Owner¶
Difficulty:
Objective¶
Task description
Help Goose James near the park discover the accidentally leaked SAS token in a public JavaScript file and determine what Azure Storage resource it exposes and what permissions it grants.
James
CLUCK CLU... I think I might be losing my mind. All the elves are gone and I'm still hearing voices.
The Neighborhood HOA uses Azure for their IT infrastructure.
The Neighborhood network admins use RBAC fo access control.
Your task is to audit their RBAC configuration to ensure they're following security best practices.
They claim all elevated access uses PIM, but you need to verify there are no permanently assigned Owner roles.
Hints¶
Owner
This terminal has built-in hints!
Solution¶
Solution
We need to execute the following commands:
Images¶
Challenge terminal.
Response¶
James
You found the permanent assignments! CLUCK! See, I'm not crazy - the security really WAS misconfigured. Now maybe I can finally get some peace and quiet...