After mounting /var/run/docker.sock to a running docker container, I would like to explore the possibilities. Can I issue docker commands from inside the container, like docker stop
? Why is it considered a security risk:- what exact commands could I run as a root user in docker that could possibly compromise the host?
2
Answers
I couldn’t give you exact commands to execute since I’m not testing this but I’m assuming you could:
It’s trivial to escalate access to the docker socket to a root shell on the host.