*** ved_lad has quit IRC | 00:28 | |
*** jg10 has joined #openstack-security | 02:50 | |
*** jg10 has left #openstack-security | 02:50 | |
*** bdpayne has joined #openstack-security | 04:42 | |
*** voodookid has joined #openstack-security | 05:02 | |
*** bdpayne has quit IRC | 05:19 | |
*** bdpayne has joined #openstack-security | 05:27 | |
*** voodookid has quit IRC | 05:39 | |
openstackgerrit | OpenStack Proposal Bot proposed a change to openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/105364 | 06:10 |
---|---|---|
*** bdpayne has quit IRC | 06:12 | |
openstackgerrit | A change was merged to openstack/security-doc: Imported Translations from Transifex https://review.openstack.org/105364 | 06:28 |
*** mariaalejandrafa has joined #openstack-security | 06:41 | |
*** j03h has joined #openstack-security | 13:07 | |
*** bknudson has joined #openstack-security | 13:13 | |
*** voodookid has joined #openstack-security | 13:26 | |
*** j03h has quit IRC | 13:55 | |
*** j03h has joined #openstack-security | 13:55 | |
*** voodookid has quit IRC | 14:11 | |
*** paulmo has joined #openstack-security | 14:28 | |
*** j03h has left #openstack-security | 15:32 | |
*** bknudson has quit IRC | 15:38 | |
*** voodookid has joined #openstack-security | 15:55 | |
*** bdpayne has joined #openstack-security | 16:40 | |
*** tmcpeak has joined #openstack-security | 16:43 | |
*** voodookid has quit IRC | 16:57 | |
*** bdpayne has quit IRC | 17:03 | |
*** ved_lad has joined #openstack-security | 17:04 | |
*** bdpayne has joined #openstack-security | 17:28 | |
*** bdpayne_ has joined #openstack-security | 17:30 | |
*** bdpayne has quit IRC | 17:34 | |
*** bdpayne_ has quit IRC | 18:12 | |
*** bdpayne has joined #openstack-security | 18:13 | |
tmcpeak | have you guys ever seen/heard of this: | 18:13 |
tmcpeak | http://www.defensecode.com/public/DefenseCode_Unix_WildCards_Gone_Wild.txt | 18:13 |
tmcpeak | ? | 18:13 |
paulmo | Nope but that is interesting reading | 18:16 |
tmcpeak | yeah good stuff huh? | 18:16 |
tmcpeak | I was thinking it might be good for a gate test | 18:16 |
paulmo | That chown one was like… woe! :) | 18:17 |
tmcpeak | haha yeah! | 18:19 |
paulmo | … and that "-rf" file… ugh | 18:19 |
tmcpeak | yeah! cool stuff :) | 18:21 |
paulmo | Makes me want to write my own linux commands suddenly | 18:25 |
tmcpeak | hahaha, make the problem worse :) | 18:25 |
paulmo | That is a very likely outcome | 18:29 |
*** voodookid has joined #openstack-security | 18:41 | |
*** voodookid has quit IRC | 20:18 | |
*** tmcpeak has left #openstack-security | 21:02 | |
*** tmcpeak has joined #openstack-security | 21:03 | |
tmcpeak | so… for dangerous file permissions, what do you guys think we want to look at? | 21:09 |
tmcpeak | I'm thinking only the "world" part, and what, RWX, RW...? | 21:10 |
*** ved_lad has quit IRC | 21:25 | |
*** voodookid has joined #openstack-security | 21:42 | |
bdpayne | world write is an immediate red flag, in my book | 21:48 |
bdpayne | world read, only on sensitive data | 21:48 |
bdpayne | that is... it is only a red flag on sensitive data | 21:48 |
tmcpeak | bdpayne: so for our automated gate checking | 21:50 |
tmcpeak | acceptable values for W: 1?, 4, 5? | 21:51 |
bdpayne | I haven't been following that work too closely... can you tell if the file has sensitive data in it? | 21:51 |
tmcpeak | bdpayne: nope, it's a line by line check | 21:52 |
bdpayne | For example, reading it and looking for key material or ?? | 21:52 |
bdpayne | ahh | 21:52 |
bdpayne | so I would just flag anything that is world writable | 21:52 |
tmcpeak | ok cool | 21:52 |
bdpayne | that should have zero false positives | 21:52 |
tmcpeak | yeah, that's what we're going for | 21:52 |
tmcpeak | zero false positives | 21:52 |
tmcpeak | cool, thanks | 21:52 |
*** voodookid has quit IRC | 22:03 | |
*** tmcpeak has quit IRC | 22:05 | |
*** tmcpeak has joined #openstack-security | 22:10 | |
*** ved_lad has joined #openstack-security | 22:44 | |
*** paulmo has quit IRC | 23:06 | |
*** ved_lad has quit IRC | 23:12 | |
*** bdpayne has quit IRC | 23:24 | |
*** bdpayne has joined #openstack-security | 23:26 | |
*** voodookid has joined #openstack-security | 23:34 | |
*** bdpayne has quit IRC | 23:37 | |
*** voodookid has quit IRC | 23:49 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!