You might be required to add this storage account to Directory Reader role
Thursday, December 5, 2024
Assign permissions to enterprise app using powershell
Wednesday, December 4, 2024
Assign administrator roles with PowerShell
General approach is that you need to get RoleID and then assign enterprise app object ID to this RoleID:
Create an app using CLI:
$app_name = "Deployment app"
$app = az ad app create --display-name $app_name --query '{appId: appId, objectId: id}' --output json
$app = $app | ConvertFrom-Json
$cred = az ad app credential reset --id $app.appId --display-name "client-secret" --years 2
$enapp = az ad sp create --id $app.appId --query '{appId: appId, objectId: objectId}' --output json
$enappID = az ad sp show --id $app.appId --query id --output tsv
Assign it to a role:
$AdminRoleObject = Get-AzureADDirectoryRole| where {$_.DisplayName -eq 'Application Administrator'}
Add-AzureADDirectoryRoleMember -ObjectId $AdminRoleObject.ObjectId -RefObjectId $enappID
If RoleID do not exist ($AdminRoleObject is empty) enable it:
$template = Get-AzureADDirectoryRoleTemplate | where {$_.DisplayName -eq 'Privileged Role Administrator'}
Enable-AzureADDirectoryRole -RoleTemplateId $template.ObjectId
Other, assign owner to subscription:
az role assignment create --assignee $app.appId --role "Owner" --scope "/subscriptions/$subscriptionID"
Tuesday, December 3, 2024
list open ports
lsof -nP -iTCP -sTCP:LISTEN
ss -tunlp
netstat -tnlp
apt-get install procpsapt install net-toolsapt install iproute2 net-tools procps
#!/bin/bash # This script lists processes with open TCP ports by reading /proc/net/tcp and # matching socket inodes to file descriptors in /proc/[pid]/fd directories. # Function to convert hexadecimal port number to decimal. convert_port() { local hex_port=$1 echo $((16#$hex_port)) } echo "Processes with open TCP ports (based on /proc):" printf "%-8s %-20s %-6s\n" "PID" "Process Name" "Port" echo "-------------------------------------------" # Skip the header line from /proc/net/tcp by using tail. tail -n +2 /proc/net/tcp | while read -r line; do # Extract the local address (field 2) and the socket inode (field 10). local_address=$(echo "$line" | awk '{print $2}') inode=$(echo "$line" | awk '{print $10}') # If inode is empty, skip this line. if [[ -z "$inode" ]]; then continue fi # Extract the port (in hex) from the local_address (format: IP:PORT). port_hex=$(echo "$local_address" | cut -d':' -f2) port=$(convert_port "$port_hex") # Use find to look for file descriptors linking to this socket inode. pids=$(find /proc/[0-9]*/fd -lname "socket:\[$inode\]" 2>/dev/null | \ cut -d'/' -f3 | sort -u) # For each matching process, retrieve the process name. for pid in $pids; do if [ -f "/proc/$pid/comm" ]; then pname=$(cat /proc/$pid/comm) else pname="N/A" fi printf "%-8s %-20s %-6s\n" "$pid" "$pname" "$port" done done
Monday, October 28, 2024
Publish CRLs
1. Login to offline RootCA and create a new crl file:
certutil –crl
2. Copy CRL file from C:\Windows\System32\Certsrv\CertEnroll\ to a USB
3. on Issuing servers upload crl file to C:\inetpub\wwwroot\pki and other locations that CRL should be uploaded to like share or AD.
