Christian Bortone
@xybytes
Followers
180
Following
5
Media
5
Statuses
14
Prague, Czech Republic
Joined February 2019
Weak ACLs in AD and misconfigured dynamic groups in Azure AD are not new vulnerabilities. But when they intersect in a hybrid environment, they create a powerful, and often overlooked, attack path. You can read here my article. 🫡
lnkd.in
This link will take you to a page that’s not on LinkedIn
0
0
2
I was at @BSidesZagreb last week. I gave a talk on Privilege Escalation in Azure Machine Learning. If you're interested, check out this article on the topic. Plus, there are two scripts in MicroBuster that you can use for enumeration. 🙂 https://t.co/debXVMJR3h
0
0
0
In my latest research article, I take a close look at the weaknesses within Azure Application Proxy, demonstrating how impersonating the connector can enable traffic hijacking from outside the infrastructure. https://t.co/a7jx0u9baq
0
6
13
During my exploration of Azure Arc, I noticed that the Azure Arc Management Tool can be used to coerce NTLM authentication. The interesting part is that all the other options require local administrator permissions—except for this one. 🤔 https://t.co/jbyn5BsoPR
0
9
27
Finally, I achieved my first Microsoft CVE! (And maybe the last one. 🤣 ) https://t.co/E8EAyw6f9k This is also a zero-day for which I received a substantial four-figure bounty, the largest reward I've ever got. So, I was quite surprised #AzureCycleCloud #CVE
0
0
6
Praticamente è il motivo, oggi, su cui si fonda la "non cultura". Quanto mi manchi, quanto mi mancano le tue parole ♥️ #MichelaMurgia
26
400
2K
I am excited to announce that I will be presenting a new attack technique in Azure Arc that I discovered, at BSides Leeds. In this talk, I will discuss a recent security flaw that enables bad actors within a corporate environment to gain control over a service principal account.
0
0
3
To all my fellow pen testing buddies out there, this meme is dedicated to the unlucky soul who started an engagement, only to face a server that took a 24-hour nap or developers who removed functionality from the web app to avoid being tested. It can be f… https://t.co/tKVDGG9dKC
linkedin.com
To all my fellow pen testing buddies out there, this meme is dedicated to the unlucky soul who started an engagement, only to face a server that took a 24-hour nap or developers who removed functio...
0
0
1