CoCalc provides the best real-time collaborative environment for Jupyter Notebooks, LaTeX documents, and SageMath, scalable from individual users to large groups and classes!
CoCalc provides the best real-time collaborative environment for Jupyter Notebooks, LaTeX documents, and SageMath, scalable from individual users to large groups and classes!
Path: blob/master/documentation/modules/post/linux/gather/checkcontainer.md
Views: 1904
Indicators
There are several indicators that a process is being executed inside of a container. This module looks for the following indicators:
Presence of
/.dockerenv
file indicates Docker.Finding select strings in
/proc/1/cgroup
indicates LXC or Docker.The value of the
container
environment variable in/proc/1/environ
indicates LXC or systemd nspawn.
Verification Steps
Start msfconsole
Get a session via exploit of your choice
run post/linux/gather/checkcontainer
You should get feedback if a container was detected
Options
SESSION
Which session to use, which can be viewed with sessions -l
Scenarios
Check if the jenkins instance you have a shell on is running inside a Docker container.
Detect a LXC container
Detect a systemd nspawn container
Detect nothing