Unique ways to Hack into a Python Web Service by Tilak T

This video features Tilak T at DjangoCon US 2018 in San Diego, California, USA.

Unique ways to Hack into a Python Web Service by Tilak T
0:43:18
Published November 10, 2018
2,619 views

DjangoCon US 2018 - Unique ways to Hack into a Python Web Service by Tilak T

Python covers a significant portion of the present day Web services landscape because of frameworks like Django, Flask, CherryPy etc. Many Highly Scalable services are built on one or more of these frameworks.

However, there is a perception among developers that these frameworks protected all classes of Web attacks and the OWASP Top 10 vulnerabilities. This is because of the inherent middleware that has battle-tested controls against some common vulnerabilities like CSRF, SQL Injection, and XSS. However, I have observed that many Python devs do not watch out for lesser-known vulnerabilities that seem to be rife in many Python Web Apps. For instance, in more recent security tests against Python Web Services that our team executes, I find that vulnerabilities like Insecure Deserialization, XML External Entities, Server-Side Template Injection and Authorization Flaws are quite prevalent.

As a developer (largely of Python Web Apps), I find that there are some simple steps that engineering teams can take towards finding and fixing such vulnerabilities with Python Web Services built on Django and Flask. My talk is meant to be a holistic perspective on finding and fixing some uncommon flaws in Python Web Apps. The talk will be replete with multiple demos, anecdotes, and examples of secure and insecure code in Python. I will also delve into SAST and DAST techniques (AST and ZAP Custom Scripts) to identify such flaws in python web applications.

The example repository will be available on GitHub for the community to use.

This talk was presented at: https://2018.djangocon.us/talk/unique-ways-to-hack-into-a-python-web/

LINKS:
Follow Tilak T 👇
On Twitter: https://twitter.com/ti1akt

Follow DjangCon US 👇
https://twitter.com/djangocon

Follow DEFNA 👇
https://twitter.com/defnado
https://www.defna.org/

Summary

Tilak T explains that Django’s middleware and defaults help prevent common web vulnerabilities, but application architecture, third-party libraries, and unsafe data handling can still introduce serious flaws. He demonstrates JWT weaknesses when tokens are validated by mutable usernames, unsafe YAML deserialization that enables environment-variable disclosure and reverse-shell access, and insecure direct object references that let one user alter another user’s data. He recommends binding tokens to immutable identifiers, expiring and revoking them, using `yaml.safe_load`, isolating deserialization in non-root containers, validating object ownership, and adding tools such as Bandit, Safety, OWASP ZAP, and Robot Framework to the development pipeline.

Key takeaways

  • JWT is used for authorization rather than authentication, and validating tokens against mutable usernames can allow token reuse after an account change.
  • JWTs should use immutable identifiers, short lifetimes, and revocation or regeneration after important account changes.
  • Unsafe YAML deserialization can execute attacker-controlled Python code, expose environment variables, and provide reverse-shell access to a server.
  • Use `yaml.safe_load`, validate incoming data, and isolate deserialization in a non-root container to limit compromise.
  • Directly trusting primary keys in URLs can create IDOR vulnerabilities; applications should verify that the authenticated user owns the requested object.
  • Bandit, Safety, OWASP ZAP, and automated Robot Framework scripts can bring source, dependency, and API security checks into a DevOps pipeline.

Summarised automatically from the transcript.

Transcript

5,631 words · auto-generated Show

Automatically transcribed, so expect mistakes in names and technical terms.

0:16

Speaker 1: Hi, everyone. Uh thank you for attending my talk. I know you are all sleepy because just now you had lunch. show you guys so before that so thank you once again so today I'm gonna talk in talk topic is unique way to hack into a python web services So don't worry, I'm not a hacker. I am just like basic developer, like how you are, like I'm a full stack developer. So I work at V45 Solution. Then and also I am a open developer of open source project called Orchestron. That's uh vulnerability correlation engine. So where we correlate multiple tools

1:01

Speaker 1: vulnerability and we show your dashboard in that we'll show some of the examples so that developer can fix the vulnerability so that kind of stuff. Then also how many of you know threat modeling So, if you know threat modeling, this is the one of the first tools we wrote, automated threat modeling. So, this is also an open source and also I am a contributor of that. So, you can check it out there. And also I am a part of multiple CTFs, Inos and also I was part of DEF CON CTFs. So this is my Twitter handle. You can follow me that So , agenda. So, agenda is introduction to web service. I will talk about what is web services and what are those types of web services are available. So, just basic introduction

1:48

Speaker 1: So next, what are the common vulnerabilities are there in web services? Like, so what are those vulnerabilities? I'll talk about that. After that, I will go into unique vulnerabilities. What are those unique vulnerabilities are they found in web services? So, and also how to mitigate some of the unique vulnerabilities So and also I have a lot of demos to show you guys. I hope demo will work fine because you guys know right once you develop the product when we want to show the client that time it won't work Right. I hope today will work fine. So what is web services? So how many of you are attended yesterday Django Rest Framework Authentication Talk?

2:33

Speaker 1: Yeah, then you know web services means, I think. So basically what is web services means? It's like centralized back-end services. So it's like machine to machine, it's transfers information or exchange. So for example , if you're written in application application backend in REST framework, if you want to integrate front-end in Vue. js or React. js, you can do that. So and also if you want to write mobile application, you if you want to like Java, it's written in Java, you can write it. Still it's like centralized. So how it looks like means You can see like blue color is the rest framework part. And these are all like uh front end. You can write it's like centralized. Centralized application, so you can do that.

3:20

Speaker 1: That's what uh that's why restrain marker very popular nowadays What are the types of web services are available? So one is soap-based web services, another one is restful web services. I won't talk about soap-based web services because soap is basically Java related So, RESTful Web Services is a lightweight web services. It transfers information via HTTP protocol. And also, one of the good things is REST Framework is it supports multiple data formats. It supports XML as well as JSON format. Next, what are restful frameworks available in Python? So you guys all have know Django rest frameworks, right? So and also

4:05

Speaker 1: Flask is there, Falcon, Pyramid, Cherry Pie, Bottle, and many more. frameworks are available. But most popular one is Django Rest framework and Flask. So what are common vulnerabilities or In REST framework. So SQL ingestion, cross-scripting, CSRF, and session hijacking, these are all common vulnerabilities we are We are seeing in our web services. So I you know, right, Django prevents some of these vulnerabilities. How many of you know this prevents some of these vulnerabilities in Django? Okay. Nice. So actually Django prevents SQL injection

4:50

Speaker 1: and cross scripting, CSRF, forgery, and also session hijacking. If you're using Django, these are all Vulnerable, it is not possible to attacker can do SQL injection in Django application. If you say we have written in our application in Django, they pen tester, they will say really, then we can't find SQL injection Because we are an information security company, we know our testers how they feel bad about when we give a Django application. So, because how Django prevents some of these attacks because of its rich middleware. Django has a middle way. So I like Django because of the their unique way they thought of security. Other than other frameworks are they didn't thought about security. They Django is

5:36

Speaker 1: I'm not saying because of this is a Django con. I started programming using Django and Python. So when I was learning Django and Python, it is so easy to use. It's like uh Django. py start project and start app your app is ready. So so simple. They made it so simple, user friendly. So because of that, we do and also they thought of security related, like they they inside middleware, if any request or response comes, it transfers via middleware. So that it checks is there any malformed injection or something, any requests are coming. It checks. If it is anything malformed or anything, it's not related to the application, it rejects the request from there itself.

6:21

Speaker 1: Or if any unauthenticated user contacts to the server, it rejects their itself. So that's why Django is most popular. So some of us we don't know because of uh we we just develop the application, that's it. We don't know about how Django works. So this is why Django is most popular And what about these vulnerabilities? So if you're using Django REST framework, this is the stateless application, right? It's completely decoupled from front end is different, back end is different. So because of that we need some of authorization to author to authorize. So because of that we use some of use JWT. If your attended yesterday talk, you know what is JWT and all.

7:07

Speaker 1: So we can make whatever this means JWT manipulation, we can do that, and XML external entity, then in IDAR, then server-side template injection. There are many more vulnerabilities. So these are all vulnerabilities we can do that. This is not an Django flaw. This is basically an architecture flaw. When we design the application architecture, we have to take care of these are all flaws. So we should make sure that avoid these are all flaw when we are architecturing the application. So first one I am talking about JWT manipulations. So we follow Wovasp standards. How many of you have heard about Wovasp

7:53

Speaker 1: school? So OAS means it's an open web application standard programming. This is an open open source project. So where they So yearly or four yearsly they will collect the vulnerabilities or attacks. Based on that, they make a standardized vulnerability, may make top 10 vulnerabilities based on that. So in that broken ac the JWT manipulation will come in the A5, that's broken access control. So why JWT is required? As I mentioned. So as I mentioned, JWT is required because of it's a stateless application. So we have one common uh understanding about JWT we think that it's an authentication mechanism.

