Hacking a Kubernetes Cluster: A Practical Example!

Поділитися
Вставка
  • Опубліковано 26 лис 2024

КОМЕНТАРІ • 61

  • @KodeKloud
    @KodeKloud  Рік тому +1

    Full Certified Kubernetes Application Developer (CKAD) Course: kode.wiki/CKAD_YT

  • @lhxperimental
    @lhxperimental 3 роки тому +44

    Not a realistic production scenario. Webservers/Load Balancers are usually on a different server and network than the Kubernetes cluster. The cluster itself has no direct internet connectivity and only ports exposed to the world are the HTTP(S) ports of the load balancers

    • @AndresLeonRangel
      @AndresLeonRangel 2 роки тому +5

      you will be surprised to know that some companies actually have scenarios like this one...

    • @okharev8114
      @okharev8114 2 роки тому +2

      if only

  • @abdurrahmanhr
    @abdurrahmanhr 3 роки тому +3

    Great clip with crisp coverage on security

    • @KodeKloud
      @KodeKloud  3 роки тому +1

      Glad you enjoyed it! Please subscribe to our channel and keep supporting😊

  • @tendaimusonza9547
    @tendaimusonza9547 3 роки тому +5

    Wonderful, great hands on presentation

    • @KodeKloud
      @KodeKloud  3 роки тому

      Many thanks! Please subscribe and encourage us to create more such quality content.

  • @makevoid
    @makevoid 3 роки тому +4

    From 2021 Kubernetes (v1.20+) removes the default dependency on docker in favour of containerd. This "attack" may work on a badly configured Kubernetes version prior to that and also on a poorly configured docker swarm cluster.

  • @ileriayoadebiyi
    @ileriayoadebiyi 3 роки тому +2

    That election story surely was scary!!!
    Great video, Mumshad!
    Always love your videos!

    • @KodeKloud
      @KodeKloud  3 роки тому

      Glad you liked it! Please subscribe and encourage us to create more such quality content.

    • @ileriayoadebiyi
      @ileriayoadebiyi 3 роки тому +1

      What!?? Never knew I wasn’t subscribed 😭
      By the way, all my DevOps friends and wannabes are tired of me talking about kodekloud

  • @anthonydelagarde3990
    @anthonydelagarde3990 2 роки тому +2

    Thank you a fantastic video and demonstration

  • @tendaimusonza9547
    @tendaimusonza9547 3 роки тому +3

    I subscribed within the first few seconds of hearing the quality stuff ,lol

  • @manojpansare2007
    @manojpansare2007 3 роки тому +3

    Excellent and eye opener....👌👌👌

    • @KodeKloud
      @KodeKloud  3 роки тому

      Glad you liked it! Thanks:)

  • @EderNucci
    @EderNucci 3 роки тому +33

    Having the docker port exposed is simply the most stupid thing I think someone can do on a cluster. Why they did this?

    • @thehackingexplorer3636
      @thehackingexplorer3636 3 роки тому +10

      Because they are dog lovers. LoL

    • @kubectlgetpo
      @kubectlgetpo 3 роки тому +7

      No one did it.. it's made up scenario that teaches theater security

    • @EderNucci
      @EderNucci 3 роки тому +1

      @@kubectlgetpo watch again at 0:40 :-)

    • @kubectlgetpo
      @kubectlgetpo 3 роки тому

      @CipherNL yeah crap scenario all around

    • @AndresLeonRangel
      @AndresLeonRangel 2 роки тому

      yes, i agree. I will give you a case scenario where this could happen:
      Cheapskate companies that would like to save Cloud costs. Instead of paying for full Kubernetes managed service they just use EC2 instances with terraform cloud. An Engineer is told to make things work. So there he goes and uses terraform to create an EC2 instance with docker engine installed. He wants to use a terraform docker provider and boom you must expose the docker engine port so that terraform creates the docker containers.
      Everyone is happy = low cost, manager can boast, the engineer can move on to do lots more things...
      This is a real life scenario and yes the docker engine was exposed to the internet :-)

  • @matteobaiguini5940
    @matteobaiguini5940 3 роки тому +3

    can you please share the material you used for the demo? maybe a git repo?

  • @ramakrishnabommerla3176
    @ramakrishnabommerla3176 3 роки тому +2

    amazing explanation :) great use-case

  • @KASANITEJ
    @KASANITEJ 3 роки тому +2

    I can understand ssh port being open by mistake.... but I can't wrap around why docker port is opened?

