wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
303 stars 61 forks source link

[Contribution] Azure Automation hidden jobs #253

Open korniko98 opened 10 months ago

korniko98 commented 10 months ago

Summary (give a brief description of the issue)

Safebreach found three methods to run cryptominers in Azure Automation without costing anything and while hiding the job from the customer (so if an attacker somehow gained access to a target environment they could run cryptomining jobs undetected, in terms of both billing and job monitoring). Following disclosure, Azure fixed some of the bugs that enabled this.

References (provide links to blogposts, etc.)

https://www.safebreach.com/blog/cryptocurrency-miner-microsoft-azure