*** freerunner has joined #openstack-security | 00:03 | |
*** dwyde has quit IRC | 00:17 | |
*** hongbin has quit IRC | 00:18 | |
*** browne has quit IRC | 00:21 | |
*** catintheroof has joined #openstack-security | 00:23 | |
*** browne has joined #openstack-security | 00:25 | |
*** jamielennox|away is now known as jamielennox | 00:37 | |
*** xin9972 has quit IRC | 00:44 | |
*** B_Smith has quit IRC | 00:47 | |
*** B_Smith has joined #openstack-security | 00:54 | |
*** mdong has quit IRC | 01:05 | |
*** salv-orlando has joined #openstack-security | 01:05 | |
*** salv-orlando has quit IRC | 01:10 | |
*** catintheroof has quit IRC | 01:13 | |
*** catintheroof has joined #openstack-security | 01:14 | |
*** catintheroof has quit IRC | 01:14 | |
*** browne has quit IRC | 01:39 | |
*** markvoelker has joined #openstack-security | 01:59 | |
*** salv-orlando has joined #openstack-security | 02:06 | |
*** salv-orlando has quit IRC | 02:11 | |
*** knangia has quit IRC | 02:20 | |
*** xin9972 has joined #openstack-security | 02:23 | |
*** gouthamr_ has joined #openstack-security | 02:34 | |
*** unrahul_ has joined #openstack-security | 02:35 | |
*** zul has quit IRC | 02:40 | |
*** gouthamr has quit IRC | 02:41 | |
*** unrahul has quit IRC | 02:41 | |
*** crdotson has quit IRC | 02:41 | |
*** hyakuhei has quit IRC | 02:41 | |
*** jamielennox has quit IRC | 02:41 | |
*** unrahul_ is now known as unrahul | 02:43 | |
*** gouthamr_ is now known as gouthamr | 02:44 | |
*** yarkot has quit IRC | 02:44 | |
*** zul has joined #openstack-security | 02:44 | |
*** yarkot has joined #openstack-security | 02:50 | |
*** markvoelker has quit IRC | 02:56 | |
*** hyakuhei has joined #openstack-security | 03:01 | |
*** markvoelker has joined #openstack-security | 03:10 | |
*** diazjf has joined #openstack-security | 03:11 | |
*** jamielennox|away has joined #openstack-security | 03:12 | |
*** jamielennox|away is now known as jamielennox | 03:12 | |
*** woodster_ has quit IRC | 03:15 | |
*** B_Smith has quit IRC | 03:19 | |
*** B_Smith has joined #openstack-security | 03:35 | |
*** diazjf has quit IRC | 03:50 | |
*** xin99721 has joined #openstack-security | 03:58 | |
*** xin9972 has quit IRC | 04:00 | |
*** edtubill has joined #openstack-security | 04:04 | |
*** salv-orlando has joined #openstack-security | 04:07 | |
*** jerrygb has quit IRC | 04:10 | |
*** salv-orlando has quit IRC | 04:11 | |
*** edtubill has quit IRC | 04:21 | |
*** B_Smith has quit IRC | 04:21 | |
*** crdotson has joined #openstack-security | 04:30 | |
*** B_Smith has joined #openstack-security | 04:33 | |
*** nkinder has joined #openstack-security | 04:42 | |
*** elmiko is now known as _elmiko | 04:58 | |
*** dikonoor has joined #openstack-security | 04:59 | |
*** nkinder has quit IRC | 05:02 | |
*** xin99721 has quit IRC | 05:02 | |
*** jerrygb has joined #openstack-security | 05:10 | |
*** jerrygb has quit IRC | 05:15 | |
*** gouthamr has quit IRC | 06:04 | |
*** salv-orlando has joined #openstack-security | 06:08 | |
*** salv-orlando has quit IRC | 06:13 | |
*** liujiong has joined #openstack-security | 06:16 | |
*** B_Smith has quit IRC | 06:49 | |
*** B_Smith has joined #openstack-security | 06:59 | |
*** jerrygb has joined #openstack-security | 07:00 | |
*** jerrygb has quit IRC | 07:05 | |
*** shohel has joined #openstack-security | 07:53 | |
*** salv-orlando has joined #openstack-security | 08:09 | |
*** tesseract has joined #openstack-security | 08:13 | |
