Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. I’ve mentioned this before: this is one of the oncoming trains for corp-security.

I’ve mentioned this before: this is one of the oncoming trains for corp-security.

Scheduled Pinned Locked Moved Uncategorized
25 Posts 22 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

    I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

    Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

    Their agents will.

    megatronicthronbanks@mastodon.socialM This user is from outside of this forum
    megatronicthronbanks@mastodon.socialM This user is from outside of this forum
    megatronicthronbanks@mastodon.social
    wrote last edited by
    #10

    @haroonmeer

    Yeah it's like Cliff Stoll and sendmail all over anew (yes I'm that old). Docker frequently writes root owned files to the FS. We are a dumb species.

    1 Reply Last reply
    0
    • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

      I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

      Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

      Their agents will.

      stux@mstdn.socialS This user is from outside of this forum
      stux@mstdn.socialS This user is from outside of this forum
      stux@mstdn.social
      wrote last edited by
      #11

      @haroonmeer People are willingly installing malware now, heck.. they’re even paying for it

      expertenkommision_cyberunfall@mastodon.socialE 1 Reply Last reply
      0
      • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

        I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

        Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

        Their agents will.

        ahhhhhhhhhhh@mastodon.socialA This user is from outside of this forum
        ahhhhhhhhhhh@mastodon.socialA This user is from outside of this forum
        ahhhhhhhhhhh@mastodon.social
        wrote last edited by
        #12

        @haroonmeer feeling less stupid for being paranoid enough to not add my user to the docker group.

        1 Reply Last reply
        0
        • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

          I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

          Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

          Their agents will.

          tdelmas@mamot.frT This user is from outside of this forum
          tdelmas@mamot.frT This user is from outside of this forum
          tdelmas@mamot.fr
          wrote last edited by
          #13

          @haroonmeer at least it didn't use the latest linux exploit

          1 Reply Last reply
          0
          • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

            I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

            Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

            Their agents will.

            cgudrian@social.tchncs.deC This user is from outside of this forum
            cgudrian@social.tchncs.deC This user is from outside of this forum
            cgudrian@social.tchncs.de
            wrote last edited by
            #14

            @haroonmeer As a last resort it would have probably tried running the copyfail exploit.

            1 Reply Last reply
            0
            • stux@mstdn.socialS stux@mstdn.social

              @haroonmeer People are willingly installing malware now, heck.. they’re even paying for it

              expertenkommision_cyberunfall@mastodon.socialE This user is from outside of this forum
              expertenkommision_cyberunfall@mastodon.socialE This user is from outside of this forum
              expertenkommision_cyberunfall@mastodon.social
              wrote last edited by
              #15

              @stux @haroonmeer

              And corp encourages them to do do.

              mdione@en.osm.townM 1 Reply Last reply
              0
              • R relay@relay.an.exchange shared this topic
              • expertenkommision_cyberunfall@mastodon.socialE expertenkommision_cyberunfall@mastodon.social

                @stux @haroonmeer

                And corp encourages them to do do.

                mdione@en.osm.townM This user is from outside of this forum
                mdione@en.osm.townM This user is from outside of this forum
                mdione@en.osm.town
                wrote last edited by
                #16

                @expertenkommision_cyberunfall @stux @haroonmeer and some corps forces us to do it.

                expertenkommision_cyberunfall@mastodon.socialE 1 Reply Last reply
                0
                • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

                  I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

                  Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

                  Their agents will.

                  mdione@en.osm.townM This user is from outside of this forum
                  mdione@en.osm.townM This user is from outside of this forum
                  mdione@en.osm.town
                  wrote last edited by
                  #17

                  @haroonmeer but isn't the docker's `root` user mapped to a host's transient normal user?

                  fuzzyfuzzyfungus@cyberplace.socialF 1 Reply Last reply
                  0
                  • mdione@en.osm.townM mdione@en.osm.town

                    @expertenkommision_cyberunfall @stux @haroonmeer and some corps forces us to do it.

                    expertenkommision_cyberunfall@mastodon.socialE This user is from outside of this forum
                    expertenkommision_cyberunfall@mastodon.socialE This user is from outside of this forum
                    expertenkommision_cyberunfall@mastodon.social
                    wrote last edited by
                    #18

                    @mdione @stux @haroonmeer

                    Feels like sabotage

                    1 Reply Last reply
                    0
                    • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

                      I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

                      Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

                      Their agents will.

                      kumarvibe@mastodon.socialK This user is from outside of this forum
                      kumarvibe@mastodon.socialK This user is from outside of this forum
                      kumarvibe@mastodon.social
                      wrote last edited by
                      #19

                      @haroonmeer @jackeric agents are very clever. I’ve seen them try all kinds of things like this just to “get the task done.” I’ve only noticed because I put them in sandbox-exec.

                      1 Reply Last reply
                      0
                      • mdione@en.osm.townM mdione@en.osm.town

                        @haroonmeer but isn't the docker's `root` user mapped to a host's transient normal user?

                        fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                        fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                        fuzzyfuzzyfungus@cyberplace.social
                        wrote last edited by
                        #20

                        @mdione @haroonmeer Docker can map to a user other than root; but it leaves whether or not it does so up to you. I'm not sure if there's some specialty lockdown config that tightens this; but by default docker doesn't even seem to intend to protect the host from the user; and leaves it up to the user whether they want any actual protection from container contents or not.

                        Link Preview Image
                        Understanding the Docker USER Instruction | Docker

                        Discover best practices and common pitfalls associated with the Docker USER instruction. Also get a hands-on demo to learn the importance of these practices.

                        favicon

                        Docker (www.docker.com)

                        fuzzyfuzzyfungus@cyberplace.socialF 1 Reply Last reply
                        0
                        • fuzzyfuzzyfungus@cyberplace.socialF fuzzyfuzzyfungus@cyberplace.social

                          @mdione @haroonmeer Docker can map to a user other than root; but it leaves whether or not it does so up to you. I'm not sure if there's some specialty lockdown config that tightens this; but by default docker doesn't even seem to intend to protect the host from the user; and leaves it up to the user whether they want any actual protection from container contents or not.

                          Link Preview Image
                          Understanding the Docker USER Instruction | Docker

                          Discover best practices and common pitfalls associated with the Docker USER instruction. Also get a hands-on demo to learn the importance of these practices.

                          favicon

                          Docker (www.docker.com)

                          fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                          fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                          fuzzyfuzzyfungus@cyberplace.social
                          wrote last edited by
                          #21

                          @mdione @haroonmeer Honestly, I can see the appeal of docker as a sort of web services oriented package manager; but it's terrifying to see people treating it as though it's a VM-tier isolation tool or security boundary. It's certainly not impossible to use it in ways that provide at least some protection from container contents; but the overall intent is much closer to easing dependency wrangling and keeping configs contained than to hard isolation.

                          1 Reply Last reply
                          0
                          • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

                            I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

                            Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

                            Their agents will.

                            feld@friedcheese.usF This user is from outside of this forum
                            feld@friedcheese.usF This user is from outside of this forum
                            feld@friedcheese.us
                            wrote last edited by
                            #22
                            @haroonmeer why are we so worried about agents using this when this was already the first thing any attacker would do?

                            Pop a shell on Linux, check for docker group access. That makes life very easy.
                            phnt@fluffytail.orgP 1 Reply Last reply
                            0
                            • feld@friedcheese.usF feld@friedcheese.us
                              @haroonmeer why are we so worried about agents using this when this was already the first thing any attacker would do?

                              Pop a shell on Linux, check for docker group access. That makes life very easy.
                              phnt@fluffytail.orgP This user is from outside of this forum
                              phnt@fluffytail.orgP This user is from outside of this forum
                              phnt@fluffytail.org
                              wrote last edited by
                              #23
                              @feld @haroonmeer Why are we so worried about agents using this when the user had the rights in the first place? Agents/LLMs should change nothing in that equation.
                              1 Reply Last reply
                              0
                              • haroonmeer@infosec.exchangeH haroonmeer@infosec.exchange

                                I’ve mentioned this before: this is one of the oncoming trains for corp-security. We’ve long failed at least-privilege, but weren’t often punished for it.

                                Helen in HR (or Bob in accounts) didn’t know what to do with the extra perms they didn’t know they had.

                                Their agents will.

                                S This user is from outside of this forum
                                S This user is from outside of this forum
                                shadur@mastodon.sandwich.net
                                wrote last edited by
                                #24

                                @haroonmeer Will this still work if docker is not run as root but as an unprivileged user?

                                1 Reply Last reply
                                1
                                0
                                • R relay@relay.infosec.exchange shared this topic
                                • webhat@infosec.exchangeW webhat@infosec.exchange

                                  @haroonmeer they need to add: "Don't hack stuff" to the prompt, that will protect them

                                  aj@techhub.socialA This user is from outside of this forum
                                  aj@techhub.socialA This user is from outside of this forum
                                  aj@techhub.social
                                  wrote last edited by
                                  #25

                                  @webhat @haroonmeer also add: "don't say anything about goblins"

                                  1 Reply Last reply
                                  1
                                  0
                                  Reply
                                  • Reply as topic
                                  Log in to reply
                                  • Oldest to Newest
                                  • Newest to Oldest
                                  • Most Votes


                                  • Login

                                  • Login or register to search.
                                  • First post
                                    Last post
                                  0
                                  • Categories
                                  • Recent
                                  • Tags
                                  • Popular
                                  • World
                                  • Users
                                  • Groups