8:41

Speaker 1: Actually JWT is not an authentication mechanism it's an authorization mechanism So once we authenticated the application, so next time the user if if he wants something information about product or something user information, So he needs to send the JWT so that we can authorize is a valid user or not. So that's why we use JWT. So it sends transfers information Between server to client and server to uh server to client and client to server. So it is very lightweight. JW2Y is there are more many more Frameworks are available, but JW is many most popular because of its lightweight and its scalable also. So JSON web

9:27

Speaker 1: token look like this basically. So if uh for example headers will be there in this header Uh it's algorithm, it's like JWM says signed, it's not encrypted, it's signed with unique ID. So that if attacker if he wants to tamper, he can't tamper. Because if he want to tamper, he needs a unique ID. Then only he can tamper the JWT. So JWT is looks like I will show you one. This is the JWT. io, this is the one you can see. So this is header. So in this header you can see the algorithm So algorithm, there are two types of algorithms are available. So HS256, another one is

10:13

Speaker 1: RSA. RSA means it's like public and private key. So it's encrypted with public key if you private key. If you want to decrypt, you need a private key. Then only it will decrypt the information. So in the payload section you can you are passing the information or data. So that is like user ID, username, email, or role. So that when you are decrypting, you can you can validate if the user or role is existing or not. Next one is as I mentioned, signature. So unique ID signature. You are signed with a unique signature So we think JWT is secure, right?

10:58

Speaker 1: Because no one can tamper with the JWT, but it's wrong. JWT, there are many ways to JWT can make wrong. So first one is if algorithm, if algorithm allows, uh is like for example, what do I say It's non-signature. If it is allows the signature is none, it's like signature which need any unique ID. If unique ID doesn't exist, it if the framework it allows non-algorithm, then it will be a flaw. So next one is there are algorithm confusion. Algorithm confusion means JWT allows two type of algorithm, one is

11:44

Speaker 1: SS 256256, another one RSA. For example, if when user asks authenticated to the server, it encrypted via using RS256. When it when client receives, that is encrypted with the RSF 256. When client sends back to the unique JWT to the server, it is bind with the HS256. So it is like algorithm this one algorithm confusion. Next one is unique uh private claims. So for example, you should validate JWT based on some of unique IDs, like using email IDs or unique IDs. You should validate based on that.

12:31

Speaker 1: There's a recent attack happened in uh JWTL. How many of you know Arch Zero? Okay. So Arch0 basically is like centralized authentication mechanism, centralized authentication, like AWS cognito. So because of they had a one flaw in JWT, so they compromised so many users' information. So this is on recent attack. So I am praying to God. I hope demo will work. Okay Can see everyone?

13:16

Speaker 1: No? No? Okay Clear? Okay. So there are list of users are available here. There are two users are there. So one is super user, another one is admin user. So what I will do now So there is a Tilak one username is Tilak. So I will take his Tilak 's token. So this is Tilak's token. So what I will do copy this and jwt dotio so now I can see the information is it you can write

14:02

Speaker 1: Okay. So this is user ID is 5, then username is tilak, then email ID is tilak. tilak at v45. in, right? So now what I will do? I will copy his token. And I will paste it somewhere. Okay. Now Tilak wants to change his username. Instead of Tilak, he wants to change his username as Tilak. t. I don't know some reason he wants to change his username. So what I'll do, I will update his username. So his username is Tilak T. So now what I will do? I will create an another user. So his email ID is different, tilap. t at v45. com.

14:47

Speaker 1: But username is tilak. So what I will do I will create user okay. Now so Okay. So now I copied this token is belongs to thlub. t at v45. in, right? If I call use this token, it should not give me the list of products because the username tilak that Tilap. t at v45. in, he changed his username. So it should not allow, right? Because I'm using this token because this is the TLAC. t, his username is TLAC.

15:34

Speaker 1: So what I'll do for a UK is Still it's accepting. So if you didn't get it, I'll show you again. So I'll get a token off TLOC. t. This I renamed username I changed. I'll token his tok take his token. So I'll copy his token into JWT. This is actually his token. So which a user I created, tlac. t at v4v. com. So if we want to authenticate with the application, he should For that you should authenticate, right?

