Skip to content
This repository has been archived by the owner on May 14, 2020. It is now read-only.

Monthly Chat Agenda October (2019-10-07) #1536 #1567

Closed
dune73 opened this issue Sep 28, 2019 · 1 comment
Closed

Monthly Chat Agenda October (2019-10-07) #1536 #1567

dune73 opened this issue Sep 28, 2019 · 1 comment

Comments

@dune73
Copy link
Contributor

dune73 commented Sep 28, 2019

This is the Agenda for the Monthly CRS Chat.

The chat is going to happen on https://owasp.slack.com in the channel #coreruleset on Monday, October 7, at 20:30 CET.

Items on the Agenda:

PRs

Other items

  • Proceedings of the planning meeting at the CRS Community Summit in Amsterdam / Things we want to do for 3.3
    • HTTP Header Whitelisting
    • Overhaul the complete tagging (@fzipi confirms he will put a student on this task)
    • Better support for non-European languages
    • Rule exclusion package for hosters
    • More node or JS rules -> better protection for the MEAN stack
    • More rules protecting users from python injections / attacks
    • consistent way dealing with transformations (working plan: apply different transformations to args at higher PL, save in TX:/xxx/, add TX:/xxx/ to every rule targetting ARGS)
    • Stop HTTP request smuggling once and for all (Content-Length + Transfer-Encoding)
    • Setup a series of demo-sites where people can test their attack payloads (PL1 to PL4)
  • Another CRS community Summit in 2020? -> 17 June 2020 in Dublin (?)
  • Close stale/old issues if no activity for N days: We are going to add a canned message to stale issues after N days asking for update or interest in fixing, then we're closing it after some time. The Github marketplace presents a standard procedure to get this by a bot via a stale-file in our repository: https://github.com/marketplace/stale (thank you @fzipi)
  • Release hashing and/or GPG signing tag
  • Setup Security policy on github (new tab!)
  • Should we add base64 decoding everywhere? v3.3/devb64decoder
  • Special proposal of textglass.org developer Reza Naghibi. The idea is to expand Textglass into a WAF executing CRS rules. This would possibly also mean to change CRS and lean on said alternative engine with our project.

Feel free to add items as you see fit either above, or below as comments.

If you are not yet on the OWASP Slack, here is your invite: https://join.slack.com/t/owasp/shared_invite/enQtNjExMTc3MTg0MzU4LWQ2Nzg3NGJiZGQ2MjRmNzkzN2Q4YzU1MWYyZTdjYjA2ZTA5M2RkNzE2ZjdkNzI5ZThhOWY5MjljYWZmYmY4ZjM .
Everybody is welcome to join our community chat.

@fzipi fzipi changed the title Monthly Chat Agenda September (2019-10-07) #1536 Monthly Chat Agenda October (2019-10-07) #1536 Oct 2, 2019
@dune73
Copy link
Contributor Author

dune73 commented Oct 7, 2019

Decisions / Infos

  • @csanders-git will be at cloudfest (-> rule exclusions for hosters)
  • @csanders-git has the demo setup almost done. We are talking end of the week.
  • Stale issues: @fzipi volunteers and the leads will make sure the permissions are being set up correctly.
  • Release signing: @fzipi volunteers to do this, signing and publication of checksums.
  • @csanders-git will look into the new github security policy that projects can set up via a new tab.
  • @spartantri and @dune73 will join forces and work on a transformation proposal resulting in a PR.

PRs

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

2 participants