-
Notifications
You must be signed in to change notification settings - Fork 107
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Bitcoin miner in docker hub postgis 13 ? #115
Comments
I can't see.
IMHO:
see more: docker-library/postgres#770 (comment) |
@ImreSamu can you please try the latest image. The 13.0 image hasn’t been updated and we generally do no back port any changes into stable images so that we do not break production environments. try the image 13-3.1 |
IMHO: This is the latest ( updated 9 hours ago ) and I can' see the
|
@ImreSamu it looks like your machine had been compromised. https://brycematheson.io/how-to-permanently-kill-and-remove-kdevtmpfsi-kinsing/ The most likely reason that popped up in your image is that you might have been using the default password which is used within the image. someone would have maliciously started that process . As a security guide you will need to use
|
@ImreSamu thanks for the insights. My configuration was: postgres 13 in a container with a 80 characters password, but no SSL and no ip restriction. I was just trying to reverse proxy tcp with traefik and had troubles getting it working... when it finally worked it was late in the day and I just let everything "as is". So the DB was opened on 5432, no ip whitelist, no SSL but a strong password, no client connecting "officialy" to it. I still can't figure out how they breach into the machine... any idea ? They had to break in postgres (password length of 80 characters) and execute the miner from within postgres ? This DB is just OSM data so nothing important for us. We can just reinstall the OS if needed. Anyway I will put in place all restrictions as I would have done if I had the time to do it properly... I just did not expect this to happen so quickly. Thanks ! |
Be more careful next time! |
In addition, if you do not enable SSL, your passwords are transmitted as clear text for which a strong password will offer no benefit. |
Hi,
it seems that there is a bitcoin miner in this image:
https://hub.docker.com/layers/kartoza/postgis/13/images/sha256-0ebcf54aa52c3c433307273c3f69a07952bb7f794f8d1ee91faaf611b974ae88?context=explore
We installed it few days ago on a machine and 2 days after the process
kdevtmpfsi
show up consuming 100% CPU.See here for an issue describing the pb: docker-library/postgres#798
I stoped the container, removed the image, rebooted and deployed the kartoza/posgis:11-2.5.
We already use this image elsewhere and it seems that the miner is not present.
Any idea why it appeared in this last image ?
The text was updated successfully, but these errors were encountered: