说得好,不如看代码。
详细信息请参阅 https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities
shell.c 中的 IP 地址。make shell.so。(我们需要在 Alpine 中构建 so,以确保它能运行在基于 musl-libc 的 nginx-ingress-controller 中。)python3 exploit.py 来获取你的 shell。你可能需要修改第 25 行和第 26 行的范围,它们表示 pid 和 fd 的范围。默认值是在速度和成功率之间折中。 在验证环境中,你可以通过运行
kpexec -n ingress-nginx ingress-nginx-controller-xxxxxxxxx-xxxxx -it -- bash以 root 身份进入容器,然后在容器中运行ls -ahl /proc/*/fd/* | grep body来获取目标值。