Hacking Articles Tips Tricks Videos Tutorials
469 subscribers
66.4K photos
15 videos
157 files
133K links
Exploit
Pentesting
Hacking
Red Team
Blue Team
Kali Linux
Bug Bounty
Black Hat
Cyber security etc

@Hacking_Video
@Hacking_attack
Download Telegram
Hacking Articles Tips Tricks Videos Tutorials
Photo
KitPloit - PenTest Tools!
Kubernetes-Goat - Is A "Vulnerable By Design" Kubernetes Cluster. Designed To Be An Intentionally Vulnerable Cluster Environment To Learn And Practice Kubernetes Security

https://blogger.googleusercontent.com/img/a/AVvXsEiCnpVDs62xyVPX-RIcFO-TEj0QRwScPp5o0VmCys8ga9rcOC6sM8rt_NIE_NGGvU6ZkoxeboxPfKxLewTLkYHb4P6ekDe5TM8eQM1zPKV1HPnVixPnuk_iwD-6auPTK4a70EGqrtYIOYTGcwgBVzWB00wl9WQ5llbDK5nBq40n7QVOMuzcQZVZRVgPcA=s320 The Kubernetes Goat is designed to be an intentionally vulnerable cluster environment to learn and practice Kubernetes security.

Refer to https://madhuakula.com/kubernetes-goat for the guide. Show us some Please feel free to send us a PR and show some https://blogger.googleusercontent.com/img/a/AVvXsEhSQYyWcW7lzlMIZqyWVytW5Ck4V8ufhiY9eWOWPxEclad3usm0harZMcH1joPAq1GiXKkNCpB9pH3Hat3ZRcNh5c0d1MuhRj1f1_bdcOpTgsAP0BpLeGPj-D9a84MqoyumdkfEEqw8BpoocQ-skDvTR2T2Us9G0AcbgJpQEzitNPbcxYcG_492WyRsqw=s320 Upcoming Training's and SessionsDEFCON DEMO Labs

* https://forum.defcon.org/node/237237

Cloud Village - DEFCON

* https://cloud-village.org/#talks?collapseMadhuAkula Recent Kubernetes Goat PresentationsOWASP Bay Area Meetup
DEFCON Red Team Village Just click and Play in the browser for free using Katacoda Playground - Try nowhttps://katacoda.com/madhuakula/scenarios/kubernetes-goat Setting up Kubernetes Goat* Before we set up the Kubernetes Goat, ensure that you have created and have admin access to the Kubernetes cluster kubectl version --short* Set up the helm version 2 in your path as helm2. Refer to helm releases for more information about setup helm2 --help* Then finally setup Kubernetes Goat by running the following command git clone https://github.com/madhuakula/kubernetes-goat.git
cd kubernetes-goat
bash setup-kubernetes-goat.sh
* To export the ports/services locally to start learning, run the following command bash access-kubernetes-goat.sh* Then navigate to http://127.0.0.1:1234 Kubernetes Goat - KIND setup* If you want to setup Kubernetes Goat using KIND, refer to kind-setup Scenarios1. Sensitive keys in code-bases
2. DIND (docker-in-docker) exploitation
3. SSRF in K8S world
4. Container escape to access host system
5. Docker CIS Benchmarks analysis
6. Kubernetes CIS Benchmarks analysis
7. Attacking private registry
8. NodePort exposed services
9. Helm v2 tiller to PwN the cluster
10. Analysing crypto miner container
11. Kubernetes Namespaces bypass
12. Gaining environment information
13. DoS the memory/CPU resources
14. Hacker Container preview
15. Hidden in layers
16. RBAC Least Privileges Misconfiguration
17. KubeAudit - Audit Kubernetes Clusters
18. Sysdig Falco - Runtime Security Monitoring & Detection
19. Popeye - A Kubernetes Cluster Sanitizer
20. Secure network boundaries using NSP Showcase* Presented at OWASP Bay Area Meetup at https://youtu.be/DQllxpb46Yw
* Presented at DEF CON RED Team Village https://youtu.be/aEaSZJRbnTo
* Presented at OWASP San Diego at https://www.meetup.com/Open-Web-Application-Security-Project-San-Diego-OWASP-SD/events/hmbbkrybckbvb/
* Featured in the official Kubernetes Podcast at https://kubernetespodcast.com/episode/109-kubermatic
* Featured in tl;dr sec https://tldrsec.com/blog/tldr-sec-039
* Featured in CloudSecList https://cloudseclist.com/issues/issue-42
* Presented at EkoParty 2020 DevSecOps https://youtu.be/XqwbVU-gtng
* Presented at c0c0cn 2020 https://india.c0c0n.org/2020/speakers#madhu_akula
* Featured in Info Ck YouTube channel https://youtu.be/5ojho4L6Xfo
* Presented in Cloud Native Indonesia Meetup https://youtu.be/pf5jOGWoWU0
* Presented in USENIX LISA 2021 Closing Note
* Presented in SANS CloudSecNext Summit 2021 DisclaimerKubern[...]

