SlideShare a Scribd company logo
1 of 41
Everything you need to know
about the TYPO3
Security Team




                    Oliver Klee, T3DD10
Making TYPO3
more secure since 2004
Andreas Förthner
                Helmut Hummel     V5 team leader
                V4 team leader                      Lars E.D. Jensen

                                                                       Marcus Krause



Making TYPO3
more secure since 2004
Rove Monteaux                                                          Georg Ringer




            Dmitry Dulepov                          Jochen Weiland
                                  Oliver Klee
We handle reports,
   create patches
      and educate
It‘sthenot
about  money
There are   good
             vulnerability reports …
There are     good
               vulnerability reports …
Subject: SQL injection in tx_moo 5.2.9

Dear security team,
I think I‘ve found an SQL injection vulnerability in the
extension tx_moo version 5.2.9.
In line 145 of the tx_moo_pi1 class, $pivars['uid'] is not
escaped:

$res = $GLOBALS['TYPO3_DB']->exec_SELECTquery(
   '*', 'tx_moo_cows', 'uid = ' . $this->piVars['uid']
);
... and there are the   others.




http://typo3.org/teams/security/resources/
Slides: TYPO3 website hacked
... and there are the      others.
  Subject: My site got hacked!

  Hi,
  I think my TYPO3 site got hacked. There suddenly is
  another user, and there's some strange JavaScript on all
  my pages. What can I do?


http://typo3.org/teams/security/resources/
Slides: TYPO3 website hacked
We coordinate extension
security fixes with the
extension authors
We coordinate extension
security fixes with the
extension authors

     report to
security@typo3.org
We coordinate extension
security fixes with the
extension authors

     report to         automatic post to
security@typo3.org   security newsgroup &
                     trouble ticket system
We coordinate extension
security fixes with the
extension authors

     report to         automatic post to
security@typo3.org   security newsgroup &    issue is real
                     trouble ticket system
We coordinate extension
security fixes with the
extension authors                                            reply

                                                    no

     report to         automatic post to
security@typo3.org   security newsgroup &    issue is real
                     trouble ticket system
We coordinate extension
security fixes with the
extension authors                                                  reply

                                                    no

     report to         automatic post to                     yes
security@typo3.org   security newsgroup &    issue is real           reply
                     trouble ticket system
We coordinate extension
security fixes with the
extension authors                                                  reply

                                                    no

     report to         automatic post to                     yes
security@typo3.org   security newsgroup &    issue is real           reply
                     trouble ticket system


                                                                   e-mail to
                                                                   extension
                                                                    author
We coordinate extension
security fixes with the
extension authors                                                  reply

                                                    no

     report to         automatic post to                     yes
security@typo3.org   security newsgroup &    issue is real           reply
                     trouble ticket system


                                               author              e-mail to
                                               replies             extension
                                                                    author
We coordinate extension
security fixes with the
extension authors                                                  reply

                                                    no

     report to         automatic post to                     yes
security@typo3.org   security newsgroup &    issue is real           reply
                     trouble ticket system


                                               author              e-mail to
                                               replies             extension
                                                                    author
                                                      no

                                              remove
                                             extension
                                             from TER
We coordinate extension
security fixes with the
extension authors                                                  reply

                                                    no

     report to         automatic post to                     yes
security@typo3.org   security newsgroup &    issue is real           reply
                     trouble ticket system


                                               author              e-mail to
                                               replies             extension
                                                                    author
                                                      no

                                              remove                SecTeam
                                             extension              releases
                                             from TER                bulletin
We coordinate extension
security fixes with the
extension authors                                                        reply

                                                          no

     report to         automatic post to                           yes
security@typo3.org   security newsgroup &          issue is real           reply
                     trouble ticket system


                         extension is        yes     author              e-mail to
                       still maintained              replies             extension
                                                                          author
                                                            no

                                                    remove                SecTeam
                                                   extension              releases
                                                   from TER                bulletin
We coordinate extension
security fixes with the
extension authors                                                             reply

