{"id":34748,"date":"2019-10-31T22:00:11","date_gmt":"2019-10-31T19:00:11","guid":{"rendered":"https:\/\/prohoster.info\/blog\/uyazvimost-v-docker-pozvolyayushhaya-vybratsya-iz-kontejnera\/"},"modified":"2019-10-31T22:00:11","modified_gmt":"2019-10-31T19:00:11","slug":"uyazvimost-v-docker-pozvolyayushhaya-vybratsya-iz-kontejnera","status":"publish","type":"post","link":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-docker-pozvolyayushhaya-vybratsya-iz-kontejnera","title":{"rendered":"O vulnerabilitate \u00een Docker, care permite ie\u0219irea din container","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00cen instrumentele de gestionare a containerelor Linux izolate Docker <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/05\/28\/1\">a fost identificat\u0103<\/a><\/noindex> vulnerabilitate (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2018-15664\">CVE-2018-15664<\/a><\/noindex>), care, \u00een anumite circumstan\u021be, permite accesul la mediu-hosta din container, \u00een cazul \u00een care se pot rula imagini proprii \u00een sistem sau exist\u0103 acces la containerul executabil. Problema se manifest\u0103 \u00een toate versiunile Docker \u0219i r\u0103m\u00e2ne nerezolvat\u0103 (provizii pentru un patch au fost oferite, dar nu au fost \u00eenc\u0103 acceptate <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/moby\/moby\/pull\/39252\">patch<\/a><\/noindex>, care implementeaz\u0103 suspendarea func\u021bion\u0103rii containerului \u00een timpul opera\u021biunilor cu sistemul de fi\u0219iere).<\/p>\n<p>Vulnerabilitatea permite extragerea fi\u0219ierelor din container \u00een orice parte a sistemului de fi\u0219iere al gazdei prin executarea comenzii \u201edocker cp\u201d. Extragerea fi\u0219ierelor se face cu privilegii root, ceea ce permite citirea sau scrierea oric\u0103ror fi\u0219iere \u00een mediu, suficient pentru a ob\u021bine controlul asupra sistemului gazd\u0103 (de exemplu, se poate rescrie \/etc\/shadow). <\/p>\n<p>Atacul poate fi efectuat doar \u00een momentul \u00een care administratorul execut\u0103 comanda \u201edocker cp\u201d pentru a copia fi\u0219iere \u00een container sau din acesta. Astfel, atacatorul trebuie s\u0103 conving\u0103 pe somehow administratorul Docker de necesitatea de a efectua aceast\u0103 opera\u021biune \u0219i s\u0103 anticipeze calea folosit\u0103 la copiere. Pe de alt\u0103 parte, atacul poate fi realizat, de exemplu, c\u00e2nd serviciile de cloud ofer\u0103 instrumente pentru copierea fi\u0219ierelor de configurare \u00een container, construite cu ajutorul comenzii \u201edocker cp\u201d.<\/p>\n<p>Problema este cauzat\u0103 de o lipse de implementare \u00een utilizarea func\u021biei <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/moby\/moby\/blob\/master\/pkg\/symlink\/fs.go#L19\">FollowSymlinkInScope<\/a><\/noindex>, calcul\u00e2nd calea absolut\u0103 \u00een sistemul de fi\u0219iere principal pe baza c\u0103ii relative, care \u021bine cont de amplasarea containerului. \u00cen timpul execut\u0103rii comenzii \u201edocker cp\u201d apare o scurt\u0103 \u00eentrerupere <noindex><a rel=\"nofollow\" href=\"https:\/\/ru.wikipedia.org\/wiki\/%D0%A1%D0%BE%D1%81%D1%82%D0%BE%D1%8F%D0%BD%D0%B8%D0%B5_%D0%B3%D0%BE%D0%BD%D0%BA%D0%B8\">condi\u021bie de curs\u0103<\/a><\/noindex>, \u00een care calea este deja verificat\u0103, dar opera\u021bia nu a fost \u00eenc\u0103 executat\u0103. Deoarece copierea se face \u00een contextul sistemului de fi\u0219iere principal al sistemului gazd\u0103, \u00een intervalul respectiv de timp se poate \u00eenlocui linkul cu o alt\u0103 cale \u0219i ini\u021bia copia de date \u00eentr-un loc arbitrar din sistemul de fi\u0219iere din afara containerului.<\/p>\n<p>\u00centruc\u00e2t fereastra temporar\u0103 de apari\u021bie a st\u0103rii de curs\u0103 este foarte limitat\u0103 \u00een prototipul preg\u0103tit <noindex><a rel=\"nofollow\" href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2019\/05\/28\/1\/1\">expoitului<\/a><\/noindex> \u00een timpul opera\u021biunilor de copiere din container, a fost reu\u0219it un atac de succes \u00een mai pu\u021bin de 1% din cazuri prin \u00eenlocuirea ciclic\u0103 a linkului simbologic din calea utilizat\u0103 \u00een opera\u021bia de copiere (atacul reu\u0219it a fost efectuat dup\u0103 aproximativ 10 secunde de \u00eencerc\u0103ri continue de a copia fi\u0219ierul cu comanda \u201edocker cp\u201d).<\/p>\n<p>La executarea opera\u021biunii de copiere \u00een container se poate ob\u021bine un atac repetitiv prin rescrierea fi\u0219ierului \u00een sistemul gazd\u0103 \u00een doar c\u00e2teva itera\u021bii. Posibilitatea atacului este asociat\u0103 cu faptul c\u0103, atunci c\u00e2nd se copiaz\u0103 \u00een container, se aplic\u0103 conceptul \u201echrootarchive\u201d, conform c\u0103ruia procesul archive.go extrage arhiva nu \u00een r\u0103d\u0103cina chroot a containerului, ci \u00een r\u0103d\u0103cina chroot a directorului-parent al c\u0103ii \u021bint\u0103, sub controlul atacatorului \u0219i nu opre\u0219te execu\u021bia containerului (chroot este folosit ca indicator pentru exploatarea unei st\u0103ri de competi\u021bie).<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Sursa: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50765\">opennet.ro<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0438 \u0434\u043b\u044f \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c\u0438 Linux-\u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430\u043c\u0438 Docker \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (CVE-2018-15664), \u043a\u043e\u0442\u043e\u0440\u0430\u044f \u043f\u0440\u0438 \u043e\u043f\u0440\u0435\u0434\u0435\u043b\u0451\u043d\u043d\u043e\u043c \u0441\u0442\u0435\u0447\u0435\u043d\u0438\u0438 \u043e\u0431\u0441\u0442\u043e\u044f\u0442\u0435\u043b\u044c\u0441\u0442\u0432 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u043a \u0445\u043e\u0441\u0442-\u043e\u043a\u0440\u0443\u0436\u0435\u043d\u0438\u044e \u0438\u0437 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430 \u043f\u0440\u0438 \u043d\u0430\u043b\u0438\u0447\u0438\u0438 \u0432\u043e\u0437\u043c\u043e\u0436\u043d\u043e\u0441\u0442\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0430 \u0441\u0432\u043e\u0438\u0445 \u043e\u0431\u0440\u0430\u0437\u043e\u0432 \u0432 \u0441\u0438\u0441\u0442\u0435\u043c\u0435 \u0438\u043b\u0438 \u043f\u0440\u0438 \u0434\u043e\u0441\u0442\u0443\u043f\u0435 \u043a \u0432\u044b\u043f\u043e\u043b\u043d\u044f\u0435\u043c\u043e\u043c\u0443 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0443. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0432\u043e \u0432\u0441\u0435\u0445 \u0432\u0435\u0440\u0441\u0438\u044f\u0445 Docker \u0438 \u043e\u0441\u0442\u0430\u0451\u0442\u0441\u044f \u043d\u0435\u0438\u0441\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u043d\u043e\u0439 (\u043f\u0440\u0435\u0434\u043b\u043e\u0436\u0435\u043d, \u043d\u043e \u043f\u043e\u043a\u0430 \u043d\u0435 \u043f\u0440\u0438\u043d\u044f\u0442, \u043f\u0430\u0442\u0447, \u0440\u0435\u0430\u043b\u0438\u0437\u0443\u044e\u0449\u0438\u0439 \u043f\u0440\u0438\u043e\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 \u0440\u0430\u0431\u043e\u0442\u044b \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-34748","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0438 \u0434\u043b\u044f \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c\u0438 Linux-\u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430\u043c\u0438 Docker \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-docker-pozvolyayushhaya-vybratsya-iz-kontejnera\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"ro_RO\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Docker, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0431\u0440\u0430\u0442\u044c\u0441\u044f \u0438\u0437 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0438 \u0434\u043b\u044f \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c\u0438 Linux-\u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430\u043c\u0438 Docker \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-docker-pozvolyayushhaya-vybratsya-iz-kontejnera\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:00:11+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:00:11+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerabilitate \u00een Docker care permite p\u0103r\u0103sirea containerului | ProHoster","description":"\u00cen instrumentele pentru gestionarea containerelor Linux izolate Docker a fost identificat\u0103 o vulnerabilitate (","canonical_url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-docker-pozvolyayushhaya-vybratsya-iz-kontejnera","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"ro_RO","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 Docker, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0432\u044b\u0431\u0440\u0430\u0442\u044c\u0441\u044f \u0438\u0437 \u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430 | ProHoster","og:description":"\u0412 \u0438\u043d\u0441\u0442\u0440\u0443\u043c\u0435\u043d\u0442\u0430\u0440\u0438\u0438 \u0434\u043b\u044f \u0443\u043f\u0440\u0430\u0432\u043b\u0435\u043d\u0438\u044f \u0438\u0437\u043e\u043b\u0438\u0440\u043e\u0432\u0430\u043d\u043d\u044b\u043c\u0438 Linux-\u043a\u043e\u043d\u0442\u0435\u0439\u043d\u0435\u0440\u0430\u043c\u0438 Docker \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c (","og:url":"https:\/\/prohoster.info\/ro\/blog\/news\/uyazvimost-v-docker-pozvolyayushhaya-vybratsya-iz-kontejnera","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:00:11+00:00","article:modified_time":"2019-10-31T19:00:11+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"34748","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 20:28:56","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:15:38","updated":"2026-01-21 20:28:56","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/34748","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/comments?post=34748"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/posts\/34748\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/media?parent=34748"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/categories?post=34748"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/ro\/wp-json\/wp\/v2\/tags?post=34748"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}