狠狠撸

狠狠撸Share a Scribd company logo
如何利用 Docker 強化網站安全
徐千洋 (TIM HSU)
CHROOT 創辦人
HITCON 創辦人
網駭科技 創辦人
曾任:
台灣大哥大 資安部經理
現職:
VARMOUR 美商安連網路公司台灣分公司
如何利用 Docker 強化網站安全
如何利用 Docker 強化網站安全
browser httpd php login.php
/bin/sh
browser httpd php upload.php
webshell.php/bin/sh
如何利用 Docker 強化網站安全
?
?
?
?
?
?
UID=165536
UID=165537
dockremap:165536
/etc/subuid
UID=0
UID=1
root:0:XXXX
daemon:1:XXXX
/etc/passwd
?
? SETUID-ROOT
? CAP_NET_RAW
# ls -al /bin/ping
-rwxr-xr-x 1 root root 44168 Mar 15 2014
# getcap /bin/ping
/bin/ping = cap_net_raw+p
?
/usr/sbin/nginx {
#include <abstractions/apache2-common> #include
<abstractions/base>
capability dac_override,
capability net_bind_service,
capability setgid,
capability setuid,
/etc/passwd r,
/etc/group r,
deny /bin/sh mrwklx,
}
如何利用 Docker 強化網站安全
?
?
?
?
?
?
?
?
?
?
?
?
?
?
?
如何利用 Docker 強化網站安全
TIMHSU.TW@GMAIL.COM
HTTP://GITHUB.COM/TIMHSUTW
1. AppArmor security profiles for Docker
https://docs.docker.com/engine/security/apparmor/
2. VulApps
https://hub.docker.com/r/medicean/vulapps/
https://github.com/Medicean/VulApps/
3. Pornhub bug bounty
https://hackerone.com/pornhub
4. Docker security
https://docs.docker.com/engine/security/security/
5. Critical: Remote Command Execution in WordPress Form Manager Plugin (CVE-2015-
7806)
http://appcheck-ng.com/remote-command-execution-in-wordpress-form-manager-
plugin-cve-2015-7806/
6. Struts2 RCE PoC
https://github.com/coffeehb/Some-PoC-oR-ExP/tree/master/Struts2

More Related Content

What's hot (20)

PDF
MQTTS mosquitto - cheat sheet -
Naoto MATSUMOTO
?
PPTX
Олег Купреев ?Уязвимости программного обеспечения телекоммуникационного обору...
Mail.ru Group
?
PDF
How to Connect MQTT Broker on ESP8266 WiFi
Naoto MATSUMOTO
?
PDF
Starting python
Kentaro Kawano
?
PDF
How to twist a IPv6 over Bluetooth (6lowpan)
Naoto MATSUMOTO
?
PDF
install mosquitto-auth-plug - cheat sheet -
Naoto MATSUMOTO
?
PDF
UP Board AI Core Configuration memo
Naoto MATSUMOTO
?
PPTX
Kali net hunter
Prashanth Sivarajan
?
PDF
贬罢罢笔プロクシライブラリ辫谤辞虫测2の设计と実装
inaz2
?
PDF
Access control
Varnish Software
?
PDF
狈别虫耻蝉で础苍蝉颈产濒别やってみた
Takehiro Yokoishi
?
PDF
44CON London 2015 - Hunting Asynchronous Vulnerabilities
44CON
?
PDF
[English] BackBox Linux and Metasploit: A practical demonstration of the Shel...
Andrea Draghetti
?
PDF
Алексей Старов - Как проводить киберраследования?
HackIT Ukraine
?
PDF
Custom Rules & Broken Tools
NotSoSecure Global Services
?
PDF
Docker on Windows
Carl Su
?
PDF
Android Tamer BH USA 2016 : Arsenal Presentation
Anant Shrivastava
?
PDF
MateriApps LIVE!の設定
Computational Materials Science Initiative
?
PDF
MIPS-X
Zoltan Balazs
?
PPTX
EKFiddle: a framework to study Exploit Kits
Jerome Segura
?
MQTTS mosquitto - cheat sheet -
Naoto MATSUMOTO
?
Олег Купреев ?Уязвимости программного обеспечения телекоммуникационного обору...
Mail.ru Group
?
How to Connect MQTT Broker on ESP8266 WiFi
Naoto MATSUMOTO
?
Starting python
Kentaro Kawano
?
How to twist a IPv6 over Bluetooth (6lowpan)
Naoto MATSUMOTO
?
install mosquitto-auth-plug - cheat sheet -
Naoto MATSUMOTO
?
UP Board AI Core Configuration memo
Naoto MATSUMOTO
?
Kali net hunter
Prashanth Sivarajan
?
贬罢罢笔プロクシライブラリ辫谤辞虫测2の设计と実装
inaz2
?
Access control
Varnish Software
?
狈别虫耻蝉で础苍蝉颈产濒别やってみた
Takehiro Yokoishi
?
44CON London 2015 - Hunting Asynchronous Vulnerabilities
44CON
?
[English] BackBox Linux and Metasploit: A practical demonstration of the Shel...
Andrea Draghetti
?
Алексей Старов - Как проводить киберраследования?
HackIT Ukraine
?
Custom Rules & Broken Tools
NotSoSecure Global Services
?
Docker on Windows
Carl Su
?
Android Tamer BH USA 2016 : Arsenal Presentation
Anant Shrivastava
?
EKFiddle: a framework to study Exploit Kits
Jerome Segura
?

