Does docker-compose insert a backdoor in it's containers?

Viewed 20

I was poking around in my docker container recently and I noticed some ports open and listening in it that I didn't set up myself. That concerns me as it could be an indication of some sort of supply-chain attack in action.

Here's how you can reproduce what I saw:

docker-compose.yml:

version: '3.3'
    
services:
    vis:
        image: ubuntu:22.04
$ docker-compose run vis bash -c 'apt update && apt install -y net-tools && netstat -tulpn'
Creating repo_vis_run ... done
Get:1 http://archive.ubuntu.com/ubuntu jammy InRelease [270 kB]                                          
Get:2 http://security.ubuntu.com/ubuntu jammy-security InRelease [110 kB]                                
Get:3 http://archive.ubuntu.com/ubuntu jammy-updates InRelease [114 kB]                
Get:4 http://security.ubuntu.com/ubuntu jammy-security/main amd64 Packages [305 kB]
Get:5 http://archive.ubuntu.com/ubuntu jammy-backports InRelease [99.8 kB]
Get:6 http://archive.ubuntu.com/ubuntu jammy/restricted amd64 Packages [164 kB]
Get:7 http://archive.ubuntu.com/ubuntu jammy/main amd64 Packages [1792 kB]
Get:8 http://security.ubuntu.com/ubuntu jammy-security/multiverse amd64 Packages [4644 B]
Get:9 http://security.ubuntu.com/ubuntu jammy-security/restricted amd64 Packages [276 kB]
Get:10 http://security.ubuntu.com/ubuntu jammy-security/universe amd64 Packages [129 kB]
Get:11 http://archive.ubuntu.com/ubuntu jammy/multiverse amd64 Packages [266 kB]         
Get:12 http://archive.ubuntu.com/ubuntu jammy/universe amd64 Packages [17.5 MB]
Get:13 http://archive.ubuntu.com/ubuntu jammy-updates/restricted amd64 Packages [354 kB]
Get:14 http://archive.ubuntu.com/ubuntu jammy-updates/multiverse amd64 Packages [7791 B]
Get:15 http://archive.ubuntu.com/ubuntu jammy-updates/universe amd64 Packages [253 kB]
Get:16 http://archive.ubuntu.com/ubuntu jammy-updates/main amd64 Packages [631 kB]
Get:17 http://archive.ubuntu.com/ubuntu jammy-backports/universe amd64 Packages [5814 B]
Fetched 22.3 MB in 6s (3609 kB/s)                                                                                          
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
1 package can be upgraded. Run 'apt list --upgradable' to see it.
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
The following NEW packages will be installed:
  net-tools
0 upgraded, 1 newly installed, 0 to remove and 1 not upgraded.
Need to get 204 kB of archives.
After this operation, 819 kB of additional disk space will be used.
Get:1 http://archive.ubuntu.com/ubuntu jammy/main amd64 net-tools amd64 1.60+git20181103.0eebece-1ubuntu5 [204 kB]
Fetched 204 kB in 3s (58.6 kB/s)    
debconf: delaying package configuration, since apt-utils is not installed
Selecting previously unselected package net-tools.
(Reading database ... 4395 files and directories currently installed.)
Preparing to unpack .../net-tools_1.60+git20181103.0eebece-1ubuntu5_amd64.deb ...
Unpacking net-tools (1.60+git20181103.0eebece-1ubuntu5) ...
Setting up net-tools (1.60+git20181103.0eebece-1ubuntu5) ...
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name    
tcp        0      0 127.0.0.11:40581        0.0.0.0:*               LISTEN      -                   
udp        0      0 127.0.0.11:49119        0.0.0.0:*                           -                   

Notice the two open ports. They seem to be different on every run of the container, but they're always binded to 127.0.0.11. That apparently is a loopback address, which theoretically means these ports are only open to my machine, but a similar exploit on my machine could relay info to the outside world.

Also note that running the same thing directly in a docker container (without docker-compose) does not result in open ports.

[andromodon@potens vis_container]$ docker run -it ubuntu:22.04 bash -c "apt update && apt install -y net-tools && netstat -tulpn"
Get:1 http://security.ubuntu.com/ubuntu jammy-security InRelease [110 kB]   
Get:2 http://archive.ubuntu.com/ubuntu jammy InRelease [270 kB]             
Get:3 http://archive.ubuntu.com/ubuntu jammy-updates InRelease [114 kB]
Get:4 http://archive.ubuntu.com/ubuntu jammy-backports InRelease [99.8 kB]
Get:5 http://security.ubuntu.com/ubuntu jammy-security/multiverse amd64 Packages [4644 B]
Get:6 http://archive.ubuntu.com/ubuntu jammy/universe amd64 Packages [17.5 MB]
Get:7 http://security.ubuntu.com/ubuntu jammy-security/restricted amd64 Packages [276 kB]
Get:8 http://security.ubuntu.com/ubuntu jammy-security/universe amd64 Packages [129 kB]
Get:9 http://security.ubuntu.com/ubuntu jammy-security/main amd64 Packages [305 kB]        
Get:10 http://archive.ubuntu.com/ubuntu jammy/restricted amd64 Packages [164 kB]          
Get:11 http://archive.ubuntu.com/ubuntu jammy/multiverse amd64 Packages [266 kB]
Get:12 http://archive.ubuntu.com/ubuntu jammy/main amd64 Packages [1792 kB]                                                
Get:13 http://archive.ubuntu.com/ubuntu jammy-updates/restricted amd64 Packages [354 kB]                                   
Get:14 http://archive.ubuntu.com/ubuntu jammy-updates/universe amd64 Packages [253 kB]                                     
Get:15 http://archive.ubuntu.com/ubuntu jammy-updates/multiverse amd64 Packages [7791 B]                                   
Get:16 http://archive.ubuntu.com/ubuntu jammy-updates/main amd64 Packages [631 kB]                                         
Get:17 http://archive.ubuntu.com/ubuntu jammy-backports/universe amd64 Packages [5814 B]                                   
Fetched 22.3 MB in 7s (3407 kB/s)                                                                                          
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
1 package can be upgraded. Run 'apt list --upgradable' to see it.
Reading package lists... Done
Building dependency tree... Done
Reading state information... Done
The following NEW packages will be installed:
  net-tools
0 upgraded, 1 newly installed, 0 to remove and 1 not upgraded.
Need to get 204 kB of archives.
After this operation, 819 kB of additional disk space will be used.
Get:1 http://archive.ubuntu.com/ubuntu jammy/main amd64 net-tools amd64 1.60+git20181103.0eebece-1ubuntu5 [204 kB]
Fetched 204 kB in 2s (96.1 kB/s)    
debconf: delaying package configuration, since apt-utils is not installed
Selecting previously unselected package net-tools.
(Reading database ... 4395 files and directories currently installed.)
Preparing to unpack .../net-tools_1.60+git20181103.0eebece-1ubuntu5_amd64.deb ...
Unpacking net-tools (1.60+git20181103.0eebece-1ubuntu5) ...
Setting up net-tools (1.60+git20181103.0eebece-1ubuntu5) ...
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name    

Does anyone know what's going on here and what these ports are for? If you can point to the code that's opening them I'll feel much more secure about this.

Thanks in advance for taking a look.

0 Answers
Related