3 ms·
I'm wondering how exploitable this is. Kube-dns doesn't listen outside of the cluster, so to you need to be able to run arbitrary code inside the cluster to mak
by bboreham 9y ago
I'm wondering how exploitable this is. Kube-dns doesn't listen outside of the cluster, so to you need to be able to run arbitrary code inside the cluster to make use of it.
Then it lets you escape to the dnsmasq container. Which does have a shell, but I'm struggling to think how this gets you more capability than "able to run arbitrary code inside the cluster".
Most likely I missed something. Help me spot it.
- dward 9y agoIt is far harder to exploit on Kubernetes then on a laptop running a dnsmasq cache attached to a starbucks wifi. You would need to middle man traffic between dnsmasq and upstream DNS or have some control over DNS records and be able to force dnsmasq to do lookups. As you point out the escalation is also far more limited. Ok, so you have a shell in the dnsmasq container. Now what?