🔒
PENTEST WRITEUP • WEB SECURITY
One Unauthenticated Endpoint. A SAS Token. Full Organisation Takeover.
A single public API endpoint leaked an Azure Blob SAS token with racwdl permissions. Zero credentials required at any step: token → write to shared storage → stored XSS across 3 apps → admin token stolen → administrator account created → escalated to SuperAdmin with org-wide scope (all countries, 200+ sites) → “Assign Permissions” used to silently backdoor existing users. Authorised pentest, full chain, three Critical findings.