*** markvoelker has joined #openstack-security | 00:00 | |
*** tkelsey has joined #openstack-security | 00:00 | |
*** ninag has joined #openstack-security | 00:01 | |
*** ninag has quit IRC | 00:01 | |
*** tkelsey has quit IRC | 00:05 | |
*** knangia has quit IRC | 00:11 | |
*** elmiko is now known as _elmiko | 00:22 | |
*** jamielennox is now known as jamielennox|away | 00:48 | |
*** jamielennox|away is now known as jamielennox | 00:49 | |
*** zhihui has joined #openstack-security | 01:37 | |
*** elo has quit IRC | 01:45 | |
*** vinaypotluri has quit IRC | 01:51 | |
*** tkelsey has joined #openstack-security | 02:02 | |
*** tkelsey has quit IRC | 02:06 | |
*** jamielennox is now known as jamielennox|away | 02:07 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Detect binary output file (txt/html) https://review.openstack.org/355305 | 02:09 |
---|---|---|
*** elo has joined #openstack-security | 02:22 | |
openstackgerrit | zhangyanxian proposed openstack/syntribos: Another patch to fix the typo https://review.openstack.org/355696 | 02:23 |
openstackgerrit | zhangyanxian proposed openstack/syntribos: Another patch to fix the typo https://review.openstack.org/355696 | 02:24 |
*** jamielennox|away is now known as jamielennox | 02:26 | |
*** vinaypotluri has joined #openstack-security | 02:42 | |
*** yuanying has quit IRC | 02:49 | |
*** elo has quit IRC | 02:51 | |
*** yuanying has joined #openstack-security | 02:52 | |
*** elo has joined #openstack-security | 02:57 | |
*** elo has quit IRC | 03:12 | |
*** elo has joined #openstack-security | 03:17 | |
*** yuanying has quit IRC | 03:48 | |
*** yuanying has joined #openstack-security | 03:51 | |
*** elo has quit IRC | 05:04 | |
*** zhihui has quit IRC | 05:10 | |
*** lala has joined #openstack-security | 05:12 | |
*** lala is now known as Guest23445 | 05:12 | |
Guest23445 | hello | 05:17 |
*** Guest23445 is now known as zh | 05:17 | |
*** zh is now known as zhh | 05:19 | |
*** markvoelker has quit IRC | 05:58 | |
*** tkelsey has joined #openstack-security | 06:05 | |
*** tkelsey has quit IRC | 06:09 | |
*** rcernin has joined #openstack-security | 06:14 | |
*** elo has joined #openstack-security | 06:16 | |
*** elo has quit IRC | 06:27 | |
*** elo has joined #openstack-security | 06:27 | |
*** murphy_zhao has joined #openstack-security | 06:33 | |
*** zhh has quit IRC | 06:40 | |
*** zhh has joined #openstack-security | 06:40 | |
*** markvoelker has joined #openstack-security | 06:51 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Imported Translations from Zanata https://review.openstack.org/355748 | 06:51 |
*** liverpooler has joined #openstack-security | 06:53 | |
*** tkelsey has joined #openstack-security | 06:54 | |
openstackgerrit | Merged openstack/security-doc: Imported Translations from Zanata https://review.openstack.org/355748 | 07:01 |
*** lhinds|out is now known as lhinds | 07:34 | |
*** liverpooler has quit IRC | 07:35 | |
*** liverpooler has joined #openstack-security | 07:37 | |
openstackgerrit | Stanislaw Pitucha proposed openstack/bandit: Fix blacklist filtering https://review.openstack.org/355772 | 08:00 |
*** markvoelker has quit IRC | 08:01 | |
*** dikonoor has joined #openstack-security | 08:35 | |
*** tkelsey has quit IRC | 08:39 | |
*** markvoelker has joined #openstack-security | 09:02 | |
*** markvoelker has quit IRC | 09:07 | |
*** vinaypotluri has quit IRC | 09:11 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/355811 | 09:25 |
*** nkinder has quit IRC | 09:44 | |
*** markvoelker has joined #openstack-security | 10:03 | |
*** markvoelker has quit IRC | 10:08 | |
*** nkinder has joined #openstack-security | 10:13 | |
*** dikonoor has quit IRC | 10:20 | |
*** v12aml has left #openstack-security | 10:28 | |
*** aastha has quit IRC | 10:37 | |
*** dikonoor has joined #openstack-security | 10:44 | |
*** v12aml has joined #openstack-security | 10:46 | |
*** dikonoor has quit IRC | 10:47 | |
*** dikonoor has joined #openstack-security | 10:47 | |
*** dikonoor has quit IRC | 10:50 | |
*** markvoelker has joined #openstack-security | 11:04 | |
*** jass93 has quit IRC | 11:08 | |
*** markvoelker has quit IRC | 11:08 | |
*** dikonoor has joined #openstack-security | 11:23 | |
*** sdake has joined #openstack-security | 11:36 | |
*** markvoelker has joined #openstack-security | 12:05 | |
*** sigmavirus|away is now known as sigmavirus | 12:05 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/355811 | 12:07 |
*** markvoelker has quit IRC | 12:09 | |
*** markvoelker has joined #openstack-security | 12:26 | |
*** zhh has quit IRC | 12:37 | |
*** _elmiko is now known as elmiko | 12:57 | |
*** edmondsw has joined #openstack-security | 13:11 | |
*** catintheroof has joined #openstack-security | 13:36 | |
*** singlethink has joined #openstack-security | 13:39 | |
*** catintheroof has quit IRC | 13:43 | |
*** liverpooler has quit IRC | 14:14 | |
*** diazjf has joined #openstack-security | 14:19 | |
*** edtubill has joined #openstack-security | 14:19 | |
*** edtubill has quit IRC | 14:23 | |
*** edtubill has joined #openstack-security | 14:31 | |
*** mvaldes has joined #openstack-security | 14:47 | |
*** woodburn has joined #openstack-security | 14:52 | |
*** vinaypotluri has joined #openstack-security | 14:56 | |
*** hockeynut has joined #openstack-security | 15:10 | |
*** dikonoor has quit IRC | 15:11 | |
*** hockeynu_ has joined #openstack-security | 15:15 | |
*** hockeynut has quit IRC | 15:18 | |
*** edtubill has quit IRC | 15:38 | |
*** rcernin has quit IRC | 15:46 | |
openstackgerrit | Doug Chivers proposed openstack/security-analysis: Designate third-party security review artifacts https://review.openstack.org/356025 | 15:48 |
*** edtubill has joined #openstack-security | 16:04 | |
*** knangia has joined #openstack-security | 16:07 | |
*** sdake has quit IRC | 16:09 | |
*** hockeynu_ has quit IRC | 16:10 | |
*** ccneill has joined #openstack-security | 16:15 | |
unrahul | ccneill: https://gist.github.com/rahulunair/7dfff7187a70c5e05eb1a19135ce0584 mitm logs.. | 16:17 |
*** mdong has joined #openstack-security | 16:34 | |
*** hockeynut has joined #openstack-security | 16:40 | |
openstackgerrit | Merged openstack/syntribos: Another patch to fix the typo https://review.openstack.org/355696 | 16:43 |
ccneill | unrahul: weird.. when I set up mitmproxy to use burp as an upstream proxy, it works.. o_O | 16:49 |
ccneill | very strange | 16:49 |
unrahul | :o | 16:54 |
unrahul | May be it is running noe | 16:54 |
unrahul | I have kept it to run | 16:54 |
unrahul | Hope our sever don't crash | 16:54 |
*** diazjf has quit IRC | 16:58 | |
*** mdong has quit IRC | 17:00 | |
*** edtubill has quit IRC | 17:00 | |
*** hockeynut has quit IRC | 17:03 | |
ccneill | for anyone who needs to rename templates from .txt->.template | 17:12 |
ccneill | for i in `ls`; do; name=`echo -n $i | sed "s#\.txt#\.template#"`; mv $i $name; done | 17:12 |
ccneill | :D | 17:12 |
ccneill | brb lunch | 17:12 |
