Table of Contents
-
About The Project
-
Getting Started
- Usage
- Roadmap
- Contributing
- License
- Contact
About The Project
Kubestroyer is a Golang exploitation tool that aims to take advantage of Kubernetes clusters misconfigurations.
The tool is scanning known Kubernetes ports that can be exposed as well as exploiting them.
(back to top)
Built With
(back to top)
Getting Started
To get a local copy up and running, follow these simple example steps.
Prerequisites
Installation
Use prebuilt binary
or
Using go install command :
$ go install github.com/Rolix44/Kubestroyer@latest
or
build from source:
- Clone the repo
$ git clone https://github.com/Rolix44/Kubestroyer.git
- build the binary
$ go build -o Kubestroyer cmd/kubestroyer/main.go
(back to top)
Usage
Parameter |
Description |
Mand/opt |
Example |
-t / --target |
Target (IP, domain or file) |
Mandatory |
-t localhost,127.0.0.1 / -t ./domain.txt |
--node-scan |
Enable node port scanning (port 30000 to 32767) |
Optionnal |
-t localhost --node-scan |
--anon-rce |
RCE using Kubelet API anonymous auth |
Optionnal |
-t localhost --anon-rce |
-x |
Command to execute when using RCE (display service account token by default) |
Optionnal |
-t localhost --anon-rce -x "ls -al" |
--etcd |
Read wanted objects if etcd anonymous access is enabled |
Optionnal |
-t localhost --etcd |
(back to top)
Currently supported features
-
Target
- List of multiple targets
- Input file as target
-
Scanning
- Known ports scan
- Node port scan (30000 to 32767)
- Port description
-
Vulnerabilities
- Annon RCE on Kubelet
- Choose command to execute
- Choose container to execute command in
- Etcd anonymous read
(back to top)
Roadmap
- Choose the pod for anon RCE
- Etcd exploit
- Kubelet read-only API parsing for information disclosure
See the open issues for a full list of proposed features (and known issues).
(back to top)
Contributing
Contributions are what make the open source community such an amazing place to learn, inspire, and create. Any contributions you make are greatly appreciated.
If you have a suggestion that would make this better, please fork the repo and create a pull request. You can also simply open an issue with the tag "enhancement".
Don't forget to give the project a star! Thanks again!
- Fork the Project
- Create your Feature Branch (
git checkout -b feature/AmazingFeature
)
- Commit your Changes (
git commit -m 'Add some AmazingFeature'
)
- Push to the Branch (
git push origin feature/AmazingFeature
)
- Open a Pull Request
(back to top)
License
Distributed under the MIT License. See LICENSE.txt
for more information.
(back to top)
Rolix - @Rolix_cy - rolixcy@protonmail.com
Project Link: https://github.com/Rolix44/Kubestroyer
(back to top)