π’Learning Objective 11
Azure Credentials Abuse
Task
In the Attack Lab:
Login using the existing service principal credentials that were extracted from resources application.
Check if the service principal has any ownership rights on any other enterprise app.
Add credentials to the enterprise app on which the current service principal has permissions.
Applies to: Attack Lab
Topic Covered: Credential Abuse
Info from Objective 4
ClientSecret: 7e7730b1-29ab-4adf-bb20-7ae61987d01f
Password: ~9j8Q~f339gnUfSBxSO5yuQXM6ztfCBL8LPjXa3I




Last updated
Was this helpful?