*** sdake_ has joined #openstack-security | 00:13 | |
*** asd112z has joined #openstack-security | 00:14 | |
*** sdake has quit IRC | 00:16 | |
*** y_sawai has joined #openstack-security | 00:17 | |
*** y_sawai has quit IRC | 00:18 | |
*** salv-orlando has quit IRC | 00:30 | |
*** openstack has joined #openstack-security | 00:34 | |
*** sigmavirus24 is now known as sigmavirus24_awa | 00:46 | |
*** sdake has joined #openstack-security | 00:56 | |
*** sdake_ has quit IRC | 00:59 | |
*** tmcpeak has quit IRC | 01:03 | |
*** browne has quit IRC | 01:24 | |
*** newradio has joined #openstack-security | 01:28 | |
*** edmondsw has joined #openstack-security | 01:39 | |
*** edmondsw has quit IRC | 01:39 | |
*** newradio has quit IRC | 02:07 | |
*** tmcpeak has joined #openstack-security | 02:13 | |
*** dave-mccowan has quit IRC | 02:27 | |
*** browne has joined #openstack-security | 03:02 | |
*** austin987 has quit IRC | 04:40 | |
*** austin987 has joined #openstack-security | 04:58 | |
*** salv-orlando has joined #openstack-security | 05:16 | |
*** salv-orlando has quit IRC | 05:21 | |
*** asd112z has quit IRC | 05:35 | |
*** tmcpeak has quit IRC | 06:13 | |
*** shohel has joined #openstack-security | 06:18 | |
*** alex_klimov has joined #openstack-security | 06:28 | |
*** salv-orlando has joined #openstack-security | 06:38 | |
*** b10n1k_ has quit IRC | 06:54 | |
*** browne1 has joined #openstack-security | 07:48 | |
*** browne has quit IRC | 07:49 | |
*** browne1 has quit IRC | 08:08 | |
*** shohel has quit IRC | 08:13 | |
*** tjt263 has quit IRC | 08:38 | |
*** tjt263 has joined #openstack-security | 09:08 | |
*** yum has joined #openstack-security | 09:10 | |
*** h00327910__ has joined #openstack-security | 09:13 | |
yum | Ciao | 09:14 |
---|---|---|
yum | Ce ne suno | 09:14 |
yum | !start | 09:16 |
openstack | yum: Error: "start" is not a valid command. | 09:16 |
yum | !help | 09:16 |
openstack | yum: (help [<plugin>] [<command>]) -- This command gives a useful description of what <command> does. <plugin> is only necessary if the command is in more than one plugin. | 09:16 |
yum | !comand | 09:16 |
openstack | yum: Error: "comand" is not a valid command. | 09:16 |
yum | !command | 09:17 |
openstack | yum: Error: "command" is not a valid command. | 09:17 |
yum | Mmm | 09:17 |
yum | !command | 09:18 |
openstack | yum: Error: "command" is not a valid command. | 09:18 |
*** daemontool_ has joined #openstack-security | 09:25 | |
*** misc_ has joined #openstack-security | 09:27 | |
*** misc has quit IRC | 09:28 | |
*** daemontool__ has quit IRC | 09:28 | |
*** goodygum has joined #openstack-security | 09:38 | |
*** yum has quit IRC | 09:46 | |
*** shohel has joined #openstack-security | 09:53 | |
*** dave-mccowan has joined #openstack-security | 10:01 | |
*** newradio has joined #openstack-security | 11:11 | |
*** misc_ is now known as misc | 11:14 | |
*** h00327910__ has quit IRC | 11:53 | |
*** heron278 has joined #openstack-security | 12:34 | |
*** edmondsw has joined #openstack-security | 12:40 | |
*** tmcpeak has joined #openstack-security | 13:08 | |
*** singlethink has joined #openstack-security | 13:30 | |
*** bknudson has joined #openstack-security | 13:38 | |
*** shohel has quit IRC | 13:39 | |
*** browne has joined #openstack-security | 13:42 | |
*** heron278 has left #openstack-security | 13:44 | |
*** jmckind has joined #openstack-security | 14:00 | |
*** sigmavirus24_awa is now known as sigmavirus24 | 14:05 | |
*** sicarie has joined #openstack-security | 14:10 | |
*** browne has quit IRC | 14:27 | |
*** browne has joined #openstack-security | 14:37 | |
*** voodookid has joined #openstack-security | 14:39 | |
*** jian5397 has joined #openstack-security | 14:40 | |
*** mdelapp has joined #openstack-security | 14:41 | |
*** yaya has joined #openstack-security | 14:51 | |
*** singleth_ has joined #openstack-security | 14:58 | |
*** sdake has quit IRC | 14:58 | |
*** singlethink has quit IRC | 15:01 | |
*** asd112z has joined #openstack-security | 15:02 | |
*** yaya has quit IRC | 15:03 | |
*** asd112z has quit IRC | 15:10 | |
*** asd112z has joined #openstack-security | 15:11 | |
*** alumno has joined #openstack-security | 15:11 | |
*** alumno has quit IRC | 15:12 | |
*** dwyde has joined #openstack-security | 15:16 | |
*** yaya has joined #openstack-security | 15:19 | |
*** ExpectxD has joined #openstack-security | 15:21 | |
*** TheEnd has joined #openstack-security | 15:24 | |
*** singlethink has joined #openstack-security | 15:25 | |
*** ExpectxD has quit IRC | 15:28 | |
*** ExpectxD has joined #openstack-security | 15:28 | |
*** TheEnd has quit IRC | 15:28 | |
*** ExpectxD has quit IRC | 15:28 | |
*** singleth_ has quit IRC | 15:29 | |
*** bucknerns has joined #openstack-security | 15:32 | |
*** arithx has joined #openstack-security | 15:32 | |
*** arithx has left #openstack-security | 15:34 | |
*** jian5397 has quit IRC | 15:41 | |
*** bucknerns has quit IRC | 15:47 | |
*** jian5397 has joined #openstack-security | 15:48 | |
*** yaya has quit IRC | 15:56 | |
*** bucknerns has joined #openstack-security | 15:57 | |
*** arithx has joined #openstack-security | 16:00 | |
*** jian5397 has quit IRC | 16:00 | |
*** mdong has joined #openstack-security | 16:05 | |
*** bucknerns has quit IRC | 16:07 | |
*** jian5397 has joined #openstack-security | 16:12 | |
*** jian5397 is now known as michaelxin | 16:12 | |
*** tjt263 has quit IRC | 16:12 | |
*** bucknerns has joined #openstack-security | 16:14 | |
michaelxin | bucknerns: hi | 16:14 |
michaelxin | morning | 16:15 |
bucknerns | Hi | 16:15 |
*** yaya has joined #openstack-security | 16:18 | |
*** sdake has joined #openstack-security | 16:20 | |
*** mvaldes has joined #openstack-security | 16:22 | |
michaelxin | hi, guys, as we mentioned in our last week's IRC meeting, we make our PoC for API fuzzing/security testing tool available. | 16:23 |
michaelxin | You can check it at https://github.com/rackerlabs/syntribos | 16:23 |
*** tjt263 has joined #openstack-security | 16:24 | |
michaelxin | At this time, we have not added lots of security checks yet. | 16:24 |
michaelxin | We want the feedbacks from you all first | 16:24 |
michaelxin | Thanks. | 16:25 |
michaelxin | If you have anything, please feel free to ping me, or nathan (bucknerns) or mvaldes | 16:25 |
michaelxin | Thanks bucknerns for his hard work on this PoC | 16:26 |
tmcpeak | michaelxin: awesome! | 16:28 |
tmcpeak | bucknerns: sweet! | 16:28 |
*** jmckind has quit IRC | 16:29 | |
bucknerns | I'm most proud of the autocomplete | 16:31 |
bucknerns | lol | 16:31 |
michaelxin | tmcpeak: Thanks. It is still in early stage. We want the feedbacks from the community and contribution from the community. Together, we can make it a great tool. | 16:32 |
michaelxin | bucknerns: I know you love autocomplete | 16:32 |
tmcpeak | michaelxin: yeah, awesome, I'm excited to check it out! | 16:33 |
*** alex_klimov has quit IRC | 16:36 | |
tmcpeak | nice touch: https://github.com/rackerlabs/syntribos/blob/master/examples/payloads/keystone/domains_get.txt#L3 | 16:38 |
bucknerns | In that example it would fuzz the domain ID and the headers including the auth token. No body fuzzing since it doesn't have a body. | 16:40 |
*** snoggla has joined #openstack-security | 16:40 | |
bucknerns | while fuzzing the headers the domain id would default to the string in the braces | 16:41 |
*** snoggla has left #openstack-security | 16:41 | |
tmcpeak | yeah for sure, makes sense | 16:42 |
bucknerns | if for instance you didn't want to fuzz the auth token you could add ACTION_FIELD: in front of the key x-auth-token: | 16:44 |
tmcpeak | cool - I've got to carve off an hour or so and give it a proper play | 16:44 |
bucknerns | the reason we went with this syntax instead of adopting something exactly like burp is because we are iterating through the body/header object recursively and fuzzing the values. It makes for better fuzzing because an object like <tag a=5 /> can be fuzzed to <tag>some fuzz string</tag> | 16:47 |
tmcpeak | makes sense | 16:48 |
mvaldes | definitely proxy it through Burp to get a good view of what it happening behind the scenes | 16:48 |
tmcpeak | something that would be cool is request logging | 16:49 |
bucknerns | I wouldn't mind input on the object fuzzing vs string replacement fuzzing sometime | 16:49 |
bucknerns | they are all logged | 16:49 |
tmcpeak | oh cool | 16:49 |
mvaldes | i forgot to include the logging details in the readme! | 16:50 |
michaelxin | mvaldes: Please add it now | 16:50 |
michaelxin | mvaldes: it is a cool feature | 16:50 |
tmcpeak | +1 | 16:50 |
*** dwyde has quit IRC | 16:53 | |
mvaldes | working on it now :) | 16:53 |
tmcpeak | michaelxin, mvaldes, bucknerns: you guys going to midcycle? | 16:55 |
tmcpeak | would love to see a demo at midcycle and get some hacking on it | 16:55 |
bucknerns | https://gist.github.com/bucknerns/9a41929e85928918f715 | 16:55 |
michaelxin | tmcpeak: Sure | 16:55 |
tmcpeak | great | 16:55 |
michaelxin | tmcpeak: I will be there. | 16:56 |
bucknerns | i made a gist of a run. I did a keyboard break | 16:56 |
bucknerns | but I showed a log and an ls of the log dir there | 16:56 |
tmcpeak | very cool | 16:56 |
tmcpeak | if you can drop a link to that output in readme or something? | 16:57 |
bucknerns | I will do one with a demo user and a smaller run so we can see the output at the end of the run. It prints the failures, unittest style. | 16:59 |
tmcpeak | perfect | 17:00 |
tristanC | michaelxin: great work :) | 17:04 |
michaelxin | tristanC: Thanks. bucknerns and mvaldes worked hard on this. I just do leg work and lip work. | 17:08 |
*** arithx has left #openstack-security | 17:09 | |
tristanC | well thanks you guys for making this opensource | 17:09 |
michaelxin | Oh, I forgot arithx too | 17:10 |
michaelxin | my bad | 17:10 |
elmiko | michaelxin, bucknerns, thanks! | 17:31 |
elmiko | tmcpeak: you missed some fun this morning, http://eavesdrop.openstack.org/irclogs/%23openstack-security/%23openstack-security.2015-08-26.log.html#t2015-08-26T09:10:08 | 17:32 |
tmcpeak | bad link | 17:32 |
tmcpeak | spammers again? | 17:32 |
tmcpeak | dammit | 17:32 |
elmiko | lol | 17:32 |
elmiko | minoks chewing on the power cables again... | 17:33 |
tmcpeak | it looks like they are trying to control a bot | 17:33 |
elmiko | yea, or something | 17:33 |
michaelxin | elmiko: Glad to help. Thank you. | 17:37 |
*** bucknerns has left #openstack-security | 17:42 | |
*** dwyde has joined #openstack-security | 17:44 | |
*** federico3 has joined #openstack-security | 17:49 | |
*** mdong has quit IRC | 17:57 | |
*** mcdong has joined #openstack-security | 18:02 | |
*** mcdong_ has joined #openstack-security | 18:07 | |
*** mcdong has quit IRC | 18:09 | |
*** mcdong_ is now known as mcdong | 18:09 | |
*** michaelxin has quit IRC | 18:14 | |
*** openstackgerrit has quit IRC | 18:17 | |
*** openstackgerrit has joined #openstack-security | 18:17 | |
*** b10n1k_ has joined #openstack-security | 18:22 | |
*** mvaldes has quit IRC | 18:35 | |
*** yaya has quit IRC | 18:39 | |
*** jian5397 has joined #openstack-security | 18:48 | |
*** mcdong has quit IRC | 18:52 | |
*** asd112z_ has joined #openstack-security | 18:52 | |
*** singleth_ has joined #openstack-security | 18:55 | |
*** asd112z has quit IRC | 18:56 | |
*** jian5397 has quit IRC | 18:57 | |
*** singlet__ has joined #openstack-security | 18:57 | |
*** singlethink has quit IRC | 18:58 | |
*** singleth_ has quit IRC | 19:01 | |
*** jian5397 has joined #openstack-security | 19:08 | |
*** jmckind has joined #openstack-security | 19:27 | |
*** singlet__ has quit IRC | 19:31 | |
*** singlethink has joined #openstack-security | 19:32 | |
*** singlethink has quit IRC | 19:38 | |
*** singlethink has joined #openstack-security | 19:39 | |
*** y_sawai has joined #openstack-security | 19:59 | |
*** y_sawai has quit IRC | 20:09 | |
*** browne has quit IRC | 20:21 | |
*** singleth_ has joined #openstack-security | 20:29 | |
*** browne has joined #openstack-security | 20:30 | |
*** singlethink has quit IRC | 20:31 | |
*** y_sawai has joined #openstack-security | 20:35 | |
*** y_sawai has quit IRC | 20:36 | |
*** yaya has joined #openstack-security | 20:41 | |
*** asd112z_ has quit IRC | 20:51 | |
*** asd112z has joined #openstack-security | 20:52 | |
*** asd112z has quit IRC | 20:52 | |
*** asd112z has joined #openstack-security | 20:53 | |
*** jian5397 has quit IRC | 21:00 | |
*** openstackgerrit has quit IRC | 21:01 | |
*** openstackgerrit has joined #openstack-security | 21:01 | |
*** elo1 has joined #openstack-security | 21:21 | |
*** elo1 has quit IRC | 21:22 | |
*** elo1 has joined #openstack-security | 21:22 | |
*** singlethink has joined #openstack-security | 21:25 | |
*** profor has left #openstack-security | 21:25 | |
*** singlet__ has joined #openstack-security | 21:27 | |
*** singleth_ has quit IRC | 21:28 | |
*** singlethink has quit IRC | 21:30 | |
*** jamielennox has quit IRC | 21:36 | |
*** timkennedy has quit IRC | 21:37 | |
*** timkennedy has joined #openstack-security | 21:37 | |
*** jamielennox has joined #openstack-security | 21:38 | |
*** alejandrito has joined #openstack-security | 21:39 | |
*** elo1 has quit IRC | 21:51 | |
*** alejandrito has quit IRC | 21:51 | |
*** edmondsw has quit IRC | 21:59 | |
*** bknudson has quit IRC | 22:08 | |
*** singlet__ has quit IRC | 22:09 | |
*** sdake_ has joined #openstack-security | 22:15 | |
*** sdake has quit IRC | 22:18 | |
*** jmckind has quit IRC | 22:19 | |
*** dwyde has quit IRC | 22:36 | |
*** sdake_ is now known as sdake | 22:41 | |
*** yaya has quit IRC | 22:42 | |
*** markvoelker has quit IRC | 22:46 | |
*** markvoelker has joined #openstack-security | 22:54 | |
*** sicarie has quit IRC | 23:06 | |
*** voodookid has quit IRC | 23:11 | |
*** jian5397 has joined #openstack-security | 23:17 | |
*** tmcpeak has quit IRC | 23:41 | |
*** jian5397 has quit IRC | 23:57 | |
*** asd112z has quit IRC | 23:57 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!