Service and network discovery

Kubernetes pod networks are usually flat: a pod can reach most services and other pods directly. Combined with in-cluster DNS, that makes service and endpoint discovery straightforward and productive.

bash
# In-cluster DNS resolves services; the API and kubelet are well-known
nslookup kubernetes.default.svc.cluster.local
getent hosts kube-dns.kube-system.svc.cluster.local

# Scan the flat pod/service network for reachable endpoints
for ip in 10.0.0.{1..254}; do (nc -z -w1 $ip 10250 2>/dev/null && echo "$ip kubelet") & done; wait

Exploitation notes#

  • Service DNS names (<svc>.<ns>.svc.cluster.local) enumerate the application and its dependencies without touching the API.
  • The kubelet (10250), etcd (2379), and dashboards are high-value endpoints to look for on the node and control-plane addresses.
  • A flat network is the precondition for Pod to pod pivoting; where a NetworkPolicy exists, see NetworkPolicy bypass.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more