                                                               no

     report to              automatic post to                           yes
security@typo3.org        security newsgroup &          issue is real           reply
                          trouble ticket system


remove extension,    no       extension is        yes     author              e-mail to
    bulletin                still maintained              replies             extension
                                                                               author
                                                                 no

                                                         remove                SecTeam
                                                        extension              releases
                                                        from TER                bulletin
We coordinate extension
security fixes with the
extension authors                                                             reply

                                                               no

     report to              automatic post to                           yes
security@typo3.org        security newsgroup &          issue is real           reply
                          trouble ticket system


remove extension,    no       extension is        yes     author              e-mail to
    bulletin                still maintained              replies             extension
                                                                               author
                                      yes                        no
                               author                                          SecTeam
                            creates patch                remove
                                                        extension              releases
                                                        from TER                bulletin
We coordinate extension
security fixes with the
extension authors                                                             reply

                                                               no

     report to              automatic post to                           yes
security@typo3.org        security newsgroup &          issue is real           reply
                          trouble ticket system


remove extension,    no       extension is        yes     author              e-mail to
    bulletin                still maintained              replies             extension
                                                                               author
                                      yes                        no
      SecTeam                  author                                          SecTeam
    reviews patch           creates patch                remove
                                                        extension              releases
                                                        from TER                bulletin
We coordinate extension
security fixes with the
extension authors                                                             reply

                                                               no

     report to              automatic post to                           yes
security@typo3.org        security newsgroup &          issue is real           reply
                          trouble ticket system


remove extension,    no       extension is        yes     author              e-mail to
    bulletin                still maintained              replies             extension
                                                                               author
                                      yes                        no
      SecTeam                  author                                          SecTeam
    reviews patch           creates patch                remove
                                                        extension              releases
                                                        from TER                bulletin


     patch
    is okay
We coordinate extension
security fixes with the
extension authors                                                             reply

                                                               no

     report to              automatic post to                           yes
security@typo3.org        security newsgroup &          issue is real           reply
                          trouble ticket system


remove extension,    no       extension is        yes     author              e-mail to
    bulletin                still maintained              replies             extension
                                                                               author
                                      yes                        no
      SecTeam                  author                                          SecTeam
    reviews patch           creates patch                remove
                                                        extension              releases
                                                        from TER                bulletin
    no

     patch
    is okay
We coordinate extension
security fixes with the
extension authors                                                             reply

                                                               no

     report to              automatic post to                           yes
security@typo3.org        security newsgroup &          issue is real           reply
                          trouble ticket system


remove extension,    no       extension is        yes     author              e-mail to
    bulletin                still maintained              replies             extension
                                                                               author
                                      yes                        no
      SecTeam                  author                                          SecTeam
    reviews patch           creates patch                remove
                                                        extension              releases
                                                        from TER                bulletin
    no

     patch            author or SecTeam
    is okay          releases new version
              yes
We coordinate extension
security fixes with the
extension authors                                                             reply

                                                               no

     report to              automatic post to                           yes
security@typo3.org        security newsgroup &          issue is real           reply
                          trouble ticket system


remove extension,    no       extension is        yes     author              e-mail to
    bulletin                still maintained              replies             extension
                                                                               author
                                      yes                        no
      SecTeam                  author                                          SecTeam
    reviews patch           creates patch                remove
                                                        extension              releases
                                                        from TER                bulletin
    no

     patch            author or SecTeam           SecTeam marks
    is okay          releases new version         old versions in
              yes                                 TER as insecure
We coordinate extension
security fixes with the
extension authors                                                             reply

                                                               no

     report to              automatic post to                           yes
security@typo3.org        security newsgroup &          issue is real           reply
                          trouble ticket system


remove extension,    no       extension is        yes     author              e-mail to
    bulletin                still maintained              replies             extension
                                                                               author
                                      yes                        no
      SecTeam                  author                                          SecTeam
    reviews patch           creates patch                remove
                                                        extension              releases
                                                        from TER                bulletin
    no

     patch            author or SecTeam           SecTeam marks                SecTeam
    is okay          releases new version         old versions in              releases
              yes                                 TER as insecure               bulletin
We cooperate with the
Core Team in fixing issues                                          reply

                                                    no

     report to         automatic post to                     yes
security@typo3.org   security newsgroup &    issue is real           reply
                     trouble ticket system
We cooperate with the
Core Team in fixing issues                                           reply

                                                    no

     report to         automatic post to                     yes
security@typo3.org   security newsgroup &    issue is real            reply
                     trouble ticket system


                                                                    SecTeam or
                                                                     CoreTeam
                                                                   creates patch
We cooperate with the
Core Team in fixing issues                                           reply

                                                    no

     report to         automatic post to                     yes
security@typo3.org   security newsgroup &    issue is real            reply
                     trouble ticket system


                                             post patch to          SecTeam or
                                             core-security           CoreTeam
                                                                   creates patch
We cooperate with the
Core Team in fixing issues                                           reply

                                                    no

     report to         automatic post to                     yes
security@typo3.org   security newsgroup &    issue is real            reply
                     trouble ticket system


                                             post patch to          SecTeam or
                          Reviews                                    CoreTeam
                                             core-security         creates patch
We cooperate with the
Core Team in fixing issues                                           reply

                                                    no

     report to         automatic post to                     yes
security@typo3.org   security newsgroup &    issue is real            reply
                     trouble ticket system


                                             post patch to          SecTeam or
                          Reviews                                    CoreTeam
                                             core-security         creates patch

                                -1
We cooperate with the
Core Team in fixing issues                                                 reply

                                                          no

     report to               automatic post to                     yes
security@typo3.org         security newsgroup &    issue is real            reply
                           trouble ticket system


        +1 by Core Team                            post patch to          SecTeam or
                                Reviews                                    CoreTeam
                                                   core-security         creates patch
          +1 by Sec Team

                                      -1




  release manager
  collects patches
We cooperate with the
Core Team in fixing issues                                                 reply

                                                          no

     report to               automatic post to                     yes
security@typo3.org         security newsgroup &    issue is real            reply
                           trouble ticket system


        +1 by Core Team                            post patch to          SecTeam or
                                Reviews                                    CoreTeam
                                                   core-security         creates patch
          +1 by Sec Team

                                      -1




  release manager          release manager
  collects patches         releases security
                                release
We cooperate with the
Core Team in fixing issues                                                 reply

                                                          no

     report to               automatic post to                     yes
security@typo3.org         security newsgroup &    issue is real            reply
                           trouble ticket system


        +1 by Core Team                            post patch to          SecTeam or
                                Reviews                                    CoreTeam
                                                   core-security         creates patch
          +1 by Sec Team

                                      -1




  release manager          release manager         SecTeam
  collects patches         releases security       releases
                                release             bulletin
We follow a
resp  onsible
(limited)
 d isclosure
 policy
We offer

   extension
    reviews
      but they
      are very

           time-
      consuming
Support the Security Team
     via the
TYPO3 Assocation
Questions?
Thank you.

More Related Content

What's hot (6)

Network security
Network securityNetwork security
Network security
 
Core Insight Enterprise 5min
Core Insight Enterprise 5minCore Insight Enterprise 5min
Core Insight Enterprise 5min
 
02 introduction to network security
02 introduction to network security02 introduction to network security
02 introduction to network security
 
Pentesting with Metasploit
Pentesting with MetasploitPentesting with Metasploit
Pentesting with Metasploit
 
Operating system vulnerability and control
Operating system vulnerability and control Operating system vulnerability and control
Operating system vulnerability and control
 
Dio - Aplicativos resilientes e seguros em Swift.
Dio - Aplicativos resilientes e seguros em Swift.Dio - Aplicativos resilientes e seguros em Swift.
Dio - Aplicativos resilientes e seguros em Swift.
 

