The Open Door

  Challenge Progession:
Act I
Difficulty:
  Location:
Dosis Neighborhood
The Open Door
Securing the Network

This challenge is located in the Grand Hotel parking lot. The goose Lucas explains that the Dosis Neighhood HOA claims the network hosted in Azure is secure. We should inspect the Azure environment just to make sure, right? Click the terminal to begin.

Network Security Group Inspection

The first thing to do is list all the resource groups in the Azure tenant.

az group list
[
  {
    "id": "/subscriptions/2b0942f3-9bca-484b-a508-abdae2db5e64/resourceGroups/theneighborhood-rg1",
    "location": "eastus",
    "managedBy": null,
    "name": "theneighborhood-rg1",
    "properties": {
      "provisioningState": "Succeeded"
    },
    "tags": {}
  },
  {
    "id": "/subscriptions/2b0942f3-9bca-484b-a508-abdae2db5e64/resourceGroups/theneighborhood-rg2",
    "location": "westus",
    "managedBy": null,
    "name": "theneighborhood-rg2",
    "properties": {
      "provisioningState": "Succeeded"
    },
    "tags": {}
  }
]
We can also show the same output formatted as a human readable table.
neighbor@7e1f93055b6b:~$ az group list -o table
Name                 Location    ProvisioningState
-------------------  ----------  -------------------
theneighborhood-rg1  eastus      Succeeded
theneighborhood-rg2  westus      Succeeded
Now list all the NSGs (Network Security Groups) in the tenant.
neighbor@7e1f93055b6b:~$ az network nsg list -o table
Location    Name                   ResourceGroup
----------  ---------------------  -------------------
eastus      nsg-web-eastus         theneighborhood-rg1
eastus      nsg-db-eastus          theneighborhood-rg1
eastus      nsg-dev-eastus         theneighborhood-rg2
eastus      nsg-mgmt-eastus        theneighborhood-rg2
eastus      nsg-production-eastus  theneighborhood-rg1
There are 5 NSGs in the tenant. The terminal wants us to inspect the "nsg-web-eastus" NSG. We can list the NSG
az network nsg show --name nsg-web-eastus --resource-group theneighborhood-rg1
Next, do the same for the "nsg-mgmt-eastus" NSG. Note it may be in a different resource group.
az network nsg show --name nsg-mgmt-eastus  --resource-group theneighborhood-rg2
These are the rules that dictate which ports and connect to which resources, sort of like a firewall. I inspected the rules for the rest of the NSGs, but the last one "nsg-production-eastus" had an interesting rule.
az network nsg show --name nsg-production-eastus --resource-group theneighborhood-rg1 | less
Scrolling though "nsg-production-eastus" rules the suspect one is found.
{
	"name": "Allow-RDP-From-Internet",
	"properties": {
	  "access": "Allow",
	  "destinationPortRange": "3389",
	  "direction": "Inbound",
	  "priority": 120,
	  "protocol": "Tcp",
	  "sourceAddressPrefix": "0.0.0.0/0"
	}
}
The name of that rule alone should set off some alarm bells. Why would anyone need to allow RDP from any address out on the internet? To inspect this rule, we can call it by name in this command:
neighbor@2bd82fdd60e5:~$ az network nsg rule show -g theneighborhood-rg1 --nsg-name nsg-production-eastus -n "Allow-RDP-From-Internet"
{
  "name": "Allow-RDP-From-Internet",
  "properties": {
    "access": "Allow",
    "destinationPortRange": "3389",
    "direction": "Inbound",
    "priority": 120,
    "protocol": "Tcp",
    "sourceAddressPrefix": "0.0.0.0/0"
  }
}
In the rule, in explicitly allows inbound RDP on TCP port 3389 from ANY address from any source. That is a wildly insecure rule. Nice find!
Victory!