SlideShare ist ein Scribd-Unternehmen logo
1 von 39
NO SUCH THING AS A
SECURE APPLICATION!
@mullican
@mullican
ASHEVILLE, NC • RAILS SINCE 2006
@mullican
CONVERSATIONS WITH
MANAGEMENT !
"IS THIS APP SECURE?"
"HOW SECURE IS THIS APP?"
@mullican
RISK !
@mullican
MORE USEFUL QUESTIONS
WHAT CAN GO WRONG? • HOW LIKELY IS IT TO GO WRONG?
HOW CAN WE STOP IT GOING WRONG?
WHAT HAPPENS IF IT GOES WRONG ANYWAY?
@mullican
MORE USEFUL QUESTIONS
WHAT CAN GO WRONG? • HOW LIKELY IS IT TO GO WRONG?
HOW CAN WE STOP IT GOING WRONG?
WHAT HAPPENS IF IT GOES WRONG ANYWAY?
@mullican
MORE USEFUL QUESTIONS
WHAT CAN GO WRONG? • HOW LIKELY IS IT TO GO WRONG?
HOW CAN WE STOP IT GOING WRONG?
WHAT HAPPENS IF IT GOES WRONG ANYWAY?
@mullican
MORE USEFUL QUESTIONS
WHAT CAN GO WRONG? • HOW LIKELY IS IT TO GO WRONG?
HOW CAN WE STOP IT GOING WRONG?
WHAT HAPPENS IF IT GOES WRONG ANYWAY?
@mullican
RESIDUAL RISK
@mullican
WHAT CAN GO WRONG?
( AND HOW LIKELY IS IT? ) !
@mullican
THREAT MODELING !
@mullican
More LIKELY
Less DAMAGING
More DAMAGING
Less LIKELY
@mullican
More LIKELY
Less DAMAGING
More DAMAGING
Less LIKELY
• SQL injection
• Vulnerable
dependencies
• Malware upload
• Phished admin
credentials
• Malicious
insider
• DDOS
• Side-channel
attacks on auth
process
• Open redirectabuse
• Abuse of
password
reset process
@mullican
HOW DO WE STOP IT
FROM GOING WRONG?!
@mullican
CORRECT
IMPLEMENTATION
IS THE HARD PART
@mullican
TEST ALL THE THINGS⛔ ✅
@mullican
EXPLICIT TESTS
Scenario: Attempting direct access to an order I don't own
Given order "1234" belongs to "client@example.com"
And I have logged in as "bad.actor@example.com"
When I navigate directly to order "1234"
Then I should see "Access Denied"
And the Slack channel "#security" should be notified
@mullican
EXPLICIT TESTS ARE MOST USEFUL FOR:
DOCUMENTING EXPECTED BEHAVIOR
CATCHING REGRESSIONS
@mullican
STATIC ANALYSIS
== Warnings ==
Confidence: High
Category: SQL Injection
Check: SQL
Message: Possible SQL injection
Code: Person.order(params[:sort_by])
File: app/controllers/people_controller.rb
Line: 3
@mullican
STATIC ANALYSIS IS MOST USEFUL FOR:
FINDING CONFIGURATION PROBLEMS
CATCHING UNSAFE USE OF USER INPUT
@mullican
DYNAMIC ANALYSIS
---------------------------------------------------------------------------
+ Target IP: 127.0.0.1
+ Target Hostname: localhost
+ Target Port: 3000
+ Start Time: 2019-04-01 12:00:00 (GMT-4)
---------------------------------------------------------------------------
+ Server: No banner retrieved
+ Uncommon header 'x-runtime' found, with contents: 0.012730
+ Uncommon header 'x-request-id' found, with contents: 986c90ad-cd80-402b-9e9c-18218a279d4f
+ Uncommon header 'x-web-console-session-id' found, with contents: 9c9b9e420b09ad9f0ca20db64aebaf33
+ No CGI Directories found (use '-C all' to force check all possible dirs)
+ ///etc/passwd: The server install allows reading of any system file by adding an extra '/' to the URL.
@mullican
DYNAMIC ANALYSIS IS MOST USEFUL FOR:
GENERATING LOTS OF UNEXPECTED INPUT
TESTING THE FULL REQUEST STACK
CHECKING KNOWN VULNERABILITY PATTERNS
SIMULATING AN AUTOMATED ATTACK
@mullican
MANUAL TESTING
@mullican
MANUAL TESTING IS MOST USEFUL FOR:
INFERRING LESS OBVIOUS VULNERABILITIES
SIMULATING A TARGETED ATTACK
@mullican
DEFENSE IN DEPTH
@mullican
WHAT HAPPENS IF IT
GOES WRONG ANYWAY?!
@mullican
EXPLOITS TAKE TIME !
@mullican
IN-APP ALERTING
# config/routes.rb
Rails.application.routes.draw do
get 'admin', to: 'tripwire#alert'
end
@mullican
IN-APP ALERTING
# app/controllers/tripwire_controller.rb
class TripwireController < ApplicationController
def alert
notify_support_team if current_user.present?
head :not_found
end
private
def notify_support_team
# Danger, Will Robinson!
end
end
@mullican
AUTOMATED RESPONSE
# config/routes.rb
Rails.application.routes.draw do
get 'wp-admin', to: 'tripwire#block'
end
@mullican
# app/controllers/tripwire_controller.rb
class TripwireController < ApplicationController
BLOCK_DURATION = 6.hours
def block
block_request_source
head :not_found
end
private
def block_request_source
Rails.logger.warn("Blocking client #{request.remote_ip}")
Rails.cache.write(cache_key_for_block, true, expires_in: BLOCK_DURATION)
end
def cache_key_for_block
['blocked-ip', request.remote_ip]
end
end
@mullican
AUTOMATED RESPONSE
# config/initializers/rack_attack.rb
Rails.application.config.middleware.use Rack::Attack
Rack::Attack.blocklist('tripwires') do |request|
Rails.cache.read(['blocked-ip', request.ip])
end
@mullican
PLAN AHEAD
@mullican
RESILIENCE!
@mullican
CULTURAL RESILIENCE
@mullican
SECURITY IMPOSTOR
SYNDROME !
@mullican
SECURITY IMPOSTOR
SYNDROME !
@mullican
CONVERSATIONAL TOOLS
AGREED THREAT MODEL • WRITTEN CODE EXPECTATIONS
PUBLIC TEST OUTPUT • RESPONSE PLANS AND POSTMORTEMS
@mullican
Tools Further Reading
Brakeman
brakemanscanner.org
Rails Security Guide
OWASP Secure Coding Practices
OWASP Top Ten
US-CERT
Gems:
rubysec/bundler-audit
kickstarter/rack-attack
@mullican

Weitere ähnliche Inhalte

Kürzlich hochgeladen

Kürzlich hochgeladen (20)

Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data DiscoveryTrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
TrustArc Webinar - Unlock the Power of AI-Driven Data Discovery
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdfUnderstanding Discord NSFW Servers A Guide for Responsible Users.pdf
Understanding Discord NSFW Servers A Guide for Responsible Users.pdf
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024Partners Life - Insurer Innovation Award 2024
Partners Life - Insurer Innovation Award 2024
 
Handwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed textsHandwritten Text Recognition for manuscripts and early printed texts
Handwritten Text Recognition for manuscripts and early printed texts
 
HTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation StrategiesHTML Injection Attacks: Impact and Mitigation Strategies
HTML Injection Attacks: Impact and Mitigation Strategies
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 

Empfohlen

Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Empfohlen (20)

PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 
12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work12 Ways to Increase Your Influence at Work
12 Ways to Increase Your Influence at Work
 
ChatGPT webinar slides
ChatGPT webinar slidesChatGPT webinar slides
ChatGPT webinar slides
 
More than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike RoutesMore than Just Lines on a Map: Best Practices for U.S Bike Routes
More than Just Lines on a Map: Best Practices for U.S Bike Routes
 
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
Ride the Storm: Navigating Through Unstable Periods / Katerina Rudko (Belka G...
 
Barbie - Brand Strategy Presentation
Barbie - Brand Strategy PresentationBarbie - Brand Strategy Presentation
Barbie - Brand Strategy Presentation
 

No Such Thing as a Secure Application - RailsConf 2019