Vitess security audit[Image](/uploads/documents/7/9/8/4/798486b9f79b00da59cc67d5376f87ea/p1_1.jpg) PRESENTS ## V itess security audit In collaboration with the Vitess maintainers, Open Source Technology Improvement Fund and The Linux of contents Table of contents 1 Executive summary 2 Notable findings 3 Project Summary 4 Audit Scope 4 Threat model formalisation 5 Fuzzing 14 Issues found 16 SLSA review 38 Conclusions Ada Logics carried out a security audit of Vitess. The primary focus of the audit was a new component of Vitess, VTAdmin. The goal was to conduct a holistic security audit which includes multiple disciplines0 码力 | 41 页 | 1.10 MB | 2 年前3
Mix Assertion, Logging, Unit Testing and Fuzzing with ZeroErr## Mix Assertion, Logging, Unit Testing and Fuzzing with ZeroErr Build Safer Modern C++ Application Speaker: Xiaofan Sun Date: Sep 19, 2024 ## Self-Introduction • Got my Ph.D. from UC, Riverside last std::unique_ptrClass from third-party library: llvm::Value* ## Logging the Data // LOG(INFO) << Data; // ASSERT(a > b, "A > B is not true", a, b); std::ostream& operator<<(std::ostream& out, llvm::Value* data); ## Logging the Data • Namespace pollution • Hard to implement with template • No extensibility • No customization0 码力 | 54 页 | 961.46 KB | 1 年前3
TiDB Audit Plugin User Guide## TiDB Audit Plugin User Guide August 4, 2022 ## I ntroduction The TiDB audit plugin records the TiDB server’s activities that are expected to follow auditing regulations of your organization. For each how to compile, package, and use the audit plugin. ## Download the plugin You can download the plugin on TiDB Enterprise Edition Downloads. ## Deploy the audit plugin After downloading the plugin, to deploy the audit plugin. ## Use TiDB Operator to deploy the plugin ## Configure TidbCluster CR tidb: additionalContainers: - command: - sh --C - touch /var/log/tidb/tidb-audit.log; tail -n00 码力 | 15 页 | 257.26 KB | 2 年前3
Dapr july 2020 security audit reportout by Cure53 in summer 2020, the project entailed comprehensive penetration test and source code audit of the Dapr scope. In terms of resources, the project was assigned to four members of the Cure53 work packages (WPs) were outlined. In WP1, Cure53 performed both a broad and thorough source code audit of the latest version of Dapr. The focus was explicitly placed on the Dapr main repository and the as they were emerging. The communications were very helpful and productive, assisting the test and audit in moving forward swiftly. Given good choices and practices regarding methodology, setup and communications0 码力 | 19 页 | 267.84 KB | 2 年前3
Dapr february 2021 security audit reportprevious code audit (Low) DAP-02-013 WP2: Access policy bypass due to missing URL normalization (High) Miscellaneous Issues DAP-02-002 WP3: Status of miscellaneous issues from previous audit (Low) Conclusions cooperation between Cure53 and Dapr, reporting on the findings of a penetration test and source code audit against the Dapr software. In addition to shedding light on the state of security on some new features security mistakes. In effect, three work packages (WPs) were delineated: • WP1: Thorough source code audit of the latest Dapr version • WP2: Penetration tests targeting the Dapr integration and setup • WP3:0 码力 | 9 页 | 161.25 KB | 2 年前3
Dapr june 2023 fuzzing audit reportPRESENTS ## Dapr Fuzzing Audit In collaboration with the Dapr project maintainers and The Linux Foundation  ## Authors 0) ## CNCF security and fuzzing audits This report details a fuzzing audit commissioned by the CNCF and the engagement is part of the broader efforts carried out by CNCF in this engagement, Dapr was doing no fuzzing for any of its sub projects, and the goal of this fuzzing audit was to build the fundamental infrastructure and improve the fuzzing efforts in a continuous manner0 码力 | 19 页 | 690.59 KB | 2 年前3
Dapr september 2023 security audit reportPRESENTS ## Dapr security audit In collaboration with the Dapr maintainers, Open Source Technology Improvement Fund and The Linux Foundation   ## Logging and Tracing Stack LOGBACK glog . 












