19.4% ea lijana tse holimo tsa 1000 tsa Docker li na le phasewete e se nang letho

Jerry Gamblin o ile a etsa qeto ea ho fumana hore na ba sa tsoa tsebahatsoa ba atile hakae bothata litšoantšong tsa Docker tsa kabo ea Alpine, e amanang le ho hlakisa senotlolo se se nang letho bakeng sa mosebelisi oa motso. Tlhahlobo ea likete tsa lijana tse tsebahalang haholo ho tsoa lethathamong la Docker Hub bontšitse, eng ka 194 ho tsena (19.4%) phasewete e se nang letho e behilwe bakeng sa motso ntle le ho notlela akhaonto (“root:::0:::::” sebakeng sa “root:!::0::::”).

Haeba setshelo se sebelisa liphutheloana tsa moriti le linux-pam, sebelisa senotlolo se se nang letho e lumella eketsa litokelo tsa hau ka har'a sets'oants'o haeba u na le phihlello e sa lokang ea sets'oants'o kapa kamora ho sebelisa hampe ts'ebeletso e se nang tokelo e sebetsang ka har'a setshelo. U ka boela ua hokahanya le setshelo se nang le litokelo tsa motso haeba u na le mokhoa oa ho fumana lisebelisoa, ke hore. bokhoni ba ho hokela ka terminal ho TTY e boletsoeng lethathamong la /etc/securetty. Ho kena ka password e se nang letho ho koetsoe ka SSH.

E tsebahalang haholo har'a lijana tse nang le password ea motso e se nang letho ke microsoft/azure-cli, kylemanna/openvpn, governmentpaas/s3-resource, phpmyadmin/phpmyadmin, mesosphere/aws-cli и hashicorp/terraform, e nang le download e fetang limilione tse 10. Lijana le tsona li totobalitsoe
govuk/gemstash-alpine (likete tse 500), monsantoco/logstash (limilione tse 5),
avhost/docker-matrix-riot (limilione tse 1),
azuresdk/azure-cli-python (limilione tse 5)
и ciscocloud/haproxy-consul (1 milione). Hoo e ka bang lijana tsena kaofela li thehiloe ho Alpine 'me ha li sebelise liphutheloana tsa moriti le linux-pam. Mokhelo feela ke microsoft/azure-cli e thehiloeng ho Debian.

Source: opennet.ru

Eketsa ka tlhaloso