Loading…
Wednesday, May 22 • 11:55 - 12:30
Crafty Requests: Deep Dive Into Kubernetes CVE-2018-1002105 - Ian Coldwater, Heroku

Sign up or log in to save this to your schedule and see who's attending!

Feedback form is now closed.
You may have heard about CVE-2018-1002105, one of the most severe Kubernetes security vulnerabilities of all time. But how does this flaw work? How can it be exploited, and what does it all mean?

This deep dive will walk the audience through the Kubernetes back end, going over relevant concepts like aggregated API servers, the kubelet API, and permissions for namespace-constrained users. We will explain the details of how this flaw works, how a cluster’s moving parts can fit together to create a vulnerable context, and the risks involved in leaving this CVE unpatched in the wild.

A live demonstration will show the audience exactly how easy it is to exploit this vulnerability. After explaining the attack pathways, the audience will leave with practical advice about mitigation and how to protect their clusters.

Speakers
avatar for Ian Coldwater

Ian Coldwater

Lead Platform Security Engineer, Heroku
Ian Coldwater is a grown teenage hacker turned Lead Platform Security Engineer at Heroku, who specializes in hacking and hardening Kubernetes, containers and cloud-native infrastructure. In their spare time, they like to go on cross-country road trips, participate in Capture the Flag... Read More →



Wednesday May 22, 2019 11:55 - 12:30
Hall 8.0 C4