7 ms·
32C3 CTF: Docker writeup
- shykes 11y agoA more accurate title would be "misconfigured Docker pwned" since '--net=host' removes the container's network isolation. Still a pretty cool excuse for playing with unix socket fd passing!
- espadrine 11y agoWhy were the constraints of the game so loose? It even gave unprivileged SSH access to the real machine, outside docker! Is docker considered as strong as a chroot nowadays? Are uid0 programs unable to escape? Is it safe to run the `try ruby`s of this world on docker? The website[0] mentions that "even if an intruder manages to escalate to root within a container, it will be much harder to do serious damage, or to escalate to the host." Has anyone succeeded in doing so with a recent version of docker? [0]: https://docs.docker.com/engine/articles/security/ https://docs.docker.com/engine/articles/security/
- kevinsimper 11y agoThe docs about Docker security could really need more honesty.
- shykes 11y agoIf you think there's an inaccuracy, please consider filing an issue on https://github.com/docker/docs.docker.com https://github.com/docker/docs.docker.com , or even better sending a pull request to fix it.
- shykes 11y agoA well-configured recent version of Docker on a well-configured recent linux host has no known exploits. But it's a matter of risk management. The general consensus in the security community is that Linux containers (the set of kernel features used by Docker to isolate processes) are a solid security layer in some configurations, and with a little more operational mileage, will be solid in all configurations (most importantly running untrusted code as root, thanks to user namespaces). The limit for linux container security will soon be linux security itself: the probability of finding bugs in the linux codebase will always be greater than, say, in Xen which is considerably smaller and simpler.
- niklas_b 11y ago> Why were the constraints of the game so loose? It even gave unprivileged SSH access to the real machine, outside docker! Usually you are not expected to come up with 0days in CTFs (although 32C3 CTF actually featured a "0.5"day-ish bug in a different challenge that was not considered a security issue before). The challenge here was to realize that you could pass a directory file descriptor to the container via a Unix socket, not to break out of a well-configured docker container. The latter would hopefully be a bit harder to do in just a few hours of time :)
- dang 11y agoWe changed the title from "Docker Pwned (32C3 CTF: Docker Writeup)".