-
Notifications
You must be signed in to change notification settings - Fork 160
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
SECURITY: user admin password admin in the images #881
Comments
Hi, @antonio24073, these docker images are samples that we created in the past to serve as a reference, but they are not expected to be utilized in production setups. You can easily remove this |
Hi, It could have been avoided. It is clearly written to use these images in documentation. I didn't read anything in the installation telling you to create your own images based on this. Could you fix it? it's not even for me, it's for another careless person. Either removing the user or warning them not to use these images. What would be the base image for websites in production? Best regards, |
I also forgot to mention... I used this image in a dockerhub repository that currently has 2500 downloads. Best regards |
Hi @antonio24073, thanks for reporting. As @rodnymolina mentioned, the images are meant to be reference examples, but we take your point that this should be more clearly indicated. As an FYI, it's mentioned a bit in the Dockerfiles for each of the images, for example this one:
It's also mentioned in this README file:
However, to your point, given that we are embedding the user-id and password in some of sample images (so people can easily try them), I think we need a stronger notice to users. Any suggestions on how best to do this? |
Hi again, |
This user is not needed to enter the docker image with |
Thanks again for the feedback @antonio24073, we will improve it. |
Hi,
I was using an image derivated of "nestybox/ubuntu-jammy-systemd-docker:latest".
But I discovered that someone was entering in my docker images with ssh installing cryptocurrency zombies.
I discovered a user admin in all images in the production sites.
I tracked where this user came from and I got to this file:
https://github.com/nestybox/dockerfiles/blob/master/ubuntu-jammy-systemd/Dockerfile
There a user admin with password admin.
I would like to know if it is a good practice and if this password is needed or could I delete?
Best regards,
The text was updated successfully, but these errors were encountered: