CAP_DAC_READ_SEARCH

CAP_DAC_READ_SEARCH bypasses file read and directory search permission checks, and it permits open_by_handle_at. That syscall opens a file by an opaque handle rather than a path, and handles for the root filesystem are guessable, so a container holding this capability can read host files outside its mount namespace. This is the classic Shocker technique.

bash
capsh --print | grep -q cap_dac_read_search && echo have
# Shocker: brute-force the host root inode handle, then read a target file
./shocker /etc/shadow        # reads the HOST /etc/shadow via open_by_handle_at

Exploitation notes#

  • It is a read primitive: no writes, no code execution, but host /etc/shadow, SSH keys, and tokens are enough to escalate elsewhere.
  • It works because file handles encode the inode on the underlying device, which is shared with the host; the container mount namespace does not gate open_by_handle_at.
  • For writes rather than reads, see CAP_DAC_OVERRIDE.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more