Writing
container security
2 articles on this subject.
Linux capabilities: root privileges without the SUID bit, and the container escape they enable
Capabilities split root into 40+ pieces, and about a dozen of them are still root. Which ones matter, how CVE-2022-0492 turned a cgroup detail into a container escape, and how to audit a host and an image.
7 min read
SSRF past the metadata endpoint: Docker on 2375, kubelet on 10250, and the 50,000 hosts TeamTNT found
IMDSv2 closed the famous SSRF target. The internal network is still full of unauthenticated control planes that will run a container for anyone who asks, and crypto-mining crews have been scanning for them since 2020.
7 min read