3 ms·
Curious about the container capabilities that enabled them to attack the host network: per the docs [1] containers do not get `CAP_NET_ADMIN` by default, but th
by terom 6y ago
Curious about the container capabilities that enabled them to attack the host network: per the docs [1] containers do not get `CAP_NET_ADMIN` by default, but they do get `CAP_NET_RAW`. I assume that's what allowed them to inspect/inject and network traffic and thus spoof the HTTP response.
So `docker run --net=host --cap-drop=NET_RAW` seems like it might be a good idea. I wonder if it's still needed for `ping` and such in modern Linux?
[1] https://docs.docker.com/engine/reference/run/#runtime-privilege-and-linux-capabilities https://docs.docker.com/engine/reference/run/#runtime-privil...
- justincormack 6y agoMostly its not needed for ping but the config is not yet great in all distros, I talked about this in https://docker.events.cube365.net/docker/dockercon/content/Videos/5xr3jskfFKk5jm6pL https://docker.events.cube365.net/docker/dockercon/content/V...