Viewers also liked (7)

Mongodb open source_high_performance_database
Mongodb open source_high_performance_databaseMongodb open source_high_performance_database
Mongodb open source_high_performance_database
 
Cassandra NoSQL
Cassandra NoSQLCassandra NoSQL
Cassandra NoSQL
 
Edisi 06 - Bermain dengan Infrastruktur Virtual (VMware® vSphere)
Edisi 06 - Bermain dengan Infrastruktur Virtual (VMware® vSphere)Edisi 06 - Bermain dengan Infrastruktur Virtual (VMware® vSphere)
Edisi 06 - Bermain dengan Infrastruktur Virtual (VMware® vSphere)
 
No sql
No sqlNo sql
No sql
 
Wmware NoSQL
Wmware NoSQLWmware NoSQL
Wmware NoSQL
 
Scaling web applications with cassandra presentation
Scaling web applications with cassandra presentationScaling web applications with cassandra presentation
Scaling web applications with cassandra presentation
 
REST vs. SOAP
REST vs. SOAPREST vs. SOAP
REST vs. SOAP
 

More from Oliver Klee

Test-Driven Development for TYPO3 @ T3CON12DE
Test-Driven Development for TYPO3 @ T3CON12DETest-Driven Development for TYPO3 @ T3CON12DE
Test-Driven Development for TYPO3 @ T3CON12DE
Oliver Klee
 
Objektorientierte Programmierung mit extbase und fluid
Objektorientierte Programmierung mit extbase und fluidObjektorientierte Programmierung mit extbase und fluid
Objektorientierte Programmierung mit extbase und fluid
Oliver Klee
 
Test-driven Development for TYPO3
Test-driven Development for TYPO3Test-driven Development for TYPO3
Test-driven Development for TYPO3
Oliver Klee
 
Stand das im Handbuch?
Stand das im Handbuch?Stand das im Handbuch?
Stand das im Handbuch?
Oliver Klee
 
Test-Driven Development ... und mehr
Test-Driven Development ... und mehrTest-Driven Development ... und mehr
Test-Driven Development ... und mehr
Oliver Klee
 
Test-Driven Development for TYPO3
Test-Driven Development for TYPO3Test-Driven Development for TYPO3
Test-Driven Development for TYPO3
Oliver Klee
 
Test-driven development for TYPO3 (T3DD11)
Test-driven development for TYPO3 (T3DD11)Test-driven development for TYPO3 (T3DD11)
Test-driven development for TYPO3 (T3DD11)
Oliver Klee
 
Test-driven Development mit TYPO3
Test-driven Development mit TYPO3Test-driven Development mit TYPO3
Test-driven Development mit TYPO3
Oliver Klee
 
Persönliches Zeitmanagement mit Getting Things Done (GTD)
Persönliches Zeitmanagement mit Getting Things Done (GTD)Persönliches Zeitmanagement mit Getting Things Done (GTD)
Persönliches Zeitmanagement mit Getting Things Done (GTD)
Oliver Klee
 
TDD & Best Practices mit TYPO3
TDD & Best Practices mit TYPO3TDD & Best Practices mit TYPO3
TDD & Best Practices mit TYPO3
Oliver Klee
 
Unit testing for the TYPO3 4.x core (T3DD10)
Unit testing for the TYPO3 4.x core (T3DD10)Unit testing for the TYPO3 4.x core (T3DD10)
Unit testing for the TYPO3 4.x core (T3DD10)
Oliver Klee
 
Unit testing for the TYPO3 4.x core
Unit testing for the TYPO3 4.x coreUnit testing for the TYPO3 4.x core
Unit testing for the TYPO3 4.x core
Oliver Klee
 

More from Oliver Klee (15)

Stand das im Handbuch?
Stand das im Handbuch?Stand das im Handbuch?
Stand das im Handbuch?
 
