[{"Value":"","Discard":false,"Expires":9999999999}] Security archivos - CloudArch https://cloudarch.es/category/security/ Blog sobre arquitectura en la nube Mon, 12 Aug 2024 20:37:28 +0000 en-US hourly 1 https://wordpress.org/?v=7.1.3 https://cloudarch.es/wp-content/uploads/2024/02/cropped-CloudArch-1-32x32.png Security archivos - CloudArch https://cloudarch.es/category/security/ 32 32 228797714 How to make Docker images more secure https://cloudarch.es/how-to-make-docker-images-more-secure/ https://cloudarch.es/how-to-make-docker-images-more-secure/#respond Mon, 12 Aug 2024 20:37:24 +0000 https://cloudarch.es/?p=578 Nowadays many of us work in daily basis with Docker, and we create our own Docker images with Dockerfile. However, […]

La entrada How to make Docker images more secure se publicó primero en CloudArch.

]]>
Nowadays many of us work in daily basis with Docker, and we create our own Docker images with Dockerfile. However, do you know how to make Docker images more secure?

When we are writing our Dockerfile, Docker is using by default the root user to run the commands declared to create every layer in our image. Also, other times he copy and paste other Dockerfile templates which implicitly are using the root user by declaring this line:

USER root

Even this is redundant because Docker already uses it as default is not a good practice to keep that user. Instead, we should have our own user created for our specific purpose with only the needed permissions.

Why this is not a good practice

Even the Docker containers have certain level of isolation, we cannot forget Docker containers are still sharing the same kernel with the host, so using the root user in the wrong hands could end in a disaster.

The root user is not intended for ordinary tasks and should not be used for running our apps.

How to make Docker images more secure

The best practice to follow is to create a new user and a new group for our service, and assignt to it the right permissions at system level.

In order to create the user, we can run the following layers on our Dockerfile:

# Create a custom user with UID 1234 and GID 1234
RUN groupadd -g 1234 customgroup && \
    useradd -m -u 1234 -g customgroup customuser
 
# Switch to the custom user
USER customuser

Did you like this post? Don’t forget to read other related posts, leave your comment and ask for more content!


La entrada How to make Docker images more secure se publicó primero en CloudArch.

]]>
https://cloudarch.es/how-to-make-docker-images-more-secure/feed/ 0 578
Run security tests on your webapps https://cloudarch.es/run-security-tests-on-your-webapps/ https://cloudarch.es/run-security-tests-on-your-webapps/#respond Mon, 29 Jul 2024 09:27:29 +0000 https://cloudarch.es/?p=560 Day after day we receive more news about another company or website being hacked and millions of users’ data being […]

La entrada Run security tests on your webapps se publicó primero en CloudArch.

]]>
Day after day we receive more news about another company or website being hacked and millions of users’ data being stolen. That’s why in this post we are going to learn how to run security tests on your webapps.

Security is not a matter only a department in IT should be take care of, it’s really important that our apps are security aware since their design to their implementation to avoid huge problems in the future.

In this example, we will be running tests using OWASP ZAP over a vulnerable site called Juice Shop which OWASP offers to do test and learn about this tool.

What is OWASP ZAP

OWASP ZAP (Zed Attack Proxy) is a web app scanner. It’s free and open source and it’s actively maintaned by volunteers in Github. You can learn more about this tool in their official website.

Deploying Juice Shop

As mentioned in the introduction, we will be using a web site designed for security testing called Juice Shop. This site has multiple vulnerabilities we may be able to detect using OWASP ZAP to learn how to use the tool properly.

OWASP provides us a docker image totally ready to just pull and run, so we can have the site up in just two very simple steps

# Pulling the image from the repository
docker pull bkimminich/juice-shop

# Running a container with the previous image maping the ports in our local machine to access it later
docker run --rm -p 3000:3000 bkimminich/juice-shop

Once we saw the previous output, we will be able to access the page from our localhost at port 3000: http://localhost:3000/#/

Installing OWASP ZAP

OWASP also provides us a docker image to run in our environment to execute our tests, and even automate it.

This tool also offers a GUI with plenty of information, however we will be covering only the command-line tool in this post.

Also, we will be setting the network as host, so we can reach the site running from our localhost. That step is not needed in case the Juice Shop is deployed somewhere else or it’s facing the public internet.

# Getting the image
docker pull softwaresecurityproject/zap-stable

# Running an interactive console in a container with the previous image
docker run -it --network=host softwaresecurityproject/zap-stable bash

Executing our first test

Before starting running the scans, we are going to update ZAP and installing two addons:

  • Wappalyzer = this is a technology detection add-on. It detects what the app is actually using.
  • Passive Scan Rules = this is the add-on that would help us to scan the web sites.

Once we have installed those add-ons, we will be ready to scan our Juice Shop site previously deployed.

# Installing the add-ons and updating ZAP
./zap.sh -cmd -addonupdate -addoninstall wappalyzer -addoninstall pscanrulesBeta

# Executing the test on our Juice Shop site
./zap.sh -cmd -zapit http://localhost:3000

After running the test we would be able to see some output with some useful information such as which technology the site is using and some problems sorted by level of criticality.

Farewell

If you want to learn how to perform deeper tests or even integrate these tests with your CI/CD pipelines, stay tune for future posts where we were digging more into this topic.

Also, if you want to know more about automation, read other related posts in the blog.

La entrada Run security tests on your webapps se publicó primero en CloudArch.

]]>
https://cloudarch.es/run-security-tests-on-your-webapps/feed/ 0 560