[{"Value":"","Discard":false,"Expires":9999999999}]
La entrada How to make Docker images more secure se publicó primero en CloudArch.
]]>
When we are writing our Dockerfile, Docker is using by default the root user to run the commands declared to create every layer in our image. Also, other times he copy and paste other Dockerfile templates which implicitly are using the root user by declaring this line:
USER rootEven this is redundant because Docker already uses it as default is not a good practice to keep that user. Instead, we should have our own user created for our specific purpose with only the needed permissions.
Even the Docker containers have certain level of isolation, we cannot forget Docker containers are still sharing the same kernel with the host, so using the root user in the wrong hands could end in a disaster.
The root user is not intended for ordinary tasks and should not be used for running our apps.
The best practice to follow is to create a new user and a new group for our service, and assignt to it the right permissions at system level.
In order to create the user, we can run the following layers on our Dockerfile:
# Create a custom user with UID 1234 and GID 1234
RUN groupadd -g 1234 customgroup && \
useradd -m -u 1234 -g customgroup customuser
# Switch to the custom user
USER customuserDid you like this post? Don’t forget to read other related posts, leave your comment and ask for more content!
La entrada How to make Docker images more secure se publicó primero en CloudArch.
]]>La entrada Run security tests on your webapps se publicó primero en CloudArch.
]]>
Security is not a matter only a department in IT should be take care of, it’s really important that our apps are security aware since their design to their implementation to avoid huge problems in the future.
In this example, we will be running tests using OWASP ZAP over a vulnerable site called Juice Shop which OWASP offers to do test and learn about this tool.
OWASP ZAP (Zed Attack Proxy) is a web app scanner. It’s free and open source and it’s actively maintaned by volunteers in Github. You can learn more about this tool in their official website.
As mentioned in the introduction, we will be using a web site designed for security testing called Juice Shop. This site has multiple vulnerabilities we may be able to detect using OWASP ZAP to learn how to use the tool properly.
OWASP provides us a docker image totally ready to just pull and run, so we can have the site up in just two very simple steps
# Pulling the image from the repository
docker pull bkimminich/juice-shop
# Running a container with the previous image maping the ports in our local machine to access it later
docker run --rm -p 3000:3000 bkimminich/juice-shop
Once we saw the previous output, we will be able to access the page from our localhost at port 3000: http://localhost:3000/#/

OWASP also provides us a docker image to run in our environment to execute our tests, and even automate it.
This tool also offers a GUI with plenty of information, however we will be covering only the command-line tool in this post.
Also, we will be setting the network as host, so we can reach the site running from our localhost. That step is not needed in case the Juice Shop is deployed somewhere else or it’s facing the public internet.
# Getting the image
docker pull softwaresecurityproject/zap-stable
# Running an interactive console in a container with the previous image
docker run -it --network=host softwaresecurityproject/zap-stable bashBefore starting running the scans, we are going to update ZAP and installing two addons:
Once we have installed those add-ons, we will be ready to scan our Juice Shop site previously deployed.
# Installing the add-ons and updating ZAP
./zap.sh -cmd -addonupdate -addoninstall wappalyzer -addoninstall pscanrulesBeta
# Executing the test on our Juice Shop site
./zap.sh -cmd -zapit http://localhost:3000After running the test we would be able to see some output with some useful information such as which technology the site is using and some problems sorted by level of criticality.

If you want to learn how to perform deeper tests or even integrate these tests with your CI/CD pipelines, stay tune for future posts where we were digging more into this topic.
Also, if you want to know more about automation, read other related posts in the blog.
La entrada Run security tests on your webapps se publicó primero en CloudArch.
]]>