ref: https://www.cyberark.com/resources/threat-research-blog/securing-kubernetes-clusters-by-eliminating-risky-permissions
本篇文章是一個基礎分享文,整個主軸圍繞於 Authentication 與 Authorization 兩大塊,同時透過這兩大概念的介紹來分享一些會可能會有資安問題的設定
開頭作者探討了 Kubernetes 的架構,並且將 API Server 這個重點核心拿來出探討,提到為了存取 Kubernetes API,使用者必須要經過三個階段的處理,分別是
Authentication, Authorization 以及 Admission Control
接者用一個簡單的流程來說明上述三者的差異,假設今天有一個 Client 想要請求 API Server 幫忙創建一個 Pod 的物件。
首先 API Server 會針對該請求進行 Authentication 的檢查,通常情況下會使用 Certificate, Tokens, Basic Authentication(username/password) 來判別。
如果通過後,則會進入到 Authorization 的階段,該階段要判別發送當前 Request 的 Client 是否擁有創建 Pod 的權限,如果有權限就會把相關操作交給後續的 Admission Control 來處理。
文章中舉了一個名為 AlwaysPullImages 的 Admission Controller,該 Controller 對於一個多用戶的 Kubernetes Cluster 來說特別有用,主要是用來確保使用者 A 想要使用的 Private Image 不能被使用者 B 存取。
試想一個情況,假設今天使用者 A 順利於 NodeA 上抓取了自己的 Private Image,那使用者 B 假如很剛好知道這個 Image 的名稱,是不是有機會就可以不需要相關權限直接使用 NodeA 上的 Image?
所以這個 Admission Controller 就是用來避免這個問題的。
接者作者從 Authentication 與 Authorization 中個挑選一個方式來介紹並且講解這兩者如何結合的。
Authentication 使用的是 Service Account Token,管理會事先於 Kubernetes 內創立一個相關的 Service Account,並且把該 SA(Service Account) 的 Token 給交給 Client(Kubeconfig 也可)
Client 發送 HTTPS 請求到 API Server 的時候就可以夾帶這個 Token 的資訊,這樣 API Server 就會去檢查該 Token 是否存在於 Cluster 內。
事實上當每個 Pod 被創立後, Kubernetes 預設情況下就會將該 namespace 下的 service account 資訊給掛載到該 Pod 內的 "/var/run/secrets/kubernetes.io/serviceaccount" 這個路徑
這樣該 Pod 就可以使用該 Service Account Token 的資訊與 API Server 溝通。
Authorization 則是使用 RBAC 的方式來處理, RBAC 由三個部分組成,分別是 Role(代表可以針對 Cluster 進行什麼樣類型的操作,譬如 create pod, delete pod), Subject(你是誰,譬如 Service Account), RoleBinding(用來將 Role 與 Subject 給綁定)
管理員要創建並且管理這些叢集的話,就要好好的去設計這三個物件的關係,來確保最後的 Client 可以擁有剛剛好符合其需求的權限,千萬不要為了懶散而給予過多權限。
接者作者列舉了五種 Risky permissions 的可能情境
1. Listing secrets
大部分的應用程式開發者都會使用 secret 的物件來管理一些機密資訊,如帳號密碼,憑證等,所以一個擁有 list secrets 的 service account 其實是相對危險的。
非必要的話,不要讓管理員以外的任何使用者有這個權限,特別是使用 ClusterRole/ClusterRoleBinding 時要特別注意
2. Creating a pod with a privileged service account
假設今天有一個攻擊者已經獲得一個可以創建 pod 的 service account,那該攻擊者已經可以很順利的於叢集內創建 Pod 去進行基本操作(譬如挖礦)
如果攻擊者很巧地又知道目標 namespace 內存在一個很強的 service account,它就有辦法讓他創立的 Pod 去使用這個很強的 Service Account 並且進行更多後續操作
3. Impersonating privileged accounts
作者提到 Impersonating 這個 Role 裡面的動作要特別小心使用,擁有這個權限的使用者可以輕鬆化身為其他的使用者/群組
舉例來說,一個擁有 Impersonating -> users/group 的 serviceaccount 是沒有辦法看到任何 secrets 的物件。
但是攻擊者只要使用的時候加上 --as=null --as-group=system:master 則就會變成如 master 般的上帝擁有這些權限
因此這種權限設定上要特別小心
4. Reading a secret – brute-forcing token IDs
5. Creating privileged RoleBindings
後續兩個有興趣的可以參考全文,都是滿有趣的一些想法,值得閱讀擴展自己的認知
同時也有11部Youtube影片,追蹤數超過2萬的網紅Handline Fishing,也在其Youtube影片中提到,我要奪金! | 香港釣魚 | 岸釣 | 港珠澳橋墩 【ActiveDim 太陽眼鏡】 I want to catch Spotted scat | [Hong Kong HK Fishing : ShoreGame] Hongkong-Zhuhai-Macao Bridge {Voice Over ...
「post authorization」的推薦目錄:
- 關於post authorization 在 矽谷牛的耕田筆記 Facebook 的最佳貼文
- 關於post authorization 在 王大師 Facebook 的最讚貼文
- 關於post authorization 在 李怡 Facebook 的精選貼文
- 關於post authorization 在 Handline Fishing Youtube 的最讚貼文
- 關於post authorization 在 Handline Fishing Youtube 的最佳貼文
- 關於post authorization 在 Handline Fishing Youtube 的最佳貼文
- 關於post authorization 在 http post - how to send Authorization header? - Stack Overflow 的評價
- 關於post authorization 在 New Authorization for Pages | Facebook for Business 的評價
- 關於post authorization 在 開發者必備知識- HTTP認證(HTTP Authentication) 的評價
- 關於post authorization 在 Post-authorization safety monitoring plans - YouTube 的評價
post authorization 在 王大師 Facebook 的最讚貼文
很有趣喔,連主流媒體的華爾街日報,都漸漸開始批評FDA禁止伊維菌素背後的邏輯!
Why Is the FDA Attacking a Safe, Effective Drug?
If the FDA were driven by science and evidence, it would give an emergency-use authorization for ivermectin for Covid-19. Instead, the FDA asserts without evidence that ivermectin is dangerous.
At the bottom of the FDA’s warning against ivermectin is this statement: “Meanwhile, effective ways to limit the spread of COVID-19 continue to be to wear your mask, stay at least 6 feet from others who don’t live with you, wash hands frequently, and avoid crowds.” Is this based on the kinds of double-blind studies that the FDA requires for drug approvals? No.
濕評:事實上,這篇WSJ評論,不但批評FDA忽略伊維菌素這類更優異的藥物,更質疑戴口罩、社交距離與勤洗手等新冠神話。
如果有更多主流媒體加入,紐倫堡大審2.0就不遠囉,因為這群新冠組織犯罪,犯了.....
二、試驗的目的必須能為社會帶來福祉,且無法以試驗以外的方式獲得。試驗不可是隨機或不必要的。
觀察:國外有研究奎寧(全名羥氯喹;hydroxychloroquine)、伊維菌素(ivermectin)等非疫苗藥物對治療「新冠現象」有幫助,卻被媒體掩蓋。台灣生產奎寧的旭富藥廠還被神秘炸毀,印度也有類似情況。這些操作皆令人感覺有種陰謀藏身於後。
事實上,增強人類免疫系統最佳的方式,是促使大家團聚,與家人及親友享受社交活動;與愛人享魚水之歡,多運動、少看電視、服用維生素C、D等補充物,或是直接曬太陽(但被封城限制)。重點是少吸收與疫情有關的負面資訊。脫下口罩,大口呼吸是增加缺氧狀最直接的作法。但這些措施,卻與政府提出的新冠防禦相左,觸犯本項紐倫堡公約機率不小。
與其吵疫苗功效,不如玩「紐倫堡大審2.0」吧!
https://accrcw75.pixnet.net/blog/post/69670642
#然後明明是WSJ核可的報導
#臉書又跑出那討厭的警告標語
其他就晚上聊囉:https://youtu.be/gAxBrG_S4rg
優質內容,需要您們的贊助!
💰 贊助連結: https://p.ecpay.com.tw/B7CB5 (留言不可空格、分段)
post authorization 在 李怡 Facebook 的精選貼文
No Forbidden Zones in Reading (Lee Yee)
German philosopher Hegel said, “The only thing we learn from history is that we learn nothing from history.”
In April 1979, the post-Cultural Revolution era of China, the first article of the first issue of Beijing-based literary magazine, Dushu [meaning “Reading” in Chinese]," shook up the Chinese literary world. The article, titled “No Forbidden Zones in Reading”, was penned by Li Honglin. At the time, the CCP had not yet emerged from the darkness of the Cultural Revolution. What was it like in the Cultural Revolution? Except for masterpieces by Marx, Engels, Lenin, Stalin and Mao, and a small fraction of practical books, all books were banned, and all libraries were closed. The Cultural Revolution ended in 1976, and 2 years later in 1978, the National Publishing Bureau decided to allow 35 books to be “unbanned”. An interlude: When the ban was first lifted, there was no paper on which to print the books because the person with authority over paper was Wang Dongxing, a long-term personal security of Mao’s, who would only give authorization to print Mao. The access to use paper to print books other than Mao was a procedural issue. The Cultural Revolution was already on its way to be overturned. The door to printing these books was opened only after several hang-ups.
