Docker containers (downloadable system images containing web applications or other alike that can be mounted and used as is) with hidden applications for crypto mining were found after security audits performed by Fortinet and Kromtech companies. The affected containers identified on the official Docker Hub have been downloaded more than 5 million times, which suggest the big power used for crypto mining purpose. ![Docker.png](https://cdn.steemitimages.com/DQmUJtcrCqV3JuHbnc8yjfydhkoS2yFvDHw7hPtXYjQ1pza/Docker.png) “Of course, we can safely assume that these had not been deployed manually. In fact, the attack seems to be fully automated. Attackers have most probably developed a script to find miss configured Docker and Kubernetes installations. Docker works as a client/server architecture, meaning the service can be fully managed remotely via the REST API,” wrote researcher David Maciejak. The hackers got around $100 000 value in cryptocurrency, which using other resources is not a little thing and also considering the simplicity of the hack itself. “Today’s growing number of publicly accessible miss configured orchestration platforms like Kubernetes allows hackers to create a fully automated tool that forces these platforms to mine Monero,” as written in a Kromtech report. “By pushing malicious images to a Docker Hub registry and pulling it from the victim’s system, hackers were able to mine 544.74 Monero, which is equal to $90,000.” “As with public repositories like GitHub, Docker Hub is there for the service of the community. When dealing with open public repositories and open source code, we recommend that you follow a few best practices including: know the content author, scan images before running and use curated official images in Docker Hub and certified content in Docker Store whenever possible,” wrote Docker’s head of security David Lawrence in a Threatpost report. Reading this got my attention as I jiggled also with purposing free available services out there for mining. Mostly using Amazon or Google cloud trials, I was able to mine some nice MONERO in the beginning. Of course I was not affecting somebody else and I was in the legal terms of those services. And with time, both introduced rules and scans that would identify such services and the joy got over. But, the thinking of using such open resources was there and seeing this with Docker I found it as a normal transition from one system to another. Of course, hacking is not good, but this just shows the security vulnerabilities of such systems which otherwise might not be identified. And, as I well said it not long time ago the first interest should be for security and secondary with building something great, otherwise at any time can be crashed by wrong doings like this.
post_id | 53,190,309 |
---|---|
author | cryptorg |
permlink | docker-hub-containers-were-hacked-and-injected-with-crypto-mining-applications |
category | docker |
json_metadata | "{"format": "markdown", "tags": ["docker", "hub", "hacked", "mining", "steemromania"], "image": ["https://cdn.steemitimages.com/DQmUJtcrCqV3JuHbnc8yjfydhkoS2yFvDHw7hPtXYjQ1pza/Docker.png"], "app": "steemit/0.1"}" |
created | 2018-06-16 06:45:48 |
last_update | 2018-06-16 06:45:48 |
depth | 0 |
children | 1 |
net_rshares | 309,885,693,753 |
last_payout | 2018-06-23 06:45:48 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.635 SBD |
curator_payout_value | 0.135 SBD |
pending_payout_value | 0.000 SBD |
promoted | 0.000 SBD |
body_length | 2,791 |
author_reputation | 8,576,958,985,908 |
root_title | "Docker Hub containers were hacked and injected with crypto mining applications" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 SBD |
percent_steem_dollars | 10,000 |
author_curate_reward | "" |
voter | weight | wgt% | rshares | pct | time |
---|---|---|---|---|---|
team | 0 | 85,460,910,248 | 10% | ||
chrispop | 0 | 634,986,263 | 37.5% | ||
alexvan | 0 | 13,602,803,687 | 20% | ||
alinabarbu | 0 | 14,573,672,726 | 37.5% | ||
minnowsupport | 0 | 23,650,572,915 | 0.5% | ||
foodlink | 0 | 591,462,230 | 100% | ||
luciancovaci | 0 | 2,603,560,234 | 100% | ||
jgr33nwood | 0 | 143,270,233 | 100% | ||
lishu | 0 | 7,176,759,855 | 37.5% | ||
sunnyali | 0 | 772,624,931 | 37.5% | ||
upvoteph | 0 | 4,803,170,427 | 20% | ||
alexandraioana26 | 0 | 12,181,500,300 | 37.5% | ||
cryptorg | 0 | 26,772,515,456 | 100% | ||
celmor | 0 | 0 | 100% | ||
ruth-elise | 0 | 563,872,293 | 37.5% | ||
vargart | 0 | 1,174,387,982 | 18.75% | ||
alphasteem | 0 | 2,116,779,797 | 3.75% | ||
photovitamin | 0 | 613,382,325 | 22.5% | ||
eliahsoul | 0 | 294,015,045 | 56.25% | ||
gadrian | 0 | 5,817,570,486 | 26.25% | ||
victorcovrig | 0 | 3,402,353,033 | 50% | ||
mu1stu | 0 | 2,924,260,256 | 37.5% | ||
qurator-tier-0 | 0 | 5,543,407,477 | 1% | ||
les.sisters | 0 | 447,656,751 | 75% | ||
steemromania | 0 | 83,232,386,302 | 75% | ||
lol.games | 0 | 1,847,294,972 | 75% | ||
educatie | 0 | 63,183,620 | 37.5% | ||
medicnet | 0 | 174,562,379 | 37.5% | ||
communityisyou | 0 | 171,499,881 | 37.5% | ||
ga10 | 0 | 578,279,417 | 100% | ||
dianas | 0 | 226,844,062 | 37.5% | ||
carolinaelly | 0 | 785,683,365 | 50% | ||
bitson | 0 | 114,750,148 | 15% | ||
ressolid | 0 | 110,601,395 | 37.5% | ||
lux-witness | 0 | 6,715,113,262 | 100% |
God bless you. https://steemit.com/@biblegateway
post_id | 53,190,315 |
---|---|
author | biblegateway |
permlink | re-cryptorg-docker-hub-containers-were-hacked-and-injected-with-crypto-mining-applications-20180616t064555321z |
category | docker |
json_metadata | "{"links": ["https://steemit.com/@biblegateway"], "tags": ["docker"], "app": "steemit/0.1"}" |
created | 2018-06-16 06:45:54 |
last_update | 2018-06-16 06:45:54 |
depth | 1 |
children | 0 |
net_rshares | 0 |
last_payout | 2018-06-23 06:45:54 |
cashout_time | 1969-12-31 23:59:59 |
total_payout_value | 0.000 SBD |
curator_payout_value | 0.000 SBD |
pending_payout_value | 0.000 SBD |
promoted | 0.000 SBD |
body_length | 48 |
author_reputation | -1,829,035,868,014 |
root_title | "Docker Hub containers were hacked and injected with crypto mining applications" |
beneficiaries | [] |
max_accepted_payout | 1,000,000.000 SBD |
percent_steem_dollars | 10,000 |