16:20

Speaker 1: He didn't do that. Without authenticating the server, he gets the access of the server because of he used other person's token. So what you have to do basically, so you have to avoid once username is changed, you should destroy his old token. Or you should bind unique IDs using email ID or any some of you have to generate some of U ID or something. You have to do based on that, you have to validate Okay. So how to mitigate? As I mentioned, you have to validate based on unique ID. And

17:05

Speaker 1: also JWT lifetime, it should be shorter. So we basically we miss uh this one. It's like we use default uh lifetime, like it should not be the more than eight hours It should be lifetime shorter than 8 hours so that we we can prevent some of these attacks. And also check library for I have not made any single changes in this code. I have used Django REST framework JWT. In that has a flaw this is. Because Django RESTFrame JWT using username based, it is validating. So someone is mentioned, but they didn't still fix this. So I use same thing here. I have not changed any code. Be careful when you are using libraries. Make sure that check library

17:50

Speaker 1: any issues are there. Then you can use in your application so that you can prevent these attacks. Because this is not your uh development flaw, this is a library flaw. Okay Next one, insecure deserialization flow. This is one I like this one actually. So because In 2013, what was 2013? This deserialization flow it was not at all there because in 2017 they included because of the insecure deserialization Attacks or breaches happened a lot. Because of that, they included in the 2017 SWOWASP category. They made it separate category for insecure deserialization itself.

18:36

Speaker 1: So what is serialization and what is deserialization means. Serialization means it's converts object into a binary. For example How do I for example one e-commerce website will be there? So vendor he wants to upload his product. So he can't create n number of products, right? So it takes time. For that purpose we will create some of the AML file. So in that file you will create you add user product name, product price, description. uh something he will add some uh information. When we upload the YAML file, so when we receive, so that is called serializing. It converts uh It converts object into a binary.

19:21

Speaker 1: So once it's in our views. py, then we we we will extract. That means we will deserialize it. That means binary to we will convert binary to into an object so that we can read and then we can save into our database. So in that case, if you are not validated what is coming or which what is coming, is there any uh malformed information is going on or something if you're not get validated properly then it will be looks like this it's like bad egg It's like completely malformed. So, because of this, the attacker he can access your

20:06

Speaker 1: Application server completely. And also you can make your application completely DDoS, that means denial of service, so that user can't use your application. So there is a recent attack happened in WordPress. So so many So many websites have been compromised because of what in some of the plugins, WordPress plugin has this serialization flaw. Because of that, so many websites has been compromised. Another one is PayPal. PayPal was using Java because Java, some of the Java serializer has some of this flaw because of that, PayPal also has been hacked.

20:51

Speaker 1: Yeah, I know Django is secure, right? As I mentioned. Yes, of course Django is secure. But what about this? We use some of the serialization, right? XML we will use. YAML we use and JSON we use, right? How many of you used PyAML? Okay. It's good. Not bad. So how many of you has tried Taven? How many of you know Taven? Okay. Taven is basically rest framework testing API. So in this, this is an open source project. In this, we found the vulnerability. We didn't inform them, but we found the vulnerability in this.

21:37

Speaker 1: I will show you how. So this is good. So I'll upload and one AML file in that contents uh name, name of the product, then category. This is a bad code, I'm so sorry. Then description of the Mobile, then price available and stock and image. This is the basic normal. This is the ML file I should upload. So I will upload now.

22:23

Speaker 1: It's created. So let's go to list of products. It's created right. So this is the way the client should upload AML file. So what if I'm a bad boy? I will do something else because of this. I'll do something So, what I will do? I will try to do get some of the environment variable. So it's like uh backend, is it validating or not? Something I will check. So for that, what I will do So this is the malicious payload. So in the description section, I will add one Python small script. This is So one line code. I will print ENV. So what is returns? How many of you know what

23:09

Speaker 1: print ENV means? It returns environment variable of the server, right? So if you are saving anything, uh s uh information like password, so we will save it in environment variable if you are deployed any application if you know why we will use environment variable So we used to save password or something information or so I will try to I'll try is there is possible it will give give it back or not. So now It's giving C environment variables. You can see it right.

