*** dave-mccowan has joined #openstack-security | 00:01 | |
*** M00nr41n has joined #openstack-security | 00:33 | |
*** M00nr41n has left #openstack-security | 00:33 | |
*** M00nr41n has joined #openstack-security | 00:36 | |
*** dave-mccowan has quit IRC | 00:52 | |
*** yuanying has quit IRC | 01:00 | |
*** M00nr41n has quit IRC | 01:15 | |
*** M00nr41n has joined #openstack-security | 02:04 | |
*** dave-mccowan has joined #openstack-security | 02:29 | |
*** yarkot1 has joined #openstack-security | 02:30 | |
*** M00nr41n has quit IRC | 03:12 | |
*** dave-mccowan has quit IRC | 03:45 | |
*** yuanying has joined #openstack-security | 04:08 | |
*** markvoelker has joined #openstack-security | 04:18 | |
*** M00nr41n has joined #openstack-security | 04:21 | |
*** markvoelker has quit IRC | 04:22 | |
*** rcernin has joined #openstack-security | 06:13 | |
*** markvoelker has joined #openstack-security | 06:18 | |
*** markvoelker has quit IRC | 06:23 | |
*** pcaruana has joined #openstack-security | 06:24 | |
*** liverpooler has joined #openstack-security | 06:59 | |
*** agireud has quit IRC | 08:06 | |
*** agireud has joined #openstack-security | 08:12 | |
*** agireud has quit IRC | 08:17 | |
*** markvoelker has joined #openstack-security | 08:19 | |
*** markvoelker has quit IRC | 08:24 | |
*** agireud has joined #openstack-security | 08:28 | |
*** yuanying has quit IRC | 08:31 | |
*** yuanying has joined #openstack-security | 09:48 | |
*** shakamunyi has quit IRC | 09:48 | |
*** shakamunyi has joined #openstack-security | 09:56 | |
*** hyakuhei has quit IRC | 10:03 | |
*** hyakuhei has joined #openstack-security | 10:03 | |
*** hyakuhei has joined #openstack-security | 10:03 | |
*** yuanying has quit IRC | 10:17 | |
*** markvoelker has joined #openstack-security | 10:20 | |
*** markvoelker has quit IRC | 10:24 | |
*** rcernin is now known as rcernin|lunch | 10:37 | |
*** yuanying has joined #openstack-security | 10:44 | |
*** yuanying has quit IRC | 10:45 | |
*** yuanying has joined #openstack-security | 10:51 | |
*** yuanying has quit IRC | 10:55 | |
*** yuanying has joined #openstack-security | 10:59 | |
*** yuanying has quit IRC | 11:01 | |
*** yuanying has joined #openstack-security | 11:13 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/331626 | 11:18 |
---|---|---|
*** yuanying has quit IRC | 11:19 | |
*** yuanying has joined #openstack-security | 11:20 | |
*** yuanying has quit IRC | 11:22 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/331626 | 11:26 |
*** yuanying has joined #openstack-security | 11:35 | |
*** yuanying has quit IRC | 11:37 | |
*** yuanying has joined #openstack-security | 11:39 | |
*** yuanying has quit IRC | 11:44 | |
*** rcernin|lunch is now known as rcernin | 11:53 | |
*** dave-mccowan has joined #openstack-security | 12:06 | |
*** yuanying has joined #openstack-security | 12:09 | |
*** yuanying has quit IRC | 12:12 | |
*** markvoelker has joined #openstack-security | 12:12 | |
*** agireud has quit IRC | 12:13 | |
*** LongyanG has quit IRC | 12:14 | |
*** LongyanG has joined #openstack-security | 12:14 | |
*** agireud has joined #openstack-security | 12:16 | |
*** B_Smith has quit IRC | 12:22 | |
*** yuanying has joined #openstack-security | 12:28 | |
*** B_Smith has joined #openstack-security | 12:28 | |
*** yuanying has quit IRC | 12:31 | |
*** B_Smith has quit IRC | 12:32 | |
*** yuanying has joined #openstack-security | 12:32 | |
*** B_Smith has joined #openstack-security | 12:33 | |
*** liverpooler has quit IRC | 12:35 | |
*** tkelsey has joined #openstack-security | 12:38 | |
*** yuanying has quit IRC | 12:43 | |
*** aurelien__ has joined #openstack-security | 12:51 | |
*** aurelien__ has quit IRC | 12:59 | |
*** yuanying has joined #openstack-security | 13:05 | |
*** yuanying has quit IRC | 13:09 | |
*** edmondsw has joined #openstack-security | 13:15 | |
*** liverpooler has joined #openstack-security | 13:44 | |
*** M00nr41n has quit IRC | 13:58 | |
*** _sigmavirus24 is now known as sigmavirus24 | 14:00 | |
*** sigmavirus24 has joined #openstack-security | 14:00 | |
*** canaimro1234 has joined #openstack-security | 14:18 | |
*** canaimro1234 has quit IRC | 14:18 | |
*** vinaypotluri has joined #openstack-security | 14:31 | |
*** mvaldes has joined #openstack-security | 14:35 | |
*** jhfeng has joined #openstack-security | 14:37 | |
*** zul_ is now known as zul | 14:40 | |
*** austin987 has quit IRC | 15:32 | |
*** unrahul has joined #openstack-security | 15:40 | |
*** austin987 has joined #openstack-security | 15:44 | |
*** pcaruana has quit IRC | 15:45 | |
*** ccneill has joined #openstack-security | 15:49 | |
*** rcernin has quit IRC | 15:55 | |
*** zul has quit IRC | 16:00 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: signals check-file to fingerprint the SUT https://review.openstack.org/331340 | 16:03 |
*** M00nr41n has joined #openstack-security | 16:22 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: Moved SSL test out of BaseFuzzTestCase https://review.openstack.org/331288 | 16:26 |
*** ibravo has joined #openstack-security | 16:30 | |
*** mvaldes has quit IRC | 16:35 | |
*** mdong has joined #openstack-security | 16:37 | |
unrahul | Hey ccneill mdong vinaypotluri , for stacktrace detection checks, what approach should we choose...? | 16:50 |
ccneill | this is the approach tristanC took with his fuzzer: http://softwarefactory-project.io/r/gitweb?p=restfuzz.git;a=blob;f=restfuzz/health.py;h=3acb38fda92fd0c25f35c3c30e4ddb59fd2b46f6;hb=refs/heads/master | 16:51 |
ccneill | basically, look for the "cookie", then look for a well-formatted stacktrace | 16:52 |
ccneill | based on the length of lines | 16:52 |
tristanC | ccneill: heh, that code is really a proof of concept, but it does extract traceback from log files | 16:53 |
*** rcernin has joined #openstack-security | 16:53 | |
tristanC | and it compute a hash to check for uniq/new tracebacks | 16:53 |
ccneill | tristanC: I think we can at least use it as an example to start from for our purposes | 16:55 |
tristanC | ccneill: yes sure, it's quite handy for local inspection, feel free to borrow that code | 16:56 |
unrahul | tristanC: thank u, ccneill: agreed, it looks straightforward, I think its a good example to start working on ours.. | 16:56 |
tristanC | ideally you want a logstash gig to chop logs and index all api logs | 16:57 |
ccneill | tristanC: we'll just be analyzing responses from the API to see if they contain stacktraces, not actually looking at the stacktraces from the app node | 16:58 |
unrahul | ccneill: +1 tristanC: so I guess we don't need to really something like that, something simple and straightforward to get a possible signal on whats going on | 16:59 |
ccneill | unrahul: we don't necessarily have to parse the stacktrace into an actual structure, we just have to be relatively sure that there is one | 17:00 |
ccneill | I suppose we COULD go that far, but I don't know how much it buys us | 17:00 |
unrahul | ccneill: yup , yeah I also dont think that is really needed ryt now.. for the initial checks.. may be a value add sometime later. | 17:00 |
ccneill | tristanC: thank you by the way for writing up that blog post about your tool. I've been trying to figure out how we might be able to work together between our two tools | 17:01 |
tristanC | ccneill: that's very nice to hear, you're welcome! | 17:01 |
ccneill | tristanC: I think there are a lot of similarities, but we're each taking a slightly different approach | 17:01 |
tristanC | ccneill: my last work-in-progress on restfuzz was to add a "--printer" mode to just output http trace... perhaps this can be used to feed api call in syntribos. it's http://softwarefactory-project.io/r/#/c/2652/ | 17:03 |
ccneill | hmmm interesting | 17:04 |
ccneill | I'll look over it | 17:05 |
ccneill | ah so this is for spitting out raw HTTP requests generated by the YAML files? | 17:06 |
ccneill | that might be very handy indeed.. | 17:06 |
*** tkelsey has quit IRC | 17:07 | |
tristanC | ccneill: yep exactly. however to get interesting call you need valid uuid. | 17:07 |
ccneill | right. that's one thing we don't really have a notion of at this point is purposefully CRUDing objects | 17:07 |
ccneill | we just kind of slam the API with whatever we can come up with, but we don't have a structure of "this is what's expected by the API, and this is what we expect to receive as a response" | 17:08 |
ccneill | since we haven't really solved for SPECIFIC APIs, but more the general case | 17:08 |
ccneill | well | 17:08 |
ccneill | we do have a notion of what's expected in terms of variable names, etc., but they aren't distinct data types as in your tool | 17:09 |
ccneill | which might be something worth looking at for us at some point | 17:09 |
ccneill | brb | 17:09 |
tristanC | ccneill: it's important to keep a generic approach, but api that uses uuid really need a tool capable of inspecting or re-using valid uuid to test behind early checks | 17:14 |
*** rcernin has quit IRC | 17:18 | |
*** tkelsey has joined #openstack-security | 17:21 | |
ccneill | tristanC: yep, we definitely want to get there in the future | 17:21 |
ccneill | tristanC: makes it possible to test for stuff like stored XSS that we don't have a great answer for right now | 17:22 |
*** mdong has quit IRC | 17:28 | |
*** ametts has joined #openstack-security | 17:39 | |
*** ibravo has quit IRC | 17:41 | |
*** ibravo has joined #openstack-security | 17:42 | |
*** browne has joined #openstack-security | 17:52 | |
*** rcernin has joined #openstack-security | 17:52 | |
openstackgerrit | Charles Neill proposed openstack/syntribos: Creates SynSignal and SignalHolder classes https://review.openstack.org/331286 | 17:55 |
*** ibravo has quit IRC | 18:01 | |
*** ibravo has joined #openstack-security | 18:02 | |
*** ibravo has quit IRC | 18:03 | |
*** ibravo has joined #openstack-security | 18:04 | |
*** mvaldes has joined #openstack-security | 18:04 | |
*** ibravo has quit IRC | 18:07 | |
*** mdong has joined #openstack-security | 18:15 | |
*** shakamunyi has quit IRC | 18:17 | |
*** ccneill has quit IRC | 18:33 | |
*** ccneill has joined #openstack-security | 18:46 | |
*** xsallowed has joined #openstack-security | 18:48 | |
*** xsallowed has quit IRC | 18:48 | |
*** zul has joined #openstack-security | 18:53 | |
*** zul has quit IRC | 18:54 | |
*** zul has joined #openstack-security | 18:54 | |
*** tkelsey has quit IRC | 19:00 | |
*** mdong has quit IRC | 19:00 | |
*** mdong_ has joined #openstack-security | 19:01 | |
*** mdong_ is now known as mdong | 19:01 | |
*** jhfeng has quit IRC | 19:19 | |
*** davidjd-gh has joined #openstack-security | 19:25 | |
davidjd-gh | hola | 19:25 |
*** M00nr41n has quit IRC | 19:27 | |
*** davidjd-gh has quit IRC | 19:30 | |
mdong | hey ccneill: can I get a +1 workflow on the reporting change? | 19:33 |
ccneill | yeah, just wanted to make sure we were happy with it and didn't need to make any changes before +workflow | 19:33 |
ccneill | done | 19:41 |
openstackgerrit | Merged openstack/syntribos: Formatter now reports by issue rather than by test https://review.openstack.org/330244 | 19:45 |
openstackgerrit | Merged openstack/syntribos: Moved SSL test out of BaseFuzzTestCase https://review.openstack.org/331288 | 19:49 |
