writeups.xyz writeups.xyz / Azure AD

Title Vulnerabilities Programs Authors
Entra ID Connect Arbitrary Password Overwrite
So you found Auth0 secrets, now what?
Hijacking Someone Else’s DCSync
Obtaining Domain Admin from Azure AD by abusing Cloud Kerberos Trust
BingBang: The AAD misconfiguration that led to Bing.com results manipulation and account takeover explained
I’d TAP That Pass
Azure security — Internal recon leveraging lack of access control
Azure Active Directory Flaw Allowed SAML Persistence
Passwordless Persistence and Privilege Escalation in Azure
SyncJacking: Hard Matching Vulnerability Enables Azure AD Account Takeover