Registry enumeration

The registry v2 API exposes a catalog of repositories and the tags under each. Where the catalog is readable, it hands over the full inventory; even where it is not, known or guessed repository names can be queried for tags and manifests.

bash
REG=https://registry.example.com
curl -s $REG/v2/_catalog | jq .                      # all repositories, if allowed
curl -s $REG/v2/<repo>/tags/list | jq .              # tags for a repository
curl -s $REG/v2/<repo>/manifests/<tag> \
  -H 'Accept: application/vnd.docker.distribution.manifest.v2+json' | jq '.config,.layers'

Exploitation notes#

  • _catalog is often left readable on internal registries; it is the fastest full inventory.
  • Manifests reference the config and layer digests you then pull for Secrets in image layers.
  • Tools like regctl and crane wrap these calls and handle auth token exchange.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more