*** jamespage has quit IRC | 00:04 | |
*** zul has quit IRC | 00:04 | |
*** Guest9435_ has joined #openstack-security | 00:04 | |
*** nicolasbock has quit IRC | 00:06 | |
*** Guest9435 has quit IRC | 00:06 | |
*** zigo has quit IRC | 00:06 | |
*** zigo_ has joined #openstack-security | 00:06 | |
*** ChanServ has quit IRC | 00:12 | |
*** jamespage has joined #openstack-security | 00:15 | |
*** zul has joined #openstack-security | 00:16 | |
*** ChanServ has joined #openstack-security | 00:33 | |
*** barjavel.freenode.net sets mode: +o ChanServ | 00:33 | |
*** atoth has quit IRC | 00:35 | |
*** gianpietro has joined #openstack-security | 00:39 | |
*** nicolasbock has joined #openstack-security | 00:40 | |
*** chyka has joined #openstack-security | 01:03 | |
*** chyka has quit IRC | 01:08 | |
*** jamespage has quit IRC | 01:30 | |
*** gyee has quit IRC | 01:31 | |
*** jamespage has joined #openstack-security | 01:44 | |
*** markvoelker_ has quit IRC | 02:45 | |
tristanC | gianpietro: isn't this fixed by https://bugs.launchpad.net/horizon/+bug/1567673 ? | 02:53 |
---|---|---|
openstack | Launchpad bug 1567673 in OpenStack Dashboard (Horizon) "[OSSA-2016-010] Possible client side template injection in horizon (CVE-2016-4428)" [Critical,Fix released] - Assigned to Tristan Cacqueray (tristan-cacqueray) | 02:53 |
*** dikonoor has joined #openstack-security | 03:29 | |
*** markvoelker has joined #openstack-security | 03:35 | |
*** markvoelker has quit IRC | 03:39 | |
*** nicolasbock has quit IRC | 03:55 | |
*** markvoelker has joined #openstack-security | 04:29 | |
*** gianpietro has quit IRC | 04:32 | |
*** gianpietro has joined #openstack-security | 04:32 | |
gianpietro | tristanC: it seems the login form is still vulnerable, he says he was able to (1) create a new parameter called 'next' and give it the value 'XSS_value', (2) modify username, login_region ansd id_region values ...I'm not sure on how to exploit this but I will privately send you the screenshots he shared | 04:51 |
gianpietro | tristanC: he also sent me an additional example where he adds the following to the login screen: '/auth/login?next={{1+1}}' and the link is accepted and changes code from the URL itself, which he says should not be happening as no web application should allow for such characters. Finally, he shares a couple of other links to describe the vulnerability: (1) https://portswigger.net/kb/issues/00200308_client-side-t | 04:57 |
gianpietro | emplate-injection (2) https://www.acunetix.com/vulnerabilities/web/angularjs-client-side-template-injection | 04:57 |
*** markvoelker has quit IRC | 05:03 | |
*** dikonoor has quit IRC | 05:05 | |
tristanC | gianpietro: it seems to be working as expected, where do you see the "{{1+1}}" getting evaluated? | 05:06 |
tristanC | though please add any new findings to the bug so that horizon dev can have a closer look | 05:11 |
*** dikonoor has joined #openstack-security | 05:11 | |
*** gianpietro has quit IRC | 05:11 | |
*** gianpietro has joined #openstack-security | 05:12 | |
*** macermak has joined #openstack-security | 05:13 | |
*** dikonoor has quit IRC | 05:23 | |
*** dikonoor has joined #openstack-security | 05:26 | |
*** dikonoor has quit IRC | 05:29 | |
*** gianpietro has quit IRC | 06:03 | |
*** gianpietro has joined #openstack-security | 06:03 | |
*** gianpietro has quit IRC | 06:06 | |
*** gianpietro has joined #openstack-security | 06:06 | |
*** gianpietro has quit IRC | 06:08 | |
*** markvoelker has joined #openstack-security | 06:20 | |
*** AlexeyAbashkin has joined #openstack-security | 06:32 | |
*** pcaruana has joined #openstack-security | 06:33 | |
*** gianpietro has joined #openstack-security | 06:49 | |
*** gianpiet_ has joined #openstack-security | 06:53 | |
*** gianpietro has quit IRC | 06:54 | |
*** markvoelker has quit IRC | 06:54 | |
*** gianpiet_ has quit IRC | 06:57 | |
*** gianpietro has joined #openstack-security | 07:09 | |
*** gianpietro has quit IRC | 07:12 | |
*** gianpiet_ has joined #openstack-security | 07:12 | |
*** jaosorior has joined #openstack-security | 07:15 | |
*** gianpiet_ has quit IRC | 07:16 | |
*** gianpietro has joined #openstack-security | 07:20 | |
*** tesseract has joined #openstack-security | 07:20 | |
*** rcernin has quit IRC | 07:27 | |
*** markvoelker has joined #openstack-security | 07:45 | |
*** markvoelker has quit IRC | 07:49 | |
*** chyka has joined #openstack-security | 07:58 | |
*** chyka has quit IRC | 08:02 | |
*** markvoelker has joined #openstack-security | 08:38 | |
*** Alexey_Abashkin has joined #openstack-security | 08:50 | |
*** Alexey_Abashkin has quit IRC | 08:51 | |
*** AlexeyAbashkin has quit IRC | 08:51 | |
*** AlexeyAbashkin has joined #openstack-security | 08:52 | |
*** salv-orlando has joined #openstack-security | 09:02 | |
*** markvoelker has quit IRC | 09:12 | |
*** zigo_ is now known as zigo | 09:56 | |
*** jaosorior has quit IRC | 10:14 | |
*** salv-orlando has quit IRC | 10:26 | |
*** AlexeyAbashkin has quit IRC | 10:30 | |
*** AlexeyAbashkin has joined #openstack-security | 10:31 | |
*** jaosorior has joined #openstack-security | 10:31 | |
*** markvoelker has joined #openstack-security | 10:35 | |
*** AlexeyAbashkin has quit IRC | 10:36 | |
*** nicolasbock has joined #openstack-security | 10:50 | |
*** markvoelker has quit IRC | 11:06 | |
*** AlexeyAbashkin has joined #openstack-security | 11:21 | |
*** dave-mccowan has joined #openstack-security | 11:21 | |
*** dave-mccowan has quit IRC | 11:26 | |
*** dave-mcc_ has joined #openstack-security | 11:26 | |
*** gianpietro has quit IRC | 11:31 | |
*** chyka has joined #openstack-security | 11:35 | |
*** chyka has quit IRC | 11:40 | |
*** gianpietro has joined #openstack-security | 12:06 | |
*** atoth has joined #openstack-security | 12:16 | |
*** salv-orlando has joined #openstack-security | 12:43 | |
*** salv-orlando has quit IRC | 12:43 | |
*** salv-orlando has joined #openstack-security | 12:44 | |
*** salv-orlando has quit IRC | 12:44 | |
*** salv-orlando has joined #openstack-security | 12:44 | |
*** salv-orlando has quit IRC | 12:44 | |
*** salv-orlando has joined #openstack-security | 12:44 | |
*** salv-orlando has quit IRC | 12:45 | |
*** salv-orlando has joined #openstack-security | 12:45 | |
*** salv-orlando has quit IRC | 12:45 | |
*** salv-orlando has joined #openstack-security | 12:46 | |
*** salv-orlando has quit IRC | 12:46 | |
*** edmondsw has joined #openstack-security | 12:50 | |
*** markvoelker has joined #openstack-security | 12:54 | |
*** gianpietro has quit IRC | 13:08 | |
*** gianpietro has joined #openstack-security | 13:20 | |
*** markvoelker has quit IRC | 13:24 | |
*** nicolasbock has quit IRC | 13:40 | |
*** nicolasbock has joined #openstack-security | 13:53 | |
*** AlexeyAbashkin has quit IRC | 14:02 | |
*** AlexeyAbashkin has joined #openstack-security | 14:04 | |
*** dave-mcc_ is now known as dave-mccowan | 14:55 | |
*** gyee has joined #openstack-security | 15:05 | |
*** markvoelker has joined #openstack-security | 15:08 | |
*** pcaruana has quit IRC | 15:33 | |
*** markvoelker has quit IRC | 15:41 | |
*** macermak has quit IRC | 15:47 | |
*** coolfortea has joined #openstack-security | 15:47 | |
*** chyka has joined #openstack-security | 16:01 | |
*** coolfortea has quit IRC | 16:05 | |
*** gianpietro has quit IRC | 16:09 | |
*** pcaruana has joined #openstack-security | 16:23 | |
*** salv-orlando has joined #openstack-security | 16:47 | |
*** salv-orlando has quit IRC | 16:47 | |
*** salv-orlando has joined #openstack-security | 16:48 | |
*** salv-orlando