay
22:22 Presenter: now I can click on that link and well I get a problem I get an arrow here and I’m
22:30 Presenter: not sure if you can see this but it’s telling me that I don’t have a license
22:35 Presenter: So I don’t have the right license to actually view those apps.
22:39 Presenter: Now here’s a clue into how we’re going to circumvent that.
22:43 Presenter: Let’s read this out.
22:45 Presenter: You don’t have the correct plan to access this app.
22:48 Presenter: Ask your admin for one or ask the admin at the organization at which you’re a guest.
22:54 Presenter: What are we going to do now?
22:57 Presenter: What happens if I have a license in my home tenant, not my guest tenant?
23:03 Presenter: Shouldn’t work, right?
23:05 Presenter: to get a trial license from Microsoft.
23:08 Presenter: So I’m gonna say, hey, I’m a hacker,
23:09 Presenter: please give me a trial license,
23:11 Presenter: and Microsoft’s gonna say, yeah, great.
23:13 Presenter: Of course, this is my home tenant, not the guest tenant.
23:18 Presenter: All right, I can get any license I want.
23:21 Presenter: And now, of course, I’m in, because why not?
23:23 Presenter: If you have a license on one tenant,
23:25 Presenter: it works for the other tenants.
23:28 Presenter: The next problem that I get is that there’s something,
23:32 Presenter: something stopping me again from logging in.
23:34 Presenter: You can see something about data loss prevention,
23:40 Presenter: a policy named denying Azure file storage,
23:44 Presenter: something like that.
23:45 Presenter: So we were able to bypass license requirement,
23:48 Presenter: but we were blocked by DLP.
23:51 Presenter: I mean, this should be a good thing right now.
23:55 Presenter: So DLP being built into Power Platform, that’s great, right?
24:00 Presenter: So, incredible, let’s create a DLP policy to find social security numbers or to label data related to social security numbers.
24:10 Presenter: So I’m going to start with the title and then I need to choose connectors and there’s all sorts of Microsoft apps here, SharePoint, OneDrive.
24:23 Presenter: Actually, this is not DLP.
24:25 Presenter: I mean, at least it’s not DLP in the security sense that we are used to.
24:30 Presenter: DLP in the security sense means something very specific.
24:33 Presenter: It means that you can label things, that you have data exfiltration protection.
24:37 Presenter: This is not that.
24:39 Presenter: This is an allow and deny list for the kinds of apps that business users would be able to use.
24:45 Presenter: Kind of note the fact that this says SharePoint.
24:48 Presenter: It doesn’t say my SharePoint, your SharePoint, which site.
24:51 Presenter: There are more advanced mechanisms here, but they are still, at the end, allow and deny list.
24:57 Presenter: On top of that, I’m sorry to say this, but it’s full of holes.
25:03 Presenter: So these are one of the hobbies that we have, is to find loopholes in DLP policies.
25:10 Presenter: We know of at least five.
25:12 Presenter: You’ll soon find out the sixth one, but you can find details right here.
25:16 Presenter: These are all well documented.
25:19 Presenter: this is not to say that this is not a good mechanism.
25:22 Presenter: It’s just to say that it’s not a security boundary.
25:24 Presenter: It’s a governance tool.
25:26 Presenter: It’s a good governance tool.
25:28 Presenter: It’s not a security boundary.
25:29 Presenter: It will not prevent a hacker from abusing power platform,
25:35 Presenter: and it will actually not prevent any persistent citizen developer as well.
25:41 Presenter: All right.
25:42 Presenter: But back to the real world, back where we were a moment ago,
25:46 Presenter: we are still blocked by the DLP,
25:48 Presenter: so we wanted to actually log in there,
25:50 Presenter: and we couldn’t.
25:51 Presenter: So let’s take a step back here.
25:54 Presenter: Let’s remove this DLP policy.
25:57 Presenter: Once I do that, then I can log in.
26:00 Presenter: I’ll get back to the role.
26:03 Presenter: Once I do that, I can log into the app,
26:05 Presenter: and you can see this little screen that should be familiar
26:08 Presenter: saying this app can use this SQL connection.
26:12 Presenter: By the way, this is not the OWASP screen
26:15 Presenter: when we grant access, right?
26:20 Presenter: Because this is credential sharing.
26:22 Presenter: This is not what we’re used to.
26:25 Presenter: So I log into the app.
26:27 Presenter: This is the app.
26:28 Presenter: There’s a bunch of different customers here.
26:32 Presenter: You can see that, so I kind of click on one of them.
26:35 Presenter: I get a bunch of information.
26:36 Presenter: Don’t worry.
26:36 Presenter: This is all generated by JetGPT.
26:41 Presenter: If I look at the requests on the browser side,
26:45 Presenter: You can see that all of this information
26:48 Presenter: is coming in from a specific request.
26:50 Presenter: To an API here called invoke.
26:53 Presenter: Now, if I look at the parameters,
26:56 Presenter: actually, this goes to an endpoint right here.
27:00 Presenter: You can see it starts with API M.
27:02 Presenter: In a moment, we’ll, let’s try and kind of understand that.
27:06 Presenter: Because essentially,
27:09 Presenter: when an app gets access through OAuth
27:13 Presenter: to perform operations,
27:15 Presenter: on the user’s behalf.
27:17 Presenter: Then you will see all of the different requests
27:20 Presenter: that are going through the app to the underlying service.
27:22 Presenter: You will see them in the browser.
27:25 Presenter: But this is not what’s happening here.
27:27 Presenter: Because this app was not provisioned access through OWASP.
27:31 Presenter: It was granted access through this accept thing
27:34 Presenter: that you did a few steps before.
27:37 Presenter: So these credentials, these connections that are being used there,
27:41 Presenter: They are just secrets that are being stored and replayed.
27:47 Presenter: This is not sharing as YAM should be, this is not the OAuth way to share permissions
27:54 Presenter: between these different users.
27:56 Presenter: This is credential sharing.
27:59 Presenter: This is one user plugging in their credential and then the app gets access to those credentials.
28:05 Presenter: Now, it doesn’t get the access directly.
28:07 Presenter: It can invoke calls with this access through this API.
28:13 Presenter: So let’s figure out this API.
Q&A and Closing Remarks — Part 2
28:16 Presenter: This is the same URL, just kind of basically to make sure it’s easier for us to see.
28:21 Presenter: You can see the domain here is Azure API M.
28:24 Presenter: This is API management.
28:25 Presenter: This is actually an internal service called API Hub built by Microsoft, used internally on top of API M.
28:33 Presenter: And API Gateway.
28:35 Presenter: The next piece is SQL.
28:39 Presenter: This is because I’m looking at the SQL connection.
28:41 Presenter: I could look at any other connection.
28:42 Presenter: And the ID for that specific connection.
28:45 Presenter: Behind that sits credentials, some sort of credentials,
28:49 Presenter: OAuth token, passwords, whatever they are.
28:52 Presenter: The next thing is an operation.
28:54 Presenter: So I’m going to a specific data set.
28:56 Presenter: You can see here that this is actually the SQL server and database.
29:00 Presenter: And then the specific operation I would like to do on this database,
29:04 Presenter: example let me fix that for you tables the view cut of customers get items all
29:11 Presenter: right now this is just the the get operation of course there’s also a
29:16 Presenter: delete operation now figuring out or trying to figure out how this works on
29:23 Presenter: the left side you have the power platform this is actually for Microsoft
29:27 Presenter: Docs on the right side you have an API you’d like to call for example SQL
29:31 Presenter: server. So Azure API management sits in the background, sits in the middle there.
29:42 Presenter: It also has a secret storage. So every time you create a connection through Power Platform,
29:48 Presenter: this connection, the credential is stored in the secret storage. And now those credentials
29:54 Presenter: aren’t shared, but the ability to call Azure API management and have it plug in those credentials
30:01 Presenter: the request on your behalf, that is being shared.
