4 ms·
On every distro in the past, i’d do sudo passwd. Always worked. No idea about Alpine.
by code_duck 7y ago
On every distro in the past, i’d do sudo passwd. Always worked. No idea about Alpine.
- matthewbauer 7y agoBut sudo access requires you to have logged in through a user in the wheel group. That at least is not a vulnerability.
- code_duck 7y agoOK. In my experience it worked with any user account. I would install, create an account, and immediately use sudo to change the root password.
- TheDong 7y agoThe first user account is considered an administrator account on most distros by default, so it has sudo privileges. If you can do what you said with a non-wheel/sudo account, that would be a serious vulnerability.
- ShinTakuya 7y agoAlternatively, it's possible the distro added the first user account to wheel also. I believe I've seen that in the past.
- Godel_unicode 7y agoHow do you think that's different than the comment to which you replied?
- code_duck 7y agoI see, thanks. I posted hoping people would inform me about this.
- zaarn 7y agoAlpine comes with no suid binaries in Docker to my knowledge (it's expected you run your stuff as root inside the container unless there is a reason not to)
- arghwhat 7y agoJust for the uninitiated: suid binaries are binaries with a special flag set that will make it run with root privileges regardless of who started it. sudo is an example of something that would use suid. When a user runs sudo, the binary actually runs with root privileges from the get-go, checks if the user is OK, then executes the command you specified. However, use of sudo or other suid binaries is entirely pointless in an alpine container. There being no password also does not matter, as you are by default already running everything as root. Who cares if root can become root?
- zaarn 7y agoWell in theory someone could escalate their privileges to the exact same ones they already have! THAT'S TERRIBLE!
- javagram 7y ago> There being no password also does not matter, as you are by default already running everything as root. Who cares if root can become root? Best practice would have you switch to a non root user before running whatever it is inside the container. Although if you haven’t added any suid binaries by accident then there’s no way to go back. E.g. the node alpine image adds a “node:node” user and group for the process to run as instead of root. https://github.com/nodejs/docker-node/blob/master/10/alpine/Dockerfile https://github.com/nodejs/docker-node/blob/master/10/alpine/...
- code_duck 7y agoOK, so what’s the entire point of this article then?