Hacking a Kubernetes Cluster: A Practical Example!

  Рет қаралды 62,706

KodeKloud

KodeKloud

Күн бұрын

Пікірлер: 62
@KodeKloud
@KodeKloud Жыл бұрын
Full Certified Kubernetes Application Developer (CKAD) Course: kode.wiki/CKAD_YT
@lhxperimental
@lhxperimental 3 жыл бұрын
Not a realistic production scenario. Webservers/Load Balancers are usually on a different server and network than the Kubernetes cluster. The cluster itself has no direct internet connectivity and only ports exposed to the world are the HTTP(S) ports of the load balancers
@AndresLeonRangel
@AndresLeonRangel 2 жыл бұрын
you will be surprised to know that some companies actually have scenarios like this one...
@okharev8114
@okharev8114 2 жыл бұрын
if only
@abdurrahmanhr
@abdurrahmanhr 3 жыл бұрын
Great clip with crisp coverage on security
@KodeKloud
@KodeKloud 3 жыл бұрын
Glad you enjoyed it! Please subscribe to our channel and keep supporting😊
@tendaimusonza9547
@tendaimusonza9547 3 жыл бұрын
Wonderful, great hands on presentation
@KodeKloud
@KodeKloud 3 жыл бұрын
Many thanks! Please subscribe and encourage us to create more such quality content.
@anthonydelagarde3990
@anthonydelagarde3990 2 жыл бұрын
Thank you a fantastic video and demonstration
@KodeKloud
@KodeKloud 2 жыл бұрын
Glad it was helpful!
@manojpansare2007
@manojpansare2007 3 жыл бұрын
Excellent and eye opener....👌👌👌
@KodeKloud
@KodeKloud 3 жыл бұрын
Glad you liked it! Thanks:)
@ramakrishnabommerla3176
@ramakrishnabommerla3176 3 жыл бұрын
amazing explanation :) great use-case
@ileriayoadebiyi
@ileriayoadebiyi 3 жыл бұрын
That election story surely was scary!!! Great video, Mumshad! Always love your videos!
@KodeKloud
@KodeKloud 3 жыл бұрын
Glad you liked it! Please subscribe and encourage us to create more such quality content.
@ileriayoadebiyi
@ileriayoadebiyi 3 жыл бұрын
What!?? Never knew I wasn’t subscribed 😭 By the way, all my DevOps friends and wannabes are tired of me talking about kodekloud
@makevoid
@makevoid 3 жыл бұрын
From 2021 Kubernetes (v1.20+) removes the default dependency on docker in favour of containerd. This "attack" may work on a badly configured Kubernetes version prior to that and also on a poorly configured docker swarm cluster.
@tendaimusonza9547
@tendaimusonza9547 3 жыл бұрын
I subscribed within the first few seconds of hearing the quality stuff ,lol
@matteobaiguini5940
@matteobaiguini5940 3 жыл бұрын
can you please share the material you used for the demo? maybe a git repo?
@KASANITEJ
@KASANITEJ 3 жыл бұрын
I can understand ssh port being open by mistake.... but I can't wrap around why docker port is opened?
@asadkhanuit
@asadkhanuit 3 жыл бұрын
Very good demo for people who don't know about hacking
@rishabhjain2940
@rishabhjain2940 2 жыл бұрын
What is this tools for port scanning? And where I can get it ?
@durden0
@durden0 3 жыл бұрын
Do people really run their docker hosts with no authentication and their kubernetes dashboards exposed to the internet?
@EderNucci
@EderNucci 3 жыл бұрын
No. :-D
@EderNucci
@EderNucci 3 жыл бұрын
Having the docker port exposed is simply the most stupid thing I think someone can do on a cluster. Why they did this?
@thehackingexplorer3636
@thehackingexplorer3636 3 жыл бұрын
Because they are dog lovers. LoL
@kubectlgetpo
@kubectlgetpo 3 жыл бұрын
No one did it.. it's made up scenario that teaches theater security
@EderNucci
@EderNucci 3 жыл бұрын
@@kubectlgetpo watch again at 0:40 :-)
@CipherNL
@CipherNL 3 жыл бұрын
I find it even more fascinating how the http and https ports are not open.
@kubectlgetpo
@kubectlgetpo 3 жыл бұрын
@@CipherNL yeah crap scenario all around
@nestorreveron
@nestorreveron 3 жыл бұрын
Awesome 👌
@aldyj4733
@aldyj4733 3 жыл бұрын
This is the epitome of one jumps into kubernetes too quickly without regards to any best practices (pain points: exposed docker port + conn string as env var) whatsoever...
@aldyj4733
@aldyj4733 3 жыл бұрын
And sadly, the majority of people still do this...
@KodeKloud
@KodeKloud 3 жыл бұрын
Yes, that's true.
@mafujaakhtar9876
