Tuesday, 2015-02-17

*** singlethink has quit IRC00:02
*** markvoelker has joined #openstack-security00:04
*** tmcpeak has joined #openstack-security00:08
*** markvoelker has quit IRC00:09
openstackgerritTyler Britten proposed openstack/security-doc: Reworded the sentence to make it clearer and less choppy  https://review.openstack.org/15503600:38
*** bknudson has joined #openstack-security00:48
*** markvoelker has joined #openstack-security01:05
*** markvoelker has quit IRC01:11
*** jamielennox is now known as jamielennox|away01:16
*** jamielennox|away is now known as jamielennox01:31
*** jamielennox is now known as jamielennox|away01:41
*** tmcpeak has quit IRC01:44
*** bdpayne has quit IRC01:49
*** markvoelker has joined #openstack-security02:08
*** jamielennox|away is now known as jamielennox02:09
*** markvoelker has quit IRC02:13
*** salv-orlando has quit IRC02:13
*** bknudson has quit IRC02:37
*** markvoelker has joined #openstack-security03:09
*** salv-orlando has joined #openstack-security03:14
*** markvoelker has quit IRC03:14
*** pdesai has joined #openstack-security03:29
*** pdesai has quit IRC03:48
*** markvoelker has joined #openstack-security04:10
*** markvoelker has quit IRC04:16
*** markvoelker has joined #openstack-security05:12
*** markvoelker has quit IRC05:17
*** pcaruana has quit IRC05:47
*** markvoelker has joined #openstack-security06:13
*** markvoelker has quit IRC06:19
*** plsph has joined #openstack-security06:39
*** salv-orlando has quit IRC07:07
*** markvoelker has joined #openstack-security07:15
*** markvoelker has quit IRC07:21
*** plsph has quit IRC07:28
*** markvoelker has joined #openstack-security08:17
*** markvoelker has quit IRC08:22
*** x3n0n has joined #openstack-security08:27
x3n0nhi08:28
x3n0nhow to find xml entity injection vulnerability and how it can be exploited?08:29
*** x3n0n has quit IRC08:31
*** shohel02 has joined #openstack-security08:37
*** salv-orlando has joined #openstack-security08:38
*** salv-orlando has quit IRC09:15
*** markvoelker has joined #openstack-security09:18
*** markvoelker has quit IRC09:23
*** shohel02 has quit IRC10:03
*** salv-orlando has joined #openstack-security10:03
*** markvoelker has joined #openstack-security10:19
*** shohel02 has joined #openstack-security10:21
*** markvoelker has quit IRC10:24
*** shohel02 has quit IRC10:25
*** shohel02 has joined #openstack-security10:39
*** salv-orlando has quit IRC11:02
*** shohel02 has quit IRC11:17
*** markvoelker has joined #openstack-security11:20
*** markvoelker has quit IRC11:25
*** shohel02 has joined #openstack-security11:48
*** shohel02 has quit IRC11:53
*** salv-orlando has joined #openstack-security12:02
*** shohel02 has joined #openstack-security12:02
*** shohel02 has quit IRC12:02
*** shohel02 has joined #openstack-security12:03
*** shohel02 has quit IRC12:04
*** shohel02 has joined #openstack-security12:05
*** markvoelker has joined #openstack-security12:21
*** markvoelker has quit IRC12:26
*** salv-orlando has quit IRC12:50
*** salv-orlando has joined #openstack-security12:50
*** markvoelker has joined #openstack-security12:52
*** plsph has joined #openstack-security13:00
*** _amrith_ is now known as amrith13:15
*** plsph has quit IRC13:22
*** shohel02 has quit IRC13:50
*** bknudson has joined #openstack-security14:20
*** JAHoagie has joined #openstack-security14:31
*** plsph has joined #openstack-security14:32
*** plsph has quit IRC14:41
*** plsph has joined #openstack-security14:57
*** tmcpeak has joined #openstack-security15:05
*** dave-mccowan has joined #openstack-security15:09
*** salv-orlando has quit IRC15:11
*** salv-orlando has joined #openstack-security15:13
*** JAHoagie has quit IRC15:16
*** plsph has quit IRC15:23
*** plsph has joined #openstack-security15:38
*** tmcpeak has quit IRC15:44
*** bpokorny has quit IRC16:05
openstackgerritHart Hoover proposed openstack/security-doc: Change 'SOC' to 'serious organized crime'  https://review.openstack.org/15664116:12
*** JAHoagie has joined #openstack-security16:15
*** bpokorny has joined #openstack-security16:15
*** plsph has quit IRC16:46
*** bknudson has quit IRC16:50
*** plsph has joined #openstack-security17:07
*** tmcpeak has joined #openstack-security17:15
*** plsph has quit IRC17:24
*** bdpayne has joined #openstack-security17:30
bdpayneOSSG Midcycle meetup is getting under way17:31
