U-19.4% weziqukathi ze-Docker eziphezulu ezingu-1000 ziqukethe iphasiwedi yempande engenalutho

UJerry Gamblin wanquma ukuthola ukuthi basakazeke kangakanani abasanda kutholakala inkinga ezithombeni ze-Docker zokusabalalisa kwe-Alpine, okuhlotshaniswa nokucacisa iphasiwedi engenalutho yomsebenzisi oyimpande. Ukuhlaziywa kwezinkulungwane zeziqukathi ezidume kakhulu kusukela kukhathalogi ye-Docker Hub kukhonjisiwe, yini ku 194 kulokhu (19.4%) iphasiwedi engenalutho isethelwe impande ngaphandle kokukhiya i-akhawunti (β€œimpande:::0:::::” esikhundleni sokuthi β€œimpande:!::0::::”).

Uma isiqukathi sisebenzisa isithunzi namaphakheji e-linux-pam, sebenzisa iphasiwedi engenalutho yempande kuvumela khulisa amalungelo akho ngaphakathi kwesiqukathi uma ufinyelela ngokungemthetho esitsheni noma ngemva kokusebenzisa ubungozi enkonzweni engenamalungelo esebenza esitsheni. Ungakwazi futhi ukuxhuma esitsheni esinamalungelo ezimpande uma ukwazi ukufinyelela kungqalasizinda, i.e. ikhono lokuxhuma nge-terminal ku-TTY eshiwo kuhlu lwe-/etc/securetty. Ukungena ngemvume ngephasiwedi engenalutho kuvinjelwe nge-SSH.

Okudume kakhulu phakathi iziqukathi ezine-password yempande engenalutho kukhona microsoft/azure-cli, kylemanna/openvpn, uhulumenipaas/s3-insiza, phpmyadmin/phpmyadmin, mesosphere/aws-cli ΠΈ i-hashicorp/terraform, ezinokulandwa okungaphezulu kwezigidi eziyi-10. Iziqukathi nazo ziyagqanyiswa
govuk/gemstash-alpine (izinkulungwane ezingama-500), monsantoco/logstash (5 amamilimitha),
i-avhost/docker-matrix-riot (1 amamilimitha),
i-azuresdk/azure-cli-python (izigidi ezingu-5)
ΠΈ ciscocloud/haproxy-consul (1 million). Cishe zonke lezi ziqukathi zisekelwe ku-Alpine futhi azisebenzisi amaphakheji ethunzi kanye ne-linux-pam. Okuwukuphela kwento ehlukile yi-microsoft/azure-cli esekelwe ku-Debian.

Source: opennet.ru

Engeza amazwana