Service account token to API

A service-account token is a bearer credential for the API. With one in hand, point a client at the API server and act as that account. The first move is to learn what it can do, then exercise it: read more secrets, create pods, or reach namespaces the original foothold could not.

bash
API=https://kubernetes.default.svc
kubectl --server=$API --token=<stolen> --insecure-skip-tls-verify auth can-i --list
kubectl --server=$API --token=<stolen> --insecure-skip-tls-verify get secrets -A

Exploitation notes#

  • Tokens are namespace-bound identities but their RBAC can be cluster-wide; auth can-i --list reveals the true scope.
  • Projected tokens are audience-bound and short-lived; use them promptly and against the intended API audience.
  • Chain into RBAC privilege escalation if the token can escalate, bind, impersonate, or create pods.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more