From 9c3d34cb6736747171a08d2ff35bb69a61ed23d7 Mon Sep 17 00:00:00 2001 From: Omar Santos Date: Sun, 11 Apr 2021 17:31:55 -0400 Subject: [PATCH 1/2] Create docker-bench-websploit.sh --- .../docker/docker-bench-websploit.sh | 17 +++++++++++++++++ 1 file changed, 17 insertions(+) create mode 100644 docker-and-k8s-security/docker/docker-bench-websploit.sh diff --git a/docker-and-k8s-security/docker/docker-bench-websploit.sh b/docker-and-k8s-security/docker/docker-bench-websploit.sh new file mode 100644 index 0000000..ee5e0ba --- /dev/null +++ b/docker-and-k8s-security/docker/docker-bench-websploit.sh @@ -0,0 +1,17 @@ +# A quick script to run docker-bench-security in WebSploit Labs + +echo "Running docker-bench-security from WebSploit" + +docker run --rm --net host --pid host --userns host --cap-add audit_control \ + -e DOCKER_CONTENT_TRUST=$DOCKER_CONTENT_TRUST \ + -v /etc:/etc:ro \ + -v /lib/systemd/system:/lib/systemd/system:ro \ + -v /usr/bin/containerd:/usr/bin/containerd:ro \ + -v /usr/bin/runc:/usr/bin/runc:ro \ + -v /usr/lib/systemd:/usr/lib/systemd:ro \ + -v /var/lib:/var/lib:ro \ + -v /var/run/docker.sock:/var/run/docker.sock:ro \ + --label docker_bench_security \ + docker/docker-bench-security > bench_results.txt + +echo "The results have been stored at $(pwd)/bench_results.txt " \ No newline at end of file From 673271763eb5d47bf7d13d8beb4d23c2f23e7b0d Mon Sep 17 00:00:00 2001 From: Omar Santos Date: Sun, 11 Apr 2021 17:34:29 -0400 Subject: [PATCH 2/2] Update docker-bench-websploit.sh --- docker-and-k8s-security/docker/docker-bench-websploit.sh | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/docker-and-k8s-security/docker/docker-bench-websploit.sh b/docker-and-k8s-security/docker/docker-bench-websploit.sh index ee5e0ba..6124357 100644 --- a/docker-and-k8s-security/docker/docker-bench-websploit.sh +++ b/docker-and-k8s-security/docker/docker-bench-websploit.sh @@ -14,4 +14,6 @@ docker run --rm --net host --pid host --userns host --cap-add audit_control \ --label docker_bench_security \ docker/docker-bench-security > bench_results.txt -echo "The results have been stored at $(pwd)/bench_results.txt " \ No newline at end of file + +cat bench_results.txt +echo "The results have been stored at $(pwd)/bench_results.txt "