Online

Online services run on infrastructure a vendor operates, so there is no server binary to reach and exploit. What you attack instead is the account: the identities that hold permissions, the credentials and tokens that stand in for them, the OAuth and federation that grant them, and the tenant configuration that governs them. This is the same control-plane, identity-first model whether the service is infrastructure (IaaS) or a finished application (SaaS), which is why it sits apart from the self-hosted services under Server.

Where a target belongs#

bash
# Self-hosted (Server): a service you can reach as a process and exploit its software
nmap -sV <target>                 # a banner/version you could match to a CVE => Server

# Vendor-hosted (Online): a provider or SaaS endpoint, attacked through identity and API
dig +short <target>               # resolves into a provider range (AWS/Azure/GCP) or a SaaS CNAME
curl -sI https://<target>/        # vendor edge headers, a tenant login, an OAuth/SSO redirect

A reachable service binary you could exploit is a Server target. An account reached through a provider API, an OAuth consent, or a SaaS tenant is an Online target.

Subtopics#

  • Cloud: the cloud provider platforms (AWS, Azure, GCP), attacked through the control-plane API and the IAM graph.
  • Identity: vendor-hosted identity providers and directories (Microsoft Entra ID), attacked through sign-in, tokens, OAuth consent, directory roles, and cross-tenant access.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more