docker / hub-feedback

Feedback and bug reports for the Docker Hub
https://hub.docker.com
235 stars 39 forks source link

Malicious image in docker hub #1554

Closed fernandodebrando closed 6 years ago

fernandodebrando commented 6 years ago

Malicious image found in the account https://hub.docker.com/r/l0s3r in the docker hub.

jmwong commented 6 years ago

Thanks for the report @fernandodebrando. Could you elaborate on those images? Have you seen it being used in an attack?

fernandodebrando commented 6 years ago

I recently found on a server a container with this image l0s3r/m3n

Run container $ docker run -it --network=none l0s3r/m3n /bin/bash

Contents of the files

jmwong commented 6 years ago

Thanks for your report. We've deactivated the user.

fangbo947705 commented 6 years ago

Malicious image found in the account https://hub.docker.com/r/l0se3/dah/ in the docker hub. please help, the same as @fernandodebrando feedback

fernandodebrando commented 6 years ago

@fangbo947705 , have you seen it being used in an attack? Also report the account on github https://github.com/l0se3x.

fangbo947705 commented 6 years ago

yes,it run on our server.when I remove it ,it will come later.I have find the result ,I have expose 2375 port to the internet,then he can use this port to control my docker service.now I forbidden this port