{"id":13589483,"url":"https://github.com/g3rzi/HackingKubernetes","last_synced_at":"2025-04-08T09:33:01.903Z","repository":{"id":38271899,"uuid":"245852683","full_name":"g3rzi/HackingKubernetes","owner":"g3rzi","description":"This repository contain any information that can be used to hack Kubernetes","archived":false,"fork":false,"pushed_at":"2022-06-08T04:23:37.000Z","size":108,"stargazers_count":97,"open_issues_count":1,"forks_count":16,"subscribers_count":2,"default_branch":"master","last_synced_at":"2024-08-01T16:15:35.950Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":null,"has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/g3rzi.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2020-03-08T16:55:45.000Z","updated_at":"2024-07-22T01:49:16.000Z","dependencies_parsed_at":"2022-07-18T01:30:44.151Z","dependency_job_id":null,"html_url":"https://github.com/g3rzi/HackingKubernetes","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/g3rzi%2FHackingKubernetes","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/g3rzi%2FHackingKubernetes/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/g3rzi%2FHackingKubernetes/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/g3rzi%2FHackingKubernetes/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/g3rzi","download_url":"https://codeload.github.com/g3rzi/HackingKubernetes/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":223314179,"owners_count":17125021,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-08-01T16:00:30.729Z","updated_at":"2024-11-06T09:31:05.492Z","avatar_url":"https://github.com/g3rzi.png","language":null,"funding_links":[],"categories":["Cloud Pentesting"],"sub_categories":["Kubernetes"],"readme":"# HackingKubernetes  \nThis repository contain any information that can be used to hack Kubernetes.\n\n# Offensive  \n## Atricles  \n[Securing Kubernetes Clusters by Eliminating Risky Permissions](https://www.cyberark.com/threat-research-blog/securing-kubernetes-clusters-by-eliminating-risky-permissions/)  \n[Kubernetes Pentest Methodology Part 1](https://www.cyberark.com/he/threat-research-blog/kubernetes-pentest-methodology-part-1/)  \n[Kubernetes Pentest Methodology Part 2](https://www.cyberark.com/threat-research-blog/kubernetes-pentest-methodology-part-2/)  \n[Kubernetes Pentest Methodology Part 3](https://www.cyberark.com/threat-research-blog/kubernetes-pentest-methodology-part-3/)  \n[Eight Ways to Create a Pod](https://www.cyberark.com/threat-research-blog/eight-ways-to-create-a-pod/)  \n[Leaked Code from Docker Registries](https://unit42.paloaltonetworks.com/leaked-docker-code/)  \n[Kubernetes Pod Escape Using Log Mounts](https://blog.aquasec.com/kubernetes-security-pod-escape-log-mounts)  \n\n\n### kubelet\n[https://faun.pub/attacking-kubernetes-clusters-using-the-kubelet-api-abafc36126ca](https://faun.pub/attacking-kubernetes-clusters-using-the-kubelet-api-abafc36126ca)  \n[https://rhinosecuritylabs.com/cloud-security/kubelet-tls-bootstrap-privilege-escalation/](https://rhinosecuritylabs.com/cloud-security/kubelet-tls-bootstrap-privilege-escalation/)  \n\n### Containers and Pods   \n[Bad Pods: Kubernetes Pod Privilege Escalation](https://labs.bishopfox.com/tech-blog/bad-pods-kubernetes-pod-privilege-escalation)   \n[Risk8s Business: Risk Analysis of Kubernetes Clusters](https://tldrsec.com/guides/kubernetes/)   \n[CVE-2020-15157 \"ContainerDrip\" Write-up](https://darkbit.io/blog/cve-2020-15157-containerdrip)   \n[Deep Dive into Real-World Kubernetes Threats](https://research.nccgroup.com/2020/02/12/command-and-kubectl-talk-follow-up/)   \n[Unpatched Docker bug allows read-write access to host OS](https://nakedsecurity.sophos.com/2019/05/31/unpatched-docker-bug-allows-read-write-access-to-host-os/)  \n[Docker Container Breakout: Abusing SYS_MODULE capability!](https://blog.pentesteracademy.com/abusing-sys-module-capability-to-perform-docker-container-breakout-cf5c29956edd)   \n[Container Breakouts – Part 1: Access to root directory of the Host](https://blog.nody.cc/posts/container-breakouts-part1/)   \n[Privileged Container Escapes with Kernel Modules](https://xcellerator.github.io/posts/docker_escape/)   \n[Digging into cgroups Escape](https://0xdf.gitlab.io/2021/05/17/digging-into-cgroups.html)  \n[Understanding Docker container escapes](https://blog.trailofbits.com/2019/07/19/understanding-docker-container-escapes/)  \n\n## PDF  \n[Abusing Privileged and Unprivileged Linux\nContainers ](https://www.nccgroup.com/globalassets/our-research/us/whitepapers/2016/june/container_whitepaper.pdf)  \n[Defending Containers](https://www.intezer.com/wp-content/uploads/2021/03/Intezer-Defending-Containers.pdf)   \n\n## Videos    \n[Compromising Kubernetes Cluster by Exploiting RBAC Permissions](https://www.youtube.com/watch?v=1LMo0CftVC4)   \n[How We Used Kubernetes to Host a Capture the Flag (CTF) - Ariel Zelivansky \u0026 Liron Levin, Twistlock](https://www.youtube.com/watch?v=kUmaKvxdfvg) ([presentation](https://static.sched.com/hosted_files/kccnceu19/6b/kubecon%20talk.pdf))  \n[Crafty Requests: Deep Dive Into Kubernetes CVE-2018-1002105 - Ian Coldwater, Heroku](https://www.youtube.com/watch?v=VjSJqc13PNk) ([presentation](https://static.sched.com/hosted_files/kccnceu19/a5/craftyrequests.pdf))\n[A Hacker's Guide to Kubernetes and the Cloud - Rory McCune, NCC Group PLC (Intermediate Skill Level)](https://www.youtube.com/watch?v=dxKpCO2dAy8)    \n[Advanced Persistence Threats: The Future of Kubernetes Attacks](https://www.youtube.com/watch?v=CH7S5rE3j8w)  \n[Hack my mis-configured Kubernetes - Or Kamara](https://www.youtube.com/watch?v=XNPDtNbcPr4)  \n[LISA19 - Deep Dive into Kubernetes Internals for Builders and Operators](https://www.youtube.com/watch?v=3KtEAa7_duA)  \n[DIY Pen-Testing for Your Kubernetes Cluster - Liz Rice, Aqua Security](https://www.youtube.com/watch?v=fVqCAUJiIn0)  \n[Hacking and Hardening Kubernetes Clusters by Example](https://www.youtube.com/watch?v=vTgQLzeBfRU)  \n[Tutorial: Attacking and Defending Kube...](https://www.youtube.com/watch?v=UdMFTdeAL1s)  \n[Securing (and pentesting) the great spaghetti monster (k8s)](https://www.youtube.com/watch?v=VjGEk-F46bs)  \n[Jay Beale - Kubernetes Practical Attack and Defense](https://www.youtube.com/watch?v=LtCx3zZpOfs)    \n[Jay Beale - Quick Intro Attacking a Kubernetes Cluster](https://www.youtube.com/watch?v=fZJ-5rAwcp0)  \n[Jay Beale - Attacking and Defending Kubernetes - DEF CON 27 Packet Hacking Village](https://www.youtube.com/watch?v=2fmAuR3rnBo)  \n[Jay Beale - Kubernetes Attack and Defense: Inception-Style](https://www.youtube.com/watch?v=cCyDAJHkNO4)  \n[Jay Beale - RSA20219: Hacking and Hardening Kubernetes](https://www.youtube.com/watch?v=wlgAWSbY0gI)  \n[Attacking Kubernetes Clusters Through Your Network Plumbing](https://www.youtube.com/watch?v=gX1WXyM4IIQ)  \n[Magno Logan - TrendMicro: Kubernetes Security - Attacking and Defending K8s Clusters](https://www.youtube.com/watch?v=pl2WVPP4-Zw)  \n[Magno Logan - CloudSecNextSummit2021: Kubernetes Security - Attacking and Defending K8s Clusters](https://www.youtube.com/watch?v=Ek1oaGwfli0)   \n[Magno Logan - Hackfest HF: Kubernetes Security: Attacking and Defending K8s Clusters](https://www.youtube.com/watch?v=ROiCGwVV_zU)  \n\n## Vulnerabilities\n### 2020  \n[Protecting Against an Unfixed Kubernetes Man-in-the-Middle Vulnerability (CVE-2020-8554)](https://unit42.paloaltonetworks.com/cve-2020-8554/)    \n[Kubernetes Vulnerability Puts Clusters at Risk of Takeover (CVE-2020-8558)](https://unit42.paloaltonetworks.com/cve-2020-8558/)   \n  \n  \n### 2019\n\n[Top 5 Kubernetes Vulnerabilities of 2019 - the Year in Review](https://www.stackrox.com/post/2020/01/top-5-kubernetes-vulnerabilities-of-2019-the-year-in-review/)   \n\n#### Kubectl vulnerability (CVE-2019-1002101)\n[Disclosing a directory traversal vulnerability in Kubernetes copy – CVE-2019-1002101](https://unit42.paloaltonetworks.com/disclosing-directory-traversal-vulnerability-kubernetes-copy-cve-2019-1002101/)  \n\n#### Kubernetes API server vulnerability (CVE-2019-11247)\n[Kubernetes API server vulnerability (CVE-2019-11247)](https://www.stackrox.com/post/2019/08/how-to-remediate-kubernetes-security-vulnerability-cve-2019-11247/)  \n\n#### Kubernetes billion laughs attack vulnerability (CVE-2019-11253)\n\n[CVE-2019-11253: Kubernetes API Server JSON/YAML parsing vulnerable to resource exhaustion attack](https://github.com/kubernetes/kubernetes/issues/83253)  \n\n### 2018\n\n[Demystifying Kubernetes CVE-2018-1002105 (and a dead simple exploit)](https://unit42.paloaltonetworks.com/demystifying-kubernetes-cve-2018-1002105-dead-simple-exploit/)  \n[https://sysdig.com/blog/privilege-escalation-kubernetes-dashboard/](CVE-2018-18264 Privilege escalation through Kubernetes dashboard.)  \n\n## Tools  \n[kubesploit](https://github.com/cyberark/kubesploit)  \n[kubiscan](https://github.com/cyberark/KubiScan)  \n[kubeletctl](https://github.com/cyberark/kubeletctl)   \n[kube-hunter](https://github.com/aquasecurity/kube-hunter)  \n\n# Defensive  \n[Smarter Kubernetes Access Control: A Simpler Approach to Auth - Rob Scott, ReactiveOps](https://www.youtube.com/watch?v=egQnymnZ9eg)  \n\n\n# Others\n## Install Docker on Ubuntu\nReference from [here](https://docs.docker.com/engine/install/ubuntu/#installation-methods).  \n```\n# remove old versions\napt-get remove docker docker-engine docker.io containerd runc\n# install\napt-get update\napt-get install \\\n    apt-transport-https \\\n    ca-certificates \\\n    curl \\\n    gnupg \\\n    lsb-release\ncurl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /usr/share/keyrings/docker-archive-keyring.gpg\necho \\\n  \"deb [arch=amd64 signed-by=/usr/share/keyrings/docker-archive-keyring.gpg] https://download.docker.com/linux/ubuntu \\\n  $(lsb_release -cs) stable\" | sudo tee /etc/apt/sources.list.d/docker.list \u003e /dev/null\n\napt-get update\napt-get install docker-ce docker-ce-cli containerd.io\n\n```\n\n## Install minikube  \nThe documentation can be found [here](https://minikube.sigs.k8s.io/docs/start/). In AWS you need to run:  \n```\ncurl -LO https://storage.googleapis.com/minikube/releases/latest/minikube-linux-amd64\ninstall minikube-linux-amd64 /usr/local/bin/minikube\nswapoff -a\napt install conntrack\nminikube start --driver=none\n```  \n\n## Install kubectl  \n```\n# https://kubernetes.io/docs/tasks/tools/install-kubectl-linux/\ncurl -LO \"https://dl.k8s.io/release/$(curl -L -s https://dl.k8s.io/release/stable.txt)/bin/linux/amd64/kubectl\"\ninstall -o root -g root -m 0755 kubectl /usr/local/bin/kubectl\n```\n\n## Create containers\n### Privileged container\n```\nkubectl apply -f - \u003c\u003cEOF\napiVersion: v1\nkind: Pod\nmetadata:\n  name: priv-pod\nspec:\n  containers:\n  - name: sec-ctx-8\n    image: gcr.io/google-samples/node-hello:1.0\n    securityContext:\n      allowPrivilegeEscalation: true\n      privileged: true\n      readOnlyRootFilesystem: true\n      runAsNonRoot: true\n      runAsUser: 1000\n      capabilities:\n        add: [\"NET_ADMIN\", \"SYS_TIME\"]\nEOF\n```\n\n### Container with environment variables passwords\n\n```\nkubectl apply -f - \u003c\u003cEOF\napiVersion: v1\nkind: Pod\nmetadata:\n  name: envvars-db\n  namespace: default\nspec:\n  containers:\n  - name: envvars-multiple-secrets\n    image: nginx\n    env:\n    - name: DB_PASSWORD\n      valueFrom:\n        secretKeyRef:\n          key: db-username-key\n          name: db-username\n    - name: DB_USERNAME\n      valueFrom:\n        secretKeyRef:\n          key: db-password-key\n          name: db-password\nEOF\n\n```\n\n\n```\nkubectl apply -f - \u003c\u003cEOF\n\napiVersion: v1\nkind: Namespace\nmetadata:\n  creationTimestamp: null\n  name: mars\n---\n\napiVersion: v1\nkind: ServiceAccount\nmetadata:\n  namespace: mars\n  name: user1\n  \n---\n\nkind: ClusterRole\napiVersion: rbac.authorization.k8s.io/v1\nmetadata:\n  namespace: kube-system\n  name: list-secrets\nrules:\n- apiGroups: [\"*\"]\n  resources: [\"secrets\"]\n  verbs: [\"get\", \"list\"]\n  \n---\n\napiVersion: rbac.authorization.k8s.io/v1beta1\nkind: ClusterRoleBinding\nmetadata:\n  namespace: kube-system\n  name: list-secrets-binding\nroleRef:\n  apiGroup: rbac.authorization.k8s.io\n  kind: ClusterRole\n  name: list-secrets\nsubjects:\n  - kind: ServiceAccount\n    name: user1\n    namespace: mars\n    \n---\n\napiVersion: v1\nkind: Pod\nmetadata:\n  name: alpine-secret\n  namespace: mars\nspec:\n  containers:\n  - name: alpine-secret\n    image: alpine\n    command: [\"/bin/sh\"]\n    args: [\"-c\", \"sleep 100000\"]\n  serviceAccountName: user1\n  automountServiceAccountToken: true\n  hostNetwork: true\n---\n\napiVersion: v1\nkind: Secret\nmetadata:\n  name: db-username\ndata:\n  db-username-key: YWRtaW4=\n\n---\n\napiVersion: v1\nkind: Secret\nmetadata:\n  name: db-password\ndata:\n  db-password-key: MTIzNDU=\n\nEOF\n\n```\n\n## Get ServiceAccount token by name\n```\nkubectl get secrets $(kubectl get sa \u003cSERVICE_ACCOUNT_NAME\u003e -o json | jq -r '.secrets[].name') -o json | jq -r '.data.token' | base64 -d\n```\n\nFunction:\n```\nalias k=kubectl\nfunction getSecretByName {\nk get secrets $(k get sa $1 -o json | jq -r '.secrets[].name') -o json | jq -r '.data.token' | base64 -d\n}\n\ngetSecretByName \u003cserviceAccountName\u003e\n```\n\n*Replace `\u003cSERVICE_ACCOUNT_NAME\u003e` with the name\n\n## Delete multiple containers\n```\n// delete by match with grep\nkubectl delete po $(kubectl get pods -o go-template -n \u003cNAMESPACE\u003e --template '{{range .items}}{{.metadata.name}}{{\"\\n\"}}{{end}}' | grep \u003cSEARCH_STRING) -n \u003cNAMESPACE\u003e\n\n// delete specific pods\nkubectl delete pods -n \u003cNAMESPACE\u003e $(echo -e 'alpine1\\nalpine2\\nalpine3')\n```\n\n## Get docker container IPs\n```\ndocker inspect --format='{{.Name}}' $(docker ps -aq -f label=kubelabel)\ndocker inspect --format='{{ .NetworkSettings.IPAddress }}' $(docker ps -aq -f label=kubelabel)\n```\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fg3rzi%2FHackingKubernetes","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fg3rzi%2FHackingKubernetes","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fg3rzi%2FHackingKubernetes/lists"}