___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
KitPloit - PenTest Tools! Kubernetes-Goat - Is A "Vulnerable By Design" Kubernetes Cluster. Designed To Be An Intentionally Vulnerable Cluster Environment To Learn And Practice Kubernetes Security https://blogger.googleusercontent.com/img/a/AVvXsEiCnpVDs62xyVPX…
etes Goat creates intentionally vulnerable resources into your cluster. DO NOT deploy Kubernetes Goat in a production environment or alongside any sensitive cluster resources.

Kubernetes Goat comes with absolutely no warranties whatsoever. By using Kubernetes Goat, you take full responsibility for all outcomes that result. Download Kubernetes-Goat

___________________________
@hacking_Attack
@Hacking_Video
Dark Reading: Attacks/Breaches
Addressing the Low-Code Security Elephant in the Room

The danger of anyone being able to spin up new applications is that few are thinking about security. Here's why everyone is responsible for the security of low-code/no-code applications.
Kubernetes-Goat - Is A "Vulnerable By Design" Kubernetes Cluster. Designed To Be An Intentionally Vulnerable Cluster Environment To Learn And Practice Kubernetes Security
http://www.kitploit.com/2021/11/kubernetes-goat-is-vulnerable-by-design.html

___________________________
@hacking_Attack
@Hacking_Video
Upcoming Training's and SessionsDEFCON DEMO Labshttps://forum.defcon.org/node/237237Cloud Village - DEFCONhttps://cloud-village.org/#talks?collapseMadhuAkula
Recent Kubernetes Goat Presentations
OWASP Bay Area Meetup DEFCON Red Team Village
Just click and Play in the browser for free using Katacoda Playground - Try nowhttps://katacoda.com/madhuakula/scenarios/kubernetes-goat
Setting up Kubernetes GoatBefore we set up the Kubernetes Goat, ensure that you have created and have admin access to the Kubernetes clusterkubectl version --shortSet up the helm version 2 in your path as helm2. Refer to helm releases (https://github.com/helm/helm/releases) for more information about setuphelm2 --helpThen finally setup Kubernetes Goat by running the following commandgit clone https://github.com/madhuakula/kubernetes-goat.git
cd kubernetes-goat
bash setup-kubernetes-goat.shTo export the ports/services locally to start learning, run the following commandbash access-kubernetes-goat.shThen navigate to http://127.0.0.1:1234 (http://127.0.0.1:1234/)
Kubernetes Goat - KIND setup
If you want to setup Kubernetes Goat using KIND, refer to kind-setup (https://github.com/madhuakula/kubernetes-goat/blob/master/kind-setup/README.md)
ScenariosSensitive keys in code-basesDIND (docker-in-docker) exploitationSSRF in K8S worldContainer escape to access host systemDocker CIS Benchmarks analysisKubernetes CIS Benchmarks analysisAttacking private registryNodePort exposed servicesHelm v2 tiller to PwN the clusterAnalysing crypto miner containerKubernetes Namespaces (https://www.kitploit.com/search/label/Namespaces) bypassGaining environment informationDoS the memory/CPU resourcesHacker Container (https://www.kitploit.com/search/label/Container) previewHidden in layersRBAC Least Privileges MisconfigurationKubeAudit - Audit Kubernetes ClustersSysdig Falco - Runtime Security Monitoring & DetectionPopeye - A Kubernetes Cluster SanitizerSecure network boundaries using NSP