*** jhfeng has joined #openstack-security | 19:50 | |
openstackgerrit | Charles Neill proposed openstack/syntribos: Creates SynSignal and SignalHolder classes https://review.openstack.org/331286 | 20:16 |
*** zul has quit IRC | 20:18 | |
*** zul has joined #openstack-security | 20:22 | |
openstackgerrit | Charles Neill proposed openstack/syntribos: Creates SynSignal and SignalHolder classes https://review.openstack.org/331286 | 20:22 |
*** jhfeng has quit IRC | 20:24 | |
*** jhfeng has joined #openstack-security | 20:30 | |
*** rcernin has quit IRC | 20:31 | |
*** zul has quit IRC | 20:39 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: Simplified imports and added constants https://review.openstack.org/331831 | 20:42 |
*** ibravo2 has joined #openstack-security | 20:44 | |
*** ibravo2 has quit IRC | 20:49 | |
*** ibravo has joined #openstack-security | 20:50 | |
*** mvaldes has quit IRC | 20:50 | |
openstackgerrit | Charles Neill proposed openstack/syntribos: Modifies HTTP client to use checks/signals https://review.openstack.org/331833 | 20:51 |
*** jhfeng has quit IRC | 20:52 | |
*** jhfeng has joined #openstack-security | 20:53 | |
*** zul has joined #openstack-security | 20:57 | |
openstackgerrit | Charles Neill proposed openstack/syntribos: Modifies HTTP client to use checks/signals https://review.openstack.org/331833 | 21:10 |
*** zul has quit IRC | 21:14 | |
*** mvaldes has joined #openstack-security | 21:15 | |
*** zul has joined #openstack-security | 21:16 | |
*** salv-orlando has joined #openstack-security | 21:22 | |
*** zul has quit IRC | 21:25 | |
*** zul has joined #openstack-security | 21:31 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: signals check-file to fingerprint the SUT https://review.openstack.org/331340 | 21:42 |
*** mvaldes has quit IRC | 21:48 | |
*** ccneill has quit IRC | 21:55 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: signals check-file to fingerprint the SUT https://review.openstack.org/331340 | 21:56 |
*** tkelsey has joined #openstack-security | 21:59 | |
*** zul has quit IRC | 22:03 | |
*** tkelsey has quit IRC | 22:03 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 22:04 | |
*** edmondsw has quit IRC | 22:07 | |
*** ccneill has joined #openstack-security | 22:23 | |
openstackgerrit | Michael Dong proposed openstack/syntribos: added min and max severity and confidence filtering https://review.openstack.org/331868 | 22:25 |
openstackgerrit | Michael Dong proposed openstack/syntribos: Simplified imports and added constants https://review.openstack.org/331831 | 22:27 |
*** ametts has quit IRC | 22:27 | |
*** ibravo has quit IRC | 22:36 | |
*** woodburn has quit IRC | 22:55 | |
*** julian1 has joined #openstack-security | 22:56 | |
*** mdong has quit IRC | 22:59 | |
*** tkelsey has joined #openstack-security | 23:00 | |
*** julian1 has quit IRC | 23:03 | |
*** julian1 has joined #openstack-security | 23:03 | |
*** tkelsey has quit IRC | 23:04 | |
openstackgerrit | Charles Neill proposed openstack/syntribos: Modifies HTTP client to use checks/signals https://review.openstack.org/331833 | 23:06 |
openstackgerrit | Charles Neill proposed openstack/syntribos: Modifies HTTP client to use checks/signals https://review.openstack.org/331833 | 23:07 |
*** julian1 has quit IRC | 23:17 | |
*** jhfeng has quit IRC | 23:17 | |
*** salv-orlando has quit IRC | 23:25 | |
*** yuanying has joined #openstack-security | 23:31 | |
*** sdake has joined #openstack-security | 23:38 | |
openstackgerrit | Merged openstack/bandit: Allow output to default to stdout using argparse https://review.openstack.org/326148 | 23:42 |
*** sdake_ has joined #openstack-security | 23:42 | |
*** sdake has quit IRC | 23:43 | |
*** ccneill has quit IRC | 23:44 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!