Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
hland
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
Azure's Weakest Link – Full Cross-Tenant Compromise
(binarysecurity.no)
1 points
by
hland
1y ago
|
1 comments
2.
▲
by
hland
1y ago
API Connections allow anyone to fully compromise any other Connection worldwide, giving full access to the connected Backend. This includes cross-tenant compromise of Key Vaults and Azure SQL databases, as well as any other externally conne
3.
▲
Finding SSRFs in Azure DevOps – Part 2
(binarysecurity.no)
1 points
by
hland
1y ago
|
1 comments
4.
▲
by
hland
1y ago
Binary Security was previously rewarded for three Server-Side Request Forgery (SSRF) vulnerabilities in Azure DevOps, which you can read about here. Now we have found another SSRF vulnerability that we also reported to Microsoft. We then by
5.
▲
by
hland
2y ago
Your take is spot on, sir.
6.
▲
Azure's Weakest Link? How API Connections Spill Secrets
(binarysecurity.no)
137 points
by
hland
2y ago
|
64 comments
7.
▲
by
hland
2y ago
Binary Security found the undocumented APIs for Azure API Connections. In this post we examine the inner workings of the Connections allowing us to escalate privileges and read secrets in backend resources for services ranging from Key Vaul