ShowcasePresented at OWASP Bay Area Meetup at https://youtu.be/DQllxpb46YwPresented at DEF CON RED Team Village https://youtu.be/aEaSZJRbnToPresented at OWASP San Diego at https://www.meetup.com/Open-Web-Application-Security-Project-San-Diego-OWASP-SD/events/hmbbkrybckbvb/Featured in the official Kubernetes Podcast at https://kubernetespodcast.com/episode/109-kubermatic (https://kubernetespodcast.com/episode/109-kubermatic/)Featured in tl;dr sec https://tldrsec.com/blog/tldr-sec-039 (https://tldrsec.com/blog/tldr-sec-039/)Featured in CloudSecList https://cloudseclist.com/issues/issue-42 (https://cloudseclist.com/issues/issue-42/)Presented at EkoParty 2020 DevSecOps https://youtu.be/XqwbVU-gtngPresented at c0c0cn 2020 https://india.c0c0n.org/2020/speakers#madhu_akulaFeatured in Info Ck YouTube channel https://youtu.be/5ojho4L6XfoPresented in Cloud Native (https://www.kitploit.com/search/label/Cloud%20Native) Indonesia Meetup https://youtu.be/pf5jOGWoWU0Presented in USENIX LISA 2021 Closing Note (https://www.usenix.org/conference/lisa21/presentation/closing)Presented in SANS CloudSecNext Summit 2021
DisclaimerKubernetes Goat creates intentionally vulnerable resources into your cluster. DO NOT deploy Kubernetes Goat in a production environment or alongside any sensitive cluster resources.Kubernetes Goat comes with absolutely no warranties whatsoever. By using Kubernetes Goat, you take full responsibility for all outcomes that result.

Download Kubernetes-Goat (https://github.com/madhuakula/kubernetes-goat)

___________________________
@hacking_Attack
@Hacking_Video
hacking: security in practice
Weird piece of malware disguised as nodejs version has us clueless

Hey there friends, today we came across a really weird piece of "malware" and we honestly have no clue what's going on anymore. Link: anonfiles Virustotal: virustotal from the behaviour we didn't notice anything out of the ordinary, only that it accessed some github pages which after some analysis turned out to be standard github repo's belonging to nodejs, google, and some other random, non-malicious repo's.

The original victim claimed that their discord account had been stolen after running this executable, after which this same exe got sent to everybody in their friendslist, prompting them to "help test a game". After the victim opened the exe, windows prevented it from running due to an unknown publisher, after which the victim continue to run it, a cmd window showed up, their discord crashed and the program seemed to exit. We were not able to find any malicious processes active on their pc, no extra sessions active on their discord, nothing seemed to have changed, we were not able to find any persistence, etc etc. The file metadata describes that it is nodejs version 14.15.1, however the hashes do not match. From behavioral analysis, it showed that it was acting with a bunch of regular nodejs files, and didn't seem to do anything weird. MalwareBytes, bitdefender and windows defender all showed no threats on the pc



We have no clue anymore what's going on, and we aren't entirely convinced that the victim pc is safe due to the nature of how the program got spread to them. It's entirely possible the original victim got infected some other way and this could all be a troll, but we still are very suspicious due to the file not being signed, while claiming to be nodejs, and not matching the hashes to a valid version



Any help would be appreciated, I'm personally very interested in learning more about this, and finding out if it's even malicious. Thanks in advance! :D

submitted by /u/Kip167
[link] [comments]

___________________________
@hacking_Attack
@Hacking_Video