Docker splits into a client and a root daemon that does the work. Offensive interest is in the daemon's API, which is a full root-equivalent control plane, and in the images, registries, and builds that feed it. Escaping a container you start through Docker uses the shared primitives in Container escape; this area is everything that is specifically Docker.
Subtopics#
- Exposed daemon API: reaching the daemon over the network or weak TLS.
- Images and registries: looting, poisoning, and enumerating images and registries.
- Build-time: secrets and code execution during the image build.