4 ms·
Exactly, many of these reports are of the kind "your java Web app container has a priv esc vuln in sudo" which is irrelevant 95% of the time. Need some smart to
by Quiark 6y ago
Exactly, many of these reports are of the kind "your java Web app container has a priv esc vuln in sudo" which is irrelevant 95% of the time. Need some smart tooling to help comb through all that noise.
- ktpsns 6y agoI don't second that. If the java web app also has some privilege escalation, this allows somebody to overtake not only the container as root, but, given how Docker works, also to overtake the docker host as root! Security matters, even if it is apparently about unused parts in a complex system.
- znpy 6y ago> if the java web app also has some privilege escalation If.
- ktpsns 6y agoOf course "if": That's how security works. The most trivial mistakes are still made in 2020, such as SQL injections. Many people write horribly insecure code, because they were never trained on a security-oriented focus. Story Time: At a customer I've once seen all (web) applications in their docker containerr running with root permissions. I raised an issue but the devops told me this would be fine. They simply did not care about security. They run all their containers on two rented VPS. They dockerized everything, also their mail infrastructure, etc.. This means: If anybody found the easiest remote code execution bug in their webpages, they immediately could take over the whole fucking company. Because root in docker = root on the whole machine. Think about that twice.