8000 Monthly Chat Agenda July (2020-07-06) · Issue #1836 · coreruleset/coreruleset · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Monthly Chat Agenda July (2020-07-06) #1836

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
fzipi opened this issue Jul 4, 2020 · 1 comment
Closed

Monthly Chat Agenda July (2020-07-06) #1836

fzipi opened this issue Jul 4, 2020 · 1 comment

Comments

@fzipi
Copy link
Member
fzipi commented Jul 4, 2020

This is the Agenda for the Monthly CRS Chat.

The chat is going to happen on https://owasp.slack.com in the channel #coreruleset on Monday, July 6th, at 20:30 CET.

Items on the Agenda: (see previous meetings decisions: here)

PRs

This is necessary because the migration of the repo was only possible to take PRs with us in forms of issues.

Other items

  • Status of CRS project co-lead Chaim Sanders - only if he is in the chat. Otherwise this is postponed for 1 month. MAX.
  • New DoS against libmodsecurity3 in conjunction with certain regexes, including 932100 (CVSS score of 7.5). Trustwave has merged a patch, but they deny it is a security issue. The issue was discovered by @airween and @theMiddleBlue and they are asking the project for guidance / potential support with a publication.
  • Consolidating projects hosted in CRS-support over the coreruleset umbrella:
    • ftw
    • modsecurity-docker
    • modsecurity-crs-docker
    • secrules_parsing
    • modsecurity-ansible-role
    • owasp-crs-documentation
  • Publication of wiki page with implementation issues with libmodsecurity3 by @airween
  • @Taiki-San of sqreen is thinking about stripping down the rule set to a distribution of rules that are guaranteed to never trigger a false positive. This picks up on the idea of a PL0 for ISPs.
  • Feedback from @dune73 after a two weeks in the HTTP Working Group chat where WAFs are discussed as a potential problem leading to protocol ossification

Feel free to add items as you see fit either above, or below as comments.

Open Issues

In January 2020, we decided to look into 10 issues at the chat every month. But only after the Other items. Pick the issues before the meeting and list them

If you are not yet on the OWASP Slack, here is your invite: https://owasp-slack.herokuapp.com/ .
Everybody is welcome to join our community chat.

@franbuehler franbuehler changed the title Monthly Chat Agenda June (2020-07-06) Monthly Chat Agenda July (2020-07-06) Jul 5, 2020
@dune73
Copy link
Member
dune73 commented Aug 3, 2020

Decisions

PRs

Other Items

  • @csanders-git is back into the project; now in the role of a developer; plans are the get the demo site to life and then try to write SSO rules (ensure that we don’t have XML signature wrapping or XXE and then there are also a whole bunch of JSON OIDC validations that can be done)
  • We plan to give TW a full 90 grace period until we publish the ModSec3 DoS, thus aiming for Monday, September 13. This is without any exploits appearing in the wild. If that happens we will publish sooner.
  • We support the 8000 idea of a rule exclusion package / PL 0 for hosters like proposed by @Taiki-San

Issues

Dedicated issue meeting was held on July 13

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants
0