Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

6/18/2018
05:28 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
100%
0%

Exposed Container Orchestration Systems Putting Many Orgs at Risk

More than 22,600 open container orchestration and API management systems discovered on the Internet.

New research confirms that many organizations are deploying workloads to the public cloud without adequate security controls and processes in place first.

Lacework recently used the Shodan search engine, SSL data mining techniques, and some internally developed tools to uncover as many as 22,672 open container orchestration dashboards and API management systems on the Internet. The applications that Lacework discovered during its research were Kubernetes, Mesos Marathon, Swagger API, Red Hat Openshift and Docker Swarm's Portainer and Swarmpit.

Some 95% of the exposed dashboards and management systems were hosted inside of Amazon Web Services. More than half of those exposed services were hosted on AWS regions in the US. Though a vast majority of the open container orchestration interfaces had credentials for controlling access, the fact that they were exposed to the Internet at all is troublesome, says Dan Hubbard, chief security at Lacework.

The dashboard provides top-level access to all the functions required to manage and administer container clusters. Anyone with access to the dashboard can carry out tasks like starting and stopping workloads, adding or modifying applications and setting key security controls.

Container management interfaces that are not properly configured and are exposed on the Internet pose a major risk for enterprises. "Even with credentials set up, information related to the organization might be disclosed," Hubbard points out. This includes information contained in host headers or SSL certificates. Lacework researchers, for instance, were relatively easily able to derive company names from certificates and hostnames without even having to access the exposed container interfaces.

Weak authentication schemes - like inadequate credential requirements - can allow an attacker to brute-force the password of an exposed container management interface. Similarly, not using SSL can allow an attacker to gain access via clear text authentication. Any vulnerabilities in the container application itself are also likely to be easier to exploit via exposed management dashboards.

Lacework's research also uncovered some 300 container management dashboards with no authentication at all, giving attackers a way to easily spin up and stop containers, delete or destroy information, and harvest data about the infrastructure, Hubbard says. Such completely open dashboards also give attackers a way to potentially move laterally to other cloud resources, log into cloud instances and launch new instances for abuse like Bitcoin mining and DDoS. In addition, attackers can exploit the dashboards to set up a backdoor or to drop malicious code for performing command-and-control and other activities.

Because Kubernetes is currently one of the most popular and fastest-growing container orchestration and management systems, Lacework researchers decided to drill down into some of the issues related to the use of these dashboards in public clouds. Although Kubernetes comes with security features like default SSL use and default authentication, Lacework researchers discovered many open Kubernetes dashboards that were still in the process of being set up; dashboards with no authentication; dashboards that could be brute-forced and those that were leaking information about the organization.

Researchers also discovered 38 servers running a container health check service called "healthz" for Kubernetes environments, live on the Internet with no authentication at all. Besides potentially giving attackers a way to potentially perform full remote code execution capabilities, the app also provides a way to monitor workloads and stop them from running via the dashboard.

The data highlights the need for organizations to follow fundamental security best practices when deploying containers in the public cloud. Examples include protecting them behind a proxy, using multifactor authentication and role-based models to control access, and enforcing the use of SSL, Hubbard says. Limiting the scope of what you can do via a management interface is also a good idea. For example, it is not a great idea to have one management hub for all workloads because if one pod is compromised, all workloads get put at risk, he says.

"The general theme of our discoveries is that there needs to be a bridge in communication, process, and technology between DevOps and security," Hubbard notes. "The operating model here is very different and that needs to be acknowledged."

Related Contents:

  

 

Top industry experts will offer a range of information and insight on who the bad guys are – and why they might be targeting your enterprise. Click for more information

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Exploits Released for As-Yet Unpatched Critical Citrix Flaw
Jai Vijayan, Contributing Writer,  1/13/2020
Active Directory Needs an Update: Here's Why
Raz Rafaeli, CEO and Co-Founder at Secret Double Octopus,  1/16/2020
Microsoft Patches Windows Vuln Discovered by the NSA
Kelly Sheridan, Staff Editor, Dark Reading,  1/14/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This comment is waiting for review by our moderators.
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
[Just Released] How Enterprises are Attacking the Cybersecurity Problem
Organizations have invested in a sweeping array of security technologies to address challenges associated with the growing number of cybersecurity attacks. However, the complexity involved in managing these technologies is emerging as a major problem. Read this report to find out what your peers biggest security challenges are and the technologies they are using to address them.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5397
PUBLISHED: 2020-01-17
Spring Framework, versions 5.2.x prior to 5.2.3 are vulnerable to CSRF attacks through CORS preflight requests that target Spring MVC (spring-webmvc module) or Spring WebFlux (spring-webflux module) endpoints. Only non-authenticated endpoints are vulnerable because preflight requests should not incl...
CVE-2019-17635
PUBLISHED: 2020-01-17
Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a deserialization vulnerability if an index file of a parsed heap dump is replaced by a malicious version and the heap dump is reopened in Memory Analyzer. The user must chose to reopen an already parsed heap dump with an untrusted inde...
CVE-2019-19339
PUBLISHED: 2020-01-17
It was found that the Red Hat Enterprise Linux 8 kpatch update did not include the complete fix for CVE-2018-12207. A flaw was found in the way Intel CPUs handle inconsistency between, virtual to physical memory address translations in CPU's local cache and system software's Paging structure entries...
CVE-2007-6070
PUBLISHED: 2020-01-17
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2008-1382. Reason: This candidate is a reservation duplicate of CVE-2008-1382. Notes: All CVE users should reference CVE-2008-1382 instead of this candidate. All references and descriptions in this candidate have been removed to prevent ...
CVE-2019-17634
PUBLISHED: 2020-01-17
Eclipse Memory Analyzer version 1.9.1 and earlier is subject to a cross site scripting (XSS) vulnerability when generating an HTML report from a malicious heap dump. The user must chose todownload, open the malicious heap dump and generate an HTML report for the problem to occur. The heap dump could...