*** salv-orlando has quit IRC | 08:14 | |
*** openstackgerrit has quit IRC | 08:33 | |
*** salv-orlando has joined #openstack-security | 09:03 | |
*** dwyde has joined #openstack-security | 09:19 | |
*** dwyde has quit IRC | 09:24 | |
*** hyakuhei has quit IRC | 09:36 | |
*** hyakuhei has joined #openstack-security | 09:36 | |
*** hyakuhei has quit IRC | 09:36 | |
*** hyakuhei has joined #openstack-security | 09:36 | |
*** Serlex has joined #openstack-security | 09:56 | |
*** B_Smith has quit IRC | 09:56 | |
*** dwyde has joined #openstack-security | 10:03 | |
*** dwyde has quit IRC | 10:07 | |
*** liujiong has quit IRC | 10:13 | |
*** salv-orl_ has joined #openstack-security | 10:23 | |
*** B_Smith has joined #openstack-security | 10:24 | |
*** salv-orlando has quit IRC | 10:26 | |
*** jerrygb has joined #openstack-security | 10:28 | |
*** B_Smith has quit IRC | 10:29 | |
*** B_Smith has joined #openstack-security | 10:30 | |
*** jerrygb has quit IRC | 10:33 | |
*** dwyde has joined #openstack-security | 11:39 | |
*** B_Smith has quit IRC | 11:40 | |
*** salv-orl_ has quit IRC | 11:42 | |
*** dwyde has quit IRC | 11:43 | |
*** dwyde has joined #openstack-security | 12:12 | |
*** dwyde has quit IRC | 12:16 | |
*** jerrygb has joined #openstack-security | 12:29 | |
*** jerrygb has quit IRC | 12:34 | |
*** dwyde has joined #openstack-security | 12:43 | |
*** catintheroof has joined #openstack-security | 12:43 | |
*** B_Smith has joined #openstack-security | 12:44 | |
*** dwyde has quit IRC | 12:47 | |
*** dave-mccowan has joined #openstack-security | 12:48 | |
*** strattao has joined #openstack-security | 13:03 | |
*** jmckind has joined #openstack-security | 13:05 | |
*** shohel1 has joined #openstack-security | 13:06 | |
*** shohel has quit IRC | 13:09 | |
*** gouthamr has joined #openstack-security | 13:12 | |
*** jerrygb has joined #openstack-security | 13:13 | |
*** dwyde has joined #openstack-security | 13:16 | |
*** jmckind has quit IRC | 13:18 | |
*** jmckind has joined #openstack-security | 13:18 | |
*** dwyde has quit IRC | 13:20 | |
*** salv-orlando has joined #openstack-security | 13:43 | |
*** dwyde has joined #openstack-security | 13:49 | |
*** strattao has quit IRC | 13:50 | |
*** dwyde has quit IRC | 13:53 | |
*** strattao has joined #openstack-security | 13:54 | |
*** markvoelker has quit IRC | 13:57 | |
*** markvoelker has joined #openstack-security | 14:01 | |
*** _elmiko is now known as elmiko | 14:03 | |
*** salv-orlando has quit IRC | 14:05 | |
*** salv-orlando has joined #openstack-security | 14:05 | |
*** strattao has quit IRC | 14:05 | |
*** shohel1 has quit IRC | 14:07 | |
*** dwyde has joined #openstack-security | 14:21 | |
*** shohel has joined #openstack-security | 14:23 | |
*** dwyde has quit IRC | 14:26 | |
*** shohel has quit IRC | 14:31 | |
*** dikonoor has quit IRC | 14:36 | |
*** liverpooler has joined #openstack-security | 14:44 | |
*** shohel has joined #openstack-security | 14:47 | |
*** liverpooler has quit IRC | 14:48 | |
*** liverpooler has joined #openstack-security | 14:49 | |
*** dwyde has joined #openstack-security | 14:52 | |
*** nkinder has joined #openstack-security | 14:53 | |
*** dwyde has quit IRC | 14:57 | |
*** salv-orlando has quit IRC | 15:02 | |
rarora | I was looking at Bandit issues, can anyone give me a little more detail about why B310 is an issue? It says "Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected." | 15:07 |
---|---|---|
