🟒Learning Objective 11

Azure Credentials Abuse

Task

In the Attack Lab:

  1. Login using the existing service principal credentials that were extracted from resources application.

  2. Check if the service principal has any ownership rights on any other enterprise app.

  3. Add credentials to the enterprise app on which the current service principal has permissions.

Applies to: Attack Lab

Topic Covered: Credential Abuse

Info from Objective 4

ClientSecret: 7e7730b1-29ab-4adf-bb20-7ae61987d01f
Password: ~9j8Q~f339gnUfSBxSO5yuQXM6ztfCBL8LPjXa3I

Last updated

Was this helpful?