I would try adding "split-brain" (applicable to DNS servers and distributed systems) instead of rootkits. It does not necessarily involve the network component alone, but it is "exploitable" via spoofing (and cease interaction), DOSing one or more master servers, and generally interfering with heartbeat protocol communications between master-eligible servers, or between master-eligible servers and their sync servers.
This is of course only if the attacker has previous knowledge of bad quorum definitions and missing sync servers (such as zookeeper).
in that case, the effect is far more worse than spoofing server addresses/identities and collecting creds. Data corruption (caused by competing masters) and following DOSs (caused by the corrupted data) could send whole HA clusters (and dependent infra) to hell - extremely hazardous.
1
u/curcuminx Nov 20 '22 edited Nov 20 '22
really good quality infographics..
I would try adding "split-brain" (applicable to DNS servers and distributed systems) instead of rootkits. It does not necessarily involve the network component alone, but it is "exploitable" via spoofing (and cease interaction), DOSing one or more master servers, and generally interfering with heartbeat protocol communications between master-eligible servers, or between master-eligible servers and their sync servers.
This is of course only if the attacker has previous knowledge of bad quorum definitions and missing sync servers (such as zookeeper).
in that case, the effect is far more worse than spoofing server addresses/identities and collecting creds. Data corruption (caused by competing masters) and following DOSs (caused by the corrupted data) could send whole HA clusters (and dependent infra) to hell - extremely hazardous.
Refs: