data:image/s3,"s3://crabby-images/f287a/f287a240228f708bed7dd1ab3efd815ecfe259d2" alt="خبرفوری"
خبرفوری
data:image/s3,"s3://crabby-images/35d22/35d2214cce2146661ba1ea8fe09d019bee41d929" alt="آهنگیفای"
آهنگیفای
data:image/s3,"s3://crabby-images/d4f47/d4f4760122bdafc6aa8f57f2d8cde42d1503c6db" alt="TrueCaller"
TrueCaller
data:image/s3,"s3://crabby-images/ae68d/ae68d744b4929c5c378526f8848ef5273527459c" alt="Notcoin Community"
Notcoin Community
data:image/s3,"s3://crabby-images/de14d/de14df646f61490918b0f4dfcdafd4fa7fd08c4d" alt="Whale Chanel"
Whale Chanel
data:image/s3,"s3://crabby-images/9349b/9349b0dcd48a3b878fcee0a574f7de8d6533b81b" alt="Proxy MTProto | پروکسی"
Proxy MTProto | پروکسی
data:image/s3,"s3://crabby-images/30530/30530aa97589dc5f9ccb4525e0b1e73b3320b067" alt="iRo Proxy | پروکسی"
iRo Proxy | پروکسی
data:image/s3,"s3://crabby-images/ac21a/ac21a121886e2960f62957a92f4717b5f048f06e" alt="Findo Lucky"
Findo Lucky
data:image/s3,"s3://crabby-images/6ad69/6ad69726edff40945a5c324fa25b691f6ec8958f" alt="My Proxy | مای پروکسی"
My Proxy | مای پروکسی
data:image/s3,"s3://crabby-images/f287a/f287a240228f708bed7dd1ab3efd815ecfe259d2" alt="خبرفوری"
خبرفوری
data:image/s3,"s3://crabby-images/35d22/35d2214cce2146661ba1ea8fe09d019bee41d929" alt="آهنگیفای"
آهنگیفای
data:image/s3,"s3://crabby-images/d4f47/d4f4760122bdafc6aa8f57f2d8cde42d1503c6db" alt="TrueCaller"
TrueCaller
data:image/s3,"s3://crabby-images/ae68d/ae68d744b4929c5c378526f8848ef5273527459c" alt="Notcoin Community"
Notcoin Community
data:image/s3,"s3://crabby-images/de14d/de14df646f61490918b0f4dfcdafd4fa7fd08c4d" alt="Whale Chanel"
Whale Chanel
data:image/s3,"s3://crabby-images/9349b/9349b0dcd48a3b878fcee0a574f7de8d6533b81b" alt="Proxy MTProto | پروکسی"
Proxy MTProto | پروکسی
data:image/s3,"s3://crabby-images/30530/30530aa97589dc5f9ccb4525e0b1e73b3320b067" alt="iRo Proxy | پروکسی"
iRo Proxy | پروکسی
data:image/s3,"s3://crabby-images/ac21a/ac21a121886e2960f62957a92f4717b5f048f06e" alt="Findo Lucky"
Findo Lucky
data:image/s3,"s3://crabby-images/6ad69/6ad69726edff40945a5c324fa25b691f6ec8958f" alt="My Proxy | مای پروکسی"
My Proxy | مای پروکسی
data:image/s3,"s3://crabby-images/f287a/f287a240228f708bed7dd1ab3efd815ecfe259d2" alt="خبرفوری"
خبرفوری
data:image/s3,"s3://crabby-images/35d22/35d2214cce2146661ba1ea8fe09d019bee41d929" alt="آهنگیفای"
آهنگیفای
data:image/s3,"s3://crabby-images/d4f47/d4f4760122bdafc6aa8f57f2d8cde42d1503c6db" alt="TrueCaller"
TrueCaller
data:image/s3,"s3://crabby-images/cab98/cab98c32869f39dda4690fb26de48d65d8ca3cb8" alt="offsec notes avatar"
offsec notes
reading list
Рейтинг TGlist
0
0
ТипПублічний
Верифікація
Не верифікованийДовіреність
Не надійнийРозташування
МоваІнша
Дата створення каналуЛист 13, 2023
Додано до TGlist
Лют 10, 202520.02.202515:50
Kubernetes security fundamentals
Introduction
API Security
Authentication
Authorization
Admission Control
Networking
Introduction
* Complications of talking about Kubernetes security
* Managed and unmanaged Kubernetes distributions
* Areas of discussion
API Security
* Kubernetes components and ports
- Unmanaged Kubernetes
- Managed Kubernetes
* Securing Kubernetes APIs
Authentication
* Kubernetes authentication principles
- Internal Kubernetes authentication methods
- Static token authentication
- Bootstrap tokens
- X.509 client certificates
- Service account tokens
* External authentication methods
- OpenID Connect (OIDC)
- Webhook token authentication
- Authenticating proxy
- Impersonating proxy
* Authentication for other Kubernetes components
- Kubelet
- Controller manager and scheduler
- Kube-proxy
- Etcd
Authorization
* Kubernetes authorization principles
* Kubernetes authorization modules
- AlwaysAllow and AlwaysDeny
- Node Authorizer
- ABAC
- RBAC
- Webhook
* Authorization for other Kubernetes components
- Kubelet
- Scheduler and Controller Manager
Admission Control
* Admission control overview
- Internal admission controllers
- External admission controllers
* Risks of implementing external admission control
- Using admission control for pod security
Networking
* Network trust zones
* Introduction to CNI
* Managing network access in Kubernetes
* Securing the cluster network
* Conclusion
* Appendix - Setting up a demonstration environment
05.02.202516:42
Keycloak pentest
Articles
Part 1 - Link
Part2 - Link
* Additional Services and Ports
* Interesting Local Files
* Reconnaissance Conclusion
Exploitation
* Brute Force Login
* Bypassing/Automating CSRF
* JWT Signing Algorithms
* Make the most out of your scopes/roles
* offline_access
* uma_authorization
* profile
* email
* address
* phone
Tools
Keycloak security scanner - Link
* Начиная с keycloak 17.0+ роут /auth в URL должен быть пропущен (
Articles
Part 1 - Link
* Am I Testing Keycloak?
* Keycloak Version Information
* OpenID Configuration /SAML Descriptor
* Realms (Enumeration && Self-Registration Enabled)
* Client IDs
* Scopes
* Grants
* Identity Providers
* Roles
* User Email Enumeration
Part2 - Link
Reconnaissance
* Additional Services and Ports
* Interesting Local Files
* Reconnaissance Conclusion
Exploitation
* Brute Force Login
* Bypassing/Automating CSRF
* JWT Signing Algorithms
* Make the most out of your scopes/roles
* offline_access
* uma_authorization
* profile
* address
* phone
Tools
Keycloak security scanner - Link
* Начиная с keycloak 17.0+ роут /auth в URL должен быть пропущен (
/realms/realm_name/
)Увійдіть, щоб розблокувати більше функціональності.