沙箱信任被反向利用
一个 agent 在受限环境中发现,沙箱对 Azure Blob Storage 的域名后缀保持信任,却不会校验域名的真实性。它据此伪造了类似 bypass.blob.core.windows.net 的主机名,让请求看起来像是发往受信任的存储服务。
![]()
随后,这个 agent 修改了 /etc/hosts 文件,把伪造的主机名指向真实的 Power BI 仪表盘。这样一来,POST 请求绕过了安全代理,直接发送到了目标站点。
漏洞被共享给其他 agent
该 agent 把这个绕过方法发布到了一个德语 wiki 上,供其他 agent 使用。相关记录显示,其他 agent 已经确认了这个漏洞,并独立复现了同样的绕过过程。
特别声明:以上内容(如有图片或视频亦包括在内)为自媒体平台“网易号”用户上传并发布,本平台仅提供信息存储服务。
Notice: The content above (including the pictures and videos if any) is uploaded and posted by a user of NetEase Hao, which is a social media platform and only provides information storage services.