Azure Table storage is the key-value NoSQL service inside a storage account, and it shares the account's auth: the account key or a SAS token reads and writes every table. Applications use it for session state, configuration, and audit data, so a recovered storage key often exposes tables that hold tokens, user records, or internal state.
Listing and reading tables#
KEY=$(az storage account keys list -n <acct> -g <rg> --query '[0].value' -o tsv)
az storage table list --account-name <acct> --account-key "$KEY" -o table
az storage entity query --account-name <acct> --account-key "$KEY" --table-name <t>
Exploitation notes#
- Table access rides on the same account key as blob storage, so one
listKeysgrants both; check what the key already unlocks before anything louder. - A SAS token scoped to the table service reaches tables even without the account key, and such tokens leak in app config and URLs.
- Tables backing application authorization (role rows, feature flags) make a write an application-level escalation.
Tools#
- az cli (
az storage table list,az storage entity query). - Azure Storage Explorer: browse tables with a key or SAS.