Local File Inclusion (interesting method)
https://captainhoook.medium.com/local-file-inclusion-interesting-method-8263c2cb7cd2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://captainhoook.medium.com/local-file-inclusion-interesting-method-8263c2cb7cd2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Local File Inclusion (interesting method)
Hello researchers, This is Captain_hook and I decide to Share An interesting LFI vulnerability That I found In BC’s program.
Hello researchers, This is Captain_hook and I decide to Share An interesting LFI vulnerability That I found In BC’s program.Continue reading on Medium » (https://captainhoook.medium.com/local-file-inclusion-interesting-method-8263c2cb7cd2?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Local File Inclusion (interesting method)
Hello researchers, This is Captain_hook and I decide to Share An interesting LFI vulnerability That I found In BC’s program.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Kali Linux Tutorials
Cybersecurity in No-Code platforms: Key Principles
If you’re developing an application using no-code platform, it’s important to understand the risks of cybersecurity.
A no-code software makes it easier than ever before for developers and non-developers alike to create applications. With so many people able to access your codebase, however, you must be equally as ready for anything that could go wrong.
Below are some generalized principles and best practices when it comes to developing secure applications using no-code platforms: Understand the no-code risksWhen you’re building an application with no-code, you’ll want to understand the risks. This will help you identify potential threats and prevent them from happening. Here are some key principles to consider:
* Understand how a malicious user can misuse your identity, such as by impersonating you or pretending to be someone else.
* Understand authorization misuses, including unauthorized access, alteration or destruction of content or data records.
* Understand data leakages and unexpected consequences that might result from improper use of personal information (such as users’ contact information) within your application or system design. Data leaks could include other types of sensitive data such as health plan information, financial account numbers and Social Security numbers.
* Address authentication and secure communication failures (for example: passwords/passphrases not properly secured). If users don’t know what they need to do in order for their credentials not being used improperly against them then they won’t know how important it is for them to protect their own security practices!
* Securing the network infrastructure itself through proper configuration management processes (including changes made on the fly without any consideration for adding new security measures). Think about the advantagesIf you’re wondering what advantages you could gain from a no-code platform, here are some of the most important ones:
* They’re easy to use
A no-code platform reduces the learning curve for most users, because they don’t require coding skills or previous technical knowledge. This makes it possible for anyone with basic computer literacy to set up and run an online business in a matter of minutes.
* They’re affordable
Because they require less training and expertise than other software products, no-code platforms tend to be more cost-effective than most alternatives on the market today. And because their initial investment requirements are so low, even small businesses can take advantage of them without fear of breaking their budgets.
* They’re accessible from anywhere at any time
Whether through desktop computers or mobile devices like smartphones or tablets (e.g., iPads). This means that individuals who need access from different locations will have no trouble getting started with these types of products; plus those businesses already struggling with remote workers might find it easier too! Ensure cybersecurity in apps built by no-codeAs you’re planning to build a no-code app, it is essential that you understand and think about some of the risks associated with cybersecurity. For example, if your app has a high degree of automation and/or uses IoT devices, there are more reasons to worry about security and privacy issues.
But there are also advantages in building an app by no-code:
* It’s easy to scale.
* Developers don’t need to learn any new languages or technologies.
* They can use their existing skill sets instead of learning new ones
* There is no complex coding needed (e.g., writing code for an algorithm)
* There is no need for specialized knowledge since everything can be done through drag-and-drop interfaces. Consider other technical precautionsEven though you’ve gotten all the basics of a No-Code platform, there are sti[...]
___________________________
@hacking_Attack
@Hacking_Video
Cybersecurity in No-Code platforms: Key Principles
If you’re developing an application using no-code platform, it’s important to understand the risks of cybersecurity.
A no-code software makes it easier than ever before for developers and non-developers alike to create applications. With so many people able to access your codebase, however, you must be equally as ready for anything that could go wrong.
Below are some generalized principles and best practices when it comes to developing secure applications using no-code platforms: Understand the no-code risksWhen you’re building an application with no-code, you’ll want to understand the risks. This will help you identify potential threats and prevent them from happening. Here are some key principles to consider:
* Understand how a malicious user can misuse your identity, such as by impersonating you or pretending to be someone else.
* Understand authorization misuses, including unauthorized access, alteration or destruction of content or data records.
