Kubelet API

Every node runs a kubelet that exposes an API, usually on 10250, to manage the node's pods. Where it allows anonymous access or the node's authorization is lax, it lists pods and runs commands inside them directly, which is code execution in any container on the node, bypassing the API server and its RBAC.

bash
K=https://<node>:10250
curl -sk $K/pods | jq '.items[].metadata | {namespace,name}'
# Run a command in a container (namespace, pod, container from /pods)
curl -sk -X POST "$K/run/<ns>/<pod>/<container>" -d "cmd=id"

Exploitation notes#

  • /pods is the inventory; /run and /exec give execution inside those containers, often including more privileged workloads than your own.
  • Target pods with powerful service-account tokens or host mounts; exec in, then steal the token or use the mount.
  • Reaching 10250 needs node network access, from a node foothold or a Host network namespace pod.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more