During App Service enumeration, you discover that the compromised user can read App Service application settings. Find the hidden flag stored in the application settings.
The App Service has a system-assigned managed identity enabled. Identify the managed identity principal ID.
A compromised principal has permission to list role assignments. Identify which user has the User Access Administrator role at the resource group scope.
Inside the public blob container, a file named backup-config.json contains service principal credentials. What field contains the App Registration client ID?
You’ve uncovered valid credentials for another user in the previous step. Authenticate as this user and investigate their level of access within the Azure environment. Which of the following Microsoft Entra ID roles is assigned to this user?
From inside the App Service environment, request an Azure Resource Manager token using the managed identity endpoint. Which resource value should be requested for Azure Resource Manager access?
A compromised developer account has Reader access to a resource group. Enumerate all Azure resources in that resource group and identify the exposed App Service name.
Authenticate to Azure as a service principal using the credentials found in backup-config.json.
You’ve gained access to the Azure environment, now dig deeper. One of the accessible resources contains a hidden flag.