Giter Site home page Giter Site logo

Comments (15)

lizrice avatar lizrice commented on June 7, 2024

Thanks for raising. Just noting that the incorrect padding error may well come from base64 decoding. Needs investigation

from kube-hunter.

lmeyemezu avatar lmeyemezu commented on June 7, 2024

Thanks for replying.
Do we need to do something on our side ?

from kube-hunter.

lmeyemezu avatar lmeyemezu commented on June 7, 2024

Hi @lizrice
Any update ?
Regards

from kube-hunter.

hypery2k avatar hypery2k commented on June 7, 2024

experencing the same error. sometimes getting the same error, but only in same cases. In most of the run it just works

from kube-hunter.

davidkarlsen avatar davidkarlsen commented on June 7, 2024

no paddng problem - but can't find any cluster here either:

~ Started
~ Discovering Open Kubernetes Services...
|
| Accessed to pod's secrets:
|   type: vulnerability
|   host: None:None
|   description: 
|     Accessing the pod's secrets within a
|     compromised pod might disclose valuable data to a
|_    potential attacker

----------


Kube Hunter couldn't find any clusters

Using this chart: https://github.com/helm/charts/tree/master/stable/kube-hunter

from kube-hunter.

ImPurshu avatar ImPurshu commented on June 7, 2024

~ Started
~ Discovering Open Kubernetes Services...
|
| Accessed to pod's secrets:
| type: vulnerability
| host: None:None
| description:
| Accessing the pod's secrets within a
| compromised pod might disclose valuable data to a
|_ potential attacker
Cannot read wireshark manuf database

Same error I am facing.
Any idea?

from kube-hunter.

jayunit100 avatar jayunit100 commented on June 7, 2024

same here, kubectl create -f job.yml, then the logs:

~ Started
~ Discovering Open Kubernetes Services...
|
| Accessed to pod's secrets:
|   type: vulnerability
|   host: None:None
|   description:
|     Accessing the pod's secrets within a
|     compromised pod might disclose valuable data to a
|_    potential attacker
----------
Kube Hunter couldn't find any clusters

from kube-hunter.

aakarshit-batchu avatar aakarshit-batchu commented on June 7, 2024

Hi Guys,
Facing the same issue here with kube-hunter pod batch job.

`
~ Started
~ Discovering Open Kubernetes Services...
|
| Read access to pod's service account token:
| type: vulnerability
| host: None:None
| description:
| Accessing the pod service account token
| gives an attacker the option to use the
|_ server API
|
| Access to pod's secrets:
| type: vulnerability
| host: None:None
| description:
| Accessing the pod's secrets within a
| compromised pod might disclose valuable data to a
|_ potential attacker
Cannot read wireshark manuf database

Kube Hunter couldn't find any clusters
`

Kindly help me with this issue.

from kube-hunter.

Richahasija avatar Richahasija commented on June 7, 2024

i Guys,
Facing the same issue here with kube-hunter remote scanning

~ Started
~ Discovering Open Kubernetes Services...

Kube Hunter couldn't find any clusters


from kube-hunter.

jgsqware avatar jgsqware commented on June 7, 2024

What is the correct format kube-hunter is expecting?

from kube-hunter.

MysteriousNeo avatar MysteriousNeo commented on June 7, 2024

Any update on this bug , i want to run kube hunter in my cluster.

from kube-hunter.

sachsachdeva avatar sachsachdeva commented on June 7, 2024

Facing the same Issue, I tried this on the AKS cluster today

~ Started
~ Discovering Open Kubernetes Services...
|
| Accessed to pod's secrets:
| type: vulnerability
| host: None:None
| description:
| Accessing the pod's secrets within a
| compromised pod might disclose valuable data to a
|_ potential attacker


from kube-hunter.

davidkarlsen avatar davidkarlsen commented on June 7, 2024

Is this project dead?

from kube-hunter.

lizrice avatar lizrice commented on June 7, 2024

Far from it! Note that not being able to find any clusters is a perfectly plausible response - for example if the cluster is not accessible over the network from where kube-hunter is run.

Please run with logging turned on @sachsachdeva so we can get some clues. Also @danielsagi to re-test on AKS when you have a chance.

from kube-hunter.

danielsagi avatar danielsagi commented on June 7, 2024

@sachsachdeva @aakarshit-batchu @davidkarlsen please see #140.
This fixes the issue in your case of not printing the vulnerabilities found from running with job.yaml.

@lmeyemezu After: #137 exceptions are now logged correctly, so if you would run now, we can debug and see the origin of the "incorrect padding" error you got, also, there has been multiple PR's regarding the exceptions, from when this issue was posted, so theres a good chance it was fixed.
if the problem consists in reproduction, please open a new issue, with the output of the debug messages of "incorrect padding"

from kube-hunter.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.