*** mvaldes has quit IRC | 17:21 | |
*** cleong has joined #openstack-security | 17:30 | |
*** crushing_kit has joined #openstack-security | 17:36 | |
*** crushing_kit has left #openstack-security | 17:37 | |
*** ccneill has quit IRC | 17:47 | |
*** sdake has joined #openstack-security | 17:55 | |
*** ccneill has joined #openstack-security | 17:56 | |
*** mdong has joined #openstack-security | 17:56 | |
unrahul | .. script-fu for today :D | 17:58 |
*** rcernin has joined #openstack-security | 18:01 | |
*** mvaldes has joined #openstack-security | 18:14 | |
*** aastha has joined #openstack-security | 18:20 | |
openstackgerrit | Vinay Potluri proposed openstack/syntribos: Overwriting config options from CLI https://review.openstack.org/353039 | 18:38 |
*** edtubill has joined #openstack-security | 19:02 | |
*** edtubill has quit IRC | 19:04 | |
*** diazjf has joined #openstack-security | 19:05 | |
*** mdong has quit IRC | 19:06 | |
*** edtubill has joined #openstack-security | 19:13 | |
*** sdake_ has joined #openstack-security | 19:14 | |
*** sdake has quit IRC | 19:14 | |
*** sdake_ has quit IRC | 19:15 | |
*** sdake has joined #openstack-security | 19:16 | |
*** edtubill has quit IRC | 19:18 | |
*** edtubill has joined #openstack-security | 19:27 | |
*** edtubill has quit IRC | 19:28 | |
*** edtubill has joined #openstack-security | 19:30 | |
mvaldes | s/mv/cp | 19:41 |
mvaldes | ;) | 19:41 |
mvaldes | just in case | 19:41 |
*** diazjf has quit IRC | 19:45 | |
vinaypotluri | http://www.qqpr.com/ascii/img/ascii-1084.gif | 19:45 |
*** diazjf has joined #openstack-security | 19:47 | |
vinaypotluri | http://3.bp.blogspot.com/-6OcthzzapiA/VmR_6SBJ-DI/AAAAAAAACcs/5eW33UdzGbU/w1200-h630-p-nu/ASCII-Scrapper-Mr-Bean.jpg | 19:47 |
openstackgerrit | Doug Chivers proposed openstack/security-analysis: Designate third-party security review artifacts https://review.openstack.org/356025 | 19:47 |
*** hockeynut has joined #openstack-security | 19:48 | |
vinaypotluri | http://nyancat.dakko.us/nyancat-new-fallback.png | 19:52 |
*** hockeynut has quit IRC | 19:53 | |
openstackgerrit | Doug Chivers proposed openstack/security-analysis: Designate third-party security review artifacts https://review.openstack.org/356025 | 19:54 |
*** hockeynut has joined #openstack-security | 19:54 | |
*** diazjf1 has joined #openstack-security | 20:00 | |
*** diazjf has quit IRC | 20:04 | |
*** edtubill has quit IRC | 20:07 | |
*** mdong has joined #openstack-security | 20:14 | |
*** diazjf1 has quit IRC | 20:19 | |
*** B_Smith has quit IRC | 20:19 | |
hyakuhei | elmiko lhinds nkinder can you take a look at https://review.openstack.org/356025 please? | 20:21 |
*** diazjf has joined #openstack-security | 20:29 | |
*** B_Smith has joined #openstack-security | 20:32 | |
*** diazjf has quit IRC | 20:37 | |
elmiko | hyakuhei: will do | 20:37 |
hyakuhei | Cheers. | 20:37 |
elmiko | likewise =) | 20:37 |
hyakuhei | It's not in the format that we'll do our own reviews in in terms of the diagrams | 20:38 |
elmiko | ack | 20:39 |
*** cleong has quit IRC | 20:49 | |
*** diazjf has joined #openstack-security | 20:49 | |
*** edtubill has joined #openstack-security | 20:52 | |
openstackgerrit | Doug Chivers proposed openstack/security-analysis: Adding templates for security review artifacts https://review.openstack.org/356130 | 20:55 |
vinaypotluri | ccneill: do you think i should look into something ? I'm just going through other CRs for now | 20:57 |
