Hacking Alibaba Cloud's Kubernetes cluster, with Ronen Shustin and Hillai Ben-Sasson | KubeFM

  Рет қаралды 63

KubeFM

KubeFM

Күн бұрын

In this KubeFM episode, Hillai and Ronen, security researchers at Wiz, explore the intricacies of hacking Alibaba Cloud's Kubernetes cluster.
They share their experiences and insights on identifying and exploiting vulnerabilities, mainly focusing on misconfigurations and their impact on cloud security.
You will learn:
- How Hillai and Ronen gained access to a Kubernetes cluster through a Postgres database.
- How they moved laterally and managed to obtain push and pull rights to a private container registry.
- Recommendations for securing multi-tenant Kubernetes clusters and maintaining environment hygiene.
Find all the links and info for this episode here: kube.fm/hacking-alibaba-ronen...
===
Interested in sponsoring a KubeFM episode? kube.fm/sponsorships
===
CHAPTERS
=========
00:00 Intro
00:27 Emerging tools
01:49 Hillai and Ronen’s background
05:12 Follow your curiosity
05:54 Staying updated on Kubernetes
07:28 Offensive security research
11:30 PostgreSQL vulnerabilities in the cloud
13:31 PostgreSQL code execution
15:12 PostgreSQL on Kubernetes: Alibaba’s approach
17:04 Container security misconfigurations and risks
19:54 Creativity in security research
22:08 Exploiting SCP for container escalation
23:59 Gaining node access via Container Engine API
24:58 Kubelet misconfiguration exposed
26:55 Responsibly disclosing flaws and next steps
29:37 Containers not a strong security barrier
32:15 Peach: a framework for cloud isolation
34:31 Considerations for isolated multi-tenancy
37:07 Security is for everyone
40:10 White hat, black hat
42:05 Hugging Face
43:02 Outro
LISTEN ON
=========
- Apple Podcast kube.fm/apple
- Spotify kube.fm/spotify
- Amazon Music kube.fm/amazon
- Overcast kube.fm/overcast
- Pocket casts kube.fm/pocket-casts
- Deezer kube.fm/deezer

Пікірлер
A Hacker Shares His Biggest Fears | Informer
6:19
VICE
Рет қаралды 3,1 МЛН
THEY made a RAINBOW M&M 🤩😳 LeoNata family #shorts
00:49
LeoNata Family
Рет қаралды 36 МЛН
50 YouTubers Fight For $1,000,000
41:27
MrBeast
Рет қаралды 89 МЛН
🤔Какой Орган самый длинный ? #shorts
00:42
버블티로 체감되는 요즘 물가
00:16
진영민yeongmin
Рет қаралды 125 МЛН
The Attacker Perspective - Insights From Hacking Alibaba Cloud... Hillai Ben-Sasson & Ronen Shustin
31:49
CNCF [Cloud Native Computing Foundation]
Рет қаралды 3,5 М.
Event-Driven Architecture (EDA) vs Request/Response (RR)
12:00
Confluent
Рет қаралды 122 М.
Why I Quit the Scrum Alliance
7:58
The Passionate Programmer
Рет қаралды 11 М.
Easy $500 Vulnerabilities! // How To Bug Bounty
13:19
NahamSec
Рет қаралды 65 М.
Waterfall Over Agile In 2023???
9:00
Continuous Delivery
Рет қаралды 57 М.
Cloud Security is the FUTURE! - Here's Why
20:30
The Bearded I.T. Dad
Рет қаралды 15 М.
Where People Go When They Want to Hack You
34:40
CyberNews
Рет қаралды 1,2 МЛН
Kubernetes NodePort vs LoadBalancer vs Ingress
6:27
Anton Putra
Рет қаралды 61 М.
Hacking into Google's Network for $133,337
31:32
LiveOverflow
Рет қаралды 1 МЛН
PART 52 || DIY Wireless Switch forElectronic Lights - Easy Guide!
1:01
HUBAB__OFFICIAL
Рет қаралды 45 МЛН
تجربة أغرب توصيلة شحن ضد القطع تماما
0:56
صدام العزي
Рет қаралды 50 МЛН
OZON РАЗБИЛИ 3 КОМПЬЮТЕРА
0:57
Кинг Комп Shorts
Рет қаралды 1,7 МЛН
Опыт использования Мини ПК от TECNO
1:00
Андронет
Рет қаралды 784 М.