3 ms·
In what sense is this a “backdoor”? Seems to me the code is coming through the front door, which the victims left open. DockerHub is just the delivery mechani
by bboreham 8y ago
In what sense is this a “backdoor”? Seems to me the code is coming through the front door, which the victims left open.
DockerHub is just the delivery mechanism.
- imtringued 8y agoI'm scratching my head at where the /mnt mount is coming from. If you're doing "docker run -v /:/mnt <sketchy_username>/mysql" then absolutely nobody can help you.
- b6z 8y agoSame for me. From Kromtech's article I deduced that this only happens when a docker daemon (or kubernetes interface) is exposed to the Internet and an attacker uses that to download and start a docker image on the victim's host. Then they can bind mount a host directory like described and attack the host computer.