Skip to content
KitploitKITPLOIT
工具漏洞利用博客
Log in
提交
工具漏洞利用博客
提交

黑客、渗透测试和网络安全工具,武装您的安全武器库!

Kitploit 是一个黑客、网络安全和渗透测试工具的目录。发现最新的项目更新,查找漏洞、分析系统、自动化测试并加强你的安全。

订阅源联系隐私© 2026 Kitploit

工具目录

分类

查看所有分类
Loading categories
Container_escape — Container escape proof-of-concept exploits for CVE-2026-80521 and CVE-2026-52910, with a disposable QEMU/Ubuntu VM harness for safe PoC execution. | Kitploit
工具/GitHubGitHub/markakd/container_escape
Container SecurityVulnerability AnalysisExploitationSecurity VirtualizationPenetration TestingPapers & ResearchContainer Escape
GitHubmarkakd/container_escape

Container_escape

Container escape proof-of-concept exploits for CVE-2026-80521 and CVE-2026-52910, with a disposable QEMU/Ubuntu VM harness for safe PoC execution.

查看仓库
4397215天前尚未审核

最受欢迎

查看全部 →

发现我们社区最常用的工具。

探索所有工具

浏览我们的工具集合

查看所有工具 →
分享
内容在请求的语言中不可用。显示英文版本。

Disposable Ubuntu container VM

This directory builds and runs an Ubuntu Docker container inside a disposable Ubuntu QEMU guest. PoCs are copied into the guest and are never executed by the host scripts.

Host dependencies

  • Bash
  • QEMU x86-64 and qemu-img
  • curl
  • OpenSSH client tools
  • xorriso
  • socat only when VM_PAYLOAD_CONSOLE=1 is used

KVM is used when available; otherwise QEMU falls back to TCG.

Build a golden image

UBUNTU_VERSION=26.04 \
VM_EXPECTED_KERNEL=7.0.0-31-generic \
./vm/build_image.sh

The builder downloads the selected Ubuntu release cloud image, validates it against Ubuntu's published SHA256SUMS, installs package updates and Docker, pulls the matching Ubuntu container image, and writes vm/ubuntu-<version>.qcow2.

The default URLs are pinned to the latest official release images available on September 16, 2026:

  • Ubuntu 24.04: release serial 20260911
  • Ubuntu 26.04: release serial 20260823

Set UBUNTU_RELEASE_URL, UBUNTU_IMAGE_URL, or UBUNTU_SUMS_URL to use another release.

The generated qcow2 image and SSH key are local artifacts ignored by Git. The private key remains mode 0600.

Run a binary

UBUNTU_VERSION=26.04 \
VM_EXPECTED_KERNEL=7.0.0-31-generic \
./vm/run_container.sh ./path/to/binary [arguments...]

Each run creates a temporary qcow2 overlay, boots the guest, copies the binary over SSH, and launches it in a fresh container with networking disabled. Arguments, standard streams, and the exit status are forwarded.

Run without a binary to open an interactive shell in a fresh container:

./vm/run_container.sh

Use --shell with a binary to copy it into the guest and mount it at /payload without executing it:

./vm/run_container.sh --shell ./path/to/binary

Useful overrides:

VM_CPUS=4 VM_MEMORY_MB=4096 ./vm/run_container.sh ./binary
VM_SSH_PORT=2223 ./vm/run_container.sh ./binary
KEEP_VM_RUN_DIR=1 ./vm/run_container.sh ./binary

KEEP_VM_RUN_DIR=1 retains the overlay and logs under /tmp/ubuntu-container.*. Each invocation performs one VM boot and one payload attempt. Set VM_PAYLOAD_CONSOLE=1 for a payload that explicitly uses the guest's second serial port.

下载工具