Giter Site home page Giter Site logo

innsecure's Introduction

Form3 InfoSec Engineering Take Home Exercise

InfoSec Engineers at Form3 work on sophisticated, highly available distributed systems in a microservices environment. We detect and evaluate threats, and set standards for engineering security. We also work with other teams to build secure systems, and to spread security awareness. This exercise is intended to mimic a real-world scenario, and should offer you the opportunity to demonstrate the security awareness, technical know-how, and communication skills.

Within this exercise we have embedded a range of vulnerabilities focusing on both application security and infrastructure security. We have added both as our goal is to build a team that encompasses both skill-sets, but we do not expect you to tackle both in their entirety. We ask that you showcase your experience as you see fit. The general ruling for what we look for is as follows; excellence within either domain or strong submission across both.

Instructions

The goal of this exercise is to find and suggest fixes for security issues in this repository. To start the exercise please create a private Github repository, with main and production branches. Then import the code from the latest release into the main branch.

Task 1

Create a Pull Request to merge from main to production. Review and comment on the PR as you would review a PR produced by a colleague. Your comments should include vulnerabilities of varying severity.

Task 2

Produce a fix branch from main to create a working fix of one of the issues you identified, allowing you to demonstrate your coding abilities. Create a PR to merge fix into main for the reviewers to see the changes you have made. Imagine that your PR will be reviewed by the original author of the code, who is keen to learn more about security.

Once Completed

Double check that your review comments have been submitted for both PRs. If they haven't yet been submitted then there will be a pending flag next to each comment and a number next to a green Finish your review button in the top-right of the page.

How to submit your exercise

Let us know you've completed the exercise using the link provided at the bottom of the email from our recruitment team and Invite @form3tech-interviewer-1 to your private repo

Troubleshooting

If you encounter any problems with the service we encourage you to do some debugging prior to reaching out to your recruiter for assistance.

How long should you spend on this?

We're conscious that there are plenty of other demands on people's time, and we don't want you to stress about doing loads for this. The aim is to see some evidence of your security knowledge, coding ability, and communication skills in a relatively low pressure environment. If we need more material to make a decision, we'll let you know. And remember that you're welcome to get in touch if you're unsure.

License

Copyright 2019-2021 Form3 Financial Cloud

Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.

innsecure's People

Contributors

rossmcf3 avatar jeeves-form3 avatar markhowardform3 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.