30:04 Presenter: And so the full power is being shared.
30:07 Presenter: All right, so we have seen where the information comes from,
30:13 Presenter: but taking us back to where we were,
30:17 Presenter: we were blocked by DLP, right?
30:19 Presenter: And actually, the first time I gave a talk
30:21 Presenter: about this problem, an earlier version was at Black Hat
30:27 Presenter: earlier this year, and at this point of the talk,
30:31 Presenter: and say, hey, I’m sorry, Microsoft is working on FX,
30:34 Presenter: so I’m not gonna share any details.
30:36 Presenter: The fix has been made, the green light has been given
30:40 Presenter: in November, and so now I’m gonna share
30:44 Presenter: kind of the technical details.
30:47 Presenter: So,
30:50 Presenter: I’m sorry, but it’s not gonna be very interesting.
30:54 Presenter: Basically, it just works.
30:55 Presenter: So,
30:57 Presenter: we were right here on one side,
31:01 Presenter: but we saw that power-ups have this API call that they can make
31:06 Presenter: to get to the information behind those connections.
31:09 Presenter: What if we just use this API call, even if this is blocked by DLP,
31:14 Presenter: without going through the app?
31:16 Presenter: That’s it. That’s it. It just works.
31:19 Presenter: It works because the DLP mechanism simply did not cover connections.
31:28 Presenter: Users could create whatever connections they want.
31:31 Presenter: to produce whatever connections they want,
31:33 Presenter: even if they are blocked by DLP.
31:35 Presenter: Because the blocking mechanism was just applied
31:38 Presenter: to the applications and to the automations.
31:41 Presenter: So when you create an application
31:44 Presenter: and you use a connection,
31:46 Presenter: then the application would get suspended,
31:48 Presenter: but the connection is still there.
31:55 Presenter: Before I go into more details about the fix,
31:59 Presenter: Let’s kind of make sure we understand.
32:02 Presenter: Let’s finish off this section of figuring out how this works.
32:06 Presenter: So I do this copy and paste, I get the data.
32:09 Presenter: But how can I get the token to actually reach out to API Hub,
32:16 Presenter: reach out to this API management instance?
32:17 Presenter: Because Power Apps was able to generate it,
32:20 Presenter: but you need the right scope.
32:22 Presenter: So if I look at this scope, you can see that this scope
32:24 Presenter: to API Hub, as I told you earlier,
32:28 Presenter: And in order to actually get the data to perform the bypass that I just told you about, I need to generate a token with this audience.
32:37 Presenter: And so can we generate a token that’s relevant to API Hub?
32:41 Presenter: Of course we can generate a token that’s easy.
32:43 Presenter: I just need the right application, the right client that has the permission to do it.
32:47 Presenter: So I can try to use a public client application, just one that exists, but actually it doesn’t work because it needs to be pre-approved.
32:57 Presenter: I can try to use my own application and just grant that application the ability to
33:01 Presenter: that relevant scope but that doesn’t work as well because it’s an internal Microsoft scope.
33:07 Presenter: So we’re stuck. We’re in a problem. Let’s try and circumvent the problem.
33:12 Presenter: So just as a reminder we got guest access. We found a bunch of credentials lying around.
33:18 Presenter: We tried to access. We were blocked by license. We got a license.
33:24 Presenter: We tried to access, but we were blocked by DLP, so we just copy-pasted the API call and we bypassed DLP.
33:32 Presenter: And now we’re blocked by the fact that we cannot generate the right token here.
33:36 Presenter: So let’s solve it.
33:39 Presenter: In order to generate this token, okay, something happened here.
33:46 Presenter: Okay, we need to find an application that A is owned by default in every tenant because
33:53 Presenter: as a hacker you want this to actually work.
33:54 Presenter: It’s pre-approved to query API hub because you cannot provision that yourself, it’s an
33:59 Presenter: internal resource.
34:00 Presenter: And it’s a public client application, otherwise we cannot generate tokens on its behalf.
