Sign inSign up

paliguoqing/attack-simulator

By paliguoqing

•Updated over 1 year ago

Web UI based simulator, to run L7 attack and malicious cmd. Design for CWPP test like Prisma Cloud.

Image
Security
0

4.6K

paliguoqing/attack-simulator repository overview

⁠CAUTION, DANGER:

For local Docker setups, users have full command execution rights, posing a significant security risk. In the Kubernetes setup, the container is assigned cluster-admin permissions. As the highest privilege level, it allows unrestricted access to the cluster, such as:

  • Accessing all cluster Secrets.
  • Deleting namespaces, nodes, or workloads.
  • Changing configurations that could crash the cluster.
  • Running unauthorized software like miners or malware.

WARNING AGAIN: Use this solution strictly in isolated test environments. Do not apply these settings to production or sensitive environments.

⁠LOGIN

Double click the words below the login UI, and user/password will be filled auto.

⁠In Docker:

docker run -d --name attack-simulator-local -p 8080:8080 paliguoqing/attack-simulator:v1-1750402414

⁠In K8S:

Create service account with cluster-admin and then run it in.

Tag summary

Content type

Image

Digest

sha256:335204ae8…

Size

125.1 MB

Last updated

over 1 year ago

docker pull paliguoqing/attack-simulator:v1-1750402414