Hidden in layers

隐藏在层中

1
kubectl get jobs
1
kubectl describe job 
  • 找到hidden-in-layers-czrlb
1
kubectl get pod hidden-in-layers-czrlb -o yaml
  • 找到完整的镜像名字,拉取镜像
1
docker pull madhuakula/k8s-goat-hidden-in-layers:latest
  • 通过利用 docker 内置命令将 docker 镜像导出为 tar 文件
1
docker save madhuakula/k8s-goat-hidden-in-layers -o hidden-in-layers.tar
1
./dive madhuakula/k8s-goat-hidden-in-layers
  • 得知敏感文件和路径

https://gh.putdown.top/https://github.com/futalk/tuchuang/raw/main/img/Snipaste_2023-10-30_17-42-36_d41d8cd98f00b204e9800998ecf8427e.jpg

  • 解压上面的的hidden-in-layers.tar文件
  • 根据上面的路径找到文件

https://gh.putdown.top/https://github.com/futalk/tuchuang/raw/main/img/Snipaste_2023-10-30_17-45-42_d41d8cd98f00b204e9800998ecf8427e.jpg

结束