Contain Me If You Can CTF: Container Escape via a Plaintext Postgres Connection
14 min read
Wiz Cloud Security Championship #2 writeup: sniff a plaintext PostgreSQL credential with tcpdump, get superuser RCE via COPY FROM PROGRAM, abuse passwordless sudo, and mount the host block device to read /flag.
Read more...
Mark LaCore