Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
uvuv
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
CosmosEscape: Taking over Every Database in Azure Cosmos DB
(wiz.io)
74 points
by
uvuv
2mo ago
|
17 comments
2.
▲
by
uvuv
2mo ago
A critical vulnerability chain in Azure Cosmos DB enabled full read and write access to every Cosmos DB database.
3.
▲
Supply Chain Vuln Compromised Core AWS GitHub Repos & Threatened the AWS Console
(wiz.io)
160 points
by
uvuv
9mo ago
|
38 comments
4.
▲
AWS Log4Shell HotPatch Introduced a Container Escape Vulnerability
(unit42.paloaltonetworks.com)
44 points
by
uvuv
4y ago
|
1 comments
5.
▲
Container Escape to Shadow Admin: Google Kubernetes Engine (GKE) Autopilot
(unit42.paloaltonetworks.com)
2 points
by
uvuv
5y ago
|
0 comments
6.
▲
Cross-Account Container Takeover in Azure
(unit42.paloaltonetworks.com)
3 points
by
uvuv
5y ago
|
0 comments
7.
▲
by
uvuv
6y ago
Definitely not secure. The author did a great job explaining container runtimes in basic terms, but there's a lot of security features missing. Mainly: * Reducing the container's capabilities * Restricting access to resources th
8.
▲
by
uvuv
7y ago
That's an option, an actually what LXD does. It's better then just chrooting, though in the case of this vulnerability even if docker-tar entered the mount NS, the exploit will still work.
9.
▲
by
uvuv
7y ago
Hi, OP here. You're correct on the symlink point, they're the reason chrooting is needed, as they caused several vulnerabilities in Docker and Podman cp in the past. The good news is that there is a new syscall designed to solve t
10.
▲
by
uvuv
7y ago
A PoC for CVE-2019-14271, which can be exploited by a malicious container to gain root code execution on the host.
11.
▲
Full Docker Breakout Exploit
(unit42.paloaltonetworks.com)
19 points
by
uvuv
7y ago
|
6 comments
12.
▲
Gaining Persistency on Vulnerable Lambdas
(twistlock.com)
4 points
by
uvuv
7y ago
|
1 comments
13.
▲
Privilege Escalation in Cloud Foundry UAA – CVE-2019-11270
(twistlock.com)
4 points
by
uvuv
7y ago
|
0 comments
14.
▲
Improper Input Validation – An SQL Vulnerability in Cloud Foundry
(twistlock.com)
1 points
by
uvuv
7y ago
|
0 comments
15.
▲
Breaking Out of Rkt Containers – 3 New Unpatched CVEs
(twistlock.com)
6 points
by
uvuv
7y ago
|
0 comments
16.
▲
by
uvuv
8y ago
They're created using https://www.draw.io/