Subscribe to Updates

    Get the latest news from USA, Canada and Europe directly to your inbox.

    What's Hot

    Why desert golf courses and artificial lakes remain untouched by the Colorado River crisis

    January 29, 2023

    Boys’ basketball: Former rivals Dylan Black and Will Householter play in sync for Mira Costa

    January 29, 2023

    Djokovic Beats Tsitsipas for 10th Australian Open, 22nd Slam

    January 29, 2023
    Facebook Twitter Instagram
    • Privacy Policy
    • Terms
    • Contact
    Facebook Twitter Instagram
    West ObserverWest Observer
    • Home
    • News
      1. United States
      2. Europe
      3. Canada
      4. Latin America
      5. Australia
      6. World
      7. View All

      Why desert golf courses and artificial lakes remain untouched by the Colorado River crisis

      January 29, 2023

      Djokovic Beats Tsitsipas for 10th Australian Open, 22nd Slam

      January 29, 2023

      Our psychological armor helps us cope with mass shootings, but numbs us to the destruction

      January 29, 2023

      Blinken Begins Middle East Trip Amid Spate of Violence

      January 29, 2023

      Protesters in the US condemn police brutality after the death of Tire Nichols

      January 29, 2023

      Arrested a man accused of two sexual assaults at the Feroz Awards party

      January 29, 2023

      Macron remembers Amini as a “martyr” and calls for more action in defense of human rights

      January 29, 2023

      “Where did the money go ?” : Jamaica afflicted by Usain Bolt case, defrauded of 12 million dollars

      January 29, 2023

      France must raise pension age to 64, prime minister says

      January 29, 2023

      As Canada’s RCMP marks 150th anniversary, a look at what it says needs to change

      January 29, 2023

      Former Mississauga, Ont. mayor Hazel McCallion dies at 101

      January 29, 2023

      Doctors say surgical training, delayed by the pandemic, continues to be affected

      January 29, 2023

      Moraes denies request to suspend deputies for alleged relationship with criminal acts

      January 29, 2023

      In Japan, people of esteem go viral for playing video games and making purchases in the donation cart

      January 29, 2023

      Djokovic wins 10th Australian Open title and equals Nadal’s record

      January 29, 2023

      Boat turns in the lake in Pakistan and at least 10 children die

      January 29, 2023

      Spanish Championship: Barcelona strengthens its lead with a difficult victory over Girona

      January 29, 2023

      Leicester City, Leeds and Southampton to the fifth round in the FA Cup

      January 29, 2023

      Australian Open Tennis: Sabalenka wins her first major title by defeating Rybakina

      January 29, 2023

      The Saudi Super… Al-Ittihad collective in the face of the Al-Faihawi barricades

      January 29, 2023

      Why desert golf courses and artificial lakes remain untouched by the Colorado River crisis

      January 29, 2023

      Djokovic Beats Tsitsipas for 10th Australian Open, 22nd Slam

      January 29, 2023

      Protesters in the US condemn police brutality after the death of Tire Nichols

      January 29, 2023

      Moraes denies request to suspend deputies for alleged relationship with criminal acts

      January 29, 2023
    • Politics
    • Business
    • Lifestyle
    • Tech
    • Sports
    • Travel
    • More
      • Entertainment
      • Videos
    en English
    en Englishes Españolfr Françaisde Deutschhi हिन्दीit Italianoja 日本語pt Portuguêsru Русскийzh-CN 简体中文
    West ObserverWest Observer
    Home » 3 Reasons Why You Shouldn’t Run Docker Without sudo

    3 Reasons Why You Shouldn’t Run Docker Without sudo

    December 8, 2022No Comments Lifestyle
    Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Docker is one of the most used containerization platforms and is highly loved among software engineers. It comes with a powerful CLI tool for managing Docker containers and other related tasks.


    By default, you need root privileges to run any Docker-related commands on Linux. Of course, you can change this for convenience and run Docker commands without root privileges, but you should be aware of the security implications.


    What Is the Docker Attack Surface?

    An attack surface is the number of attack points, more like the number of windows, that a malicious user can use to gain entry into your system and cause havoc. As a rule of thumb, IT systems should have minimal attack surfaces to reduce security risks.

    In general, Docker’s attack surface is very minimal. Containers run in a secure isolated environment and do not affect the host operating system unless otherwise. In addition, Docker containers only run minimal services which makes it more secure.

    You can configure your Linux system to control Docker without sudo privileges. This can be convenient in development environments but can be a serious security vulnerability in production systems. And here’s why you should never run Docker without sudo.

    1. Ability to Control Docker Containers

    Without the sudo privileges, anyone that has access to your system or server can control every aspect of Docker. They have access to your Docker log files and can stop and delete containers at will, or accidentally. You could also lose critical data which is vital for business continuity.

    If you are using Docker containers in production environments, downtime results in a loss of business and trust.

    2. Gain Control of the Host OS Directories

    Docker Volumes is a powerful service that allows you to share and persist container data by writing it to a specified folder on the host OS.

    One of the biggest threats that running Docker without sudo presents is that anyone on your system can gain control of the host OS’s directories, including the root directory.

    All you have to do is run a Linux Docker image, for example, the Ubuntu image, and mount it on the root folder using the following command:


    docker run -ti -v /:/hostproot ubuntu bash

    And since Linux Docker containers run as the root user, it essentially means that you have access to the entire root folder.

    The aforementioned command will download and run the latest Ubuntu image and mount it on the root directory.

    On the Docker container terminal, go to the /hostproot directory using the cd command:


    cd /hostproot

    Listing the contents of this directory using the ls command shows all files of the host OS which are now available in your container. Now, you can manipulate files, view secret files, hide and un-hide files, change permissions, etc.

    3. Install Malicious Software

    A well-crafted Docker image can run in the background and manipulate your system or gather sensitive data. Worse still, a malicious user could spread malicious code on your network via Docker containers.

    There are several practical use cases of Docker containers, and with each application comes a different set of security threats.

    Secure Your Docker Containers on Linux

    Docker is a powerful and secure platform. Running Docker without sudo increases your attack surface and makes your system vulnerable. In production environments, it is highly recommended that you should use sudo with Docker.

    With so many users on a system, it becomes extremely hard to assign permissions to each user. In such cases, following the best access control practices can help you maintain the security of your system.

    Source: Make Use Of

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email VKontakte WhatsApp

    Related Posts

    Spot vs. shelter dogs: Who will win the title of Goodest Boy?

    January 28, 2023

    L.A. Affairs: I love my husband but I also love dating women

    January 27, 2023

    The L.A. style education of Shiona Turini

    January 26, 2023

    How to see and help tiny blue butterflies in L.A.

    January 26, 2023

    Asian seniors should keep dancing — and other advice on how to rebuild after a tragedy

    January 26, 2023

    His long wonderful life is an inspiration, but aging means compromise, and it’s expensive

    January 22, 2023
    Don't Miss

    Djokovic Beats Tsitsipas for 10th Australian Open, 22nd Slam

    United States January 29, 2023

    Melbourne —  Novak Djokovic was simply too good at the most crucial moments and claimed…

    Protesters in the US condemn police brutality after the death of Tire Nichols

    January 29, 2023

    Moraes denies request to suspend deputies for alleged relationship with criminal acts

    January 29, 2023

    Arrested a man accused of two sexual assaults at the Feroz Awards party

    January 29, 2023
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Our Picks

    Macron remembers Amini as a “martyr” and calls for more action in defense of human rights

    January 29, 2023

    “Where did the money go ?” : Jamaica afflicted by Usain Bolt case, defrauded of 12 million dollars

    January 29, 2023

    “Have we become blind, to no longer discern the beauty in research and invention? »

    January 29, 2023

    Visit to NATO partners in Asia

    January 29, 2023

    Subscribe to Updates

    Get the latest news from USA, Canada and Europe directly to your inbox.

    About Us
    About Us

    Your #1 source for all the website news, follow USA, Europe and Canada News. Latest reports about business, politics and entertainment.

    We're accepting new partnerships right now.

    Email Us: [email protected]

    Facebook Twitter YouTube LinkedIn
    Our Picks

    Why desert golf courses and artificial lakes remain untouched by the Colorado River crisis

    January 29, 2023

    Boys’ basketball: Former rivals Dylan Black and Will Householter play in sync for Mira Costa

    January 29, 2023

    Djokovic Beats Tsitsipas for 10th Australian Open, 22nd Slam

    January 29, 2023
    Newsletter

    Subscribe to Updates

    Get the latest news from USA, Canada and Europe directly to your inbox.

    © 2023 West Observer. All Rights Reserved.
    • Privacy Policy
    • Terms
    • Contact
    • Khaleej Voice

    Type above and press Enter to search. Press Esc to cancel.