
OpenStack Security Group에서 제공하는 Python API 보안 테스트 도구
.. image:: http://governance.openstack.org/badges/syntribos.svg :target: http://governance.openstack.org/reference/tags/index.html
.. image:: http://img.shields.io/badge/docs-latest-brightgreen.svg?style=flat :target: http://docs.openstack.org/developer/syntribos/
.. image:: http://img.shields.io/pypi/v/syntribos.svg :target: http://pypi.python.org/pypi/syntribos/
.. image:: http://img.shields.io/pypi/pyversions/syntribos.svg :target: http://pypi.python.org/pypi/syntribos/
.. image:: http://img.shields.io/pypi/wheel/syntribos.svg :target: http://pypi.python.org/pypi/syntribos/
.. image:: http://img.shields.io/irc/%23openstack-security.png :target: http://webchat.freenode.net/?channels=openstack-security
Syntribos는 OpenStack 보안 프로젝트 <https://wiki.openstack.org/wiki/Security>_ 회원들이 유지 관리하는 오픈 소스 자동화 API 보안 테스트 도구입니다.
간단한 구성 파일과 예제 HTTP 요청이 주어지면, syntribos는 모든 API URL, URL 매개변수, HTTP 헤더 및 요청 본문 필드를 주어진 문자열 집합으로 대체할 수 있습니다. Syntribos는 요청 내 각 위치를 자동으로 반복합니다. Syntribos는 SQL 인젝션, LDAP 인젝션, 버퍼 오버플로 등과 같은 일반적인 보안 결함을 자동으로 탐지하는 것을 목표로 합니다. 또한 syntribos는 자동화된 퍼징을 통해 새로운 보안 결함을 식별하는 데 사용될 수 있습니다.
Syntribos는 모든 API를 테스트할 수 있는 기능을 가지고 있지만, OpenStack <https://www.openstack.org/>__ 애플리케이션을 염두에 두고 설계되었습니다.
테스트 목록~~~~~~~~~~~~~
With syntribos, you can initiate automated testing of any API with minimal configuration effort. Syntribos is ideal for testing the OpenStack API as it will help you in automatically downloading a set of templates of some of the bigger OpenStack projects like nova, neutron, keystone, etc.
A short list of tests that can be run using syntribos is given below:
Buffer overflow_ attacks, in the context of a web application,
force an application to handle more data than it can hold in a buffer.
In syntribos, a buffer overflow test is attempted by injecting a large
string into the body of an HTTP request.
Command injection_ attacks are done by injecting arbitrary commands in an
attempt to execute these commands on a remote system. In syntribos, this is
achieved by injecting a set of strings that have been proven as successful
executors of injection attacks.
CORS wildcard_ tests are used to verify if a web server allows cross-domain
resource sharing from any external URL (wild carding of
Access-Control-Allow-Origin header), rather than a white list of URLs.
Integer overflow_ tests in syntribos attempt to inject numeric values that
the remote application may fail to represent within its storage. For example,
injecting a 64 bit number into a 32 bit integer type.
Syntribos attempts LDAP injection_ attacks by injecting LDAP statements
into HTTP requests; if an application fails to properly sanitize the
request content, it may be possible to execute arbitrary commands.
SQL injection_ attacks are one of the most common web application attacks.
If the user input is not properly sanitized, it is fairly easy to
execute SQL queries that may result in an attacker reading sensitive
information or gaining control of the SQL server. In syntribos,
an application is tested for SQL injection vulnerabilities by injecting
SQL strings into the HTTP request.
Some string patterns are not sanitized effectively by the input validator and may cause the application to crash. String validation attacks in syntribos try to exploit this by inputting characters that may cause string validation vulnerabilities. For example, special unicode characters, emojis, etc.
XML external entity_ attacks target the web application's XML parser.
If an XML parser allows processing of external entities referenced in an
XML document then an attacker might be able to cause a denial of service,
or leakage of information, etc. Syntribos tries to inject a few malicious
strings into an XML body while sending requests to an application in an
attempt to obtain an appropriate response.
XSS_ attacks inject malicious JavaScript into a web
application. Syntribos tries to find potential XSS issues by injecting
string containing "script" and other HTML tags into request fields.
ReDoS_ attacks attempt to produce a denial of service by
providing a regular expression that takes a very long time to evaluate.
This can cause the regex engine to backtrack indefinitely, which can
slow down some parsers or even cause a processing halt. The attack
exploits the fact that most regular expression implementations have
an exponential time worst case complexity.
There is a possibility that the JSON parser will reach depth limit and crash, resulting in a successful overflow of the JSON parsers depth limit, leading to a DoS vulnerability. Syntribos tries to check for this, and raises an issue if the parser crashes.
This test gives users the ability to fuzz using user defined fuzz data and
provides an option to look for failure strings provided by the user. The fuzz
data needs to be provided using the config option [user_defined].
Example::
[user_defined] payload=<payload_file> failure_strings=<[list_of_failure_strings] # optional
Other than these built-in tests, you can extend syntribos by writing
your own custom tests. To do this, download the source code and look at
the tests in the syntribos/tests directory. The CORS test may be an easy
one to emulate. In the same way, you can also add different extensions
to the tests. To see how extensions can be written please see the
syntribos/extensions directory.
.. _buffer overflow: https://en.wikipedia.org/wiki/Buffer_overflow .. _Command injection: https://www.owasp.org/index.php/Command_Injection .. _CORS wildcard: https://www.owasp.org/index.php/Test_Cross_Origin_Resource_Sharing_(OTG-CLIENT-007) .. _Integer overflow: https://en.wikipedia.org/wiki/Integer_overflow .. _LDAP injection: https://www.owasp.org/index.php/LDAP_injection .. _SQL injection: https://www.owasp.org/index.php/SQL_Injection .. _XML external entity: https://www.owasp.org/index.php/XML_External_Entity_(XXE)_Processing .. _XSS: https://www.owasp.org/index.php/Cross-site_Scripting_(XSS) .. _ReDoS: https://en.wikipedia.org/wiki/ReDoS
Details
Documentation_Apache license_Launchpad project_Blueprints_Bugs_Source code_Supported Operating Systems
Syntribos는 주로 Linux 및 Mac 환경에서 개발되었으며, 대부분의 Unix 및 Linux 기반 운영 체제에서 작동합니다. 현재로서는 Windows를 지원하지 않지만, 향후 변경될 수 있습니다.
.. _Documentation: https://docs.openstack.org/developer/syntribos/
.. _Apache license: https://github.com/openstack/syntribos/blob/master/LICENSE
.. _Launchpad project: https://launchpad.net/syntribos
.. _Blueprints: https://blueprints.launchpad.net/syntribos
.. _Bugs: https://bugs.launchpad.net/syntribos
.. _Source code: https://github.com/openstack/syntribos
============
설치
============
Syntribos는 `pypi와 pip를 통해 <https://pypi.python.org/pypi/pip>`__ 직접 설치할 수 있습니다.
::
pip install syntribos
최신 변경 사항을 적용하려면 `소스 <https://www.github.com/openstack/syntribos.git>`__ 에서
`pip <https://pypi.python.org/pypi/pip>`__ 를 통해 syntribos를 설치하세요.
저장소를 복제합니다::