Skip to content

Scanning and private triage of dangling DNS records #172

@tabbysable

Description

@tabbysable

A common type of issue reported to the Security Response Committe under the Kubernetes bug bounty program is netlify takeovers. These occur when a Kubernetes DNS record points to a Netlify account that does not exist, and allow anyone to publish web content under a Kubernetes-project hostname.

We could help the project and the user community to be safer by doing proactive scanning for these sorts of issues.

I have discussed this idea with other SRC members, and we would like to ask the SIG Security Tooling community to help make it happen.

Metadata

Metadata

Assignees

No one assigned

    Labels

    help wantedDenotes an issue that needs help from a contributor. Must meet "help wanted" guidelines.sig/securityCategorizes an issue or PR as relevant to SIG Security.triage/acceptedIndicates an issue or PR is ready to be actively worked on.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions