· Containers
When LIST is a Lie in Kubernetes
I’m writing about the Kubernetes API’s use of the “LIST” verb it controls access to Secrets in a cluster. I’ve seen way too may environments, tools, templates, and examples that are hoping …
/dev/loop3 ro squashfs ---------------------------------------------------------~inode 0x4e21c8
uts:ns 4026532198 ----------------------------------------------------------#cap_sys_admin -eff
seccomp filt 0x1f ---------------------------------------------------------#rtt 12.4ms mtu 1500
::fe80::4a2c/64 ::::::::::::::::::::::::::::::::::::::::::::::::::::::::[vmalloc 0xffffc90000]
Containers, kubernetes, AI, sandboxes, security, Linux isolation
and whatever else looks interesting enough to take apart.
research · 01 Nov 2020
· Containers
I’m writing about the Kubernetes API’s use of the “LIST” verb it controls access to Secrets in a cluster. I’ve seen way too may environments, tools, templates, and examples that are hoping …
· Containers
TL;DR The Linux Kernel keyring is known to be a security issue for containers Download my tool for breaking out of a container to steal all the host keys here: keyctl-unmask We can use this in Kubernetes to steal all …