@mafujaakhtar9876 Жыл бұрын
Hi Mumshad brother, is it possible to be a DevOps engineer for a non tech person? I am an an anthropologist, had career break for children now I got interested in cloud. I am a certified cloud practitioners and courntly I am doing cybersecurity program. I am interested about cloud security though I am new in this field. How long need to I have to work in cloud then I can try for the cloud security? I am a mother of two teenage kids and fourty plass cloud savvy.
@KodeKloud
@KodeKloud Жыл бұрын
Certainly, transitioning into a DevOps or cloud security role is achievable, even without a traditional tech background. With your Cloud Practitioner certification, explore advanced cloud certifications and gain hands-on experience. Learn automation tools and DevOps practices. Leverage your unique background in anthropology for soft skills. Focus on cloud security by building on your existing cloud knowledge and pursuing security certifications.
@ismaelgrahms
@ismaelgrahms 3 жыл бұрын
Great content
@KodeKloud
@KodeKloud 3 жыл бұрын
Thanks:)
@LuizJrDeveloper
@LuizJrDeveloper Жыл бұрын
How did you put an icon in ZSH?
@KodeKloud
@KodeKloud Жыл бұрын
You can use powerlevel10k for custom ZSH
@tomknud
@tomknud Жыл бұрын
100% !
@KodeKloud
@KodeKloud Жыл бұрын
Thank you so much : ) We are glad to be a part of your learning journey
@bestviraltubeshorts
@bestviraltubeshorts 3 жыл бұрын
Someone know how can i put a logo in my zsh terminal, like that?
@tengiz
@tengiz 3 жыл бұрын
Marvellous
@KodeKloud
@KodeKloud 3 жыл бұрын
Thanks👍 Please subscribe and encourage us to provide more such quality content.
@anathema157
@anathema157 3 жыл бұрын
By default docker running only as Unix service
@abhishekjaiswal5239
@abhishekjaiswal5239 3 жыл бұрын
where can we get the dirty-cow.sh
@abhishekhiremath8955
@abhishekhiremath8955 3 жыл бұрын
Nice
@KodeKloud
@KodeKloud 3 жыл бұрын
Thanks! Please subscribe to our channel and keep supporting😊
@nguyenanhnguyen7658
@nguyenanhnguyen7658 3 жыл бұрын
Nice... :)
@prashanthjs915
@prashanthjs915 3 жыл бұрын
cue fargo theme
@simonshkilevich3032
@simonshkilevich3032 Жыл бұрын
😳
@KodeKloud
@KodeKloud Жыл бұрын
Thanks for watching our video. Cheers!
@AbhijeetSachdev
@AbhijeetSachdev 3 жыл бұрын
:D
@debkr
@debkr Жыл бұрын
Awesome 👍
@KodeKloud
@KodeKloud Жыл бұрын
Thanks for your love and support!
@nksajeer
@nksajeer 3 жыл бұрын
great content
@KodeKloud
@KodeKloud 3 жыл бұрын
Welcome! Please subscribe to our channel and help us create more such videos. Thanks 😊
@aogunnaike
@aogunnaike 3 жыл бұрын
Awesome 👍😎
@KodeKloud
@KodeKloud 3 жыл бұрын
Thanks! Please subscribe to the channel and help us do more such creative educational videos.
@aogunnaike
@aogunnaike 3 жыл бұрын
@@KodeKloud already a subscriber sir, cheers!
Complete Lens Course | The Best Kubernetes IDE for DevOps
32:00
Kubernetes Hacking: From Weak Applications to Cluster Control
36:22
Men Vs Women Survive The Wilderness For $500,000
31:48
MrBeast
Рет қаралды 99 МЛН
Je peux le faire
00:13
Daniil le Russe
Рет қаралды 21 МЛН
HAH Chaos in the Bathroom 🚽✨ Smart Tools for the Throne 😜
00:49
123 GO! Kevin
Рет қаралды 13 МЛН
Or is Harriet Quinn good? #cosplay#joker #Harriet Quinn
00:20
佐助与鸣人
Рет қаралды 58 МЛН
Kubernetes Security Best Practices - Ian Lewis, Google
28:53
CNCF [Cloud Native Computing Foundation]
Рет қаралды 50 М.
Hacking and Hardening Kubernetes Clusters by Example [I] - Brad Geesaman, Symantec
39:31
CNCF [Cloud Native Computing Foundation]
Рет қаралды 41 М.
Kubernetes Services networking
7:13
Project Calico
Рет қаралды 85 М.
Detecting Kubernetes Security Threats with Falco
17:48
DevOps Toolkit
Рет қаралды 6 М.
Conduct a Penetration Test Like a Pro in 6 Phases  [Tutorial]
13:37
Container Security Explained
6:51
IBM Technology
Рет қаралды 63 М.
Attacking and Detecting Attacks on Kubernetes Clusters
49:29
RSA Conference
Рет қаралды 1,2 М.
How to Hack ArgoCD to Cluster Administrator
19:24
John Hammond
Рет қаралды 11 М.
Men Vs Women Survive The Wilderness For $500,000
31:48
MrBeast
Рет қаралды 99 МЛН