1“安装漏洞”
2复杂漏洞场景
git clone https://github.com/brant-ruan/metarget.gitcd metarget/pip install -r requirements.txt
./metarget cnv install cve-2019-5736./metarget cnv install cve-2018-1002105 --domestic./metarget appv install dvwa --external:/home/nsfocus/metarget# ./metarget cnv install cve-2019-5736is going to be installeduninstalling current docker if applicableinstalling prerequisitesadding apt repository deb [arch=amd64] https://download.docker.com/linux/ubuntu bionic stableinstalling docker-ce with 18.03.1~ce~3-0~ubuntu versionsuccessfully installed:/home/nsfocus/metarget# ./metarget cnv install cve-2018-1002105 --domesticdocker already installedis going to be installeduninstalling current kubernetes if applicablepre-configuringpre-installingadding apt repository deb https://mirrors.aliyun.com/kubernetes/apt/ kubernetes-xenial maininstalling kubernetes-cni with 0.7.5-00 versioninstalling kubectl with 1.11.10-00 versioninstalling kubelet with 1.11.10-00 versioninstalling kubeadm with 1.11.10-00 versionpulling registry.cn-hangzhou.aliyuncs.com/google_containers/kube-proxy-amd64:v1.11.1pulling registry.cn-hangzhou.aliyuncs.com/google_containers/kube-controller-manager-amd64:v1.11.1pulling registry.cn-hangzhou.aliyuncs.com/google_containers/kube-apiserver-amd64:v1.11.1pulling registry.cn-hangzhou.aliyuncs.com/google_containers/kube-scheduler-amd64:v1.11.1pulling registry.cn-hangzhou.aliyuncs.com/google_containers/pause:3.1pulling registry.cn-hangzhou.aliyuncs.com/google_containers/etcd-amd64:3.2.18pulling registry.cn-hangzhou.aliyuncs.com/google_containers/coredns:1.1.3running kubeadminstalling cni plugininstalling flannelpulling quay.mirrors.ustc.edu.cn/coreos/flannel:v0.10.0-amd64generating kubernetes worker scriptkubernetes worker script generated at tools/install_k8s_worker.shsuccessfully installed:/home/nsfocus/metarget# ./metarget appv install dvwa --externaldocker already installedkubernetes already installeddvwa is going to be installednode port 30000 is allocated for service in vulns_app/dvwa/dvwa//dvwa-service.yamlapplying yamls/k8s_metarget_namespace.yamlapplying vulns_app/dvwa/dvwa//dvwa-deployment.yamlapplying data//dvwa-service.yamldvwa successfully installed
./metarget appv remove dvwa./metarget cnv remove cve-2018-1002105./metarget cnv remove cve-2019-5736
1云原生组件脆弱场景
2云原生应用脆弱场景
./metarget appv list星云实验室专注于云计算安全、解决方案研究与虚拟化网络安全问题研究。基于IaaS环境的安全防护,利用SDN/NFV等新技术和新理念,提出了软件定义安全的云安全防护体系。承担并完成多个国家、省、市以及行业重点单位创新研究课题,已成功孵化落地绿盟科技云安全解决方案。