23:55

Speaker 1: Here somewhere MySQL Server DB see MySQL host. MySQL DB is showing because I am using Docker Compose, so that's why MySQL DB is showing So it's showing entire environment variables. So now I know that in back end I am not validating anything. It's like I can do any activities. I can do now reversal access. Reverse shell means I can compromise the server. So I can gain the access in my local system. I will set up one local server. I will contact that server, then I will gain the shell access in my local system. It should not do actually. If it does, then your application is gone. It's like done. So we'll try that one. So for that, I will

24:40

Speaker 1: set up Netcat think it's around name. Is it right? How many of you Netcat? Yeah. So if then in my malicious code this is the reverse shell code and before that I have to check my IP of my local systems IP because I want to I want a shell access in my local system that servers shell access I want. So for that I want I will access if config

25:26

Speaker 1: This is my IP. So this is single line shell code execution. So this is a single line Python code this one is So I gave my IP here and port is 1337. Okay. So Netcat is running 133. Right? Yes, one three three seven. Netcat is running one three three seven. Right? So now it's too big. So this is the reverse shell. This is the file ML file I uploaded. I updated so now I will upload. So if If I come to this, see now I have complete server access.

26:13

Speaker 1: It's boom completely. Now I can do whatever I want. Right? So right cat e t c slash Oh, sorry, okay, slash ETC. Slash. I have now password ETC. So in Ubuntu it all passwords are stored in ETC directly, right? So now I have all users password. So now attacker can do whatever he wants, like

27:00

Speaker 1: he can compromise, he can lock your application completely. Okay How do we mitigate this, right? What was the problem happened in this case? I will show you. That's a single-line code problem. One line code because of that our entire application server has been compromised because of one line code. If anyone used AML, they will know Al show you the code. Okay, this one. Because of AML. load. In a way it's correct. ML. load, it like loads the information and it's just dumped into the database.

27:46

Speaker 1: That's it. It won't validate. Is it a valid? It's like multi uh malicious activities are going on nothing, it won't check nothing. It's just dumped into database. It requests some dump what is the information comes, then it's dumped into the So when we're deserializing it, you should deserialize based on You should integrate the checks visual signature. And also, you should when you are serializing make it isolated environment. Use containers. So use container and also make sure that container should be normal user, not as a root user. If you are using root user, then he can compromise your host system as well as So be careful when you are using isolating, make sure that it is a normal user so that if

28:33

Speaker 1: attacker can compromise that he will be in that container box only. He can't access other host system Next, monitor incoming and outgoing outputs. So, how many of your uh heard about recent Facebook breach If you are heard about because of their monitoring system was they good, because of that they avoided the major breach. Then this is what instead of aml. load use aml. safe underscore load. That's it. So that you can prevent this attack if you're using AML file. So and also another way is that I'll show you how to prevent these attacks. So

29:19

Speaker 1: uh How many of you know bandit like Sastool school? So use bandit. Bandit means is This is a source code analysis. It analyzes code if it finds any vulnerability in your code, it it will say that you have a vulnerability in this line. So please fix this So we can do it this one using git commit post hook. So if you integrate in that so that we can prevent some of these vulnerability, I will show you how.

30:22

Speaker 1: Okay, some changes I some changes I made. So if I when I'm committing, it scans. So this is before pushing into the repository. So before pushing into your repository, you can scan. It says the vulnerability it found. So please fix this vulnerability. This is somewhere This is there is something Yeah, this is the Yeah. See here. In line number 119, aml dot load you are using So it says so that if you are using if

31:09

Speaker 1: use git uh post hoop so that you can prevent in some of the attacks Next one is IDAR, insecure direct object reference. So omin F you know IDAR means it's a shorter format. Okay. So one hand. Okay I think security is low. Hold on. So IDA is in OASP as the JWT is a broken access control, it comes under. So, how many of you used PKID in the URL as a Django developer, which you know, right? uh same I also use same PKID already. So while using that you should be be careful when you are using it.

31:54

Speaker 1: For example Uh user profile, if we want to access some of the user profile, what we will do? In the URL, we will pass PK, right? So that we can validate in our backend, we can validate PK. So user. objects. get. I'll show you like this. Uh this is what we are using, right? Yeah. Pk. We are getting pk value, then we are validating a user. objects. get. ID equal to PK, then we are showing this information to the uh client. So if you are not properly validated, then The attacker can change the superuser's email ID

32:40

Speaker 1: or Password you can change. So how? So for that you can prevent using that. If uh just in Django, there is one good thing I like about in middleware, request at user, you can get who is requested. you cle you will get so based on that we can validate that. So we can I'll show you ex demo you'll get to know how it works Okay. Then how many of you are Ahu Bridge in 2014? No one. Okay. Twenty fourteen Yahoo breach has happened because of this one small mistake what he made developer. That's in subdomain suggestion. com because of he can

33:26

Speaker 1: Traverse others users profile. So he got around 1. 5 million users records. So I'll show you demo how it works C I D I say So I d this is so this is the username is two. Okay. So what I will do So I'll make three use of there is no through. I don't want to create passes

34:12

Speaker 1: So I just copy-pasted that. So what I'll do, Tilak is a normal user. So now what I'll do in this case Yes, his ID is technically his ID is 7, right? You are able to see right 7 ID. So instead of 7, what he does, he changes fifth one ID. Fifth one is admin user ID. Okay. He changes admin user ID using his token. I'll uh take his token. This is normal Telux token. So e uses J W T. This one. So

34:57

Speaker 1: now he will change email as admin at v4fair. com. Then username is jangakana. He will make it change. It should not accept, right? So this is the current username You're able to see? I don't think I can't zoom this one. I can't, I think so. This time. Okay. So I have a time concern, I'm so sorry. So I will change it. It's accepted. So if you go into database. See. Now there is no Tilak username, he's a admin. But I changed it into as DjangoCon and also I have changed Tilak. t at v45. in instead of that I changed it into an admin at v45.

35:43

Speaker 1: tin. So now if I am admin at v4. com, now I can access applications. So how do we mitigate this? As I mentioned, Django has a good thing that Validate in while requesting request instead of direct sending PK, just validate request. user. id is a valid user or not. So that you can avoid such kind of things. Next Check database that genuine or not as I mentioned same thing. I'll skip, I don't think I don't have time. So some of tips I will give because I don't have time constraints. I have I have made lot of demos, I have to skip No, so sorry. I'll share with you anyway. So use

36:29

Speaker 1: SCA, source composition analysis. That means it scans your packages. So if you are finding any vulnerabilities in your packager, it says this vulnerability exists in this version. Please upgrade this version. That source composition analysis it will say use that one Also use SAST as I showed you bandit use that one for Python so that if any vulnerabilities in there in our code so that we can prevent these attacks. And also run Dash, use Zap, that's an open source project. So it gives a good API. So we can integrate in our as a developer we love to use APIs right. No? Okay. I love

37:14

Speaker 1: to use APS. Okay. If you didn't, please try. It is really good. So include security testing in a DevOps pipeline. If you are using Jenkins or Travis, anything, so use this pipeline, make it as a pipeline. So I have how many of your robot framework, how many of you have heard robot framework? None? Okay. So robot framework is like Selenium. It's like Sel M. We have to do X path, it's like blah blah blah. We have to do so many things, right? In robot framework, we have to do like markdown extra. Run this zap. Run bandit. That's it. It will take care of everything. So that's a very easy I will show you how it looks like. So I have a basic demo also within ten minutes. I'm not sure.

37:59

Speaker 1: Okay, I'll show you S right? This is the robot script. You are able to see right So this is the robot zap. It runs zap, then it's like I am using safety also for source composition analysis. I am coming I commented bandit because it takes time. She should read all my codes. It takes time. So just I commented that. And Zap will run the scan. Zap is basically pen tester use the tool to scan your application. So here I am using that zap. So we will run that zap script. I hope it was Right?

38:46

Speaker 1: Robot. So th this is the running. That's simple so simple, right? This is using robot. Run safety again as requirements, then use this path. That's it. Run zap. You have to give that path. In SelNM you have to give XPAR like so many things. I didn't learn Jap. It was CelNM. I hate that one. It's too complex. So I that's why I love this uh Robo script. So I'll run this. Okay. Oh as I mentioned, some problem has happened. No, no. I'm so sorry.

39:32

Speaker 1: Yeah. I'm so sorry. So it's now it will start zap. I uh you can see zap is starting now. So this is the Zap, if you're not familiar with Zap, this is the basically pen penetration testing. They team, they use Zap and Bub the most. So they test against your application, they find vulnerability, and they give a report to you, right? No? Okay. So I'll just click. So you can see now it's automated. See it's set to the context. Now you can see some actions will go on here. See? Okay. So it will scan like this.

