Skip to content
This repository has been archived by the owner on Nov 12, 2021. It is now read-only.

Init script makes all Pictshare files world writable and executable #16

Open
Nutomic opened this issue Jun 5, 2020 · 3 comments
Open

Comments

@Nutomic
Copy link

Nutomic commented Jun 5, 2020

This is very bad for security.

https://github.com/HaschekSolutions/PictShare-Docker/blob/master/rootfs/pictshare.sh#L21

@Nutomic
Copy link
Author

Nutomic commented Jun 5, 2020

Wow that file is a disaster. Secretly downloading source code, not checking the hash and then running that? I'm actually speechless.

@geek-at
Copy link
Member

geek-at commented Jun 5, 2020

Not that secret if you ever restarted your container and looked at the logs. Also it's via https pointing to github.com so if the cert would fail in an mitm attack, the download wouldn't go through

@Nutomic
Copy link
Author

Nutomic commented Jun 9, 2020

Why are you marking the image files as executable and writeable by anyone? That is completely unnecessary (the chmod 777).

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants