Back to directory
WRITEUP #276

These Services Shall Not Pass: Abusing Service Tags to Bypass Azure Firewall Rules (Customer Action Required)

CloudWAF bypassSSRF
by@terminatorLM(Liv Matan)
Program
Microsoft (Azure)
Published
Jun 3, 2024
Added to HackDex
Aug 14, 2024
Read Full Writeuphttps://www.tenable.com/blog/these-services-shall-not-pass-abusing-service-tags-to-bypass-azure-firewall-rules-customer
RELATED WRITEUPS
Listen to the whispers: web timing attacks that actually work
SSRFTiming attack
Directory Traversal, SQL Injection and Server-Side Request Forgery
SQL InjectionPath traversal
IIS welcome page to source code review to LFI!
SSRFLFI
NTLM Credential Theft in Python Windows Applications
SSRFNTLMv2 hash disclosure
Vulnerabilities in Homepage Dashboard
RCESSRF

Built with ❤️ by Shubham Rawat