Viewers also liked (20)

PDF
Practical Attacks Against Encrypted VoIP Communications
iphonepentest
?
PPTX
Harden Your Linux
Tim Hsu
?
PDF
BASH 漏洞深入探討
Tim Hsu
?
PPTX
如何用 Docker 快速建立 honeypot public
Tim Hsu
?
PDF
资安人员如何协助公司面对层出不穷的资安威胁
Tim Hsu
?
PDF
台科大網路鑑識課程 封包分析及中繼站追蹤
jack51706
?
PDF
HITCON GIRLS 成大講座 惡意程式分析(Turkey)
HITCON GIRLS
?
PDF
勒索软体态势与应措
jack51706
?
PDF
Webshell 簡單應用
hackstuff
?
PDF
第一次使用厂丑辞诲补苍.颈辞就上手
Ting-En Lin
?
PDF
台科逆向简报
耀德 蔡
?
PDF
逆向工程入门
耀德 蔡
?
PDF
HITCON GIRLS: CTF 介紹 (小魚&念奇)
HITCON GIRLS
?
PDF
HITCON CTF 2016導覽
HITCON GIRLS
?
PDF
20150616 NPO要知道的駭客攻擊手法
Net Tuesday Taiwan
?
PDF
Web2.0 attack and defence
hackstuff
?
PDF
Python 網頁爬蟲由淺入淺
hackstuff
?
PDF
HITCON GIRLS 成大講座 基礎知識(蜘子珣)
HITCON GIRLS
?
PPTX
贬补肠办辫补诲教学
儀萍 陳
?
PDF
連貓也會輕鬆安裝Burp suite
Catcatcatcat Hong
?
Practical Attacks Against Encrypted VoIP Communications
iphonepentest
?
Harden Your Linux
Tim Hsu
?
BASH 漏洞深入探討
Tim Hsu
?
如何用 Docker 快速建立 honeypot public
Tim Hsu
?
资安人员如何协助公司面对层出不穷的资安威胁
Tim Hsu
?
台科大網路鑑識課程 封包分析及中繼站追蹤
jack51706
?
HITCON GIRLS 成大講座 惡意程式分析(Turkey)
HITCON GIRLS
?
勒索软体态势与应措
jack51706
?
Webshell 簡單應用
hackstuff
?
第一次使用厂丑辞诲补苍.颈辞就上手
Ting-En Lin
?
台科逆向简报
耀德 蔡
?
逆向工程入门
耀德 蔡
?
HITCON GIRLS: CTF 介紹 (小魚&念奇)
HITCON GIRLS
?
HITCON CTF 2016導覽
HITCON GIRLS
?
20150616 NPO要知道的駭客攻擊手法
Net Tuesday Taiwan
?
Web2.0 attack and defence
hackstuff
?
Python 網頁爬蟲由淺入淺
hackstuff
?
HITCON GIRLS 成大講座 基礎知識(蜘子珣)
HITCON GIRLS
?
贬补肠办辫补诲教学
儀萍 陳
?
連貓也會輕鬆安裝Burp suite
Catcatcatcat Hong
?
Ad

Recently uploaded (20)

