Hacker News new | past | comments | ask | show | jobs | submit login
Hacking DigitalOcean's New Kubernetes Service (4armed.com)
15 points by developer2 on Dec 20, 2018 | hide | past | favorite | 2 comments



the only problem i see is one thing. once you have the access token you can access all resources in all projects.

but besides that, you only breach/change your own account. I mean keep in mind the GKE cluster does not use NetworkPolicy or other stuff to secure their cluster, too.


exposing the etcd key via the metadata service and then having etcd visible on the Internet is bad.

This means that a single SSRF or RCE bug in any application running on a cluster using this approach can be trivially escalated to full cluster compromise.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: