
insject는 컨테이너를 건드리기 위한 도구입니다. 이를 통해 컨테이너 또는 Linux 네임스페이스의 임의 조합에서 임의의 명령을 실행할 수 있습니다.
insject는 컨테이너를 건드리기 위한 도구입니다. 컨테이너 또는 Linux 네임스페이스의 임의의 조합에서 임의의 명령을 실행할 수 있게 해줍니다. 세 가지 주요 사용 사례를 지원합니다:
libsetns.so를 사용하는 LD_PRELOAD 모드 (LD_PRELOAD=./libsetns.so SETNS_ARGS="...")insject ... -- <cmd>...)insject ... -! <pid>)처음 두 모드를 사용할 때, -s <symbol> 옵션은 프로세스의 컨테이너화를 트리거하는 함수 훅을 배치하는 데 사용됩니다. 이는 초기화 후 특정 함수를 호출할 때 컨테이너화되도록 하여 호스트 파일시스템에서 리소스를 로드해야 하는 간단한 명령에 도움이 될 수 있습니다.
스크립팅 언어와 같이 초기화 루틴이 더 복잡한 프로세스의 경우, 세 번째 사용 사례가 더 선호될 수 있으며, 컨테이너에 들어가기 전에 완전한 초기화를 보장할 수 있습니다.
참고: insject와 libsetns.so는 setns(2)와 동일한 제한 사항을 공유합니다. 즉, 프로세스에 여러 스레드가 포함된 경우 실패할 수 있습니다.
경고: 컨테이너 내의 파일에 접근하거나 실행할 때 주의하십시오. 컨테이너가 결합된 프로세스의 접근 권한을 악용하여 탈출할 수 있습니다.
$ wget https://github.com/frida/frida/releases/download/14.2.17/frida-gum-devkit-14.2.17-linux-x86_64.tar.xz
$ tar -xvJf frida-gum-devkit-14.2.17-linux-x86_64.tar.xz
$ mv frida-gum.h setns-so/frida/
$ mv libfrida-gum.a setns-so/frida/x86_64-unknown-linux-gnu/
$ pip3 install --user lief
$ cd setns-so
$ cargo build --lib --release
$ cargo build --bin insject --release
$ python3 patch.py target/release/insject
## Terminal 1
$ docker run --rm -it -v $(PWD):/FOO:ro alpine /bin/sh
/ # ls /
bin dev etc FOO home lib media mnt opt proc root run sbin srv sys tmp usr var
## Terminal 2
$ sudo bash
# echo $$
164001
#
## Terminal 3
$ docker ps -q
acd1d4d97027
$ docker inspect acd1d4d97027 | jq .[0].State.Pid
68575
$ sudo LD_PRELOAD=./target/release/libsetns.so SETNS_ARGS="-I 68575 --user 0:85:0,1,2,3,4" ls /
setns -> mnt: 0, net: 0, time: 0, ipc: N/A, uts: 0, pid: 0, cgroup: 0, userns: 0, apparmor: docker-default, user: 0/0/0
bin dev etc FOO home lib media mnt opt proc root run sbin srv sys tmp usr var
## Terminal 2
# setns -> mnt: 0, net: 0, time: 0, ipc: N/A, uts: 0, pid: 0, cgroup: 0, userns: 0, apparmor: docker-default, user: 0/0/0
# ls /
bin dev etc FOO home lib media mnt opt proc root run sbin srv sys tmp usr var
# ifconfig
eth0 Link encap:Ethernet HWaddr 02:42:AC:11:00:02
inet addr:172.17.0.2 Bcast:172.17.255.255 Mask:255.255.0.0
UP BROADCAST RUNNING MULTICAST MTU:1500 Metric:1
RX packets:525 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:0
RX bytes:49454 (48.2 KiB) TX bytes:0 (0.0 B)
lo Link encap:Local Loopback
inet addr:127.0.0.1 Mask:255.0.0.0
UP LOOPBACK RUNNING MTU:65536 Metric:1
RX packets:0 errors:0 dropped:0 overruns:0 frame:0
TX packets:0 errors:0 dropped:0 overruns:0 carrier:0
collisions:0 txqueuelen:1000
RX bytes:0 (0.0 B) TX bytes:0 (0.0 B)
## Terminal 3
$ sudo ./target/release/insject -I 68575 --user 0:85:0,1,2,3,4 -- ls /
setns -> mnt: 0, net: 0, time: 0, ipc: N/A, uts: 0, pid: 0, cgroup: 0, userns: 0, apparmor: docker-default, user: 0/0/0
bin dev etc FOO home lib media mnt opt proc root run sbin srv sys tmp usr var
$ sudo ./target/release/insject -I 68575 --user 0:85:0,1,2,3,4 -- id
setns -> mnt: 0, net: 0, time: 0, ipc: N/A, uts: 0, pid: 0, cgroup: 0, userns: 0, apparmor: docker-default, user: 0/0/0