Test-Driven Development for TYPO3 @ T3CON12DE
Test-Driven Development for TYPO3 @ T3CON12DETest-Driven Development for TYPO3 @ T3CON12DE
Test-Driven Development for TYPO3 @ T3CON12DE
 
Objektorientierte Programmierung mit extbase und fluid
Objektorientierte Programmierung mit extbase und fluidObjektorientierte Programmierung mit extbase und fluid
Objektorientierte Programmierung mit extbase und fluid
 
Test-driven Development for TYPO3
Test-driven Development for TYPO3Test-driven Development for TYPO3
Test-driven Development for TYPO3
 
Stand das im Handbuch?
Stand das im Handbuch?Stand das im Handbuch?
Stand das im Handbuch?
 
Test-Driven Development ... und mehr
Test-Driven Development ... und mehrTest-Driven Development ... und mehr
Test-Driven Development ... und mehr
 
Test-Driven Development for TYPO3
Test-Driven Development for TYPO3Test-Driven Development for TYPO3
Test-Driven Development for TYPO3
 
Test-driven development for TYPO3 (T3DD11)
Test-driven development for TYPO3 (T3DD11)Test-driven development for TYPO3 (T3DD11)
Test-driven development for TYPO3 (T3DD11)
 
Test-driven Development mit TYPO3
Test-driven Development mit TYPO3Test-driven Development mit TYPO3
Test-driven Development mit TYPO3
 
Test-driven development with TYPO3 (T3CON10)
Test-driven development with TYPO3 (T3CON10)Test-driven development with TYPO3 (T3CON10)
Test-driven development with TYPO3 (T3CON10)
 
Persönliches Zeitmanagement mit Getting Things Done (GTD)
Persönliches Zeitmanagement mit Getting Things Done (GTD)Persönliches Zeitmanagement mit Getting Things Done (GTD)
Persönliches Zeitmanagement mit Getting Things Done (GTD)
 
TDD & Best Practices mit TYPO3
TDD & Best Practices mit TYPO3TDD & Best Practices mit TYPO3
TDD & Best Practices mit TYPO3
 
Unit testing for the TYPO3 4.x core (T3DD10)
Unit testing for the TYPO3 4.x core (T3DD10)Unit testing for the TYPO3 4.x core (T3DD10)
Unit testing for the TYPO3 4.x core (T3DD10)
 
GPG Workshop
GPG WorkshopGPG Workshop
GPG Workshop
 
Unit testing for the TYPO3 4.x core
Unit testing for the TYPO3 4.x coreUnit testing for the TYPO3 4.x core
Unit testing for the TYPO3 4.x core
 

Recently uploaded

Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
vu2urc
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
?#DUbAI#??##{{(☎️+971_581248768%)**%*]'#abortion pills for sale in dubai@
 

Recently uploaded (20)

Advantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your BusinessAdvantages of Hiring UIUX Design Service Providers for Your Business
Advantages of Hiring UIUX Design Service Providers for Your Business
 
Real Time Object Detection Using Open CV
Real Time Object Detection Using Open CVReal Time Object Detection Using Open CV
Real Time Object Detection Using Open CV
 
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
Apidays Singapore 2024 - Building Digital Trust in a Digital Economy by Veron...
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?What Are The Drone Anti-jamming Systems Technology?
What Are The Drone Anti-jamming Systems Technology?
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
Exploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone ProcessorsExploring the Future Potential of AI-Enabled Smartphone Processors
Exploring the Future Potential of AI-Enabled Smartphone Processors
 
Developing An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of BrazilDeveloping An App To Navigate The Roads of Brazil
Developing An App To Navigate The Roads of Brazil
 
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024Finology Group – Insurtech Innovation Award 2024
Finology Group – Insurtech Innovation Award 2024
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
presentation ICT roal in 21st century education
presentation ICT roal in 21st century educationpresentation ICT roal in 21st century education
presentation ICT roal in 21st century education
 
Scaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organizationScaling API-first – The story of a global engineering organization
Scaling API-first – The story of a global engineering organization
 
Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...Driving Behavioral Change for Information Management through Data-Driven Gree...
Driving Behavioral Change for Information Management through Data-Driven Gree...
 
2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...2024: Domino Containers - The Next Step. News from the Domino Container commu...
2024: Domino Containers - The Next Step. News from the Domino Container commu...
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Histor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slideHistor y of HAM Radio presentation slide
Histor y of HAM Radio presentation slide
 
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
+971581248768>> SAFE AND ORIGINAL ABORTION PILLS FOR SALE IN DUBAI AND ABUDHA...
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024The 7 Things I Know About Cyber Security After 25 Years | April 2024
The 7 Things I Know About Cyber Security After 25 Years | April 2024
 

Everything you need to know about the TYPO3 Security Team (T3DD10)

  • 1. Everything you need to know about the TYPO3 Security Team Oliver Klee, T3DD10
  • 3. Andreas Förthner Helmut Hummel V5 team leader V4 team leader Lars E.D. Jensen Marcus Krause Making TYPO3 more secure since 2004 Rove Monteaux Georg Ringer Dmitry Dulepov Jochen Weiland Oliver Klee
  • 4. We handle reports, create patches and educate
  • 6. There are good vulnerability reports …
  • 7. There are good vulnerability reports … Subject: SQL injection in tx_moo 5.2.9 Dear security team, I think I‘ve found an SQL injection vulnerability in the extension tx_moo version 5.2.9. In line 145 of the tx_moo_pi1 class, $pivars['uid'] is not escaped: $res = $GLOBALS['TYPO3_DB']->exec_SELECTquery( '*', 'tx_moo_cows', 'uid = ' . $this->piVars['uid'] );
  • 8. ... and there are the others. http://typo3.org/teams/security/resources/ Slides: TYPO3 website hacked
  • 9. ... and there are the others. Subject: My site got hacked! Hi, I think my TYPO3 site got hacked. There suddenly is another user, and there's some strange JavaScript on all my pages. What can I do? http://typo3.org/teams/security/resources/ Slides: TYPO3 website hacked
  • 10. We coordinate extension security fixes with the extension authors
  • 11. We coordinate extension security fixes with the extension authors report to security@typo3.org
  • 12. We coordinate extension security fixes with the extension authors report to automatic post to security@typo3.org security newsgroup & trouble ticket system
  • 13. We coordinate extension security fixes with the extension authors report to automatic post to security@typo3.org security newsgroup & issue is real trouble ticket system
  • 14. We coordinate extension security fixes with the extension authors reply no report to automatic post to security@typo3.org security newsgroup & issue is real trouble ticket system
  • 15. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system
  • 16. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system e-mail to extension author
  • 17. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system author e-mail to replies extension author
  • 18. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system author e-mail to replies extension author no remove extension from TER
  • 19. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system author e-mail to replies extension author no remove SecTeam extension releases from TER bulletin
  • 20. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system extension is yes author e-mail to still maintained replies extension author no remove SecTeam extension releases from TER bulletin
  • 21. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system remove extension, no extension is yes author e-mail to bulletin still maintained replies extension author no remove SecTeam extension releases from TER bulletin
  • 22. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system remove extension, no extension is yes author e-mail to bulletin still maintained replies extension author yes no author SecTeam creates patch remove extension releases from TER bulletin
  • 23. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system remove extension, no extension is yes author e-mail to bulletin still maintained replies extension author yes no SecTeam author SecTeam reviews patch creates patch remove extension releases from TER bulletin
  • 24. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system remove extension, no extension is yes author e-mail to bulletin still maintained replies extension author yes no SecTeam author SecTeam reviews patch creates patch remove extension releases from TER bulletin patch is okay
  • 25. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system remove extension, no extension is yes author e-mail to bulletin still maintained replies extension author yes no SecTeam author SecTeam reviews patch creates patch remove extension releases from TER bulletin no patch is okay
  • 26. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system remove extension, no extension is yes author e-mail to bulletin still maintained replies extension author yes no SecTeam author SecTeam reviews patch creates patch remove extension releases from TER bulletin no patch author or SecTeam is okay releases new version yes
  • 27. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system remove extension, no extension is yes author e-mail to bulletin still maintained replies extension author yes no SecTeam author SecTeam reviews patch creates patch remove extension releases from TER bulletin no patch author or SecTeam SecTeam marks is okay releases new version old versions in yes TER as insecure
  • 28. We coordinate extension security fixes with the extension authors reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system remove extension, no extension is yes author e-mail to bulletin still maintained replies extension author yes no SecTeam author SecTeam reviews patch creates patch remove extension releases from TER bulletin no patch author or SecTeam SecTeam marks SecTeam is okay releases new version old versions in releases yes TER as insecure bulletin
  • 29. We cooperate with the Core Team in fixing issues reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system
  • 30. We cooperate with the Core Team in fixing issues reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system SecTeam or CoreTeam creates patch
  • 31. We cooperate with the Core Team in fixing issues reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system post patch to SecTeam or core-security CoreTeam creates patch
  • 32. We cooperate with the Core Team in fixing issues reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system post patch to SecTeam or Reviews CoreTeam core-security creates patch
  • 33. We cooperate with the Core Team in fixing issues reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system post patch to SecTeam or Reviews CoreTeam core-security creates patch -1
  • 34. We cooperate with the Core Team in fixing issues reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system +1 by Core Team post patch to SecTeam or Reviews CoreTeam core-security creates patch +1 by Sec Team -1 release manager collects patches
  • 35. We cooperate with the Core Team in fixing issues reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system +1 by Core Team post patch to SecTeam or Reviews CoreTeam core-security creates patch +1 by Sec Team -1 release manager release manager collects patches releases security release
  • 36. We cooperate with the Core Team in fixing issues reply no report to automatic post to yes security@typo3.org security newsgroup & issue is real reply trouble ticket system +1 by Core Team post patch to SecTeam or Reviews CoreTeam core-security creates patch +1 by Sec Team -1 release manager release manager SecTeam collects patches releases security releases release bulletin
  • 37. We follow a resp onsible (limited) d isclosure policy
  • 38. We offer extension reviews but they are very time- consuming
  • 39. Support the Security Team via the TYPO3 Assocation

