Secrets in image layers

Images are built up as layers, and a file deleted in a later layer still exists in the earlier one. Secrets copied in during a build, then removed, remain recoverable from the image. Build arguments and environment also persist in the image config and history.

bash
docker pull <image> && docker history --no-trunc <image>   # commands, ARG/ENV values
docker save <image> -o img.tar && mkdir x && tar -xf img.tar -C x   # unpack layers

# Scan layers and history for secrets
dive <image>
trufflehog docker --image <image>

Exploitation notes#

  • docker history exposes ARG and ENV values and the exact build commands, often enough on its own.
  • Deleted-but-present files live in the layer tarballs under x/; search them for keys, .npmrc, .git-credentials, and cloud config.
  • This is the payoff of pulling private images via Registry access or an open registry.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more