CAP_NET_RAW

CAP_NET_RAW allows raw and packet sockets. It is not a host escape but a network attack primitive: the container can sniff traffic on networks it shares and craft arbitrary packets to spoof, poison, or redirect. On a shared or host network it is especially dangerous.

bash
capsh --print | grep -q cap_net_raw && echo have
tcpdump -i any -c 20 2>/dev/null                 # sniff reachable traffic
# Spoof responses: ARP poisoning, DHCP, or DNS depending on the segment

Exploitation notes#

  • The impact scales with the network the container sits on; combine with a Host network namespace to reach the host's own interfaces and services.
  • Classic uses are ARP and DNS spoofing to man-in-the-middle other pods or the node, and capturing credentials in cleartext protocols.
  • In Kubernetes, raw sockets plus a flat pod network often reach services a NetworkPolicy was assumed to protect.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more