Project

General

Profile

Actions

action #133472

open

Pentesting of o3

Added by okurz 10 months ago. Updated 9 months ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Feature requests
Target version:
Start date:
2023-07-27
Due date:
% Done:

0%

Estimated time:

Description

Motivation

With openqa.opensuse.org now served from PRG2 it's a good opportunity to check how secure it is. So we should try with pentesting ourselves if and where any vulnerabilities are.

Actions #1

Updated by favogt 9 months ago

"secure" in which way? Which privilege boundaries and attack vectors are relvant here?

Actions #2

Updated by pperego 9 months ago

okurz wrote:

Motivation

With openqa.opensuse.org now served from PRG2 it's a good opportunity to check how secure it is. So we should try with pentesting ourselves if and where any vulnerabilities are.

Since of the sensitiveness of the activity, can be a good idea to talk internally with security team.
Makes sense?

Actions #3

Updated by okurz 9 months ago

pperego wrote:

Since of the sensitiveness of the activity, can be a good idea to talk internally with security team.
Makes sense?

Sure. I already brought it up there :)

Actions

Also available in: Atom PDF