This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Wiki sandbox

From OWASP
Jump to: navigation, search
Fortify_Defender.gif
Sponsored advertisement. OWASP does not endorse commercial products or services     


Welcome to OWASP
the free and open application security community
About · Searching · Editing · New Article · OWASP Categories Statistics · Recent Changes

Every vibrant technology marketplace needs an unbiased source of information on best practices as well as an active body advocating open standards. In the Application Security space, one of those groups is the Open Web Application Security Project™ (or OWASP for short).

The Open Web Application Security Project (OWASP) is a 501(c)(3) worldwide not-for-profit charitable organization focused on improving the security of software. Our mission is to make software security visible, so that individuals and organizations are able to make informed decisions. OWASP is in a unique position to provide impartial, practical information about AppSec to individuals, corporations, universities, government agencies, and other organizations worldwide. Operating as a community of like-minded professionals, OWASP issues software tools and knowledge-based documentation on application security.

Everyone is free to participate in OWASP and all of our materials are available under a free and open software license. You'll find everything about OWASP here on or linked from our wiki and current information on our OWASP Blog. OWASP does not endorse or recommend commercial products or services, allowing our community to remain vendor neutral with the collective wisdom of the best minds in software security worldwide.

We ask that the community look out for inappropriate uses of the OWASP brand including use of our name, logos, project names, and other trademark issues.

There are thousands of active wiki users around the globe who review the changes to the site to help ensure quality. If you're new, you may want to check out our getting started page. As a global group of volunteers with over 45,000 participants, questions or comments should be sent to one of our many mailing lists focused on a topic or directed to the staff using the OWASP Contact Us Form.

Pick an OWASP Project - Find Your Local OWASP Chapter

Flagship Projects

Projects that have demonstrated strategic value to OWASP and application security as a whole

Tool Projects
Automatically finds security vulnerabilities in your web applications while you are developing and testing your applications
A collection of easy-to-use application security tools and documentation available in multiple formats
Pentesting tool to more efficiently find, verify and combine vulnerabilities in short timeframes
A utility that identifies project dependencies and checks if there are any known, publicly disclosed, vulnerabilities
A web and mobile application security training platform to foster and improve security awareness among a varied skill-set demographic
An open source vulnerability management tool that streamlines the testing process by offering templating, report generation, metrics, and baseline self-service tools
An intentionally insecure webapp for security trainings written entirely in JavaScript which encompasses the entire OWASP Top Ten and other severe security flaws
A tool that is used as a guide for building and verifying secure software that can also be used to train developers about application security
A Software Composition Analysis (SCA) platform that keeps track of all third-party components used in all the applications an organization creates or consumes. It monitors all applications in its portfolio in order to proactively identify vulnerabilities in components that are placing your applications at risk
Code Projects
A set of generic attack detection rules for use with ModSecurity or compatible web application firewalls which aims to protect web applications from a wide range of attacks
A library that implements a variant of the synchronizer token pattern to mitigate the risk of Cross-Site Request Forgery (CSRF) attacks
Documentation Projects
Provides a basis for testing web application technical security controls and also provides developers with a list of requirements for secure development
A conceptual framework and methodology that offers prescriptive guidance to implement intrusion detection and automated response into applications
An open framework to help organizations formulate and implement a strategy for software security that is tailored to the specific risks facing the organization
A powerful awareness document for web application security that represents a broad consensus about the most critical security risks to web applications
Includes a "best practice" penetration testing framework which users can implement in their own organizations and a "low level" penetration testing guide that describes techniques for testing most common web application and web service security issues
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics. These cheat sheets were created by various application security professionals who have expertise in specific topics.
A security standard for mobile apps and a comprehensive testing guide that covers the processes, techniques, and tools used during a mobile app security test, as well as an exhaustive set of test cases that enables testers to deliver consistent and complete results.

Thank-you-word-cloud-1024x791.jpg

Thank you to our our corporate supporters that enable us to make software security visible, so that individuals and organizations worldwide can make informed decisions about true software security risks. A complete list of our current corporate and academic supporters can be found on our Acknowledgements Page





Hundreds of Hours of AppSec Videos



Stack-of-books.jpg

Citations

Who Trusts OWASP?
Citations of National & International Legislation, Standards, Guidelines, Committees and Industry Codes of Practice - Click Here
Book-cup2.png

OCoC

How can OWASP help your org?
Government Bodies
Educational Institutions
Standards Groups
Trade Organizations
Certifying Bodies
Development Organizations

Security101

Ask a software security question on our Slack channel - open to all, experts to beginners
Podium-icon.jpg

Upcoming Events

Security Conferences, Training
Global, Regional and Local - Click Here
ProjectIcon 1.png

Start a Project

How to Start an OWASP Project

New Project

How to update an existing project

Existing Project

My recent documents.gif

News

OWASP News

OWASP in the news: An excellent article on OWASP and the Internet of Things
OWASP newsletters report on events, projects, people, tools, updates Sign Up Here...

Social-networking.png

Social Media

Blog-icon-200.png

Blog

OWASP Blog
The OWASP blog has global announcements - Click Here
Podcast.png

Podcast

Security Podcast
Listen as interviews are conducted with OWASP volunteers, industry experts Click Here
Globe Icon House 1330502.jpg

Start a Chapter

OWASP Chapters

Start/Locate a Local Chapter

QuestionMark.png

Contact Us

Got Questions?
Please submit your questions, comments and requests and our staff will help Click Here




Click here for a brief description of our Corporate Members
Click here for more information on our Membership packages or Join Now BlueIcon.JPG

Accuvant_Labs.jpg        Acunetix_logo_200.png        Adobe_logo.png        Adp.jpg        Akamai_Logo_resized.png        Amazon_Logo.jpg        Architectgroup_130131.png        Arxan_Logo_for_OWASP-_Resized.jpg        Astech.jpg        Aspect_Logo.png        Bccriskadvisory_logo_for_owasp_acknowlegements_webpage_150_by_45px.png        BestBuy_Logo_Resized.png        Blackhat-black.png        Bah-color.PNG        Checkmarx_logo_resized.png        Cigital_OWASP.GIF        Cloudfair_logo.png        Cloud_Passage_Logo.png        Coverity_Logo.png        Dbapp_logo.jpg        Denim_Group_Logo.gif        Dropbox_resized_logo.png        ELearnSecurity_owasp_150-45.png        Ernst_%26_Young_Logo_Resized.png        FICO-logo-108px.gif        Fishnet_Logo_Resized.png        Gemalto_brand.jpg        GDS_LOGO_SMALL.jpg        AppSecDC2012-HP.jpg        Ibm_Logo.jpg        Imperva_2color_RGB.jpg        IBI_Logo.jpg        IpswitchFT_logo_138-80.png        ISC2_main_logo-small.jpg        Lynx_Logo.png        MONITORAPP_Logo.png        Mozilla.png        Mstar_logo.jpg        NetSparker_Logo_Resized7-3-13.png        Netspi_logo.png        Nokia.jpg        OneConsult_Logo.jpg        Oracle_logo.gif        PARASOF_Logo.gif        PI_LinearLogo.png        Protiviti.jpg        PWC_log_resized.png        Qualys_Logo.gif        Quotium_with_Seeker_Logo.png        Rakuten-Global-150x45_72dpi.JPG        Rackspace_logo_Resized.png        Riverbed_Logo.png        Salesforce_logo_resized.png        Sys_scsk_logo_banner_3.jpg        Security_Innovation_Logo_150x41.jpg        Sonatype_Logo_Resized.png        SWAMP_Logo.png        Trent_Micro.jpg        SPL-LOGO-SMALL.png        Twitter-bird-blue-on-white_sized.png        UPS.jpg        VeraCode_Resized.png        Whitehat.gif       

 

Academic Supporters Join Today

AdelphiLogo-105x45.png        Aut.jpg        AngliaRuskinLogo.png        Auburn.jpg        LogoBFHforOWASP.gif        CU-72dpi.jpg        Cit_logo.gif        Dartmouth_BW.png        Dsulogo.jpg        Dculogo3.gif        LOGO_EPN.jpg        Logo_Postgrado.PNG        Fatec.jpg        Fhb_logo.gif        FOI-vert-1.jpg        FORDHAM_UNIVERSITY_LOGO_RESIZSED.jpg        Kuleuven.jpg        GTISCLogo.gif        HSLogo.gif        HEIG-VD_logo_couleur_small.jpg        Logo_Hochschule_Furtwangen_University.jpg        298px-University_of_Hyderabad_Logo.svg.png        IDC_Arazi_E_Black.jpg        Iscte-iul-logo.png        TecnologicoMonterrey.png        Logo_ISEP_pour_le_Web.jpg        IT_Blanchardstown.jpg        Korea_University_Logo.jpg        MIT_logo.gif        Logotype-int-miun.png        NYP_Logo_vert_300.jpg        Nlu_logo.png        LogoORT.png        Pace_University_Logo.png        RHUL_logo_WEB_289x85pix_72dpi.png        Uw-university.gif        TCD_logo_stacked.jpg        Logo_sgu-01_copy_copy.jpg        Stevens-Official-Logo-Preview.jpg        Logotei_thessaloniki.jpg        TPLOGO_master.jpg        Ucirvine_07_bluhex_sm3.jpg        Nku_main-logo.gif        Northumbrialogo.jpg        UNT.gif        Gw_stack_black.gif        Poly-nyu-logo.jpg        TEIL.jpg        Logo_fiuba_baja.gif        Ucla_cw125.gif        Logo_udemm.jpg        UCV2_%281%29.jpg        UISRAEL_small_OK.jpg        Ukl.jpg        University_of_British_Columbia_Logo.png        UnivID_G_CC9900_O_T.gif        TEXWordmark.jpg       

Supporters
Click here for more information on our Membership packages or Join Now BlueIcon.JPG