Insekube - TryHackMe - Kubernetes - Grafana Platform Local File Inclusion
Security_cnr
0:00 / 0:00
Insekube - TryHackMe - Kubernetes - Grafana Platform Local File Inclusion
642 просмотра · 4 года назад
Security_cnr
125 подписчиков
642 просмотра · 4 года назад
This lab demonstrates how one of the pods in the Kubernetes environment can be hijacked by leveraging a Grafana Local File Injection vulnerability. It is demonstrated that bad actors were able to navigate outside the Grafana folder and remotely access restricted locations on the server. In this tutorial, we reached to the token of the service account running a pod. To achieve pod privilege escalation, an "Everything Allowed" type pod was created. Using the exec command in the pod, a shell session was established with root privileges.