Capability abuse

Docker and Kubernetes drop most capabilities by default, but workloads routinely add one or two back for convenience, and each dangerous capability is its own escape. Read the effective set, then pick the matching technique.

bash
capsh --print | sed -n 's/^Current: //p'
grep CapEff /proc/self/status        # decode with: capsh --decode=<hex>

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more