{"id":34141,"date":"2019-10-31T21:56:37","date_gmt":"2019-10-31T18:56:37","guid":{"rendered":"https:\/\/prohoster.info\/blog\/v-19-populyarnejshih-docker-obrazov-net-parolya-dlya-root\/"},"modified":"2019-10-31T21:56:37","modified_gmt":"2019-10-31T18:56:37","slug":"v-19-populyarnejshih-docker-obrazov-net-parolya-dlya-root","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/v-19-populyarnejshih-docker-obrazov-net-parolya-dlya-root","title":{"rendered":"19% of the most popular Docker images lack a password for root","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Last Saturday, May 18, Jerry Gamblin from Kenna Security <noindex><a rel=\"nofollow\" href=\"https:\/\/www.kennasecurity.com\/20-of-the-1000-most-popular-docker-containers-have-no-root-password\/\">reviewed<\/a><\/noindex> the 1000 most popular images from Docker Hub for the password used for the root user. In 19% of cases, it was found to be empty.<\/p>\n<p><img decoding=\"async\" alt=\"19% of the most popular Docker images lack a password for root\" src=\"\/wp-content\/uploads\/50d68e9378a116909318240ae1ca318a.png\" style=\"display:block;margin: 0 auto;\" \/><noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<h2>Background on Alpine<\/h2>\n<p>\nThe motivation for this mini-research was the Talos Vulnerability Report that appeared earlier this month (<noindex><a rel=\"nofollow\" href=\"https:\/\/talosintelligence.com\/vulnerability_reports\/TALOS-2019-0782\">TALOS-2019-0782<\/a><\/noindex>), authored by Peter Adkins from Cisco Umbrella, which reported that Docker images with the popular container distribution Alpine do not have a password for root:<\/p>\n<blockquote><p>\"Official versions of Docker images of Alpine Linux (starting from v3.3) contain a NULL password for the root user. This vulnerability emerged from a regression introduced in December 2015. The essence of the issue is that systems deployed with problematic versions of Alpine Linux in a container and using Linux PAM or another mechanism relying on the system's shadow file as the authentication database may accept a NULL password for the root user.\"<\/p><\/blockquote>\n<p>\nThe versions of Docker images with Alpine known to be problematic were from 3.3 to 3.9 inclusive, as well as the latest edge release.<\/p>\n<p>The authors provided the following recommendation for affected users:<\/p>\n<blockquote><p>\"The root account should be explicitly disabled in Docker images built on the problematic versions of Alpine. The likelihood of exploiting the vulnerability depends on the environment, as its success requires a service or application exposed externally that uses Linux PAM or another similar mechanism.\"<\/p><\/blockquote>\n<p>\nThe problem was <noindex><a rel=\"nofollow\" href=\"https:\/\/alpinelinux.org\/posts\/Docker-image-vulnerability-CVE-2019-5021.html\">has been closed<\/a><\/noindex> in Alpine versions 3.6.5, 3.7.3, 3.8.4, 3.9.2, and edge (20190228 snapshot), and users with affected images were advised to comment out the line with root in <code>\/etc\/shadow<\/code> or ensure the absence of the package <code>linux-pam<\/code>.<\/p>\n<h2>Continuation from Docker Hub<\/h2>\n<p>\nJerry Gamblin decided to find out how widespread the practice of using null passwords in containers might be. For this, he wrote a small <noindex><a rel=\"nofollow\" href=\"https:\/\/gist.github.com\/jgamblin\/fd94d9078709fe68d13f36f82c29fdab\">Bash script<\/a><\/noindex>, the essence of which is quite simple:<\/p>\n<ul>\n<li> a curl request to the Docker Hub API retrieves a list of hosted Docker images;<\/li>\n<li> it is sorted by the field <code>popularity<\/code>, and from the results, the top thousand is selected;<\/li>\n<li> for each of them, a <code>docker pull<\/code>;<\/li>\n<li> for each retrieved Docker image from Docker Hub, the <code>docker run<\/code> is executed by reading the first line of the file; <code>\/etc\/shadow<\/code>;<\/li>\n<li> if the value of the line turns out to be <code>root:::0:::::<\/code>, the name of the image is saved to a separate file.<\/li>\n<\/ul>\n<p>\nWhat did he find? In <noindex><a rel=\"nofollow\" href=\"https:\/\/gist.github.com\/jgamblin\/6015a2020c1de3bc3aab19b361573b7f\">this file<\/a><\/noindex> There were 194 entries with names of popular Docker images with Linux systems where the root user does not have a set password:<\/p>\n<blockquote><p>\"Among the most well-known names on this list are govuk\/governmentpaas, hashicorp, microsoft, monsanto, and mesosphere. Meanwhile, kylemanna\/openvpn is the most popular container on the list, boasting over 10 million pulls.\"<\/p><\/blockquote>\n<p>\nHowever, it is important to note that this phenomenon does not in itself indicate a direct vulnerability in the security of the systems that use them: it all depends on how exactly they are applied. <i>(see the comment from the Alpine case above)<\/i>. Yet the 'moral of the story' has been seen many times before: apparent simplicity often has a downside that must always be remembered and whose consequences must be considered in technology deployment scenarios.<\/p>\n<h2>P.S.