TechSNAP

Problematic Privileges


Listen Later

Wes takes a quick look at a container escape proof-of-concept and reviews Docker security best practices.

Links:

  • Understanding Docker container escapes | Trail of Bits Blog — Linux cgroups are one of the mechanisms by which Docker isolates containers. The PoC abuses the functionality of the notify_on_release.
  • Felix Wilhelm on Twitter — Quick and dirty way to get out of a privileged k8s pod or docker container by using cgroups release_agent feature.
...more
View all episodesView all episodes
Download on the App Store

TechSNAPBy Jupiter Broadcasting

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

112 ratings