TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Kubernetes clusters being hijacked to mine cryptocurrencies

183 点作者 igama超过 6 年前

10 条评论

tetha超过 6 年前
Ugh. I mean, I recently got in an argument if anything but a hard firewall could or should be exposed to a WAN interface on the internet and we kinda agreed to not agree for now.<p>But, popular services, on default ports, with default APIs enabled, without hard authentication on a WAN interface? That should be a paddling. That doesn&#x27;t fly. Or, well it does, except not for the guy paying the power.
评论 #18623128 未加载
whalesalad超过 6 年前
Got in a pretty heated debate with a colleague once about this. We had a really great infrastructure setup with a VPN bastion host that would get you into our VPC. You couldn&#x27;t reach any of our kube nodes externally. Your Google account was your VPN account. It was pretty solid.<p>When this engineer redid things they opted to go the public internet route where the master runs a public api and auth is done via a certificate. The logic here was so that external 3rd party stuff (CI) could control our master.<p>To my knowledge this setup is still running and chances are these machines are vulnerable to this issue.<p>Contrast to the prior setup where, immediately upon being offboarded from the company your VPN access became automatically terminated (thank you LDAP and Foxpass!)
评论 #18623975 未加载
评论 #18625631 未加载
评论 #18625333 未加载
评论 #18625454 未加载
评论 #18625247 未加载
评论 #18623934 未加载
评论 #18626123 未加载
评论 #18625539 未加载
voltagex_超过 6 年前
At least cryptocurrency has removed most of the creativity from script kiddies - there&#x27;s so many more interesting things you could do than just mine coins.
评论 #18625639 未加载
nineteen999超过 6 年前
This is one of the side-effects of products having enormous hype in this industry.<p>Far too many people are adopting Docker&#x2F;Kubernetes as they have been the hot new product for the last couple of years, often regardless of whether they are actually the best or most appropriate tool for the job.<p>A lot of the people who get sucked into the hype are often inexperienced programmers, devops or admin types who are in positions of power or influence in companies that they probably shouldn&#x27;t be, IMHO.<p>As a result, they don&#x27;t have the Linux or networking experience to be able to know when they are deploying these complex products securely or not, and they are putting their employers businesses at risk.
评论 #18624615 未加载
评论 #18625785 未加载
评论 #18623938 未加载
评论 #18622688 未加载
igama超过 6 年前
CTO Binaryedge here. For those wondering, We have detected more than 15k Kubernetes APIs with Auth. This post focuses on ~1.5k found without Auth, that are fully open.<p>It&#x27;s not just a Kubernetes Problem. Like many have posted, many databases, other types of clusters, shares, are accessible without Auth for those that know how to look for them (not that hard now days), mainly malicious actors.
WrtCdEvrydy超过 6 年前
JSON file is still available (<a href="http:&#x2F;&#x2F;192.99.142.232:8220&#x2F;222.json" rel="nofollow">http:&#x2F;&#x2F;192.99.142.232:8220&#x2F;222.json</a>)
评论 #18622586 未加载
unstatusthequo超过 6 年前
Heading continued: “... thieves make off with $4.50”
clubm8超过 6 年前
Is anyone else a little tired of &quot;X used to mine crypto&quot; stories?<p>Yes - if it has a CPU and access to the public internet, someone will hack it and make it mine &quot;cypto&quot;. Let&#x27;s stop pretending we aren&#x27;t aware that the internet of things exists and writing breathless stories every time a toaster, router, or adult toy starts churning out Monero.
评论 #18624131 未加载
conanthe超过 6 年前
Is kubernetes a mongodb of orchestrators?
gipmon超过 6 年前
These guys are amazing. They have a lot of data and an excellent app with a lot of potential!