* Understand data leakages and unexpected consequences that might result from improper use of personal information (such as users’ contact information) within your application or system design. Data leaks could include other types of sensitive data such as health plan information, financial account numbers and Social Security numbers.
* Address authentication and secure communication failures (for example: passwords/passphrases not properly secured). If users don’t know what they need to do in order for their credentials not being used improperly against them then they won’t know how important it is for them to protect their own security practices!
* Securing the network infrastructure itself through proper configuration management processes (including changes made on the fly without any consideration for adding new security measures). Think about the advantagesIf you’re wondering what advantages you could gain from a no-code platform, here are some of the most important ones:
* They’re easy to use
A no-code platform reduces the learning curve for most users, because they don’t require coding skills or previous technical knowledge. This makes it possible for anyone with basic computer literacy to set up and run an online business in a matter of minutes.
* They’re affordable
Because they require less training and expertise than other software products, no-code platforms tend to be more cost-effective than most alternatives on the market today. And because their initial investment requirements are so low, even small businesses can take advantage of them without fear of breaking their budgets.
* They’re accessible from anywhere at any time
Whether through desktop computers or mobile devices like smartphones or tablets (e.g., iPads). This means that individuals who need access from different locations will have no trouble getting started with these types of products; plus those businesses already struggling with remote workers might find it easier too! Ensure cybersecurity in apps built by no-codeAs you’re planning to build a no-code app, it is essential that you understand and think about some of the risks associated with cybersecurity. For example, if your app has a high degree of automation and/or uses IoT devices, there are more reasons to worry about security and privacy issues.
But there are also advantages in building an app by no-code:
* It’s easy to scale.
* Developers don’t need to learn any new languages or technologies.
* They can use their existing skill sets instead of learning new ones
* There is no complex coding needed (e.g., writing code for an algorithm)
* There is no need for specialized knowledge since everything can be done through drag-and-drop interfaces. Consider other technical precautionsEven though you’ve gotten all the basics of a No-Code platform, there are sti[...]
___________________________
@hacking_Attack
@Hacking_Video
Kali Linux Tutorials
Cybersecurity in No-Code platforms: Key Principles - Kali Linux Tutorials
If you’re developing an application using no-code platform, it’s important to understand the risks of cybersecurity. A no-code software makes it easier than ever before for developers and non-developers alike to create applications. With so many people able…
Hacking Articles Tips Tricks Videos Tutorials
Kali Linux Tutorials Cybersecurity in No-Code platforms: Key Principles If you’re developing an application using no-code platform, it’s important to understand the risks of cybersecurity. A no-code software makes it easier than ever before for developers…
ll some important things to consider. In addition to the best practices above, make sure that you’re taking advantage of other technical precautions:
* Using 2-Factor Authentication (2FA) can help ensure that only authorized users are accessing your site and its data. If an attacker gains access to your account and changes any data, 2FA will stop them from being able to log in again without proof they’re authorized.
* HTTPS adds another layer of security by encrypting the traffic between visitors’ devices and your server. It’s an industry standard that most browsers now require by default when visiting websites with unsecured connections—but not all sites use it yet! You should make sure yours does if possible, since it makes it harder for hackers who may be intercepting web traffic on public Wi-Fi networks or through man-in-the-middle attacks.
* A Content Delivery Network (CDN) is a service that stores copies of your website files across multiple servers around the world so they load faster for everyone visiting from anywhere else in their region too. How to maintain cybersecurity in no-code?It’s important to ensure that your no-code platform is secure. The following are some of the key security principles to keep in mind when designing and building your project:
* Choose a secure platform. Make sure you use a platform that offers access controls and encryption, as well as something like two-factor authentication.
* Use a secure cloud provider. If you host your application on your own servers, make sure they’re protected by robust firewalls, antivirus software, anti-malware software and ransomware protection tools.
* Use secure networks when possible. When collaborating with external parties online—whether it’s other developers or partners like marketing agencies—be careful not to give them access to sensitive data unless absolutely necessary. Otherwise, they could potentially gain access via their own credentials (even if those credentials aren’t working). No-code platforms offer significant advantages to many businesses, but you need to understand the risks.No-code platforms can be a great way to build apps, no matter what your level of technical knowledge. They’re easy to use, offer many features and are easy to learn. However, there are also significant security risks associated with these platforms that you need to understand. ConclusionYou don’t have to be a developer to build powerful apps with no-code platforms. You just need to understand the risks and take steps to mitigate them. Investing in cybersecurity is one of the best ways to do this, but it isn’t always easy or intuitive for everyone. The good news is that there are plenty of resources available for non-technical users who want their apps to have robust security features. The key is having access to those resources so that when you need help, you can find it!
___________________________
@hacking_Attack
@Hacking_Video
* Using 2-Factor Authentication (2FA) can help ensure that only authorized users are accessing your site and its data. If an attacker gains access to your account and changes any data, 2FA will stop them from being able to log in again without proof they’re authorized.
* HTTPS adds another layer of security by encrypting the traffic between visitors’ devices and your server. It’s an industry standard that most browsers now require by default when visiting websites with unsecured connections—but not all sites use it yet! You should make sure yours does if possible, since it makes it harder for hackers who may be intercepting web traffic on public Wi-Fi networks or through man-in-the-middle attacks.
* A Content Delivery Network (CDN) is a service that stores copies of your website files across multiple servers around the world so they load faster for everyone visiting from anywhere else in their region too. How to maintain cybersecurity in no-code?It’s important to ensure that your no-code platform is secure. The following are some of the key security principles to keep in mind when designing and building your project:
* Choose a secure platform. Make sure you use a platform that offers access controls and encryption, as well as something like two-factor authentication.
* Use a secure cloud provider. If you host your application on your own servers, make sure they’re protected by robust firewalls, antivirus software, anti-malware software and ransomware protection tools.
* Use secure networks when possible. When collaborating with external parties online—whether it’s other developers or partners like marketing agencies—be careful not to give them access to sensitive data unless absolutely necessary. Otherwise, they could potentially gain access via their own credentials (even if those credentials aren’t working). No-code platforms offer significant advantages to many businesses, but you need to understand the risks.No-code platforms can be a great way to build apps, no matter what your level of technical knowledge. They’re easy to use, offer many features and are easy to learn. However, there are also significant security risks associated with these platforms that you need to understand. ConclusionYou don’t have to be a developer to build powerful apps with no-code platforms. You just need to understand the risks and take steps to mitigate them. Investing in cybersecurity is one of the best ways to do this, but it isn’t always easy or intuitive for everyone. The good news is that there are plenty of resources available for non-technical users who want their apps to have robust security features. The key is having access to those resources so that when you need help, you can find it!
___________________________
@hacking_Attack
@Hacking_Video
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
The Complete Guide to Phishing Define and How They Can Help You Avoid Getting Scammed 2021…
Phishing is a one of common method which is used in hacking methods.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
The Complete Guide to Phishing Define and How They Can Help You Avoid Getting Scammed 2021…
Phishing is a one of common method which is used in hacking methods.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
The Complete Guide to Phishing Define and How They Can Help You Avoid Getting Scammed 2021 |Tec-hacks
Phishing is a one of common method which is used in hacking methods. The main aim of the phishing is to collect the user’s credentials like…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How to hack Facebook account with Android 2021 | Tec-hacks
Hi, in this blog we will discuss Facebook account hacking or password cracking.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How to hack Facebook account with Android 2021 | Tec-hacks
Hi, in this blog we will discuss Facebook account hacking or password cracking.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How to hack Facebook account with Android 2021 | Tec-hacks
Hi, in this blog we will discuss Facebook account hacking or password cracking. The number of Facebook users is increasing day by day there…
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
Local File Inclusion (interesting method)
https://cdn-images-1.medium.com/max/680/0*S9PNriCTFQUcLo_F.png
Hello researchers, This is Captain_hook and I decide to Share An interesting LFI vulnerability That I found In BC’s program.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Local File Inclusion (interesting method)
https://cdn-images-1.medium.com/max/680/0*S9PNriCTFQUcLo_F.png
Hello researchers, This is Captain_hook and I decide to Share An interesting LFI vulnerability That I found In BC’s program.
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
Local File Inclusion (interesting method)
Hello researchers, This is Captain_hook and I decide to Share An interesting LFI vulnerability That I found In BC’s program.
