BSides Bristol 2024

9001 ways to break out of a container
, Track 1

Discover 9001 insane ways to break out of a container! from bypassing eBPF validation to privilege escalation, this talk is covers a variety of different attack vectors aimed at breaking free from the container.


Container security is essential, but what happens when the bad guys get creative? In ""9001 ways to break out of a container,"" we’ll explore the fascinating and terrifying techniques hackers use to escape containers. this talk will cover:

  • Learn how attackers slip through the cracks to take over the Linux kernel by bypassing the eBPF validator
  • Understand why ""you want stars in the sky, not in your rbac.""
  • See the most common and overlooked weaknesses that make containers vulnerable.
  • Hear about real-world cases of container escapes and the aftermath.

Whether you’re a seasoned security professional or just curious about hacking techniques, this talk should have takeaways for everyone!

From a young age, technology captured Josie’s imagination, leading her on a self-taught journey into coding, Linux system experimentation, and open-source contributions. With over seven years of professional experience, Josie has enriched enterprises, SMEs, and startups. Her roles have spanned platform engineering, DevOps, Site Reliability Engineering, and technology management. Currently, Josie is a Cloud Native Consultant at Red Hat where she helps customers with Infrastructure and Security topics.

josie@redhat.com
https://github.com/pfeifferj
https://josie.lol