19.4% of the 1000 most popular Docker containers have an empty root password

Jerry Gamblin decided to investigate how widespread the recently discovered issue in Docker images of the Alpine distribution related to the specification of an empty password for the root user. An analysis of a thousand of the most popular containers from the Docker Hub catalog showed, that among 194 them (19.4%) a blank password is set for root without account locking ("root:::0:::::" instead of "root:!::0:::::").

In the case of using shadow and linux-pam packages in the container, the use of an empty root password , rather than taking focus. can escalate privileges within the container if there is unprivileged access to the container or after exploiting a vulnerability in an unprivileged service running in the container. It is also possible to connect to the container with root privileges if there is access to the infrastructure, i.e., the ability to connect via terminal to the TTY specified in the /etc/securetty list. SSH access with an empty password is blocked.

The most popular among containers with an empty root password include microsoft/azure-cli, kylemanna/openvpn, governmentpaas/s3-resource, phpmyadmin/phpmyadmin, mesosphere/aws-cli and hashicorp/terraform, which have over 10 million downloads. Additionally, the following containers are noted:
govuk/gemstash-alpine (500k), monsantoco/logstash (5 million),
avhost/docker-matrix-riot (1 million),
azuresdk/azure-cli-python (5 million)
and ciscocloud/haproxy-consul (1 million). Almost all of these containers are based on Alpine and do not use shadow and linux-pam packages. The only exception is microsoft/azure-cli, which is based on Debian.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster