Remove Accountability Remove B2C Remove Penetration Testing
article thumbnail

SPA is for Single-Page Abuse! – Using Single-Page Application Tokens to Enumerate Azure

Security Boulevard

We were tasked with identifying methods of escalating privileges, assisting defenders in improving detections, and documenting attack paths in the client Azure environment using a compromised non-privileged user account on a Windows Virtual Desktop Image (VDI). The team began looking at the resources our user account had access to.