kubernetes / kubernetes/sig-security

Scanning and private triage of dangling DNS records

Open
#172 9 comments 1 reaction 0 assignees View on GitHub
help wanted sig/security triage/accepted
Dominant language
Go
Stars
249
Forks
82
Avg merge
7d 12h
Merged PRs (30d)
2

Description

A common type of issue reported to the Security Response Committe under the Kubernetes bug bounty program is netlify takeovers. These occur when a Kubernetes DNS record points to a Netlify account that does not exist, and allow anyone to publish web content under a Kubernetes-project hostname.

We could help the project and the user community to be safer by doing proactive scanning for these sorts of issues.

I have discussed this idea with other SRC members, and we would like to ask the SIG Security Tooling community to help make it happen.

Contributor guide

Open the contributing guide

Research direction

The issue names no files, tests, or entry points; start by reading the discussion and the Kubernetes bug bounty context, then clarify the scope with SIG Security Tooling. Define what proactive dangling-DNS scanning and private triage should include, and consider the work done when the community agrees on an actionable design.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.