Skip to content

Exploit: check istio

neargle edited this page Jan 13, 2021 · 1 revision

Check was the shell in a istio(service mesh) network, please note that this feature will request http://httpbin.org/get, it is also the reason why we put it in exploit subcommand.

./cdk_linux_amd64 run istio-check
2021/01/13 13:56:30 the shell is in a istio(service mesh) network.
2021/01/13 13:56:30 X-Envoy-Peer-Metadata-Id is sidecar~192.168.10.14~postgres-6f9884dfdb-wt4sl.default~default.svc.cluster.local.
2021/01/13 13:56:30 X-Envoy-Peer-Metadata is xxxxx.
Clone this wiki locally