Host access and shell

A Proxmox node is a Debian host with a web UI on 8006 and a shell. Root on the host owns every VM and container on it, and the clustered configuration filesystem pmxcfs (mounted at /etc/pve) exposes the whole cluster's definitions, users, and tokens. Reaching the node is ordinary Linux compromise or a management-plane pivot.

bash
qm list                                   # KVM guests on this node
pct list                                  # LXC containers on this node
qm terminal <vmid>                         # guest serial console
cat /etc/pve/user.cfg                      # users and roles (cluster-wide)
ls /etc/pve/qemu-server/                   # VM configs, disk references

Exploitation notes#

  • /etc/pve is a cluster-wide view: user and token definitions, VM configs, and storage, readable with root on any node.
  • qm and pct give console and full control of guests, and the storage is directly readable for Disk and backup theft.
  • LXC containers are local to the node, so a container escape (standard Linux container-escape primitives) lands directly on the node.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more