ECR repositories can be made public through the ECR Public gallery, or left pullable by an over-broad repository policy. Either way, anyone who can pull the image gets its full layer history, which frequently holds hardcoded credentials, API tokens, internal hostnames, and source code.
Pulling and inspecting#
# Public gallery image
docker pull public.ecr.aws/<alias>/<repo>:<tag>
# Inspect layers and history for secrets
docker history --no-trunc <image>
dive <image> # interactive layer explorer
Scan the unpacked layers with a secret scanner rather than reading by hand:
docker save <image> -o img.tar && mkdir x && tar -xf img.tar -C x
trufflehog filesystem x/
Exploitation notes#
- Secrets in an early layer persist even if a later layer deletes the file, so always scan the full history, not the final filesystem.
- Internal image names and tags leak the service inventory and version, which seeds targeting of the running workloads.
- A repository left pullable cross-account is the repository policy case; a truly public one needs no credentials at all.
Tools#
- docker / crane: pull and export images.
- dive: inspect layers interactively.
- TruffleHog / gitleaks: scan extracted layers for secrets.