K8S Webhook Abuse

Kubernetes Admission Webhook 滥用与策略引擎利用。当集群存在 Kyverno/OPA Gatekeeper/自定义 Webhook、DNS 扫描发现 kyverno-svc 或 gatekeeper 服务、或需要从 Mutating Webhook 提取注入的 Secret 时使用。核心手法:伪造 AdmissionReview 请求。任何在 K8s 中发现 Webhook 服务或策略引擎的场景都应使用此技能

netvar1337 d1e6b4a 2 files · 6.5 KB Updated

File contents

netvar1337/agent-skill-canon/tree/main/skills/aboutsecurity/cloud/k8s-webhook-abuse commit d1e6b4aa4a

Frequently asked questions

npx skillmds@latest add netvar1337/k8s-webhook-abuse