has quit IRC | 16:48 | |
*** salv-orlando has joined #openstack-security | 16:48 | |
*** salv-orlando has quit IRC | 16:49 | |
*** salv-orlando has joined #openstack-security | 16:49 | |
*** salv-orlando has quit IRC | 16:50 | |
*** salv-orlando has joined #openstack-security | 16:50 | |
*** salv-orlando has quit IRC | 16:50 | |
*** salv-orlando has joined #openstack-security | 16:51 | |
*** salv-orlando has quit IRC | 16:51 | |
*** SimAloo has joined #openstack-security | 17:00 | |
*** tesseract has quit IRC | 17:10 | |
*** AlexeyAbashkin has quit IRC | 17:29 | |
*** markvoelker has joined #openstack-security | 17:30 | |
*** AlexeyAbashkin has joined #openstack-security | 17:31 | |
*** AlexeyAbashkin has quit IRC | 17:36 | |
*** gianpietro has joined #openstack-security | 17:47 | |
*** gianpietro has quit IRC | 17:51 | |
*** AlexeyAbashkin has joined #openstack-security | 17:57 | |
*** markvoelker has quit IRC | 18:00 | |
*** Alexey_Abashkin has joined #openstack-security | 18:00 | |
*** AlexeyAbashkin has quit IRC | 18:02 | |
*** Alexey_Abashkin is now known as AlexeyAbashkin | 18:02 | |
*** pcaruana has quit IRC | 18:09 | |
*** gianpietro has joined #openstack-security | 18:27 | |
*** AlexeyAbashkin has quit IRC | 18:40 | |
*** markvoelker has joined #openstack-security | 18:50 | |
*** markvoelker has quit IRC | 18:55 | |
*** atoth has quit IRC | 18:55 | |
*** gianpietro has quit IRC | 18:58 | |
*** gianpietro has joined #openstack-security | 18:59 | |
*** gianpietro has quit IRC | 19:01 | |
*** gianpietro has joined #openstack-security | 19:01 | |
*** nicolasbock has quit IRC | 19:33 | |
*** markvoelker has joined #openstack-security | 19:45 | |
*** nicolasbock has joined #openstack-security | 19:48 | |
*** markvoelker has quit IRC | 19:54 | |
*** gianpietro has quit IRC | 20:09 | |
*** markvoelker has joined #openstack-security | 20:25 | |
*** gianpietro has joined #openstack-security | 20:40 | |
*** salv-orlando has joined #openstack-security | 21:00 | |
*** salv-orlando has quit IRC | 21:01 | |
*** salv-orlando has joined #openstack-security | 21:01 | |
*** SimAloo has quit IRC | 21:03 | |
*** salv-orlando has quit IRC | 21:13 | |
*** markvoelker has quit IRC | 21:14 | |
*** markvoelker has joined #openstack-security | 21:14 | |
*** gianpietro has quit IRC | 21:15 | |
*** gianpietro has joined #openstack-security | 21:16 | |
*** gianpietro has joined #openstack-security | 21:16 | |
*** gianpietro has quit IRC | 21:17 | |
*** gianpiet_ has joined #openstack-security | 21:17 | |
*** gianpiet_ has quit IRC | 21:17 | |
*** gianpietro has joined #openstack-security | 21:18 | |
*** markvoelker has quit IRC | 21:18 | |
*** gianpietro has quit IRC | 21:18 | |
*** gianpiet_ has joined #openstack-security | 21:19 | |
*** gianpiet_ has quit IRC | 22:17 | |
*** gianpietro has joined #openstack-security | 22:18 | |
*** gianpietro has quit IRC | 22:22 | |
*** rcernin has joined #openstack-security | 22:22 | |
*** dave-mccowan has quit IRC | 22:23 | |
*** salv-orlando has joined #openstack-security | 22:32 | |
*** salv-orlando has quit IRC | 22:37 | |
*** nicolasbock has quit IRC | 22:47 | |
*** edmondsw has quit IRC | 22:52 | |
*** edmondsw has joined #openstack-security | 22:53 | |
*** edmondsw has quit IRC | 22:57 | |
*** markvoelker has joined #openstack-security | 23:25 | |
*** chyka has quit IRC | 23:31 | |
*** salv-orlando has joined #openstack-security | 23:33 | |
*** salv-orlando has quit IRC | 23:34 | |
*** salv-orlando has joined #openstack-security | 23:34 | |
*** salv-orlando has quit IRC | 23:40 | |
*** markvoelker has quit IRC | 23:43 | |
*** markvoelker has joined #openstack-security | 23:44 | |
*** markvoelker has quit IRC | 23:48 |
Generated by irclog2html.py 2.15.3 by Marius Gedminas - find it at mg.pov.lt!