vinaypotluri | sometimes "Happiness is seeing jenkins pass !" | 00:16 |
---|---|---|
vinaypotluri | unrahul: thank you for modifying tox.ini | 00:18 |
*** deblike has joined #openstack-security | 00:20 | |
*** ccneill has quit IRC | 00:20 | |
*** sdake has quit IRC | 00:23 | |
*** deblike has quit IRC | 00:24 | |
*** tmcpeak has quit IRC | 00:28 | |
openstackgerrit | Merged openstack/security-doc: Adds rate-limiting section to API endpoint section https://review.openstack.org/348290 | 00:29 |
*** jamielennox is now known as jamielennox|away | 00:49 | |
*** jass93 has quit IRC | 00:58 | |
*** elo has quit IRC | 00:59 | |
*** browne has quit IRC | 01:01 | |
*** davidjd-gh has joined #openstack-security | 01:01 | |
*** davidjd-gh has left #openstack-security | 01:02 | |
*** elo has joined #openstack-security | 01:11 | |
*** jass93 has joined #openstack-security | 01:12 | |
*** sdake has joined #openstack-security | 01:13 | |
*** sdake has quit IRC | 01:13 | |
*** tmcpeak has joined #openstack-security | 01:13 | |
*** sdake has joined #openstack-security | 01:13 | |
*** sdake_ has joined #openstack-security | 01:15 | |
*** sdake has quit IRC | 01:18 | |
*** davidjd-gh has joined #openstack-security | 01:27 | |
*** davidjd-gh has left #openstack-security | 01:27 | |
openstackgerrit | Merged openstack/syntribos: Added signals to results output https://review.openstack.org/348490 | 01:31 |
openstackgerrit | Merged openstack/syntribos: Added string presence check https://review.openstack.org/344489 | 01:33 |
*** jamielennox|away is now known as jamielennox | 01:34 | |
*** deblike has joined #openstack-security | 01:46 | |
*** deblike has quit IRC | 01:51 | |
*** sdake_ has quit IRC | 02:19 | |
*** tmcpeak has quit IRC | 02:22 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/anchor: Updated from global requirements https://review.openstack.org/314347 | 02:26 |
*** jamielennox is now known as jamielennox|away | 02:32 | |
*** elo has quit IRC | 02:56 | |
*** yuanying_ has quit IRC | 02:57 | |
*** elo has joined #openstack-security | 02:59 | |
*** yuanying has joined #openstack-security | 03:51 | |
*** Nikolay_St has joined #openstack-security | 03:53 | |
*** browne has joined #openstack-security | 04:02 | |
*** browne has quit IRC | 04:10 | |
*** elo has quit IRC | 04:56 | |
*** elo has joined #openstack-security | 05:00 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding unique_id to tests https://review.openstack.org/345286 | 05:19 |
*** amitkqed has quit IRC | 05:19 | |
*** amitkqed has joined #openstack-security | 05:20 | |
*** Nikolay_St has quit IRC | 05:27 | |
*** tesseract- has joined #openstack-security | 06:37 | |
*** pcaruana has joined #openstack-security | 06:45 | |
*** Nikolay_St has joined #openstack-security | 07:18 | |
*** vinaypotluri has quit IRC | 07:51 | |
openstackgerrit | Aastha Dixit proposed openstack/syntribos: List available test types in --help output https://review.openstack.org/348465 | 08:17 |
*** tkelsey has joined #openstack-security | 08:30 | |
*** NanKe has joined #openstack-security | 08:45 | |
*** donald1 has joined #openstack-security | 10:07 | |
*** sdake has joined #openstack-security | 10:25 | |
*** donald1 has quit IRC | 10:47 | |
*** sdake has quit IRC | 11:27 | |
*** aastha has quit IRC | 11:29 | |
*** NanKe has quit IRC | 12:41 | |
*** NanKe has joined #openstack-security | 12:46 | |
*** _elmiko is now known as elmiko | 12:48 | |
*** edmondsw has joined #openstack-security | 12:54 | |
*** NanKe has quit IRC | 