Hacking Articles Tips Tricks Videos Tutorials
Photo
Hacking on Medium
How Quantum Computer Can Crack Bitcoin Network
https://cdn-images-1.medium.com/max/1900/1*VSlGRF74oaAPUsQeQgh1SQ.png
Author By Dr. Varin Khera
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
How Quantum Computer Can Crack Bitcoin Network
https://cdn-images-1.medium.com/max/1900/1*VSlGRF74oaAPUsQeQgh1SQ.png
Author By Dr. Varin Khera
Continue reading on Medium »
___________________________
@hacking_Attack
@Hacking_Video
Medium
How Quantum Computer Can Crack Bitcoin Network
Author By Dr. Varin Khera
Kubeaudit - Tool To Audit Your Kubernetes Clusters Against Common Security Controls
http://www.kitploit.com/2022/07/kubeaudit-tool-to-audit-your-kubernetes.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/07/kubeaudit-tool-to-audit-your-kubernetes.html
___________________________
@hacking_Attack
@Hacking_Video
Kitploit
Kitploit – Maintenance in Progress
Kitploit is temporarily under maintenance. We’ll be back shortly with improvements.
kubeaudit is a command line (https://www.kitploit.com/search/label/Command%20Line) tool and a Go package to audit Kubernetes clusters for various different security concerns, such as: run as non-root use a read-only root filesystem drop scary capabilities, don't add new ones don't run privileged and more! tldr. kubeaudit makes sure you deploy secure containers! Package To use kubeaudit as a Go package, see the package docs (https://pkg.go.dev/github.com/Shopify/kubeaudit). The rest of this README will focus on how to use kubeaudit as a command line tool. Command Line Interface (CLI) Installation (https://github.com/Shopify/kubeaudit#installation) Quick Start (https://github.com/Shopify/kubeaudit#quick-start) Audit Results (https://github.com/Shopify/kubeaudit#audit-results) Commands (https://github.com/Shopify/kubeaudit#commands) Configuration File (https://github.com/Shopify/kubeaudit#configuration-file) Override Errors (https://github.com/Shopify/kubeaudit#override-errors) Contributing (https://github.com/Shopify/kubeaudit#contributing) Installation Brew brew install kubeaudit
Download a binary Kubeaudit has official releases that are blessed and stable: Official releases (https://github.com/Shopify/kubeaudit/releases) DIY build Master may have newer features than the stable releases. If you need a newer feature not yet included in a release, make sure you're using Go 1.17+ and run the following: go get -v github.com/Shopify/kubeaudit Start using kubeaudit with the Quick Start (https://github.com/Shopify/kubeaudit#quick-start) or view all the supported commands (https://github.com/Shopify/kubeaudit#commands). Kubectl Plugin Prerequisite: kubectl v1.12.0 or later With kubectl v1.12.0 introducing easy pluggability (https://kubernetes.io/docs/tasks/extend-kubectl/kubectl-plugins/) of external functions, kubeaudit can be invoked as kubectl audit by running make plugin and having $GOPATH/bin available in your path. or renaming the binary to kubectl-audit and having it available in your path. Docker We also release a Docker image (https://hub.docker.com/r/shopify/kubeaudit): shopify/kubeaudit. To run kubeaudit as a job in your cluster see Running kubeaudit in a cluster (https://github.com/Shopify/kubeaudit/blob/main/docs/cluster.md). Quick Start kubeaudit has three modes: Manifest mode Local mode Cluster mode Manifest Mode If a Kubernetes manifest file is provided using the -f/--manifest flag, kubeaudit will audit the manifest file. Example command: kubeaudit all -f "/path/to/manifest.yml"
Example output: $ kubeaudit all -f "internal/test/fixtures/all_resources/deployment-apps-v1.yml"
---------------- Results for ---------------
apiVersion: apps/v1
kind: Deployment
metadata:
name: deployment
namespace: deployment-apps-v1
--------------------------------------------
-- [error] AppArmorAnnotationMissing
Message: AppArmor annotation missing. The annotation 'container.apparmor.security.beta.kubernetes.io/container' should be added.
Metadata:
Container: container
MissingAnnotation: container.apparmor.security.beta.kubernetes.io/container
-- [error] AutomountServiceAccountTokenTrueAndDefaultSA
Message: Default service account with token mounted. automountServiceAccountToken should be set to 'false' or a non-default service account should be used.
-- [error] CapabilityShouldDropAll
Message: Capability not set to ALL. Ideally, you should drop ALL capabilities and add the specific ones you need to the add list.
Metadata:
Container: container
Capability: AUDIT_WRITE
...
If no errors with a given minimum severity are found, the following is returned: All checks completed. 0 high-risk vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) found Autofix Manifest mode also supports autofixing all security issues using the autofix command: kubeaudit autofix -f "/path/to/manifest.yml"
___________________________
@hacking_Attack
@Hacking_Video
Download a binary Kubeaudit has official releases that are blessed and stable: Official releases (https://github.com/Shopify/kubeaudit/releases) DIY build Master may have newer features than the stable releases. If you need a newer feature not yet included in a release, make sure you're using Go 1.17+ and run the following: go get -v github.com/Shopify/kubeaudit Start using kubeaudit with the Quick Start (https://github.com/Shopify/kubeaudit#quick-start) or view all the supported commands (https://github.com/Shopify/kubeaudit#commands). Kubectl Plugin Prerequisite: kubectl v1.12.0 or later With kubectl v1.12.0 introducing easy pluggability (https://kubernetes.io/docs/tasks/extend-kubectl/kubectl-plugins/) of external functions, kubeaudit can be invoked as kubectl audit by running make plugin and having $GOPATH/bin available in your path. or renaming the binary to kubectl-audit and having it available in your path. Docker We also release a Docker image (https://hub.docker.com/r/shopify/kubeaudit): shopify/kubeaudit. To run kubeaudit as a job in your cluster see Running kubeaudit in a cluster (https://github.com/Shopify/kubeaudit/blob/main/docs/cluster.md). Quick Start kubeaudit has three modes: Manifest mode Local mode Cluster mode Manifest Mode If a Kubernetes manifest file is provided using the -f/--manifest flag, kubeaudit will audit the manifest file. Example command: kubeaudit all -f "/path/to/manifest.yml"
Example output: $ kubeaudit all -f "internal/test/fixtures/all_resources/deployment-apps-v1.yml"
---------------- Results for ---------------
apiVersion: apps/v1
kind: Deployment
metadata:
name: deployment
namespace: deployment-apps-v1
--------------------------------------------
-- [error] AppArmorAnnotationMissing
Message: AppArmor annotation missing. The annotation 'container.apparmor.security.beta.kubernetes.io/container' should be added.
Metadata:
Container: container
MissingAnnotation: container.apparmor.security.beta.kubernetes.io/container
-- [error] AutomountServiceAccountTokenTrueAndDefaultSA
Message: Default service account with token mounted. automountServiceAccountToken should be set to 'false' or a non-default service account should be used.
-- [error] CapabilityShouldDropAll
Message: Capability not set to ALL. Ideally, you should drop ALL capabilities and add the specific ones you need to the add list.
Metadata:
Container: container
Capability: AUDIT_WRITE
...
If no errors with a given minimum severity are found, the following is returned: All checks completed. 0 high-risk vulnerabilities (https://www.kitploit.com/search/label/vulnerabilities) found Autofix Manifest mode also supports autofixing all security issues using the autofix command: kubeaudit autofix -f "/path/to/manifest.yml"
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
To write the fixed manifest to a new file instead of modifying the source file, use the -o/--output flag. kubeaudit autofix -f "/path/to/manifest.yml" -o "/path/to/fixed"
To fix a manifest based on custom rules specified on a kubeaudit config file, use the -k/--kconfig flag. kubeaudit autofix -k "/path/to/kubeaudit-config.yml" -f "/path/to/manifest.yml" -o "/path/to/fixed"
Cluster Mode Kubeaudit can detect if it is running within a container in a cluster. If so, it will try to audit all Kubernetes resources in that cluster: kubeaudit all
Local Mode Kubeaudit will try to connect to a cluster using the local kubeconfig (https://www.kitploit.com/search/label/Kubeconfig) file ($HOME/.kube/config). A different kubeconfig location can be specified using the --kubeconfig flag. To specify a context of the kubeconfig, use the -c/--context flag. kubeaudit all --kubeconfig "/path/to/config" --context my_cluster
For more information on kubernetes config files, see https://kubernetes.io/docs/concepts/configuration/organize-cluster-access-kubeconfig/ Audit Results Kubeaudit produces results with three levels of severity: Error: A security issue or invalid kubernetes configuration Warning: A best practice recommendation Info: Informational, no action required. This includes results that are overridden (https://github.com/Shopify/kubeaudit#override-errors) The minimum severity level can be set using the --minSeverity/-m flag. By default kubeaudit will output results in a human-readable way. If the output is intended to be further processed, it can be set to output JSON using the --format json flag. To output results as logs (the previous default) use --format logrus. Some output formats include colors to make results easier to read in a terminal. To disable colors (for example, if you are sending output to a text file), you can use the --no-color flag. If there are results of severity level error, kubeaudit will exit with exit code 2. This can be changed using the --exitcode/-e flag. For all the ways kubeaudit can be customized, see Global Flags (https://github.com/Shopify/kubeaudit#global-flags). Commands Command Description Documentation all Runs all available auditors, or those specified using a kubeaudit config. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/all.md) autofix Automatically fixes security issues. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/autofix.md) version Prints the current kubeaudit version. Auditors Auditors can also be run individually. Command Description Documentation apparmor Finds containers (https://www.kitploit.com/search/label/Containers) running without AppArmor. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/apparmor.md) asat Finds pods using an automatically mounted default service account docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/asat.md) capabilities Finds containers that do not drop the recommended capabilities or add new ones. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/capabilities.md) deprecatedapis Finds any resource defined with a deprecated API version. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/deprecatedapis.md) hostns Finds containers that have HostPID, HostIPC or HostNetwork enabled. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/hostns.md) image Finds containers which do not use the desired version of an image (via the tag) or use an image without a tag. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/image.md) limits Finds containers which exceed the specified CPU and memory limits or do not specify any. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/limits.md) mounts Finds containers that have sensitive host paths mounted. docs
___________________________
@hacking_Attack
@Hacking_Video
To fix a manifest based on custom rules specified on a kubeaudit config file, use the -k/--kconfig flag. kubeaudit autofix -k "/path/to/kubeaudit-config.yml" -f "/path/to/manifest.yml" -o "/path/to/fixed"
Cluster Mode Kubeaudit can detect if it is running within a container in a cluster. If so, it will try to audit all Kubernetes resources in that cluster: kubeaudit all
Local Mode Kubeaudit will try to connect to a cluster using the local kubeconfig (https://www.kitploit.com/search/label/Kubeconfig) file ($HOME/.kube/config). A different kubeconfig location can be specified using the --kubeconfig flag. To specify a context of the kubeconfig, use the -c/--context flag. kubeaudit all --kubeconfig "/path/to/config" --context my_cluster
For more information on kubernetes config files, see https://kubernetes.io/docs/concepts/configuration/organize-cluster-access-kubeconfig/ Audit Results Kubeaudit produces results with three levels of severity: Error: A security issue or invalid kubernetes configuration Warning: A best practice recommendation Info: Informational, no action required. This includes results that are overridden (https://github.com/Shopify/kubeaudit#override-errors) The minimum severity level can be set using the --minSeverity/-m flag. By default kubeaudit will output results in a human-readable way. If the output is intended to be further processed, it can be set to output JSON using the --format json flag. To output results as logs (the previous default) use --format logrus. Some output formats include colors to make results easier to read in a terminal. To disable colors (for example, if you are sending output to a text file), you can use the --no-color flag. If there are results of severity level error, kubeaudit will exit with exit code 2. This can be changed using the --exitcode/-e flag. For all the ways kubeaudit can be customized, see Global Flags (https://github.com/Shopify/kubeaudit#global-flags). Commands Command Description Documentation all Runs all available auditors, or those specified using a kubeaudit config. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/all.md) autofix Automatically fixes security issues. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/autofix.md) version Prints the current kubeaudit version. Auditors Auditors can also be run individually. Command Description Documentation apparmor Finds containers (https://www.kitploit.com/search/label/Containers) running without AppArmor. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/apparmor.md) asat Finds pods using an automatically mounted default service account docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/asat.md) capabilities Finds containers that do not drop the recommended capabilities or add new ones. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/capabilities.md) deprecatedapis Finds any resource defined with a deprecated API version. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/deprecatedapis.md) hostns Finds containers that have HostPID, HostIPC or HostNetwork enabled. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/hostns.md) image Finds containers which do not use the desired version of an image (via the tag) or use an image without a tag. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/image.md) limits Finds containers which exceed the specified CPU and memory limits or do not specify any. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/limits.md) mounts Finds containers that have sensitive host paths mounted. docs
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
