News: 1653328818

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

381,000-plus Kubernetes API servers 'exposed to internet'

(2022/05/23)


A large number of servers running the Kubernetes API have been left exposed to the internet, which is not great: they're potentially vulnerable to abuse.

Nonprofit security organization The Shadowserver Foundation recently scanned 454,729 systems hosting the popular open-source platform for managing and orchestrating containers, finding that more than 381,645 – or about 84 percent – are accessible via the internet to varying degrees thus providing a cracked door into a corporate network.

"While this does not mean that these instances are fully open or vulnerable to an attack, it is likely that this level of access was not intended and these instances are an unnecessarily exposed attack surface," Shadowserver's team stressed in a [1]write-up . "They also allow for information leakage on version and build."

[2]

That said, enterprises shouldn't downplay the risk that such exposed Kubernetes API servers represent, according to Erfan Shadabi, head of market for data security firm comforte AG.

[3]

[4]

"Kubernetes growth is unstoppable, and while it provides massive benefits to enterprises for agile app delivery, there are a few characteristics that make it an ideal attack target for exploitation," Shadabi told The Register . "For instance, as a result of having many containers, Kubernetes has a large attack surface that could be exploited if not pre-emptively secured, so it is not a surprise that The Shadowserver Foundation's scan found so many vulnerabilities."

What's most concerning is that the data security capabilities built into Kubernetes meet the bare minimum standards, with protection for data at rest and data in motion, but "no persistent protection of data itself, for example, using industry accepted techniques like field-level tokenization," Shadabi said.

[5]

"If an ecosystem is compromised, it's only a matter of time before the sensitive data being processed by it succumbs to a more insidious attack. Organizations that use containers and Kubernetes in their production environments must take Kubernetes security very seriously."

Kubernetes was developed by Google almost a decade ago and is now the most popular tool for managing containers both on premises and in the public cloud, with such vendors as Red Hat (OpenShift), VMware (Tanzu), and SUSE (Rancher) selling commercial versions. Almost 50 percent of organizations worldwide have adopted Kubernetes in some form as of 2021, [6]according to market research firm Statista.

[7]How to find NPM dependencies vulnerable to account hijacking

[8]Microsoft sounds the alarm on – wait for it – a Linux botnet

[9]South Korean and US presidents gang up on North Korea's cyber-offensives

[10]Conti: Russian-backed rulers of Costa Rican hacktocracy?

Shadowserver scanned for accessible Kubernetes API instances that responded with 200 OK , listing in its report almost two dozen instances that came back with that response. The group also disclosed the five most-accessible platforms.

The researchers also noted that almost 53 percent of the accessible instances – 201,348 Kubernetes API servers – were located in the United States.

Open-source systems are an increasingly popular target for threat actors. In the era of cloud computing, the attack surface around Linux is only expanding.

[11]

Cybersecurity vendor Trend Micro, in a [12]report last year, noted that of the cloud workloads that its Cloud One product protects, 61 percent were Linux systems, with 39 percent running Windows. The cyberthreats range from ransomware and trojans to coinminers and web shells.

"Given how deeply Linux is rooted in daily life, especially as an integral part of cloud infrastructure and the internet of things (IoT), the security of Linux and Linux workloads must be treated at par with that of Windows and other operating systems," the Trend Micro researchers wrote.

The threat to opens-source systems was highlighted late last year, when vulnerabilities in the ubiquitous [13]Apache Log4j logging tool surfaced. The flaws were easy to exploit and Log4j was so widely used that it was difficult for many enterprises to find all the instances within their IT environments to patch them. Cybercriminals moved quickly to exploit the flaws – dubbed Log4Shell – and continue to use them as access points into systems.

That was illustrated in a [14]report last week that found the Russia-linked Wizard Spider – the threat group behind such ransomware as Conti and Ryuk – was [15]leveraging Log4Shell in some of its campaigns.

Shadowserver recommended that enterprises using a Kubernetes API server that is accessible implement authorization for access or block it at the firewall to reduce the attack surface. ®

Get our [16]Tech Resources



[1] https://www.shadowserver.org/news/over-380-000-open-kubernetes-api-servers/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YowEA9HTGBFc@buKP-jjMAAAAMU&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YowEA9HTGBFc@buKP-jjMAAAAMU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YowEA9HTGBFc@buKP-jjMAAAAMU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YowEA9HTGBFc@buKP-jjMAAAAMU&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.statista.com/topics/8409/kubernetes/#topicHeader__wrapper

[7] https://www.theregister.com/2022/05/23/npm_dependencies_vulnerable/

[8] https://www.theregister.com/2022/05/23/microsoft_linux_botnet/

[9] https://www.theregister.com/2022/05/23/s_korean_and_us_presidents/

[10] https://www.theregister.com/2022/05/21/in_brief_security/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/devops&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YowEA9HTGBFc@buKP-jjMAAAAMU&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[12] https://www.trendmicro.com/vinfo/us/security/news/cybercrime-and-digital-threats/linux-threat-report-2021-1h-linux-threats-in-the-cloud-and-security-recommendations

[13] https://www.theregister.com/2022/04/20/aws_log4j_patches/

[14] https://www.prodaft.com/resource/detail/ws-wizard-spider-group-depth-analysis

[15] https://www.theregister.com/2022/05/18/wizard-spider-ransomware-conti/

[16] https://whitepapers.theregister.com/



Honest request

Anonymous Coward

Could someone please explain to me, in simple words, how they successfully used Kubernetes to their benefit? What specific problem did it solve for you?

Re: Honest request

Gorbachov

It solves many small things in a consistent manner. Encourages you to containerise your service, apply configuration and manage secrets responsibly.

Encourages resource consumption management and scales accordingly. The large ecosystem allows for easy deployment of third-party products for logging and monitoring. All that and it's vendor neutral so you can mostly run your workload anywhere.

Makes managing a microservice deployment less of a nightmare.

raesene

Well this is... massively not news, not really sure why Shadowserver are acting like it is :P Binary Edge, Censys and Shodan have been indexing k8s servers on the Internet for quite a while (I did a write-up on some of the exposures https://raesene.github.io/blog/2021/06/05/A-Census-of-Kubernetes-Clusters/ )

The reason for the high number (IME at least) is that the major managed k8s distributions (AKS, GKE, EKS) all default to exposing the API server on the Internet. There's a load of possible problems with this, not least of which is that Kubernetes features multiple authentication methods with non-expiring credentials, so an attacker who steals creds (or a disgruntled ex-admin) can easily get access.

Gorbachov

Yeah.

Most people keep it public because private clusters are way harder to build and operate. Suddenly you need private DNS resolution, jump hosts for access to the API, private build nodes so that CI / CD can build and deploy. The cloud provider UI can no longer show you workload info unless you VPN in so you'll need a VPN too).

And then you find out you need special resources to keep all the private bits to talk to each other. Did I mention that those are only available in the premium tier? No? Well, they are so everything will cost 3x what you thought it would.

It's probably not worth it. Access to the API is secured with certs (at least) so you would have to be extremely risk-averse to go down that rabbit hole.

It should be a case of "Just plug in a new kernel, and suddenly your
existing filesystem just allows you to do more! 20% more for the same
price! AND we'll throw in this useful ginzu knife for just 4.95 for
shipping and handling. Absolutely free!"

- Linus Torvalds on linux-kernel