{"id":2184,"date":"2019-12-16T17:52:31","date_gmt":"2019-12-16T15:52:31","guid":{"rendered":"https:\/\/archive.brucon.org\/2020\/?page_id=2184"},"modified":"2020-05-10T20:55:30","modified_gmt":"2020-05-10T18:55:30","slug":"a-hackers-view-on-containers-and-kubernetes","status":"publish","type":"page","link":"https:\/\/archive.brucon.org\/2020\/brucon-2020-training\/a-hackers-view-on-containers-and-kubernetes\/","title":{"rendered":"A hacker\u2019s view on #containers and #kubernetes"},"content":{"rendered":"<div class=\"wpb-content-wrapper\"><p>[vc_row][vc_column][vc_column_text]<\/p>\n<h2>Course Description<\/h2>\n<p><strong>UPDATE May 10th &#8211; We have decided to host this training virtually due to the Corona crisis.\u00a0<\/strong><\/p>\n<p><span style=\"font-weight: 400\">Kubernetes and containers are a very hot topic nowadays and are very easy to use. On the other hand, the underlying components that make up Kubernetes is a very c<\/span><\/p>\n<p><span style=\"font-weight: 400\">omplex system that few people really understand. To make things more complex, in a world where automation, registries, CI\/CD and vaults rules \u2026 how to implement and automate security?<\/span><\/p>\n<p><span style=\"font-weight: 400\">A lot of different attack vectors aimed at data theft, currency mining, cluster takeover and much more put the sometimes-immense clusters at risk.\u00a0 Current in-use security controls like firewalls, malware protection, role-based access control, etc. do not offer an acceptable level of protection anymore and are blind for what is happening inside.\u00a0<\/span><span style=\"font-weight: 400\">We&#8217;ll discuss the key concepts of containers and Kubernetes. During the training, we will focus and learn how it all works in detail, but in very practical way, in order to learn to better and reliably protect our applications, workloads and clusters.<\/span><\/p>\n<p><span style=\"font-weight: 400\">There are a lot of concepts to be explained (pods, namespaces, services, etc. ) , but we will do that so that you understand the purpose and the security aspects of all of them.\u00a0<\/span><span style=\"font-weight: 400\">This training is not about application or exploit development \u2026 but it will give you the necessary insights into this emerging and exciting world and bring your hacking skills to the next level! Promised!<\/span>[\/vc_column_text][\/vc_column][\/vc_row][vc_row][vc_column][vc_column_text]<\/p>\n<h2>Course contents<\/h2>\n<h3><b>Day 1<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Setting the scene!<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Advanced introduction to containers and docker<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Building our first hacking container<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">What about Seccomp, AppArmor, Capabilties?<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Finding vulnerabilities in container images<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Understanding the K8S architecture and components<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Deploying a hacking pod<\/span><\/li>\n<\/ul>\n<h3><b>Day 2<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Deep diving into pods, deployments, namespaces, services, etc \u2026<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Exposing applications (load balancing, Ingress, node port \u2026)<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Deploying and analyzing a complex microservice<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">K8S secrets and config maps<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Network security and pod security<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Introduction to ISTIO framework<\/span><\/li>\n<\/ul>\n<h3><b>Day 3<\/b><\/h3>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Understanding K8S authentication and API<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">How to use legacy and advanced hacking tools in K8S<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Dissecting a pod<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Advanced containers and POD tricks<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Backdooring K8S POD<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Admission controllers in K8S<\/span><\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_column][\/vc_row][vc_row][vc_column][vc_column_text]<\/p>\n<h2>What would the attendees gain?