Skip to content

Commit 90d6165

Browse files
committed
bypass user namespaces docs
1 parent 33e5508 commit 90d6165

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

documentation/modules/exploit/linux/http/docker_daemon_tcp.md

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -67,6 +67,8 @@ OK
6767

6868
[Disable][5] or [protect][6] the Docker tcp socket.
6969

70+
[User namespaces][7] did **not** protect against this.
71+
7072
# Exploitation
7173
This module is designed for the attacker to leverage, creation of a
7274
Docker container with out authentication through the Docker tcp socket
@@ -128,3 +130,4 @@ meterpreter >
128130
[4]:https://docs.docker.com/engine/admin/systemd/
129131
[5]:https://docs.docker.com/engine/reference/commandline/dockerd/#options
130132
[6]:https://docs.docker.com/engine/security/https/
133+
[7]:https://docs.docker.com/engine/security/userns-remap/#disable-namespace-remapping-for-a-container

0 commit comments

Comments
 (0)