Thursday, 2015-03-05

*** dave-mccowan has quit IRC00:03
*** voodookid has quit IRC00:03
*** markvoelker has quit IRC00:07
*** dwyde has quit IRC00:08
*** bdpayne has quit IRC00:11
*** sicarie has left #openstack-security00:58
*** markvoelker has joined #openstack-security01:08
*** markvoelker has quit IRC01:13
*** markvoelker has joined #openstack-security01:15
*** salv-orlando has quit IRC01:16
*** markvoelker has quit IRC01:20
openstackgerritDave Belcher proposed stackforge/bandit: Refactored AST processing  https://review.openstack.org/16016601:42
*** jamielennox is now known as jamielennox|lunc01:51
*** markvoelker has joined #openstack-security02:16
*** bpokorny_ has joined #openstack-security02:17
*** bpokorny has quit IRC02:20
*** nkinder has quit IRC02:21
*** markvoelker has quit IRC02:21
*** ljfisher has joined #openstack-security02:23
*** amrith is now known as _amrith_02:26
*** nkinder has joined #openstack-security02:26
openstackgerritShail Bhargava proposed openstack/security-doc: MySQL TLS transport config example  https://review.openstack.org/15966802:26
*** bpokorny has joined #openstack-security02:35
*** bpokorny_ has quit IRC02:38
*** bpokorny has quit IRC02:42
*** bpokorny has joined #openstack-security02:43
*** jamielennox|lunc is now known as jamielennox02:47
*** bpokorny has quit IRC02:47
*** vozcelik has joined #openstack-security02:58
*** ljfisher has quit IRC03:16
*** markvoelker has joined #openstack-security03:17
*** fletcher has quit IRC03:18
*** markvoelker has quit IRC03:22
openstackgerritShail Bhargava proposed openstack/security-doc: Fix typo "administator"  https://review.openstack.org/16155903:28
*** browne has quit IRC03:34
*** vozcelik has quit IRC03:40
*** vozcelik has joined #openstack-security03:41
*** jamielennox is now known as jamielennox|away03:45
*** vozcelik has quit IRC03:52
*** dave-mccowan has joined #openstack-security03:58
*** dave-mcc_ has joined #openstack-security04:03
*** dave-mccowan has quit IRC04:03
*** salv-orlando has joined #openstack-security04:16
*** markvoelker has joined #openstack-security04:19
*** salv-orlando has quit IRC04:21
*** markvoelker has quit IRC04:23
*** dave-mcc_ has quit IRC04:27
*** browne has joined #openstack-security04:27
*** markvoelker has joined #openstack-security05:20
*** markvoelker has quit IRC05:25
*** markvoelker has joined #openstack-security06:22
*** markvoelker has quit IRC06:27
*** Krast has joined #openstack-security06:51
*** salv-orlando has joined #openstack-security07:14
*** salv-orlando has quit IRC07:19
*** markvoelker has joined #openstack-security07:22
*** salv-orlando has joined #openstack-security07:27
*** markvoelker has quit IRC07:28
*** openstackgerrit has quit IRC07:36
*** openstackgerrit has joined #openstack-security07:36
*** browne has quit IRC08:15
*** markvoelker has joined #openstack-security08:25
*** markvoelker has quit IRC08:29
*** Krast has quit IRC08:33
*** salv-orlando has quit IRC08:33
*** salv-orlando has joined #openstack-security09:05
*** browne has joined #openstack-security09:14
*** elmiko has quit IRC09:20
*** elmiko has joined #openstack-security09:20
*** markvoelker has joined #openstack-security09:26
*** markvoelker has quit IRC09:31
openstackgerritTim Kelsey proposed stackforge/anchor: Fixing several issues in Anchor startup  https://review.openstack.org/16130109:52
*** salv-orlando has quit IRC09:59
openstackgerritDave Belcher proposed stackforge/bandit: Refactored AST processing  https://review.openstack.org/16016610:01
*** browne has quit IRC10:11
*** markvoelker has joined #openstack-security10:27
*** markvoelker has quit IRC10:31
openstackgerritTim Kelsey proposed stackforge/anchor: Fixing several issues in Anchor startup  https://review.openstack.org/16130110:49
*** salv-orlando has joined #openstack-security11:00
*** rkgudboy has joined #openstack-security11:16
*** markvoelker has joined #openstack-security11:28
*** markvoelker has quit IRC11:32
openstackgerritTim Kelsey proposed stackforge/anchor: Fixing several issues in Anchor startup  https://review.openstack.org/16130111:38
*** rohitkashyap has joined #openstack-security11:41
*** salv-orlando has quit IRC11:42
*** rkgudboy has quit IRC11:44
openstackgerritTim Kelsey proposed stackforge/anchor: Fixing several issues in Anchor startup  https://review.openstack.org/16130111:48
*** _amrith_ is now known as amrith12:25
*** markvoelker has joined #openstack-security12:29
*** tmcpeak has joined #openstack-security12:31
*** markvoelker has quit IRC12:34
*** markvoelker has joined #openstack-security12:38
*** rohitkashyap has quit IRC12:40
*** salv-orlando has joined #openstack-security12:56
openstackgerritMerged stackforge/bandit: Refactored AST processing  https://review.openstack.org/16016612:57
openstackgerritMerged stackforge/bandit: Clean up test property decorators after refactor  https://review.openstack.org/16102413:06
openstackgerritMerged stackforge/bandit: Refactor functional tests to clarify scoring  https://review.openstack.org/16100513:08
*** dave-mccowan has joined #openstack-security13:11
*** ljfisher has joined #openstack-security13:54
*** browne has joined #openstack-security14:45
*** voodookid has joined #openstack-security15:26
*** dwyde has joined #openstack-security15:39
*** edmondsw has joined #openstack-security15:46
*** edmondsw has quit IRC15:47
*** edmondsw has joined #openstack-security15:47
*** edmondsw has quit IRC15:47
*** edmondsw has joined #openstack-security15:48
*** browne has quit IRC15:55
*** dwyde has quit IRC16:09
*** browne has joined #openstack-security16:10
*** dwyde has joined #openstack-security16:21
*** dave-mcc_ has joined #openstack-security16:28
*** salv-orlando has quit IRC16:29
*** dave-mccowan has quit IRC16:30
*** dave-mccowan has joined #openstack-security16:31
*** dave-mcc_ has quit IRC16:34
*** salv-orlando has joined #openstack-security16:39
openstackgerritRob Fletcher proposed stackforge/bandit: Add mako templating plugin and XSS profile  https://review.openstack.org/15880116:44
*** tkelsey has joined #openstack-security16:46
*** sicarie has joined #openstack-security16:47
tmcpeakreminder: meeting in 5 mins - #openstack-meeting-alt16:55
*** fletcher has joined #openstack-security17:00
*** fletcher has quit IRC17:00
*** fletcher has joined #openstack-security17:01
*** fletcher_ has joined #openstack-security17:01
*** bdpayne has joined #openstack-security17:04
*** fletcher has quit IRC17:04
*** bpokorny has joined #openstack-security17:08
*** bpokorny has quit IRC17:16
tmcpeaksweston: can you come to #openstack-meeting-alt?17:16
*** bpokorny has joined #openstack-security17:18
openstackgerritMerged openstack/security-doc: Fix typo "administator"  https://review.openstack.org/16155917:19
openstackgerritMerged openstack/security-doc: Add reference links to Openstack Security Guide  https://review.openstack.org/16086817:29
openstackgerritMerged openstack/security-doc: Removal of unnecessary parts of the text about boot process using TLS  https://review.openstack.org/16088117:31
*** browne has quit IRC17:33
openstackgerritTim Kelsey proposed stackforge/anchor: Adding functional testing  https://review.openstack.org/16182118:04
*** JAHoagie has joined #openstack-security18:15
openstackgerritShail Bhargava proposed openstack/security-doc: MySQL TLS transport config example  https://review.openstack.org/15966818:25
openstackgerritTim Kelsey proposed stackforge/anchor: Adding functional testing  https://review.openstack.org/16182118:29
*** ljfisher has quit IRC18:32
*** ljfisher has joined #openstack-security18:36
*** dwyde has quit IRC18:37
*** amrith is now known as _amrith_18:46
*** _amrith_ is now known as amrith18:49
openstackgerritMerged stackforge/bandit: Add mako templating plugin and XSS profile  https://review.openstack.org/15880118:59
*** ljfisher has quit IRC19:01
*** ljfisher has joined #openstack-security19:02
*** ljfisher has quit IRC19:06
*** dwyde has joined #openstack-security19:14
*** browne has joined #openstack-security19:41
*** bdpayne has quit IRC19:56
*** bpokorny_ has joined #openstack-security20:02
*** bpokorny has quit IRC20:06
*** sicarie has quit IRC20:07
dwydeI'm working on a bunch of additions to bandit's checks for dangerous functions20:07
dwydethings like os.system, pickle.load, cPickle, etc.20:07
dwydeI think it's cleaner to write plugins than to clutter "blacklist_functions" in the config file20:07
dwydeany thoughts?20:07
*** bpokorny has joined #openstack-security20:08
*** bpokorny_ has quit IRC20:11
tmcpeakdwyde: either is a viable approach, the original thought behind blacklist_functions was basically just that a bunch of tests are literally the same thing20:25
tmcpeakis this function being used?20:25
*** openstackgerrit has quit IRC20:25
*** openstackgerrit has joined #openstack-security20:25
tmcpeakif it's just that test, then it's up to implementer about where to put it, but blacklist_functions handles the logic for those extremely simple - flag every time this function is used, case20:26
tmcpeakif you have a single operating theme, it might be cleaner to implement them all in one plugin, in which case you can leave them out of blacklist_functions20:26
tmcpeakthe choice is yours20:26
dwydetmcpeak: got it, thanks20:27
tmcpeaksure20:27
dwydethe other thing I was thinking is that some tests might want to know about all the ways of calling a shell20:28
dwydelinux_commands_wildcard_injection, for example20:28
tmcpeakcan you elaborate please?20:29
dwydethat test loops through a list of functions that can shell out (currently os.system, subprocess.Popen, and os.popen)20:29
tmcpeakyep20:30
dwydeso maybe it makes sense to have a central listing of functions that can call a shell20:30
tmcpeakthe wildcard injection case is special20:30
tmcpeakit's not an issue that they can call shell, it's an issue in the way those particular commands work20:30
tmcpeakcheck this out: http://www.defensecode.com/public/DefenseCode_Unix_WildCards_Gone_Wild.txt20:31
dwyderight, maybe I’m just riding the DRY high from the functional tests :-)20:32
tmcpeak:)20:32
tmcpeakbrb20:33
*** bdpayne has joined #openstack-security20:47
*** tkelsey has quit IRC20:58
*** salv-orlando is now known as ihate-salv-orlan20:59
*** ihate-salv-orlan is now known as salv-orlando21:00
*** tmcpeak has quit IRC21:17
*** tmcpeak has joined #openstack-security21:19
tmcpeakdwyde: I see what you're saying21:21
tmcpeakby all means, clean that up :)21:21
tmcpeaksounds like a good optimization21:21
dwydecool21:22
*** gabriela has joined #openstack-security21:44
*** gabriela has left #openstack-security21:44
*** jamielennox|away is now known as jamielennox21:56
*** bpokorny_ has joined #openstack-security22:02
*** bpokorny has quit IRC22:05
*** edmondsw has quit IRC22:07
openstackgerritJoel Coffman proposed openstack/security-doc: Remove duplicate word in sentence  https://review.openstack.org/16192622:19
*** tmcpeak has quit IRC23:12
*** openstack has joined #openstack-security23:53

Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!