Hacking Articles Tips Tricks Videos Tutorials
dive_4_demo-778677.gif
KitPloit - PenTest Tools!
Dive - A Tool For Exploring Each Layer In A Docker Image
http://3.bp.blogspot.com/-jY8vytUej2s/Yd0cA00InbI/AAAAAAAA8a8/00PdXF346cs7bXgFNqwMMFAhfsq5XKZpgCK4BGAYYCw/w640-h400/dive_4_demo-778677.gif A tool for exploring a docker image, layer contents, and discovering ways to shrink the size of your Docker/OCI image.
To analyze a Docker image simply run dive with an image tag/id/digest: dive or if you want to build your image then jump straight into analyzing it: dive build -t Building on Macbook (supporting only the Docker container engine)
docker run --rm -it \
-v /var/run/docker.sock:/var/run/docker.sock \
-v "$(pwd)":"$(pwd)" \
-w "$(pwd)" \
-v "$HOME/.dive.yaml":"$HOME/.dive.yaml" \
wagoodman/dive:latest build -t
Additionally you can run this in your CI pipeline to ensure you're keeping wasted space to a minimum (this skips the UI): CI=true dive http://4.bp.blogspot.com/-PbsUesOm8uQ/Yd0cBGawlQI/AAAAAAAA8bE/EdM9Ebp3_h0rQ_R4PmAt7TsvlmghNByeQCK4BGAYYCw/w640-h382/dive_5_demo-ci-780139.png This is beta quality! Feel free to submit an issue if you want a new feature or find a bug :) Basic FeaturesShow Docker image contents broken down by layer
As you select a layer on the left, you are shown the contents of that layer combined with all previous layers on the right. Also, you can fully explore the file tree with the arrow keys.
Indicate what's changed in each layer
Files that have changed, been modified, added, or removed are indicated in the file tree. This can be adjusted to show changes for a specific layer, or aggregated changes up to this layer.
Estimate "image efficiency"
The lower left pane shows basic layer info and an experimental metric that will guess how much wasted space your image contains. This might be from duplicating files across layers, moving files across layers, or not fully removing files. Both a percentage "score" and total wasted file space is provided.
Quick build/analysis cycles
You can build a Docker image and do an immediate analysis with one command:
CI Integration
Analyze an image and get a pass/fail result based on the image efficiency and wasted space. Simply set
Multiple Image Sources and Container Engines Supported
With the
*
*
*
Available as dive in the Arch User Repository (AUR).
Mac
If you use Homebrew:
Windows
Download the latest release.
Go tools Requires Go version 1.10 or higher.
___________________________
@hacking_Attack
@Hacking_Video
Dive - A Tool For Exploring Each Layer In A Docker Image
http://3.bp.blogspot.com/-jY8vytUej2s/Yd0cA00InbI/AAAAAAAA8a8/00PdXF346cs7bXgFNqwMMFAhfsq5XKZpgCK4BGAYYCw/w640-h400/dive_4_demo-778677.gif A tool for exploring a docker image, layer contents, and discovering ways to shrink the size of your Docker/OCI image.
To analyze a Docker image simply run dive with an image tag/id/digest: dive or if you want to build your image then jump straight into analyzing it: dive build -t Building on Macbook (supporting only the Docker container engine)
docker run --rm -it \
-v /var/run/docker.sock:/var/run/docker.sock \
-v "$(pwd)":"$(pwd)" \
-w "$(pwd)" \
-v "$HOME/.dive.yaml":"$HOME/.dive.yaml" \
wagoodman/dive:latest build -t
Additionally you can run this in your CI pipeline to ensure you're keeping wasted space to a minimum (this skips the UI): CI=true dive http://4.bp.blogspot.com/-PbsUesOm8uQ/Yd0cBGawlQI/AAAAAAAA8bE/EdM9Ebp3_h0rQ_R4PmAt7TsvlmghNByeQCK4BGAYYCw/w640-h382/dive_5_demo-ci-780139.png This is beta quality! Feel free to submit an issue if you want a new feature or find a bug :) Basic FeaturesShow Docker image contents broken down by layer
As you select a layer on the left, you are shown the contents of that layer combined with all previous layers on the right. Also, you can fully explore the file tree with the arrow keys.
Indicate what's changed in each layer
Files that have changed, been modified, added, or removed are indicated in the file tree. This can be adjusted to show changes for a specific layer, or aggregated changes up to this layer.
Estimate "image efficiency"
The lower left pane shows basic layer info and an experimental metric that will guess how much wasted space your image contains. This might be from duplicating files across layers, moving files across layers, or not fully removing files. Both a percentage "score" and total wasted file space is provided.
Quick build/analysis cycles
You can build a Docker image and do an immediate analysis with one command:
dive build -t some-tag .You only need to replace your docker buildcommand with the same dive buildcommand.CI Integration
Analyze an image and get a pass/fail result based on the image efficiency and wasted space. Simply set
CI=truein the environment when invoking any valid dive command.Multiple Image Sources and Container Engines Supported
With the
--sourceoption, you can select where to fetch the container image from: dive or dive ://With valid sourceoptions as such:*
docker: Docker engine (the default option)*
docker-archive: A Docker Tar Archive from disk*
podman: Podman engine (linux only) InstallationUbuntu/Debian wget https://github.com/wagoodman/dive/releases/download/v0.9.2/dive_0.9.2_linux_amd64.deb
sudo apt install ./dive_0.9.2_linux_amd64.debRHEL/Centos curl -OL https://github.com/wagoodman/dive/releases/download/v0.9.2/dive_0.9.2_linux_amd64.rpm
rpm -i dive_0.9.2_linux_amd64.rpmArch LinuxAvailable as dive in the Arch User Repository (AUR).
yay -S diveThe above example assumes yayas the tool for installing AUR packages.Mac
If you use Homebrew:
brew install diveIf you use MacPorts: sudo port install diveOr download the latest Darwin build from the releases page.Windows
Download the latest release.
Go tools Requires Go version 1.10 or higher.
go get github.com/wagoodman/diveNote: installing in this way you will not see a proper version [...]___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Dive - A Tool For Exploring Each Layer In A Docker Image
KitPloit - PenTest Tools!
Dive - A Tool For Exploring Each Layer In A Docker Image
___________________________
@hacking_Attack
@Hacking_Video
Dive - A Tool For Exploring Each Layer In A Docker Image
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Dive - A Tool For Exploring Each Layer In A Docker Image
QRCDR Path Traversal Vulnerability
QRCDR is a popular PHP — JavaScript QR-Code Generator, which is widely used for creating customized QR-Code in easy steps. also, it’s used…Continue reading on Medium »
Read more...
QRCDR is a popular PHP — JavaScript QR-Code Generator, which is widely used for creating customized QR-Code in easy steps. also, it’s used…Continue reading on Medium »
Read more...
Hacking ticketastic
https://medium.com/@noli.mtz/hacking-ticketastic-b8b08fac79e2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@noli.mtz/hacking-ticketastic-b8b08fac79e2?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking ticketastic
Hi guys! I’m back with another great blog, with this blog you can learn more about SQLi and Cross Site Request Forgery (CSRF).
Hi guys! I’m back with another great blog, with this blog you can learn more about SQLi and Cross Site Request Forgery (CSRF).Continue reading on Medium » (https://medium.com/@noli.mtz/hacking-ticketastic-b8b08fac79e2?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Hacking ticketastic
Hi guys! I’m back with another great blog, with this blog you can learn more about SQLi and Cross Site Request Forgery (CSRF).
QRCDR Path Traversal Vulnerability
https://n0lsec.medium.com/qrcdr-path-traversal-vulnerability-bb89acc0c100?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://n0lsec.medium.com/qrcdr-path-traversal-vulnerability-bb89acc0c100?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
QRCDR Path Traversal Vulnerability
QRCDR is a popular PHP — JavaScript QR-Code Generator, which is widely used for creating customized QR-Code in easy steps. also, it’s used…
QRCDR is a popular PHP — JavaScript QR-Code Generator, which is widely used for creating customized QR-Code in easy steps.
also, it’s used…Continue reading on Medium » (https://n0lsec.medium.com/qrcdr-path-traversal-vulnerability-bb89acc0c100?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
also, it’s used…Continue reading on Medium » (https://n0lsec.medium.com/qrcdr-path-traversal-vulnerability-bb89acc0c100?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
Medium
QRCDR Path Traversal Vulnerability
QRCDR is a popular PHP — JavaScript QR-Code Generator, which is widely used for creating customized QR-Code in easy steps. also, it’s used…
Adding customers to victim’s store via Insecure Direct Object Reference
Hello! I am back with my 2nd bug bounty write up. This time I’ll be showing you how I found an Insecure Direct Object Reference bug on an…Continue reading on Medium »
Read more...
Hello! I am back with my 2nd bug bounty write up. This time I’ll be showing you how I found an Insecure Direct Object Reference bug on an…Continue reading on Medium »
Read more...
