×
Copy
Open
Link
Embed
Share
Beginning
This slide
Copy link URL
Copy link URL
Copy iframe embed code
Copy iframe embed code
Copy javascript embed code
Copy javascript embed code
Share
Tweet
Share
Tweet
Slide 1
Slide 1 text
Keeping Rails Applications on Track with Brakeman Justin Collins @presidentbeef RailsConf 2012 1
Slide 2
Slide 2 text
Everyone knows they “should” worry about security 2
Slide 3
Slide 3 text
But when should you worry? 3
Slide 4
Slide 4 text
Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing Idealized Software Development 4
Slide 5
Slide 5 text
Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing Cost to Fix Defects 5
Slide 6
Slide 6 text
Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing Cost to Fix Defects 6
Slide 7
Slide 7 text
Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing Security Review Cost to Fix Defects 6
Slide 8
Slide 8 text
Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing Security Review Cost to Fix Defects 6
Slide 9
Slide 9 text
Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing Security Review Cost to Fix Defects 6
Slide 10
Slide 10 text
Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing Security Review Cost to Fix Defects 6
Slide 11
Slide 11 text
Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing Security Review Cost to Fix Defects 6
Slide 12
Slide 12 text
Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing Security Review Cost to Fix Defects 6
Slide 13
Slide 13 text
Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing Security Review Cost to Fix Defects 6
Slide 14
Slide 14 text
Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing Security Review Cost to Fix Defects 6
Slide 15
Slide 15 text
Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing Security Review Save code Cost to Fix Defects 6
Slide 16
Slide 16 text
brakemanscanner.org github.com/presidentbeef/brakeman @brakeman 7
Slide 17
Slide 17 text
“zero configuration” security scanning 8
Slide 18
Slide 18 text
gem install brakeman cd my_rails_app/ brakeman 9
Slide 19
Slide 19 text
10
Slide 20
Slide 20 text
gem install brakeman cd my_rails_app/ brakeman -o report.html 11
Slide 21
Slide 21 text
12
Slide 22
Slide 22 text
“Confidence” View Render Location Warning Type Line Number Code Snippet 13
Slide 23
Slide 23 text
Line 5 14
Slide 24
Slide 24 text
Static Analysis Detour 15
Slide 25
Slide 25 text
Static Analysis Anything that can be determined about a program without actually executing it 16
Slide 26
Slide 26 text
“But Ruby is way too dynamic for that!” 17
Slide 27
Slide 27 text
eval(File.read(gets.strip)) 18
Slide 28
Slide 28 text
We don’t have to know everything 19
Slide 29
Slide 29 text
Most of the Action Happens Here Controller View Partials Filters 20
Slide 30
Slide 30 text
View <%= params[:user][:name] %> Start Simple: User Input in Views 21
Slide 31
Slide 31 text
Controller View Next: From Controllers to Views <%= @user[:name] %> @user = params[:user] 22
Slide 32
Slide 32 text
Controller View Next: From Controllers to Views <%= @user[:name] %> @user = params[:user] 22
Slide 33
Slide 33 text
Next: From Controllers to Views Controller View <%= params[:user][:name] %> @user = params[:user] 23
Slide 34
Slide 34 text
user = params[:user] user_id = user[:id] @current_user = User.find(user_id) @current_user.update_attributes(user) Really Simple Data Flow 24
Slide 35
Slide 35 text
user = params[:user] user_id = user[:id] @current_user = User.find(user_id) @current_user.update_attributes(user) Really Simple Data Flow 24
Slide 36
Slide 36 text
Really Simple Data Flow user = params[:user] user_id = params[:id] @current_user = User.find(user_id) @current_user.update_attributes(user) 25
Slide 37
Slide 37 text
Really Simple Data Flow user = params[:user] user_id = params[:id] @current_user = User.find(user_id) @current_user.update_attributes(user) 25
Slide 38
Slide 38 text
Really Simple Data Flow user = params[:user] user_id = params[:id] @current_user = User.find(params[:user][:id]) @current_user.update_attributes(user) 26
Slide 39
Slide 39 text
Really Simple Data Flow user = params[:user] user_id = params[:id] @current_user = User.find(params[:user][:id]) @current_user.update_attributes(user) 26
Slide 40
Slide 40 text
Really Simple Data Flow user = params[:user] user_id = params[:id] @current_user = User.find(params[:user][:id]) User.find(params[:user][:id]).update_attributes(user) 27
Slide 41
Slide 41 text
Really Simple Data Flow user = params[:user] user_id = params[:id] @current_user = User.find(params[:user][:id]) User.find(params[:user][:id]).update_attributes(user) 27
Slide 42
Slide 42 text
Really Simple Data Flow user = params[:user] user_id = params[:id] @current_user = User.find(params[:user][:id]) User.find(params[:user][:id]).update_attributes(params[:user]) 28
Slide 43
Slide 43 text
Really Simple Data Flow Mass Assignment user = params[:user] user_id = params[:id] @current_user = User.find(params[:user][:id]) User.find(params[:user][:id]).update_attributes(params[:user]) 28
Slide 44
Slide 44 text
Brakeman Can Detect... • Cross site scripting • SQL injection • Command injection • Unrestricted mass assignment • Unprotected redirects • Unsafe file access • Insufficient model validation • Version-specific security issues • Dangerous use of eval • Dangerous use of send • Default routes • Dynamic render paths • …and more! 29
Slide 45
Slide 45 text
Performance Twitter Main App < 2m nventory (66c, 58m, 688t) ~1m Redmine (50c, 77m, 256t) ~20s Typo (34c, 47m, 113t) ~5s Brakeman 1.6.0, Ruby 1.9.3-p125 30
Slide 46
Slide 46 text
Back to SDLC Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing 31
Slide 47
Slide 47 text
Run Brakeman Anytime Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing 32
Slide 48
Slide 48 text
Run Brakeman Anytime Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing 32
Slide 49
Slide 49 text
Run Brakeman Anytime Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing 32
Slide 50
Slide 50 text
Run Brakeman Anytime Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing 32
Slide 51
Slide 51 text
Run Brakeman Anytime Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing 32
Slide 52
Slide 52 text
Brakeman + jenkins-ci.org open source CI server 33
Slide 53
Slide 53 text
Brakeman + 34
Slide 54
Slide 54 text
Brakeman + 35
Slide 55
Slide 55 text
Brakeman Programatically require “brakeman” Brakeman.run “myapp” 36
Slide 56
Slide 56 text
Run Brakeman Anytime Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing 37
Slide 57
Slide 57 text
Run Brakeman Anytime Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing 37
Slide 58
Slide 58 text
Run Brakeman Anytime Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing 37
Slide 59
Slide 59 text
Brakeman + Rake brakeman --rake rake brakeman:run 38
Slide 60
Slide 60 text
Hardcore Mode brakeman -z 39
Slide 61
Slide 61 text
Comparing Brakeman Results brakeman -o report.json brakeman --compare report.json 40
Slide 62
Slide 62 text
Brakeman...All the Time? Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing 41
Slide 63
Slide 63 text
Brakeman...All the Time? Write code Run tests Deploy code Commit code Push to CI server Code review QA Testing Save code 41
Slide 64
Slide 64 text
Fast Rescanning Brakeman supports fast rescanning of changed files* 42
Slide 65
Slide 65 text
Fast Rescanning *If scan is kept in memory 43
Slide 66
Slide 66 text
Brakeman + Guard group :development do gem 'guard-brakeman' end 44
Slide 67
Slide 67 text
Brakeman + Guard guard init brakeman guard 45
Slide 68
Slide 68 text
http://www.youtube.com/ watch?v=CMgYcr9_ONs Brakeman + Guard Demo 46
Slide 69
Slide 69 text
Caveats 47
Slide 70
Slide 70 text
warnings != vulnerabilities 48
Slide 71
Slide 71 text
zero warnings does not mean zero vulnerabilities 49
Slide 72
Slide 72 text
Brakeman is not omniscient 50
Slide 73
Slide 73 text
Supports • Rails 2.x & 3.x • Ruby 1.8.7 & 1.9.x • JRuby 51
Slide 74
Slide 74 text
brakemanscanner.org github.com/presidentbeef/brakeman @brakeman 52