Secrets at Sea: Hunting Exposed Code & Container Registries
Action | Key |
---|---|
Play / Pause | K or space |
Mute / Unmute | M |
Toggle fullscreen mode | F |
Select next subtitles | C |
Select next audio track | A |
Toggle automatic slides maximization | V |
Seek 5s backward | left arrow |
Seek 5s forward | right arrow |
Seek 10s backward | shift + left arrow or J |
Seek 10s forward | shift + right arrow or L |
Seek 60s backward | control + left arrow |
Seek 60s forward | control + right arrow |
Seek 1 frame backward | alt + left arrow |
Seek 1 frame forward | alt + right arrow |
Decrease volume | shift + down arrow |
Increase volume | shift + up arrow |
Decrease playback rate | < |
Increase playback rate | > |
Seek to end | end |
Seek to beginning | beginning |
Share this media
HLS video stream
You can use an external player to play this stream (like VLC).
HLS video streamWhen subscribed to notifications, an email will be sent to you for all added annotations.
Your user account has no email address.
Information on this media
Publicly accessible registries and repositories are often associated with well-known SaaS platforms such as GitHub or DockerHub. However, a significant number of individuals and companies rely on self-hosted solutions like GitLab or Harbor for managing their code and container images. Surprisingly, many of these self-hosted instances are inadvertently exposed, granting unauthenticated access to repositories and container images. This talk will explore methods for discovering publicly accessible self-hosted registries using techniques such as Certificate Transparency (CT) logs and Shodan scanning. We will discuss how to retrieve repository contents and container images from these sources, subsequently performing secrets scanning to assess the extent of exposure and raise awareness of potential security risks. From a tooling perspective, our investigation reveals a critical gap: most scanning tools fail to retrieve images from registries that are only available via plain HTTP. We will take this opportunity to discuss the registry API, and demonstrate approaches for interacting with it. Through real-world examples and hands-on insights, this talk aims to shed light on the current state of public registry exposure, providing actionable recommendations for improving security posture.
Other media in the channel "2025"
10 views, 10 this year, 10 this monthEXADPrinter: Exhaustive Permissionless Device Fingerprinting Within the Android EcosystemJuly 3rd, 2025
7 views, 7 this year, 7 this monthMetadata Protection in Instant Messaging Applications: a ReviewJuly 3rd, 2025
4 views, 4 this year, 4 this monthThe Even Darker Web - Dirty tricks and questionable code choices on some of the world's largest websitesJuly 4th, 2025
13 views, 13 this year, 13 this monthAnalyzing Microarchitectural Side-Channel Attacks Using Open-source gem5 simulatorJuly 3rd, 2025
8 views, 8 this year, 8 this monthFun with flags: How Compilers Break and Fix Constant-Time CodeJuly 3rd, 2025
9 views, 9 this year, 9 this monthRootAsRole: Simplifying Linux Privileges and Fortifying Ansible DeploymentsJuly 3rd, 2025