🚀 Darkpro.net Advertisement Service

Promote your service, product or offer on Darkpro.net and get real targeted buyers. Boost your visibility with our premium ad placement system.

Darkpro : Carding Forums - Carders Forums - Best Carding Forums - Hacking Forum - Dread Forum,

This is a sample guest message. Register a free account today to become a member! Once signed in, you'll be able to participate on this site by adding your own topics and posts, as well as connect with other members through your own private inbox!



DRACO
⚡ Premium Trusted Carder Vendor ⚡
FORUM VERIFIED & VOUCHED
💸 Cash App 💳 PayPal ⚡ Chime ⭐ Skrill 💥 Zelle 🌀 Venmo 🔥 Revolut 🌍 MoneyGram
L UFFY
VERIFIED
💰 Western Union 📱 Cash App 💳 PayPal 🏦 Bank Transfer

⭐ RED✘ ⭐

⭐⭐⭐⭐⭐
Staff member
Verified Trusted Seller
Premium User
Forum Elite
[IMG]


best carding forum
tool launches attack on k8s cluster from within. That means you already need to have an access with permission to deploy pods in a cluster to run it. After running the kube-alien pod it tries to takeover cluster's nodes by adding your public key to node's /root/.ssh/authorized_keys file by using this image https://github.com/nixwizard/dockercloud-authorizedkeys (Can be adjusted using ADD_AUTHKEYS_IMAGE param in config.py) forked from docker/dockercloud-authorizedkeys. The attack succeedes if there is a misconfiguration in one of the cluster's components it goes along the following vectors:
  • Kubernetes API
  • Kubelet service
  • Etcd service
  • Kubernetes-Dashboard
What is the purpose of this tool?
  • While doing security audit of a k8s cluster one can quickly assess it's security posture.
  • Partical demostration of the mentioned attack vectors exploitation.
How can k8s cluster be attacked from within in a real life?
  • RCE or SSRF vunerability in an app which is being run in one of your cluster's pods.
 
Back
Top