ccneill | yeah, you really can't test production instances with this without a cleanup mechanism of some kind lol | 00:01 |
---|---|---|
*** zul has quit IRC | 00:01 | |
unrahul | yeah ..:D | 00:02 |
unrahul | I had to login and clean up a few times today.. | 00:03 |
*** sicarie has quit IRC | 00:05 | |
*** trisq has joined #openstack-security | 00:26 | |
*** austin987 has joined #openstack-security | 00:30 | |
*** tmcpeak has quit IRC | 00:58 | |
*** diazjf has joined #openstack-security | 00:59 | |
*** diazjf has quit IRC | 00:59 | |
*** trisq has quit IRC | 01:03 | |
*** mdong has joined #openstack-security | 01:08 | |
*** salv-orlando has joined #openstack-security | 01:23 | |
*** salv-orlando has quit IRC | 01:26 | |
*** trisq has joined #openstack-security | 01:29 | |
*** tmcpeak has joined #openstack-security | 01:32 | |
*** sdake has joined #openstack-security | 01:32 | |
*** openstack has joined #openstack-security | 01:42 | |
*** ccneill has quit IRC | 02:04 | |
*** salv-orlando has joined #openstack-security | 02:33 | |
*** tmcpeak has quit IRC | 02:35 | |
*** salv-orlando has quit IRC | 02:43 | |
*** yuanying has quit IRC | 02:47 | |
*** mdong has quit IRC | 03:29 | |
*** salv-orlando has joined #openstack-security | 03:42 | |
*** salv-orlando has quit IRC | 03:49 | |
*** yuanying has joined #openstack-security | 03:51 | |
*** markvoelker has quit IRC | 04:30 | |
*** markvoelker has joined #openstack-security | 04:31 | |
*** dikonoor has joined #openstack-security | 04:39 | |
*** woodster_ has quit IRC | 04:39 | |
*** can8dnSix has joined #openstack-security | 04:40 | |
*** salv-orlando has joined #openstack-security | 04:52 | |
*** dikonoor has quit IRC | 04:54 | |
*** dikonoor has joined #openstack-security | 04:56 | |
*** sdake has quit IRC | 04:56 | |
*** salv-orl_ has joined #openstack-security | 04:59 | |
*** salv-orl_ has quit IRC | 04:59 | |
*** salv-orlando has quit IRC | 04:59 | |
*** salv-orlando has joined #openstack-security | 05:00 | |
*** sdake has joined #openstack-security | 05:00 | |
*** can8dnSix has quit IRC | 05:10 | |
*** zhihui has quit IRC | 05:12 | |
*** dikonoor has quit IRC | 05:33 | |
*** dikonoor has joined #openstack-security | 05:48 | |
*** sdake_ has joined #openstack-security | 05:56 | |
*** sdake has quit IRC | 05:58 | |
*** austin987 has quit IRC | 06:00 | |
*** dikonoor has quit IRC | 06:03 | |
*** liverpooler has quit IRC | 06:21 | |
*** austin987 has joined #openstack-security | 06:45 | |
*** salv-orlando has quit IRC | 06:54 | |
*** trisq has quit IRC | 07:01 | |
*** trisq has joined #openstack-security | 07:02 | |
*** tesseract- has joined #openstack-security | 07:04 | |
*** trisq has quit IRC | 07:08 | |
*** trisq has joined #openstack-security | 07:09 | |
*** jass93 has quit IRC | 07:13 | |
*** austin987 has quit IRC | 07:14 | |
*** trisq has quit IRC | 07:14 | |
*** trisq has joined #openstack-security | 07:15 | |
*** knangia has quit IRC | 07:21 | |
*** liverpooler has joined #openstack-security | 07:22 | |
openstackgerrit | chen.xing proposed openstack/security-doc: Set the picture width https://review.openstack.org/367143 | 07:28 |
*** openstackgerrit has quit IRC | 07:33 | |
*** openstackgerrit has joined #openstack-security | 07:34 | |
*** austin987 has joined #openstack-security | 07:34 | |
*** austin987 has quit IRC | 07:40 | |
*** jass93 has joined #openstack-security | 07:50 | |
*** salv-orlando has joined #openstack-security | 07:59 | |
*** salv-orlando has quit IRC | 08:01 | |
*** Mateuyeu has joined #openstack-security | 08:10 | |
*** sdake_ is now known as sdake | 08:17 | |
*** salv-orlando has joined #openstack-security | 08:23 | |
*** dikonoor has joined #openstack-security | 08:24 | |
*** Mateuyeu has quit IRC | 08:28 | |
*** salv-orl_ has joined #openstack-security | 08:30 | |
*** salv-orlando has quit IRC | 08:33 | |
*** shohel has joined #openstack-security | 08:38 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/367250 | 09:42 |
*** sirbt has joined #openstack-security | 10:49 | |
sirbt | where can i find a meteor channel | 10:51 |
*** dikonoor has quit IRC | 10:53 | |
*** trisq has quit IRC | 11:12 | |
*** salv-orl_ has quit IRC | 11:22 | |
*** dikonoor has joined #openstack-security | 11:23 | |
*** dikonoor has quit IRC | 11:28 | |
*** dikonoor has joined #openstack-security | 11:29 | |
*** sirbt has quit IRC | 11:36 | |
*** dikonoor has quit IRC | 11:40 | |
*** sirbt has joined #openstack-security | 11:47 | |
*** sirbt has quit IRC | 11:54 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/367250 | 12:05 |
*** dikonoor has joined #openstack-security | 12:54 | |
*** cleong has joined #openstack-security | 12:56 | |
*** liverpooler has quit IRC | 12:58 | |
*** liverpooler has joined #openstack-security | 13:01 | |
*** sdake_ has joined #openstack-security | 13:20 | |
*** sdake has quit IRC | 13:22 | |
*** liverpooler has quit IRC | 13:28 | |
*** liverpooler has joined #openstack-security | 13:30 | |
*** salv-orlando has joined #openstack-security | 13:34 | |
*** salv-orlando has quit IRC | 13:42 | |
*** woodster_ has joined #openstack-security | 13:45 | |
*** liverpooler has quit IRC | 13:55 | |
*** jmckind has joined #openstack-security | 13:59 | |
*** mvaldes has joined #openstack-security | 14:03 | |
*** jass93 has quit IRC | 14:05 | |
*** sdake has joined #openstack-security | 14:10 | |
*** sdake_ has quit IRC | 14:12 | |
*** shohel has quit IRC | 14:19 | |
*** shohel has joined #openstack-security | 14:19 | |
*** zul has joined #openstack-security | 14:20 | |
*** zul has quit IRC | 14:22 | |
*** zul has joined #openstack-security | 14:23 | |
*** singlethink has joined #openstack-security | 14:36 | |
*** knangia has joined #openstack-security | 14:38 | |
*** scarab_ has joined #openstack-security | 14:39 | |
*** salv-orlando has joined #openstack-security | 14:40 | |
*** dikonoor has quit IRC | 14:52 | |
*** vinaypotluri has joined #openstack-security | 14:53 | |
*** shohel has quit IRC | 14:53 | |
*** sirbt has joined #openstack-security | 14:54 | |
*** tmcpeak has joined #openstack-security | 14:57 | |
*** diazjf has joined #openstack-security | 14:57 | |
*** scarab_ has quit IRC | 15:10 | |
*** sdake_ has joined #openstack-security | 15:21 | |
*** sdake has quit IRC | 15:22 | |
*** diazjf has quit IRC | 15:28 | |
*** austin987 has joined #openstack-security | 15:31 | |
*** zul has quit IRC | 15:39 | |
*** zul has joined #openstack-security | 15:40 | |
*** diazjf has joined #openstack-security | 15:40 | |
*** zul has quit IRC | 15:40 | |
*** zul has joined #openstack-security | 15:41 | |
*** browne has joined #openstack-security | 15:44 | |
*** sicarie has joined #openstack-security | 15:45 | |
*** diazjf has quit IRC | 16:00 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Upgrading memoize to memoize functions with same kwargs as well https://review.openstack.org/367481 | 16:02 |
*** ccneill has joined #openstack-security | 16:05 | |
*** liverpooler has joined #openstack-security | 16:08 | |
*** mdong has joined #openstack-security | 16:15 | |
ccneill | unrahul, vinaypotluri, knangia, mdong : looks like our vidyo room has been co-opted | 16:16 |
mdong | osic-5? | 16:16 |
ccneill | I'm in OSIC-5 right now | 16:16 |
ccneill | does everyone have the link? | 16:16 |
*** woodburn has left #openstack-security | 16:16 | |
ccneill | mdong and I have a hard stop at 11:30 today | 16:16 |
*** woodburn has joined #openstack-security | 16:17 | |
knangia | ccneill: which room do we have meeting | 16:17 |
knangia | Our room is used by other team | 16:17 |
mdong | Osic-5-recordable | 16:18 |
knangia | Whats the room extension | 16:18 |
mdong | 4000351 | 16:19 |
*** diazjf has joined #openstack-security | 16:20 | |
*** tesseract- has quit IRC | 16:21 | |
*** tkelsey has joined #openstack-security | 16:22 | |
*** ametts has joined #openstack-security | 16:32 | |
*** jmckind_ has joined #openstack-security | 16:44 | |
*** jmckind has quit IRC | 16:47 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Fixing some documentation nits https://review.openstack.org/367509 | 16:48 |
*** mvaldes has quit IRC | 16:50 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Fixing some documentation nits https://review.openstack.org/367509 | 16:54 |
openstackgerrit | Eric Brown proposed openstack/anchor: Anchor can now be installed and invoked as simply "anchor" https://review.openstack.org/221290 | 17:01 |
*** sirbt has quit IRC | 17:03 | |
*** sirbt has joined #openstack-security | 17:06 | |
*** zul has quit IRC | 17:10 | |
*** zul has joined #openstack-security | 17:14 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/anchor: Updated from global requirements https://review.openstack.org/314347 | 17:16 |
*** sirbt has quit IRC | 17:19 | |
*** sirbt has joined #openstack-security | 17:23 | |
*** diazjf has quit IRC | 17:23 | |
*** sirbt has quit IRC | 17:27 | |
*** sirbt has joined #openstack-security | 17:30 | |
*** sirbt has quit IRC | 17:40 | |
*** sirbt has joined #openstack-security | 17:43 | |
*** sirbt has quit IRC | 17:55 | |
*** sirbt has joined #openstack-security | 17:57 | |
*** jass93 has joined #openstack-security | 17:58 | |
*** sirbt has quit IRC | 18:02 | |
*** sirbt has joined #openstack-security | 18:02 | |
*** mdong has quit IRC | 18:04 | |
openstackgerrit | Merged openstack/syntribos: Fixing some documentation nits https://review.openstack.org/367509 | 18:06 |
*** sirbt has quit IRC | 18:07 | |
*** sirbt has joined #openstack-security | 18:08 | |
openstackgerrit | Khanak Nangia proposed openstack/security-doc: Updated OSSN-0073 Added information about horizon dashboard leaks https://review.openstack.org/357328 | 18:14 |
*** lhinds is now known as lhinds|away | 18:15 | |
*** sirbt has quit IRC | 18:18 | |
*** sirbt has joined #openstack-security | 18:22 | |
*** sdake_ is now known as sdake | 18:27 | |
*** tkelsey has quit IRC | 18:32 | |
*** diazjf has joined #openstack-security | 18:36 | |
unrahul | hey ccneill I am working the networks subnets and ports part | 18:51 |
ccneill | seeing anything cool? | 18:51 |
unrahul | :| .. nop.. getting my act together.. so.. lets c.. | 18:52 |
unrahul | what about u..? anything cool? | 18:52 |
ccneill | trying to get devstack to work :| | 18:53 |
ccneill | gonna send an email soon about my lessons learned | 18:53 |
unrahul | okay ccneill | 18:55 |
*** salv-orlando has quit IRC | 19:06 | |
*** jmckind_ has quit IRC | 19:07 | |
*** jmckind has joined #openstack-security | 19:08 | |
*** tmcpeak has quit IRC | 19:21 | |
*** jass93 has quit IRC | 19:31 | |
*** mvaldes has joined #openstack-security | 19:32 | |
*** sicarie has quit IRC | 19:33 | |
*** sicarie has joined #openstack-security | 19:35 | |
*** diazjf has quit IRC | 19:39 | |
*** mdong has joined #openstack-security | 19:42 | |
*** singlethink has quit IRC | 19:45 | |
*** singlethink has joined #openstack-security | 19:47 | |
*** sdake_ has joined #openstack-security | 19:50 | |
*** diazjf has joined #openstack-security | 19:50 | |
*** sdake has quit IRC | 19:52 | |
openstackgerrit | Merged openstack/security-doc: [sec-guide] Consistent the 'Nginx' term https://review.openstack.org/366457 | 20:00 |
*** jass93 has joined #openstack-security | 20:10 | |
*** jmckind_ has joined #openstack-security | 20:12 | |
*** jmckind has quit IRC | 20:15 | |
*** salv-orlando has joined #openstack-security | 20:18 | |
openstackgerrit | Merged openstack/security-doc: Updated OSSN-0073 Added information about horizon dashboard leaks https://review.openstack.org/357328 | 20:19 |
*** mvaldes has quit IRC | 20:21 | |
*** salv-orlando has quit IRC | 20:22 | |
*** mdong has quit IRC | 20:24 | |
*** salv-orlando has joined #openstack-security | 20:33 | |
unrahul | hey ccneill | 20:51 |
ccneill | sup unrahul | 20:51 |
unrahul | I got a few input validation issues with the openstack client.. not neutron.. basically it doesn't validate terminal control characters.. | 20:52 |
unrahul | nothing major.. | 20:52 |
unrahul | how about u..? | 20:52 |
ccneill | unrahul: nice! I think the terminal chars thing is probably worth calling out | 20:53 |
ccneill | still trying to get devstack to work | 20:53 |
ccneill | v_v | 20:53 |
ccneill | lots of Rackspace meetings today.. got a Security Engineering meeting with our VP in 5 | 20:53 |
unrahul | oh really.. yeah.. i didt play much with it.. but basically I can paint the entire screen whatever color I want etc by creating a network.. | 20:53 |
ccneill | had to disable the proxy stuff.. was getting to be too much of a pain during the install process | 20:53 |
unrahul | ohh. | 20:53 |
ccneill | haha nice! | 20:54 |
unrahul | hehe.. yeah.. :D | 20:54 |
ccneill | I'm sure there are probably other interesting things you could do there.. | 20:54 |
unrahul | yeah.. thats where I was looking into.. but it is openstack client not neutron.. so.. does that matter? | 20:55 |
ccneill | well, you'll report it to the openstack client launchpad, but you can mention neutron as one affected project | 20:56 |
*** diazjf has quit IRC | 20:57 | |
ccneill | I don't think neutron will do any additional filtering, but the openstack client can | 20:57 |
ccneill | similar to if we found a second-order XSS with horizon - we'd probably want to handle that in horizon instead of neutron | 20:57 |
ccneill | or at least that's my experience - project teams rarely want to change their API outputs, and suggest that the frontends handle it | 20:57 |
unrahul | I tried a few.. like <script></script> but seems the framework is filtering those out.. | 20:59 |
unrahul | makes sense | 20:59 |
unrahul | ccneill: | 20:59 |
ccneill | unrahul: I figured as much - I think people have found a number of issues over the years, so it might take some digging to find more | 20:59 |
*** jmckind_ has quit IRC | 21:03 | |
unrahul | yeah... cant wait to find a major vuln :D | 21:04 |
*** diazjf has joined #openstack-security | 21:09 | |
*** ametts has quit IRC | 21:19 | |
*** sicarie has quit IRC | 21:20 | |
*** sicarie has joined #openstack-security | 21:20 | |
*** tmcpeak has joined #openstack-security | 21:22 | |
*** cleong has quit IRC | 21:30 | |
*** diazjf has quit IRC | 21:31 | |
*** ametts has joined #openstack-security | 21:31 | |
*** ametts has quit IRC | 21:57 | |
*** mvaldes has joined #openstack-security | 21:59 | |
*** mdong has joined #openstack-security | 22:00 | |
*** sicarie has quit IRC | 22:01 | |
*** sicarie has joined #openstack-security | 22:02 | |
*** mvaldes has quit IRC | 22:03 | |
*** jass93 has quit IRC | 22:05 | |
*** jass93 has joined #openstack-security | 22:09 | |
*** tristanC has quit IRC | 22:12 | |
*** tristanC has joined #openstack-security | 22:13 | |
*** sdake has joined #openstack-security | 22:34 | |
ccneill | YES | 22:36 |
ccneill | looks like devstack installed successfully.. | 22:36 |
*** sdake_ has quit IRC | 22:36 | |
*** mdong has quit IRC | 22:38 | |
ccneill | Horizon seems to be pretty sluggish.. | 22:38 |
ccneill | on my vm anyway | 22:38 |
*** tkelsey has joined #openstack-security | 22:40 | |
*** singlethink has quit IRC | 22:42 | |
*** tkelsey has quit IRC | 22:45 | |
*** elmiko is now known as _elmiko | 22:47 | |
unrahul | yay! | 22:50 |
unrahul | yeah horizon.. is a tad sluggish. | 22:51 |
unrahul | I have give 8 GB as my vm memory | 22:51 |
unrahul | so its kinda okay | 22:51 |
ccneill | sigh.. of course, tried to reload the vm | 22:51 |
ccneill | and it threw up all over me :( | 22:51 |
ccneill | re-provisioning now.. should only take another decade :P | 22:51 |
ccneill | but I think I got all the kinks worked out, other than vagrant being weird | 22:52 |
ccneill | gonna try to run syntribos against neutron tonight, hopefully +admin | 22:52 |
ccneill | here goes nothing.. | 22:54 |
*** sicarie has quit IRC | 22:59 | |
*** sdake has quit IRC | 22:59 | |
ccneill | gotta say, it is pretty darn cool watching a bash script handle all the complexity of openstack and it Just Works™ | 23:02 |
ccneill | lol, pretty dire warning on the readme though: "DevStack runs rampant over the system it runs on, installing things and uninstalling other things. Running this on a system you care about is a recipe for disappointment, or worse." | 23:06 |
ccneill | mm then there's this nugget: https://github.com/openstack-dev/devstack/blob/master/stack.sh#L124 | 23:15 |
ccneill | create a ~/.no-devstack file on your host system so you don't accidentally defile it with devstack lol | 23:16 |
*** markvoelker has quit IRC | 23:25 | |
*** jass93 has quit IRC | 23:28 | |
vinaypotluri | ccneill: take a snapshot of the virtual machine state... | 23:35 |
vinaypotluri | if you reboot the VM directly, then the services might not boot properly | 23:36 |
ccneill | good point, will do! | 23:36 |
unrahul | :D | 23:52 |
unrahul | hehe yeah liked the statement on devstack read me | 23:52 |
unrahul | yeah suspending is a good option.. often I have had to re run stack.sh | 23:52 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!