13:05 | |
*** nkinder has joined #openstack-security | 13:16 | |
*** cleong has joined #openstack-security | 13:22 | |
*** Vivek has quit IRC | 13:22 | |
*** catintheroof has quit IRC | 13:42 | |
*** deblike has joined #openstack-security | 13:49 | |
*** tmcpeak has joined #openstack-security | 13:50 | |
*** edmondsw has quit IRC | 13:56 | |
*** deblike has quit IRC | 13:57 | |
*** edmondsw has joined #openstack-security | 14:34 | |
*** mdong has joined #openstack-security | 14:55 | |
*** ccneill has joined #openstack-security | 14:57 | |
*** vinaypotluri has joined #openstack-security | 15:17 | |
*** aastha has joined #openstack-security | 15:17 | |
*** austin987 has quit IRC | 15:34 | |
*** sdake has joined #openstack-security | 15:39 | |
*** Nikolay_St has quit IRC | 15:40 | |
*** austin987 has joined #openstack-security | 15:48 | |
*** unrahul has joined #openstack-security | 16:01 | |
*** pcaruana has quit IRC | 16:01 | |
openstackgerrit | Aastha Dixit proposed openstack/syntribos: Adding additional fields to debug log https://review.openstack.org/347089 | 16:10 |
mhayden | has anyone in here worked with CCIs and STIGs? | 16:16 |
tmcpeak | I heard my man mhayden is the STIG expert | 16:17 |
mhayden | i'm looking over the RHEL 7 draft STIG and the numbering is totally different than the RHEL 6 ones :/ | 16:17 |
tmcpeak | that's suboptimal | 16:17 |
mhayden | RHEL 6 was V-XXXXX and now it's RHEL-07-##### | 16:17 |
tmcpeak | super unhelpful :\ | 16:17 |
mhayden | however, they all tie back to CCIs, which are standardized from NIST 800-53 | 16:17 |
mhayden | so part of me is wondering if i should use the CCI #'s as a key | 16:18 |
mhayden | and correlate the individual STIG rules to those | 16:18 |
tmcpeak | if those are static that seems the best choice | 16:18 |
mhayden | they're based on NIST 800-53, which is revised less often :P | 16:18 |
tmcpeak | renumbering stigs seems pointless, hopefully that was a one time change and not a usual thing | 16:21 |
mhayden | https://github.com/MindPointGroup/RHEL7-STIG/blob/master/tasks/fix-cat2.yml | 16:23 |
mhayden | it's easier when you only deal with one os in an ansible role | 16:23 |
mhayden | :) | 16:23 |
mhayden | i'll send something to the ML in the hopes that someone has been down this road before | 16:23 |
*** tesseract- has quit IRC | 16:30 | |
*** jamielennox|away is now known as jamielennox | 16:32 | |
*** mdong has quit IRC | 16:56 | |
*** mdong has joined #openstack-security | 16:57 | |
*** austin987 has quit IRC | 17:02 | |
*** ccneill has quit IRC | 17:12 | |
*** deblike has joined #openstack-security | 17:14 | |
*** jamielennox is now known as jamielennox|away | 17:35 | |
*** tkelsey has quit IRC | 17:37 | |
*** Nikolay_St has joined #openstack-security | 17:39 | |
*** Nikolay_St has quit IRC | 18:13 | |
*** Nikolay_St has joined #openstack-security | 18:30 | |
*** tkelsey has joined #openstack-security | 18:33 | |
openstackgerrit | Grant Murphy proposed openstack/bandit: Add check for httpoxy vulnerability https://review.openstack.org/349015 | 18:36 |
*** tkelsey has quit IRC | 18:38 | |
*** sdake has quit IRC | 18:47 | |
*** cleong has quit IRC | 19:05 | |
*** elo has quit IRC | 19:06 | |
*** elo has joined #openstack-security | 19:07 | |
*** sdake has joined #openstack-security | 19:35 | |
*** edmondsw has quit IRC | 19:35 | |
*** ccneill has joined #openstack-security | 19:45 | |
openstackgerrit | Charles Neill proposed openstack/syntribos: Renaming BaseTestCase/BaseFuzzTestCase methods https://review.openstack.org/348572 | 19:55 |
