Crap app tapped to trap mishaps: Demo insecure software built to school devs on secure coding

The Damn Vulnerable Serverless Application ships expletive-ready

To help those deploying serverless applications do so without stumbling into vulnerabilities, security biz Protego Labs has released crappy code in the hope there's something to be learned from studying the bugs.

The company has developed a slipshod app called the Damn Vulnerable Serverless Application (DVSA) and donated it to the Open Web Application Security Project (OWASP), a non-profit focused on helping developers write more secure code.

In a phone interview with The Register, Tal Melamed, head of security research at Protego Labs, explained that the name represents a continuation of a tradition in the security community. DVSA follows in the footsteps of the Damn Vulnerable Web Application (DVWA), the Damn Vulnerable iOS App (DVIA), Damn Insecure and Vulnerable App for Android (DIVA), and the discontinued Damn Vulnerable Linux (DVL).

DVSA also follows a similarly shoddy serverless project called Serverless Goat, donated to OWASP by security biz PureSec last month.

"Security methodologies that were efficient in traditional applications no longer apply to serverless, and the best way to demonstrate this is through a serverless application that can highlight the new challenges and the risks associated with adopting these architectures," Ory Segal, CTO of PureSec, said in an email to The Register.

Developers now have both Serverless Goat and DVSA has hazard maps.

Melamed said it wasn't hard to create bug-riddled code for DVSA. "We wanted to make it realistic," he said. "What we did was wrote a regular application then tweaked it to make it vulnerable."

The flaws, he said, focus on the particular nature of serverless applications, so there's no cross-site scripting vulnerability, something often seen in web apps.

Local storage servers. Photo by Shutterstock

Serverless is awesome (if you overlook inflated costs, dislike distributed computing, love vendor lock-in), say boffins


DVSA comes chock full of flaws, both documented and undocumented, related to event injection, authentication, data exposure, cloud configuration, access controls, denial of service, over-privileged functions, logic vulnerabilities, dependencies and unhandled exceptions, among others.

Melamed said when companies adopt serverless apps, they often mistakenly assume that their cloud service provider will take care of security. "They forget they need to make sure their code is secure," he said.

The biggest challenge, said Melamed, is to know the risks and how they differ in a serverless app. "People may assume it's the same as any application but it's not," he said.

For example, he points to monolithic apps where there's a single entry point, usually a network protocol. "In serverless, the entry point could be various events you don't control," he said, adding that the situation becomes complicated because you can't rely on an IPS or firewall to filter bad input.

Ultimately, Melamed said the biggest benefit of bad code for the serverless community will be the opportunity to learn to avoid those mistakes. ®

Broader topics

Other stories you might like

  • VMware claims ‘bare-metal’ performance from virtualized Nvidia GPUs
    Is... is that why Broadcom wants to buy it?

    The future of high-performance computing will be virtualized, VMware's Uday Kurkure has told The Register.

    Kurkure, the lead engineer for VMware's performance engineering team, has spent the past five years working on ways to virtualize machine-learning workloads running on accelerators. Earlier this month his team reported "near or better than bare-metal performance" for Bidirectional Encoder Representations from Transformers (BERT) and Mask R-CNN — two popular machine-learning workloads — running on virtualized GPUs (vGPU) connected using Nvidia's NVLink interconnect.

    NVLink enables compute and memory resources to be shared across up to four GPUs over a high-bandwidth mesh fabric operating at 6.25GB/s per lane compared to PCIe 4.0's 2.5GB/s. The interconnect enabled Kurkure's team to pool 160GB of GPU memory from the Dell PowerEdge system's four 40GB Nvidia A100 SXM GPUs.

    Continue reading
  • Nvidia promises annual datacenter product updates across CPU, GPU, and DPU
    Arm one year, x86 the next, and always faster than a certain chip shop that still can't ship even one standalone GPU

    Computex Nvidia's push deeper into enterprise computing will see its practice of introducing a new GPU architecture every two years brought to its CPUs and data processing units (DPUs, aka SmartNICs).

    Speaking on the company's pre-recorded keynote released to coincide with the Computex exhibition in Taiwan this week, senior vice president for hardware engineering Brian Kelleher spoke of the company's "reputation for unmatched execution on silicon." That's language that needs to be considered in the context of Intel, an Nvidia rival, again delaying a planned entry to the discrete GPU market.

    "We will extend our execution excellence and give each of our chip architectures a two-year rhythm," Kelleher added.

    Continue reading
  • Now Amazon puts 'creepy' AI cameras in UK delivery vans
    Big Bezos is watching you

    Amazon is reportedly installing AI-powered cameras in delivery vans to keep tabs on its drivers in the UK.

    The technology was first deployed, with numerous errors that reportedly denied drivers' bonuses after malfunctions, in the US. Last year, the internet giant produced a corporate video detailing how the cameras monitor drivers' driving behavior for safety reasons. The same system is now apparently being rolled out to vehicles in the UK. 

    Multiple camera lenses are placed under the front mirror. One is directed at the person behind the wheel, one is facing the road, and two are located on either side to provide a wider view. The cameras are monitored by software built by Netradyne, a computer-vision startup focused on driver safety. This code uses machine-learning algorithms to figure out what's going on in and around the vehicle.

    Continue reading

Biting the hand that feeds IT © 1998–2022