<\/h2>\n<p>\nAlso read in our blog:<\/p>\n<ul>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/337448\/\">Statistics on base operating systems in images on Docker Hub<\/a><\/noindex>\u00bb;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/440504\/\">Note: The topic of Docker security is perhaps one of the eternal issues in the modern IT world. Therefore, without further ado, we present the translation of another collection of relevant recommendations.<\/a><\/noindex>\u00bb;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/439964\/\">Vulnerability CVE-2019-5736 in runc, allowing root privileges on the host<\/a><\/noindex>\u00bb;<\/li>\n<li> \u00ab<noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/337154\/\">Vulnerable Docker VM \u2014 a puzzle VM about Docker and pentesting<\/a><\/noindex>\u00bb.<\/li>\n<\/ul>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/flant\/blog\/452754\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u043c\u0438\u043d\u0443\u0432\u0448\u0443\u044e \u0441\u0443\u0431\u0431\u043e\u0442\u0443, 18 \u043c\u0430\u044f, Jerry Gamblin \u0438\u0437 Kenna Security \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u043b 1000 \u0441\u0430\u043c\u044b\u0445 \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u044b\u0445 \u043e\u0431\u0440\u0430\u0437\u043e\u0432 \u0441 Docker Hub \u043d\u0430 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u0435\u043c\u044b\u0439 \u0432 \u043d\u0438\u0445 \u043f\u0430\u0440\u043e\u043b\u044c \u0434\u043b\u044f \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f root. \u0412 19% \u0441\u043b\u0443\u0447\u0430\u0435\u0432 \u043e\u043d \u043e\u043a\u0430\u0437\u0430\u043b\u0441\u044f \u043f\u0443\u0441\u0442\u044b\u043c. \u041f\u0440\u0435\u0434\u044b\u0441\u0442\u043e\u0440\u0438\u044f \u0441 Alpine \u041f\u043e\u0432\u043e\u0434\u043e\u043c \u0434\u043b\u044f \u043f\u0440\u043e\u0432\u0435\u0434\u0451\u043d\u043d\u043e\u0433\u043e \u043c\u0438\u043d\u0438-\u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u043d\u0438\u044f \u0441\u0442\u0430\u043b \u043f\u043e\u044f\u0432\u0438\u0432\u0448\u0438\u0439\u0441\u044f \u0440\u0430\u043d\u0435\u0435 \u0432 \u044d\u0442\u043e\u043c \u043c\u0435\u0441\u044f\u0446\u0435 Talos Vulnerability Report (TALOS-2019-0782), \u0430\u0432\u0442\u043e\u0440\u044b \u043a\u043e\u0442\u043e\u0440\u043e\u0433\u043e \u2014 \u0431\u043b\u0430\u0433\u043e\u0434\u0430\u0440\u044f \u043d\u0430\u0445\u043e\u0434\u043a\u0435 Peter [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-34141","post","type-post","status-publish","format-standard","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u043c\u0438\u043d\u0443\u0432\u0448\u0443\u044e \u0441\u0443\u0431\u0431\u043e\u0442\u0443, 18 \u043c\u0430\u044f, Jerry Gamblin \u0438\u0437 Kenna Security \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u043b.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/v-19-populyarnejshih-docker-obrazov-net-parolya-dlya-root\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0412 19% \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u0435\u0439\u0448\u0438\u0445 Docker-\u043e\u0431\u0440\u0430\u0437\u043e\u0432 \u043d\u0435\u0442 \u043f\u0430\u0440\u043e\u043b\u044f \u0434\u043b\u044f root | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u043c\u0438\u043d\u0443\u0432\u0448\u0443\u044e \u0441\u0443\u0431\u0431\u043e\u0442\u0443, 18 \u043c\u0430\u044f, Jerry Gamblin \u0438\u0437 Kenna Security \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u043b.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/v-19-populyarnejshih-docker-obrazov-net-parolya-dlya-root\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:56:37+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:56:37+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd4719% of the most popular Docker images do not have a password for root | ProHoster","description":"Last Saturday, May 18, Jerry Gamblin from Kenna Security checked.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/v-19-populyarnejshih-docker-obrazov-net-parolya-dlya-root","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0412 19% \u043f\u043e\u043f\u0443\u043b\u044f\u0440\u043d\u0435\u0439\u0448\u0438\u0445 Docker-\u043e\u0431\u0440\u0430\u0437\u043e\u0432 \u043d\u0435\u0442 \u043f\u0430\u0440\u043e\u043b\u044f \u0434\u043b\u044f root | ProHoster","og:description":"\u0412 \u043c\u0438\u043d\u0443\u0432\u0448\u0443\u044e \u0441\u0443\u0431\u0431\u043e\u0442\u0443, 18 \u043c\u0430\u044f, Jerry Gamblin \u0438\u0437 Kenna Security \u043f\u0440\u043e\u0432\u0435\u0440\u0438\u043b.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/v-19-populyarnejshih-docker-obrazov-net-parolya-dlya-root","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:56:37+00:00","article:modified_time":"2019-10-31T18:56:37+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"34141","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 18:05:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 23:13:00","updated":"2026-01-21 18:05:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/34141","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=34141"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/34141\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=34141"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=34141"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=34141"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}