Get a Pentest and security assessment of your IT network.

Cyber Security

Escaping Containers to Execute Commands on Play with Docker Servers

CyberArk researchers hacked Play with Docker, a Docker containerization platform. The exploit preyed on the fact that containers all use the same kernel code, something that makes the technology so lightweight and attractive. CyberArk experts were able to take a Linux kernel module that was compiled in their laboratory and inject it into the PWD Linux kernel. They used a module that tricked the target kernel into loading it. The module they used was ceph.ko, loaded by the kernel for the Ceph software storage platform. On January 7, 2019, CyberArk confirmed the vulnerability was no longer present.

Source: https://www.bleepingcomputer.com/news/security/escaping-containers-to-execute-commands-on-play-with-docker-servers/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security