4 ms·
It is far harder to exploit on Kubernetes then on a laptop running a dnsmasq cache attached to a starbucks wifi. You would need to middle man traffic between d
by dward 9y ago
It is far harder to exploit on Kubernetes then on a laptop running a dnsmasq cache attached to a starbucks wifi.
You would need to middle man traffic between dnsmasq and upstream DNS or have some control over DNS records and be able to force dnsmasq to do lookups. As you point out the escalation is also far more limited. Ok, so you have a shell in the dnsmasq container. Now what?