Deepdive Containers - Kernel Sources and nsenter @LiveOverflow
Deepdive Containers - Kernel Sources and nsenter  @LiveOverflow
Uploaded February 2020 | Updated September 2026, 2 weeks ago
Let's play around with Docker a bit more. We learn how nsenter joins an existing container, why kernel code execution can escape namespace isolation, and how getpid() finds the correct process ID in the Linux kernel source.

LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-docker/how-containers-work
Join the Hextree Discord: discord.gg/xgQpCQCpvy

Daniel Mitre's blog: medium.com/@flag_seeker/linux-container-from-scratch-339c3ba0411d
bocker: github.com/p8952/bocker
Elixir: elixir.bootlin.com/linux/latest/source/kernel/sys.c#L891
Denis Andzakovic: pulsesecurity.co.nz/articles/docker-rootkits

CHAPTERS
00:00 - Learning containers through playful experiments
01:21 - Recreating Docker with C and system calls
01:49 - Bocker: Docker in 100 lines of Bash
03:24 - Using nsenter instead of docker exec
05:16 - Entering a container as root for debugging
06:27 - Privileged containers and kernel-level escapes
07:52 - Following getpid() through the Linux kernel source
08:48 - Resolving a PID for the current namespace
10:53 - How namespaces change kernel behavior

SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com

WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog

#LinuxSecurity #Docker #LiveOverflow

(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
Deepdive Containers - Kernel Sources and nsenterPentesting vs. Bug Bounty vs. Pentesting ???Solving Nintendo HireMe!!! with Basic MathDeveloping GDB Extension for Heap Exploitation | Ep. 12Hacking Google Cloud?The First Exploit  - Pwn2Own Documentary (Part 2)Why Pick sudo as Research Target? | Ep. 01Can AI Create a Minecraft Hack?Design Flaw in Security Product - ALLES! CTF 2021Log4j Vulnerability (Log4Shell) Explained // CVE-2021-44228Defusing a Bomb at Google London HQ - Having a Blast Google CTF Finals 2019 (hardware)Do you know this common Go vulnerability?
LiveOverflow |

Deepdive Containers - Kernel Sources and nsenter

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER