openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding unittests for glance client https://review.openstack.org/371224 | 00:11 |
---|---|---|
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding unittest for neutron client extension https://review.openstack.org/371219 | 00:16 |
*** markvoelker has joined #openstack-security | 00:34 | |
*** tmcpeak has joined #openstack-security | 00:35 | |
*** austin987 has joined #openstack-security | 00:53 | |
*** jass93 has joined #openstack-security | 01:00 | |
*** browne has quit IRC | 01:14 | |
*** salv-orl_ has joined #openstack-security | 01:41 | |
*** salv-orlando has quit IRC | 01:43 | |
*** tkelsey has joined #openstack-security | 01:47 | |
*** tkelsey has quit IRC | 01:51 | |
*** diazjf has joined #openstack-security | 02:04 | |
*** jass93 has quit IRC | 02:07 | |
*** knangia has quit IRC | 02:21 | |
*** catintheroof has joined #openstack-security | 02:27 | |
*** jass93 has joined #openstack-security | 02:28 | |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/371222 | 02:30 |
*** jass93 has quit IRC | 02:32 | |
*** jass93 has joined #openstack-security | 02:33 | |
*** yuanying has quit IRC | 02:47 | |
*** browne has joined #openstack-security | 02:53 | |
*** tmcpeak has quit IRC | 02:59 | |
*** sdake_ has quit IRC | 03:01 | |
*** vinaypotluri has quit IRC | 03:02 | |
*** browne has quit IRC | 03:12 | |
*** vinaypotluri has joined #openstack-security | 03:18 | |
*** dave-mccowan has quit IRC | 04:08 | |
*** austin987 has quit IRC | 04:12 | |
*** yuanying has joined #openstack-security | 04:13 | |
*** diazjf has quit IRC | 04:17 | |
*** austin987 has joined #openstack-security | 04:24 | |
*** markvoelker has quit IRC | 04:28 | |
*** rcernin has quit IRC | 04:37 | |
*** tkelsey has joined #openstack-security | 04:49 | |
*** tkelsey has quit IRC | 04:53 | |
*** austin987 has quit IRC | 05:12 | |
*** woodster_ has quit IRC | 05:20 | |
*** markvoelker has joined #openstack-security | 05:28 | |
*** markvoelker has quit IRC | 05:33 | |
*** rcernin has joined #openstack-security | 05:43 | |
*** austin987 has joined #openstack-security | 06:13 | |
*** rcernin has quit IRC | 06:14 | |
*** rcernin has joined #openstack-security | 06:19 | |
*** pcaruana has joined #openstack-security | 06:23 | |
*** vinaypotluri has quit IRC | 06:42 | |
*** salv-orl_ has quit IRC | 06:48 | |
*** salv-orlando has joined #openstack-security | 06:48 | |
*** tkelsey has joined #openstack-security | 06:51 | |
*** tkelsey has quit IRC | 06:55 | |
*** shohel has joined #openstack-security | 07:04 | |
*** julian1 has quit IRC | 07:19 | |
*** lhinds has quit IRC | 07:20 | |
*** lhinds has joined #openstack-security | 07:20 | |
*** julian1 has joined #openstack-security | 07:20 | |
*** markvoelker has joined #openstack-security | 07:29 | |
*** markvoelker has quit IRC | 07:34 | |
*** tkelsey has joined #openstack-security | 08:01 | |
*** openstackgerrit has quit IRC | 08:03 | |
*** openstackgerrit has joined #openstack-security | 08:04 | |
*** salv-orl_ has joined #openstack-security | 08:27 | |
*** salv-orlando has quit IRC | 08:31 | |
*** gszafranski has joined #openstack-security | 08:43 | |
*** gszafranski has quit IRC | 08:44 | |
*** gszafranski has joined #openstack-security | 08:45 | |
*** tkelsey has quit IRC | 09:43 | |
openstackgerrit | Emma Foley proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/371222 | 10:15 |
openstackgerrit | OpenStack Proposal Bot proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/371222 | 10:22 |
*** shohel1 has joined #openstack-security | 10:36 | |
*** shohel1 has quit IRC | 10:36 | |
*** shohel has quit IRC | 10:37 | |
openstackgerrit | Andreas Jaeger proposed openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/371222 | 10:37 |