Publish in AD with: certutil –dspublish -f C:\CRKRoot.crl
Some Kusto queries
1. Find resource using TLS lower than 1.2:
2.Find blocked queried in app gateway
AzureDiagnostics
| where ResourceProvider == "MICROSOFT.NETWORK"
| where Category == "ApplicationGatewayFirewallLog"
| where action_s == "Matched"
| project
TimeGenerated,
ClientIP = clientIp_s,
RequestURI = requestUri_s,
RuleId = ruleId_s,
RuleSetType = ruleSetType_s,
Action = action_s,
Message,
Hostname = hostname_s,
TransactionId = transactionId_g
| sort by TimeGenerated desc
3. Find timeouts:
AzureDiagnostics
| where Category == "ApplicationGatewayAccessLog"
| where httpStatus_d in (408, 504, 502) // Common timeout-related HTTP status codes
| where host_s == "ylukscaleprod.eu.yusen-logistics.com"
4. Statistics, success rate in every 5 minute slot:
AzureDiagnostics
| where ResourceType == "APPLICATIONGATEWAYS"
| where Category == "ApplicationGatewayFirewallLog" or Category == "ApplicationGatewayAccessLog"
| where TimeGenerated >= ago(30d) // Adjust timeframe as needed
| where listenerName_s == "https-ylukscaleprod-eu-yusen-logisitcs-com" // Filter for specific listener if needed
| extend ListenerName = listenerName_s
| extend ResponseCode = httpStatus_d
| extend IsHealthy = iff(ResponseCode >= 200 and ResponseCode < 400, true, false)
| summarize
TotalRequests = count(),
FailedRequests = countif(not(IsHealthy)),
SuccessRate = (count() - countif(not(IsHealthy))) * 100.0 / count()
by bin(TimeGenerated, 5m), ListenerName, _ResourceId
| extend IsDown = iff(SuccessRate < 50, true, false) // Define downtime threshold
| order by TimeGenerated desc
5. Success rate in last 7 dates:
AzureDiagnostics
| where ResourceType == "APPLICATIONGATEWAYS"
| where Category == "ApplicationGatewayFirewallLog" or Category == "ApplicationGatewayAccessLog"
| where TimeGenerated >= ago(30d) // Adjust timeframe as needed
| where listenerName_s == "https-ylukscaleprod-eu-yusen-logisitcs-com" // Filter for specific listener if needed
| extend ListenerName = listenerName_s
| extend ResponseCode = httpStatus_d
| extend IsHealthy = iff(ResponseCode >= 200 and ResponseCode < 400, true, false)
| summarize
TotalRequests = count(),
FailedRequests = countif(not(IsHealthy)),
SuccessRate = (count() - countif(not(IsHealthy))) * 100.0 / count()
by bin(TimeGenerated, 5m), ListenerName, _ResourceId
| extend IsDown = iff(SuccessRate < 50, true, false) // Define downtime threshold
| order by TimeGenerated desc
6. Statistics with error code failures and successes:
AzureDiagnostics
| where ResourceProvider == "MICROSOFT.NETWORK"
| where Category == "ApplicationGatewayFirewallLog"
| where action_s == "Matched"
| where hostname_s == "ylukscaleprod.eu.yusen-logistics.com"
| project
TimeGenerated,
ClientIP = clientIp_s,
RequestURI = requestUri_s,
RuleId = ruleId_s,
RuleSetType = ruleSetType_s,
Action = action_s,
Message,
Hostname = hostname_s,
TransactionId = transactionId_g
| sort by TimeGenerated desc
Tuesday, October 15, 2024
Converting VM to generation 2 in Hyper-v
1. Create a VM from vagrant, this is gen1.
2. Although disk is VHDX, export it, add more space in Hyper-V
3. Attach this drive to old VM and expand drive is disk management.
4. Convert to GPT using MBR2GPT.
mbr2gpt.exe /validate /disk:1 /allowFullOS
mbr2gpt.exe /convert /disk:1 /allowFullOS
This will create a partition at the end.
5. Create a new VM (Gen2) and use exported drive.
Thursday, September 19, 2024
openssl basics
1. check web site expiration:
echo test | openssl s_client -connect google.com:443 | openssl x509 -noout -dates
2. PFX to PEM convertion (PFX do not have any pass):
openssl pkcs12 -in cert-in.pfx -out cert-out.pem -nodes
3. copying with scp:
scp -i C:\Users\name\OneDrive\ssh\MyPrv.pem .\file.pem remote-host.com:\tmp
4. Logging to remote host with local port forward
az ssh vm --resource-group rg-poc --name ubuntu1 -- -L 1433:localhost:1433
5. Add a password to PFX file:
openssl pkcs12 -in kv-msr-acme-letw.pfx -out c:\temp\temp1.pem -nodes
Press Enter.
.\openssl pkcs12 -export -in c:\temp\temp1.pem -out c:\temp\new_protected1.pfx -passout pass:strongpass
6. Convert cer file into pem;
openssl x509 -inform der -in .\RootCA.cer -out .\RootCA.pem