*** sdake has quit IRC | 19:59 | |
gmurphy | sigmavirus: tmcpeak: will add tests for that httpoxy test. i wonder if i should look for specific version string also? | 20:29 |
tmcpeak | gmurphy: lolwut | 20:29 |
tmcpeak | I will not | 20:29 |
gmurphy | lol no | 20:29 |
gmurphy | i just was saying i will add tests. | 20:30 |
tmcpeak | oh, haha | 20:30 |
tmcpeak | I thought you were telling sigma I was going to add them | 20:30 |
gmurphy | but more asking should we be concerned about a specific version of the import | 20:30 |
gmurphy | i imagine this will get patched eventually | 20:30 |
tmcpeak | what's the backstory on this issue? | 20:31 |
gmurphy | but tbh you probably shouldn't be using cgi | 20:31 |
tmcpeak | is there a link you have to something | 20:31 |
tmcpeak | r/netsec ? | 20:31 |
gmurphy | https://httpoxy.org/ | 20:31 |
tmcpeak | oh, I thought the issue was just using cgi :P | 20:31 |
tmcpeak | oh god | 20:31 |
tmcpeak | a logo | 20:31 |
gmurphy | well it is because cgi. but yeah. specifically handler passing HTTP_PROXY to client cgi script etc. | 20:32 |
gmurphy | we just detected the import for the Go version. | 20:33 |
tmcpeak | I wonder if we ought to be looking at strings then | 20:33 |
tmcpeak | that specific environment variable would be referenced as a string, wouldn't it? | 20:33 |
gmurphy | no | 20:33 |
gmurphy | not necessarily | 20:33 |
gmurphy | like the cgi script might not actually reference it | 20:33 |
gmurphy | but say the cgi script uses requests to make a http call | 20:34 |
gmurphy | an attacker can inject an intermediate proxy by setting the HTTP_PROXY header to http://evil.org and intercept that request | 20:34 |
gmurphy | https://access.redhat.com/security/cve/cve-2016-1000110 <- or what this says | 20:34 |
* tmcpeak reads | 20:34 | |
*** tkelsey has joined #openstack-security | 20:34 | |
tmcpeak | how does the attacker set HTTP_PROXY? | 20:35 |
gmurphy | header. | 20:36 |
gmurphy | that is just set in os.environ by CGIHandler etc | 20:36 |
gmurphy | so when cgi script executes | 20:36 |
tmcpeak | so an attacker makes a request, and then CGI takes that header and just stores the value in an environment variable all subsequent requests use? | 20:36 |
gmurphy | requests.get( ) will automatically pick up the proxy environment variable and use that for the request | 20:36 |
gmurphy | yah | 20:37 |
tmcpeak | so as an attacker I make one request with that header and then all subsequent requests use my header value? | 20:37 |
tmcpeak | as an actual proxy | 20:37 |
gmurphy | yes requests by the cgi script in that specific request context | 20:37 |
tmcpeak | lol, oh, that's fun | 20:37 |
gmurphy | so if your making backend calls etc | 20:38 |
gmurphy | they would be routed by attacker controlled url | 20:38 |
gmurphy | anyway | 20:38 |
gmurphy | was just a fun / easy test to implement | 20:38 |
gmurphy | but then i was like should we limit these import checks to specific versions | 20:38 |
gmurphy | like are any of the xml issues fixed in a newer version of those libraries? | 20:39 |
gmurphy | etc | 20:39 |
tmcpeak | yeah somebody just posted that very issue today I think | 20:39 |
*** tkelsey has quit IRC | 20:39 | |
tmcpeak | what's the status of defusedxml and all that jazz | 20:39 |
gmurphy | k. | 20:39 |
gmurphy | so how about this. | 20:39 |
gmurphy | i add this test for now | 20:39 |
tmcpeak | great! | 20:40 |
gmurphy | and add a fixme to review recommended versions for all blacklisted imports etc | 20:40 |