“No Forbidden Zones in Reading” in the first issue of Dushu raised a question of common sense: Do citizens have the freedom to read? “We have not enacted laws that restrict people’s freedom of reading. Instead, our Constitution stipulates that people have the freedom of speech and publication, as well as the freedom to engage in cultural activities. Reading ought to be a cultural activity,” argued Li. It was not even about the freedom of speech, but simply reading. Yet this common sense would appear as a subversion of the paralyzing rigid ideas formulated during the Cultural Revolution, like a tossed stone that raises a thousand ripples. Dushu’s editorial department received a large number of objections: first, that there would be no gatekeeper and mentally immature minors would be influenced by trashy literature; second, that with the opening of the Pandora box, feudalism, capitalism and revisionism would now occupy our cultural stage. The article also aroused waves of debates within the CCP. Hu Yaobang, then Minister of Central Propaganda, transferred and appointed Li Honglin as the Deputy Director of the Theory Bureau in his department. A colleague asked him directly, “Can primary school students read Jin Pin Mei [also known in English as The Plum in the Golden Vase, a Chinese novel of manners composed in late Ming dynasty with explicit depiction of sexuality]?”
“All Four Doors of the Library Should be Open” was published in the second issue of Dushu, as an extension to “No Forbidden Zones in Reading”. The author was Fan Yuming, but was really Zeng Yansiu, president of the People’s Publishing House.
In the old days, there was a shorthand for the three Chinese characters for “library”: “book” within a “mouth”. The four sides of the book are all wide open, meaning that all the shackles of the banned books are released. “No Forbidden Zones in Reading” explains this on a theoretical level: the people have the freedom to read; “All Four Doors of the Library Should be Open” states that other than special collection books, all other books should be available for the public to loan.
The controversy caused by “No Forbidden Zones in Reading” lasted 2 years, and in April 1981, at the second anniversary of Dushu, Director of the Publishing Bureau, Chen Hanbo, penned an article that reiterated that there are “No Forbidden Zones in Reading”, and that was targeting an “unprecedented ban on books that did happen”.
Books are records of human wisdom, including strange, boring, vulgar thoughts, which are all valuable as long as they remain. After Emperor Qin Shihuang burned the books, he buried the scholars. In history, the ban on books and literary crimes have never ceased.
Engraved on the entrance to Dachau concentration camp in Germany, a famous poem cautions: When a regime begins to burn books, if it is not stopped, they will turn to burn people; when a regime begins to silent words, if it is not stopped, they will turn to silent the person. At the exit, a famous admonishment: When the world forgets these things, they will continue to happen.
Heine, a German poet of the 19th century, came up with “burning books and burning people”. There was a line before this: This is just foreplay.
Yes, all burning and banning of books are just foreplay. Next comes the literary crimes, and then “burning people”.
I started working at a publishing house with a high school degree at 18, and lived my entire life in a pile of books. 42 years ago, when I read “No Forbidden Zones in Reading” in Dushu, I thought that banned books were a thing of the past. Half a century since and here we are, encountering the exact same thing in the freest zone for reading in the past century in the place which enlightened Sun Yat-sen and the rest of modern intellectuals, a place called Hong Kong.
Oh, Hegel’s words are the most genuine.
post authorization 在 Handline Fishing Youtube 的最讚貼文
我要奪金! | 香港釣魚 | 岸釣 | 港珠澳橋墩 【ActiveDim 太陽眼鏡】
I want to catch Spotted scat | [Hong Kong HK Fishing : ShoreGame] Hongkong-Zhuhai-Macao Bridge {Voice Over + CC}
ActiveDim 太陽眼鏡介紹
一副能因應環境調節光暗的太陽眼鏡,對我們整天長時間釣魚愛好者而言,是不可缺少。這一副是ActiveDim 自動調節光暗及偏光的太陽眼鏡,無論是清晨,中午或是黃昏時間配戴,同樣適合。
官方網站:https://activedim.com
優惠碼:handlinefishing20
或使用以下連結:https://activedim.com/discount/handlinefishing20
(可額外再享有20% 折扣!!!!)
