17 Backdoored Images Downloaded 5 Million Times Removed From Docker Hub (bleepingcomputer.com)
An anonymous reader writes: "The Docker team has pulled 17 Docker container images that have been backdoored and used to install reverse shells and cryptocurrency miners on users' servers for the past year," reports Bleeping Computer. "The malicious Docker container images have been uploaded on Docker Hub, the official repository of ready-made Docker images that sysadmins can pull and use on their servers, work, or personal computers." The images, downloaded over 5 million times, helped crooks mine Monero worth over $90,000 at today's exchange rate. Docker Hub is now just the latest package repository to feature backdoored libraries, after npm and PyPl. Docker Hub is now facing criticism for taking months to intervene after user reports, and then going on stage at a developer conference and claiming they care about security.
I have always been too picky to trust peoples images, if theres something I want to use I will build it myself and store it on my private docker repo. Building your business on something anyone can just upload or change seems dangerous. I started to wonder if extra work really made sense, apparently yes.
I read that there are images, some backdoors, downloaded gorillion times... and I was ready with the lube next to me... ...but apparently, images can mean .iso files.
Damn it.
All 17 images were uploaded on the Docker Hub portal by the same person/group, using the pseudonym of "docker123321."
WHO THE FUCK pulls an image called docker123321/tomcat22 ?
So you are saying that when the image is run under Docker, it can write to the host filesystem, open ports, etc.. Isn't it sandboxed?
I am not sure how one can claim to care about security without a secure sandbox.
The real "Libtards" are the Libertarians!
They didn't. Nobody wanted to use your malware.
You're suppose to run the entire docker system in a VM. As for mainframes, yes containers run on them as well.
https://containerjournal.com/2017/07/24/ibm-makes-case-mainframes-container-platforms/
Docker folks can care about security and , you know, not have infinite resources to look into every claim of a bad image ... It's like YouTube cares about copyright but maybe doesn't take a video down the moment you ask them to. And for security it's harder because they would need to check that the images actually are bad... and the reputation of the person submitting the report. Or else they are facilitating a denial of service attack against some innocent account.
It would be different if the malware was in the ubuntu:latest or some other official image. But it was in some personal account ... The people who downloaded those images are idiots. I don't blame Docker at all for not handling it the minute it was reported.
As long as I don't have to sit there and install gcc and all that other crap just to get a web server running, docker is fine with me! I trust the internet!
Democrat funded forum disruption trolls sure do hate homosexuals.
Indeed, even Hitler agrees with that
CLI paste? paste.pr0.tips!
Since a lot of NAS have virtualization services, I'd say a Docker curated store would be in everyone's best interest.
See subject & via APK Hosts File Engine 2.0++ 64-bit for Linux h t t p : / / a p k . i t - m a t e . c o . u k / A P K H o s t s F i l e E n g i n e F o r L i n u x . z i p (remove spaces between characters & download).
For more security/speed/reliability/anonymity vs. any SINGLE solution (99% of threats = hostnames vs. IP address (that most firewalls use)) more efficiently/FASTER + NATIVELY 4 less!
(Vs. "Bolt on 'MoAr' illogic-logic" competitors slowing you, hosts speed you up 2 ways (adblocks + hardcodes u spend most time @) vs. competition loaded w/ bugs (DNS/AntiVir) + their overheads (messagepass ('souled-out' to advertiser addons) + filtering drivers) & their complexity leads to exploit).
* See subject & "Windows hosts trick to block the Coinhive or Crypto-Loot domains" - https://www.bleepingcomputer.com/news/security/a-new-player-joins-coinhive-on-the-browser-cryptojacking-scene/ - BLEEPING COMPUTER
APK
P.S.=> It's better vs. the Windows model... apk
Your software is just fine - well written, functional... I'm going to continue using the Host File Engine by mmell February 17, 2017
(APK's work), I've flat out said it's good by BronsCon February 11 2016
his hosts program is actually pretty good by xenotransplant August 10 2015
his hosts tool is actually useful for those cases in which one does indeed want to locally block stuff outright while consuming minimum system resources by alexgieg September 25 2015
I like your host file system by Karmashock September 09 2015
I do use APK's host file on all my systems at home by OrangeTide December 01 2017
I personally use a HOSTS file blocker produced from a genius called APK by 110010001000 October 27 2017
* See subject: Best part is this Linux 64-bit model is faster & more efficient (does 2x the work in 1/2 the time, literally)
APK
P.S.=> Enjoy a faster/safer/more reliable internet... apk