logo

DNS Spoofing on Kubernetes Clusters

ID: 6e4d91f4-f91f-5f67-8814-e44b07b07cbf

STIX ID: report--6e4d91f4-f91f-5f67-8814-e44b07b07cbf

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2019-08-29

Date Updated: 2026-04-26

...
...

This report demonstrates a proof-of-concept Kubernetes network attack in which a malicious pod with CAP_NET_RAW can ARP-spoof the node bridge (cbr0) to impersonate CoreDNS, intercept and spoof DNS responses cluster-wide, and run a DNS proxy to enable MITM of pod traffic; the post provides scapy-based PoC code, detection guidance, and mitigations (drop NET_RAW, use L3 CNI/OVS-based CNIs, run kube-hunter).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.