Business Cooperation and Media 商業合作、採訪通知:tkcmarco@gmail.com
******************************************************************
Media Interview(s) OR Reproduce with authorization 媒體採訪或授權轉載
Media 媒體報導
: viuTV 電視特輯 :
發展局 海濱事務委員會呈獻 【維港.圍講】
播出時間(2021年5月1日 )
第4集 - 魚樂無窮: 釣魚發燒友維港遊
https://viu.tv/encore/lets-talk-about-victoria-harbour/lets-talk-about-victoria-harboure4yue-lok-mo-kung--diu-yue-faat-siu-yau-wai-gong-yau
: Oriental Daily 東方日報 :
【手絲釣魚】岸釣系列#1 數碼港係熱門釣魚點?釣足30條泥鯭!
https://tv.on.cc/index.html?vid=OUGC20200707_900009_01&createtime=1594094281&subsection=468
More...Please refer to the channel description 更多... 請參閱頻道簡介
******************************************************************
==================================================================
YouTube Channel 頻道 : https://www.youtube.com/channel/UCO_5XP-qd-udNxBlzzSzgvw?sub_confirmation=1
Donate and Support my Channel 資助我的頻道:https://www.paypal.me/handlinefishing
==================================================================
Facebook 手絲釣魚交流群: https://www.facebook.com/groups/616740025403230/
Instagram 官方賬戶: https://www.instagram.com/handlinefishing_hk/
==================================================================
You can purchase my gear through the link below 你可以經以下連結購買產品
硬件
1人稱相機 (新) Insta360 Go 2 - https://www.insta360.com/sal/go_2?insrc=INRW1ZI
360相機 Insta360 ONE X2 - https://www.insta360.com/sal/one_x2?insrc=INRW1ZI
360相機 Insta360 ONE R - https://www.insta360.com/sal/one_r?insrc=INRW1ZI
1拖2咪 MirFakAudio - https://store.mirfakaudio.com?sca_ref=986772.ti6Y4oRgJX
以上是購買連結,你在購買時會得到額外的商家優惠,同時,不會因為商家的優惠而產生額外成本,可以支持這個頻道發展,先感謝你使用
音樂連結 Artlist.io Referral link Artlist 介紹碼連結 : https://artlist.io/Handline-861488
==================================================================
Background Music 背景音樂名稱 : Around Again by Ian Post
Source 來源 : Artlist.io
Referral link 介紹碼連結 : https://artlist.io/Handline-861488
Background Music 背景音樂名稱 : Dead-end maze (https://johnnyhk.bandcamp.com/track/dead-end-maze)
Source 來源 : Troglojam
==================================================================
#港珠澳橋墩 #Fishing #釣魚 #手絲釣魚 #香港釣魚

post authorization 在 Handline Fishing Youtube 的最佳貼文
雞魚仕掛不求人,1分鐘學識 | 釣魚教學 | 香港釣魚 | 艇釣 | 手絲釣魚 | #Shorts
Business Cooperation and Media 商業合作、採訪通知:tkcmarco@gmail.com
******************************************************************
Media Interview(s) OR Reproduce with authorization 媒體採訪或授權轉載
Media 媒體報導
: viuTV 電視特輯 :
發展局 海濱事務委員會呈獻 【維港.圍講】
播出時間(2021年5月1日 )
第4集 - 魚樂無窮: 釣魚發燒友維港遊
https://viu.tv/encore/lets-talk-about-victoria-harbour/lets-talk-about-victoria-harboure4yue-lok-mo-kung--diu-yue-faat-siu-yau-wai-gong-yau
: Oriental Daily 東方日報 :
【手絲釣魚】岸釣系列#1 數碼港係熱門釣魚點?釣足30條泥鯭!
