Phantom Track

Level 23 → Level 24

Docker API
ACT IV960 pts+50 first-blood bonus
First Blood: @galile0

Mission

Attack the unauthenticated Docker API on TCP :2375 — POST a container-create payload that bind-mounts the host and reads the flag from the returned logs.

Why this matters in 2026

Unauthenticated :2375 still turns up on cloud perimeters and internal networks. Engine-API fluency is the required skill.

Mitigation era: 2026-04 · rotation policy: levels may be refreshed as CVEs are patched out of distro defaults.

Connection Terminal

Use the password for phantom23 that you captured on the previous level, then:
ssh [email protected] -p 2223
SSH command copied to clipboard!

Flag Submission

Log in to submit flags and track progress.
🩸
First Blood captured by
ACTIVE RECORD