ANTITREE

/dev/loop3 ro squashfs ---------------------------------------------------------~inode 0x4e21c8

uts:ns 4026532198 ----------------------------------------------------------#cap_sys_admin -eff

seccomp filt 0x1f ---------------------------------------------------------#rtt 12.4ms mtu 1500

::fe80::4a2c/64 ::::::::::::::::::::::::::::::::::::::::::::::::::::::::[vmalloc 0xffffc90000]

antiTree

Containers, kubernetes, AI, sandboxes, security, Linux isolation

and whatever else looks interesting enough to take apart.

[SANDBOXES]
[RUNTIME]GVISORID: RTM-49GVISOR / SYSCALL 0x2A / 11:16:45
Syscalls & sandboxes
[CONTAINERS]
[CLUSTER]CONTAINERDNODE: K8S-17CGROUP V2 / CAP_SYS_ADMIN / 04:22:09
Containers
[AI AGENTS]
[INFERENCE]TOOL-CALLCTX: 128KMCP / TOKENS 4096 / 19:41:02
AI & agents

· Containers

Shmoocon Command and KubeCTL Talk Follow Up

Saturday, I gave my talk titled “Command and KubeCTL: Real-World Kubernetes Security for Pentesters” at Shmoocon 2020. I’m following up with this post that goes into more details than I could cover in 50 minutes.

Here’s the important stuff:

Premise

This talk was designed to be a Kubernetes security talk for people doing offensive security or looking at Kubernetes security from the perspective of an attacker. This is demo-focused where much of the talk is one long demo showing an attack chain. The goal being I wanted something complicated and simple to exploit. I wanted things to not work initially and you had to figure out ways around them.

If you’d like to read more and go throught he walk through, I’ve moved a lot of the write-up details to NCC Group’s research blog. You can find it here.