Registry access

Private registries gate pulls behind credentials, which are routinely recoverable: a ~/.docker/config.json, a Kubernetes image pull secret, or a cloud registry token from instance metadata. With them, pull any image the identity can read.

bash
# Credentials from a recovered docker config (base64 auth entries)
cat ~/.docker/config.json | jq '.auths'

# Cloud registries mint short-lived tokens from the instance/workload identity
aws ecr get-login-password | docker login --username AWS --password-stdin <acct>.dkr.ecr.<region>.amazonaws.com
docker pull <acct>.dkr.ecr.<region>.amazonaws.com/<repo>:<tag>

Exploitation notes#

  • A cloud identity on a compromised host or pod often has registry pull (or push) rights; mint the token from metadata rather than hunting for static creds.
  • Pull rights alone leak source, configs, and secrets; push rights enable Image backdooring.
  • Image pull secrets stored in orchestrators are a prime source, see Image pull secret theft.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more