SovereignCloudStack / issues

This repository is used for issues that are cross-repository or not bound to a specific repository.
https://github.com/orgs/SovereignCloudStack/projects/6
2 stars 1 forks source link

Pentesting within an instance deployed in a Testbed project #530

Open 90n20 opened 7 months ago

90n20 commented 7 months ago

As a SCS security auditor, I want to perform a pentest from an instance deployed on a testbed project, so that I could identify and report possible security flaws from the point of view of a "cloud user".

Related to #410

Definition of Ready:

Definition of Done:

90n20 commented 7 months ago

We have created an Ubuntu instance in default Testbed "test" project and installed needed tooling (the same as defined in the proposed pentesting methodology, this is, Naabu + Httpx + Nuclei + ZAP + Greenbone CE ).

The goal of the tests being performed (either with the above tools and by hand) is to determine if there are components that could be reached from the network and/or if infrastructure services are accesible.

90n20 commented 6 months ago

Work has been finished performing the tests over two different instances, one running the included CirrOS and another running Ubuntu 22.04.

No significant issues have been identified, as machines only have visibility to Horizon and Homer web interfaces.

Results have been uploaded to nextcloud at CirrOS+Ubuntu instances internal assessment report

90n20 commented 5 months ago

Summarized pdf report uploaded to nextcloud at Instances internal assessment report