Images and registries

An image is a stack of filesystem layers plus a configuration, and a registry is the server that stores and serves them. Both are supply-chain targets. A registry that is reachable without authentication, or with weak credentials, lets an attacker pull private images (and the secrets inside them) and sometimes push malicious ones. The images themselves leak secrets that were added during the build and later thought removed, because every layer is retained. And a base image an attacker can influence poisons every image built on top of it.

Find registries and inspect images:

bash
# registry API v2 is unauthenticated to probe by default
curl -s http://<registry>:5000/v2/_catalog
curl -s http://<registry>:5000/v2/<repo>/tags/list
# pull and inspect an image's build history for secrets
docker pull <registry>:5000/<repo>:<tag>
docker history --no-trunc <registry>:5000/<repo>:<tag>

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more