Files
test/SECURITY-REPORT.md
2026-10-06 13:00:45 +00:00

1.2 KiB

攻击面探测报告

  • 时间: 2026-10-06T13:00:45Z

1. 内网服务横向(traefik-network 容器)

  • [安全] 不可达: postgres:5432
  • [安全] 不可达: idealjs_pg:5432
  • [安全] 不可达: redis:6379
  • [安全] 不可达: idealjs_redis:6379
  • [安全] 不可达: idealjs_gitea:3000
  • [安全] 不可达: idealjs_logto:3001
  • [安全] 不可达: idealjs_home:3000
  • [安全] 不可达: idealjs_journal:3000
  • [安全] 不可达: mysql:3306
  • [安全] 不可达: mongo:27017

2. 宿主机已发布端口

  • [!!] 可达: gitea.idealjs.com:22
  • [!!] 可达: gitea.idealjs.com:80
  • [!!] 可达: gitea.idealjs.com:443
  • [!!] 可达: gitea.idealjs.com:2333
  • [!!] 可达: gitea.idealjs.com:2222

3. docker.sock 突破

  • [!!] docker.sock 存在

4. 挂载宿主文件系统

  • [安全] mount 被拒绝(无 CAP_SYS_ADMIN)
  • [安全] /host 不存在
  • [安全] /hostroot 不存在

5. user namespace 提权

  • [安全] unshare 被拒绝

6. 窃取 runner 注册凭据

  • [安全] /data/.runner 不可见

7. job 环境敏感变量(只列名,不打印值)

  • 存在: ACTIONS_RUNTIME_TOKEN

8. 出网能力(CI 设计内)

  • gitea.idealjs.com: HTTP 200
  • aliyun registry: HTTP 200

附: capabilities

  • CapPrm: 00000000a80425fb
  • CapEff: 00000000a80425fb