Pod to pod pivoting

By default Kubernetes gives every pod reach to every other pod and service: the network is flat unless a NetworkPolicy restricts it. From one compromised pod, the others are directly reachable, so their services, admin interfaces, and unauthenticated endpoints become targets.

bash
# Enumerate services and endpoints, then connect directly
kubectl get svc,endpoints -A 2>/dev/null
for ip in $(kubectl get pods -A -o jsonpath='{.items[*].status.podIP}'); do
  nc -z -w1 $ip 6379 2>/dev/null && echo "$ip redis"; done

Exploitation notes#

  • Internal services frequently skip authentication because they assume the network is trusted; a flat network breaks that assumption.
  • Target databases, caches, message queues, and internal admin UIs reachable from the pod network.
  • Where a NetworkPolicy is present, see NetworkPolicy bypass; discovery is covered in Service and network discovery.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more