Code Monkey home page Code Monkey logo

cloud-security's Introduction

云安全

                     _                 _                                 _ _         
                    | |               | |                               (_) |        
                 ___| | ___  _   _  __| |______ ___  ___  ___ _   _ _ __ _| |_ _   _ 
                / __| |/ _ \| | | |/ _` |______/ __|/ _ \/ __| | | | '__| | __| | | |
                | (__| | (_) | |_| | (_| |      \__ \  __/ (__| |_| | |  | | |_| |_| |
                \___|_|\___/ \__,_|\__,_|      |___/\___|\___|\__,_|_|  |_|\__|\__, |
                                                                                __/ |
                                                                               |___/ 

GitHub Contributors GitHub Contributors GitHub Contributors


         国内关于k8s docker安全内容少之又少,关于靶场部分只是讲的很模糊,这里我学习了国外的云安全文章的一些笔记,希望对各位师傅有一些帮助[还有很多东西还在编写中]

🚀上手指南

  • k8s靶场搭建
  • Sensitive keys in codebases [代码库中敏感信息]
  • DIND (docker-in-docker) exploitation [DIND (docker-in-docker) 漏洞利用]
  • SSRF in the Kubernetes (K8S) world [K8s中的ssrf]
  • Container escape to the host system [容器逃逸到主机系统]
  • Docker CIS benchmarks analysis [Docker CIS 基准测试分析--docker安全排查]
  • Kubernetes CIS benchmarks analysis [Kubernetes CIS 基准测试分析--k8s安全排查]
  • Attacking private registry [攻击docker私有注册表]
  • NodePort exposed services [NodePort 暴露的服务]
  • Analyzing crypto miner container 分析加密挖矿容器[将挖矿木马映像推送到公共容器注册表]
  • Kubernetes namespaces bypass [Kubernetes 命名空间绕过 内核路由表]
  • 环境地址:https://pan.baidu.com/s/1h6nr8izEoRtcIhP27BcHuQ?pwd=ymi7
  • 还在编写中

⚡提交问题

有问题建议请提交issues

加我微信进开发者微信群聊


🗺️版本更新

2023/11/20
  k8s靶场搭建
  Sensitive keys in codebases
  DIND (docker-in-docker) exploitation
  SSRF in the Kubernetes (K8S) world
  Container escape to the host system
  k8s基础知识
--------------------------------------------------
2023/11/21
  Docker CIS benchmarks analysis [Docker CIS 基准测试分析--docker安全排查]
  Kubernetes CIS benchmarks analysis [Kubernetes CIS 基准测试分析--k8s安全排查]
  Attacking private registry [攻击docker私有注册表--k8s靶场]
  NodePort exposed services [NodePort 暴露的服务--k8s靶场]
--------------------------------------------------
2023/11/25
  Analyzing crypto miner container 分析加密挖矿容器[将挖矿木马映像推送到公共容器注册表--k8s安全排查]
  Kubernetes namespaces bypass [Kubernetes 命名空间绕过 内核路由表--k8s靶场]

👏致谢

https://madhuakula.com/kubernetes-goat/docs/
https://github.com/madhuakula/kubernetes-goat
https://cloud.hacktricks.xyz/
感谢以上博客以及github,让我受益良多[以上排名不分先后]

🚨扫码添加 回复 弱鸡交流群

d8180401c3e68be9d03d26cfc55ca33

🌟Stargazers over time Star History Chart

Stargazers

Stargazers repo roster for @RuoJi6/cloud-security

Forkers

Forkers repo roster for @RuoJi6/cloud-security



cloud-security's People

Contributors

ruoji6 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.