Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Catalin Cimpanu
@campuscodi@mastodon.social  ·  activity timestamp 4 days ago

Bruh... there's a "master key" that grants access to every Cosmos DB on Azure? Wut?

https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db

wiz.io

CosmosEscape: Taking Over Every Azure Cosmos DB | Wiz Blog

Wiz Research details CosmosEscape, a critical vulnerability in Azure Cosmos DB that granted full read/write access to every database. Now fully remediated.
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
12
  • Copy link
  • Flag this post
  • Block
WooShell
@WooShell@chaosfurs.social replied  ·  activity timestamp 3 days ago

@campuscodi Yet another demonstration that putting your data on other people's computers is a bad idea..

  • Copy link
  • Flag this comment
  • Block
Jan Katins
@jankatins@fosstodon.org replied  ·  activity timestamp 3 days ago

@campuscodi every DB at least needs a place where the internal key to setup replicas is placed. I guess every DB vendor has such a key saved (per database)bin their control plane data store. E.g. AWS only gives you a non superuser credential (or gave you a few years back) and I guess the real superuser was reserved for internal stuff like replica setup and monitoring.

  • Copy link
  • Flag this comment
  • Block
Joshua Byrd :mastodon:
@phocks@bne.social replied  ·  activity timestamp 3 days ago

@campuscodi 😬

  • Copy link
  • Flag this comment
  • Block
Julia Clement
@juliaclement@mastodon.nz replied  ·  activity timestamp 3 days ago

@campuscodi I see this and know why it was incredibly bad. I also know on my server I have a user "root" that gives full access to every Mariadb database on the server and a backup user that has full read access to every Mariadb database to facilitate doing backups.

Yes, I know the scale is vastly different and it was microsloppy having a single key for a huge number of datacentres but this is just what I and many other server owners do scaled up to ridiculous size.

  • Copy link
  • Flag this comment
  • Block
Jonathan Kamens 86 47
@jik@federate.social replied  ·  activity timestamp 3 days ago

@campuscodi There WAS a master key that granted access to every Cosmos DB on Azure. As part of mitigating this vulnerability MS changed the architecture and got rid of it.
Still bad, but not _quite_ as bad.

  • Copy link
  • Flag this comment
  • Block
shtwzrd@mas.to:~$:idle:
@shtwzrd@mas.to replied  ·  activity timestamp 4 days ago

@campuscodi Jeez, ChaosDB was not even that long ago.

https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-vulnerability-walkthrough

Both of these walkthroughs are a scary peeks at what cloud infra really is. The two together are damning of Service Fabric, there are security failures at multiple levels but escalation from one host to an entire region happens with basically no effort, in both exploits. It just looks like bad design.

wiz.io

ChaosDB explained: Azure's Cosmos DB vulnerability walkthrough | Wiz Blog

This is the full story of the Azure ChaosDB Vulnerability that was discovered and disclosed by the Wiz Research Team, where we were able to gain complete unrestricted access to the databases of several thousand Microsoft Azure customers.
  • Copy link
  • Flag this comment
  • Block
AlexanderMars
@AlexanderMars@mastodon.social replied  ·  activity timestamp 4 days ago

@campuscodi I close the blinds and turn down the lights, then take an aluminium foil hat out of the bottom drawer, all while mumbling about NSA backdoors.

  • Copy link
  • Flag this comment
  • Block
spdrnl
@spdrnl@sigmoid.social replied  ·  activity timestamp 4 days ago

@campuscodi I am sure you will like this blog post: https://isolveproblems.substack.com/p/how-microsoft-vaporized-a-trillion

How Microsoft Vaporized a Trillion Dollars

Inside the complacency and decisions that eroded trust in Azure—from a former Azure Core engineer.
  • Copy link
  • Flag this comment
  • Block
Psychadelic Banana Slug
@psychadelic_banana_slug@mastodon.soupformy.community replied  ·  activity timestamp 4 days ago

@campuscodi
I get that key management is hard, but man, if the risk is complete takeover of all resources in a service that I'm hosting for customers as a hyperscaler, I might try to do better than a single main key that grants access to literally everything...

  • Copy link
  • Flag this comment
  • Block
loStronzoRocco
@desantis@mastodon.bida.im replied  ·  activity timestamp 4 days ago

@campuscodi Remember when “they” said let’s put everything in the cloud? Tools, all of them.

  • Copy link
  • Flag this comment
  • Block
Omnivore
@Ralph@hear-me.social replied  ·  activity timestamp 4 days ago

@campuscodi

#alttext

CosmosEscape: Taking Over Every Database in Azure CosmosDB
Any region | Any API flavor | Including private databases
Exploits CosmosEscape
Attacker (using)
Cosmos Master Key
(opens)
Azure Cosmos DB Backend
US East
Org A DBS
Europe
Org B DBS
Asia
Org C DBs
US West
Internal Microsoft DBs
Brazil
Internal Azure DBS
(by) WIZ Research

  • Copy link
  • Flag this comment
  • Block
Andrew Golding
@huronbikes@cyberplace.social replied  ·  activity timestamp 4 days ago

@campuscodi my "yes I have a key that allows access to everyone's database don't worry about it" t-shirt is causing a lot of questions already answered by the t-shirt.

  • Copy link
  • Flag this comment
  • Block
Log in

CoreSignal social

A minimalist social node dedicated to high-fidelity exchange and digital autonomy. CoreSignal strips away the noise of the modern web to provide a clean, functional space for meaningful connection within the Fediverse

CoreSignal social: About · Code of conduct · Privacy · Users · Instances
CoreSignal social · 1.0.0-rc.3.6 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login