K8S Storage Exploit

Kubernetes 存储与文件共享利用。当 Pod 挂载了 NFS/EFS/PV/ConfigMap/Secret、发现 /efs 或 /mnt 目录、或 mount 输出中有远程文件系统时使用。覆盖 NFS 挂载利用、AWS EFS uid/gid 伪造、nfs-cat 免挂载读取、PV 敏感数据提取。只要在容器中发现任何远程挂载或共享存储,就应使用此技能

wgpsec 7d04077 3.8 KB Updated

File contents

wgpsec/aboutsecurity/tree/main/skills/cloud/k8s-storage-exploit commit 7d04077c94

Frequently asked questions

npx skillmds@latest add wgpsec/k8s-storage-exploit