*** xin9972 has joined #openstack-security | 15:13 | |
sigmavirus | rarora: do you mean, why B310 exists (rather than why it's problematic)? | 15:14 |
rarora | sigmavirus: yes | 15:14 |
sigmavirus | rarora: B310 exists to alert the developer to the fact that untrusted URLs can access local files | 15:14 |
rarora | I looked at some of the documentation for the library but was still a little confused | 15:14 |
sigmavirus | rarora: for example, if some gives you a URL to download data from (ostensibly to store locally) and they give you a file:// URL, you might be tricked into downloading /etc/shadow | 15:15 |
rarora | Oh, alright. My understanding was that you would be able to get untrusted files from the web, not that the URL would be able to access files on the machine | 15:15 |
sigmavirus | And this check exists to warn you | 15:15 |
sigmavirus | If you're not handling untrusted URLs, then you can ignore B310 | 15:15 |
sigmavirus | rarora: file:// is local only | 15:15 |
sigmavirus | You can use urlopen to access a local file on your machine as long as you can read it | 15:16 |
rarora | So if it is local only how would I be downloading something? | 15:16 |
*** strattao has joined #openstack-security | 15:17 | |
rarora | I'm thinking of this from the perspective of me running Cinder on a machine, if a URL is file:/ I'm just a little confused about the security issue if the file is already somewhere on my machine? | 15:17 |
*** edtubill has joined #openstack-security | 15:19 | |
*** strattao has quit IRC | 15:21 | |
*** markvoelker_ has joined #openstack-security | 15:28 | |
*** markvoelker has quit IRC | 15:29 | |
*** markvoelker has joined #openstack-security | 15:31 | |
rarora | sigmavirus: ? | 15:32 |
*** markvoelker_ has quit IRC | 15:33 | |
sigmavirus | rarora: so a better OpenStack-y example is with glance | 15:33 |
sigmavirus | let's say you use glance v1 and tell it to copy-from file:///etc/shadow | 15:33 |
sigmavirus | Glance (were it not careful) would copy that as image data | 15:33 |
sigmavirus | Then the user could do "glance image-download <id>" | 15:33 |
sigmavirus | and get that | 15:33 |
sigmavirus | So in some cases it can be used for data exfiltration | 15:34 |
sigmavirus | With Cinder, I don't think there's a way for you a user to download a volume | 15:34 |
rarora | ahh, I see now, okay thanks! sorry I was a bit dense :D | 15:34 |
rarora | sigmavirus: yeah, I'll have to look into each case, but I don't think it will be an issue there | 15:35 |
sigmavirus | rarora: no need to apologize at all! | 15:35 |
sigmavirus | rarora: like I said, it's merely a warning that will get you to loko a little more closely ideally | 15:35 |
*** dikonoor has joined #openstack-security | 15:42 | |
*** hongbin has joined #openstack-security | 15:48 | |
*** dwyde has joined #openstack-security | 15:57 | |
*** salv-orlando has joined #openstack-security | 16:03 | |
*** salv-orl_ has joined #openstack-security | 16:24 | |
*** salv-orlando has quit IRC | 16:27 | |
*** salv-orl_ has quit IRC | 16:34 | |
*** jmckind_ has joined #openstack-security | 16:37 | |
*** strattao has joined #openstack-security | 16:38 | |
*** jmckind has quit IRC | 16:39 | |
*** strattao has quit IRC | 16:41 | |
sigmavirus | hyakuhei: meeting in ~14 min? | 16:46 |
*** edtubill has quit IRC | 16:51 | |
hyakuhei | sigmavirus yup :) | 16:56 |
*** salv-orlando has joined #openstack-security | 16:57 | |
*** knangia has joined #openstack-security | 17:00 | |
hyakuhei | Meeting started over in #openstack-meeting-alt | 17:00 |
