| *** sdake_ has joined #openstack-security | 00:13 | |
| *** asd112z has joined #openstack-security | 00:14 | |
| *** sdake has quit IRC | 00:16 | |
| *** y_sawai has joined #openstack-security | 00:17 | |
| *** y_sawai has quit IRC | 00:18 | |
| *** salv-orlando has quit IRC | 00:30 | |
| *** openstack has joined #openstack-security | 00:34 | |
| *** sigmavirus24 is now known as sigmavirus24_awa | 00:46 | |
| *** sdake has joined #openstack-security | 00:56 | |
| *** sdake_ has quit IRC | 00:59 | |
| *** tmcpeak has quit IRC | 01:03 | |
| *** browne has quit IRC | 01:24 | |
| *** newradio has joined #openstack-security | 01:28 | |
| *** edmondsw has joined #openstack-security | 01:39 | |
| *** edmondsw has quit IRC | 01:39 | |
| *** newradio has quit IRC | 02:07 | |
| *** tmcpeak has joined #openstack-security | 02:13 | |
| *** dave-mccowan has quit IRC | 02:27 | |
| *** browne has joined #openstack-security | 03:02 | |
| *** austin987 has quit IRC | 04:40 | |
| *** austin987 has joined #openstack-security | 04:58 | |
| *** salv-orlando has joined #openstack-security | 05:16 | |
| *** salv-orlando has quit IRC | 05:21 | |
| *** asd112z has quit IRC | 05:35 | |
| *** tmcpeak has quit IRC | 06:13 | |
| *** shohel has joined #openstack-security | 06:18 | |
| *** alex_klimov has joined #openstack-security | 06:28 | |
| *** salv-orlando has joined #openstack-security | 06:38 | |
| *** b10n1k_ has quit IRC | 06:54 | |
| *** browne1 has joined #openstack-security | 07:48 | |
| *** browne has quit IRC | 07:49 | |
| *** browne1 has quit IRC | 08:08 | |
| *** shohel has quit IRC | 08:13 | |
| *** tjt263 has quit IRC | 08:38 | |
| *** tjt263 has joined #openstack-security | 09:08 | |
| *** yum has joined #openstack-security | 09:10 | |
| *** h00327910__ has joined #openstack-security | 09:13 | |
| yum | Ciao | 09:14 |
|---|---|---|
| yum | Ce ne suno | 09:14 |
| yum | !start | 09:16 |
| openstack | yum: Error: "start" is not a valid command. | 09:16 |
| yum | !help | 09:16 |
| openstack | yum: (help [<plugin>] [<command>]) -- This command gives a useful description of what <command> does. <plugin> is only necessary if the command is in more than one plugin. | 09:16 |
| yum | !comand | 09:16 |
| openstack | yum: Error: "comand" is not a valid command. | 09:16 |
| yum | !command | 09:17 |
| openstack | yum: Error: "command" is not a valid command. | 09:17 |
| yum | Mmm | 09:17 |
| yum | !command | 09:18 |
| openstack | yum: Error: "command" is not a valid command. | 09:18 |
| *** daemontool_ has joined #openstack-security | 09:25 | |
| *** misc_ has joined #openstack-security | 09:27 | |
| *** misc has quit IRC | 09:28 | |
| *** daemontool__ has quit IRC | 09:28 | |
| *** goodygum has joined #openstack-security | 09:38 | |
| *** yum has quit IRC | 09:46 | |
| *** shohel has joined #openstack-security | 09:53 | |
| *** dave-mccowan has joined #openstack-security | 10:01 | |
| *** newradio has joined #openstack-security | 11:11 | |
| *** misc_ is now known as misc | 11:14 | |
| *** h00327910__ has quit IRC | 11:53 | |
| *** heron278 has joined #openstack-security | 12:34 | |
| *** edmondsw has joined #openstack-security | 12:40 | |
| *** tmcpeak has joined #openstack-security | 13:08 | |
| *** singlethink has joined #openstack-security | 13:30 | |
| *** bknudson has joined #openstack-security | 13:38 | |
| *** shohel has quit IRC | 13:39 | |
| *** browne has joined #openstack-security | 13:42 | |
| *** heron278 has left #openstack-security | 13:44 | |
| *** jmckind has joined #openstack-security | 14:00 | |
| *** sigmavirus24_awa is now known as sigmavirus24 | 14:05 | |
