Image pull secret theft

To pull private images, the runtime stores registry credentials on the node, and Kubernetes materializes image pull secrets there too. A node foothold recovers them from the runtime's auth files and from the kubelet's on-disk secret state, then reuses them against the registry.

bash
# Runtime and kubelet auth material on the node
find / -name config.json -path '*containers*' 2>/dev/null -exec cat {} \;
cat /var/lib/kubelet/config.json 2>/dev/null
ls /var/lib/kubelet/pods/*/volumes/kubernetes.io~secret/*/.dockerconfigjson 2>/dev/null

Exploitation notes#

  • Pull credentials often reach registries beyond the images on this node, widening access to the whole project's private images.
  • Recovered credentials feed Registry access; push rights among them enable backdooring.
  • Kubelet-materialized secrets on the node also include non-registry secrets mounted into pods, worth sweeping at the same time.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more