*** edtubill has joined #openstack-security | 17:01 | |
*** diazjf has joined #openstack-security | 17:03 | |
*** liverpooler has quit IRC | 17:04 | |
*** liverpooler has joined #openstack-security | 17:05 | |
*** sicarie has joined #openstack-security | 17:07 | |
*** mdong has joined #openstack-security | 17:11 | |
*** liverpooler has quit IRC | 17:12 | |
*** liverpooler has joined #openstack-security | 17:12 | |
*** dikonoor has quit IRC | 17:14 | |
*** strattao has joined #openstack-security | 17:14 | |
*** liverpooler has quit IRC | 17:16 | |
*** liverpooler has joined #openstack-security | 17:17 | |
*** shohel has quit IRC | 17:18 | |
*** B_Smith has quit IRC | 17:31 | |
*** strattao has quit IRC | 17:32 | |
*** browne has joined #openstack-security | 17:37 | |
*** Serlex has quit IRC | 17:39 | |
*** B_Smith has joined #openstack-security | 17:44 | |
*** salv-orlando has quit IRC | 17:45 | |
*** diazjf has quit IRC | 17:54 | |
*** dwyde has quit IRC | 17:54 | |
*** catinthe_ has joined #openstack-security | 18:18 | |
*** catintheroof has quit IRC | 18:18 | |
*** dwyde has joined #openstack-security | 18:25 | |
*** mdong has quit IRC | 18:39 | |
*** mdong_ has joined #openstack-security | 18:39 | |
*** mdong_ has quit IRC | 18:40 | |
*** mdong has joined #openstack-security | 18:44 | |
*** B_Smith has quit IRC | 18:45 | |
*** jmckind_ has quit IRC | 19:02 | |
*** jmckind has joined #openstack-security | 19:08 | |
*** diazjf has joined #openstack-security | 19:15 | |
*** sicarie has quit IRC | 19:24 | |
*** tesseract has quit IRC | 19:29 | |
*** jmckind_ has joined #openstack-security | 19:30 | |
*** jmckind has quit IRC | 19:32 | |
*** strattao has joined #openstack-security | 19:35 | |
*** nkinder has quit IRC | 19:39 | |
*** B_Smith has joined #openstack-security | 19:42 | |
*** dave-mccowan has quit IRC | 20:08 | |
*** dave-mccowan has joined #openstack-security | 20:09 | |
*** salv-orlando has joined #openstack-security | 20:11 | |
*** jmckind has joined #openstack-security | 20:17 | |
*** jmckind_ has quit IRC | 20:19 | |
*** openstackgerrit has joined #openstack-security | 20:24 | |
openstackgerrit | Philip Jones proposed openstack/bandit: Alter SQL injection plugin to consider .format strings https://review.openstack.org/417695 | 20:24 |
*** strattao has quit IRC | 20:28 | |
*** jmckind_ has joined #openstack-security | 20:29 | |
*** jmckind has quit IRC | 20:30 | |
*** jmckind_ has quit IRC | 20:33 | |
*** jmckind has joined #openstack-security | 20:39 | |
*** browne has quit IRC | 20:47 | |
*** diazjf has quit IRC | 20:47 | |
*** diazjf has joined #openstack-security | 20:49 | |
*** browne has joined #openstack-security | 20:49 | |
*** mdong has quit IRC | 20:56 | |
*** mdong has joined #openstack-security | 20:56 | |
*** pablo|500| has quit IRC | 20:57 | |
*** salv-orlando has quit IRC | 20:57 | |
*** woodster_ has joined #openstack-security | 21:30 | |
*** salv-orlando has joined #openstack-security | 21:36 | |
*** diazjf has quit IRC | 21:57 | |
*** jmckind has quit IRC | 22:02 | |
*** dave-mccowan has quit IRC | 22:08 | |
*** salv-orl_ has joined #openstack-security | 22:24 | |
*** salv-orlando has quit IRC | 22:27 | |
*** gouthamr has quit IRC | 22:45 | |
*** gouthamr has joined #openstack-security | 23:02 | |
*** edtubill has quit IRC | 23:22 | |
*** elmiko is now known as _elmiko | 23:25 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!