PDF
The Convergence of Threat Behaviors Across Intrusions
Joe Slowik
?
PDF
B M Mostofa Kamal Al-Azad [Document & Localization Expert]
Mostofa Kamal Al-Azad
?
PDF
狠狠撸s: Eco Economic Epochs for The World Game (s) pdf
Steven McGee
?
PPT
Almos Entirely Correct Mixing with Apps to Voting
gapati2964
?
PDF
Beginning-Laravel-Build-Websites-with-Laravel-5.8-by-Sanjib-Sinha-z-lib.org.pdf
TagumLibuganonRiverB
?
PDF
Clive Dickens RedTech Public Copy - Collaborate or Die
Clive Dickens
?
PDF
I Want to join occult brotherhood for money ritual#((+2347089754903))
haragonoccult
?
PDF
Download Google Chrome for Fast and Secure Web Browsing Experience
hgfdsqetuiplmnvcz43
?
PDF
What Is Google Chrome? Fast & Secure Web Browser Guide
hgfdsqetuiplmnvcz43
?
PDF
web application development company in bangalore.pdf
https://dkpractice.co.in/seo.html tech
?
PPTX
BitRecover OST to PST Converter Software
antoniogosling01
?
PPTX
Class_4_Limbgvchgchgchgchgchgcjhgchgcnked_Lists.pptx
test123n
?
PPTX
The ARUBA Kind of new Proposal Umum .pptx
andiwarneri
?
PDF
ContextForge MCP Gateway - the missing proxy for AI Agents and Tools
Mihai Criveti
?
PPTX
原版一样(础狈鲍毕业证书)澳洲澳大利亚国立大学毕业证在线购买
Taqyea
?
PDF
Materi tentang From Digital Economy to Fintech.pdf
Abdul Hakim
?
PPTX
Q1 English3 Week5 PPT-MATATAG@edumaymay.pptx
JenniferCawaling1
?
PDF
Google Chrome vs Other Browsers: Why Users Still Prefer It.pdf
hgfdsqetuiplmnvcz43
?
PDF
03 Internal Analysis Strategik Manajemen.pdf
AhmadRifaldhi
?
PDF
BroadLink Cloud Service introduction.pdf
DevendraDwivdi1
?
The Convergence of Threat Behaviors Across Intrusions
Joe Slowik
?
B M Mostofa Kamal Al-Azad [Document & Localization Expert]
Mostofa Kamal Al-Azad
?
狠狠撸s: Eco Economic Epochs for The World Game (s) pdf
Steven McGee
?
Almos Entirely Correct Mixing with Apps to Voting
gapati2964
?
Beginning-Laravel-Build-Websites-with-Laravel-5.8-by-Sanjib-Sinha-z-lib.org.pdf
TagumLibuganonRiverB
?
Clive Dickens RedTech Public Copy - Collaborate or Die
Clive Dickens
?
I Want to join occult brotherhood for money ritual#((+2347089754903))
haragonoccult
?
Download Google Chrome for Fast and Secure Web Browsing Experience
hgfdsqetuiplmnvcz43
?
What Is Google Chrome? Fast & Secure Web Browser Guide
hgfdsqetuiplmnvcz43
?
web application development company in bangalore.pdf
https://dkpractice.co.in/seo.html tech
?
BitRecover OST to PST Converter Software
antoniogosling01
?
Class_4_Limbgvchgchgchgchgchgcjhgchgcnked_Lists.pptx
test123n
?
The ARUBA Kind of new Proposal Umum .pptx
andiwarneri
?
ContextForge MCP Gateway - the missing proxy for AI Agents and Tools
Mihai Criveti
?
原版一样(础狈鲍毕业证书)澳洲澳大利亚国立大学毕业证在线购买
Taqyea
?
Materi tentang From Digital Economy to Fintech.pdf
Abdul Hakim
?
Q1 English3 Week5 PPT-MATATAG@edumaymay.pptx
JenniferCawaling1
?
Google Chrome vs Other Browsers: Why Users Still Prefer It.pdf
hgfdsqetuiplmnvcz43
?
03 Internal Analysis Strategik Manajemen.pdf
AhmadRifaldhi
?
BroadLink Cloud Service introduction.pdf
DevendraDwivdi1
?
Ad

如何利用 Docker 強化網站安全