  • @durden0
    @durden0 3 роки тому +8

    Do people really run their docker hosts with no authentication and their kubernetes dashboards exposed to the internet?

  • @rishabhjain2940
    @rishabhjain2940 3 роки тому +1

    What is this tools for port scanning? And where I can get it ?

  • @aldyj4733
    @aldyj4733 3 роки тому +5

    This is the epitome of one jumps into kubernetes too quickly without regards to any best practices (pain points: exposed docker port + conn string as env var) whatsoever...

    • @aldyj4733
      @aldyj4733 3 роки тому

      And sadly, the majority of people still do this...

    • @KodeKloud
      @KodeKloud  3 роки тому

      Yes, that's true.

  • @LuizJrDeveloper
    @LuizJrDeveloper Рік тому +1

    How did you put an icon in ZSH?

    • @KodeKloud
      @KodeKloud  Рік тому +1

      You can use powerlevel10k for custom ZSH

  • @mafujaakhtar9876
    @mafujaakhtar9876 Рік тому +1

    Hi Mumshad brother, is it possible to be a DevOps engineer for a non tech person? I am an an anthropologist, had career break for children now I got interested in cloud. I am a certified cloud practitioners and courntly I am doing cybersecurity program. I am interested about cloud security though I am new in this field. How long need to I have to work in cloud then I can try for the cloud security? I am a mother of two teenage kids and fourty plass cloud savvy.

    • @KodeKloud
      @KodeKloud  Рік тому

      Certainly, transitioning into a DevOps or cloud security role is achievable, even without a traditional tech background. With your Cloud Practitioner certification, explore advanced cloud certifications and gain hands-on experience. Learn automation tools and DevOps practices. Leverage your unique background in anthropology for soft skills. Focus on cloud security by building on your existing cloud knowledge and pursuing security certifications.

  • @asadkhanuit
    @asadkhanuit 3 роки тому

    Very good demo for people who don't know about hacking

  • @tomknud
    @tomknud Рік тому +1

    100% !

    • @KodeKloud
      @KodeKloud  Рік тому

      Thank you so much : ) We are glad to be a part of your learning journey

  • @nksajeer
    @nksajeer 3 роки тому

    great content

    • @KodeKloud
      @KodeKloud  3 роки тому +1

      Welcome! Please subscribe to our channel and help us create more such videos. Thanks 😊

  • @tengiz
    @tengiz 3 роки тому +1

    Marvellous

    • @KodeKloud
      @KodeKloud  3 роки тому +1

      Thanks👍
      Please subscribe and encourage us to provide more such quality content.

  • @abhishekhiremath8955
    @abhishekhiremath8955 3 роки тому +1

    Nice

    • @KodeKloud
      @KodeKloud  3 роки тому

      Thanks! Please subscribe to our channel and keep supporting😊

  • @aogunnaike
    @aogunnaike 3 роки тому

    Awesome 👍😎

    • @KodeKloud
      @KodeKloud  3 роки тому

      Thanks! Please subscribe to the channel and help us do more such creative educational videos.

    • @aogunnaike
      @aogunnaike 3 роки тому

      @@KodeKloud already a subscriber sir, cheers!

  • @anathema157
    @anathema157 3 роки тому

    By default docker running only as Unix service

  • @bestviraltubeshorts
    @bestviraltubeshorts 3 роки тому

    Someone know how can i put a logo in my zsh terminal, like that?

  • @nguyenanhnguyen7658
    @nguyenanhnguyen7658 3 роки тому

    Nice... :)

  • @abhishekjaiswal5239
    @abhishekjaiswal5239 3 роки тому

    where can we get the dirty-cow.sh

  • @prashanthjs915
    @prashanthjs915 3 роки тому +1

    cue fargo theme

  • @simonshkilevich3032
    @simonshkilevich3032 Рік тому +2

    😳

    • @KodeKloud
      @KodeKloud  Рік тому

      Thanks for watching our video. Cheers!

  • @AbhijeetSachdev
    @AbhijeetSachdev 3 роки тому

    :D

  • @nestorreveron
    @nestorreveron 3 роки тому +1

    Awesome 👌

  • @ismaelgrahms
    @ismaelgrahms 3 роки тому

    Great content

  • @debkr
    @debkr Рік тому

    Awesome 👍

    • @KodeKloud
      @KodeKloud  Рік тому

      Thanks for your love and support!