4 ms·
Oh... these are inside a docker container... that sounds ripe for a kernel privesc -- Also its not /real/ root :V
by jetbalsa 4y ago
Oh... these are inside a docker container... that sounds ripe for a kernel privesc -- Also its not /real/ root :V
- normaler 4y agoBetter term would be disposable root shell. I am interested in the networking part of it. How that is achieved.
- kxrm 4y agoGitHub repo https://github.com/hackerschoice/segfault https://github.com/hackerschoice/segfault Not sure if it covers your question though.
- woodruffw 4y agoIt looks like they bind the Docker socket into the guest controller[1], but maybe not the guest itself. But yeah: unrestricted container root plus any capabilities means that they're only one low-effort bug away from a container escape. [1]: https://github.com/hackerschoice/segfault/blob/main/docker-compose.yml#L335 https://github.com/hackerschoice/segfault/blob/main/docker-c...
- coderintherye 4y agoGiven how valuable 0-day container escape exploits are and how knowledgeable the people are who host this, it would seem to make sense economically to host this for free with the explicit hope that someone does in fact escape and pwn the box, assuming they can log enough to determine the method of exploit and be able to reproduce it.
- bigiain 4y agoParanoid me wonders if this is run by law enforcement, who’ve made the segfault.net owners/admins “an offer that can’t refuse”?
- pinebox 4y agoThat was my first thought. Shut down voluntarily in 2019 for no particular reason after 22 years? Mysteriously back and even better? Doesn't pass the smell test. The page talks a big game about hating criminals, but these days if you don't put up a cookie banner RoboCop will shoot you in the dick. And if someone really isn't a criminal we've got a fix for that, too: Just ship them to a country where they are! On the other hand maybe this post-HSA, post-Snowden world has made me jaded and the site really is just good clean fun.