https://tv.on.cc/index.html?vid=OUGC20200707_900009_01&createtime=1594094281&subsection=468
More...Please refer to the channel description 更多... 請參閱頻道簡介
******************************************************************
==================================================================
YouTube Channel 頻道 : https://www.youtube.com/channel/UCO_5XP-qd-udNxBlzzSzgvw?sub_confirmation=1
Donate and Support my Channel 資助我的頻道:https://www.paypal.me/handlinefishing
==================================================================
Facebook 手絲釣魚交流群: https://www.facebook.com/groups/616740025403230/
Instagram 官方賬戶: https://www.instagram.com/handlinefishing_hk/
==================================================================
You can purchase my gear through the link below 你可以經以下連結購買產品
硬件
1人稱相機 (新) Insta360 Go 2 - https://www.insta360.com/sal/go_2?insrc=INRW1ZI
360相機 Insta360 ONE X2 - https://www.insta360.com/sal/one_x2?insrc=INRW1ZI
360相機 Insta360 ONE R - https://www.insta360.com/sal/one_r?insrc=INRW1ZI
1拖2咪 MirFakAudio - https://store.mirfakaudio.com?sca_ref=986772.ti6Y4oRgJX
以上是購買連結,你在購買時會得到額外的商家優惠,同時,不會因為商家的優惠而產生額外成本,可以支持這個頻道發展,先感謝你使用
音樂連結 Artlist.io Referral link Artlist 介紹碼連結 : https://artlist.io/Handline-861488
==================================================================
Background Music 背景音樂名稱 : Trickster by Ian Post
Source 來源 : Artlist.io
Referral link 介紹碼連結 : https://artlist.io/Handline-861488
Background Music 背景音樂名稱 : Dead-end maze (https://johnnyhk.bandcamp.com/track/dead-end-maze)
Source 來源 : Troglojam
==================================================================
#雞魚 #仕掛 #釣魚教學 #Fishing #釣魚 #手絲釣魚 #香港釣魚

post authorization 在 Handline Fishing Youtube 的最佳貼文
釣魚比賽牙骹戰 | 蛋糕偉 | 香港釣魚 | 艇釣 | 維港【Capillus 香港】
Fishing Competition | [Hong Kong HK Fishing : BoatGame] Victoria Harbour {Voice Over + CC}
Capillus香港專賣店:尖沙咀彌敦道132美麗華商場一期地庫B133店
(星期一至日, 中午12:00 至晚上8:30)
優惠碼:MARCO
全店貨品限時8折優惠
Business Cooperation and Media 商業合作、採訪通知:tkcmarco@gmail.com
******************************************************************
Media Interview(s) OR Reproduce with authorization 媒體採訪或授權轉載
Media 媒體報導
: viuTV 電視特輯 :
發展局 海濱事務委員會呈獻 【維港.圍講】
播出時間(2021年5月1日 )
第4集 - 魚樂無窮: 釣魚發燒友維港遊
https://viu.tv/encore/lets-talk-about-victoria-harbour/lets-talk-about-victoria-harboure4yue-lok-mo-kung--diu-yue-faat-siu-yau-wai-gong-yau
: Oriental Daily 東方日報 :
【手絲釣魚】岸釣系列#1 數碼港係熱門釣魚點?釣足30條泥鯭!
https://tv.on.cc/index.html?vid=OUGC20200707_900009_01&createtime=1594094281&subsection=468
More...Please refer to the channel description 更多... 請參閱頻道簡介
******************************************************************
==================================================================
YouTube Channel 頻道 : https://www.youtube.com/channel/UCO_5XP-qd-udNxBlzzSzgvw?sub_confirmation=1
Donate and Support my Channel 資助我的頻道:https://www.paypal.me/handlinefishing
==================================================================
Facebook 手絲釣魚交流群: https://www.facebook.com/groups/616740025403230/
Instagram 官方賬戶: https://www.instagram.com/handlinefishing_hk/
==================================================================
You can purchase my gear through the link below 你可以經以下連結購買產品
硬件
1人稱相機 (新) Insta360 Go 2 - https://www.insta360.com/sal/go_2?insrc=INRW1ZI
360相機 Insta360 ONE X2 - https://www.insta360.com/sal/one_x2?insrc=INRW1ZI
360相機 Insta360 ONE R - https://www.insta360.com/sal/one_r?insrc=INRW1ZI
1拖2咪 MirFakAudio - https://store.mirfakaudio.com?sca_ref=986772.ti6Y4oRgJX
以上是購買連結,你在購買時會得到額外的商家優惠,同時,不會因為商家的優惠而產生額外成本,可以支持這個頻道發展,先感謝你使用
音樂連結 Artlist.io Referral link Artlist 介紹碼連結 : https://artlist.io/Handline-861488
==================================================================
Background Music 背景音樂名稱 : Around Again by Ian Post
Source 來源 : Artlist.io
Referral link 介紹碼連結 : https://artlist.io/Handline-861488
Background Music 背景音樂名稱 : Dead-end maze (https://johnnyhk.bandcamp.com/track/dead-end-maze)
Source 來源 : Troglojam
==================================================================
#釣魚比賽 #Fishing #釣魚 #手絲釣魚 #香港釣魚

post authorization 在 New Authorization for Pages | Facebook for Business 的推薦與評價
We're introducing Page publishing authorization starting with people who ... be asked to complete an authorization process in order to continue to post, ... ... <看更多>
post authorization 在 開發者必備知識- HTTP認證(HTTP Authentication) 的推薦與評價
2018/11/18 posted in Security 2 Comments. 認證(Authentication)是建構Web應用或Web伺服器不可或缺的一環。以下簡單介紹一下各種常見的HTTP Authentication方式。 ... <看更多>
post authorization 在 http post - how to send Authorization header? - Stack Overflow 的推薦與評價
... <看更多>