(https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/mounts.md) netpols Finds namespaces that do not have a default-deny network policy. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/netpols.md) nonroot Finds containers running as root. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/nonroot.md) privesc Finds containers that allow privilege escalation. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/privesc.md) privileged Finds containers running as privileged. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/privileged.md) rootfs Finds containers which do not have a read-only filesystem. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/rootfs.md) seccomp Finds containers running without Seccomp. docs (https://github.com/Shopify/kubeaudit/blob/main/docs/auditors/seccomp.md) Global Flags Short Long Description --format The output format to use (one of "pretty", "logrus", "json") (default is "pretty") --kubeconfig Path to local Kubernetes config file. Only used in local mode (default is $HOME/.kube/config) -c --context The name of the kubeconfig context to use -f --manifest Path to the yaml configuration to audit. Only used in manifest mode. You may use - to read from stdin. -n --namespace Only audit resources in the specified namespace. Not currently supported in manifest mode. -g --includegenerated Include generated resources in scan (such as Pods generated by deployments). If you would like kubeaudit to produce results for generated resources (for example if you have custom resources or want to catch orphaned resources where the owner resource no longer exists) you can use this flag. -m --minseverity Set the lowest severity level to report (one of "error", "warning", "info") (default is "info") -e --exitcode Exit code to use if there are results with severity of "error". Conventionally, 0 is used for success and all non-zero codes for an error. (default is 2) --no-color Don't use colors in the output (default is false) Configuration File The kubeaudit config can be used for two things: Enabling only some auditors Specifying configuration for auditors Any configuration that can be specified using flags for the individual auditors can be represented using the config. The config has the following format: enabledAuditors:
# Auditors are enabled by default if they are not explicitly set to "false"
apparmor: false
asat: false
capabilities: true
deprecatedapis: true
hostns: true
image: true
limits: true
mounts: true
netpols: true
nonroot: true
privesc: true
privileged: true
rootfs: true
seccomp: true
auditors:
capabilities:
# add capabilities needed to the add list, so kubeaudit won't report errors
allowAddList: ['AUDIT_WRITE', 'CHOWN']
deprecatedapis:
# If no versions are specified and the'deprecatedapis' auditor is enabled, WARN
# results will be genereted for the resources defined with a deprecated API.
currentVersion: '1.22'
targetedVersion: '1.25'
image:
# If no image is specified and the 'image' auditor is enabled, WARN results
# will be generated for containers which use an ima ge without a tag
image: 'myimage:mytag'
limits:
# If no limits are specified and the 'limits' auditor is enabled, WARN results
# will be generated for containers which have no cpu or memory limits specified
cpu: '750m'
memory: '500m' For more details about each auditor, including a description of the auditor-specific configuration in the config, see the Auditor Docs (https://github.com/Shopify/kubeaudit#auditors). Note: The kubeaudit config is not the same as the kubeconfig file specified with the --kubeconfig flag, which refers to the Kubernetes config file (see Local Mode
___________________________
@hacking_Attack
@Hacking_Video
# Auditors are enabled by default if they are not explicitly set to "false"
apparmor: false
asat: false
capabilities: true
deprecatedapis: true
hostns: true
image: true
limits: true
mounts: true
netpols: true
nonroot: true
privesc: true
privileged: true
rootfs: true
seccomp: true
auditors:
capabilities:
# add capabilities needed to the add list, so kubeaudit won't report errors
allowAddList: ['AUDIT_WRITE', 'CHOWN']
deprecatedapis:
# If no versions are specified and the'deprecatedapis' auditor is enabled, WARN
# results will be genereted for the resources defined with a deprecated API.
currentVersion: '1.22'
targetedVersion: '1.25'
image:
# If no image is specified and the 'image' auditor is enabled, WARN results
# will be generated for containers which use an ima ge without a tag
image: 'myimage:mytag'
limits:
# If no limits are specified and the 'limits' auditor is enabled, WARN results
# will be generated for containers which have no cpu or memory limits specified
cpu: '750m'
memory: '500m' For more details about each auditor, including a description of the auditor-specific configuration in the config, see the Auditor Docs (https://github.com/Shopify/kubeaudit#auditors). Note: The kubeaudit config is not the same as the kubeconfig file specified with the --kubeconfig flag, which refers to the Kubernetes config file (see Local Mode
___________________________
@hacking_Attack
@Hacking_Video
GitHub
kubeaudit/mounts.md at main · Shopify/kubeaudit
kubeaudit helps you audit your Kubernetes clusters against common security controls - kubeaudit/mounts.md at main · Shopify/kubeaudit