Get a Pentest and security assessment of your IT network.

Cyber Security

Escaping Containers to Execute Commands on Play with Docker Servers

CyberArk researchers hacked Play with Docker, a Docker containerization platform. The exploit preyed on the fact that containers all use the same kernel code, something that makes the technology so lightweight and attractive. CyberArk experts were able to take a Linux kernel module that was compiled in their laboratory and inject it into the PWD Linux kernel. They used a module that tricked the target kernel into loading it. The module they used was ceph.ko, loaded by the kernel for the Ceph software storage platform. On January 7, 2019, CyberArk confirmed the vulnerability was no longer present.

Source: https://www.bleepingcomputer.com/news/security/escaping-containers-to-execute-commands-on-play-with-docker-servers/

Related posts
Cyber Security

Zip Codes & PII: Are They Personal Data?

Cyber Security

Zero-Day Vulnerabilities: User Defence Guide

Cyber Security

Zero Knowledge Voting with Trusted Server

Cyber Security

ZeroNet: 51% Attack Risks & Mitigation