Privileged configuration

The most common container escapes need no exploit at all: the container was simply configured with more power than isolation can survive. Each setting here removes one of the walls, and several of them collapse straight to host code execution. Check what you were given first:

bash
capsh --print 2>/dev/null                 # capabilities in the container
cat /proc/self/status | grep -i cap       # CapEff bitmask
cat /sys/fs/cgroup/*/release_agent 2>/dev/null

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more