Description
Utilizing the DCOS Cluster's Marathon UI, an attacker can create a docker container with the '/' path mounted with read/write permissions on the host server that is running the docker container. As the docker container executes command as uid 0 it is honored by the host operating system allowing the attacker to edit/create files owed by root. This exploit abuses this to creates a cron job in the '/etc/cron.d/' path of the host server.
*Notes: The docker image must be a valid docker image from hub.docker.com. Furthermore the docker container will only deploy if there are resources available in the DC/OS cluster.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/http/dcos/marathonmsf undefined(marathon) > show actions ...actions...msf undefined(marathon) > set ACTION < action-name >msf undefined(marathon) > show options ...show and set options...msf undefined(marathon) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub