YoVDO

ChaosDB - How We Hacked Databases of Thousands of Azure Customers

Offered By: Black Hat via YouTube

Tags

Black Hat Courses Cybersecurity Courses Cloud Computing Courses Database Management Courses Server Configuration Courses Network Reconnaissance Courses

Course Description

Overview

Dive into a critical cybersecurity presentation from Black Hat that exposes ChaosDB, a severe cross-tenant vulnerability in Azure Cosmos DB. Discover how the Wiz Research Team uncovered this unprecedented cloud vulnerability that allowed unauthorized access to thousands of Azure customers' databases. Learn about the exploitation process, including Jupyter Notebook LPE, unrestricted network access, and account service takeover. Explore the research mindset, network reconnaissance techniques, and the full exploit chain. Gain insights into the disclosure timeline and the far-reaching implications of this security flaw for organizations worldwide.

Syllabus

Intro
Wiz Research Team
Motivation
Research Mindset
Bug #1 - Jupyter Notebook LPE
Bug #2 - Unrestricted Network Access
Network Recon - IMDS
Network Recon - WireServer
WireServer 101 - Extension Configuration
Wire Server 101 - Certificate Endpoint
Decoding CertificatesBondPackage
Listing Running Applications in Cluster
Recap - The Full Exploit
Disclosure Timeline
Account Service Takeover


Taught by

Black Hat

Related Courses

Attack on Titan M, Reloaded - Vulnerability Research on a Modern Security Chip
Black Hat via YouTube
Attacks From a New Front Door in 4G & 5G Mobile Networks
Black Hat via YouTube
AAD Joined Machines - The New Lateral Movement
Black Hat via YouTube
Better Privacy Through Offense - How to Build a Privacy Red Team
Black Hat via YouTube
Whip the Whisperer - Simulating Side Channel Leakage
Black Hat via YouTube