kubernetes / kubernetes/sig-security
Scanning and private triage of dangling DNS records
- Dominant language
- Go
- Stars
- 249
- Forks
- 82
- Avg merge
- 7d 12h
- Merged PRs (30d)
- 2
Description
A common type of issue reported to the Security Response Committe under the Kubernetes bug bounty program is netlify takeovers. These occur when a Kubernetes DNS record points to a Netlify account that does not exist, and allow anyone to publish web content under a Kubernetes-project hostname.
We could help the project and the user community to be safer by doing proactive scanning for these sorts of issues.
I have discussed this idea with other SRC members, and we would like to ask the SIG Security Tooling community to help make it happen.
Contributor guide
Research direction
The issue names no files, tests, or entry points; start by reading the discussion and the Kubernetes bug bounty context, then clarify the scope with SIG Security Tooling. Define what proactive dangling-DNS scanning and private triage should include, and consider the work done when the community agrees on an actionable design.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100