<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Docker Exec on WE ARE THE BUG</title><link>https://wearethebug.dev/tags/docker-exec/</link><description>Recent content on WE ARE THE BUG</description><generator>Tradecraft</generator><language>en-us</language><lastBuildDate>Sun, 23 Jan 2022 00:00:00 +0000</lastBuildDate><atom:link href="https://wearethebug.dev/tags/docker-exec/index.xml" rel="self" type="application/rss+xml"/><item><title>VULNLAB: Data</title><link>https://wearethebug.dev/posts/vl-data/</link><pubDate>Sun, 23 Jan 2022 00:00:00 +0000</pubDate><guid>https://wearethebug.dev/posts/vl-data/</guid><description>Data is an Easy Linux machine that involves exploiting CVE-2021-43798, an arbitrary file read via path traversal in Grafana. By exploiting this vulnerability, the database file for Grafana is extracted, and the hashes in the database are converted to a format readable by Hashcat. The hash is then cracked and can be used for SSH access to the target as user boris. The compromised user has the privileges to execute docker exec as root on the system, allowing the user to escalate and obtain root access by adding the privileged flag to running containers and mounting the host filesystem.</description></item></channel></rss>