Menu

Post image 1
Post image 2
Post image 3
Post image 4
Post image 5
Post image 6
Post image 7
Post image 8
1 / 8
0

Recovering Plaintext Passwords from Azure Virtual Machines

Akamai·Daniel Goldberg·about 1 month ago
#3ZoGcAza
Reading 0:00
15s threshold

Daniel is a security research expert at Guardicore Labs, where he is responsible for tracking the latest security intelligence, including detailed analysis of hackers' methodologies, for use in creating advanced countermeasures for Guardicore products and services. Daniel has more than 10 years of cybersecurity research experience. Azure provides an incredible amount of add-on services for its  IaaS  offerings. These services are provided by the Azure Guest Agent through a large collection of plugins such as Chef integration, a Jenkins interface, a diagnostic channel for apps running inside the machine and many more. While researching the Azure Guest Agent, we’ve uncovered several security issues which have all been reported to Microsoft. This post will focus on a security design flaw in the  VM Access  plugin that may enable a cross platform attack impacting every machine type provided by Azure.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More