Skip to content

Latest commit

 

History

History
75 lines (38 loc) · 2.18 KB

SteamCloud.md

File metadata and controls

75 lines (38 loc) · 2.18 KB

SteamCloud HACKTHEBOX

ENUMERATION

NMAP

image

When you can see this is a kubernetes machines

Let's try to use kubectl

image

I don't have credentials.

Let's try with kubeletctl

image

Nice i recivied pods from Kubelets

I try to gain RCE in any pod

image

Nginx and Kube-Proxy are injectables

I try with nginx and next Kube-Proxy

I have shell in nginx!

image

Hacktricks

https://book.hacktricks.xyz/cloud-security/pentesting-kubernetes/kubernetes-enumeration

image

I try to see Token an Certificate

I have all:

image

Look that

image

Let's list privilieges

image

I can create new pod!!

I copy same structuere

image

image

I comprove:

image

Perfect!!

I gain shell:

image

image

DONE :)