uid=0 gid=85 groups=85,0,1,2,3,4
$ sudo ./target/release/insject -I 68575 --user 0:85:0,1,2,3,4 -- sh -c id
setns -> mnt: 0, net: 0, time: 0, ipc: N/A, uts: 0, pid: 0, cgroup: 0, userns: 0, apparmor: docker-default, user: 0/0/0
uid=0(root) gid=85(usb) groups=0(root),1(bin),2(daemon),3(sys),4(adm)
$ insject --help
insject 1.0
Jeff Dileo <[email protected]>
A tool to simplify container testing that runs an arbitrary
command in the Linux namespaces of other processes.
WARNING: Be careful when accessing or executing files in containers as they may
be able to abuse the access of the joined process to escape.
Note: The -! instrumentation mode has several differences from the LD_PRELOAD modes:
* Forking is not supported
* -S,--strict is not supported
* errno values are not returned
USAGE:
insject [FLAGS] [OPTIONS] [setns-opts]... [-- <cmd>...]
ARGS:
<setns-opts>... setns.so options. For detailed information, use --help-setns
<cmd>...
FLAGS:
-h, --help Prints help information
--help-setns Prints help information for setns.so
-V, --version Prints version information
OPTIONS:
-! <pid> PID to instrument
$ insject --help-setns
libsetns.so 1.0
Jeff Dileo <[email protected]>
An inject-/LD_PRELOAD-able shim to simplify container testing by joining an external program
run with it into the Linux namespaces of other processes.
WARNING: Be careful when accessing or executing files in containers as they may
be able to abuse the access of the joined process to escape.
USAGE:
libsetns.so [FLAGS] [OPTIONS] [target-pid]
ARGS:
<target-pid> PID to source namespaces from by default
FLAGS:
--help Prints help information
-A, --no-apparmor Skip setting AppArmor profile
-C, --no-cgroup Skip setting cgroup namespace
-F, --no-fork Skip fork after entering PID namespace, if entering PID namespace
-I, --no-ipc Skip setting IPC namespace
-M, --no-mnt Skip setting mount namespace
-N, --no-net Skip setting network namespace
-P, --no-pid Skip setting PID namespace
-T, --no-time Skip setting time namespace
-U, --no-userns Skip setting user namespace
-H, --no-uts Skip setting UTS (hostname) namespace
-S, --strict Exit if any namespace attach fails
-1, --userns-first Set user namespace before other namespaces
-V, --version Prints version information
OPTIONS:
-@, --raw-address <address> Raw memory address to hook instead of a symbol
Note: This is not an offset
-c, --cgroup <cgroup> Path to cgroup namespace to set
-i, --ipc <ipc> Path to IPC namespace to set
-m, --mnt <mnt> Path to mount namespace to set
-n, --net <net> Path to network namespace to set
-p, --pid <pid> Path to PID namespace to set
-a, --apparmor-profile <profile> Alternate AppArmor profile to set
-s, --symbol <symbol> Symbol to hook entry of instead of main
-t, --time <time> Path to time namespace to set
--user <user> <uid>[:<gid>[:<group,ids>]]) [default: 0:0:0]
-u, --userns <userns> Path to user namespace to set
-h, --uts <uts> Path to UTS (hostname) namespace to set
insject는 2-clause BSD 라이선스에 따라 라이선스가 부여됩니다.