Privileges escalation in kubernetes

LeoFVO profile picture

I'm Léo

Platform security engineer, red teamer

Passionnate about cybersecurity, cloud-native & productivity

I started out in cybersecurity with an offensive approach, developing a real passion for hacking and social engineering. Today, I use my real-life experience to improve the security of cloud infrastructures and DevOps methodology.

I love doing cloud architecture and designing concepts and solutions that address real-world problems in today's cloud and web applications. I have a great attraction for Kubernetes, my deep interest in this system has led me to become a Kubernetes security expert.
I'm also active in various communities, contributing to open-source projects, taking part in bug-bounty programs and giving talks.

Competitive and dynamic by nature, I constantly feel the need to improve myself. However, I'm also pedagogue and aspire to share my knowledge, so I write articles on subjects that inspire me and give courses in engineering school.

Otherwise, I am deeply interested in finance. Mostly in technical analysis, but also market psychology.
Boxer.

Being productive rather than busy.

Talks

Conferences and events where I took part as a speaker.

Horizontal Privileges Escalation in Kubernetes

Discover the best solutions and practices for strengthening the security of your Kubernetes clusters. This presentation includes a demonstration of a horizontal privilege escalation attack, offering a practical, in-depth perspective on protecting your kubernetes clsuter.


Cloud Native Montpellier

Teads Head Office, Montpellier, France

Why DevOps guys have to care about cybersecurity

Have you ever heard of DevSecOps? probably. But can you assure that you understand what it is and what are its daily challenges, would you imagine that its main challenge is actually: you...


Polycloud

Polytech, Montpellier, France

Articles

Articles I wrote about things I known or discovered and wanted to share

Practical Look at Horizontal Privileges Escalation in Kubernetes

pentest
grafana
kubernetes
This articles will cover a real-world scenario of how an hackers will try to escalate privileges horizontally in a kubernetes cluster. Taking a particular attention to Grafana.

Overview of email security

smtp
email
spoofing
Email remains a primary channel for exchanging information. However, the convenience of email also opens doors to potential security threats.

Mastering JWT authentication

authentication
jwt
refresh-token
Working in cybersecurity, I have recently spent some time doing technology watch and developing my skills on a recurring topic when developing web and mobile applications: authentication.
View all articles

Researchs

Vulnerability discovered and reported on my free-time.

Stored XSS on Algolia search engine

I was able to execute client-side code on all browsers interacting with the search functionnality in Magento. I reported it to the security team, at this date, vulnerability have been fixed.

Artists informations disclosure on Deezer

I found a personnal information diclosure on Deezer IOS application. I was able to get personnal informations on artist that are using a pseudonym.

Projects

Project I founded and/or contributed on.

Gosurp

cybersecurity
smtp
spoofing
go
Email spoofer wrote from scratch. Doesn't need tier-parties or smtp server. Fully written in Go.

RustScan

cybersecurity
scanner
nmap
rust
RustScan is a modern take on the port scanner. Sleek & fast. All while providing extensive extendability to you.

Rik (Rust In Kubernetes)

cloud
Kubernetes
rust
RIK is an experimental workload orchestrator that allows you to deploy your cloud applications, written in Rust.

Morty

cloud
FaaS
go
Morty is an open source serverless platform allowing users to deploy function as a service, without the need of managing servers.

GoBucket

cybersecurity
scanner
S3 dumper
golang
Object Storage bucket dumper/analyser written in go.

GoSSTI

cybersecurity
scanner
SSTI
golang
GoSSTI is a SSTI scanner for web application. Developed in Go.

Polyflix

kubernetes
terraform
react
microservices
Polyflix is a web platform intended to serve as a workspace for people, allowing the provision of resources for learning content.