BlobHunter - Find Exposed Data In Azure With This Public Blob Scanner

2 years ago 174
BOOK THIS SPACE FOR AD
ARTICLE AD

An opensource tool for scanning Azure blob storage accounts for publicly opened blobs.
BlobHunter is a part of "Hunting Azure Blobs Exposes Millions of Sensitive Files" research:
https://www.cyberark.com/resources/threat-research-blog/hunting-azure-blobs-exposes-millions-of-sensitive-files

Overview

BlobHunter helps you identify Azure blob storage containers which store files that are publicly available to anyone with an internet connection.
The tool will help mitigate risk by identifying poorly configured containers that store sensitive data, which is specifically helpful in larger scale Azure subscriptions where there are a significant number of storage accounts that could be hard to track.
BlobHunter produces an informative csv result file that provides important details on each publicly opened container in the scanned environment.

Requirements

Python 3.5+

Azure CLI

requirements.txt packages

Azure user with one of the following built-in roles:

Owner Contributor Storage Account Contributor

Or any Azure user with a role that allows to perform the following Azure actions:

Microsoft.Resources/subscriptions/read
Microsoft.Resources/subscriptions/resourceGroups/read
Microsoft.Storage/storageAccounts/read
Microsoft.Storage/storageAccounts/listkeys/action
Microsoft.Storage/storageAccounts/blobServices/containers/read
Microsoft.Storage/storageAccounts/blobServices/containers/blobs/read

Build

Example for installation on Ubuntu:

curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash
pip3 install -r requirements.txt

Usage

Simply run

If you are not logged in in the Azure CLI, a browser window will be prompted at you for inserting your Azure user credentials.

References

For any question or feedback, please contact Daniel Niv, Asaf Hecht and CyberArk Labs.

BlobHunter - Find Exposed Data In Azure With This Public Blob Scanner BlobHunter - Find Exposed Data In Azure With This Public Blob Scanner Reviewed by Zion3R on 5:30 PM Rating: 5

Read Entire Article