Adding customers to victim’s store via Insecure Direct Object Reference
https://medium.com/@ba7manhacks/adding-customers-to-victims-store-via-insecure-direct-object-reference-6359d9069523?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
https://medium.com/@ba7manhacks/adding-customers-to-victims-store-via-insecure-direct-object-reference-6359d9069523?source=rss------bug_bounty-5
___________________________
@hacking_Attack
@Hacking_Video
Medium
Adding customers to victim’s store via Insecure Direct Object Reference
Hello! I am back with my 2nd bug bounty write up. This time I’ll be showing you how I found an Insecure Direct Object Reference bug on an…
Hello! I am back with my 2nd bug bounty write up. This time I’ll be showing you how I found an Insecure Direct Object Reference bug on an…Continue reading on Medium » (https://medium.com/@ba7manhacks/adding-customers-to-victims-store-via-insecure-direct-object-reference-6359d9069523?source=rss------bug_bounty-5)
___________________________
@hacking_Attack
@Hacking_Video
___________________________
@hacking_Attack
@Hacking_Video
Medium
Adding customers to victim’s store via Insecure Direct Object Reference
Hello! I am back with my 2nd bug bounty write up. This time I’ll be showing you how I found an Insecure Direct Object Reference bug on an…
Dive - A Tool For Exploring Each Layer In A Docker Image
http://www.kitploit.com/2022/02/dive-tool-for-exploring-each-layer-in.html
___________________________
@hacking_Attack
@Hacking_Video
http://www.kitploit.com/2022/02/dive-tool-for-exploring-each-layer-in.html
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Dive - A Tool For Exploring Each Layer In A Docker Image
A tool for exploring a docker image, layer contents, and discovering ways to shrink the size of your Docker/OCI image.
To analyze a Docker image simply run dive with an image tag/id/digest: dive or if you want to build your image then jump straight into analyzing it: dive build -t . Building on Macbook (supporting only the Docker container engine) .'>docker run --rm -it \
-v /var/run/docker.sock:/var/run/docker.sock \
-v "$(pwd)":"$(pwd)" \
-w "$(pwd)" \
-v "$HOME/.dive.yaml":"$HOME/.dive.yaml" \
wagoodman/dive:latest build -t . Additionally you can run this in your CI pipeline (https://www.kitploit.com/search/label/Pipeline) to ensure you're keeping wasted space to a minimum (this skips the UI): CI=true dive
___________________________
@hacking_Attack
@Hacking_Video
To analyze a Docker image simply run dive with an image tag/id/digest: dive or if you want to build your image then jump straight into analyzing it: dive build -t . Building on Macbook (supporting only the Docker container engine) .'>docker run --rm -it \
-v /var/run/docker.sock:/var/run/docker.sock \
-v "$(pwd)":"$(pwd)" \
-w "$(pwd)" \
-v "$HOME/.dive.yaml":"$HOME/.dive.yaml" \
wagoodman/dive:latest build -t . Additionally you can run this in your CI pipeline (https://www.kitploit.com/search/label/Pipeline) to ensure you're keeping wasted space to a minimum (this skips the UI): CI=true dive
___________________________
@hacking_Attack
@Hacking_Video
KitPloit - PenTest & Hacking Tools
Leading source of security tools, hacking tools, cybersecurity and network security. Learn about new tools and updates in one place.
sudo apt install ./dive_0.9.2_linux_amd64.deb RHEL/Centos curl -OL https://github.com/wagoodman/dive/releases/download/v0.9.2/dive_0.9.2_linux_amd64.rpm
rpm -i dive_0.9.2_linux_amd64.rpm Arch Linux Available as dive (https://aur.archlinux.org/packages/dive/) in the Arch User Repository (AUR). yay -S dive The above example assumes yay as the tool for installing AUR packages. Mac If you use Homebrew (https://brew.sh/): brew install dive If you use MacPorts (https://www.macports.org/): sudo port install dive Or download the latest Darwin build from the releases page (https://github.com/wagoodman/dive/releases/download/v0.9.2/dive_0.9.2_darwin_amd64.tar.gz). Windows Download the latest release (https://github.com/wagoodman/dive/releases/download/v0.9.2/dive_0.9.2_windows_amd64.zip). Go tools Requires Go version 1.10 or higher. go get github.com/wagoodman/dive Note: installing in this way you will not see a proper version when running dive -v. Docker docker pull wagoodman/dive or docker pull quay.io/wagoodman/dive When running you'll need to include the docker socket file: ">docker run --rm -it \
-v /var/run/docker.sock:/var/run/docker.sock \
wagoodman/dive:latest Docker for Windows (showing PowerShell (https://www.kitploit.com/search/label/PowerShell) compatible line breaks; collapse to a single line for Command Prompt compatibility) ">docker run --rm -it `
-v /var/run/docker.sock:/var/run/docker.sock `
wagoodman/dive:latest Note: depending on the version of docker you are running locally you may need to specify the docker API version as an environment variable: DOCKER_API_VERSION=1.37 dive ... or if you are running with a docker image: ">docker run --rm -it \
-v /var/run/docker.sock:/var/run/docker.sock \
-e DOCKER_API_VERSION=1.37 \
wagoodman/dive:latest CI Integration When running dive with the environment variable CI=true then the dive UI will be bypassed and will instead analyze your docker image, giving it a pass/fail indication via return code. Currently there are three metrics supported via a .dive-ci file that you can put at the root of your repo: rules:
# If the efficiency is measured below X%, mark as failed.
# Expressed as a ratio between 0-1.
lowestEfficiency: 0.95
# If the amount of wasted space is at least X or larger than X, mark as failed.
# Expressed in B, KB, MB, and GB.
highestWastedBytes: 20MB
# If the amount of wasted space makes up for X% or more of the image, mark as failed.
# Note: the base image layer is NOT included in the total image size.
# Expressed as a ratio between 0-1; fails if the threshold is met or crossed.
highestUserWastedPercent: 0.20
You can override (https://www.kitploit.com/search/label/OverRide) the CI config path with the --ci-config option. KeyBindings Key Binding Description Ctrl + C Exit Tab Switch between the layer and filetree views Ctrl + F Filter files PageUp Scroll up a page PageDown Scroll down a page Ctrl + A Layer view: see aggregated image modifications Ctrl + L Layer view: see current layer modifications Space Filetree view: collapse/uncollapse a directory Ctrl + Space Filetree view: collapse/uncollapse all directories Ctrl + A Filetree view: show/hide added files Ctrl + R Filetree view: show/hide removed files Ctrl + M Filetree view: show/hide modified files Ctrl + U Filetree view: show/hide unmodified files Ctrl + B Filetree view: show/hide file attributes PageUp Filetree view: scroll up a page PageDown Filetree view: scroll down a page UI Configuration No configuration is necessary, however, you can create a config file and override values: 0 and # supported options are "docker" and "podman"
container-engine: docker
# continue with analysis even if there are errors parsing the image archive
ignore-errors: false
log:
enabled: true
path: ./dive.log
level: info
___________________________
@hacking_Attack
@Hacking_Video
rpm -i dive_0.9.2_linux_amd64.rpm Arch Linux Available as dive (https://aur.archlinux.org/packages/dive/) in the Arch User Repository (AUR). yay -S dive The above example assumes yay as the tool for installing AUR packages. Mac If you use Homebrew (https://brew.sh/): brew install dive If you use MacPorts (https://www.macports.org/): sudo port install dive Or download the latest Darwin build from the releases page (https://github.com/wagoodman/dive/releases/download/v0.9.2/dive_0.9.2_darwin_amd64.tar.gz). Windows Download the latest release (https://github.com/wagoodman/dive/releases/download/v0.9.2/dive_0.9.2_windows_amd64.zip). Go tools Requires Go version 1.10 or higher. go get github.com/wagoodman/dive Note: installing in this way you will not see a proper version when running dive -v. Docker docker pull wagoodman/dive or docker pull quay.io/wagoodman/dive When running you'll need to include the docker socket file: ">docker run --rm -it \
-v /var/run/docker.sock:/var/run/docker.sock \
wagoodman/dive:latest Docker for Windows (showing PowerShell (https://www.kitploit.com/search/label/PowerShell) compatible line breaks; collapse to a single line for Command Prompt compatibility) ">docker run --rm -it `
-v /var/run/docker.sock:/var/run/docker.sock `
wagoodman/dive:latest Note: depending on the version of docker you are running locally you may need to specify the docker API version as an environment variable: DOCKER_API_VERSION=1.37 dive ... or if you are running with a docker image: ">docker run --rm -it \
-v /var/run/docker.sock:/var/run/docker.sock \
-e DOCKER_API_VERSION=1.37 \
wagoodman/dive:latest CI Integration When running dive with the environment variable CI=true then the dive UI will be bypassed and will instead analyze your docker image, giving it a pass/fail indication via return code. Currently there are three metrics supported via a .dive-ci file that you can put at the root of your repo: rules:
# If the efficiency is measured below X%, mark as failed.
# Expressed as a ratio between 0-1.
lowestEfficiency: 0.95
# If the amount of wasted space is at least X or larger than X, mark as failed.
# Expressed in B, KB, MB, and GB.
highestWastedBytes: 20MB
# If the amount of wasted space makes up for X% or more of the image, mark as failed.
# Note: the base image layer is NOT included in the total image size.
# Expressed as a ratio between 0-1; fails if the threshold is met or crossed.
highestUserWastedPercent: 0.20
You can override (https://www.kitploit.com/search/label/OverRide) the CI config path with the --ci-config option. KeyBindings Key Binding Description Ctrl + C Exit Tab Switch between the layer and filetree views Ctrl + F Filter files PageUp Scroll up a page PageDown Scroll down a page Ctrl + A Layer view: see aggregated image modifications Ctrl + L Layer view: see current layer modifications Space Filetree view: collapse/uncollapse a directory Ctrl + Space Filetree view: collapse/uncollapse all directories Ctrl + A Filetree view: show/hide added files Ctrl + R Filetree view: show/hide removed files Ctrl + M Filetree view: show/hide modified files Ctrl + U Filetree view: show/hide unmodified files Ctrl + B Filetree view: show/hide file attributes PageUp Filetree view: scroll up a page PageDown Filetree view: scroll down a page UI Configuration No configuration is necessary, however, you can create a config file and override values: 0 and # supported options are "docker" and "podman"
container-engine: docker
# continue with analysis even if there are errors parsing the image archive
ignore-errors: false
log:
enabled: true
path: ./dive.log
level: info
___________________________
@hacking_Attack
@Hacking_Video
# Note: you can specify multiple bindings by separating values with a comma.
# Note: UI hinting is derived from the first binding
keybinding:
# Global bindings
quit: ctrl+c
toggle-view: tab
filter-files: ctrl+f, ctrl+slash
# Layer view specific bindings
compare-all: ctrl+a
compare-layer: ctrl+l
# File view specific bindings
toggle-collapse-dir: space
toggle-collapse-all-dir: ctrl+space
toggle-added-files: ctrl+a
toggle-removed-files: ctrl+r
toggle-modified-files: ctrl+m
toggle-unmodified-files: ctrl+u
toggle-filetree-attributes: ctrl+b
page-up: pgup
page-down: pgdn
diff:
# You can cha nge the default files shown in the filetree (right pane). All diff types are shown by default.
hide:
- added
- removed
- modified
- unmodified
filetree:
# The default directory-collapse state
collapse-dir: false
# The percentage of screen width the filetree should take on the screen (must be >0 and dive will search for configs in the following locations: $XDG_CONFIG_HOME/dive/*.yaml $XDG_CONFIG_DIRS/dive/*.yaml ~/.config/dive/*.yaml ~/.dive.yaml
Download Dive (https://github.com/wagoodman/dive)
___________________________
@hacking_Attack
@Hacking_Video
# Note: UI hinting is derived from the first binding
keybinding:
# Global bindings
quit: ctrl+c
toggle-view: tab
filter-files: ctrl+f, ctrl+slash
# Layer view specific bindings
compare-all: ctrl+a
compare-layer: ctrl+l
# File view specific bindings
toggle-collapse-dir: space
toggle-collapse-all-dir: ctrl+space
toggle-added-files: ctrl+a
toggle-removed-files: ctrl+r
toggle-modified-files: ctrl+m
toggle-unmodified-files: ctrl+u
toggle-filetree-attributes: ctrl+b
page-up: pgup
page-down: pgdn
diff:
# You can cha nge the default files shown in the filetree (right pane). All diff types are shown by default.
hide:
- added
- removed
- modified
- unmodified
filetree:
# The default directory-collapse state
collapse-dir: false
# The percentage of screen width the filetree should take on the screen (must be >0 and dive will search for configs in the following locations: $XDG_CONFIG_HOME/dive/*.yaml $XDG_CONFIG_DIRS/dive/*.yaml ~/.config/dive/*.yaml ~/.dive.yaml
Download Dive (https://github.com/wagoodman/dive)
___________________________
@hacking_Attack
@Hacking_Video
GitHub
GitHub - wagoodman/dive: A tool for exploring each layer in a docker image
A tool for exploring each layer in a docker image. Contribute to wagoodman/dive development by creating an account on GitHub.