34:05 Presenter: And so can you recall an app that does at least some of these?
34:12 Presenter: I mean, we know of one, this is the Power Apps portal.
34:15 Presenter: The Power Apps portal is owned by default in every tenant.
34:19 Presenter: It’s also pre-approved to query API hub.
34:22 Presenter: This is what we’ve seen a moment ago.
34:25 Presenter: Unfortunately, it’s not a public client application.
34:27 Presenter: So you cannot generate tokens on its behalf.
34:30 Presenter: So the way that we’re going to solve this problem
34:33 Presenter: is with a neat little piece of research called family of client IDs.
34:38 Presenter: This is not my research.
34:41 Presenter: check it out, it’s really amazing.
34:43 Presenter: There’s an undocumented set of behavior in EntraID,
34:48 Presenter: which is aimed to solve the following problem.
34:51 Presenter: When you go to a Microsoft app, let’s say,
34:55 Presenter: through your browser, let’s say Teams,
34:56 Presenter: and then you go to SharePoint.
34:58 Presenter: These are different domains, different scopes.
35:00 Presenter: You didn’t have to log in again, right?
35:02 Presenter: How does this work?
35:03 Presenter: This works because you can take one refresh token
35:08 Presenter: for one Microsoft app and replace it with a refresh token to another app.
Q&A and Closing Remarks — Part 3
35:12 Presenter: If you log into one Microsoft app, that token allows the user to get access to any other Microsoft app
35:20 Presenter: within this family of apps.
35:22 Presenter: This is undocumented behavior which people have been able to uncover.
35:25 Presenter: And so this is how we’re going to solve it.
35:27 Presenter: This is the list of the clients that we are aware of, the applications we are aware of that are part of this family.
35:33 Presenter: Again, if a hacker compromises a refresh token for one of them, they have compromised it for all of them.
35:39 Presenter: There are two things here that are interesting for us.
35:42 Presenter: One is power-ups and the other is Azure CLI.
35:46 Presenter: And now, do we understand how we’re going to solve it?
35:50 Presenter: Creating tokens with Azure CLI, of course, is easy.
35:54 Presenter: That’s why it’s there.
35:56 Presenter: Power-ups should have the right access.
35:58 Presenter: So this is what we’re going to do.
35:59 Presenter: we’re gonna generate a token with Azure CLI,
36:01 Presenter: replace it with a token to PowerApps,
36:04 Presenter: PowerApps will have the right scope, and it’ll work.
36:08 Presenter: And that actually works.
36:10 Presenter: So that’s how we generate that token.
36:13 Presenter: PowerApps is pre-approved to get to query API hub.
36:19 Presenter: So now we fully have an exploit.
36:24 Presenter: We have a way to get to these connections
36:26 Presenter: and to run this, to fetch information behind them
36:29 Presenter: without going through power apps at all.
36:31 Presenter: Now this, I’m sorry to say this,
36:33 Presenter: but this leaves no logs behind.
36:35 Presenter: You don’t have any logs for somebody using connections.
36:39 Presenter: All right, let’s go to implications.
36:41 Presenter: The first thing I want to look into
36:44 Presenter: is the fix that Microsoft has applied to this problem.
36:48 Presenter: The first thing I want to, like, when you look at this fix,
36:52 Presenter: this fix is focused only on the DLP bypass path.
36:56 Presenter: It’s not affixed to the bigger problem.
36:58 Presenter: The bigger problem is that there’s a mechanism in M365 right now that allows the user to plug in their credentials,
37:05 Presenter: get a nice little share button from Microsoft, and share these credentials with whoever they like.
37:11 Presenter: Like, Office now has credential sharing as a service built in.
37:15 Presenter: Everybody can use it.
37:16 Presenter: That’s the real problem.
37:17 Presenter: That hasn’t been addressed.
37:18 Presenter: The problem that has been addressed, at least partially, is that DLP bypass.
37:23 Presenter: Now, DLP bypass means I can use connections even though they are blocked by DLP.
