<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:media="http://search.yahoo.com/mrss/"><channel><title>Attack Vectors on Shaowen Chen's Website</title><link>https://www.chenshaowen.com/en/tags/attack-vectors/</link><description>Recent content in Attack Vectors on Shaowen Chen's Website</description><generator>Hugo -- gohugo.io</generator><language>en</language><copyright>&amp;copy;2016 - {year}, All Rights Reserved.</copyright><lastBuildDate>Fri, 22 Jan 2021 00:00:00 +0000</lastBuildDate><sy:updatePeriod>weekly</sy:updatePeriod><atom:link href="https://www.chenshaowen.com/en/tags/attack-vectors/atom.xml" rel="self" type="application/rss+xml"/><item><title>Run `rm -rf /` Under Kubernetes and You Can Just Run Away</title><link>https://www.chenshaowen.com/en/blog/attack-vectors-under-kubernetes.html</link><pubDate>Fri, 22 Jan 2021 00:00:00 +0000</pubDate><atom:modified>Fri, 22 Jan 2021 00:00:00 +0000</atom:modified><guid>https://www.chenshaowen.com/en/blog/attack-vectors-under-kubernetes.html</guid><description>This document is mainly meant to demonstrate the dangers of Docker privileged mode, so please proceed with caution. Users without CLI access can copy the example YAML and directly create cluster workloads such as Pod, Job, and DaemonSet to carry out the operations.
1. Directly Deleting All Resources If you can log in to the machine, pack your things, and run the command:</description><dc:creator>微信公众号</dc:creator><category>Kubernetes</category><category>Security</category><category>Attack Vectors</category><category>Operations</category><category>Docker</category><category>Troubleshooting</category></item></channel></rss>