arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.17361cs.CR

可信工作流中继:多租户云中的跨租户电子邮件滥用与可组合红队初始访问原语

Trusted Workflow Relays:Cross-Tenant Email Abuse and Composable Red Team Initial-Access Primitives in Multi-Tenant Clouds

Priyank Nigam

首次发表
浏览论文内容

中文总结 AI 辅助

该研究发现多租户云存在可信工作流中继漏洞,可被用于跨租户电子邮件滥用,提出相关原语并给出修复控制措施。

中文摘要 AI 辅助

云应用通常通过提供商运营的邮件身份发送通知,这提升了送达率,但也导致提供通知参数的主体与发起消息的服务主体分离。在三项负责任披露并修复的跨租户通知工作流中,经认证的主体可跨租户边界触达收件人,并在不同程度上控制可信提供商服务所发送消息的内容。第一项中,后端请求绕过了UI长度限制,原始HTML和CSS被保留在送达消息中,攻击者链接得以渲染,CSS可隐藏服务控制的文本;iframe和非Web URI方案被拒绝。第二项结合了缺失的收件人租户验证与攻击者控制的主题及HTML字段。第三项为审批应用,存在弱访问控制、顺序对象标识符、缺失的操作授权及不完整的令牌验证,将通知滥用与授权失败组合在一起。该模式类似于经典的未认证SMTP开放中继,但故障已上移至栈:主体是经认证的,提供商是合法发送方,但应用层授权仍无法约束谁可导致其向谁发送什么。我们将可信工作流中继定义为一种已送达的、服务认证的消息,其应用层发送授权谓词为假。我们提供了通知管道的测试矩阵,将该原语映射到MITRE ATT&CK的无附件钓鱼技术,并将其与设备代码钓鱼(RFC 8628)关联。SPF、DKIM和DMARC可对消息进行认证,但无法确认应用层发送是否被授权。我们最后提出了租户绑定、类型化模板、对象级授权、令牌受众验证及身份遥测等控制措施。

英文摘要

Cloud applications routinely send notifications through provider-operated mail identities, which improves deliverability but separates the actor who supplies notification parameters from the service principal that originates the message. In three responsibly disclosed and remediated cross-tenant notification workflows, an authenticated actor could reach recipients across tenant boundaries and, to varying degrees, control content that a trusted provider service delivered. In the first, backend requests bypassed a UI length limit, raw HTML and CSS survived into the delivered message, attacker links rendered, and CSS could hide service-controlled text; iframes and non-web URI schemes were rejected. The second combined missing recipient-tenant validation with attacker-controlled subject and HTML fields. The third, an approval application, added weak access control, sequential object identifiers, missing action authorization, and incomplete token validation, composing notification abuse with authorization failures. The pattern is analogous to a classical unauthenticated SMTP open relay, but the failure has moved up the stack: the actor is authenticated and the provider is the legitimate sender, yet application-layer authorization still fails to constrain who may cause it to send what to whom. We define a trusted workflow relay as a delivered, service-authentic message for which the application-level send-authorization predicate is false. We give a test matrix for notification pipelines, map the primitive to MITRE ATT&CK techniques for attachment-free phishing, and link it to device-code phishing (RFC 8628). SPF, DKIM, and DMARC can authenticate a message yet cannot establish that an application-level send was authorized. We conclude with controls for tenant binding, typed templates, object-level authorization, token audience validation, and identity telemetry.

↑