37:30 Presenter: We have three things to consider.
37:32 Presenter: What happens with new connections?
37:34 Presenter: Can I create new connections that should be blocked by DLP?
37:40 Presenter: What about existing connections?
37:41 Presenter: Do they work?
37:42 Presenter: And what happens when DLP policy changes?
37:44 Presenter: Because of course it changes, right?
37:47 Presenter: This part has been fixed.
37:49 Presenter: So you cannot create new connections right now.
37:52 Presenter: If they violate DLP, you’ll get an error.
37:54 Presenter: This is great.
37:55 Presenter: Good job, Microsoft, for fixing it.
37:59 Presenter: This part has been fixed.
38:02 Presenter: Existing connections are still vulnerable.
38:04 Presenter: This means that every large enterprise
38:07 Presenter: is still vulnerable because you already have
38:11 Presenter: these connections, they have been created since 2018.
38:15 Presenter: They are there, right?
38:17 Presenter: This is not solved.
38:19 Presenter: A guest could go into your tenant, find these connections, use them today.
38:25 Presenter: DLP policy changes, that’s also vulnerable.
38:29 Presenter: Because if somebody creates a connection that is fine because the DLP doesn’t stop it,
38:35 Presenter: and then the DLP changes to block those connections, you still have those connections left.
38:40 Presenter: This hasn’t been addressed.
38:44 Presenter: This is the timeline for the disclosure of this issue.
38:49 Presenter: We disclosed this back in June.
38:52 Presenter: Got a green light to publish in November.
38:56 Presenter: I feel like now is a good time to put this out there
38:58 Presenter: because hackers are already using it.
39:00 Presenter: We need to put urgency to fix this problem.
39:05 Presenter: All right, now let’s see what you can do with this.
39:08 Presenter: So introducing PowerPoint.
39:09 Presenter: PowerPoint is an open source red-teaming tool.
39:12 Presenter: You can use it right now.
39:13 Presenter: It’s up there on GitHub.
39:14 Presenter: You can just kind of take it and try to play with it.
39:19 Presenter: It has different modules.
39:21 Presenter: It’s all focused on the Power Platform
39:22 Presenter: and how hackers can live off the land of Power Platform
39:25 Presenter: to do their bidding.
39:27 Presenter: We are going to look right now at the dump and the GUI model,
39:30 Presenter: but actually this can do so much more.
39:33 Presenter: There are models here that allow you to install a backdoor
39:35 Presenter: that would persist even if the user gets deleted afterwards,
39:39 Presenter: or to do phishing through Power Apps,
39:42 Presenter: which is an amazing phishing mechanism
39:43 Presenter: because it’s an application on a Microsoft domain.
39:47 Presenter: So I strongly encourage you to check it out.
39:50 Presenter: There’s plenty more information there.
39:52 Presenter: But let’s look at what the dump command does.
39:55 Presenter: So this is a command, Power Platform dump,
40:01 Presenter: PowerPoint dump, I’m going to pass in the guest tenant
40:05 Presenter: that I’d like to exploit.
40:07 Presenter: And then I get, like I need to log in as a hacker,
40:11 Presenter: I log in, and then I get this screen of everything
40:16 Presenter: find in the tenant. You can see credentials, automations, applications. By the way, I can
40:23 Presenter: invoke automations. Maybe these automations do something interesting.
40:28 Presenter: This is a bunch of credentials here. These are the same credentials we saw at the beginning of
40:33 Presenter: this talk. You can see information about them, and then you can see a playground grow and dump.
40:39 Presenter: Here are the two connections we looked at, the Azure file storage and the SQL server.
40:46 Presenter: that each of them has a dump ready for you.
40:49 Presenter: If you click on that, then you get to a nice little
40:52 Presenter: file system up here, and you can see all of the different,
40:57 Presenter: so this is a SQL server, you can see that I’m going through
41:02 Presenter: each and every table, these are all of the tables
41:04 Presenter: in the SQL server, each of them, you’ll find full dumps
41:08 Presenter: of all the data behind it.