40:18

Speaker 1: So why uh just my suggestion, I am anyway I am sharing this script in GitHub, please use this. In IDAR I am doing I have written script but uh it's not working. I am just do uh working on that. Once it is done, I will update in GitHub. Please use this script uh in your Daily, daily, daily basis your application development so that you can prevent some of the vulnerabilities. So this is what the gives and also robot give a reports It's really good HTML report it gives you. Where it is. Okay, here. So this is one report. Okay. It gives a really good report.

41:05

Speaker 1: We can check it out. And also now safety has a written So PyML has a flaw, please fix this. JuniKarne has a flaw, you have to fix that it says. And also bandit has some of problems. This is bandit giving results. So you can check out these results. So this zap is give you some of the result like medium, what is the vulnerability name, what is the request, what is the response. So So that using this you can prevent some of the attacks. And I am sharing with you in this link please have a look and also if you are anyone interested to contribute with our orchestra on and thread playbook please

41:51

Speaker 1: And this is my Twitter link and thank you so much for your patience. I hope you like this.

42:03

Speaker 2: uh time uh lifespan uh okay for tokens what what's your recommendation for a short lifespan span.

42:12

Speaker 1: Make it lifetime shorter. Make it uh maximum six to eight hour. Once the user is not logged uh user is deleted or uh His n changed username or something his activity has done, please make sure that make JWT is revoked. You generate new JWT token. So that's a good way so that we can avoid some of these uh attacks

42:33

Speaker 3: Uh nice talk. Thank you. Whatever you showed here, is it specific to Django or can you apply this to any other framework?

42:39

Speaker 1: Any other framework you can apply. This is actually Django talk, so that's why I showed Django related stuff So you can do it in uh if you're using Java, if you are using dot net, you can do it. It's very simple. So uh zap doesn't care if it is a Django, only I will do Django related, I find all that don't do that. It's like tool, right? You can do any applications, any programming languages.

43:02

Speaker 4: Let's thank TLAC again for the incredible presentation.

Questions this talk answers

What is a RESTful web service, and what Python frameworks can I use to build one?

A web service is a centralized backend that exchanges information between applications, such as a Django REST backend and a Vue, React, or mobile client. RESTful services use HTTP and commonly support JSON and XML; Python options include Django REST framework, Flask, Falcon, Pyramid, CherryPy, and Bottle.

Discussed at 2:33

What JWT vulnerabilities can let someone access an account without authenticating?

JWTs can be abused when the server accepts an unsigned token, mishandles algorithm choices, or validates claims using changeable values such as usernames. An old token may then remain valid after a user changes identity-related data, allowing another user to use it.

Discussed at 10:58

How do I prevent JWT manipulation and stolen-token attacks?

Validate tokens against an immutable unique identifier, such as an email or generated user ID, rather than a mutable username. Use short token lifetimes—roughly no more than six to eight hours—and revoke or replace tokens when the user changes or is removed.

Discussed at 16:20

How can unsafe YAML deserialization compromise a Python web server?

Loading attacker-controlled YAML without validation can execute Python code, expose environment variables, create a reverse shell, and potentially give the attacker control of the server. The talk demonstrates this through a malicious product upload processed with unsafe YAML loading.

Discussed at 22:13

How do I fix unsafe YAML deserialization in Python?

Use a safe loader such as `yaml.safe_load` instead of `yaml.load`, validate the deserialized data, and isolate processing in a container running as a non-root user. Source-analysis tools such as Bandit can also flag unsafe loading before code is committed.

Discussed at 27:00

How does insecure direct object reference happen in a Django API, and how do I prevent it?

If an endpoint trusts a primary-key value from the URL without checking ownership, a normal user can change the ID and modify another user’s profile. Validate the requested object against `request.user` and confirm in the database that the requesting user is authorized to access it.

Discussed at 31:09

How can I automate security testing for a Python web application?

Add software-composition analysis, Bandit, and OWASP ZAP to the development or CI/CD pipeline. The talk demonstrates using Robot Framework to run these checks and generate reports before vulnerabilities reach production.

Discussed at 36:29

How long should a JWT token remain valid?

The recommendation is to keep the lifetime short—at most about six to eight hours—and revoke or regenerate the token when the user is deleted or changes their username or other relevant account information.

Discussed at 42:12

Presenters

Note: We understand that names change, people change, and bodies change. We respect each individual's journey and privacy. If you have any concerns about a video or need us to remove content, please don't hesitate to contact us. We will handle your request with care and promptly address any issues.

More videos from DjangoCon US