bdpayneetherpad is at https://etherpad.openstack.org/p/ossg-kilo-meetup17:31
*** tkelsey has joined #openstack-security17:31
*** ljfisher has joined #openstack-security17:31
*** sicarie has joined #openstack-security17:32
bdpayneSecurity guidelines on the wiki https://wiki.openstack.org/wiki/Security/Guidelines17:40
*** hyakuhei has joined #openstack-security17:58
sicariecurrent bugs: #link: https://bugs.launchpad.net/openstack-manuals/+bugs?field.tag=sec-guide17:59
*** plsph has joined #openstack-security18:00
*** bknudson has joined #openstack-security18:01
bdpaynesecurity guide repo https://github.com/openstack/security-doc/tree/master/security-guide18:01
bdpaynesecurity guide online http://docs.openstack.org/sec/18:02
*** ukbelch has joined #openstack-security18:04
openstackgerritMerged openstack/security-doc: Change 'SOC' to 'serious organized crime'  https://review.openstack.org/15664118:05
*** hyakuhei has quit IRC18:08
*** hyakuhei has joined #openstack-security18:10
*** bknudson has quit IRC18:14
*** bknudson has joined #openstack-security18:16
hyakuheihttps://wiki.openstack.org/wiki/Security/Projects/Anchor18:20
*** plsph has quit IRC18:24
bdpayneCleanup anchor readme https://review.openstack.org/15670018:28
*** bpokorny_ has joined #openstack-security18:29
*** bpokorny has quit IRC18:32
*** dg_ has joined #openstack-security18:34
*** singlethink has joined #openstack-security18:34
hyakuhei@tkelsey @dg_ https://review.openstack.org/15670018:34
dg_@bdpayne thankyou :)18:35
hyakuhei+1 :)18:36
*** bpokorny has joined #openstack-security18:45
*** ljfisher has quit IRC18:46
*** bpokorny_ has quit IRC18:48
*** hyakuhei has quit IRC18:49
*** plsph has joined #openstack-security18:54
*** tmcpeak has quit IRC18:55
*** hyakuhei has joined #openstack-security18:58
*** ljfisher has joined #openstack-security18:58
bdpaynetkelsey dg_ hyakuhei Here's another: https://review.openstack.org/15670919:02
tkelseythanks bdpayne :)19:02
*** ljfisher has quit IRC19:09
*** hyakuhei has quit IRC19:09
*** dg_ has quit IRC19:11
*** sicarie has quit IRC19:11
*** hyakuhei has joined #openstack-security19:13
*** sicarie has joined #openstack-security19:15
*** openstackgerrit has quit IRC19:20
*** openstackgerrit has joined #openstack-security19:20
*** elo has joined #openstack-security19:20
*** dg_ has joined #openstack-security19:21
*** ljfisher has joined #openstack-security19:31
*** tmcpeak has joined #openstack-security19:32
tmcpeakhttps://github.com/openstack-infra/project-config/blob/master/gerrit/acls/stackforge/bandit.config19:37
bknudsonhere's infra docs on publishinghttp://docs.openstack.org/infra/manual/creators.html19:41
*** browne has joined #openstack-security19:44
bknudsonhttps://review.openstack.org/#/c/151285/19:45
*** ljfisher has quit IRC19:49
bknudsontmcpeak: http://docs.openstack.org/infra/manual/creators.html#tagging-a-release19:51
tkelseybdpayne: https://review.openstack.org/#/c/154868/3/tests/X509/test_x509_csr.py19:54
tkelseyhyakuhei: dg_ https://review.openstack.org/#/c/154868/19:55
tkelseyhyakuhei: dg_ https://review.openstack.org/#/c/154837/19:56
tkelseyhttps://etherpad.openstack.org/p/anchor-kilo20:01
*** dg_ has quit IRC20:03
*** plsph has quit IRC20:05
openstackgerritBrant Knudson proposed stackforge/bandit: Update test-requirements.txt to match global requirements  https://review.openstack.org/15674120:06
*** dg_ has joined #openstack-security20:07
tkelseyhttps://etherpad.openstack.org/p/anchor-kilo20:07
tmcpeak(band)MacBook-Pro:bandit travismcpeak$ find ~/Documents/projects/keystone/ -name '*.py' | xargs bandit -n 520:10
openstackgerritMerged stackforge/bandit: Minor changes to profile-related debug output  https://review.openstack.org/15588320:10
openstackgerritMerged stackforge/bandit: Add __repr__ to the context object  https://review.openstack.org/15589820:11
openstackgerritMerged stackforge/bandit: Update test-requirements.txt to match global requirements  https://review.openstack.org/15674120:19
openstackgerritEric Brown proposed stackforge/bandit: Rename README.md to README.rst  https://review.openstack.org/15675120:25
*** bpokorny_ has joined #openstack-security20:25
openstackgerritTravis McPeak proposed stackforge/bandit: Dummy check-in  https://review.openstack.org/15675420:27
*** bpokorny has quit IRC20:27
openstackgerritEric Brown proposed stackforge/bandit: Rename README.md to README.rst  https://review.openstack.org/15675120:27
openstackgerritEric Brown proposed stackforge/bandit: Rename README.md to README.rst  https://review.openstack.org/15675120:29
*** singlethink has quit IRC20:35
*** ljfisher has joined #openstack-security20:35
*** singlethink has joined #openstack-security20:37
*** ljfisher has quit IRC20:41
bdpaynetkelsey dg_ https://review.openstack.org/15676220:46
*** hyakuhei has quit IRC20:47
openstackgerritEric Brown proposed stackforge/bandit: Rename README.md to README.rst  https://review.openstack.org/15675120:51
*** hyakuhei has joined #openstack-security20:54
*** pdesai has joined #openstack-security21:03
bknudsonfind /opt/stack/keystone/keystone -path "/opt/stack/keystone/keystone/tests" -prune -o -name "*.py" -print | xargs bandit -n 521:03
*** ljfisher has joined #openstack-security21:05
openstackgerritMerged stackforge/bandit: Rename README.md to README.rst  https://review.openstack.org/15675121:07
tmcpeakhttps://review.openstack.org/15677221:12
*** ljfisher has quit IRC21:13
*** elo2 has joined #openstack-security21:13
*** elo2 has quit IRC21:15
*** tmcpeak has quit IRC21:17
*** elo has quit IRC21:17
*** tmcpeak has joined #openstack-security21:18
*** pdesai has quit IRC21:20
browne[testenv:bandit]21:25
brownecommands = bash -c "find . -path ./.tox -prune -o -name '*.py' | xargs bandit -n 5"21:25
*** dave-mccowan has quit IRC21:47
brownetestenv:bandit]21:57
brownecommands = bash -c "find ./keystone -path ./keystone/tests -prune -o -name '*.py' | xargs bandit -n 5"21:57
bdpayneA few more commits for anchor @dg_21:58
bdpaynehttps://review.openstack.org/15678921:58
bdpaynehttps://review.openstack.org/15679021:58
bdpaynehttps://review.openstack.org/15679121:58
bdpaynehyakuhei ^^21:58
hyakuheity!21:59
hyakuheiLGTM :)22:00
*** dg_ has quit IRC22:00
*** bknudson has quit IRC22:00
*** dg_ has joined #openstack-security22:04
*** salv-orlando has quit IRC22:10
*** salv-orlando has joined #openstack-security22:13
*** dg_ has quit IRC22:17
*** ljfisher has joined #openstack-security22:21
*** xavi_ has joined #openstack-security22:22
*** xavi_ has left #openstack-security22:23
*** dg_ has joined #openstack-security22:27
*** ukbelch has quit IRC22:39
*** ukbelch has joined #openstack-security22:39
*** ukbelch has quit IRC22:40
*** ukbelch has joined #openstack-security22:40
*** ukbelch has quit IRC22:41
*** ukbelch has joined #openstack-security22:42
*** znrmv has joined #openstack-security22:45
znrmvHello22:45
*** znrmv has left #openstack-security22:47
*** bknudson has joined #openstack-security22:48
*** ukbelch has quit IRC22:48
*** tmcpeak has quit IRC22:48
*** ukbelch has joined #openstack-security22:48
*** tmcpeak has joined #openstack-security22:49
*** PaulM has joined #openstack-security22:49
hyakuheiAnyone know why netaddr.IPAddress(‘google.com’) would raise an exception? @tkelsey ?22:50
tkelseyhumm22:50
tkelseycant think of a reason off the top of my head22:51
hyakuheiI think I know why, one sec.22:51
hyakuheiYeah I’m an idiot, that was the problem22:52
*** singlethink has quit IRC22:52
hyakuheiThough I’m pretty sure I just found a bug in Anchor22:52
*** dg_ has quit IRC22:53
*** JAHoagie has quit IRC22:56
*** fletcher has joined #openstack-security23:00
ljfisherhttps://github.com/ljfisher/bandit/blob/plugin_setup_finish/bandit/core/test_set.py23:05
openstackgerritTravis McPeak proposed stackforge/bandit: Adding meaningful exit codes to support use in gate  https://review.openstack.org/15682823:12
*** ljfisher has quit IRC23:22
*** PaulM has quit IRC23:23
*** tmcpeak has quit IRC23:24
*** ljfisher has joined #openstack-security23:28
*** ukbelch has quit IRC23:32
*** tkelsey has quit IRC23:33
openstackgerritJamie Finnigan proposed stackforge/bandit: New constants to support updated results structure  https://review.openstack.org/15684623:47
*** tmcpeak has joined #openstack-security23:52
*** ukbelch has joined #openstack-security23:53
openstackgerritTravis McPeak proposed stackforge/bandit: Adding meaningful exit codes to support use in gate  https://review.openstack.org/15682823:53
brownehttps://wiki.openstack.org/wiki/Neutron/FunctionalGateSetup23:53
*** tmcpeak has quit IRC23:55
*** tmcpeak has joined #openstack-security23:56
*** PaulM has joined #openstack-security23:57

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!