gmurphy | something like that | 20:40 |
tmcpeak | seems reasonable | 20:40 |
*** elo has quit IRC | 21:14 | |
aastha | hey ccneill what exactly is updating test anatomy section thats mentioned in trello documentation card. | 21:15 |
ccneill | https://github.com/openstack/syntribos/blob/master/doc/source/test.anatomy.rst | 21:16 |
ccneill | we need to change the calls so that they reflect our new command line options | 21:16 |
ccneill | we're also missing a section explaining that you can use variables like "{variable_name:default_value}" in URLs (e.g. "/api/v1/user/{user_id:123}/resource/{resource_id:1234}") | 21:17 |
ccneill | we should probably work together as a team to come up with all the deficiencies in each of those files | 21:17 |
ccneill | I just wanted to start adding rough action items for us to define more specifically later | 21:17 |
ccneill | looks like Jenkins is still feeling lazy today.. | 21:21 |
*** elo has joined #openstack-security | 21:22 | |
*** deblike has quit IRC | 21:23 | |
openstackgerrit | Grant Murphy proposed openstack/bandit: Add check for httpoxy vulnerability https://review.openstack.org/349015 | 21:27 |
*** elo has quit IRC | 21:27 | |
*** davidjd-gh has joined #openstack-security | 21:32 | |
*** davidjd-gh has left #openstack-security | 21:32 | |
*** elmiko is now known as _elmiko | 21:32 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: List available test types in --help output https://review.openstack.org/348465 | 21:38 |
aastha | okay. we can discuss about it in our next week's design session. yep jinkins is in friday mood today!! :D | 21:49 |
ccneill | lol yep yep | 21:54 |
*** elo has joined #openstack-security | 21:56 | |
*** whitewabbit has joined #openstack-security | 22:09 | |
*** whitewabbit has quit IRC | 22:11 | |
ccneill | going on 2 hours for a +V on the BTC/BFTC renaming CR :( | 22:31 |
unrahul | :) , one of those days.. I guess it would be like when we waited for the tox patch to get merged. | 22:32 |
ccneill | yeah, it must just have a big backlog to work through or something.. | 22:32 |
unrahul | i thought moving to zuul , fixed lot of these issues.. | 22:32 |
ccneill | not sure exactly what this dashboard is telling me, but it SEEMS to suggest it's geting slammed right now | 22:33 |
ccneill | http://status.openstack.org/zuul/ | 22:33 |
ccneill | ah, yeah the zuul job queue at the bottom left looks like there are a bunch of backlogged jobs, but it also looks like everyone's headed home for the day and not adding new jobs lol | 22:35 |
ccneill | well, on that note, I think I'm gonna call it a day myself. y'all have a good weekend! | 22:36 |
unrahul | :D. at least that is a positive sign, that it wont break. | 22:36 |
unrahul | cool, good weekend ccneill | 22:37 |
*** tkelsey has joined #openstack-security | 22:37 | |
*** ccneill has left #openstack-security | 22:37 | |
*** ccneill has quit IRC | 22:37 | |
*** dave-mccowan has quit IRC | 22:38 | |
*** tkelsey has quit IRC | 22:42 | |
*** davidjd-gh has joined #openstack-security | 22:55 | |
*** davidjd-gh has left #openstack-security | 22:56 | |
*** Nikolay_St has quit IRC | 23:22 | |
*** mdong has quit IRC | 23:30 | |
*** davidjd-gh has joined #openstack-security | 23:37 | |
*** davidjd-gh has left #openstack-security | 23:37 | |
openstackgerrit | Merged openstack/syntribos: Renaming BaseTestCase/BaseFuzzTestCase methods https://review.openstack.org/348572 | 23:38 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!