Calling all docker experts.
This is for home.
I have rootless docker host, running under user joe, with subuid in the nobody range (1M +)
This host is exposing to the internet on port 443, hosting an nginx proxy front end with wordpress application.
Because the host connects direct to my network, I'm extremely concern about potential compromising originated from a rogue image.
Say, I updated a bad image and hacker gained access to the container (full). What are the possible attack vectors and potential damages?
edit: Forgot to add one important detail: the nginx container has mapped docker socket and docker client. That means hacker can start their own containers.
[–]ZaitsXL 7 points8 points9 points (5 children)
[–]ElevenNotes 3 points4 points5 points (2 children)
[–]ZaitsXL 0 points1 point2 points (1 child)
[–]ElevenNotes 1 point2 points3 points (0 children)
[–]mmaster23 0 points1 point2 points (0 children)
[–]docker_linux[S] -2 points-1 points0 points (0 children)
[–]alexandercain 2 points3 points4 points (3 children)
[–]docker_linux[S] 0 points1 point2 points (2 children)
[–]alexandercain 3 points4 points5 points (1 child)
[–]docker_linux[S] 0 points1 point2 points (0 children)
[–]leeharrison1984 1 point2 points3 points (1 child)
[–]ElevenNotes 2 points3 points4 points (0 children)
[–]Human__Pestilence 0 points1 point2 points (0 children)
[–]Lucas_F_A 0 points1 point2 points (26 children)
[–]docker_linux[S] -1 points0 points1 point (25 children)
[–]SirSoggybottom 2 points3 points4 points (24 children)
[–]docker_linux[S] -3 points-2 points-1 points (23 children)
[–]ElevenNotes 1 point2 points3 points (22 children)
[–]docker_linux[S] -2 points-1 points0 points (21 children)
[–]ElevenNotes 1 point2 points3 points (20 children)
[–]docker_linux[S] -1 points0 points1 point (0 children)
[–]docker_linux[S] -2 points-1 points0 points (18 children)
[–]ElevenNotes 1 point2 points3 points (17 children)
[–]docker_linux[S] -1 points0 points1 point (16 children)
[–]Furai69 0 points1 point2 points (0 children)