ccneill | hmm.. maybe create some of the templates for barbican so that we're able to test it with Syntribos tomorrow? http://docs.openstack.org/developer/barbican/api/ | 21:00 |
ccneill | or reviewing any findings from our testing on keystone, looking at the code to try and figure out where we were getting those 500 issues? | 21:01 |
ccneill | I don't think we want to launch into anything too big today since we'll be at the midcycle for the rest of the week | 21:01 |
ccneill | reviewing open CRs would be good too | 21:02 |
dstanek | ccneill: 500s? | 21:02 |
ccneill | dstanek: we found that one particular string, "..%c0%af" | 21:02 |
ccneill | dstanek: we found that one particular string, "..%c0%af", when inserted in certain places caused a few 500 errors | 21:03 |
ccneill | sorry for repeating myself lol | 21:03 |
dstanek | ccneill: we'll that's not cool. is there a bug already? | 21:03 |
ccneill | dstanek: I don't think so, I'll try to get more details for ya | 21:04 |
dstanek | ccneill: cool, thanks | 21:06 |
dstanek | i'm going to guess it catalog or federation mapping since we operate on those strings a little | 21:06 |
ccneill | it was in a bunch of places actually.. let me see if I can find some good examples. our results output isn't great right now, so it's a lot to sift through unfortunately | 21:07 |
dstanek | ccneill: cool, if you paste it or create a bug with it, just mention my nick. taking off for a bit | 21:12 |
ccneill | sure thing | 21:12 |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding sub commands to Syntribos https://review.openstack.org/350325 | 21:15 |
*** edtubill has quit IRC | 21:20 | |
*** rcernin has quit IRC | 21:27 | |
*** aastha has quit IRC | 21:27 | |
*** elmiko is now known as _elmiko | 21:55 | |
*** mvaldes has quit IRC | 21:57 | |
openstackgerrit | Merged openstack/syntribos: Overwriting config options from CLI https://review.openstack.org/353039 | 21:58 |
*** edmondsw has quit IRC | 21:58 | |
*** diazjf has quit IRC | 22:03 | |
*** mdong has quit IRC | 22:23 | |
*** sdake has quit IRC | 22:27 | |
*** sdake has joined #openstack-security | 22:28 | |
openstackgerrit | Merged openstack/syntribos: Adding sub commands to Syntribos https://review.openstack.org/350325 | 22:38 |
*** singlethink has quit IRC | 22:43 | |
openstackgerrit | Doug Chivers proposed openstack/security-doc: Added section on security review https://review.openstack.org/356153 | 22:43 |
*** dave-mccowan has quit IRC | 22:48 | |
*** hockeynut has quit IRC | 22:55 | |
*** jass93 has joined #openstack-security | 22:58 | |
ccneill | dstanek: https://bugs.launchpad.net/keystone/+bug/1613901 | 23:31 |
openstack | ccneill: Error: malone bug 1613901 not found | 23:31 |
ccneill | marked as a security defect, not sure if it's warranted but wanted to be on the safe side since I'm thinking it might be a bug in paste or some other framework rather than just a one-off thing | 23:32 |
dstanek | ccneill: great, thanks | 23:43 |
ccneill | np | 23:43 |
ccneill | let me know if there's any other info that would be helpful to add | 23:43 |
dstanek | ccneill: commented on the bug. it's super easy to reproduce. | 23:57 |
ccneill | I guess that's a good thing? haha | 23:57 |
dstanek | i'm not sure if it's a security issue as i can't see a way to attack it | 23:58 |
ccneill | yeah, if it's just a utf-8 parse bug it's probably not security-impacting unless it somehow crashes the server, which it doesn't appear to | 23:59 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!