Application Security in Continuous Delivery

Total Page:16

File Type:pdf, Size:1020Kb

Application Security in Continuous Delivery Application Security in Continuous Delivery Fábio Freitas Master’s Degree in Information Security Departament of Computer Science 2020 Orientador Prof. Dr. Eduardo R. B. Marques, Faculty of Sciences of University of Porto Coorientador Eng. Pedro Borges, LOQR S.A. Todas as correções determinadas pelo júri, e só essas, foram efetuadas. O Presidente do Júri, Porto, / / UNIVERSIDADE DO PORTO MASTERS THESIS Application Security in Continuous Delivery Author: Supervisor: Fábio FREITAS Eduardo R. B. MARQUES Co-supervisor: Pedro BORGES A thesis submitted in fulfilment of the requirements for the degree of MSc. Information Security at the Faculdade de Ciências da Universidade do Porto November 25, 2020 Acknowledgements Firstly, I would like to thank my thesis supervisors Prof. Dr. Eduardo R. B. Marques and Eng. Pedro Borges, whose expertise and guidance throughout the entire project proved itself invaluable. Secondly, I would like to thank my co-workers at Euronext, in special to my two mentors and good friends Duarte Monteiro and Ricardo Gonçalves, both alumni of this department and experts in this subject. I’m lucky to have worked alongside you two and to have learned so much from both of you. Then to all my friends, specially to my colleagues at the Information Security Master’s Degree André Cirne and Nuno Lopes, who taught me a lot in the past two years, and helped me grow as both a student and more recently, as a professional of the Information Security field. And lastly, and most importantly, to my family - most of all to my parents and siblings - who have been there for me for all of my academic journey and allowed me this opportunity to pursue and now work in a field that I’m passionate about. iii Abstract In the last few years, software development has seen a shift regarding the gap between the development and operation activities, with more and more focus with automating the building, testing and deployment of the application in what is usually called the Continuous Integration/Continuous Delivery process. However, this process has still few concerns with security in the real world. This thesis studies and implements security checks on top of a standard software delivery pipeline using a modular approach and considering a wide range of security checks of both Static and Dynamic nature. This framework is then instantiated for two different applications written in two different programming languages and the results are analyzed. Keywords: Application Security, Software Delivery Automation, Security Automation, De- vOps, DevSecOps v Resumo Nos últimos anos, o desenvolvimento de software tem sofrido mudanças no que toca à distância entre as desenvolvimento e as atividades das operações, com cada vez mais foco na automação do building, dos testes e do deployment das aplicações, no processo que é chamado Integração Contínua / Entrega Contínua (CI/CD). No entanto, no mundo real, este processo ainda considera muito poucas preocupações com a segurança das aplicações. Nesta tese será feito o estudo e implementação de validações de segurança assentes em cima de uma software delivery pipeline padrão utilizando uma abordagem modular com um leque vasto de validações de segurança distintas, de natureza estática e dinâmica. Esta framework é depois instanciada em duas aplicações escritas em duas linguagens diferentes, e os respetivos resultados analisados. Palavras-chave: Segurança Aplicacional, Automação de Segurança, Integração Contínua, DevOps, DevSecOps vii Contents Acknowledgements iii Abstract v Resumo vii Contents vii List of Figures xi List of Tables xiii 1 Introduction 1 1.1 Problem statement....................................1 1.2 Contributions.......................................2 1.3 Thesis structure......................................2 2 State of the Art3 2.1 DevOps...........................................4 2.1.1 Software Version Control............................5 2.1.2 GitLab.......................................6 2.1.3 Continuous Integration.............................6 2.1.4 Continuous Delivery...............................6 2.2 Containers.........................................7 2.2.1 Docker.......................................8 2.2.2 Container Security................................9 2.3 Application Security................................... 10 2.3.1 OWASP...................................... 10 2.3.2 Static Application Security Testing (SAST).................. 11 2.3.3 Source-Code Analysis.............................. 11 2.3.4 Secrets Scanning................................. 12 2.3.5 Dependency Scanning.............................. 13 2.3.6 Dynamic Application Security Testing (DAST)................ 13 2.4 Vulnerability Management................................ 