danielsagi / kube-pod-escape
Kubernetes POC for utilizing write mount to /var/log for getting a root on the host
☆95Updated 4 years ago
Alternatives and similar repositories for kube-pod-escape:
Users that are interested in kube-pod-escape are comparing it to the libraries listed below
- Executes commands in a container on a kubelet endpoint that allows anonymous authentication (default)☆112Updated 6 years ago
- Information about Kubernetes CVE-2020-8558, including proof of concept exploit.☆42Updated 4 years ago
- Exploit for CVE-2021-25741 vulnerability☆28Updated 3 years ago
- Post-exploit a compromised etcd, gain persistence and remote shell to nodes.☆74Updated 11 months ago
- This is a PoC exploit for CVE-2020-8559 Kubernetes Vulnerability☆54Updated 4 years ago
- Container Excape PoC for CVE-2022-0847 "DirtyPipe"☆78Updated 3 years ago
- A POC for DNS spoofing in kubernetes clusters. Runs with minimum capabilities, on default installations of kuberentes.☆77Updated 5 years ago
- Security testing tool for Kubernetes, abusing kubelet credentials on public cloud providers.☆161Updated last year
- Kubolt utility for scanning public kubernetes clusters☆109Updated 10 months ago
- POC for CVE-2022-23648☆36Updated 3 years ago
- A penetration toolkit for container environment☆77Updated 3 months ago
- This repository contain any information that can be used to hack Kubernetes☆101Updated 2 years ago
- Proof of Concept exploit for Kubernetes CVE-2020-8559☆20Updated 4 years ago
- 🌶 一些和容器化/容器编排/服务网格等技术相关的安全代码片段[自用备份]☆80Updated 3 years ago
- Kubernetes Pwnage for all☆57Updated 4 years ago
- Research on various techniques to bypass default falco ruleset (based on falco v0.28.1).☆81Updated last year
- Links and resources for the O'Reilly Kubernetes Security book☆98Updated 4 years ago
- Sample Spring Boot App Demonstrating RCE via Exposed env Actuator and H2 Database☆106Updated 5 years ago
- Ready to use docker image for CodeQL☆89Updated last year
- Based on Lightspin proprietary data, research, and our tracking of cloud security trends in the market, our research team has compiled a …☆40Updated 2 years ago
- Apache Tomcat + MongoDB Remote Code Execution☆114Updated 4 years ago
- DEF CON 26 Workshop - Attacking & Auditing Docker Containers Using Open Source☆108Updated 5 years ago
- Detect and bypass Istio sidecar☆20Updated 3 years ago
- Some helpful Helm Charts for pentesters☆39Updated 6 years ago
- PoC exploit for VMware Cloud Director RCE (CVE-2020-3956)☆89Updated 4 years ago
- ☆27Updated 5 months ago
- ☆243Updated 7 months ago
- Intentionally vulnerable Go web app.☆43Updated 2 months ago
- PoC for CVE-2020-8617 (BIND)☆45Updated 4 years ago
- Simple webhook to block exploitation of CVE-2022-0811☆8Updated 3 years ago