For example, let's say I take this exact command from the gist:
docker run -e POSTGRES_PASSWORD=password -p 127.0.0.1:5432:5432 postgres
And run that on a VPS somewhere out in the world, let's say it's on a public IP address of 106.12.52.111 (I completely made up this IP address btw).How can you sitting on your dev box on a different network open a psql connection to 106.12.52.111 on port 5432 to the point where you haven't been blocked by iptables?
The part I don't get is the gist mentions:
> An attacker that sends traffic to 172.17.0.2:80 through the docker host will match the rule above and successfully connect to the container, obviating any security benefit of binding the published port on the host to 127.0.0.1. What's worse, users who bind their published ports to 127.0.0.1 operate under a false sense of security and may not bother taking further precautions against unintentional exposure.
In the above example how is someone going to send traffic to 172.17.0.2:80 through the Docker host from a box on a different network than the Docker host?
Also is this still exploitable if you drop everything at the iptables level before you start using Docker?
For example all of my iptables configs start with:
:INPUT DROP [0:0]
:FORWARD DROP [0:0]
:OUTPUT ACCEPT [0:0]