41:12 Presenter: The other thing that you can do with PowerPoint,
41:16 Presenter: The other thing you can do with PowerPoint
41:18 Presenter: is that you can actually do whatever you’d like.
41:22 Presenter: Like dump is just one thing.
41:25 Presenter: But actually, you can do whatever you’d like
41:27 Presenter: with this connection.
41:28 Presenter: So here’s an example.
41:29 Presenter: If you click on Playground,
41:31 Presenter: it actually generates a Swagger UI for you.
41:34 Presenter: With all of the different actions you can perform
41:36 Presenter: through API Hub with those credentials.
41:40 Presenter: For SQL, for example, you can pass in an arbitrary query.
41:44 Presenter: Any query you’d like, just full remote code execution on that SQL server.
41:53 Presenter: All right, so have fun.
41:56 Presenter: It’s out there.
41:58 Presenter: Go play around.
42:00 Presenter: All right.
42:03 Presenter: Let me go briefly into defense, and then we do a Q&A if we have the right time.
Q&A and Closing Remarks — Part 4
42:09 Presenter: I want to start by reminding us of the shared responsibility model.
42:15 Presenter: Because we’ve forgotten about it in this world of citizen development.
42:20 Presenter: We just have.
42:22 Presenter: Like, we know what the shared responsibility model means for cloud.
42:28 Presenter: It applies to anywhere else.
42:31 Presenter: Like, if you have business users that are building things on MSO 65, of course you need to own your part.
42:36 Presenter: Of course Microsoft can’t just fix the problem.
42:39 Presenter: They need to fix their things.
42:41 Presenter: They need to have a platform that’s easy to secure.
42:44 Presenter: But we have a role here too.
42:48 Presenter: Of course the platform has problems to do, problems to fix.
42:53 Presenter: There should not be a button in M365 allowing people to share credentials with everyone.
43:00 Presenter: This just should not happen.
43:01 Presenter: But even if they fix it, they can still share with a specific guest.
43:07 Presenter: people share not with guests just with thousands of enterprise users those
43:11 Presenter: connections right I mean this problem is not going away there’s also keeping the
43:19 Presenter: platform itself secure so this is a research by tenable last year they found
43:23 Presenter: a multi-tenant vulnerability within power platform were able to compromise
43:28 Presenter: custom connectors across all of the different tenants bypass the kind of
43:32 Presenter: replace the code behind them.
43:34 Presenter: This is kind of the,
43:36 Presenter: these vulnerabilities exist in every platform,
43:38 Presenter: but of course this is something
43:40 Presenter: that platforms need to fix.
43:43 Presenter: We have our part as well.
43:45 Presenter: Like here’s a bunch of questions.
43:48 Presenter: Can you answer them?
43:49 Presenter: Because most organizations can’t.
43:51 Presenter: Most organizations have this citizen development.
43:54 Presenter: Even if they say they don’t,
43:55 Presenter: this is a bring your own device scenario.
43:57 Presenter: Like we don’t get a chance to say no.
44:00 Presenter: somebody needs to own AppSec for the things that these business users are building.
44:05 Presenter: Otherwise, they’re going to make mistakes.
44:06 Presenter: The mistakes that I showed you today are just partial.
44:09 Presenter: There are plenty of others.
44:12 Presenter: So here’s takeaways for you.
44:15 Presenter: All of the links for that are available here in this blog.
44:19 Presenter: So kind of check it out.
44:20 Presenter: It’s already out there.
44:22 Presenter: Other than the links, you’ll find links for everything I described in this talk.
44:26 Presenter: you’ll find additional demos, more materials, more runs.
44:31 Presenter: Go ahead.
44:33 Presenter: So here’s a bunch of things that I suggest you do.
44:36 Presenter: First, hack your environment.
44:37 Presenter: Do it as soon as possible.
44:39 Presenter: Just take PowerPoint.
44:41 Presenter: It takes five minutes.
44:42 Presenter: You’ll get full dumps with social security numbers,
44:46 Presenter: with confidential information.
44:47 Presenter: This will give you the buying you need
44:49 Presenter: from your management to fix this problem.
44:54 Presenter: Harden your environment.
44:57 Presenter: So the default configuration allows everybody to invite guests,
45:01 Presenter: but you can change it.
45:02 Presenter: Change it.
45:03 Presenter: Do it.
45:04 Presenter: Like, again, this print screen won’t tell you what to do,
45:08 Presenter: but the blog will.
45:10 Presenter: There are audit logs that you can turn on
45:12 Presenter: for specific things in Power Platform.
45:15 Presenter: Again, connections, there’s nothing you can do about it,
45:17 Presenter: unfortunately.
45:20 Presenter: But more importantly, start to own application security
45:26 Presenter: for what citizen developers are building.
45:28 Presenter: They are already building it.
45:30 Presenter: We are seeing financial services organizations
45:33 Presenter: with processes related to risk, to credit scoring,
45:38 Presenter: built in those platforms.
45:40 Presenter: Like, we need to be a part of this.
45:46 Presenter: And set guardrails.
45:47 Presenter: I mean, help your users prevent mistakes.
45:52 Presenter: The last thing I’ll point to is the OWASP
45:56 Presenter: which is a framework dedicated to what these businesses are building
46:01 Presenter: and how you can address not just the problem I talked about today,
46:04 Presenter: but all of those different problems.
46:07 Presenter: This is a collaborative effort by the entire community.
46:14 Presenter: I really encourage you to look into it.
46:16 Presenter: And with that, we’re done.
46:18 Presenter: Thank you very much.
46:20 Presenter: Thank you.
46:26 Presenter: I think we have like three minutes for Q&A.
46:29 Presenter: So there are two mics here.
46:36 Presenter: Yes, hi.
46:37 Presenter: So if you do run into seeing that someone has shared credentials like this
46:42 Presenter: across the entire organization, as an admin,
46:46 Presenter: do you have the ability to go in and make that change yourself
46:50 Presenter: or do you have to go to the app owner for that?
47:00 Presenter: The unfortunate answer is that it depends.
47:04 Presenter: You can find those connections, but in order to find them,
47:08 Presenter: you need to enumerate all of the connections in your tenant.
47:11 Presenter: If your tenant is more than small, it just won’t work.
47:17 Presenter: Like the API will fail on you.
47:18 Presenter: But there are Microsoft tools that would allow you to try and do that.
47:25 Presenter: it’s just difficult.
47:26 Presenter: And in a large setting, in a large enterprise setting,
47:29 Presenter: it doesn’t really work.
47:30 Presenter: You do have ways through the COE
47:35 Presenter: and through the data export to find some of that.
47:39 Presenter: It depends on your size.
47:41 Presenter: Awesome. Thank you.
47:44 Presenter: I have one question.
47:46 Presenter: So as a security professor,
47:48 Presenter: how we can get better visibility for the entire organization?
47:51 Presenter: like who is sharing their credential with different partners as a connector?
47:59 Presenter: I think that when we look at citizen development,
48:02 Presenter: this is actually a very big opportunity for us as security professionals
48:07 Presenter: because we’ve been wanting to get visibility into the business forever, right?
48:13 Presenter: And we did not have a way.
48:15 Presenter: Now they are doing it in a platform where there’s an API you can call and ask questions.
48:21 Presenter: to analyze it, we need to build the right tools, we need to be the right programs, but
48:26 Presenter: you can go and figure out what business users have built. Like you can gain access to the
48:31 Presenter: apps that they’ve built, you can analyze them yourself. There’s just, this is a very immature
48:37 Presenter: world in terms of… Are there any monitoring tools available for, to find any such things,
48:42 Presenter: like especially credential sharing? Yes, there are some open source, there are some commercials,
48:47 Presenter: We can talk about it later if you like.
48:49 Presenter: Thank you.
48:55 Presenter: Any more questions?
48:59 Presenter: Thank you.