Editor's Notes

  1. - who has been contact - who has subscribed to typo3-announce - who has reported a vulnerability
  2. - handle extension and core vulnerability reports - answer security-related questions, educate people - do paid extension reviews - create and review Core security fixes
  3. - contribute to make TYPO3 & the web more secure - we learn a lot - it‘s fun (team) - mostly unpaid, some projects/tasks have a budged: 4.3.0 patches, Incident Handling System
  4. - Incident Handling System will automate some steps
  5. - Incident Handling System will automate some steps
  6. - Incident Handling System will automate some steps
  7. - Incident Handling System will automate some steps
  8. - Incident Handling System will automate some steps
  9. - Incident Handling System will automate some steps
  10. - Incident Handling System will automate some steps
  11. - Incident Handling System will automate some steps
  12. - Incident Handling System will automate some steps
  13. - Incident Handling System will automate some steps
  14. - Incident Handling System will automate some steps
  15. - Incident Handling System will automate some steps
  16. - Incident Handling System will automate some steps
  17. - Incident Handling System will automate some steps
  18. - Incident Handling System will automate some steps
  19. - Incident Handling System will automate some steps
  20. - Incident Handling System will automate some steps
  21. - Incident Handling System will automate some steps
  22. - != full disclosure - least necessary information, responsible disclure - no PoC, keine Infos ohne Fix
  23. - time-consuming - only on demaid, and paid (contact us, price) - only for one version - concept or „reviewed extensions“ in the TER is dead, still helpful
  24. - become an association member - donate to the association - create great reports