Settings

Theme

I Hacked Play-With-Docker and Remotely Ran Code on the Host

cyberark.com

16 points by tigerente 7 years ago · 4 comments

Reader

WestCoastJustin 7 years ago

What an awesome hacking session. Very nice angle on writing their own kernel module. Thanks for posting this!

theamk 7 years ago

TL/DR: Docker runs "Play with docker" service, and they did not block insmod there, nor did they block access to the boot disk. Wow! To quote the author:

> The reason is quite simple: PWD uses a privileged container

This is such an obvious failure that I wonder how it could even get into production.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection