<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Abhi+M+Balakrishnan</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Abhi+M+Balakrishnan"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Abhi_M_Balakrishnan"/>
		<updated>2026-04-27T23:23:41Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/Offline&amp;diff=256189</id>
		<title>OWASP Vulnerable Web Applications Directory Project/Pages/Offline</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Vulnerable_Web_Applications_Directory_Project/Pages/Offline&amp;diff=256189"/>
				<updated>2019-11-26T19:05:33Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: Added Alert Labs&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| border=&amp;quot;1&amp;quot; width=&amp;quot;80%&amp;quot; cellspacing=&amp;quot;0&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | App Name / Link&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | Technology&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | Other links&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | Author&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | Notes&lt;br /&gt;
|-&lt;br /&gt;
|[https://github.com/Abhi-M/alert-labs Alert Labs]&lt;br /&gt;
|PHP&lt;br /&gt;
|[https://exploitme.info/alert-labs/ demo] [https://github.com/Abhi-M/alert-labs/archive/master.zip download] [https://exploitme.info/alert-labs/user-guide.php docs]&lt;br /&gt;
|Abhi M Balakrishnan&lt;br /&gt;
|Focusing only on XSS&lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/CSPF-Founder/btslab/ btslab]&lt;br /&gt;
| PHP&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Includes flash-based xss, SSRF, and SSI&lt;br /&gt;
|-&lt;br /&gt;
| [http://www.badstore.net/ BadStore]&lt;br /&gt;
| Perl(CGI)&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://code.google.com/p/bodgeit/ BodgeIt Store]&lt;br /&gt;
| Java&lt;br /&gt;
| [http://code.google.com/p/bodgeit/downloads/list download]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://sechow.com/bricks/index.html Bricks]&lt;br /&gt;
| PHP&lt;br /&gt;
| [http://sechow.com/bricks/download.html download] [http://sechow.com/bricks/docs/ docs]&lt;br /&gt;
| OWASP&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://sourceforge.net/projects/thebutterflytmp/files/ButterFly%20Project/ Butterfly Security Project]&lt;br /&gt;
| PHP&lt;br /&gt;
| [http://sourceforge.net/projects/thebutterflytmp/files/ download]&lt;br /&gt;
| &lt;br /&gt;
| Last updated in 2008&lt;br /&gt;
|-&lt;br /&gt;
| [http://www.itsecgames.com/ bWAPP]&lt;br /&gt;
| PHP&lt;br /&gt;
| [http://sourceforge.net/projects/bwapp/files/ download] [http://itsecgames.blogspot.be/2013/01/bwapp-installation.html docs]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/fridaygoldsmith/bwa_cyclone_transfers Cyclone Transfers]&lt;br /&gt;
| Ruby on Rails&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/quantumfoam/DVNA/ Damn Vulnerable Node Application - DVNA]&lt;br /&gt;
| Node.js&lt;br /&gt;
| [https://github.com/quantumfoam/DVNA/ download]&lt;br /&gt;
| Claudio Lacayo&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://www.dvwa.co.uk/ Damn Vulnerable Web Application - DVWA]&lt;br /&gt;
| PHP&lt;br /&gt;
| [http://code.google.com/p/dvwa/downloads/list download]&lt;br /&gt;
| RandomStorm&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://dvws.secureideas.net/ Damn Vulnerable Web Service - DVWS]&lt;br /&gt;
| PHP&lt;br /&gt;
| [http://dvws.secureideas.net/downloads/files/dvws.tgz download]&lt;br /&gt;
| Secure Ideas (depriciated?)&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/snoopysecurity/dvws Damn Vulnerable Web Services - DVWS]&lt;br /&gt;
| PHP&lt;br /&gt;
| &lt;br /&gt;
| snoopysecurity&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/secvulture/dvta Damn Vulnerable Thick Client App - DVTA]&lt;br /&gt;
| C# .NET&lt;br /&gt;
| &lt;br /&gt;
| secvulture&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://google-gruyere.appspot.com/ Gruyere]&lt;br /&gt;
| Python&lt;br /&gt;
| [http://google-gruyere.appspot.com/gruyere-code.zip download]&lt;br /&gt;
| Google&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://www.owasp.org/index.php/OWASP_Hackademic_Challenges_Project Hackademic Challenges Project]&lt;br /&gt;
| PHP&lt;br /&gt;
| [https://code.google.com/p/owasp-hackademic-challenges/ download]&lt;br /&gt;
| OWASP&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/rapid7/hackazon Hackazon]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Rapid7&lt;br /&gt;
| Has some REST and new-school web components.&lt;br /&gt;
|-&lt;br /&gt;
| [http://www.mcafee.com/us/downloads/free-tools/hacme-bank-android.aspx Hacme Bank - Android]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| McAfee / Foundstone&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://www.mcafee.com/us/downloads/free-tools/hacme-bank.aspx Hacme Bank]&lt;br /&gt;
| .NET&lt;br /&gt;
| [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacme-bank.aspx download]&lt;br /&gt;
| McAfee / Foundstone&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://www.mcafee.com/us/downloads/free-tools/hacmebooks.aspx Hacme Books]&lt;br /&gt;
| Java&lt;br /&gt;
| [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacmebooks.aspx download]&lt;br /&gt;
| McAfee / Foundstone&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://www.mcafee.com/us/downloads/free-tools/hacme-casino.aspx Hacme Casino]&lt;br /&gt;
| Ruby on Rails&lt;br /&gt;
| [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacme-casino.aspx download]&lt;br /&gt;
| McAfee / Foundstone&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://www.mcafee.com/us/downloads/free-tools/hacmeshipping.aspx Hacme Shipping]&lt;br /&gt;
| ColdFusion&lt;br /&gt;
| [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacmeshipping.aspx download]&lt;br /&gt;
| McAfee / Foundstone&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://www.mcafee.com/us/downloads/free-tools/hacmetravel.aspx Hacme Travel]&lt;br /&gt;
| C++&lt;br /&gt;
| [http://www.mcafee.com/apps/free-tools/termsofuse.aspx?url=/us/downloads/free-tools/hacmetravel.aspx download]&lt;br /&gt;
| McAfee / Foundstone&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://hackxor.sourceforge.net/cgi-bin/index.pl hackxor]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| First 2 levels online, rest offline&lt;br /&gt;
|-&lt;br /&gt;
| [https://www.owasp.org/index.php/OWASP_Juice_Shop_Project Juice Shop]&lt;br /&gt;
| Node/JS&lt;br /&gt;
| [https://github.com/bkimminich/juice-shop download] [https://hub.docker.com/r/bkimminich/juice-shop/ docker] [https://www.gitbook.com/book/bkimminich/pwning-owasp-juice-shop guide]&lt;br /&gt;
| OWASP&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://sourceforge.net/projects/lampsecurity/ LampSecurity]&lt;br /&gt;
| PHP&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://www.irongeek.com/i.php?page=mutillidae/mutillidae-deliberately-vulnerable-php-owasp-top-10 Mutillidae]&lt;br /&gt;
| PHP&lt;br /&gt;
| [http://www.irongeek.com/mutillidae/ download]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/jerryhoff/WebGoat.NET .NET Goat]&lt;br /&gt;
| C#&lt;br /&gt;
| [https://github.com/jerryhoff/WebGoat.NET git repository]&lt;br /&gt;
| OWASP&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://www.owasp.org/index.php/OWASP_Node_js_Goat_Project NodeGoat]&lt;br /&gt;
| Node.js&lt;br /&gt;
| [https://github.com/OWASP/NodeGoat git repository]&lt;br /&gt;
| OWASP&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://peruggia.sourceforge.net/ Peruggia]&lt;br /&gt;
| PHP&lt;br /&gt;
| [http://sourceforge.net/projects/peruggia/files/ download]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://code.google.com/p/puzzlemall/ Puzzlemall]&lt;br /&gt;
| Java&lt;br /&gt;
| [https://code.google.com/p/puzzlemall/downloads/list download] [https://code.google.com/p/puzzlemall/downloads/list docs]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://www.owasp.org/index.php/OWASP_Rails_Goat_Project Rails Goat]&lt;br /&gt;
| Ruby on Rails&lt;br /&gt;
| [https://github.com/OWASP/railsgoat/archive/master.zip download] [http://railsgoat.cktricky.com/getting_started.html docs]&lt;br /&gt;
| OWASP&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://suif.stanford.edu/%7Elivshits/securibench/ SecuriBench]&lt;br /&gt;
| Java&lt;br /&gt;
| &lt;br /&gt;
| Stanford&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://suif.stanford.edu/%7Elivshits/work/securibench-micro/ SecuriBench Micro]&lt;br /&gt;
| Java&lt;br /&gt;
| [http://suif.stanford.edu/~livshits/securibench/download.html download]&lt;br /&gt;
| Stanford&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://www.owasp.org/index.php/OWASP_Security_Shepherd Security Shepherd]&lt;br /&gt;
| Java&lt;br /&gt;
| [https://sourceforge.net/projects/owaspshepherd/ download]&lt;br /&gt;
| OWASP&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/sqlmapproject/testenv SQL injection test environment]&lt;br /&gt;
| PHP&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| SQLmap Project&lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/Audi-1/sqli-labs SQLI-labs]&lt;br /&gt;
| PHP&lt;br /&gt;
| [https://github.com/Audi-1/sqli-labs/archive/master.zip download] [http://dummy2dummies.blogspot.com/ blog]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/SpiderLabs/SQLol SQLol]&lt;br /&gt;
| PHP&lt;br /&gt;
| [https://github.com/SpiderLabs/SQLol/archive/master.zip download]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/SpiderLabs/SQLol SQLol]&lt;br /&gt;
| PHP&lt;br /&gt;
| [https://github.com/SpiderLabs/SQLol/archive/master.zip download]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/sakti/twitterlike twitterlike]&lt;br /&gt;
| PHP&lt;br /&gt;
| [https://github.com/sakti/twitterlike git repository]&lt;br /&gt;
| Sakti Dwi Cahyono&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://www.nth-dimension.org.uk/blog.php?id=88 VulnApp]&lt;br /&gt;
| .NET&lt;br /&gt;
| [http://projects.nth-dimension.org.uk/dir?d=VulnApp CVS download] [http://projects.nth-dimension.org.uk/rptview?rn=6 vulns]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [http://exploit.co.il/hacking/exploit-kb-vulnerable-web-app/ Vulnerable Web App]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
| Exploit.co.il&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|[https://www.owasp.org/index.php/OWASP_Vulnerable_Web_Application Vulnerable Web Application Project]&lt;br /&gt;
|PHP&lt;br /&gt;
|[https://github.com/OWASP/Vulnerable-Web-Application Github]&lt;br /&gt;
|[https://github.com/hummingbirdscyber/ Hummingbirds Cyber Security Community]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/adamdoupe/WackoPicko WackoPicko]&lt;br /&gt;
| PHP&lt;br /&gt;
| [https://github.com/adamdoupe/WackoPicko/zipball/master download] [http://cs.ucsb.edu/~adoupe/static/black-box-scanners-dimva2010.pdf whitepaper]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/sectooladdict/wavsep WAVSEP - Web Application Vulnerability Scanner Evaluation Project]&lt;br /&gt;
| Java&lt;br /&gt;
| [https://sourceforge.net/projects/wavsep/ download (builds)] [https://code.google.com/p/wavsep/downloads/list download (old)] [https://github.com/sectooladdict/wavsep/wiki wiki]&lt;br /&gt;
| Shay Chen&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://www.owasp.org/index.php/Category:OWASP_WebGoat_Project WebGoat]&lt;br /&gt;
| Java&lt;br /&gt;
| [http://code.google.com/p/webgoat/downloads/list download] [https://www.owasp.org/index.php/WebGoat_User_and_Install_Guide_Table_of_Contents guide]&lt;br /&gt;
| OWASP&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://www.owasp.org/index.php/WebGoatPHP WebGoatPHP]&lt;br /&gt;
| PHP&lt;br /&gt;
| [https://github.com/OWASP/OWASPWebGoatPHP download] [https://github.com/OWASP/OWASPWebGoatPHP/blob/master/README.md guide]&lt;br /&gt;
| OWASP&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://code.google.com/p/wivet/ WIVET&amp;amp;nbsp;- Web Input Vector Extractor Teaser]&lt;br /&gt;
| &lt;br /&gt;
| [http://www.webguvenligi.org/projeler/wivet download] [https://code.google.com/p/wivet/downloads/list?can=1&amp;amp;amp;q= tests]&lt;br /&gt;
| &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| [https://github.com/s4n7h0/xvwa Xtreme Vulnerable Web Application (XVWA)]&lt;br /&gt;
| PHP/MySQL&lt;br /&gt;
| [https://github.com/s4n7h0/xvwa download]&lt;br /&gt;
| @s4n7h0, @samanL33T&lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:XSS_Filter_Evasion_Cheat_Sheet&amp;diff=222378</id>
		<title>Talk:XSS Filter Evasion Cheat Sheet</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:XSS_Filter_Evasion_Cheat_Sheet&amp;diff=222378"/>
				<updated>2016-10-12T20:22:51Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: /* Filter bypass based polyglot */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;I can speak from being on the receiving end of XSS Evasion Attacks :)&lt;br /&gt;
&lt;br /&gt;
    http://blog.spiderlabs.com/2013/09/modsecurity-xss-evasion-challenge-results.html&lt;br /&gt;
    http://blog.spiderlabs.com/2013/08/the-web-is-vulnerable-xss-on-the-battlefront-part-1.html&lt;br /&gt;
&lt;br /&gt;
Essentially what we need to do is to consolidate a couple of key resources.  The top two being -&lt;br /&gt;
&lt;br /&gt;
    HTML5Sec Vectors - https://raw.githubusercontent.com/cure53/H5SC/master/vectors.txt.  These are taken from Mario's awesome work - http://html5sec.org/&lt;br /&gt;
    Shazzer's Successful Fuzzes - https://raw.githubusercontent.com/client9/libinjection/master/data/xss-shazzer.txt.  These are from Gareth's equally awesome work - http://shazzer.co.uk/home.  &lt;br /&gt;
&lt;br /&gt;
I would start with these two resources as the base and build from there.&lt;br /&gt;
&lt;br /&gt;
-Ryan&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Outdated Examples?'''&lt;br /&gt;
&lt;br /&gt;
According to https://www.owasp.org/index.php/Script_in_IMG_tags and due to my own observations, it seems that the examples with &amp;lt;img src=&amp;quot;...&amp;quot;&amp;gt; provided here are outdated and irrelevant. Means: they are only relevant to Browsers &amp;lt;=IE6 . This makes it hard to collect the relevant (test-)cases from this page and may make people think that an application is not xss save if it does not handle these cases (as it was in my case).&lt;br /&gt;
Can these examples either be removed or moved to a dedicated sub-chapter?&lt;br /&gt;
Or I am completely wrong?&lt;br /&gt;
- Markus&lt;br /&gt;
&lt;br /&gt;
== ha.ckers.org Down ==&lt;br /&gt;
&lt;br /&gt;
The ha.ckers.org site has been down for quite some time now, breaking the examples listed on the page. I've setup a mirror for these files, so the samples will work again. If ha.ckers.org ever comes back, the change to use the xss.rocks mirror can be reverted.&lt;br /&gt;
&lt;br /&gt;
If anyone objects to this, please let me know. --[[User:Adam Caudill|Adam Caudill]] ([[User talk:Adam Caudill|talk]]) 18:43, 3 March 2016 (CST)&lt;br /&gt;
&lt;br /&gt;
== %tag ==&lt;br /&gt;
&lt;br /&gt;
I searched online with &amp;lt;tt&amp;gt;&amp;quot;%tag&amp;quot; internet explorer&amp;lt;/tt&amp;gt;, saw an example in [https://archive.org/stream/TheBrowserHackersHandbook2014/The%20Browser%20Hackers%20Handbook%202014_djvu.txt The Browser Hackers Handbook 2014] and a reference to the main article.  I wonder if the main article should include the &amp;lt;tt&amp;gt;&amp;lt;%tag style=xss:expression(alert(6))&amp;gt;&amp;lt;/tt&amp;gt; trick.  Another article explained that IE ignored a possibility of code execution via the unexpected tag, http://real-hacker-network.blogspot.ca/2012/09/aspnet-cross-site-scripting.html --[[User:Eelgheez|Eelgheez]] ([[User talk:Eelgheez|talk]])&lt;br /&gt;
:: My attempt with &amp;lt;tt&amp;gt;%tag&amp;lt;/tt&amp;gt; could not evade IE11's XSS filter.  Oh well.  --[[User:Eelgheez|Eelgheez]] ([[User talk:Eelgheez|talk]]) 17:14, 7 July 2016 (CDT)&lt;br /&gt;
&lt;br /&gt;
== Filter bypass based polyglot ==&lt;br /&gt;
&lt;br /&gt;
Why is this polyglot linking to a resource on a private website? (shellypalmer.com)&lt;br /&gt;
I believe it should link to localhost. In the case of a successful execution of the payload, the referrer header will get listed on the logs of shellypalmer.com&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi M Balakrishnan|Abhi M Balakrishnan]] ([[User talk:Abhi M Balakrishnan|talk]])&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:XSS_Filter_Evasion_Cheat_Sheet&amp;diff=222377</id>
		<title>Talk:XSS Filter Evasion Cheat Sheet</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:XSS_Filter_Evasion_Cheat_Sheet&amp;diff=222377"/>
				<updated>2016-10-12T20:22:29Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: /* Filter bypass based polyglot */ new section&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;I can speak from being on the receiving end of XSS Evasion Attacks :)&lt;br /&gt;
&lt;br /&gt;
    http://blog.spiderlabs.com/2013/09/modsecurity-xss-evasion-challenge-results.html&lt;br /&gt;
    http://blog.spiderlabs.com/2013/08/the-web-is-vulnerable-xss-on-the-battlefront-part-1.html&lt;br /&gt;
&lt;br /&gt;
Essentially what we need to do is to consolidate a couple of key resources.  The top two being -&lt;br /&gt;
&lt;br /&gt;
    HTML5Sec Vectors - https://raw.githubusercontent.com/cure53/H5SC/master/vectors.txt.  These are taken from Mario's awesome work - http://html5sec.org/&lt;br /&gt;
    Shazzer's Successful Fuzzes - https://raw.githubusercontent.com/client9/libinjection/master/data/xss-shazzer.txt.  These are from Gareth's equally awesome work - http://shazzer.co.uk/home.  &lt;br /&gt;
&lt;br /&gt;
I would start with these two resources as the base and build from there.&lt;br /&gt;
&lt;br /&gt;
-Ryan&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Outdated Examples?'''&lt;br /&gt;
&lt;br /&gt;
According to https://www.owasp.org/index.php/Script_in_IMG_tags and due to my own observations, it seems that the examples with &amp;lt;img src=&amp;quot;...&amp;quot;&amp;gt; provided here are outdated and irrelevant. Means: they are only relevant to Browsers &amp;lt;=IE6 . This makes it hard to collect the relevant (test-)cases from this page and may make people think that an application is not xss save if it does not handle these cases (as it was in my case).&lt;br /&gt;
Can these examples either be removed or moved to a dedicated sub-chapter?&lt;br /&gt;
Or I am completely wrong?&lt;br /&gt;
- Markus&lt;br /&gt;
&lt;br /&gt;
== ha.ckers.org Down ==&lt;br /&gt;
&lt;br /&gt;
The ha.ckers.org site has been down for quite some time now, breaking the examples listed on the page. I've setup a mirror for these files, so the samples will work again. If ha.ckers.org ever comes back, the change to use the xss.rocks mirror can be reverted.&lt;br /&gt;
&lt;br /&gt;
If anyone objects to this, please let me know. --[[User:Adam Caudill|Adam Caudill]] ([[User talk:Adam Caudill|talk]]) 18:43, 3 March 2016 (CST)&lt;br /&gt;
&lt;br /&gt;
== %tag ==&lt;br /&gt;
&lt;br /&gt;
I searched online with &amp;lt;tt&amp;gt;&amp;quot;%tag&amp;quot; internet explorer&amp;lt;/tt&amp;gt;, saw an example in [https://archive.org/stream/TheBrowserHackersHandbook2014/The%20Browser%20Hackers%20Handbook%202014_djvu.txt The Browser Hackers Handbook 2014] and a reference to the main article.  I wonder if the main article should include the &amp;lt;tt&amp;gt;&amp;lt;%tag style=xss:expression(alert(6))&amp;gt;&amp;lt;/tt&amp;gt; trick.  Another article explained that IE ignored a possibility of code execution via the unexpected tag, http://real-hacker-network.blogspot.ca/2012/09/aspnet-cross-site-scripting.html --[[User:Eelgheez|Eelgheez]] ([[User talk:Eelgheez|talk]])&lt;br /&gt;
:: My attempt with &amp;lt;tt&amp;gt;%tag&amp;lt;/tt&amp;gt; could not evade IE11's XSS filter.  Oh well.  --[[User:Eelgheez|Eelgheez]] ([[User talk:Eelgheez|talk]]) 17:14, 7 July 2016 (CDT)&lt;br /&gt;
&lt;br /&gt;
== Filter bypass based polyglot ==&lt;br /&gt;
&lt;br /&gt;
Why is this polyglot linking to a resource on a private website? (shellypalmer.com)&lt;br /&gt;
I believe it should link to localhost. In the case of a successful execution of the payload, the referrer header will get listed on the logs of shellypalmer.com&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=188333</id>
		<title>OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=188333"/>
				<updated>2015-01-21T12:07:05Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Bricks==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks is a deliberately vulnerable web application built on PHP &amp;amp; MySQL focuses on variations of commonly seen application security vulnerabilities &amp;amp; exploits, which can be exploited using tools like Mantra and ZAP.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
* OWASP Bricks is a deliberately vulnerable web application built on PHP and MySQL. &lt;br /&gt;
* The project focuses on variations of commonly seen application security vulnerabilities and exploits. &lt;br /&gt;
* Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP). &lt;br /&gt;
* The mission is to 'break the bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Bricks is a web application security learning platform built on PHP and MySQL. The project focuses on variations of commonly seen application security issues. Each 'Brick' has some sort of security issue which can be leveraged manually or using automated software tools. The mission is to 'Break the Bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
Bricks is a completely free and open source project brought to you by OWASP. The complete documentation and instruction videos can also be accessed or downloaded for free. Bricks are classified into three different sections: login pages, file upload pages and content pages.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Bricks is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Bricks? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks  provides:&lt;br /&gt;
&lt;br /&gt;
* A platform for learning web application security.&lt;br /&gt;
* A test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASP_Bricks_Presentation_Slides.pptx|OWASP Bricks Presentation Slides]]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan| Abhi_M_Balakrishnan]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Mantra - Security Framework]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/owaspbricks&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* [http://sechow.com/bricks/download.html Download Bricks]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
Bricks is brought to you by OWASP, a free and open software security community focusing on improving the security of software. Our mission is to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks.&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks project is led by Abhi M Balakrishnan, an information security enthusiast. He is the founding member of OWASP Mantra, Secpedia and Bbroy.&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
# Demonstrate maximum variations of most common vulnerabilities&lt;br /&gt;
# Help people to learn the need of secure codding practices and SSDLC&lt;br /&gt;
# Attract people to design more bricks&lt;br /&gt;
# Become a test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
# Help people learn the manual method of testing the applications&lt;br /&gt;
# Demonstrate the possibilities of various security tools and techniques&lt;br /&gt;
# Become a platform to teach web application security in a class room/lab environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Bricks is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Spread the word - Facebook, Twitter, Google+ or any other communication platform.&lt;br /&gt;
* Write about OWASP Bricks on your web site/ book.&lt;br /&gt;
* Mention it in your resume - It helps you, it helps the company and it helps us and thus everybody wins.&lt;br /&gt;
* Make tutorials/videos of Bricks in languages you know of.&lt;br /&gt;
* Include it in your training materials, talks, discussions etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
* [http://news.softpedia.com/news/Security-App-of-the-Week-OWASP-Bricks-375093.shtml OWASP Bricks was the Softpedia Security App of the week]&lt;br /&gt;
* [http://is-ra.org/c0c0n/2014/ OWASP Bricks was supporting partner of c0c0n 2014]  &lt;br /&gt;
* [https://www.youtube.com/watch?v=pPg8bA7ps3U OWASP Bricks was presented at OWASP/Null combined meet in Delhi November 2014]&lt;br /&gt;
* [https://www.facebook.com/OwaspBricks/posts/646717422114772 Adwiteeya Agrawal presented OWASP Bricks at Indira Gandhi Delhi Technical University for Women - IGDTU]&lt;br /&gt;
* [http://dl.packetstormsecurity.net/papers/general/poor_mans_security_lab.pdf The Poor Man's Security Lab guide recommends OWASP Bricks]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Bricks}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Bricks]]&lt;br /&gt;
[[Category:OWASP Download|Bricks]]&lt;br /&gt;
[[Category:OWASP Tool|Bricks]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool|Bricks]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=188332</id>
		<title>OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=188332"/>
				<updated>2015-01-21T12:06:26Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: News&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Bricks==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks is a deliberately vulnerable web application built on PHP &amp;amp; MySQL focuses on variations of commonly seen application security vulnerabilities &amp;amp; exploits, which can be exploited using tools like Mantra and ZAP.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
* OWASP Bricks is a deliberately vulnerable web application built on PHP and MySQL. &lt;br /&gt;
* The project focuses on variations of commonly seen application security vulnerabilities and exploits. &lt;br /&gt;
* Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP). &lt;br /&gt;
* The mission is to 'break the bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Bricks is a web application security learning platform built on PHP and MySQL. The project focuses on variations of commonly seen application security issues. Each 'Brick' has some sort of security issue which can be leveraged manually or using automated software tools. The mission is to 'Break the Bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
Bricks is a completely free and open source project brought to you by OWASP. The complete documentation and instruction videos can also be accessed or downloaded for free. Bricks are classified into three different sections: login pages, file upload pages and content pages.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Bricks is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Bricks? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks  provides:&lt;br /&gt;
&lt;br /&gt;
* A platform for learning web application security.&lt;br /&gt;
* A test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASP_Bricks_Presentation_Slides.pptx|OWASP Bricks Presentation Slides]]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan| Abhi_M_Balakrishnan]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Mantra - Security Framework]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/owaspbricks&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* [http://sechow.com/bricks/download.html Download Bricks]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
Bricks is brought to you by OWASP, a free and open software security community focusing on improving the security of software. Our mission is to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks.&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks project is led by Abhi M Balakrishnan, an information security enthusiast. He is the founding member of OWASP Mantra, Secpedia and Bbroy.&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
# Demonstrate maximum variations of most common vulnerabilities&lt;br /&gt;
# Help people to learn the need of secure codding practices and SSDLC&lt;br /&gt;
# Attract people to design more bricks&lt;br /&gt;
# Become a test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
# Help people learn the manual method of testing the applications&lt;br /&gt;
# Demonstrate the possibilities of various security tools and techniques&lt;br /&gt;
# Become a platform to teach web application security in a class room/lab environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Bricks is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Spread the word - Facebook, Twitter, Google+ or any other communication platform.&lt;br /&gt;
* Write about OWASP Bricks on your web site/ book.&lt;br /&gt;
* Mention it in your resume - It helps you, it helps the company and it helps us and thus everybody wins.&lt;br /&gt;
* Make tutorials/videos of Bricks in languages you know of.&lt;br /&gt;
* Include it in your training materials, talks, discussions etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
[http://news.softpedia.com/news/Security-App-of-the-Week-OWASP-Bricks-375093.shtml OWASP Bricks was the Softpedia Security App of the week]&lt;br /&gt;
[http://is-ra.org/c0c0n/2014/ OWASP Bricks was supporting partner of c0c0n 2014]  &lt;br /&gt;
[https://www.youtube.com/watch?v=pPg8bA7ps3U OWASP Bricks was presented at OWASP/Null combined meet in Delhi November 2014]&lt;br /&gt;
[https://www.facebook.com/OwaspBricks/posts/646717422114772 Adwiteeya Agrawal presented OWASP Bricks at Indira Gandhi Delhi Technical University for Women - IGDTU]&lt;br /&gt;
[http://dl.packetstormsecurity.net/papers/general/poor_mans_security_lab.pdf The Poor Man's Security Lab guide recommends OWASP Bricks]&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Bricks}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Bricks]]&lt;br /&gt;
[[Category:OWASP Download|Bricks]]&lt;br /&gt;
[[Category:OWASP Tool|Bricks]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool|Bricks]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=188331</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=188331"/>
				<updated>2015-01-21T11:29:23Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: Null &amp;amp; OWASP Delhi Combined Meeting November 2014&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/getmantra&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework#News More News and Events]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://hack-tools.blackploit.com/2014/06/owasp-mantra-security-toolkit-browser.html  Article about OWASP Mantra on KitPloit]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://osarena.net/logismiko/applications/mantra-enas-ekpliktikos-browser-asfalias.html Article about OWASP Mantra on OS Arena]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://habrahabr.ru/post/125317/ OWASP Mantra was in the list of free and popular security tools on habrahabr.ru]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.mundodoshackers.com.br/mantra-navegador-hacker-pentests Article about OWASP Mantra on Mundodoshackers]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://korben.info/owasp-mantra.html Korben featured Mantra in 2011]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://phpsp.org.br/index.php/mais-seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on PHP Developers Group of Sao Paulo]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://imasters.com.br/infra/seguranca/seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on iMasters]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://infosecplatform.com/2013/08/04/owasp-mantra-fully-loaded-browser-with-pentest-bookmarks/ Article about Hackery and Galley by Niraj]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://devopsweekly.com/2014/05/25/177/ OWASP Mantra was mentioned in 177th edition of Devops Weekly]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.thegeeksclub.com/16671-hacking-penetration-testing-security-software-linux/ OWASP Mantra was on of the Best Hacking, Penetration Testing, Security software for Linux listed by thegeeksclub]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.darknet.org.uk/2014/06/owasp-mantra-browser-based-security-framework/ Article about OWASP Mantra Janus on Darknet]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://efytimes.com/e1/fullnews.asp?edid=136674 OWASP Mantra was mentioned as a handy tool for SysAdmins at EFYTimes]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.gfi.com/blog/18-free-security-tools-for-sysadmins/ OWASP Mantra was one among 18 Free Security Tools for SysAdmins by Andrew Zammit Tabona on GFI blog]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://cypherpunk.fr/distributions-gnu-linux-orientees-securite/ OWASP Mantra was mentioned in Cyberpunk.fr]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.pensandoenlaweb.com/2012/07/auditorias-web-con-mantra-de-owasp.html Article about OWASP Mantra on pensandoenlaweb.com]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://intellavis.com/blog/?p=325 OWASP Mantra was mentioned in Increased Visibility article titled 'Detecting Cross Site Scripting Vulnerabilities']&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/18632/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on OneFileCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/24507/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on chillyCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://is-ra.org/c0c0n/ OWASP Mantra is a supporting partner of c0c0n 2014]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://thepowerofapostrophe.blogspot.com/ The Power of Apostrophe blog created as part of [[OWASP_Security_Blitz]]]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/Null_%26_OWASP_Delhi_Combined_Meeting_November_2014 LAMP Security CTF 6 walk through using OWASP Mantra by Abhi M Balakrishnan on Null &amp;amp; OWASP Delhi Combined Meeting November 2014]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
[[Image:OWASP Mantra cross platform.jpg|600px|OWASP Mantra cross platform.jpg]]&amp;lt;br/&amp;gt;&lt;br /&gt;
'''OWASP Mantra Security Toolkit - Beta 0.92 code named Janus'''&lt;br /&gt;
{|&lt;br /&gt;
|''Linux 32 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2032.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2032.tar.gz Mirror 2] [http://burnbit.com/download/233734/OWASP_Mantra_Janus_Linux_32_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Linux 64 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2064.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2064.tar.gz Mirror 2] [http://burnbit.com/download/233735/OWASP_Mantra_Janus_Linux_64_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Windows: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.exe/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.exe Mirror 2] [http://burnbit.com/download/233648/OWASP_Mantra_Janus_exe Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Macintosh: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.mpkg.zip/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 2] [http://burnbit.com/download/233736/OWASP_Mantra_Janus_mpkg_zip Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Source: '' &lt;br /&gt;
|[https://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20source.7z&amp;amp;can=1&amp;amp;q= Mirror 1]&lt;br /&gt;
|}&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Old Versions==&lt;br /&gt;
Old versions of OWASP Mantra and their source code can be obtained from:&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://code.google.com/p/getmantra/downloads/list?can=1&amp;amp;q=&amp;amp;colspec=Filename+Summary+Uploaded+ReleaseDate+Size+DownloadCount OWASP Mantra download page on Google Code] or&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/ Sourceforge page of OWASP Mantra]&lt;br /&gt;
&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179028</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179028"/>
				<updated>2014-07-19T05:06:08Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/getmantra&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework#News More News and Events]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://hack-tools.blackploit.com/2014/06/owasp-mantra-security-toolkit-browser.html  Article about OWASP Mantra on KitPloit]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://osarena.net/logismiko/applications/mantra-enas-ekpliktikos-browser-asfalias.html Article about OWASP Mantra on OS Arena]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://habrahabr.ru/post/125317/ OWASP Mantra was in the list of free and popular security tools on habrahabr.ru]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.mundodoshackers.com.br/mantra-navegador-hacker-pentests Article about OWASP Mantra on Mundodoshackers]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://korben.info/owasp-mantra.html Korben featured Mantra in 2011]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://phpsp.org.br/index.php/mais-seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on PHP Developers Group of Sao Paulo]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://imasters.com.br/infra/seguranca/seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on iMasters]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://infosecplatform.com/2013/08/04/owasp-mantra-fully-loaded-browser-with-pentest-bookmarks/ Article about Hackery and Galley by Niraj]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://devopsweekly.com/2014/05/25/177/ OWASP Mantra was mentioned in 177th edition of Devops Weekly]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.thegeeksclub.com/16671-hacking-penetration-testing-security-software-linux/ OWASP Mantra was on of the Best Hacking, Penetration Testing, Security software for Linux listed by thegeeksclub]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.darknet.org.uk/2014/06/owasp-mantra-browser-based-security-framework/ Article about OWASP Mantra Janus on Darknet]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://efytimes.com/e1/fullnews.asp?edid=136674 OWASP Mantra was mentioned as a handy tool for SysAdmins at EFYTimes]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.gfi.com/blog/18-free-security-tools-for-sysadmins/ OWASP Mantra was one among 18 Free Security Tools for SysAdmins by Andrew Zammit Tabona on GFI blog]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://cypherpunk.fr/distributions-gnu-linux-orientees-securite/ OWASP Mantra was mentioned in Cyberpunk.fr]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.pensandoenlaweb.com/2012/07/auditorias-web-con-mantra-de-owasp.html Article about OWASP Mantra on pensandoenlaweb.com]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://intellavis.com/blog/?p=325 OWASP Mantra was mentioned in Increased Visibility article titled 'Detecting Cross Site Scripting Vulnerabilities']&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/18632/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on OneFileCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/24507/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on chillyCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://is-ra.org/c0c0n/ OWASP Mantra is a supporting partner of c0c0n 2014]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://thepowerofapostrophe.blogspot.com/ The Power of Apostrophe blog created as part of [[OWASP_Security_Blitz]]]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
[[Image:OWASP Mantra cross platform.jpg|600px|OWASP Mantra cross platform.jpg]]&amp;lt;br/&amp;gt;&lt;br /&gt;
'''OWASP Mantra Security Toolkit - Beta 0.92 code named Janus'''&lt;br /&gt;
{|&lt;br /&gt;
|''Linux 32 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2032.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2032.tar.gz Mirror 2] [http://burnbit.com/download/233734/OWASP_Mantra_Janus_Linux_32_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Linux 64 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2064.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2064.tar.gz Mirror 2] [http://burnbit.com/download/233735/OWASP_Mantra_Janus_Linux_64_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Windows: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.exe/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.exe Mirror 2] [http://burnbit.com/download/233648/OWASP_Mantra_Janus_exe Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Macintosh: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.mpkg.zip/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 2] [http://burnbit.com/download/233736/OWASP_Mantra_Janus_mpkg_zip Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Source: '' &lt;br /&gt;
|[https://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20source.7z&amp;amp;can=1&amp;amp;q= Mirror 1]&lt;br /&gt;
|}&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Old Versions==&lt;br /&gt;
Old versions of OWASP Mantra and their source code can be obtained from:&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://code.google.com/p/getmantra/downloads/list?can=1&amp;amp;q=&amp;amp;colspec=Filename+Summary+Uploaded+ReleaseDate+Size+DownloadCount OWASP Mantra download page on Google Code] or&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/ Sourceforge page of OWASP Mantra]&lt;br /&gt;
&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179027</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179027"/>
				<updated>2014-07-19T05:05:15Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/getmantra&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework#News More News and Events]&lt;br /&gt;
[http://thepowerofapostrophe.blogspot.com/ The Power of Apostrophe blog created as part of [[OWASP_Security_Blitz]]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://hack-tools.blackploit.com/2014/06/owasp-mantra-security-toolkit-browser.html  Article about OWASP Mantra on KitPloit]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://osarena.net/logismiko/applications/mantra-enas-ekpliktikos-browser-asfalias.html Article about OWASP Mantra on OS Arena]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://habrahabr.ru/post/125317/ OWASP Mantra was in the list of free and popular security tools on habrahabr.ru]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.mundodoshackers.com.br/mantra-navegador-hacker-pentests Article about OWASP Mantra on Mundodoshackers]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://korben.info/owasp-mantra.html Korben featured Mantra in 2011]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://phpsp.org.br/index.php/mais-seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on PHP Developers Group of Sao Paulo]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://imasters.com.br/infra/seguranca/seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on iMasters]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://infosecplatform.com/2013/08/04/owasp-mantra-fully-loaded-browser-with-pentest-bookmarks/ Article about Hackery and Galley by Niraj]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://devopsweekly.com/2014/05/25/177/ OWASP Mantra was mentioned in 177th edition of Devops Weekly]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.thegeeksclub.com/16671-hacking-penetration-testing-security-software-linux/ OWASP Mantra was on of the Best Hacking, Penetration Testing, Security software for Linux listed by thegeeksclub]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.darknet.org.uk/2014/06/owasp-mantra-browser-based-security-framework/ Article about OWASP Mantra Janus on Darknet]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://efytimes.com/e1/fullnews.asp?edid=136674 OWASP Mantra was mentioned as a handy tool for SysAdmins at EFYTimes]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.gfi.com/blog/18-free-security-tools-for-sysadmins/ OWASP Mantra was one among 18 Free Security Tools for SysAdmins by Andrew Zammit Tabona on GFI blog]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://cypherpunk.fr/distributions-gnu-linux-orientees-securite/ OWASP Mantra was mentioned in Cyberpunk.fr]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.pensandoenlaweb.com/2012/07/auditorias-web-con-mantra-de-owasp.html Article about OWASP Mantra on pensandoenlaweb.com]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://intellavis.com/blog/?p=325 OWASP Mantra was mentioned in Increased Visibility article titled 'Detecting Cross Site Scripting Vulnerabilities']&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/18632/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on OneFileCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/24507/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on chillyCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://is-ra.org/c0c0n/ OWASP Mantra is a supporting partner of c0c0n 2014]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
[[Image:OWASP Mantra cross platform.jpg|600px|OWASP Mantra cross platform.jpg]]&amp;lt;br/&amp;gt;&lt;br /&gt;
'''OWASP Mantra Security Toolkit - Beta 0.92 code named Janus'''&lt;br /&gt;
{|&lt;br /&gt;
|''Linux 32 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2032.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2032.tar.gz Mirror 2] [http://burnbit.com/download/233734/OWASP_Mantra_Janus_Linux_32_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Linux 64 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2064.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2064.tar.gz Mirror 2] [http://burnbit.com/download/233735/OWASP_Mantra_Janus_Linux_64_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Windows: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.exe/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.exe Mirror 2] [http://burnbit.com/download/233648/OWASP_Mantra_Janus_exe Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Macintosh: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.mpkg.zip/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 2] [http://burnbit.com/download/233736/OWASP_Mantra_Janus_mpkg_zip Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Source: '' &lt;br /&gt;
|[https://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20source.7z&amp;amp;can=1&amp;amp;q= Mirror 1]&lt;br /&gt;
|}&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Old Versions==&lt;br /&gt;
Old versions of OWASP Mantra and their source code can be obtained from:&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://code.google.com/p/getmantra/downloads/list?can=1&amp;amp;q=&amp;amp;colspec=Filename+Summary+Uploaded+ReleaseDate+Size+DownloadCount OWASP Mantra download page on Google Code] or&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/ Sourceforge page of OWASP Mantra]&lt;br /&gt;
&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179026</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179026"/>
				<updated>2014-07-19T04:10:35Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/getmantra&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework#News More News and Events]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://hack-tools.blackploit.com/2014/06/owasp-mantra-security-toolkit-browser.html  Article about OWASP Mantra on KitPloit]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://osarena.net/logismiko/applications/mantra-enas-ekpliktikos-browser-asfalias.html Article about OWASP Mantra on OS Arena]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://habrahabr.ru/post/125317/ OWASP Mantra was in the list of free and popular security tools on habrahabr.ru]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.mundodoshackers.com.br/mantra-navegador-hacker-pentests Article about OWASP Mantra on Mundodoshackers]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://korben.info/owasp-mantra.html Korben featured Mantra in 2011]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://phpsp.org.br/index.php/mais-seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on PHP Developers Group of Sao Paulo]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://imasters.com.br/infra/seguranca/seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on iMasters]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://infosecplatform.com/2013/08/04/owasp-mantra-fully-loaded-browser-with-pentest-bookmarks/ Article about Hackery and Galley by Niraj]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://devopsweekly.com/2014/05/25/177/ OWASP Mantra was mentioned in 177th edition of Devops Weekly]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.thegeeksclub.com/16671-hacking-penetration-testing-security-software-linux/ OWASP Mantra was on of the Best Hacking, Penetration Testing, Security software for Linux listed by thegeeksclub]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.darknet.org.uk/2014/06/owasp-mantra-browser-based-security-framework/ Article about OWASP Mantra Janus on Darknet]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://efytimes.com/e1/fullnews.asp?edid=136674 OWASP Mantra was mentioned as a handy tool for SysAdmins at EFYTimes]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.gfi.com/blog/18-free-security-tools-for-sysadmins/ OWASP Mantra was one among 18 Free Security Tools for SysAdmins by Andrew Zammit Tabona on GFI blog]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://cypherpunk.fr/distributions-gnu-linux-orientees-securite/ OWASP Mantra was mentioned in Cyberpunk.fr]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.pensandoenlaweb.com/2012/07/auditorias-web-con-mantra-de-owasp.html Article about OWASP Mantra on pensandoenlaweb.com]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://intellavis.com/blog/?p=325 OWASP Mantra was mentioned in Increased Visibility article titled 'Detecting Cross Site Scripting Vulnerabilities']&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/18632/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on OneFileCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/24507/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on chillyCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://is-ra.org/c0c0n/ OWASP Mantra is a supporting partner of c0c0n 2014]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
[[Image:OWASP Mantra cross platform.jpg|600px|OWASP Mantra cross platform.jpg]]&amp;lt;br/&amp;gt;&lt;br /&gt;
'''OWASP Mantra Security Toolkit - Beta 0.92 code named Janus'''&lt;br /&gt;
{|&lt;br /&gt;
|''Linux 32 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2032.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2032.tar.gz Mirror 2] [http://burnbit.com/download/233734/OWASP_Mantra_Janus_Linux_32_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Linux 64 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2064.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2064.tar.gz Mirror 2] [http://burnbit.com/download/233735/OWASP_Mantra_Janus_Linux_64_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Windows: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.exe/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.exe Mirror 2] [http://burnbit.com/download/233648/OWASP_Mantra_Janus_exe Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Macintosh: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.mpkg.zip/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 2] [http://burnbit.com/download/233736/OWASP_Mantra_Janus_mpkg_zip Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Source: '' &lt;br /&gt;
|[https://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20source.7z&amp;amp;can=1&amp;amp;q= Mirror 1]&lt;br /&gt;
|}&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Old Versions==&lt;br /&gt;
Old versions of OWASP Mantra and their source code can be obtained from:&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://code.google.com/p/getmantra/downloads/list?can=1&amp;amp;q=&amp;amp;colspec=Filename+Summary+Uploaded+ReleaseDate+Size+DownloadCount OWASP Mantra download page on Google Code] or&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/ Sourceforge page of OWASP Mantra]&lt;br /&gt;
&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179025</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179025"/>
				<updated>2014-07-19T04:09:31Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/getmantra&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework#News More News and Events]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://hack-tools.blackploit.com/2014/06/owasp-mantra-security-toolkit-browser.html  Article about OWASP Mantra on KitPloit]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://osarena.net/logismiko/applications/mantra-enas-ekpliktikos-browser-asfalias.html Article about OWASP Mantra on OS Arena]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://habrahabr.ru/post/125317/ OWASP Mantra was in the list of free and popular security tools on habrahabr.ru]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.mundodoshackers.com.br/mantra-navegador-hacker-pentests Article about OWASP Mantra on Mundodoshackers]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://korben.info/owasp-mantra.html Korben featured Mantra in 2011]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://phpsp.org.br/index.php/mais-seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on PHP Developers Group of Sao Paulo]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://imasters.com.br/infra/seguranca/seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on iMasters]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://infosecplatform.com/2013/08/04/owasp-mantra-fully-loaded-browser-with-pentest-bookmarks/ Article about Hackery and Galley by Niraj]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://devopsweekly.com/2014/05/25/177/ OWASP Mantra was mentioned in 177th edition of Devops Weekly]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.thegeeksclub.com/16671-hacking-penetration-testing-security-software-linux/ OWASP Mantra was on of the Best Hacking, Penetration Testing, Security software for Linux listed by thegeeksclub]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.darknet.org.uk/2014/06/owasp-mantra-browser-based-security-framework/ Article about OWASP Mantra Janus on Darknet]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://efytimes.com/e1/fullnews.asp?edid=136674 OWASP Mantra was mentioned as a handy tool for SysAdmins at EFYTimes]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.gfi.com/blog/18-free-security-tools-for-sysadmins/ OWASP Mantra was one among 18 Free Security Tools for SysAdmins by Andrew Zammit Tabona on GFI blog]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://cypherpunk.fr/distributions-gnu-linux-orientees-securite/ OWASP Mantra was mentioned in Cyberpunk.fr]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.pensandoenlaweb.com/2012/07/auditorias-web-con-mantra-de-owasp.html Article about OWASP Mantra on pensandoenlaweb.com]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://intellavis.com/blog/?p=325 OWASP Mantra was mentioned in Increased Visibility article titled 'Detecting Cross Site Scripting Vulnerabilities']&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/18632/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on OneFileCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/24507/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on chillyCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://is-ra.org/c0c0n/ OWASP Mantra is a supporting partner of c0c0n 2014]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
[[Image:OWASP Mantra cross platform.jpg|600px|OWASP Mantra cross platform.jpg]]&amp;lt;br/&amp;gt;&lt;br /&gt;
'''OWASP Mantra Security Toolkit - Beta 0.92 code named Janus'''&lt;br /&gt;
{|&lt;br /&gt;
|''Linux 32 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2032.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2032.tar.gz Mirror 2] [http://burnbit.com/download/233734/OWASP_Mantra_Janus_Linux_32_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Linux 64 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2064.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2064.tar.gz Mirror 2] [http://burnbit.com/download/233735/OWASP_Mantra_Janus_Linux_64_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Windows: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.exe/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.exe Mirror 2] [http://burnbit.com/download/233648/OWASP_Mantra_Janus_exe Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Macintosh: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.mpkg.zip/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 2] [http://burnbit.com/download/233736/OWASP_Mantra_Janus_mpkg_zip Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Source: '' &lt;br /&gt;
|[https://getmantra.googlecode.com/files/OWASP%20Mantra%20Janus%20source.7z Mirror 1]&lt;br /&gt;
|}&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Old Versions==&lt;br /&gt;
Old versions of OWASP Mantra and their source code can be obtained from:&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://code.google.com/p/getmantra/downloads/list?can=1&amp;amp;q=&amp;amp;colspec=Filename+Summary+Uploaded+ReleaseDate+Size+DownloadCount OWASP Mantra download page on Google Code] or&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/ Sourceforge page of OWASP Mantra]&lt;br /&gt;
&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179024</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179024"/>
				<updated>2014-07-19T03:29:54Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/getmantra&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework#News More News and Events]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://hack-tools.blackploit.com/2014/06/owasp-mantra-security-toolkit-browser.html  Article about OWASP Mantra on KitPloit]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://osarena.net/logismiko/applications/mantra-enas-ekpliktikos-browser-asfalias.html Article about OWASP Mantra on OS Arena]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://habrahabr.ru/post/125317/ OWASP Mantra was in the list of free and popular security tools on habrahabr.ru]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.mundodoshackers.com.br/mantra-navegador-hacker-pentests Article about OWASP Mantra on Mundodoshackers]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://korben.info/owasp-mantra.html Korben featured Mantra in 2011]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://phpsp.org.br/index.php/mais-seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on PHP Developers Group of Sao Paulo]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://imasters.com.br/infra/seguranca/seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on iMasters]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://infosecplatform.com/2013/08/04/owasp-mantra-fully-loaded-browser-with-pentest-bookmarks/ Article about Hackery and Galley by Niraj]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://devopsweekly.com/2014/05/25/177/ OWASP Mantra was mentioned in 177th edition of Devops Weekly]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.thegeeksclub.com/16671-hacking-penetration-testing-security-software-linux/ OWASP Mantra was on of the Best Hacking, Penetration Testing, Security software for Linux listed by thegeeksclub]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.darknet.org.uk/2014/06/owasp-mantra-browser-based-security-framework/ Article about OWASP Mantra Janus on Darknet]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://efytimes.com/e1/fullnews.asp?edid=136674 OWASP Mantra was mentioned as a handy tool for SysAdmins at EFYTimes]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.gfi.com/blog/18-free-security-tools-for-sysadmins/ OWASP Mantra was one among 18 Free Security Tools for SysAdmins by Andrew Zammit Tabona on GFI blog]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://cypherpunk.fr/distributions-gnu-linux-orientees-securite/ OWASP Mantra was mentioned in Cyberpunk.fr]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.pensandoenlaweb.com/2012/07/auditorias-web-con-mantra-de-owasp.html Article about OWASP Mantra on pensandoenlaweb.com]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://intellavis.com/blog/?p=325 OWASP Mantra was mentioned in Increased Visibility article titled 'Detecting Cross Site Scripting Vulnerabilities']&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/18632/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on OneFileCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/24507/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on chillyCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://is-ra.org/c0c0n/ OWASP Mantra is a supporting partner of c0c0n 2014]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
[[Image:OWASP Mantra cross platform.jpg|600px|OWASP Mantra cross platform.jpg]]&amp;lt;br/&amp;gt;&lt;br /&gt;
'''OWASP Mantra Security Toolkit - Beta 0.92 code named Janus'''&lt;br /&gt;
{|&lt;br /&gt;
|''Linux 32 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2032.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2032.tar.gz Mirror 2] [http://burnbit.com/download/233734/OWASP_Mantra_Janus_Linux_32_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Linux 64 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2064.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2064.tar.gz Mirror 2] [http://burnbit.com/download/233735/OWASP_Mantra_Janus_Linux_64_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Windows: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.exe/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.exe Mirror 2] [http://burnbit.com/download/233648/OWASP_Mantra_Janus_exe Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Macintosh: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.mpkg.zip/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 2] [http://burnbit.com/download/233736/OWASP_Mantra_Janus_mpkg_zip Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Source: '' &lt;br /&gt;
|[http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 1]&lt;br /&gt;
|}&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Old Versions==&lt;br /&gt;
Old versions of OWASP Mantra and their source code can be obtained from:&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://code.google.com/p/getmantra/downloads/list?can=1&amp;amp;q=&amp;amp;colspec=Filename+Summary+Uploaded+ReleaseDate+Size+DownloadCount OWASP Mantra download page on Google Code] or&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/ Sourceforge page of OWASP Mantra]&lt;br /&gt;
&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179023</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179023"/>
				<updated>2014-07-19T03:27:52Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/getmantra&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework#News More News and Events]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://hack-tools.blackploit.com/2014/06/owasp-mantra-security-toolkit-browser.html  Article about OWASP Mantra on KitPloit]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://osarena.net/logismiko/applications/mantra-enas-ekpliktikos-browser-asfalias.html Article about OWASP Mantra on OS Arena]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://habrahabr.ru/post/125317/ OWASP Mantra was in the list of free and popular security tools on habrahabr.ru]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.mundodoshackers.com.br/mantra-navegador-hacker-pentests Article about OWASP Mantra on Mundodoshackers]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://korben.info/owasp-mantra.html Korben featured Mantra in 2011]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://phpsp.org.br/index.php/mais-seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on PHP Developers Group of Sao Paulo]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://imasters.com.br/infra/seguranca/seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on iMasters]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://infosecplatform.com/2013/08/04/owasp-mantra-fully-loaded-browser-with-pentest-bookmarks/ Article about Hackery and Galley by Niraj]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://devopsweekly.com/2014/05/25/177/ OWASP Mantra was mentioned in 177th edition of Devops Weekly]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.thegeeksclub.com/16671-hacking-penetration-testing-security-software-linux/ OWASP Mantra was on of the Best Hacking, Penetration Testing, Security software for Linux listed by thegeeksclub]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.darknet.org.uk/2014/06/owasp-mantra-browser-based-security-framework/ Article about OWASP Mantra Janus on Darknet]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://efytimes.com/e1/fullnews.asp?edid=136674 OWASP Mantra was mentioned as a handy tool for SysAdmins at EFYTimes]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.gfi.com/blog/18-free-security-tools-for-sysadmins/ OWASP Mantra was one among 18 Free Security Tools for SysAdmins by Andrew Zammit Tabona on GFI blog]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://cypherpunk.fr/distributions-gnu-linux-orientees-securite/ OWASP Mantra was mentioned in Cyberpunk.fr]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.pensandoenlaweb.com/2012/07/auditorias-web-con-mantra-de-owasp.html Article about OWASP Mantra on pensandoenlaweb.com]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://intellavis.com/blog/?p=325 OWASP Mantra was mentioned in Increased Visibility article titled 'Detecting Cross Site Scripting Vulnerabilities']&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/18632/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on OneFileCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/24507/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on chillyCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
[[Image:OWASP Mantra cross platform.jpg|600px|OWASP Mantra cross platform.jpg]]&amp;lt;br/&amp;gt;&lt;br /&gt;
'''OWASP Mantra Security Toolkit - Beta 0.92 code named Janus'''&lt;br /&gt;
{|&lt;br /&gt;
|''Linux 32 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2032.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2032.tar.gz Mirror 2] [http://burnbit.com/download/233734/OWASP_Mantra_Janus_Linux_32_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Linux 64 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2064.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2064.tar.gz Mirror 2] [http://burnbit.com/download/233735/OWASP_Mantra_Janus_Linux_64_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Windows: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.exe/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.exe Mirror 2] [http://burnbit.com/download/233648/OWASP_Mantra_Janus_exe Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Macintosh: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.mpkg.zip/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 2] [http://burnbit.com/download/233736/OWASP_Mantra_Janus_mpkg_zip Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Source: '' &lt;br /&gt;
|[http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 1]&lt;br /&gt;
|}&amp;lt;br/&amp;gt;&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Old Versions==&lt;br /&gt;
Old versions of OWASP Mantra and their source code can be obtained from:&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://code.google.com/p/getmantra/downloads/list?can=1&amp;amp;q=&amp;amp;colspec=Filename+Summary+Uploaded+ReleaseDate+Size+DownloadCount OWASP Mantra download page on Google Code] or&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/ Sourceforge page of OWASP Mantra]&lt;br /&gt;
&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179022</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179022"/>
				<updated>2014-07-19T03:27:16Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/getmantra&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework#News More News and Events]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://hack-tools.blackploit.com/2014/06/owasp-mantra-security-toolkit-browser.html  Article about OWASP Mantra on KitPloit]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://osarena.net/logismiko/applications/mantra-enas-ekpliktikos-browser-asfalias.html Article about OWASP Mantra on OS Arena]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://habrahabr.ru/post/125317/ OWASP Mantra was in the list of free and popular security tools on habrahabr.ru]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.mundodoshackers.com.br/mantra-navegador-hacker-pentests Article about OWASP Mantra on Mundodoshackers]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://korben.info/owasp-mantra.html Korben featured Mantra in 2011]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://phpsp.org.br/index.php/mais-seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on PHP Developers Group of Sao Paulo]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://imasters.com.br/infra/seguranca/seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on iMasters]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://infosecplatform.com/2013/08/04/owasp-mantra-fully-loaded-browser-with-pentest-bookmarks/ Article about Hackery and Galley by Niraj]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://devopsweekly.com/2014/05/25/177/ OWASP Mantra was mentioned in 177th edition of Devops Weekly]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.thegeeksclub.com/16671-hacking-penetration-testing-security-software-linux/ OWASP Mantra was on of the Best Hacking, Penetration Testing, Security software for Linux listed by thegeeksclub]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.darknet.org.uk/2014/06/owasp-mantra-browser-based-security-framework/ Article about OWASP Mantra Janus on Darknet]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://efytimes.com/e1/fullnews.asp?edid=136674 OWASP Mantra was mentioned as a handy tool for SysAdmins at EFYTimes]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.gfi.com/blog/18-free-security-tools-for-sysadmins/ OWASP Mantra was one among 18 Free Security Tools for SysAdmins by Andrew Zammit Tabona on GFI blog]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://cypherpunk.fr/distributions-gnu-linux-orientees-securite/ OWASP Mantra was mentioned in Cyberpunk.fr]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.pensandoenlaweb.com/2012/07/auditorias-web-con-mantra-de-owasp.html Article about OWASP Mantra on pensandoenlaweb.com]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://intellavis.com/blog/?p=325 OWASP Mantra was mentioned in Increased Visibility article titled 'Detecting Cross Site Scripting Vulnerabilities']&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/18632/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on OneFileCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/24507/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on chillyCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
[[Image:OWASP Mantra cross platform.jpg|600px|OWASP Mantra cross platform.jpg]]&amp;lt;br/&amp;gt;&lt;br /&gt;
'''OWASP Mantra Security Toolkit - Beta 0.92 code named Janus'''&lt;br /&gt;
{|&lt;br /&gt;
|''Linux 32 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2032.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2032.tar.gz Mirror 2] [http://burnbit.com/download/233734/OWASP_Mantra_Janus_Linux_32_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Linux 64 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2064.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2064.tar.gz Mirror 2] [http://burnbit.com/download/233735/OWASP_Mantra_Janus_Linux_64_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Windows: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.exe/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.exe Mirror 2] [http://burnbit.com/download/233648/OWASP_Mantra_Janus_exe Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Macintosh: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.mpkg.zip/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 2] [http://burnbit.com/download/233736/OWASP_Mantra_Janus_mpkg_zip Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Source: '' &lt;br /&gt;
|[http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 1]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Old Versions==&lt;br /&gt;
Old versions of OWASP Mantra and their source code can be obtained from:&lt;br /&gt;
[https://code.google.com/p/getmantra/downloads/list?can=1&amp;amp;q=&amp;amp;colspec=Filename+Summary+Uploaded+ReleaseDate+Size+DownloadCount OWASP Mantra download page on Google Code] or&lt;br /&gt;
[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/ Sourceforge page of OWASP Mantra]&lt;br /&gt;
&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179021</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179021"/>
				<updated>2014-07-19T03:23:41Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/getmantra&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework#News More News and Events]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://hack-tools.blackploit.com/2014/06/owasp-mantra-security-toolkit-browser.html  Article about OWASP Mantra on KitPloit]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://osarena.net/logismiko/applications/mantra-enas-ekpliktikos-browser-asfalias.html Article about OWASP Mantra on OS Arena]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://habrahabr.ru/post/125317/ OWASP Mantra was in the list of free and popular security tools on habrahabr.ru]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.mundodoshackers.com.br/mantra-navegador-hacker-pentests Article about OWASP Mantra on Mundodoshackers]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://korben.info/owasp-mantra.html Korben featured Mantra in 2011]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://phpsp.org.br/index.php/mais-seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on PHP Developers Group of Sao Paulo]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://imasters.com.br/infra/seguranca/seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on iMasters]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://infosecplatform.com/2013/08/04/owasp-mantra-fully-loaded-browser-with-pentest-bookmarks/ Article about Hackery and Galley by Niraj]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://devopsweekly.com/2014/05/25/177/ OWASP Mantra was mentioned in 177th edition of Devops Weekly]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.thegeeksclub.com/16671-hacking-penetration-testing-security-software-linux/ OWASP Mantra was on of the Best Hacking, Penetration Testing, Security software for Linux listed by thegeeksclub]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.darknet.org.uk/2014/06/owasp-mantra-browser-based-security-framework/ Article about OWASP Mantra Janus on Darknet]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://efytimes.com/e1/fullnews.asp?edid=136674 OWASP Mantra was mentioned as a handy tool for SysAdmins at EFYTimes]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.gfi.com/blog/18-free-security-tools-for-sysadmins/ OWASP Mantra was one among 18 Free Security Tools for SysAdmins by Andrew Zammit Tabona on GFI blog]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://cypherpunk.fr/distributions-gnu-linux-orientees-securite/ OWASP Mantra was mentioned in Cyberpunk.fr]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.pensandoenlaweb.com/2012/07/auditorias-web-con-mantra-de-owasp.html Article about OWASP Mantra on pensandoenlaweb.com]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://intellavis.com/blog/?p=325 OWASP Mantra was mentioned in Increased Visibility article titled 'Detecting Cross Site Scripting Vulnerabilities']&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/18632/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on OneFileCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.exploit-db.com/exploits/24507/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on chillyCMS]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
[[Image:OWASP Mantra cross platform.jpg|600px|OWASP Mantra cross platform.jpg]]&amp;lt;br/&amp;gt;&lt;br /&gt;
'''OWASP Mantra Security Toolkit - Beta 0.92 code named Janus'''&lt;br /&gt;
{|&lt;br /&gt;
|''Linux 32 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2032.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2032.tar.gz Mirror 2] [http://burnbit.com/download/233734/OWASP_Mantra_Janus_Linux_32_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Linux 64 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2064.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2064.tar.gz Mirror 2] [http://burnbit.com/download/233735/OWASP_Mantra_Janus_Linux_64_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Windows: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.exe/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.exe Mirror 2] [http://burnbit.com/download/233648/OWASP_Mantra_Janus_exe Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Macintosh: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.mpkg.zip/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 2] [http://burnbit.com/download/233736/OWASP_Mantra_Janus_mpkg_zip Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Source: '' &lt;br /&gt;
|[http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 1]&lt;br /&gt;
|}&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179020</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179020"/>
				<updated>2014-07-19T03:22:16Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/getmantra&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework#News More News and Events]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&lt;br /&gt;
[http://hack-tools.blackploit.com/2014/06/owasp-mantra-security-toolkit-browser.html  Article about OWASP Mantra on KitPloit]&lt;br /&gt;
[http://osarena.net/logismiko/applications/mantra-enas-ekpliktikos-browser-asfalias.html Article about OWASP Mantra on OS Arena]&lt;br /&gt;
[http://habrahabr.ru/post/125317/ OWASP Mantra was in the list of free and popular security tools on habrahabr.ru]&lt;br /&gt;
[http://www.mundodoshackers.com.br/mantra-navegador-hacker-pentests Article about OWASP Mantra on Mundodoshackers]&lt;br /&gt;
[http://korben.info/owasp-mantra.html Korben featured Mantra in 2011]&lt;br /&gt;
[http://phpsp.org.br/index.php/mais-seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on PHP Developers Group of Sao Paulo]&lt;br /&gt;
[http://imasters.com.br/infra/seguranca/seguranca-em-aplicacoes-web-com-php/ OWASP Mantra was mentioned by Alexsandro Souza on iMasters]&lt;br /&gt;
[http://infosecplatform.com/2013/08/04/owasp-mantra-fully-loaded-browser-with-pentest-bookmarks/ Article about Hackery and Galley by Niraj]&lt;br /&gt;
[http://devopsweekly.com/2014/05/25/177/ OWASP Mantra was mentioned in 177th edition of Devops Weekly]&lt;br /&gt;
[http://www.thegeeksclub.com/16671-hacking-penetration-testing-security-software-linux/ OWASP Mantra was on of the Best Hacking, Penetration Testing, Security software for Linux listed by thegeeksclub]&lt;br /&gt;
[http://www.darknet.org.uk/2014/06/owasp-mantra-browser-based-security-framework/ Article about OWASP Mantra Janus on Darknet]&lt;br /&gt;
[http://efytimes.com/e1/fullnews.asp?edid=136674 OWASP Mantra was mentioned as a handy tool for SysAdmins at EFYTimes]&lt;br /&gt;
[http://www.gfi.com/blog/18-free-security-tools-for-sysadmins/ OWASP Mantra was one among 18 Free Security Tools for SysAdmins by Andrew Zammit Tabona on GFI blog]&lt;br /&gt;
[http://cypherpunk.fr/distributions-gnu-linux-orientees-securite/ OWASP Mantra was mentioned in Cyberpunk.fr]&lt;br /&gt;
[http://www.pensandoenlaweb.com/2012/07/auditorias-web-con-mantra-de-owasp.html Article about OWASP Mantra on pensandoenlaweb.com]&lt;br /&gt;
[http://intellavis.com/blog/?p=325 OWASP Mantra was mentioned in Increased Visibility article titled 'Detecting Cross Site Scripting Vulnerabilities']&lt;br /&gt;
[http://www.exploit-db.com/exploits/18632/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on OneFileCMS]&lt;br /&gt;
[http://www.exploit-db.com/exploits/24507/ OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on chillyCMS]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
[[Image:OWASP Mantra cross platform.jpg|600px|OWASP Mantra cross platform.jpg]]&amp;lt;br/&amp;gt;&lt;br /&gt;
'''OWASP Mantra Security Toolkit - Beta 0.92 code named Janus'''&lt;br /&gt;
{|&lt;br /&gt;
|''Linux 32 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2032.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2032.tar.gz Mirror 2] [http://burnbit.com/download/233734/OWASP_Mantra_Janus_Linux_32_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Linux 64 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2064.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2064.tar.gz Mirror 2] [http://burnbit.com/download/233735/OWASP_Mantra_Janus_Linux_64_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Windows: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.exe/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.exe Mirror 2] [http://burnbit.com/download/233648/OWASP_Mantra_Janus_exe Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Macintosh: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.mpkg.zip/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 2] [http://burnbit.com/download/233736/OWASP_Mantra_Janus_mpkg_zip Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Source: '' &lt;br /&gt;
|[http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 1]&lt;br /&gt;
|}&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179019</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179019"/>
				<updated>2014-07-19T02:53:07Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/getmantra&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework#News More News and Events]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
[[Image:OWASP Mantra cross platform.jpg|600px|OWASP Mantra cross platform.jpg]]&amp;lt;br/&amp;gt;&lt;br /&gt;
'''OWASP Mantra Security Toolkit - Beta 0.92 code named Janus'''&lt;br /&gt;
{|&lt;br /&gt;
|''Linux 32 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2032.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2032.tar.gz Mirror 2] [http://burnbit.com/download/233734/OWASP_Mantra_Janus_Linux_32_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Linux 64 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2064.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2064.tar.gz Mirror 2] [http://burnbit.com/download/233735/OWASP_Mantra_Janus_Linux_64_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Windows: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.exe/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.exe Mirror 2] [http://burnbit.com/download/233648/OWASP_Mantra_Janus_exe Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Macintosh: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.mpkg.zip/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 2] [http://burnbit.com/download/233736/OWASP_Mantra_Janus_mpkg_zip Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Source: '' &lt;br /&gt;
|[http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 1]&lt;br /&gt;
|}&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179018</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=179018"/>
				<updated>2014-07-19T02:51:49Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
== Ohloh ==&lt;br /&gt;
&lt;br /&gt;
*https://www.ohloh.net/p/getmantra&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
[[Image:OWASP Mantra cross platform.jpg|600px|OWASP Mantra cross platform.jpg]]&amp;lt;br/&amp;gt;&lt;br /&gt;
'''OWASP Mantra Security Toolkit - Beta 0.92 code named Janus'''&lt;br /&gt;
{|&lt;br /&gt;
|''Linux 32 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2032.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2032.tar.gz Mirror 2] [http://burnbit.com/download/233734/OWASP_Mantra_Janus_Linux_32_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Linux 64 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2064.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2064.tar.gz Mirror 2] [http://burnbit.com/download/233735/OWASP_Mantra_Janus_Linux_64_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Windows: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.exe/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.exe Mirror 2] [http://burnbit.com/download/233648/OWASP_Mantra_Janus_exe Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Macintosh: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.mpkg.zip/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 2] [http://burnbit.com/download/233736/OWASP_Mantra_Janus_mpkg_zip Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Source: '' &lt;br /&gt;
|[http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 1]&lt;br /&gt;
|}&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=News=&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171589</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171589"/>
				<updated>2014-04-04T11:47:15Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Downloads=&lt;br /&gt;
[[Image:OWASP Mantra cross platform.jpg|600px|OWASP Mantra cross platform.jpg]]&amp;lt;br/&amp;gt;&lt;br /&gt;
'''OWASP Mantra Security Toolkit - Beta 0.92 code named Janus'''&lt;br /&gt;
{|&lt;br /&gt;
|''Linux 32 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2032.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2032.tar.gz Mirror 2] [http://burnbit.com/download/233734/OWASP_Mantra_Janus_Linux_32_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Linux 64 bit: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus%20Linux%2064.tar.gz/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus%20Linux%2064.tar.gz Mirror 2] [http://burnbit.com/download/233735/OWASP_Mantra_Janus_Linux_64_tar_gz Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Windows: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.exe/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.exe Mirror 2] [http://burnbit.com/download/233648/OWASP_Mantra_Janus_exe Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Macintosh: '' &lt;br /&gt;
|[http://sourceforge.net/projects/getmantra/files/Mantra%20Security%20Toolkit/Janus%20-%200.92%20Beta/OWASP%20Mantra%20Janus.mpkg.zip/download Mirror 1] [http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 2] [http://burnbit.com/download/233736/OWASP_Mantra_Janus_mpkg_zip Torrent]&lt;br /&gt;
|-&lt;br /&gt;
|''Source: '' &lt;br /&gt;
|[http://code.google.com/p/getmantra/downloads/detail?name=OWASP%20Mantra%20Janus.mpkg.zip Mirror 1]&lt;br /&gt;
|}&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171588</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171588"/>
				<updated>2014-04-04T11:45:49Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171587</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171587"/>
				<updated>2014-04-04T11:45:10Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
=Tutorials=&lt;br /&gt;
'''Tutorials'''&lt;br /&gt;
{|&lt;br /&gt;
|''Text Tutorials''&lt;br /&gt;
|&lt;br /&gt;
|''Video Tutorials''&lt;br /&gt;
|-&lt;br /&gt;
|[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-how-to-use-moc-crawler How to use MoC crawler]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]&amp;lt;br/&amp;gt;[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]&lt;br /&gt;
|&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&lt;br /&gt;
|[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 SearchSecurity Screencast]&amp;lt;br/&amp;gt;ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting Demonstration]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=p94ssETMbQ0&amp;amp; Introduction + How to use Mantra Security Toolkit]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=fxHlthnVJpA Introduction to Mantra (Arabic)]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=exyUAGseifI Introducing FoxyProxy (Arabic)]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=vFcY584Wmw0 OWASP Mantra - URL Shortener Script SQL Injection Vulnerability]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=CRJkGZlV6Vk OWASP Mantra and LAMP Security CTF 6]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.youtube.com/watch?v=aPk5vCqh-2k OWASP Mantra and Who Wants to be a Millionaire]&amp;lt;br/&amp;gt;[http://www.youtube.com/watch?v=0lPz24Z7Q_4 OWASP Mantra - One File CMS - Failure to Restrict URL Access]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171586</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171586"/>
				<updated>2014-04-04T11:37:44Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]], [[User:Maximiliano_Soler|Maximiliano Soler]], [[User:Niraj T Mohite|Niraj Mohite]], [[User:Rahul Babu R|Rahul Babu R]], Gopu C Gopinath and Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP Mantra - Security Framework | Project About}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171585</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171585"/>
				<updated>2014-04-04T11:35:25Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]] and &lt;br /&gt;
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
[[User:Gokul_C_Gopinath|Gokul C Gopinath]]&lt;br /&gt;
[[User:Maximiliano_Soler|Maximiliano Soler]]&lt;br /&gt;
[[User:Niraj T Mohite|Niraj Mohite]]&lt;br /&gt;
[[User:Rahul Babu R|Rahul Babu R]]&lt;br /&gt;
Gopu C Gopinath and &lt;br /&gt;
Thomas Mackenzie&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171584</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171584"/>
				<updated>2014-04-04T11:33:38Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Mantra provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[Abhi M BalaKrishnan]]&lt;br /&gt;
[[Yashartha Chaturvedi]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171583</id>
		<title>OWASP Mantra - Security Framework</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Mantra_-_Security_Framework&amp;diff=171583"/>
				<updated>2014-04-04T11:31:20Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: New Template Migration&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Mantra - Security Framework==&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
Free and Open Source Browser based Security Framework&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to  know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.&lt;br /&gt;
&lt;br /&gt;
Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Mantra? ==&lt;br /&gt;
&lt;br /&gt;
OWASP XXX  provides:&lt;br /&gt;
&lt;br /&gt;
* A web application security testing framework built on top of a browser. &lt;br /&gt;
* Supports Windows, Linux(both 32 and 64 bit) and Macintosh. &lt;br /&gt;
* Can work with other software like [[OWASP_Zed_Attack_Proxy_Project|ZAP]] using built in proxy management function which makes it much more convenient.&lt;br /&gt;
* Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish&lt;br /&gt;
* Comes installed with major security distributions including BackTrack and Matriux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1] | &lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Project Presentation  2]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Abhi M BalaKrishnan&lt;br /&gt;
Yashartha Chaturvedi&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Bricks]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* http://www.getmantra.com/owasp-mantra.html&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
https://lists.owasp.org/mailman/listinfo/owasp-mantra&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
[http://www.computerweekly.com/blogs/open-source-insider/2011/10/free-software-testing-on-usb-for-students-to-web-developers-with-mantra.html Computer Weekly Article]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-owasp-mantra-c0c0n-11-and-appseclatam-11-release OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ekoparty.org/2011/workshops/owasp-mantra-security-framework.php Mantra at Ekoparty Security Conference]&amp;lt;br/&amp;gt;&lt;br /&gt;
[https://www.owasp.org/images/d/dc/OWASP-Mantra_BAires-Argentina.ppt Mantra at OWASP LatamTour - Buenos Aires, Argentina]&amp;lt;br/&amp;gt;&lt;br /&gt;
Getting secure with Mantra: An open source penetration testing kit - 1. [http://www.computerworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss Computer World] 2. [http://www.cio.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ CIO] 3. [http://www.techworld.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/ Tech World] 4. [http://www.cso.com.au/article/392346/getting_secure_mantra_an_open_source_penetration_testing_kit/?uts_source=taxonomyfeed&amp;amp;utm_medium=rss CSO]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://link.brightcove.com/services/player/bcpid1078581830001?bclid=1077362296001&amp;amp;bctid=1078245078001 Searchsecurity Screencast]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-matriux-upcoming-release-leaked Mantra in Matriux Security Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://getmantra.com/forums/Thread-mantra-in-backtrack-5 Mantra in Backtrack 5 - Penetration Testing Distribution]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.facebook.com/photo.php?fbid=185544081485201&amp;amp;set=a.170788249627451.33033.170787489627527&amp;amp;type=1&amp;amp;ref=nf Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://clubhack.com/2010/speakers/ ClubHACK 2010 Mantra release]&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://secpedia.net/wiki/OWASP_Mantra_Security_Framework OWASP Mantra page on Secpedia, the information security encyclopedia]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
XXX is developed by a worldwide team of volunteers. The primary contributors to date have been:&lt;br /&gt;
&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
As of now, the priorities are:&lt;br /&gt;
Create an ecosystem for hackers based on browser&lt;br /&gt;
To bring the attention of security people to the potential of a browser based security platform&lt;br /&gt;
Provide easy to use and portable platform for demonstrating common web based attacks( read training )&lt;br /&gt;
To associate with other security tools/products to make a better environment. Eg:&lt;br /&gt;
It can be a nice addition to OWASP Live CD&lt;br /&gt;
It can be used to solve basic levels of CTF contests&lt;br /&gt;
It can associate with projects like DVWA to showcase attacks&lt;br /&gt;
It can bring functions like crawler, SQL injection scanner etc by installing extensions.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Mantra is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* xxx&lt;br /&gt;
* xxx&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Tool|Mantra - Security Framework]] [[Category:OWASP_Alpha_Quality_Tool|Mantra - Security Framework]] [[Category:OWASP_Project|Mantra - Security Framework]]&lt;br /&gt;
[[Category:OWASP Download|Mantra - Security Framework]]{{OWASP Breakers}} [[Category:OWASP_Download]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=167185</id>
		<title>OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=167185"/>
				<updated>2014-02-01T08:43:47Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Bricks==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks is a deliberately vulnerable web application built on PHP &amp;amp; MySQL focuses on variations of commonly seen application security vulnerabilities &amp;amp; exploits, which can be exploited using tools like Mantra and ZAP.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
* OWASP Bricks is a deliberately vulnerable web application built on PHP and MySQL. &lt;br /&gt;
* The project focuses on variations of commonly seen application security vulnerabilities and exploits. &lt;br /&gt;
* Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP). &lt;br /&gt;
* The mission is to 'break the bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Bricks is a web application security learning platform built on PHP and MySQL. The project focuses on variations of commonly seen application security issues. Each 'Brick' has some sort of security issue which can be leveraged manually or using automated software tools. The mission is to 'Break the Bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
Bricks is a completely free and open source project brought to you by OWASP. The complete documentation and instruction videos can also be accessed or downloaded for free. Bricks are classified into three different sections: login pages, file upload pages and content pages.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Bricks is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Bricks? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks  provides:&lt;br /&gt;
&lt;br /&gt;
* A platform for learning web application security.&lt;br /&gt;
* A test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASP_Bricks_Presentation_Slides.pptx|OWASP Bricks Presentation Slides]]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan| Abhi_M_Balakrishnan]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Mantra - Security Framework]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* [http://sechow.com/bricks/download.html Download Bricks]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
Bricks is brought to you by OWASP, a free and open software security community focusing on improving the security of software. Our mission is to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks.&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks project is led by Abhi M Balakrishnan, an information security enthusiast. He is the founding member of OWASP Mantra, Secpedia and Bbroy.&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
# Demonstrate maximum variations of most common vulnerabilities&lt;br /&gt;
# Help people to learn the need of secure codding practices and SSDLC&lt;br /&gt;
# Attract people to design more bricks&lt;br /&gt;
# Become a test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
# Help people learn the manual method of testing the applications&lt;br /&gt;
# Demonstrate the possibilities of various security tools and techniques&lt;br /&gt;
# Become a platform to teach web application security in a class room/lab environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Bricks is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Spread the word - Facebook, Twitter, Google+ or any other communication platform.&lt;br /&gt;
* Write about OWASP Bricks on your web site/ book.&lt;br /&gt;
* Mention it in your resume - It helps you, it helps the company and it helps us and thus everybody wins.&lt;br /&gt;
* Make tutorials/videos of Bricks in languages you know of.&lt;br /&gt;
* Include it in your training materials, talks, discussions etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Bricks}}   &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Bricks]]&lt;br /&gt;
[[Category:OWASP Download|Bricks]]&lt;br /&gt;
[[Category:OWASP Tool|Bricks]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool|Bricks]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=167184</id>
		<title>OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=167184"/>
				<updated>2014-02-01T08:39:23Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Bricks==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks is a deliberately vulnerable web application built on PHP &amp;amp; MySQL focuses on variations of commonly seen application security vulnerabilities &amp;amp; exploits, which can be exploited using tools like Mantra and ZAP.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
* OWASP Bricks is a deliberately vulnerable web application built on PHP and MySQL. &lt;br /&gt;
* The project focuses on variations of commonly seen application security vulnerabilities and exploits. &lt;br /&gt;
* Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP). &lt;br /&gt;
* The mission is to 'break the bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Bricks is a web application security learning platform built on PHP and MySQL. The project focuses on variations of commonly seen application security issues. Each 'Brick' has some sort of security issue which can be leveraged manually or using automated software tools. The mission is to 'Break the Bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
Bricks is a completely free and open source project brought to you by OWASP. The complete documentation and instruction videos can also be accessed or downloaded for free. Bricks are classified into three different sections: login pages, file upload pages and content pages.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Bricks is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Bricks? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks  provides:&lt;br /&gt;
&lt;br /&gt;
* A platform for learning web application security.&lt;br /&gt;
* A test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASP_Bricks_Presentation_Slides.pptx|OWASP Bricks Presentation Slides]]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan| Abhi_M_Balakrishnan]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Mantra - Security Framework]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* [http://sechow.com/bricks/download.html Download Bricks]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
Bricks is brought to you by OWASP, a free and open software security community focusing on improving the security of software. Our mission is to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks.&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks project is led by Abhi M Balakrishnan, an information security enthusiast. He is the founding member of OWASP Mantra, Secpedia and Bbroy.&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
# Demonstrate maximum variations of most common vulnerabilities&lt;br /&gt;
# Help people to learn the need of secure codding practices and SSDLC&lt;br /&gt;
# Attract people to design more bricks&lt;br /&gt;
# Become a test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
# Help people learn the manual method of testing the applications&lt;br /&gt;
# Demonstrate the possibilities of various security tools and techniques&lt;br /&gt;
# Become a platform to teach web application security in a class room/lab environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Bricks is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Spread the word - Facebook, Twitter, Google+ or any other communication platform.&lt;br /&gt;
* Write about OWASP Bricks on your web site/ book.&lt;br /&gt;
* Mention it in your resume - It helps you, it helps the company and it helps us and thus everybody wins.&lt;br /&gt;
* Make tutorials/videos of Bricks in languages you know of.&lt;br /&gt;
* Include it in your training materials, talks, discussions etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;br /&gt;
{{:Projects/OWASP_Bricks}} &lt;br /&gt;
[[Category:OWASP Project|Bricks]]&lt;br /&gt;
[[Category:OWASP Download|Bricks]]&lt;br /&gt;
[[Category:OWASP Tool|Bricks]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool|Bricks]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=167183</id>
		<title>OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=167183"/>
				<updated>2014-02-01T08:38:27Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Bricks==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks is a deliberately vulnerable web application built on PHP &amp;amp; MySQL focuses on variations of commonly seen application security vulnerabilities &amp;amp; exploits, which can be exploited using tools like Mantra and ZAP.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
* OWASP Bricks is a deliberately vulnerable web application built on PHP and MySQL. &lt;br /&gt;
* The project focuses on variations of commonly seen application security vulnerabilities and exploits. &lt;br /&gt;
* Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP). &lt;br /&gt;
* The mission is to 'break the bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Bricks is a web application security learning platform built on PHP and MySQL. The project focuses on variations of commonly seen application security issues. Each 'Brick' has some sort of security issue which can be leveraged manually or using automated software tools. The mission is to 'Break the Bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
Bricks is a completely free and open source project brought to you by OWASP. The complete documentation and instruction videos can also be accessed or downloaded for free. Bricks are classified into three different sections: login pages, file upload pages and content pages.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Bricks is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Bricks? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks  provides:&lt;br /&gt;
&lt;br /&gt;
* A platform for learning web application security.&lt;br /&gt;
* A test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASP_Bricks_Presentation_Slides.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan| Abhi_M_Balakrishnan]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Mantra - Security Framework]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* [http://sechow.com/bricks/download.html Download Bricks]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
Bricks is brought to you by OWASP, a free and open software security community focusing on improving the security of software. Our mission is to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks.&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks project is led by Abhi M Balakrishnan, an information security enthusiast. He is the founding member of OWASP Mantra, Secpedia and Bbroy.&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
# Demonstrate maximum variations of most common vulnerabilities&lt;br /&gt;
# Help people to learn the need of secure codding practices and SSDLC&lt;br /&gt;
# Attract people to design more bricks&lt;br /&gt;
# Become a test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
# Help people learn the manual method of testing the applications&lt;br /&gt;
# Demonstrate the possibilities of various security tools and techniques&lt;br /&gt;
# Become a platform to teach web application security in a class room/lab environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Bricks is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Spread the word - Facebook, Twitter, Google+ or any other communication platform.&lt;br /&gt;
* Write about OWASP Bricks on your web site/ book.&lt;br /&gt;
* Mention it in your resume - It helps you, it helps the company and it helps us and thus everybody wins.&lt;br /&gt;
* Make tutorials/videos of Bricks in languages you know of.&lt;br /&gt;
* Include it in your training materials, talks, discussions etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;br /&gt;
{{:Projects/OWASP_Bricks}} &lt;br /&gt;
[[Category:OWASP Project|Bricks]]&lt;br /&gt;
[[Category:OWASP Download|Bricks]]&lt;br /&gt;
[[Category:OWASP Tool|Bricks]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool|Bricks]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=167182</id>
		<title>OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=167182"/>
				<updated>2014-02-01T08:37:38Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Bricks==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks is a deliberately vulnerable web application built on PHP &amp;amp; MySQL focuses on variations of commonly seen application security vulnerabilities &amp;amp; exploits, which can be exploited using tools like Mantra and ZAP.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
* OWASP Bricks is a deliberately vulnerable web application built on PHP and MySQL. &lt;br /&gt;
* The project focuses on variations of commonly seen application security vulnerabilities and exploits. &lt;br /&gt;
* Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP). &lt;br /&gt;
* The mission is to 'break the bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Bricks is a web application security learning platform built on PHP and MySQL. The project focuses on variations of commonly seen application security issues. Each 'Brick' has some sort of security issue which can be leveraged manually or using automated software tools. The mission is to 'Break the Bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
Bricks is a completely free and open source project brought to you by OWASP. The complete documentation and instruction videos can also be accessed or downloaded for free. Bricks are classified into three different sections: login pages, file upload pages and content pages.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Bricks is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Bricks? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks  provides:&lt;br /&gt;
&lt;br /&gt;
* A platform for learning web application security.&lt;br /&gt;
* A test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASP_Bricks_Presentation_Slides.pptx]]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan Abhi_M_Balakrishnan]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Mantra - Security Framework]]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* [http://sechow.com/bricks/download.html Download Bricks]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
Bricks is brought to you by OWASP, a free and open software security community focusing on improving the security of software. Our mission is to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks.&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks project is led by Abhi M Balakrishnan, an information security enthusiast. He is the founding member of OWASP Mantra, Secpedia and Bbroy.&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
# Demonstrate maximum variations of most common vulnerabilities&lt;br /&gt;
# Help people to learn the need of secure codding practices and SSDLC&lt;br /&gt;
# Attract people to design more bricks&lt;br /&gt;
# Become a test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
# Help people learn the manual method of testing the applications&lt;br /&gt;
# Demonstrate the possibilities of various security tools and techniques&lt;br /&gt;
# Become a platform to teach web application security in a class room/lab environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Bricks is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Spread the word - Facebook, Twitter, Google+ or any other communication platform.&lt;br /&gt;
* Write about OWASP Bricks on your web site/ book.&lt;br /&gt;
* Mention it in your resume - It helps you, it helps the company and it helps us and thus everybody wins.&lt;br /&gt;
* Make tutorials/videos of Bricks in languages you know of.&lt;br /&gt;
* Include it in your training materials, talks, discussions etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;br /&gt;
{{:Projects/OWASP_Bricks}} &lt;br /&gt;
[[Category:OWASP Project|Bricks]]&lt;br /&gt;
[[Category:OWASP Download|Bricks]]&lt;br /&gt;
[[Category:OWASP Tool|Bricks]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool|Bricks]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=167181</id>
		<title>OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=167181"/>
				<updated>2014-02-01T08:36:39Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Bricks==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks is a deliberately vulnerable web application built on PHP &amp;amp; MySQL focuses on variations of commonly seen application security vulnerabilities &amp;amp; exploits, which can be exploited using tools like Mantra and ZAP.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
* OWASP Bricks is a deliberately vulnerable web application built on PHP and MySQL. &lt;br /&gt;
* The project focuses on variations of commonly seen application security vulnerabilities and exploits. &lt;br /&gt;
* Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP). &lt;br /&gt;
* The mission is to 'break the bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Bricks is a web application security learning platform built on PHP and MySQL. The project focuses on variations of commonly seen application security issues. Each 'Brick' has some sort of security issue which can be leveraged manually or using automated software tools. The mission is to 'Break the Bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
Bricks is a completely free and open source project brought to you by OWASP. The complete documentation and instruction videos can also be accessed or downloaded for free. Bricks are classified into three different sections: login pages, file upload pages and content pages.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Bricks is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is Bricks? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks  provides:&lt;br /&gt;
&lt;br /&gt;
* A platform for learning web application security.&lt;br /&gt;
* A test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASP_Bricks_Presentation_Slides.pptx]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Mantra - Security Framework]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* [http://sechow.com/bricks/download.html Download Bricks]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
Bricks is brought to you by OWASP, a free and open software security community focusing on improving the security of software. Our mission is to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks.&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks project is led by Abhi M Balakrishnan, an information security enthusiast. He is the founding member of OWASP Mantra, Secpedia and Bbroy.&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
# Demonstrate maximum variations of most common vulnerabilities&lt;br /&gt;
# Help people to learn the need of secure codding practices and SSDLC&lt;br /&gt;
# Attract people to design more bricks&lt;br /&gt;
# Become a test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
# Help people learn the manual method of testing the applications&lt;br /&gt;
# Demonstrate the possibilities of various security tools and techniques&lt;br /&gt;
# Become a platform to teach web application security in a class room/lab environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Bricks is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Spread the word - Facebook, Twitter, Google+ or any other communication platform.&lt;br /&gt;
* Write about OWASP Bricks on your web site/ book.&lt;br /&gt;
* Mention it in your resume - It helps you, it helps the company and it helps us and thus everybody wins.&lt;br /&gt;
* Make tutorials/videos of Bricks in languages you know of.&lt;br /&gt;
* Include it in your training materials, talks, discussions etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;br /&gt;
{{:Projects/OWASP_Bricks}} &lt;br /&gt;
[[Category:OWASP Project|Bricks]]&lt;br /&gt;
[[Category:OWASP Download|Bricks]]&lt;br /&gt;
[[Category:OWASP Tool|Bricks]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool|Bricks]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=167180</id>
		<title>OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=167180"/>
				<updated>2014-02-01T08:35:55Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: New template&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Bricks==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks is a deliberately vulnerable web application built on PHP &amp;amp; MySQL focuses on variations of commonly seen application security vulnerabilities &amp;amp; exploits, which can be exploited using tools like Mantra and ZAP.&lt;br /&gt;
&lt;br /&gt;
==Introduction==&lt;br /&gt;
&lt;br /&gt;
* OWASP Bricks is a deliberately vulnerable web application built on PHP and MySQL. &lt;br /&gt;
* The project focuses on variations of commonly seen application security vulnerabilities and exploits. &lt;br /&gt;
* Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP). &lt;br /&gt;
* The mission is to 'break the bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
Bricks is a web application security learning platform built on PHP and MySQL. The project focuses on variations of commonly seen application security issues. Each 'Brick' has some sort of security issue which can be leveraged manually or using automated software tools. The mission is to 'Break the Bricks' and thus learn the various aspects of web application security.&lt;br /&gt;
&lt;br /&gt;
Bricks is a completely free and open source project brought to you by OWASP. The complete documentation and instruction videos can also be accessed or downloaded for free. Bricks are classified into three different sections: login pages, file upload pages and content pages.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP Bricks is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Bricks? ==&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks  provides:&lt;br /&gt;
&lt;br /&gt;
* A platform for learning web application security.&lt;br /&gt;
* A test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
[[File:OWASP_Bricks_Presentation_Slides.pptx]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[[User:Abhi_M_Balakrishnan]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP Mantra - Security Framework]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* [http://sechow.com/bricks/download.html Download Bricks]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
; Q1&lt;br /&gt;
: A1&lt;br /&gt;
&lt;br /&gt;
; Q2&lt;br /&gt;
: A2&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
Bricks is brought to you by OWASP, a free and open software security community focusing on improving the security of software. Our mission is to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks.&lt;br /&gt;
&lt;br /&gt;
OWASP Bricks project is led by Abhi M Balakrishnan, an information security enthusiast. He is the founding member of OWASP Mantra, Secpedia and Bbroy.&lt;br /&gt;
&lt;br /&gt;
==Others==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
# Demonstrate maximum variations of most common vulnerabilities&lt;br /&gt;
# Help people to learn the need of secure codding practices and SSDLC&lt;br /&gt;
# Attract people to design more bricks&lt;br /&gt;
# Become a test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
# Help people learn the manual method of testing the applications&lt;br /&gt;
# Demonstrate the possibilities of various security tools and techniques&lt;br /&gt;
# Become a platform to teach web application security in a class room/lab environment.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of OWASP Bricks is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Spread the word - Facebook, Twitter, Google+ or any other communication platform.&lt;br /&gt;
* Write about OWASP Bricks on your web site/ book.&lt;br /&gt;
* Mention it in your resume - It helps you, it helps the company and it helps us and thus everybody wins.&lt;br /&gt;
* Make tutorials/videos of Bricks in languages you know of.&lt;br /&gt;
* Include it in your training materials, talks, discussions etc.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}}  &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;br /&gt;
{{:Projects/OWASP_Bricks}} &lt;br /&gt;
[[Category:OWASP Project|Bricks]]&lt;br /&gt;
[[Category:OWASP Download|Bricks]]&lt;br /&gt;
[[Category:OWASP Tool|Bricks]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool|Bricks]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=164003</id>
		<title>OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=164003"/>
				<updated>2013-11-30T02:34:05Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: OWASP Bricks - 2.2 Tuivai&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:OWASP Bricks logo.png|400px|OWASP Bricks]]&amp;lt;br&amp;gt; &amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:112%;border:none;margin: 0;color:#000;&amp;quot;&amp;gt;&lt;br /&gt;
* Bricks is a deliberately vulnerable web application built on PHP and MySQL. &lt;br /&gt;
* The project focuses on variations of commonly seen application security vulnerabilities and exploits. &lt;br /&gt;
* Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP). &lt;br /&gt;
* The mission is to 'break the bricks' and thus learn the various aspects of web application security.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''[http://sechow.com/bricks/download.html Download Bricks] | [https://www.youtube.com/OWASPBricks Watch videos] | [http://sechow.com/bricks/docs/ Documentation]&amp;lt;br&amp;gt;&lt;br /&gt;
= Bricks =&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Challenge&lt;br /&gt;
! Page&lt;br /&gt;
! URL&lt;br /&gt;
! Documentations&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| Log in page #1&lt;br /&gt;
| bricks/login-1/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-1.html Text],  [http://www.youtube.com/watch?v=mCo6ajvBv50 Video]&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| File upload page #1&lt;br /&gt;
| bricks/upload-1/&lt;br /&gt;
| [http://sechow.com/bricks/docs/file-upload-1.html Text], [http://www.youtube.com/watch?v=N6SAzEkgJ3s Video]&lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| Content page #1&lt;br /&gt;
| bricks/content-1/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-1.html Text], [http://www.youtube.com/watch?v=j5I0wPvQxTg Video]&lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| Log in page #2&lt;br /&gt;
| bricks/login-2/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-2.html Text], [http://www.youtube.com/watch?v=nZYejElQxhk Video]&lt;br /&gt;
|-&lt;br /&gt;
| 5&lt;br /&gt;
| Content page #2&lt;br /&gt;
| bricks/content-2/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-2.html Text], [http://www.youtube.com/watch?v=7TkRBREYn6Y Video]&lt;br /&gt;
|-&lt;br /&gt;
| 6&lt;br /&gt;
| File upload page #2&lt;br /&gt;
| bricks/upload-2/&lt;br /&gt;
| [http://sechow.com/bricks/docs/file-upload-2.html Text], [http://www.youtube.com/watch?v=tsDClYorsXI Video]&lt;br /&gt;
|-&lt;br /&gt;
| 7&lt;br /&gt;
| Log in page #3&lt;br /&gt;
| bricks/login-3/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-3.html Text], [http://www.youtube.com/watch?v=Glsl-UR2OmU Video]&lt;br /&gt;
|-&lt;br /&gt;
| 8&lt;br /&gt;
| Content page #3&lt;br /&gt;
| bricks/content-3/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-3.html Text], [http://www.youtube.com/watch?v=qWpqZbymsl8 Video]&lt;br /&gt;
|-&lt;br /&gt;
| 9&lt;br /&gt;
| Log in page #4&lt;br /&gt;
| bricks/login-4/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-4.html Text], [https://www.youtube.com/watch?v=z4JUplVRG1U Video]&lt;br /&gt;
|-&lt;br /&gt;
| 10&lt;br /&gt;
| Content page #4&lt;br /&gt;
| bricks/content-4/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-4.html Text]&lt;br /&gt;
|-&lt;br /&gt;
| 11&lt;br /&gt;
| File upload page #3&lt;br /&gt;
| bricks/upload-3/&lt;br /&gt;
| [http://sechow.com/bricks/docs/file-upload-3.html Text]&lt;br /&gt;
|-&lt;br /&gt;
| 12&lt;br /&gt;
| Log in page #5&lt;br /&gt;
| bricks/login-5/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-5.html Text]&lt;br /&gt;
|-&lt;br /&gt;
| 13&lt;br /&gt;
| Content page #5&lt;br /&gt;
| bricks/content-5/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-5.html Text]&lt;br /&gt;
|-&lt;br /&gt;
| 14&lt;br /&gt;
| Login page #6&lt;br /&gt;
| bricks/login-6/&lt;br /&gt;
| Open for public&lt;br /&gt;
|-&lt;br /&gt;
| 15&lt;br /&gt;
| Content page #6&lt;br /&gt;
| bricks/content-6/&lt;br /&gt;
| Open for public&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
= Road map =&lt;br /&gt;
# Demonstrate maximum variations of most common vulnerabilities&lt;br /&gt;
# Help people to learn the need of secure codding practices and SSDLC&lt;br /&gt;
# Attract people to design more bricks&lt;br /&gt;
# Become a test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
# Help people learn the manual method of testing the applications&lt;br /&gt;
# Demonstrate the possibilities of various security tools and techniques&lt;br /&gt;
# Become a platform to teach web application security in a class room/lab environment.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Bricks}} &lt;br /&gt;
[[Category:OWASP Project|Bricks]]&lt;br /&gt;
[[Category:OWASP Download|Bricks]]&lt;br /&gt;
[[Category:OWASP Tool|Bricks]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool|Bricks]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks&amp;diff=164002</id>
		<title>Projects/OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks&amp;diff=164002"/>
				<updated>2013-11-30T02:32:37Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name =OWASP Bricks&lt;br /&gt;
| project_home_page =OWASP_Bricks&lt;br /&gt;
| project_description =Bricks, a deliberately vulnerable web application built on PHP &amp;amp; MySQL focuses on variations of commonly seen application security vulnerabilities &amp;amp; exploits, which can be exploited using tools (Mantra &amp;amp; ZAP). The mission is to 'break the bricks'.&lt;br /&gt;
| project_license =Apache 2.0 License  (fewest restrictions, even allowing proprietary modifications and proprietary forks of your project)&lt;br /&gt;
| leader_name1 =Abhi M Balakrishnan&lt;br /&gt;
| leader_email1 =abhi.balakrishnan@owasp.org&lt;br /&gt;
&lt;br /&gt;
| pamphlet_link = https://www.owasp.org/images/c/c9/OWASP_Bricks_Project_Pamphlet.pdf&lt;br /&gt;
| presentation_link = https://www.owasp.org/index.php/File:OWASP_Bricks_Presentation_Slides.pptx&lt;br /&gt;
&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp_bricks&lt;br /&gt;
| project_road_map = https://www.owasp.org/index.php/Projects/OWASP_Bricks/Roadmap&lt;br /&gt;
| release_1 = Narmada&lt;br /&gt;
| release_2 = Betwa&lt;br /&gt;
| release_3 = Feni&lt;br /&gt;
| release_4 = Torsa&lt;br /&gt;
| release_5 = Punpun&lt;br /&gt;
| release_6 = Lachen&lt;br /&gt;
| release_7 = Raidak&lt;br /&gt;
| release_8 = Phalgu&lt;br /&gt;
| release_9 = Atrai&lt;br /&gt;
| release_10 = Barak&lt;br /&gt;
| release_11 = Dakatua&lt;br /&gt;
| release_12 = Mora&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Current&amp;diff=164001</id>
		<title>Projects/OWASP Bricks/Releases/Current</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Current&amp;diff=164001"/>
				<updated>2013-11-30T02:32:08Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: OWASP Bricks - 2.2 Tuivai&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template: &amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Release About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| project_name = OWASP Bricks&lt;br /&gt;
&lt;br /&gt;
| project_home_page = OWASP Bricks&lt;br /&gt;
&lt;br /&gt;
| release_name = Tuivai&lt;br /&gt;
&lt;br /&gt;
| release_date = 30 November 2013&lt;br /&gt;
&lt;br /&gt;
| release_description = 13th public release&lt;br /&gt;
&lt;br /&gt;
| release_license = [http://www.apache.org/licenses/LICENSE-2.0 Apache License 2.0]&lt;br /&gt;
&lt;br /&gt;
| release_download_link = http://sechow.com/bricks/download.html&lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Abhi M BalaKrishnan &lt;br /&gt;
| leader_email1 = abhi@getmantra.com&lt;br /&gt;
| leader_username1 = Abhi_M_Balakrishnan&lt;br /&gt;
&lt;br /&gt;
| release_notes = http://owaspbricks.blogspot.com/2013/11/owasp-bricks-22-tuivai-release.html&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASP_Bricks_Tuivai.jpg&amp;diff=164000</id>
		<title>File:OWASP Bricks Tuivai.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASP_Bricks_Tuivai.jpg&amp;diff=164000"/>
				<updated>2013-11-30T02:31:10Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: OWASP Bricks Tuivai&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OWASP Bricks Tuivai&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Tuivai&amp;diff=163999</id>
		<title>Projects/OWASP Bricks/Releases/Tuivai</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Tuivai&amp;diff=163999"/>
				<updated>2013-11-30T02:30:46Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template: &amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Release About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Bricks&lt;br /&gt;
| project_home_page = OWASP Bricks&lt;br /&gt;
| release_name = Tuivai&lt;br /&gt;
| release_date = 30/11/2013&lt;br /&gt;
| release_description = &lt;br /&gt;
&lt;br /&gt;
'''This is the 13th public release.'''&lt;br /&gt;
&lt;br /&gt;
| release_license = [http://www.apache.org/licenses/LICENSE-2.0 Apache License 2.0]&lt;br /&gt;
| release_download_link = http://sechow.com/bricks/download.html&lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Abhi M Balakrishnan &lt;br /&gt;
| leader_email1 = abhi@getmantra.com&lt;br /&gt;
| leader_username1 = Abhi_M_Balakrishnan&lt;br /&gt;
&lt;br /&gt;
| release_notes = http://owaspbricks.blogspot.com/2013/11/owasp-bricks-22-tuivai-release.html&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
==Screenshot==&lt;br /&gt;
[[Image:OWASP Bricks Tuivai.jpg|600px|OWASP Bricks Tuivai]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Tuivai&amp;diff=163998</id>
		<title>Projects/OWASP Bricks/Releases/Tuivai</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Tuivai&amp;diff=163998"/>
				<updated>2013-11-30T02:30:18Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: OWASP Bricks Tuivai&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template: &amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Release About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Bricks&lt;br /&gt;
| project_home_page = OWASP Bricks&lt;br /&gt;
| release_name = Dakatua&lt;br /&gt;
| release_date = 30/11/2013&lt;br /&gt;
| release_description = &lt;br /&gt;
&lt;br /&gt;
'''This is the 13th public release.'''&lt;br /&gt;
&lt;br /&gt;
| release_license = [http://www.apache.org/licenses/LICENSE-2.0 Apache License 2.0]&lt;br /&gt;
| release_download_link = http://sechow.com/bricks/download.html&lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Abhi M Balakrishnan &lt;br /&gt;
| leader_email1 = abhi@getmantra.com&lt;br /&gt;
| leader_username1 = Abhi_M_Balakrishnan&lt;br /&gt;
&lt;br /&gt;
| release_notes = http://owaspbricks.blogspot.com/2013/11/owasp-bricks-22-tuivai-release.html&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
==Screenshot==&lt;br /&gt;
[[Image:OWASP Bricks Tuivai.jpg|600px|OWASP Bricks Tuivai]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks&amp;diff=163445</id>
		<title>Projects/OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks&amp;diff=163445"/>
				<updated>2013-11-16T02:47:21Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name =OWASP Bricks&lt;br /&gt;
| project_home_page =OWASP_Bricks&lt;br /&gt;
| project_description =Bricks, a deliberately vulnerable web application built on PHP &amp;amp; MySQL focuses on variations of commonly seen application security vulnerabilities &amp;amp; exploits, which can be exploited using tools (Mantra &amp;amp; ZAP). The mission is to 'break the bricks'.&lt;br /&gt;
| project_license =Apache 2.0 License  (fewest restrictions, even allowing proprietary modifications and proprietary forks of your project)&lt;br /&gt;
| leader_name1 =Abhi M Balakrishnan&lt;br /&gt;
| leader_email1 =abhi.balakrishnan@owasp.org&lt;br /&gt;
&lt;br /&gt;
| pamphlet_link = https://www.owasp.org/images/c/c9/OWASP_Bricks_Project_Pamphlet.pdf&lt;br /&gt;
| presentation_link = https://www.owasp.org/index.php/File:OWASP_Bricks_Presentation_Slides.pptx&lt;br /&gt;
&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp_bricks&lt;br /&gt;
| project_road_map = https://www.owasp.org/index.php/Projects/OWASP_Bricks/Roadmap&lt;br /&gt;
| release_1 = Narmada&lt;br /&gt;
| release_2 = Betwa&lt;br /&gt;
| release_3 = Feni&lt;br /&gt;
| release_4 = Torsa&lt;br /&gt;
| release_5 = Punpun&lt;br /&gt;
| release_6 = Lachen&lt;br /&gt;
| release_7 = Raidak&lt;br /&gt;
| release_8 = Phalgu&lt;br /&gt;
| release_9 = Atrai&lt;br /&gt;
| release_10 = Barak&lt;br /&gt;
| release_11 = Dakatua&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASP_Bricks_Mora.jpg&amp;diff=163444</id>
		<title>File:OWASP Bricks Mora.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASP_Bricks_Mora.jpg&amp;diff=163444"/>
				<updated>2013-11-16T02:46:06Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Mora&amp;diff=163443</id>
		<title>Projects/OWASP Bricks/Releases/Mora</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Mora&amp;diff=163443"/>
				<updated>2013-11-16T02:45:29Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: Created page with &amp;quot;{{Template: &amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Release About&amp;lt;/noinclude&amp;gt; | project_name = OWASP Bricks | project_home_page = OWASP Bricks | release_name = Mora | rel...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template: &amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Release About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Bricks&lt;br /&gt;
| project_home_page = OWASP Bricks&lt;br /&gt;
| release_name = Mora&lt;br /&gt;
| release_date = 16/11/2013&lt;br /&gt;
| release_description = &lt;br /&gt;
&lt;br /&gt;
'''This is the 12th public release.'''&lt;br /&gt;
&lt;br /&gt;
| release_license = [http://www.apache.org/licenses/LICENSE-2.0 Apache License 2.0]&lt;br /&gt;
| release_download_link = http://sechow.com/bricks/download.html&lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Abhi M Balakrishnan &lt;br /&gt;
| leader_email1 = abhi@getmantra.com&lt;br /&gt;
| leader_username1 = Abhi_M_Balakrishnan&lt;br /&gt;
&lt;br /&gt;
| release_notes = http://owaspbricks.blogspot.com/2013/11/owasp-bricks-21-mora-release.html&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
==Screenshot==&lt;br /&gt;
[[Image:OWASP Bricks Mora.jpg|600px|OWASP Bricks Mora]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Current&amp;diff=163442</id>
		<title>Projects/OWASP Bricks/Releases/Current</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Current&amp;diff=163442"/>
				<updated>2013-11-16T02:43:43Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template: &amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Release About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| project_name = OWASP Bricks&lt;br /&gt;
&lt;br /&gt;
| project_home_page = OWASP Bricks&lt;br /&gt;
&lt;br /&gt;
| release_name = Mora&lt;br /&gt;
&lt;br /&gt;
| release_date = 16 November 2013&lt;br /&gt;
&lt;br /&gt;
| release_description = 12th public release&lt;br /&gt;
&lt;br /&gt;
| release_license = [http://www.apache.org/licenses/LICENSE-2.0 Apache License 2.0]&lt;br /&gt;
&lt;br /&gt;
| release_download_link = http://sechow.com/bricks/download.html&lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Abhi M BalaKrishnan &lt;br /&gt;
| leader_email1 = abhi@getmantra.com&lt;br /&gt;
| leader_username1 = Abhi_M_Balakrishnan&lt;br /&gt;
&lt;br /&gt;
| release_notes = http://owaspbricks.blogspot.com/2013/11/owasp-bricks-21-mora-release.html&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=163440</id>
		<title>OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=163440"/>
				<updated>2013-11-16T02:36:13Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:OWASP Bricks logo.png|400px|OWASP Bricks]]&amp;lt;br&amp;gt; &amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:112%;border:none;margin: 0;color:#000;&amp;quot;&amp;gt;&lt;br /&gt;
* Bricks is a deliberately vulnerable web application built on PHP and MySQL. &lt;br /&gt;
* The project focuses on variations of commonly seen application security vulnerabilities and exploits. &lt;br /&gt;
* Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP). &lt;br /&gt;
* The mission is to 'break the bricks' and thus learn the various aspects of web application security.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''[http://sechow.com/bricks/download.html Download Bricks] | [https://www.youtube.com/OWASPBricks Watch videos] | [http://sechow.com/bricks/docs/ Documentation]&amp;lt;br&amp;gt;&lt;br /&gt;
= Bricks =&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Challenge&lt;br /&gt;
! Page&lt;br /&gt;
! URL&lt;br /&gt;
! Documentations&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| Log in page #1&lt;br /&gt;
| bricks/login-1/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-1.html Text],  [http://www.youtube.com/watch?v=mCo6ajvBv50 Video]&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| File upload page #1&lt;br /&gt;
| bricks/upload-1/&lt;br /&gt;
| [http://sechow.com/bricks/docs/file-upload-1.html Text], [http://www.youtube.com/watch?v=N6SAzEkgJ3s Video]&lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| Content page #1&lt;br /&gt;
| bricks/content-1/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-1.html Text], [http://www.youtube.com/watch?v=j5I0wPvQxTg Video]&lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| Log in page #2&lt;br /&gt;
| bricks/login-2/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-2.html Text], [http://www.youtube.com/watch?v=nZYejElQxhk Video]&lt;br /&gt;
|-&lt;br /&gt;
| 5&lt;br /&gt;
| Content page #2&lt;br /&gt;
| bricks/content-2/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-2.html Text], [http://www.youtube.com/watch?v=7TkRBREYn6Y Video]&lt;br /&gt;
|-&lt;br /&gt;
| 6&lt;br /&gt;
| File upload page #2&lt;br /&gt;
| bricks/upload-2/&lt;br /&gt;
| [http://sechow.com/bricks/docs/file-upload-2.html Text], [http://www.youtube.com/watch?v=tsDClYorsXI Video]&lt;br /&gt;
|-&lt;br /&gt;
| 7&lt;br /&gt;
| Log in page #3&lt;br /&gt;
| bricks/login-3/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-3.html Text], [http://www.youtube.com/watch?v=Glsl-UR2OmU Video]&lt;br /&gt;
|-&lt;br /&gt;
| 8&lt;br /&gt;
| Content page #3&lt;br /&gt;
| bricks/content-3/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-3.html Text], [http://www.youtube.com/watch?v=qWpqZbymsl8 Video]&lt;br /&gt;
|-&lt;br /&gt;
| 9&lt;br /&gt;
| Log in page #4&lt;br /&gt;
| bricks/login-4/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-4.html Text], [https://www.youtube.com/watch?v=z4JUplVRG1U Video]&lt;br /&gt;
|-&lt;br /&gt;
| 10&lt;br /&gt;
| Content page #4&lt;br /&gt;
| bricks/content-4/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-4.html Text]&lt;br /&gt;
|-&lt;br /&gt;
| 11&lt;br /&gt;
| File upload page #3&lt;br /&gt;
| bricks/upload-3/&lt;br /&gt;
| [http://sechow.com/bricks/docs/file-upload-3.html Text]&lt;br /&gt;
|-&lt;br /&gt;
| 12&lt;br /&gt;
| Log in page #5&lt;br /&gt;
| bricks/login-5/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-5.html Text]&lt;br /&gt;
|-&lt;br /&gt;
| 13&lt;br /&gt;
| Content page #5&lt;br /&gt;
| bricks/content-5/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-5.html Text]&lt;br /&gt;
|-&lt;br /&gt;
| 14&lt;br /&gt;
| Login page #6&lt;br /&gt;
| bricks/login-6/&lt;br /&gt;
| Open for public&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
= Road map =&lt;br /&gt;
# Demonstrate maximum variations of most common vulnerabilities&lt;br /&gt;
# Help people to learn the need of secure codding practices and SSDLC&lt;br /&gt;
# Attract people to design more bricks&lt;br /&gt;
# Become a test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
# Help people learn the manual method of testing the applications&lt;br /&gt;
# Demonstrate the possibilities of various security tools and techniques&lt;br /&gt;
# Become a platform to teach web application security in a class room/lab environment.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Bricks}} &lt;br /&gt;
[[Category:OWASP Project|Bricks]]&lt;br /&gt;
[[Category:OWASP Download|Bricks]]&lt;br /&gt;
[[Category:OWASP Tool|Bricks]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool|Bricks]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=161672</id>
		<title>OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=161672"/>
				<updated>2013-10-26T06:24:37Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:OWASP Bricks logo.png|400px|OWASP Bricks]]&amp;lt;br&amp;gt; &amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:112%;border:none;margin: 0;color:#000;&amp;quot;&amp;gt;&lt;br /&gt;
* Bricks is a deliberately vulnerable web application built on PHP and MySQL. &lt;br /&gt;
* The project focuses on variations of commonly seen application security vulnerabilities and exploits. &lt;br /&gt;
* Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP). &lt;br /&gt;
* The mission is to 'break the bricks' and thus learn the various aspects of web application security.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''[http://sechow.com/bricks/download.html Download Bricks] | [https://www.youtube.com/OWASPBricks Watch videos] | [http://sechow.com/bricks/docs/ Documentation]&amp;lt;br&amp;gt;&lt;br /&gt;
= Bricks =&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Challenge&lt;br /&gt;
! Page&lt;br /&gt;
! URL&lt;br /&gt;
! Documentations&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| Log in page #1&lt;br /&gt;
| bricks/login-1/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-1.html Text],  [http://www.youtube.com/watch?v=mCo6ajvBv50 Video]&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| File upload page #1&lt;br /&gt;
| bricks/upload-1/&lt;br /&gt;
| [http://sechow.com/bricks/docs/file-upload-1.html Text], [http://www.youtube.com/watch?v=N6SAzEkgJ3s Video]&lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| Content page #1&lt;br /&gt;
| bricks/content-1/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-1.html Text], [http://www.youtube.com/watch?v=j5I0wPvQxTg Video]&lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| Log in page #2&lt;br /&gt;
| bricks/login-2/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-2.html Text], [http://www.youtube.com/watch?v=nZYejElQxhk Video]&lt;br /&gt;
|-&lt;br /&gt;
| 5&lt;br /&gt;
| Content page #2&lt;br /&gt;
| bricks/content-2/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-2.html Text], [http://www.youtube.com/watch?v=7TkRBREYn6Y Video]&lt;br /&gt;
|-&lt;br /&gt;
| 6&lt;br /&gt;
| File upload page #2&lt;br /&gt;
| bricks/upload-2/&lt;br /&gt;
| [http://sechow.com/bricks/docs/file-upload-2.html Text], [http://www.youtube.com/watch?v=tsDClYorsXI Video]&lt;br /&gt;
|-&lt;br /&gt;
| 7&lt;br /&gt;
| Log in page #3&lt;br /&gt;
| bricks/login-3/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-3.html Text], [http://www.youtube.com/watch?v=Glsl-UR2OmU Video]&lt;br /&gt;
|-&lt;br /&gt;
| 8&lt;br /&gt;
| Content page #3&lt;br /&gt;
| bricks/content-3/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-3.html Text], [http://www.youtube.com/watch?v=qWpqZbymsl8 Video]&lt;br /&gt;
|-&lt;br /&gt;
| 9&lt;br /&gt;
| Log in page #4&lt;br /&gt;
| bricks/login-4/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-4.html Text], [https://www.youtube.com/watch?v=z4JUplVRG1U Video]&lt;br /&gt;
|-&lt;br /&gt;
| 10&lt;br /&gt;
| Content page #4&lt;br /&gt;
| bricks/content-4/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-4.html Text]&lt;br /&gt;
|-&lt;br /&gt;
| 11&lt;br /&gt;
| File upload page #3&lt;br /&gt;
| bricks/upload-3/&lt;br /&gt;
| Open for public&lt;br /&gt;
|-&lt;br /&gt;
| 12&lt;br /&gt;
| Log in page #5&lt;br /&gt;
| bricks/login-5/&lt;br /&gt;
| Open for public&lt;br /&gt;
|-&lt;br /&gt;
| 13&lt;br /&gt;
| Content page #5&lt;br /&gt;
| bricks/content-5/&lt;br /&gt;
| Open for public&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
= Road map =&lt;br /&gt;
# Demonstrate maximum variations of most common vulnerabilities&lt;br /&gt;
# Help people to learn the need of secure codding practices and SSDLC&lt;br /&gt;
# Attract people to design more bricks&lt;br /&gt;
# Become a test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
# Help people learn the manual method of testing the applications&lt;br /&gt;
# Demonstrate the possibilities of various security tools and techniques&lt;br /&gt;
# Become a platform to teach web application security in a class room/lab environment.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Bricks}} &lt;br /&gt;
[[Category:OWASP Project|Bricks]]&lt;br /&gt;
[[Category:OWASP Download|Bricks]]&lt;br /&gt;
[[Category:OWASP Tool|Bricks]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool|Bricks]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks&amp;diff=161671</id>
		<title>Projects/OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks&amp;diff=161671"/>
				<updated>2013-10-26T06:23:54Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name =OWASP Bricks&lt;br /&gt;
| project_home_page =OWASP_Bricks&lt;br /&gt;
| project_description =Bricks, a deliberately vulnerable web application built on PHP &amp;amp; MySQL focuses on variations of commonly seen application security vulnerabilities &amp;amp; exploits, which can be exploited using tools (Mantra &amp;amp; ZAP). The mission is to 'break the bricks'.&lt;br /&gt;
| project_license =Apache 2.0 License  (fewest restrictions, even allowing proprietary modifications and proprietary forks of your project)&lt;br /&gt;
| leader_name1 =Abhi M Balakrishnan&lt;br /&gt;
| leader_email1 =abhi.balakrishnan@owasp.org&lt;br /&gt;
&lt;br /&gt;
| pamphlet_link = https://www.owasp.org/images/c/c9/OWASP_Bricks_Project_Pamphlet.pdf&lt;br /&gt;
| presentation_link = https://www.owasp.org/index.php/File:OWASP_Bricks_Presentation_Slides.pptx&lt;br /&gt;
&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp_bricks&lt;br /&gt;
| project_road_map = https://www.owasp.org/index.php/Projects/OWASP_Bricks/Roadmap&lt;br /&gt;
| release_1 = Narmada&lt;br /&gt;
| release_2 = Betwa&lt;br /&gt;
| release_3 = Feni&lt;br /&gt;
| release_4 = Torsa&lt;br /&gt;
| release_5 = Punpun&lt;br /&gt;
| release_6 = Lachen&lt;br /&gt;
| release_7 = Raidak&lt;br /&gt;
| release_8 = Phalgu&lt;br /&gt;
| release_9 = Atrai&lt;br /&gt;
| release_10 = Barak&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASP_Bricks_Dakatua.jpg&amp;diff=161670</id>
		<title>File:OWASP Bricks Dakatua.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASP_Bricks_Dakatua.jpg&amp;diff=161670"/>
				<updated>2013-10-26T06:21:31Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: Dakatua&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Dakatua&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Dakatua&amp;diff=161669</id>
		<title>Projects/OWASP Bricks/Releases/Dakatua</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Dakatua&amp;diff=161669"/>
				<updated>2013-10-26T06:20:59Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: Dakatua&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template: &amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Release About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Bricks&lt;br /&gt;
| project_home_page = OWASP Bricks&lt;br /&gt;
| release_name = Dakatua&lt;br /&gt;
| release_date = 26/10/2013&lt;br /&gt;
| release_description = &lt;br /&gt;
&lt;br /&gt;
'''This is the 11th public release.'''&lt;br /&gt;
&lt;br /&gt;
| release_license = [http://www.apache.org/licenses/LICENSE-2.0 Apache License 2.0]&lt;br /&gt;
| release_download_link = http://sechow.com/bricks/download.html&lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Abhi M Balakrishnan &lt;br /&gt;
| leader_email1 = abhi@getmantra.com&lt;br /&gt;
| leader_username1 = Abhi_M_Balakrishnan&lt;br /&gt;
&lt;br /&gt;
| release_notes = http://owaspbricks.blogspot.com/2013/10/owasp-bricks-20-dakatua-release.html&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
==Screenshot==&lt;br /&gt;
[[Image:OWASP Bricks Dakatua.jpg|600px|OWASP Bricks Dakatua]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Current&amp;diff=161668</id>
		<title>Projects/OWASP Bricks/Releases/Current</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Current&amp;diff=161668"/>
				<updated>2013-10-26T06:19:50Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: Dakatua&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template: &amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Release About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
&lt;br /&gt;
| project_name = OWASP Bricks&lt;br /&gt;
&lt;br /&gt;
| project_home_page = OWASP Bricks&lt;br /&gt;
&lt;br /&gt;
| release_name = Dakatua&lt;br /&gt;
&lt;br /&gt;
| release_date = 26 Octber 2013&lt;br /&gt;
&lt;br /&gt;
| release_description = 11th public release&lt;br /&gt;
&lt;br /&gt;
| release_license = [http://www.apache.org/licenses/LICENSE-2.0 Apache License 2.0]&lt;br /&gt;
&lt;br /&gt;
| release_download_link = http://sechow.com/bricks/download.html&lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Abhi M BalaKrishnan &lt;br /&gt;
| leader_email1 = abhi@getmantra.com&lt;br /&gt;
| leader_username1 = Abhi_M_Balakrishnan&lt;br /&gt;
&lt;br /&gt;
| release_notes = http://owaspbricks.blogspot.com/2013/10/owasp-bricks-20-dakatua-release.html&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=161662</id>
		<title>OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Bricks&amp;diff=161662"/>
				<updated>2013-10-26T03:03:38Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Image:OWASP Bricks logo.png|400px|OWASP Bricks]]&amp;lt;br&amp;gt; &amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;div style=&amp;quot;font-size:112%;border:none;margin: 0;color:#000;&amp;quot;&amp;gt;&lt;br /&gt;
* Bricks is a deliberately vulnerable web application built on PHP and MySQL. &lt;br /&gt;
* The project focuses on variations of commonly seen application security vulnerabilities and exploits. &lt;br /&gt;
* Each 'brick' has some sort of vulnerability which can be exploited using tools (Mantra and ZAP). &lt;br /&gt;
* The mission is to 'break the bricks' and thus learn the various aspects of web application security.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''[http://sechow.com/bricks/download.html Download Bricks] | [https://www.youtube.com/OWASPBricks Watch videos] | [http://sechow.com/bricks/docs/ Documentation]&amp;lt;br&amp;gt;&lt;br /&gt;
= Bricks =&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Challenge&lt;br /&gt;
! Page&lt;br /&gt;
! URL&lt;br /&gt;
! Documentations&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| Log in page #1&lt;br /&gt;
| bricks/login-1/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-1.html Text],  [http://www.youtube.com/watch?v=mCo6ajvBv50 Video]&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| File upload page #1&lt;br /&gt;
| bricks/upload-1/&lt;br /&gt;
| [http://sechow.com/bricks/docs/file-upload-1.html Text], [http://www.youtube.com/watch?v=N6SAzEkgJ3s Video]&lt;br /&gt;
|-&lt;br /&gt;
| 3&lt;br /&gt;
| Content page #1&lt;br /&gt;
| bricks/content-1/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-1.html Text], [http://www.youtube.com/watch?v=j5I0wPvQxTg Video]&lt;br /&gt;
|-&lt;br /&gt;
| 4&lt;br /&gt;
| Log in page #2&lt;br /&gt;
| bricks/login-2/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-2.html Text], [http://www.youtube.com/watch?v=nZYejElQxhk Video]&lt;br /&gt;
|-&lt;br /&gt;
| 5&lt;br /&gt;
| Content page #2&lt;br /&gt;
| bricks/content-2/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-2.html Text], [http://www.youtube.com/watch?v=7TkRBREYn6Y Video]&lt;br /&gt;
|-&lt;br /&gt;
| 6&lt;br /&gt;
| File upload page #2&lt;br /&gt;
| bricks/upload-2/&lt;br /&gt;
| [http://sechow.com/bricks/docs/file-upload-2.html Text], [http://www.youtube.com/watch?v=tsDClYorsXI Video]&lt;br /&gt;
|-&lt;br /&gt;
| 7&lt;br /&gt;
| Log in page #3&lt;br /&gt;
| bricks/login-3/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-3.html Text], [http://www.youtube.com/watch?v=Glsl-UR2OmU Video]&lt;br /&gt;
|-&lt;br /&gt;
| 8&lt;br /&gt;
| Content page #3&lt;br /&gt;
| bricks/content-3/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-3.html Text], [http://www.youtube.com/watch?v=qWpqZbymsl8 Video]&lt;br /&gt;
|-&lt;br /&gt;
| 9&lt;br /&gt;
| Log in page #4&lt;br /&gt;
| bricks/login-4/&lt;br /&gt;
| [http://sechow.com/bricks/docs/login-4.html Text], [https://www.youtube.com/watch?v=z4JUplVRG1U Video]&lt;br /&gt;
|-&lt;br /&gt;
| 10&lt;br /&gt;
| Content page #4&lt;br /&gt;
| bricks/content-4/&lt;br /&gt;
| [http://sechow.com/bricks/docs/content-page-4.html Text]&lt;br /&gt;
|-&lt;br /&gt;
| 11&lt;br /&gt;
| File upload page #3&lt;br /&gt;
| bricks/upload-3/&lt;br /&gt;
| Open for public&lt;br /&gt;
|-&lt;br /&gt;
| 12&lt;br /&gt;
| Log in page #5&lt;br /&gt;
| bricks/login-5/&lt;br /&gt;
| Open for public&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
= Road map =&lt;br /&gt;
# Demonstrate maximum variations of most common vulnerabilities&lt;br /&gt;
# Help people to learn the need of secure codding practices and SSDLC&lt;br /&gt;
# Attract people to design more bricks&lt;br /&gt;
# Become a test bed for analyzing the performance of web application security scanners.&lt;br /&gt;
# Help people learn the manual method of testing the applications&lt;br /&gt;
# Demonstrate the possibilities of various security tools and techniques&lt;br /&gt;
# Become a platform to teach web application security in a class room/lab environment.&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
=Project About=&lt;br /&gt;
{{:Projects/OWASP_Bricks}} &lt;br /&gt;
[[Category:OWASP Project|Bricks]]&lt;br /&gt;
[[Category:OWASP Download|Bricks]]&lt;br /&gt;
[[Category:OWASP Tool|Bricks]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool|Bricks]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks&amp;diff=159785</id>
		<title>Projects/OWASP Bricks</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks&amp;diff=159785"/>
				<updated>2013-10-05T06:56:07Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name =OWASP Bricks&lt;br /&gt;
| project_home_page =OWASP_Bricks&lt;br /&gt;
| project_description =Bricks, a deliberately vulnerable web application built on PHP &amp;amp; MySQL focuses on variations of commonly seen application security vulnerabilities &amp;amp; exploits, which can be exploited using tools (Mantra &amp;amp; ZAP). The mission is to 'break the bricks'.&lt;br /&gt;
| project_license =Apache 2.0 License  (fewest restrictions, even allowing proprietary modifications and proprietary forks of your project)&lt;br /&gt;
| leader_name1 =Abhi M Balakrishnan&lt;br /&gt;
| leader_email1 =abhi.balakrishnan@owasp.org&lt;br /&gt;
&lt;br /&gt;
| pamphlet_link = https://www.owasp.org/images/c/c9/OWASP_Bricks_Project_Pamphlet.pdf&lt;br /&gt;
| presentation_link = https://www.owasp.org/index.php/File:OWASP_Bricks_Presentation_Slides.pptx&lt;br /&gt;
&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp_bricks&lt;br /&gt;
| project_road_map = https://www.owasp.org/index.php/Projects/OWASP_Bricks/Roadmap&lt;br /&gt;
| release_1 = Narmada&lt;br /&gt;
| release_2 = Betwa&lt;br /&gt;
| release_3 = Feni&lt;br /&gt;
| release_4 = Torsa&lt;br /&gt;
| release_5 = Punpun&lt;br /&gt;
| release_6 = Lachen&lt;br /&gt;
| release_7 = Raidak&lt;br /&gt;
| release_8 = Phalgu&lt;br /&gt;
| release_9 = Atrai&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASP_Bricks_Barak.jpg&amp;diff=159784</id>
		<title>File:OWASP Bricks Barak.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASP_Bricks_Barak.jpg&amp;diff=159784"/>
				<updated>2013-10-05T06:54:01Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: http://owaspbricks.blogspot.in/2013/10/owasp-bricks-19-barak-release.html&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;http://owaspbricks.blogspot.in/2013/10/owasp-bricks-19-barak-release.html&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Barak&amp;diff=159783</id>
		<title>Projects/OWASP Bricks/Releases/Barak</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Bricks/Releases/Barak&amp;diff=159783"/>
				<updated>2013-10-05T06:51:42Z</updated>
		
		<summary type="html">&lt;p&gt;Abhi M Balakrishnan: Barak&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template: &amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Release About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Bricks&lt;br /&gt;
| project_home_page = OWASP Bricks&lt;br /&gt;
| release_name = Barak&lt;br /&gt;
| release_date = 05/10/2013&lt;br /&gt;
| release_description = &lt;br /&gt;
&lt;br /&gt;
'''This is the tenth public release.'''&lt;br /&gt;
&lt;br /&gt;
| release_license = [http://www.apache.org/licenses/LICENSE-2.0 Apache License 2.0]&lt;br /&gt;
| release_download_link = http://sechow.com/bricks/download.html&lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Abhi M Balakrishnan &lt;br /&gt;
| leader_email1 = abhi@getmantra.com&lt;br /&gt;
| leader_username1 = Abhi_M_Balakrishnan&lt;br /&gt;
&lt;br /&gt;
| release_notes = http://owaspbricks.blogspot.in/2013/10/owasp-bricks-19-barak-release.html&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
==Screenshot==&lt;br /&gt;
[[Image:OWASP Bricks Barak.jpg|600px|OWASP Bricks Barak]]&lt;/div&gt;</summary>
		<author><name>Abhi M Balakrishnan</name></author>	</entry>

	</feed>