14 2.4.1 DefectDojo..................................... 15 2.5 Integrating Security Checks in a CI/CD Pipeline................... 15 3 Implementation 17 ix x APPLICATION SECURITY IN CONTINUOUS DELIVERY 3.1 Architecture........................................ 17 3.2 Setting up the environment............................... 20 3.2.1 Software Versioning Control System - GitLab ................ 21 3.2.2 Automation Server - Gitlab CI/CD + Runner ................ 21 3.3 Implementing the Secure Pipeline........................... 24 3.3.1 Baseline...................................... 24 3.3.2 Integrating Source-Code Analysis - Sonarqube ............... 28 3.3.3 Integrating DAST - Zed Attack Proxy ..................... 32 3.3.4 Integrating Container Scanning - Clair .................... 36 3.3.5 Integrating Secrets Scanning - Gitleaks .................... 38 3.3.6 Integrating Dependency Checks - OWASP Dependency Checker ..... 41 3.3.7 Integrating a results aggregator (custom script) - build_risk_calc.py ... 44 3.3.8 Integrating a Vulnerability Tracker - DefectDojo ............... 47 4 Results 55 4.1 Instantiation 1 - Java Vulnerable Lab - Java...................... 55 4.1.1 Vulnerabilities................................... 56 4.1.2 Performance.................................... 56 4.2 Instantiation 2 - OWASP Juice Shop - JavaScript/NodeJS.............. 57 4.2.1 Vulnerabilities................................... 58 4.2.2 Performance.................................... 58 5 Conclusion 61 5.1 Concluding Remarks................................... 61 5.2 Future Work........................................ 61 Bibliography 63 List of Figures 2.1 DevOps Process Overview - as described by AWS..................4 2.2 Google Trends Query - "DevOps" - January 2010 to January 2020..........5 2.3 Continuous Delivery Pipeline..............................7 2.4 Architecture - Containers vs Virtual Machines....................8 2.5 Docker Architecture...................................9 3.1 Complete Pipeline..................................... 19 3.2 Prototype - System Architecture............................. 20 3.3 GitLab Runner Token................................... 23 3.4 GitLab Runner Test 1................................... 24 3.5 Baseline for Software Delivery Pipeline........................ 25 3.6 SAST Check in the Pipeline - Flow........................... 28 3.7 Secure Pipeline with SAST................................ 31 3.8 DAST Check in the Pipeline - Flow........................... 33 3.9 Secure Pipeline with DAST............................... 35 3.10 Container Scanning in the Pipeline - Flow....................... 37 3.11 Secrets Scanning in the Pipeline - Flow......................... 40 3.12 Dependency Check in the Pipeline - Flow....................... 42 3.13 Results aggregator in the Pipeline - Flow........................ 45 3.14 build_risk_calc.py - HTML Dashboard......................... 46 3.15 Pipeline results submitted to DefectDojo Vulnerability Tracker - Flow....... 48 3.16 Deduplication of issues at the Product Level..................... 49 3.17 DefectDojo - Main Product Dashboard......................... 52 3.18 DefectDojo - Engagement View............................. 52 3.19 DefectDojo - Issues View................................. 53 xi List of Tables 4.1 Issues Table - By Severity and Security Check..................... 56 4.2 Pipeline Performance - Times over 5 Executions................... 57 4.3 Issues Table - By Severity and Security Check..................... 58 4.4 Pipeline Performance - Times over 5 Executions................... 59 xiii Listings 2.1 Gitleaks Rules TOML file example........................... 12 3.1 Gitlab CI/CD Runner Installation Commands.................... 22 3.2 Gitlab CI/CD Runner Installation Check........................ 22 3.3 Gitlab Runner Registration................................ 23 3.4 Test .gitlab-ci.yml file................................... 23 3.5 .gitlab.yml - Baseline definition for Java Project.................... 25 3.6 .gitlab.yml - Baseline definition for NodeJS Project.................. 26 3.7 SonarQube.service file in /etc/system/systemd/.................. 29 3.8 sonar-project.properties................................. 30 3.9 code-analysis.yml..................................... 30 3.10 SonarQube output result - report_sast.json...................... 32 3.11 connection_check.sh................................... 33 3.12 dynamic-analysis.yml.................................. 34 3.13 ZAP output result - report_dast.json.......................... 35 3.14 container-scan.yml.................................... 37 3.15 Clair output result - report_container-scan.json.................... 38 3.16 Hardwired E-mails Regex Rule - .gitleaks.toml.................... 39 3.17 secrets-scan.yml.....................................
Recommended publications
  • Code Review Guide
    CODE REVIEW GUIDE 3.0 RELEASE Project leaders: Mr. John Doe and Jane Doe Creative Commons (CC) Attribution Free Version at: https://www.owasp.org 1 2 F I 1 Forward - Eoin Keary Introduction How to use the Code Review Guide 7 8 10 2 Secure Code Review 11 Framework Specific Configuration: Jetty 16 2.1 Why does code have vulnerabilities? 12 Framework Specific Configuration: JBoss AS 17 2.2 What is secure code review? 13 Framework Specific Configuration: Oracle WebLogic 18 2.3 What is the difference between code review and secure code review? 13 Programmatic Configuration: JEE 18 2.4 Determining the scale of a secure source code review? 14 Microsoft IIS 20 2.5 We can’t hack ourselves secure 15 Framework Specific Configuration: Microsoft IIS 40 2.6 Coupling source code review and penetration testing 19 Programmatic Configuration: Microsoft IIS 43 2.7 Implicit advantages of code review to development practices 20 2.8 Technical aspects of secure code review 21 2.9 Code reviews and regulatory compliance 22 5 A1 3 Injection 51 Injection 52 Blind SQL Injection 53 Methodology 25 Parameterized SQL Queries 53 3.1 Factors to Consider when Developing a Code Review Process 25 Safe String Concatenation? 53 3.2 Integrating Code Reviews in the S-SDLC 26 Using Flexible Parameterized Statements 54 3.3 When to Code Review 27 PHP SQL Injection 55 3.4 Security Code Review for Agile and Waterfall Development 28 JAVA SQL Injection 56 3.5 A Risk Based Approach to Code Review 29 .NET Sql Injection 56 3.6 Code Review Preparation 31 Parameter collections 57 3.7 Code Review Discovery and Gathering the Information 32 3.8 Static Code Analysis 35 3.9 Application Threat Modeling 39 4.3.2.
    [Show full text]
  • Multi-Step Scanning in ZAP Handling Sequences in OWASP ZAP
    M.Sc. Thesis Master of Science in Engineering Multi-step scanning in ZAP Handling sequences in OWASP ZAP Lars Kristensen (s072662) Stefan Østergaard Pedersen (s072653) Kongens Lyngby 2014 DTU Compute Department of Applied Mathematics and Computer Science Technical University of Denmark Matematiktorvet Building 303B 2800 Kongens Lyngby, Denmark Phone +45 4525 3031 [email protected] www.compute.dtu.dk Summary English This report presents a solution for scanning sequences of HTTP requests in the open source penetration testing tool, Zed Attack Proxy or ZAP. The report documents the analysis, design and implementation phases of the project, as well as explain how the different test scenarios were set up and used for verification of the functionality devel- oped in this project. The proposed solution will serve as a proof-of-concept, before being integrated with the publically available version of the application. Dansk Denne rapport præsenterer en løsning der gør det muligt at skanne HTTP fore- spørgsler i open source værktøjet til penetrationstest, Zed Attack Proxy eller ZAP. Rapporten dokumenterer faserne for analyse, design og implementering af løsningen, samt hvordan forskellige test scenarier blev opstillet og anvendt til at verificere funk- tionaliteten udviklet i dette projekt. Den foreslåede løsning vil fungere som et proof- of-concept, før det integreres med den offentligt tilgængelige version af applikationen. ii Preface This thesis was prepared at the department of Applied Mathematics and Computer Science at the Technical University of Denmark in fulfilment of the requirements for acquiring a M.Sc. degree in respectivly Computer Science and Engineering, and in Digital Media Engineering. Kongens Lyngby, September 5.
    [Show full text]
  • Code Review Guide
    CODE REVIEW GUIDE 2.0 RELEASE Project leaders: Larry Conklin and Gary Robinson Creative Commons (CC) Attribution Free Version at: https://www.owasp.org 1 F I 1 Forward - Eoin Keary Introduction How to use the Code Review Guide 7 8 10 2 Secure Code Review 11 Framework Specific Configuration: Jetty 16 2.1 Why does code have vulnerabilities? 12 Framework Specific Configuration: JBoss AS 17 2.2 What is secure code review? 13 Framework Specific Configuration: Oracle WebLogic 18 2.3 What is the difference between code review and secure code review? 13 Programmatic Configuration: JEE 18 2.4 Determining the scale of a secure source code review? 14 Microsoft IIS 20 2.5 We can’t hack ourselves secure 15 Framework Specific Configuration: Microsoft IIS 40 2.6 Coupling source code review and penetration testing 19 Programmatic Configuration: Microsoft IIS 43 2.7 Implicit advantages of code review to development practices 20 2.8 Technical aspects of secure code review 21 2.9 Code reviews and regulatory compliance 22 5 A1 3 Injection 51 Injection 52 Blind SQL Injection 53 Methodology 25 Parameterized SQL Queries 53 3.1 Factors to Consider when Developing a Code Review Process 25 Safe String Concatenation? 53 3.2 Integrating Code Reviews in the S-SDLC 26 Using Flexible Parameterized Statements 54 3.3 When to Code Review 27 PHP SQL Injection 55 3.4 Security Code Review for Agile and Waterfall Development 28 JAVA SQL Injection 56 3.5 A Risk Based Approach to Code Review 29 .NET Sql Injection 56 3.6 Code Review Preparation 31 Parameter collections 57 3.7 Code Review Discovery and Gathering the Information 32 3.8 Static Code Analysis 35 3.9 Application Threat Modeling 39 4.3.2.
    [Show full text]
  • WEB SERVICES TESTING in This Pentest Magazine We Prepared Special Combination of Topics Which, for Sure, Will Interest You
    ��������� ������������������ �������������������� �������������� ������������� ������������ ������������ ������� � � � � � � � � � �� ����������������� ���� ������������������������������������ ������ ����������������� �������� ��������� ���������������������� ��������������������� � ���������������� �� ��������������������� ����������������������������� ������������ pwnplug - Dave-ad3-203x293mm.indd 1 1/5/12 3:32 PM EDITOR’S NOTE Dear Readers! WEB SERVICES TESTING In this Pentest Magazine we prepared special combination of topics which, for sure, will interest you. Security Assessment of web 06 Services Let’s take a closer look on what you can find there. By Rudra Peram In the section Web services testing If you go to page 6, you’ll find there Rudra Peram, who Web services which are designed primarily for is a Software Security Analyst and has over 10 years of systems to interact with each other and are not experience in the field of Information Technology focusing on Web Application Security, Application Development and intended to be consumed directly by human beings. Software. In his article entitled: Security Assessment of This assumption has severe consequences in several Web Services he will guide us, among other things, through areas: developers are not as security conscious when several ways of attacking web services. In the next article,Jan will lead us,with examples, through developing web services. Negative testing of these popular web services with which we meet daily. For example services and Security teams are not focusing on these social networks. Jan will finish his voyage on storage files in web cloud. services either. The level of maturity of automated Right next to the Jan’s article you will find something security testing tools for web services is not helping which gives you an overview in testing web services. In this the situation either. article Malhotra will show you several forms of web services testing and will explain why and how we should test them.
    [Show full text]
  • Securing Devops — Detection of Vulnerabilities in CD Pipelines
    Institute of Software Technology Reliable Software Systems University of Stuttgart Universitätsstraße 38 D–70569 Stuttgart Masterarbeit Securing DevOps — Detection of vulnerabilities in CD pipelines Christina Paule Course of Study: Softwaretechnik Examiner: Dr.-Ing. André van Hoorn Supervisors: Thomas Düllmann, M.Sc., University of Stuttgart Andreas Falk, Managing Consultant, NovaTec Consulting GmbH Andreas Reinhardt, Senior Consultant, NovaTec Consulting GmbH Commenced: October 19, 2017 Completed: April 19, 2018 Abstract Nowadays more and more companies implement the DevOps approach. DevOps was developed to enable more efficient collaboration between development (dev) and opera- tion (ops) teams. An important reason why companies use the DevOps approach is that they aspire to continuously deliver applications using agile methods. The continuous delivery (CD) process can be achieved with the aid of the DevOps approach, of which the CD pipeline is an elementary component. Because of the fact, that a new General Data Protection Regulation (GDPR) will enter into force in the European Union in May 2018, many companies are looking at how they can increase the security level of their applications. The regulation requires that companies which process personal data have to secure their applications. An attacker can gain access to personal data if there are vulnerabilities in applications. This problem can be applied to CD pipelines. If CD pipelines have vulnerabilities then an exploitation of vulnerabilities can lead to a damage of the CD pipeline and the delivery process. One example is that the network can be scanned by running injected malicious unit tests. This can have a negative effect on the image of the company which operates and uses CD pipelines.
    [Show full text]
  • Testing​ ​Security​ ​Of​ ​Html5:​ ​Automated Scanning
    Escola Tècnica Superior d’Enginyeria Informàtica ​ ​ ​ ​ ​ ​ ​ ​ Universitat Politècnica de València ​ ​ ​ ​ ​ ​ Testing security of html5: automated ​ ​ ​ ​ ​ ​ ​ ​ scanning vulnerabilities ​ ​ Trabajo Fin de Máster ​ ​ ​ ​ ​ ​ Máster Universitario en Ingeniería Informática ​ ​ ​ ​ ​ ​ ​ ​ Autor: Javier Gil Pascual ​ ​ ​ ​ ​ ​ ​ Tutor: Jose Ismael Ripoll Ripoll ​ ​ ​ ​ ​ ​ ​ ​ ​ Hugo Jonker (externo) ​ ​ ​ ​ 2016-2017 Testing security of HTML5: detecting and mitigating vulnerabilities ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ 2 Resumen HTML5 tiene varios nuevos componentes como XHR-Level2, DOM, Storage. Con esta introducción de nuevas tecnologías, HTML5 también lleva consigo potenciales riesgos de seguridad. Algunos originados de los elementos del estándar en sí, otros de la implementación particular del estándar en cada navegador, y otros del cuidado que pongan los desarrolladores a la hora de escribir código. En esta tesis vamos hablas de estas nuevas estrategias de ataque y posibles amenazas. También cubriremos cómo detectar estas vulnerabilidad automatizando el proceso. Esta tesis describe una serie de vulnerabilidad web, sobre las que hemos construido unos test para probar las capacidad de algunas herramientas de pentesting. Basándonos en los resultados observados, discutiremos futuros resultados. ​ ​ ​ ​ ​ ​ ​ ​ Palabras clave: HTML5, pentesting, web, seguridad. ​ ​ ​ ​ ​ ​ ​ ​ ​ ​ Abstract HTML5 has several new components like XHR-Level2, DOM, Storage. With any major introduction of new features, HTML5 also brings with it potential security vulnerabilities. It allows crafting stealth attack vectors and adding risk to end client. Some originate from elements of the standard itself, some from implementations of the standard in each browser, and some from the care that developers do (or do not) take in building their HTML5 code. In this thesis we are going to talk about this new attack surface and possible threats. We are also going to cover how to automatically detect these possible vulnerabilities.
    [Show full text]
  • Comparative Analysis of the Automated Penetration Testing Tools
    Comparative Analysis of the Automated Penetration Testing Tools MSc Internship Cybersecurity Mandar Prashant Shah Student ID: x18139469 School of Computing National College of Ireland Supervisor: Dr. Muhammad Iqbal National College of Ireland MSc Project Submission Sheet School of Computing Student Name: Mandar Prashant Shah Student ID: X18139469 Programme: MSc Cybersecurity Year: 2019 Module: Internship Thesis Supervisor: Dr Muhammad Iqbal Submission Due Date: 08/01/2020 Project Title: Comparative analysis of the automated penetration testing tools Word Count: 8573 Page Count 25 I hereby certify that the information contained in this (my submission) is information pertaining to research I conducted for this project. All information other than my own contribution will be fully referenced and listed in the relevant bibliography section at the rear of the project. ALL internet material must be referenced in the bibliography section. Students are required to use the Referencing Standard specified in the report template. To use other author's written or electronic work is illegal (plagiarism) and may result in disciplinary action. I agree to an electronic copy of my thesis being made publicly available on NORMA the National College of Ireland’s Institutional Repository for consultation. Signature: ……………………………………………………………………………………………………………… Date: ……………………………………………………………………………………………………………… PLEASE READ THE FOLLOWING INSTRUCTIONS AND CHECKLIST Attach a completed copy of this sheet to each project (including multiple □ copies) Attach a Moodle submission receipt of the online project □ submission, to each project (including multiple copies). You must ensure that you retain a HARD COPY of the project, □ both for your own reference and in case a project is lost or mislaid. It is not sufficient to keep a copy on computer.
    [Show full text]
  • A Multilayer Secured Messaging Protocol for REST-Based Services
    Journal of International Technology and Information Management Volume 28 Issue 3 Article 2 2019 A Multilayer Secured Messaging Protocol for REST-based Services Idongesit Efaemiode Eteng Dr, [email protected] Follow this and additional works at: https://scholarworks.lib.csusb.edu/jitim Part of the Business Intelligence Commons, Communication Technology and New Media Commons, Computer and Systems Architecture Commons, Data Storage Systems Commons, Digital Communications and Networking Commons, E-Commerce Commons, Information Literacy Commons, Management Information Systems Commons, Management Sciences and Quantitative Methods Commons, Operational Research Commons, Science and Technology Studies Commons, Social Media Commons, and the Technology and Innovation Commons Recommended Citation Eteng, Idongesit Efaemiode (2019) "A Multilayer Secured Messaging Protocol for REST-based Services," Journal of International Technology and Information Management: Vol. 28 : Iss. 3 , Article 2. Available at: https://scholarworks.lib.csusb.edu/jitim/vol28/iss3/2 This Article is brought to you for free and open access by CSUSB ScholarWorks. It has been accepted for inclusion in Journal of International Technology and Information Management by an authorized editor of CSUSB ScholarWorks. For more information, please contact [email protected]. Journal of International Technology and Information Management Volume 28, Number 3 2019 A Multilayer Secured Messaging Protocol for REST- based Services ETENG Idongesit E. Department of Computer Science University of Calabar P. M. B. 1115 Calabar Email: [email protected], [email protected] OLUFEMI Oluwaseun O., Department of Computer Science University of Calabar P. M. B. 1115 Calabar Email:[email protected] ABSTRACT The lack of a descriptive language and security guidelines poses a big challenge to implementing security in Representational State Transfer (REST) architecture.
    [Show full text]
  • Deception Strategies for Web Application Security: Application-Layer Approaches and a Testing Platform
    Deception strategies for web application security: application-layer approaches and a testing platform Mikel Izagirre Information Security, master's level (120 credits) 2017 Luleå University of Technology Department of Computer Science, Electrical and Space Engineering Master Thesis Project Deception strategies for web application security: application-layer approaches and a testing platform Author: Mikel Izagirre E-mail: [email protected] Supervisor: Dr. Ali Ismail Awad June 2017 Master of Science in Information Security Luleå University of Technology Department of Computer Science, Electrical and Space Engineering Abstract The popularity of the internet has made the use of web applications ubiquitous and essential to the daily lives of people, businesses and governments. Web servers and web applications are commonly used to handle tasks and data that can be critical and highly valuable, making them a very attractive target for attackers and a vector for successful attacks that are aimed at the application layer. Existing misuse and anomaly-based detection and prevention techniques fail to cope with the volume and sophistication of new attacks that are continuously appearing, which suggests that there is a need to provide new additional layers of protection. This work aims to design a new layer of defense based on deception that is employed in the context of web application-layer traffic with the purpose of detecting and preventing attacks. The proposed design is composed of five deception strategies: Deceptive Comments, Deceptive Request Parameters, Deceptive Session Cookies, Deceptive Status Codes and Deceptive JavaScript. The strategies were implemented as a software artifact and their performance evaluated in a testing environment using a custom test script, the OWASP ZAP penetration testing tool and two vulnerable web applications.
    [Show full text]
  • ZAP, Burp, and Other Funny Noises
    ZAP, Burp, and Other Funny Noises Paul Kern December 13, 2018 INTERCEPTION PROXIES The Lowdown • Analyze, inject, modify web traffic • Works with a browser • Some are simple with limited function • Some are multi-function and can scan • Essential for pen-testers • Incredibly useful for developers Santa says: “Only test sites for which you have permission!” Popular Examples • OWASP Zed Attack Proxy (ZAP) • Burp Suite • Web Scarab, W3AF, MITMProxy, Fiddler • Typically utilize local system/browser proxy settings • Recommend a proxy switcher plugin • Foxy Proxy is my goto plugin • Works best in Chrome and Firefox Proxy Switcher Plugin • Browser plugin • Quickly enable/disable/switch proxies • Foxy Proxy and SwitchyOmega • https://getfoxyproxy.org/downloads/ • https://chrome.google.com/webstore/ detail/proxy-switchyomega/ padekgcemlokbadohgkifijomclgjgif Foxy Proxy Quick Change Foxy Proxy Settings OWASP ZAP ZAP • Zed Attack Proxy • Current version is 2.7.0 • Requires the Java Runtime Environment • Useful for pen testers, developers, beginners • Open Source (Free) • Windows/Mac/Linux • https://www.owasp.org/ index.php/ OWASP_Zed_Attack_Proxy_Project ZAP Functionality • Intercepting Proxy • Traditional and AJAX Spiders • Automated Scanner • Passive Scanner • Forced Browsing • Fuzzer • Supports Web Sockets • REST based API • More ZAP Root CA Certificate • First run will tell you to regenerate the root CA certificate • Needed to prevent the browser from throwing SSL warnings • Tools > Options > Dynamic SSL Certs • Click Generate and then save the
    [Show full text]
  • Integrating Automated Security Testing in the Agile Development Process
    DEGREE PROJECT, IN COMPUTER SCIENCE , SECOND LEVEL STOCKHOLM, SWEDEN 2015 Integrating Automated Security Testing in the Agile Development Process EARLIER VULNERABILITY DETECTION IN AN ENVIRONMENT WITH HIGH SECURITY DEMANDS ANDREAS BROSTRÖM KTH ROYAL INSTITUTE OF TECHNOLOGY SCHOOL OF COMPUTER SCIENCE AND COMMUNICATION (CSC) Integrating Automated Security Testing in the Agile Development Process Earlier Vulnerability Detection in an Environment with High Security Demands Integrering av automatiserad säkerhetstestning i den agila utvecklingsprocessen Upptäck sårbarheter tidigare i en miljö med höga säkerhetskrav ANDREAS BROSTRÖM <[email protected]> DA225X, Master’s Thesis in Computer Science (30 ECTS credits) Degree Progr. in Computer Science and Engineering 300 credits Royal Institute of Technology year 2015 Supervisor at CSC was Linda Kann Examiner was Mads Dam Employer was Nordnet Bank AB Supervisor at Nordnet was Joakim Hollstrand June 22, 2015 Abstract The number of vulnerabilities discovered in software has been growing fast the last few years. At the same time the Agile method has quickly become one of the most popular methods for software development. However, it contains no mention of security, and since security is not traditionally agile it is hard to develop secure software using the Agile method. To make software secure, security testing must be included in the development process. The aim of this thesis is to investigate how and where security can be integrated in the Agile development pro- cess when developing web applications. In the thesis some possible approaches for this are presented, one of which is to use a web application security scanner. The crawling and detection abilities of four scanners are compared, on scanner evaluation applications and on applications made by Nordnet.
    [Show full text]
  • Automated, Scheduled and CI/CD Web Injection
    Instituto Politécnico de Leiria Escola Superior de Tecnologia e Gestão Departamento de Engenharia Informática Mestrado em Cibersegurança e Informática Forense AUTOMATED,SCHEDULEDANDCI/CDWEB INJECTION mykyta zhygulskyy Leiria, Fevereiro de 2021 [ January 15, 2021 at 18:25 – Version 1 ] [ January 15, 2021 at 18:25 – Version 1 ] Instituto Politécnico de Leiria Escola Superior de Tecnologia e Gestão Departamento de Engenharia Informática Mestrado em Cibersegurança e Informática Forense AUTOMATED,SCHEDULEDANDCI/CDWEB INJECTION mykyta zhygulskyy Número: 2180074 Projeto realizada sob orientação do Professor Ricardo Gomes ([email protected]). Leiria, Fevereiro de 2021 [ January 15, 2021 at 18:25 – Version 1 ] [ January 15, 2021 at 18:25 – Version 1 ] ACKNOWLEDGEMENTS I thank my advisor Ricardo Jorge Pereira Gomes, for all the guidance and availability along this path, for all the help, for all the technologies and tools that were taught to me, and more especially for many of the doubts solved, and also in the way of thinking, problem-solving. I would also like to thank Professor Mário Antunes for providing me this advisor for the implementation of this project. i [ January 15, 2021 at 18:25 – Version 1 ] [ January 15, 2021 at 18:25 – Version 1 ] ABSTRACT This report is made within the Curricular Unit (UC) Project, in the 2nd year of the Master in Cyber-security and Forensic Informatics (MCIF) provided by the Polytechnic Institute of Leiria (IPL). The purpose of this project is to study SQL Injection vulnerabilities in web applications. According to OWASP (Open Web Application Security Project) [20][19], this is one of the more prevalent attacks on web applications.
    [Show full text]