| *** sicarie has joined #openstack-security | 14:10 | |
| *** browne has quit IRC | 14:27 | |
| *** browne has joined #openstack-security | 14:37 | |
| *** voodookid has joined #openstack-security | 14:39 | |
| *** jian5397 has joined #openstack-security | 14:40 | |
| *** mdelapp has joined #openstack-security | 14:41 | |
| *** yaya has joined #openstack-security | 14:51 | |
| *** singleth_ has joined #openstack-security | 14:58 | |
| *** sdake has quit IRC | 14:58 | |
| *** singlethink has quit IRC | 15:01 | |
| *** asd112z has joined #openstack-security | 15:02 | |
| *** yaya has quit IRC | 15:03 | |
| *** asd112z has quit IRC | 15:10 | |
| *** asd112z has joined #openstack-security | 15:11 | |
| *** alumno has joined #openstack-security | 15:11 | |
| *** alumno has quit IRC | 15:12 | |
| *** dwyde has joined #openstack-security | 15:16 | |
| *** yaya has joined #openstack-security | 15:19 | |
| *** ExpectxD has joined #openstack-security | 15:21 | |
| *** TheEnd has joined #openstack-security | 15:24 | |
| *** singlethink has joined #openstack-security | 15:25 | |
| *** ExpectxD has quit IRC | 15:28 | |
| *** ExpectxD has joined #openstack-security | 15:28 | |
| *** TheEnd has quit IRC | 15:28 | |
| *** ExpectxD has quit IRC | 15:28 | |
| *** singleth_ has quit IRC | 15:29 | |
| *** bucknerns has joined #openstack-security | 15:32 | |
| *** arithx has joined #openstack-security | 15:32 | |
| *** arithx has left #openstack-security | 15:34 | |
| *** jian5397 has quit IRC | 15:41 | |
| *** bucknerns has quit IRC | 15:47 | |
| *** jian5397 has joined #openstack-security | 15:48 | |
| *** yaya has quit IRC | 15:56 | |
| *** bucknerns has joined #openstack-security | 15:57 | |
| *** arithx has joined #openstack-security | 16:00 | |
| *** jian5397 has quit IRC | 16:00 | |
| *** mdong has joined #openstack-security | 16:05 | |
| *** bucknerns has quit IRC | 16:07 | |
| *** jian5397 has joined #openstack-security | 16:12 | |
| *** jian5397 is now known as michaelxin | 16:12 | |
| *** tjt263 has quit IRC | 16:12 | |
| *** bucknerns has joined #openstack-security | 16:14 | |
| michaelxin | bucknerns: hi | 16:14 |
| michaelxin | morning | 16:15 |
| bucknerns | Hi | 16:15 |
| *** yaya has joined #openstack-security | 16:18 | |
| *** sdake has joined #openstack-security | 16:20 | |
| *** mvaldes has joined #openstack-security | 16:22 | |
| michaelxin | hi, guys, as we mentioned in our last week's IRC meeting, we make our PoC for API fuzzing/security testing tool available. | 16:23 |
| michaelxin | You can check it at https://github.com/rackerlabs/syntribos | 16:23 |
| *** tjt263 has joined #openstack-security | 16:24 | |
| michaelxin | At this time, we have not added lots of security checks yet. | 16:24 |
| michaelxin | We want the feedbacks from you all first | 16:24 |
| michaelxin | Thanks. | 16:25 |
| michaelxin | If you have anything, please feel free to ping me, or nathan (bucknerns) or mvaldes | 16:25 |
| michaelxin | Thanks bucknerns for his hard work on this PoC | 16:26 |
| tmcpeak | michaelxin: awesome! | 16:28 |
| tmcpeak | bucknerns: sweet! | 16:28 |
| *** jmckind has quit IRC | 16:29 | |
| bucknerns | I'm most proud of the autocomplete | 16:31 |
| bucknerns | lol | 16:31 |
| michaelxin | tmcpeak: Thanks. It is still in early stage. We want the feedbacks from the community and contribution from the community. Together, we can make it a great tool. | 16:32 |
| michaelxin | bucknerns: I know you love autocomplete | 16:32 |
| tmcpeak | michaelxin: yeah, awesome, I'm excited to check it out! | 16:33 |
| *** alex_klimov has quit IRC | 16:36 | |
| tmcpeak | nice touch: https://github.com/rackerlabs/syntribos/blob/master/examples/payloads/keystone/domains_get.txt#L3 | 16:38 |
| bucknerns | In that example it would fuzz the domain ID and the headers including the auth token. No body fuzzing since it doesn't have a body. | 16:40 |
| *** snoggla has joined #openstack-security | 16:40 | |
| bucknerns | while fuzzing the headers the domain id would default to the string in the braces | 16:41 |
| *** snoggla has left #openstack-security | 16:41 | |
| tmcpeak | yeah for sure, makes sense | 16:42 |
| bucknerns | if for instance you didn't want to fuzz the auth token you could add ACTION_FIELD: in front of the key x-auth-token: | 16:44 |
| tmcpeak | cool - I've got to carve off an hour or so and give it a proper play | 16:44 |
| bucknerns | the reason we went with this syntax instead of adopting something exactly like burp is because we are iterating through the body/header object recursively and fuzzing the values. It makes for better fuzzing because an object like <tag a=5 /> can be fuzzed to <tag>some fuzz string</tag> | 16:47 |
| tmcpeak | makes sense | 16:48 |
| mvaldes | definitely proxy it through Burp to get a good view of what it happening behind the scenes | 16:48 |
| tmcpeak | something that would be cool is request logging | 16:49 |
| bucknerns | I wouldn't mind input on the object fuzzing vs string replacement fuzzing sometime | 16:49 |
| bucknerns | they are all logged | 16:49 |
| tmcpeak | oh cool | 16:49 |
| mvaldes | i forgot to include the logging details in the readme! | 16:50 |
| michaelxin | mvaldes: Please add it now | 16:50 |
| michaelxin | mvaldes: it is a cool feature | 16:50 |
| tmcpeak | +1 | 16:50 |
| *** dwyde has quit IRC | 16:53 | |
| mvaldes | working on it now :) | 16:53 |
| tmcpeak | michaelxin, mvaldes, bucknerns: you guys going to midcycle? | 16:55 |
| tmcpeak | would love to see a demo at midcycle and get some hacking on it | 16:55 |
| bucknerns | https://gist.github.com/bucknerns/9a41929e85928918f715 | 16:55 |
| michaelxin | tmcpeak: Sure | 16:55 |
| tmcpeak | great | 16:55 |
| michaelxin | tmcpeak: I will be there. | 16:56 |
| bucknerns | i made a gist of a run. I did a keyboard break | 16:56 |
| bucknerns | but I showed a log and an ls of the log dir there | 16:56 |
| tmcpeak | very cool | 16:56 |
| tmcpeak | if you can drop a link to that output in readme or something? | 16:57 |
| bucknerns | I will do one with a demo user and a smaller run so we can see the output at the end of the run. It prints the failures, unittest style. | 16:59 |
| tmcpeak | perfect | 17:00 |
| tristanC | michaelxin: great work :) | 17:04 |
| michaelxin | tristanC: Thanks. bucknerns and mvaldes worked hard on this. I just do leg work and lip work. | 17:08 |
| *** arithx has left #openstack-security | 17:09 | |
| tristanC | well thanks you guys for making this opensource | 17:09 |
| michaelxin | Oh, I forgot arithx too | 17:10 |
| michaelxin | my bad | 17:10 |
| elmiko | michaelxin, bucknerns, thanks! | 17:31 |
| elmiko | tmcpeak: you missed some fun this morning, http://eavesdrop.openstack.org/irclogs/%23openstack-security/%23openstack-security.2015-08-26.log.html#t2015-08-26T09:10:08 | 17:32 |
| tmcpeak | bad link | 17:32 |
| tmcpeak | spammers again? | 17:32 |
| tmcpeak | dammit | 17:32 |
| elmiko | lol | 17:32 |
| elmiko | minoks chewing on the power cables again... | 17:33 |
| tmcpeak | it looks like they are trying to control a bot | 17:33 |
| elmiko | yea, or something | 17:33 |
| michaelxin | elmiko: Glad to help. Thank you. | 17:37 |
| *** bucknerns has left #openstack-security | 17:42 | |
| *** dwyde has joined #openstack-security | 17:44 | |
| *** federico3 has joined #openstack-security | 17:49 | |
| *** mdong has quit IRC | 17:57 | |
| *** mcdong has joined #openstack-security | 18:02 | |
| *** mcdong_ has joined #openstack-security | 18:07 | |
| *** mcdong has quit IRC | 18:09 | |
| *** mcdong_ is now known as mcdong | 18:09 | |
| *** michaelxin has quit IRC | 18:14 | |
| *** openstackgerrit has quit IRC | 18:17 | |
| *** openstackgerrit has joined #openstack-security | 18:17 | |
| *** b10n1k_ has joined #openstack-security | 18:22 | |
| *** mvaldes has quit IRC | 18:35 | |
| *** yaya has quit IRC | 18:39 | |
| *** jian5397 has joined #openstack-security | 18:48 | |
| *** mcdong has quit IRC | 18:52 | |
| *** asd112z_ has joined #openstack-security | 18:52 | |
| *** singleth_ has joined #openstack-security | 18:55 | |
| *** asd112z has quit IRC | 18:56 | |
| *** jian5397 has quit IRC | 18:57 | |
| *** singlet__ has joined #openstack-security | 18:57 | |
| *** singlethink has quit IRC | 18:58 | |
| *** singleth_ has quit IRC | 19:01 | |
| *** jian5397 has joined #openstack-security | 19:08 | |
| *** jmckind has joined #openstack-security | 19:27 | |
| *** singlet__ has quit IRC | 19:31 | |
| *** singlethink has joined #openstack-security | 19:32 | |
| *** singlethink has quit IRC | 19:38 | |
| *** singlethink has joined #openstack-security | 19:39 | |
| *** y_sawai has joined #openstack-security | 19:59 | |
| *** y_sawai has quit IRC | 20:09 | |
| *** browne has quit IRC | 20:21 | |
| *** singleth_ has joined #openstack-security | 20:29 | |
| *** browne has joined #openstack-security | 20:30 | |
| *** singlethink has quit IRC | 20:31 | |
| *** y_sawai has joined #openstack-security | 20:35 | |
| *** y_sawai has quit IRC | 20:36 | |
| *** yaya has joined #openstack-security | 20:41 | |
| *** asd112z_ has quit IRC | 20:51 | |
| *** asd112z has joined #openstack-security | 20:52 | |
| *** asd112z has quit IRC | 20:52 | |
| *** asd112z has joined #openstack-security | 20:53 | |
| *** jian5397 has quit IRC | 21:00 | |
| *** openstackgerrit has quit IRC | 21:01 | |
| *** openstackgerrit has joined #openstack-security | 21:01 | |
| *** elo1 has joined #openstack-security | 21:21 | |
| *** elo1 has quit IRC | 21:22 | |
| *** elo1 has joined #openstack-security | 21:22 | |
| *** singlethink has joined #openstack-security | 21:25 | |
| *** profor has left #openstack-security | 21:25 | |
| *** singlet__ has joined #openstack-security | 21:27 | |
| *** singleth_ has quit IRC | 21:28 | |
| *** singlethink has quit IRC | 21:30 | |
| *** jamielennox has quit IRC | 21:36 | |
| *** timkennedy has quit IRC | 21:37 | |
| *** timkennedy has joined #openstack-security | 21:37 | |
| *** jamielennox has joined #openstack-security | 21:38 | |
| *** alejandrito has joined #openstack-security | 21:39 | |
| *** elo1 has quit IRC | 21:51 | |
| *** alejandrito has quit IRC | 21:51 | |
| *** edmondsw has quit IRC | 21:59 | |
| *** bknudson has quit IRC | 22:08 | |
| *** singlet__ has quit IRC | 22:09 | |
| *** sdake_ has joined #openstack-security | 22:15 | |
| *** sdake has quit IRC | 22:18 | |
| *** jmckind has quit IRC | 22:19 | |
| *** dwyde has quit IRC | 22:36 | |
| *** sdake_ is now known as sdake | 22:41 | |
| *** yaya has quit IRC | 22:42 | |
| *** markvoelker has quit IRC | 22:46 | |
| *** markvoelker has joined #openstack-security | 22:54 | |
| *** sicarie has quit IRC | 23:06 | |
| *** voodookid has quit IRC | 23:11 | |
| *** jian5397 has joined #openstack-security | 23:17 | |
| *** tmcpeak has quit IRC | 23:41 | |
| *** jian5397 has quit IRC | 23:57 | |
| *** asd112z has quit IRC | 23:57 | |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!