Skip to content
Sedat Özdemir

Posts on hardening

8 posts on hardening. Notes from public sources and my own test lab.

Docker's 'Privileged' Trap: Trojan Horses Inside Containers

Think that --privileged flag is a lifesaver? Think again. Here is how container misconfigurations turn into open doors for attackers, based on my early career blunders and Red Team field experience.

May 28, 2026·4 dk readcontainer-securitydevsecopshardening

From Docker Socket to Root Shell: Is Container Isolation an Illusion?

A deep dive into how misconfigured Docker containers, privileged flags, and exposed sockets turn your 'secure' environment into a playground for Red Teamers.

May 27, 2026·3 dk readcontainer-securitydevsecopsdocker

A Tale of Isolation and Container Chaos: Where Do We Go Wrong While Getting 'Dockerized'?

Think containers are inherently secure? Think again. From bloated base images to secret leaks in layers, let's explore how 'dockerized' applications actually fall apart and how to fix them.

May 16, 2026·4 dk readcontainer-securitydevsecopsdocker

The Day You Exposed Kube-apiserver to the Internet, You Handed Over the Keys to Your Cluster

If you aren't seeing 401 or 403 errors in your logs, you're either not being targeted or you're already compromised. Let's dive into the dirty realities of Kubernetes security and how to harden your cluster.

May 9, 2026·4 dk readcloud-nativedevsecopshardening

Is the Ship Sinking? Lost Security Between Container Layers and Lessons from the Field

Let’s debunk the myth that containers are inherently secure. From root user illusions to supply chain risks, I’m diving into why your 'isolated' environments might be more vulnerable than you think.

May 1, 2026·4 dk readcontainer-securitydevsecopsdocker

Loosening the Prison Bars: Docker Escape and the Art of Defense

A deep dive into why privileged containers are a Red Teamer's dream, how to spot escape routes like the Docker socket, and the right way to harden your containerized infrastructure.

April 29, 2026·4 dk readcontainer-securitydevsecopsdocker-escape

The Illusion of Container Isolation: Owning the Host via docker.sock

Think your containers are securely isolated? Think again. From exposed Docker sockets to unnecessary privileges, let's talk about how misconfigurations turn your secure containers into host-level backdoors.

April 13, 2026·3 dk readcontainer-securitydevsecopsdocker

Small Box, Big Trouble: Let’s Stop Romanticizing Alpine Linux

Think a 5MB container image makes you unhackable? Think again. We're diving into the myths of Alpine Linux and why your container's 'diet' might be making life easier for Red Teams.

March 17, 2026·4 dk readcontainersecuritydevsecopsdocker