<\/h2>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Understanding containers (Docker) and advanced (security) features<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">How to find vulnerabilities in containers and images<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Deep understanding of Kubernetes pods, labels and selectors<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Deep understanding of Kubernetes inner workings and cluster networking<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Deep understanding of Kubernetes RBAC and authentication<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Network security and pod security<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Hijacking containers and pods<\/span><\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_column][\/vc_row][vc_row][vc_column][vc_column_text]<\/p>\n<h2>Target audience<\/h2>\n<p><span style=\"font-weight: 400\">This training is intended for everyone that wants to learn about the inner workings of K8S and the related security concepts. If you are a security admin, a network engineer, a pen-tester or a DevOps engineer and interested in security and containers\u2026\u00a0 you\u2019re welcome! It will be an advanced course, but we\u2019ll start from the beginning!<\/span>[\/vc_column_text][\/vc_column][\/vc_row][vc_row][vc_column][vc_column_text]<\/p>\n<h2>Requirements<\/h2>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">A notebook with access to SSH<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Administrative rights<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">Docker for Mac or Windows (preferred)<\/span><\/li>\n<\/ul>\n<p>[\/vc_column_text][\/vc_column][\/vc_row][vc_row][vc_column width=&#8221;5\/6&#8243;][vc_column_text]<\/p>\n<h2>Trainer Biography<\/h2>\n<p><span style=\"font-weight: 400\"><strong>Philippe Bogaerts<\/strong> brings more than 20+ years of experience in security. Starting out as a trainer specializing in advanced TCP\/IP protocols, networking and security, Philippe quickly became known by colleagues as \u201c<em>Philippe hacks to learn<\/em>\u201d.\u00a0<\/span><span style=\"font-weight: 400\">Being a pioneer in network firewall, reverse proxy and load-balancing, Philippe later on specialized in web application security with a focus on penetration testing and web application firewalling.<\/span><\/p>\n<p><span style=\"font-weight: 400\">About +4 years ago, containers and orchestration grabbed his attention and started researching (mostly as a hobby), the architecture and security aspects of these new emerging technologies.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Today, Philippe contributes mostly by writing blog post<\/span><a href=\"https:\/\/medium.com\/@xxradar\" target=\"_blank\" rel=\"noopener noreferrer\"> <span style=\"font-weight: 400\">https:\/\/medium.com\/@xxradar<\/span><\/a><span style=\"font-weight: 400\"> , talking at meetups as well as co-organizing a renowned security conference BruCON (Sounds familiar ;-))<\/span><span style=\"font-weight: 400\">. During daytime, Philippe is a solution architect at<\/span><a href=\"https:\/\/aquasec.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"> <span style=\"font-weight: 400\">https:\/\/aquasec.com<\/span><\/a><span style=\"font-weight: 400\">.<\/span>[\/vc_column_text][\/vc_column][vc_column width=&#8221;1\/6&#8243;][vc_single_image image=&#8221;2197&#8243; css=&#8221;.vc_custom_1576698301160{margin-top: 50% !important;}&#8221;][\/vc_column][\/vc_row][vc_row][vc_column][vc_column_text]<\/p>\n<h2>Social Media<\/h2>\n<p><span style=\"font-weight: 400\">Twitter :<\/span><a href=\"https:\/\/twitter.com\/xxradar\" target=\"_blank\" rel=\"noopener noreferrer\"><span style=\"font-weight: 400\">@xxradar<\/span><\/a><\/p>\n<p><span style=\"font-weight: 400\">LinkedIn: <a href=\"https:\/\/www.linkedin.com\/in\/philippebogaerts\/\" target=\"_blank\" rel=\"noopener noreferrer\">https:\/\/www.linkedin.com\/in\/philippebogaerts\/<\/a><\/span>[\/vc_column_text][\/vc_column][\/vc_row][vc_row][vc_column][vc_empty_space][\/vc_column][\/vc_row]<\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>[vc_row][vc_column][vc_column_text] Course Description UPDATE May 10th &#8211; We have decided to host this training virtually due to the Corona crisis.\u00a0 Kubernetes and containers are a very hot topic nowadays and are very easy to use. On the other hand, the underlying components that make up Kubernetes is a very c omplex system that few people really understand. To make things more complex, in a world where automation, registries, CI\/CD and vaults rules \u2026 how to&#8230;<\/p>\n","protected":false},"author":8,"featured_media":0,"parent":75,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-2184","page","type-page","status-publish"],"_links":{"self":[{"href":"https:\/\/archive.brucon.org\/2020\/wp-json\/wp\/v2\/pages\/2184","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/archive.brucon.org\/2020\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/archive.brucon.org\/2020\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/archive.brucon.org\/2020\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/archive.brucon.org\/2020\/wp-json\/wp\/v2\/comments?post=2184"}],"version-history":[{"count":8,"href":"https:\/\/archive.brucon.org\/2020\/wp-json\/wp\/v2\/pages\/2184\/revisions"}],"predecessor-version":[{"id":2355,"href":"https:\/\/archive.brucon.org\/2020\/wp-json\/wp\/v2\/pages\/2184\/revisions\/2355"}],"up":[{"embeddable":true,"href":"https:\/\/archive.brucon.org\/2020\/wp-json\/wp\/v2\/pages\/75"}],"wp:attachment":[{"href":"https:\/\/archive.brucon.org\/2020\/wp-json\/wp\/v2\/media?parent=2184"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}