Trending

Quiz: How Much Do You Know about Dockerhub hack ?

On Thursday, April 25th, 2019, there was unauthorized access to a single Docker Hub database storing a subset of non-financial user data (approximately 190,000 users had been exposed).Docker has reacted quickly to minimize/nullify the risk of attackers misusing the data,in this post we take look at key points about attack & further steps.

Quick recap on what is Docker Hub:

Docker Hub is a service provided by Docker for finding and sharing container images across teams/organizations/or with Docker community. Following are key features:

  • Image Repository:  It allows you to share container images across teams/organizations, or with Docker community,Container Images can be Pushed and pulled using docker client.
  • Official Images: Pull and use high-quality container images provided by Docker.
  • Publisher Images: Pull and use high-quality container images provided by external vendors.
  • Automated Builds: You can automatically build container images from GitHub and Bitbucket and push them to Docker Hub.
  • Webhooks: Trigger actions after a successful push to a repository to integrate Docker Hub with other services.

Key points about attack & further steps:

  1. Sensitive data from approximately 190,000 accounts may have been exposed (~ 5% of Hub users).
  2. Data includes usernames and hashed passwords, as well as GitHub and Bitbucket tokens for Docker autobuilds. Users who have enabled autobuilds, respective repositories has been unlinked.Tokens has also been revoked to protect from attack.
  3. For users with autobuilds that may have been impacted, GitHub tokens and access keys have been revoked. This means your autobuilds will fail, unlink & relink as required.Also  review GitHub and Bitbucket account login logs for any unauthorized access from unknown IP addresses.
  4. No Official Images have been compromised. There are additional security measures in place for Official Images that includes GPG signatures on git commits as well as Notary signing to ensure the integrity of each image.Notary is a tool for publishing and managing trusted images,checkout more here.
  5. A password reset link has been sent to users who potentially had their password hash exposed.For other Docker Hub users, there is NO action required.

Please reach out info@docker.com for any questions/support.

References :

Check out Docker Official Notification here

Summary
Article Name
Quiz: How Much Do You Know about Dockerhub hack ?
Description
In this post we take look at key points about attack & further steps.
Author
Publisher Name
Upnxtblog
Publisher Logo
Karthik

Allo! My name is Karthik,experienced IT professional.Upnxtblog covers key technology trends that impacts technology industry.This includes Cloud computing,Blockchain,Machine learning & AI,Best mobile apps, Best tools/open source libs etc.,I hope you would love it and you can be sure that each post is fantastic and will be worth your time.

Share
Published by
Karthik

Recent Posts

Looking Back at 2024: A Year of Innovation and Growth on Upnxtblog

As we wrap up 2024, it’s time to reflect on the incredible journey we’ve had…

3 weeks ago

Developing a Strong Disaster Recovery Plan for Your Business

Operating a business often entails balancing tight schedules, evolving market dynamics, and shifting consumer requirements.…

4 weeks ago

How to Secure Your WordPress Hosting by Upgrading Your Login URL

Of course, every site has different needs. In the end, however, there is one aspect…

4 weeks ago

Social Media Marketing: A Key to Business Success with Easy Digital Life

In today's digital-first world, businesses must adopt effective strategies to stay competitive. Social media marketing…

1 month ago

Best 7 AI Tools Every UI/UX Designer Should Know About

62% of UX designers now use AI to enhance their workflows. Artificial intelligence (AI) rapidly…

1 month ago

How AI Enhances Photoshop Workflow: A Beginner’s Guide

The integration of artificial intelligence into graphic design through tools like Adobe Photoshop can save…

2 months ago

This website uses cookies.