Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

拉取的容器存在挖矿病毒 #15

Open
thlz998 opened this issue Jan 7, 2020 · 5 comments
Open

拉取的容器存在挖矿病毒 #15

thlz998 opened this issue Jan 7, 2020 · 5 comments

Comments

@thlz998
Copy link

thlz998 commented Jan 7, 2020

系统:Ubuntu

进程:kdevtmpfsi

启动之后,kdevtmpfsi进程会直接跑满cpu,重装服务器重新安装之后,kdevtmpfsi再次启动

@thlz998
Copy link
Author

thlz998 commented Jan 7, 2020

我停止了tools,病毒暂时没有启动,目前单独搞了个环境还在观察

@thlz998
Copy link
Author

thlz998 commented Jan 7, 2020

排查出来是redis容器,然后找到了这个

redis/docker-library-redis#217

@thlz998
Copy link
Author

thlz998 commented Jan 7, 2020

分析了一下原因,redis默认是没有密码的,绑定到宿主机之后,就等于对外网开发了,这时候外部网络就直接可以连接,导致了后边一系列的问题。

我目前的解决方案是清楚完所有的容器之后
①在redis的config文件中加上密码
②修改docker-compose里redis绑定到主机的端口
③配置防火墙

@usoftglobal
Copy link
Contributor

感谢,换个端口应该会好些

@544867814
Copy link

php镜像也有挖矿病毒

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants