Earlier quoted context omitted.
This affects podman too.
Not if you run it in rootless mode, which is more of a first class citizen in Podman compared to Docker.
Same as for docker, yes?
141–150 of 422 posts
Earlier quoted context omitted.
This affects podman too.
Not if you run it in rootless mode, which is more of a first class citizen in Podman compared to Docker.
Same as for docker, yes?
Still confused what I am supposed to do to avoid all this.
Learning to manage an operating system in full, and having a healthy amount of paranoia, is a good first step.
Next year is the 5th year of my current personal project. Ten to go.
Earlier quoted context omitted.
Is there a way to do that and still be able to access the server?
Yes, cloudflare tunnels do this, but I don't think it's really necessary for this. I use them for self-hosting.
> The Reddit post I’d seen earlier? That guy got completely owned because his container was running as root. The malware could: [...] Is that the case, though? My understanding was, that even if I run a docker container as root and the container is 100% compromised, there still would need to be a vulnerability in docker for it to “attack” the host, or am I missing something?
"CVE-2025-66478 - Next.js/Puppeteer RCE)"
> Here’s the test. If /tmp/.XIN-unix/javae exists on my host, I’m fucked. If it doesn’t exist, then what I’m seeing is just Docker’s default behavior of showing container processes in the host’s ps output, but they’re actually isolated. /tmp/.XIN-unix/javae & rm /tmp/.XIN-unix/javae This article’s LLM writing style is painful, and it’s full of misinformation (is Puppeteer even involved in the vulnerability?).
Yeah fair, I asked claude to help because honestly this was a little beyond my writing skills. I'm real though. Sorry. Will change
It has since been fixed: Lesson learned.
I wouldn't trust that boot image or storage again, I'd nuke it for peace of mind. That said, do you have an image of the box or a container image? I'm curious about it.
Yeah I did consider just killing it, I'm going to keep an eye on it for a few days with a gun to it just in case. I was lucky in that my DB backups were working so all my persistence wax backed up to S3. I think I could stand up another one in an hour. Unfortunately I didn't keep an image no. I almost didn't have the foresight to investigate before yeeting the whole box into the sun!
Not proof read by a human. It claims more than once the vulnerability was related to Puppeteer. Hallucination! "CVE-2025-66478 - Next.js/Puppeteer RCE)"