*** shohel has joined #openstack-security | 10:41 | |
*** sdake has joined #openstack-security | 10:42 | |
openstackgerrit | Merged openstack/security-doc: Updated from openstack-manuals https://review.openstack.org/371222 | 10:43 |
*** markvoelker has joined #openstack-security | 11:31 | |
*** markvoelker has quit IRC | 11:35 | |
*** catintheroof has quit IRC | 11:39 | |
*** shohel has quit IRC | 12:07 | |
*** shohel1 has joined #openstack-security | 12:07 | |
*** shohel1 has quit IRC | 12:11 | |
openstackgerrit | Doug Chivers proposed openstack/security-analysis: Initial draft of Barbican review https://review.openstack.org/357978 | 12:17 |
*** shohel has joined #openstack-security | 12:25 | |
*** markvoelker has joined #openstack-security | 12:26 | |
*** catintheroof has joined #openstack-security | 12:27 | |
*** edmondsw has joined #openstack-security | 12:32 | |
*** _elmiko is now known as elmiko | 12:51 | |
*** sdake_ has joined #openstack-security | 13:00 | |
*** sdake has quit IRC | 13:03 | |
*** dave-mccowan has joined #openstack-security | 13:07 | |
*** ayoung_ has joined #openstack-security | 13:11 | |
*** shohel has quit IRC | 13:49 | |
*** sdake_ has quit IRC | 13:52 | |
*** tmcpeak has joined #openstack-security | 14:15 | |
*** salv-orl_ has quit IRC | 14:23 | |
*** salv-orlando has joined #openstack-security | 14:24 | |
*** knangia has joined #openstack-security | 14:26 | |
*** mvaldes has joined #openstack-security | 14:29 | |
*** woodburn has quit IRC | 14:56 | |
*** woodburn has joined #openstack-security | 15:06 | |
*** diazjf has joined #openstack-security | 15:13 | |
*** sdake has joined #openstack-security | 15:14 | |
*** rcernin has quit IRC | 15:15 | |
*** diazjf has quit IRC | 15:16 | |
*** sdake_ has joined #openstack-security | 15:18 | |
*** sdake has quit IRC | 15:20 | |
*** vinaypotluri has joined #openstack-security | 15:26 | |
*** mdong has joined #openstack-security | 16:07 | |
*** jass93 has quit IRC | 16:12 | |
*** ccneill has joined #openstack-security | 16:36 | |
*** browne has joined #openstack-security | 16:43 | |
openstackgerrit | Merged openstack/syntribos: Minor modifications to the neutron templates https://review.openstack.org/371023 | 16:48 |
*** gfhellma has joined #openstack-security | 16:48 | |
*** agireud has quit IRC | 16:49 | |
*** diazjf has joined #openstack-security | 16:51 | |
*** agireud has joined #openstack-security | 16:51 | |
*** mwturvey has quit IRC | 16:56 | |
*** jass93 has joined #openstack-security | 16:59 | |
*** mvaldes has quit IRC | 17:04 | |
*** mvaldes has joined #openstack-security | 17:06 | |
*** capnoday has joined #openstack-security | 17:13 | |
*** sdake_ has quit IRC | 17:18 | |
*** diazjf has quit IRC | 17:36 | |
unrahul | hey ccneill | 18:08 |
unrahul | u there? | 18:08 |
ccneill | yep | 18:08 |
ccneill | what's up? | 18:08 |
unrahul | So, I ran bandit against glance and got a few ElementTree to parse untrusted XML data issues.. | 18:09 |
ccneill | nice, that's definitely worth looking into | 18:09 |
ccneill | need to figure out if they're remotely exploitable or if they would require file-system access | 18:09 |
unrahul | what do u think of this scenario https://github.com/openstack/glance/blob/master/glance/async/flows/ovf_process.py | 18:10 |
unrahul | cant the ovf file be anything ... like the user can give pretty much anything.. ryt..? do u see this as a possible attack surface? | 18:10 |
mdong | we haven’t ran bandit against these projects yet have w? | 18:10 |
unrahul | nop | 18:10 |
mdong | might be a good place to use it | 18:10 |
ccneill | yep, definitely worth a try | 18:11 |
*** dave-mcc_ has joined #openstack-security | 18:12 | |
unrahul | I am not sure how to set it up and give it a try.. let me see .. do you guys have any poinetrs on this? | 18:12 |
unrahul | ccneill: mdong ^ | 18:13 |
ccneill | how to set up bandit? | 18:13 |
mdong | I actually haven’t run it in a while, but I believe that it has some really good documentation | 18:13 |
mdong | https://github.com/openstack/bandit | 18:13 |
ccneill | yeah, I haven't used it for a little while myself | 18:13 |
unrahul | nop.. i have run bandit.. it was pretty straight forward | 18:14 |
unrahul | I wanted to setup the ovf thing and use a vulnerable xml .. | 18:15 |
*** dave-mccowan has quit IRC | 18:16 | |
ccneill | ah | 18:16 |
ccneill | that I'm not sure about | 18:16 |
mdong | me neither, it could be interesting to look into though, I know the etree package is susceptible to billion laughs | 18:17 |
unrahul | whoa neat.. got a doc to how to set up the ovf import. https://wiki.openstack.org/wiki/Enhanced-Platform-Awareness-OVF-Meta-Data-Import | 18:17 |
unrahul | let me try this out will let u guys know. | 18:17 |
ccneill | :thumbsup: | 18:19 |
ccneill | :) | 18:19 |
*** gfhellma has quit IRC | 18:34 | |
openstackgerrit | Doug Chivers proposed openstack/security-analysis: Initial draft of Barbican review https://review.openstack.org/357978 | 18:51 |
openstackgerrit | Doug Chivers proposed openstack/security-analysis: Initial draft of Barbican review https://review.openstack.org/357978 | 18:52 |
*** gfhellma has joined #openstack-security | 19:26 | |
*** diazjf has joined #openstack-security | 19:26 | |
*** diazjf has quit IRC | 19:27 | |
*** diazjf has joined #openstack-security | 19:37 | |
*** salv-orl_ has joined #openstack-security | 19:41 | |
*** salv-orlando has quit IRC | 19:43 | |
*** diazjf has quit IRC | 19:48 | |
*** sdake has joined #openstack-security | 19:59 | |
*** dave-mcc_ has quit IRC | 20:11 | |
*** diazjf has joined #openstack-security | 20:11 | |
*** gfhellma has quit IRC | 20:16 | |
*** diazjf has quit IRC | 20:24 | |
*** woodburn has left #openstack-security | 20:31 | |
*** dave-mccowan has joined #openstack-security | 20:33 | |
*** diazjf has joined #openstack-security | 20:34 | |
*** mdong has quit IRC | 20:35 | |
*** mdong has joined #openstack-security | 20:35 | |
*** sdake has quit IRC | 20:37 | |
*** dave-mccowan has quit IRC | 20:38 | |
*** mdong has quit IRC | 20:41 | |
*** mdong has joined #openstack-security | 20:42 | |
*** jass93 has quit IRC | 20:45 | |
*** edmondsw has quit IRC | 20:51 | |
openstackgerrit | Rahul U Nair proposed openstack/syntribos: Adding unittests for glance client https://review.openstack.org/371224 | 20:52 |
*** sdake has joined #openstack-security | 20:55 | |
*** jass93 has joined #openstack-security | 21:00 | |
openstackgerrit | Doug Chivers proposed openstack/security-analysis: Initial draft of Barbican review https://review.openstack.org/357978 | 21:04 |
*** mvaldes1 has joined #openstack-security | 21:06 | |
*** mvaldes has quit IRC | 21:09 | |
*** capnoday has quit IRC | 21:10 | |
*** diazjf has quit IRC | 21:16 | |
*** sdake has quit IRC | 21:20 | |
*** sdake has joined #openstack-security | 21:21 | |
*** salv-orl_ has quit IRC | 21:22 | |
*** salv-orlando has joined #openstack-security | 21:22 | |
*** sdake has quit IRC | 21:25 | |
openstackgerrit | Merged openstack/syntribos: Adding unittest for neutron client extension https://review.openstack.org/371219 | 21:37 |
*** mvaldes1 has quit IRC | 21:57 | |
*** jass93 has quit IRC | 22:00 | |
*** elmiko is now known as _elmiko | 22:09 | |
*** gszafranski has quit IRC | 22:10 | |
*** jass93 has joined #openstack-security | 22:19 | |
*** mdong has quit IRC | 22:24 | |
*** ayoung_ has quit IRC | 22:24 | |
*** catintheroof has quit IRC | 22:31 | |
*** mdong has joined #openstack-security | 22:32 | |
*** markvoelker has quit IRC | 22:34 | |
*** mdong has quit IRC | 23:22 |
Generated by irclog2html.py 2.14.0 by Marius Gedminas - find it at mg.pov.lt!