Thursday, 2016-06-09

*** bpokorny_ has quit IRC01:23
*** JAHoagie has quit IRC05:26
*** salv-orlando has joined #openstack-security08:39
*** salv-orlando has joined #openstack-security12:49
*** salv-orlando has joined #openstack-security13:04
tmcpeakdstufft: you going under cover? :P14:43
dstuffttmcpeak: :D15:00
michaelxin@vinaypotluri ?15:58
michaelxinunrahul: ?15:59
michaelxinvinaypotluri: ?15:59
unrahulyup Michael15:59
michaelxinWhat size of T-shirt do you wear?15:59
michaelxinTrying to get OSIC T-shirts for you two.15:59
michaelxinHow about vinay?15:59
unrahulCool Michael,  Thanks.16:00
vinaypotlurimichaelxin small size16:02
michaelxinGot it. Thanks16:02
michaelxinI will send an email to Homer and include you two.16:02
michaelxinHow is testing against broken API using Syntribos?16:03
michaelxinIt should help you guys get better understanding about the process of API security testing.16:03
unrahulmichaelxin: what i got from it, we are leasing way too many options to the end user16:03
michaelxinmy concern is about adding values to the end user16:04
unrahulthere is very lil decision making, and as the tool is meant for developers and not security ppl I think, we should add bit more logic into it ,I feel that would make decision making for the end user easier16:05
michaelxinEspecially about the findings.16:05
michaelxinNo, the tool is meant for the security ppl.16:05
michaelxinWe need to work on it16:05
michaelxinThat is why we need you all16:05
unrahulbut then, when we integrate to the pipeline for example keystone or something, wouldnt it be better if the results are bit more focussed and clear cut?16:06
michaelxinEven for broken API, the results should be more focused and clear cut.16:07
michaelxinThere is a tech talk this afternoon about Ansible security and openstack16:07
unrahulyup I agree16:07
unrahuloh!.. in rackspace.??16:07
michaelxinTech Talk about Automated security hardening with OpenStack-Ansible16:08
michaelxinSAT6-2367-Snow Crash /VC; Vidyo room: 643116:08
michaelxin2:00 - 3:00pm16:08
michaelxinunrahul: Is the team using IRC a lot?16:08
michaelxinI do not think so.16:08
michaelxinWonder why you guys do not use IRC as often as I expect?16:09
unrahuloh.. thanks MIchael will join in16:09
unrahulwe do it not that often I guess..16:10
michaelxinWe can do it more.16:14
michaelxinI will ask questions more here.16:14
michaelxinI will miss the standup today.16:14
michaelxinunrahul: ccneill: How was the standup?16:39
ccneillmichaelxin: sounds like there may be some lingering errors in my signals code that unrahul has found, so we'll try to get that worked out today16:50
ccneillmichaelxin: also set up a 30 minute meeting tomorrow for us to discuss the questions we have here:
michaelxinnice job! unrahul!16:51
ccneilltrying to get feedback on those questions today before the meeting tomorrow so that we're not trying to come up with our thoughts on the spot in the meeting16:51
michaelxinhere is a good place to talk about them.16:51
ccneillany feedback would be appreciated if you have time to take a look16:51
ccneillthis room is good for discussion, but not so much for preserving the conversation we have16:52
michaelxinEvery convesation is logged16:53
unrahulthanks michaelxin , we are trying out the singals (http_signal2 branch) approach of writing tests16:53
ccneillmichaelxin: sure, but it's not as easy to sift through if it's not categorized16:53
ccneillunrahul: have you compared http_signal vs. http_signal2?16:54
michaelxinThat's true.16:54
unrahulmichaelxin: the version ccneill  wrote where signals uses an overloaded constructor and signals is kinda split into issues.16:54
ccneillI'm leaning toward the http_signal2 approach (no custom "signal types"), but curious what y'alls thoughts are16:54
michaelxinThere is no perfect solutino.16:54
michaelxinWhere is Mdong?16:55
mdongI’m here16:55
mdongI’ve also been adding to the etherpad16:55
unrahulmichaelxin: ccneill mdong  did you guys get time to check the way wfuzz shows results to the end user..? what do you guys think.?16:56
michaelxinDid you guys all spend time running Syntribos again the broken API? Review the results? Check the output for findings?16:57
michaelxinNot yet.16:57
michaelxinunrahul: Will look for sur.16:57
michaelxinI have something that I want.16:57
ccneillunrahul: not yet16:57
unrahulmichaelxin: yea we did Michael, I felt it was way too generic/broad and we need to add more logic to the tool end result  to give more informed suggestions, dont know if its the rating approach that ccneill  suggested , but something should be there.16:58
michaelxinWe need to streamline it. Category it based on severity.16:58
michaelxinIRC meeting17:01
ccneillmichaelxin: /j #openstack-meeting-alt17:01
ccneillderp derp derp..17:01
ccneillignore me17:01
michaelxinafter a two hour meeting for test strategy, need a break.17:02
*** mvaldes2 has quit IRC17:04
ccneillI bet17:05
*** mvaldes has joined #openstack-security17:05
tmcpeaknkinder: you around?17:23
nkindertmcpeak: I'm around, but in the middle of meetings17:24
tmcpeakahh ok17:24
tmcpeakwe've got another published OSSN, do you still want to handle the wiki and announce and stuff?17:24
*** browne has quit IRC17:52
nkindertmcpeak: yeah, I can handle it this afternoon17:52
unrahulmichaelxin: the output ryt now looks like this, , as we saw in the last meeting17:52
tmcpeaknkinder: thank you!17:53
unrahulmichaelxin:  this doesn't really put forward a concrete set of issues, but a lot of warnings, we really want to clean it up a bit, may be use error codes, and wiki approach .17:54
*** jhfeng has joined #openstack-security18:41
*** jhfeng has quit IRC18:46
*** mvaldes has quit IRC18:54
*** sdake has joined #openstack-security18:59
nkindertmcpeak: just to confirm, this is OSSN-0063, right?19:13
*** mvaldes has joined #openstack-security19:14
tmcpeaknkinder: yep!19:15
tmcpeak68 will be coming soon too19:15
nkindertmcpeak: cool.  Working on publishing it now.19:15
nkindertmcpeak: arg, line wrapping is off.  I'm going to get a quick patch in for it.19:16
tmcpeaknkinder: ahh crap, we should have checked that19:16
nkindereasy mistake.  No worries.19:17
nkindertmcpeak: stand by for a quick review19:17
*** vinaypotluri has joined #openstack-security19:19
*** davidjd-gh has joined #openstack-security19:22
openstackgerritNathan Kinder proposed openstack/security-doc: Correct line-wrapping in OSSN-0063
nkindertmcpeak: ^^^19:26
*** davidjd-gh has joined #openstack-security19:50
ccneillholy heck19:53
ccneillunrahul: wfuzz is SUPER fast... o_o19:53
nkindertmcpeak: ok, all published now.19:53
tmcpeaknkinder: thanks! you're awesome19:54
*** davidjd-gh has joined #openstack-security19:58
unrahulccneill: :o they are using multi threading it seems.20:05
ccneillI do like the simplicity of their output, but I'm not sure if it's such a good fit for us...20:06
unrahulccneill:  too late for us in the game.. and not sure how it helps in requests/resp time.. as we are spending most of the time there..20:06
ccneillunrahul: yeah, that's not my greatest concern at the moment, but it did surprise me20:06
ccneillunrahul: the output is very handy for saying "did it match one thing" but it doesn't really help you figure out exactly what happened20:06
unrahulccneill: yeah.. something in between ours and wfuzz type.. thing would be ideal..?20:07
unrahulccneill: yeah.. too minimal20:07
ccneillunrahul: it would be cool for our normal output to be similar though.. instead of just PASS/FAIL20:07
ccneilllike what it's printing in the terminal while it's running, not the actual results output20:07
unrahulccneill:  like..? error coding and  all?20:07
unrahulccneill:  oh yeah..20:08
ccneillI don't know.. just maybe something like "hey, this request for this test type failed"20:08
ccneillwith the path, status code, and test type20:08
ccneillnot too fancy20:08
ccneillbut again, that's not my biggest concern at the moment20:08
*** bpokorny has joined #openstack-security20:09
unrahulccneill:  yeah that cleans up a lil i guess.. though if all the tests are run.. then it would take a while to scroll through.20:10
ccneillunrahul: right.. it's really not for you to DO anything with, it's just to let you know "hey, this is what's going on right now"20:11
ccneillbut that's definitely not a top priority, just maybe something to think about sometime before 1.020:11
unrahulccneill:  yeah..20:11
unrahulccneill: +120:11
unrahulccneill: The stack trace I was getting, was because in the CORS test, as the new send_request returns a tuple of resp and signals, changed the test and its working fine.21:07
ccneillyeah I haven't finished updating the other tests yet21:20
ccneillI only worked on INT_OVERFLOW21:21
ccneillso we'll have to convert the rest of the tests, but I figured that was something that might be good for you, mdong, and vinaypotluri to look into so that you get experience with it21:21
ccneilland can get a feel for what the pain points are21:21
ccneilland what signals we still need to implement21:21
unrahulyup.. it helped21:21
unrahulthe INT_OVERFLOw tests21:21
unrahulusing that a reference21:21
*** ccneill has quit IRC22:45
