This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Category:OWASP Testing Project"

From OWASP
Jump to: navigation, search
(Welcome to the new OWASP Testing Guide)
(Redirected page to OWASP Testing Project)
 
(33 intermediate revisions by 6 users not shown)
Line 1: Line 1:
{{OWASP Book|1375886}}
+
#redirect [[:OWASP Testing Project]]
 
 
[[:Category:OWASP Project|Click here to return to OWASP Projects page.]]<br>
 
[[:Project Information:template Testing Guide 3.0|Click here to see (& edit, if wanted) the template.]]
 
{{:Project Information:template Testing Guide 3.0}}
 
 
 
 
 
== Welcome to the new OWASP Testing Guide ==
 
 
 
=== OWASP Testing Guide v3 ===
 
 
 
6th November 2008: OWASP Testing Guide v3 will be published [[Image:OWASP_Testing_Guide_v3.pdf here]]
 
 
 
26th April 2008: Thanks to the [http://www.owasp.org/index.php/OWASP_Summer_0f_Code_2008_:_Selection SoC 08 results] the planning stage has started for version 3.0 of the Testing Guide. If you have knowledge and experience in application testing, and can spare a few hours a week, please do get in [mailto:[email protected] touch]. Alternatively you can join the [http://lists.owasp.org/mailman/listinfo/owasp-testing OWASP Testing mailing list]. The project is lead by [[User:Mmeucci|Matteo Meucci]].
 
 
 
'''Testing Guide v3: plan'''
 
 
 
'''Project deadlines:'''<br>
 
'''I phase: create the Index'''
 
Call for participation.
 
[http://www.owasp.org/index.php/OWASP_Testing_Guide_v3_Startup Index brainstorming]
 
Discuss the article content.
 
<br>Deadline: Sun 18th May 2008.
 
 
 
'''II phase: start writing'''
 
After creating the new [https://www.owasp.org/index.php/OWASP_Testing_Guide_v3_Table_of_Contents Index], we will assign each paragraph to the volunteers, start writing!
 
Each author will write the article on the wiki and reviewed by the OWASP Testing guide team.
 
<br>Deadline: 30th June 2008
 
 
 
'''III phase: start reviewing'''
 
Create the reviewer team. Assign each new paragraph to the reviewer.
 
<br>Deadline: 20th July 2008
 
 
 
'''IV phase: finish writing'''
 
<br>Deadline: 24th August 2008
 
 
 
'''V phase: finish reviewing'''
 
Finish the reviewing phase
 
<br>Deadline: 31st August 2008
 
 
 
'''VI phase: Finalize the Guide'''
 
Create the doc and pdf format of the v3.
 
<br>Deadline: 6th November 2008
 
 
 
 
 
===Roadmap===
 
 
 
View the [[OWASP Testing Project v3 Roadmap]]
 
 
 
 
 
=== Background and Motivation ===
 
 
 
'''History Behind Project'''
 
The Testing guide originated in 2003 with Dan Cuthbert as one of the original editors. It was handed over to [[User:EoinKeary|Eoin Keary]] in 2005 and transformed into a wiki.
 
Being a wiki it is easier for people to contribute and should make updating much easier.
 
[[User:Mmeucci|Matteo Meucci]] has decided to take on the Testing guide and update it creating the OWASP Testing Guide v2.
 
 
 
Now it's time to create a new Guide, improving each chapter and adding the new testing methodologies.
 
 
 
The OWASP Testing Guide is a defacto web application security assessment guide.
 
 
 
===Overview===
 
 
 
This projects goal is to create a "best practices" penetration testing framework which users can implement in their own organizations and a "low level" penetration testing guide that describes how to find certain issues.
 
 
 
===Volunteers needed===
 
Positions for v3 of the guide are now open!
 
 
 
If you have knowledge and experience in application testing, and can spare a few hours a week, please do get in [mailto:[email protected] touch]
 
 
 
===Testing Project Phase Three Guide(draft) ===
 
 
 
This is the working draft of the OWASP Testing Guide v3. Please login to make changes as you see fit. Changes will be vetted by the OWASP Testing Project team.
 
 
 
[[OWASP Testing Guide v3 Table of Contents|OWASP Testing Guide v3 Table of Contents]]
 
 
 
== Project History ==
 
 
 
===  OWASP Testing Guide v2 (stable release) ===
 
 
 
'''10th February 2007: The OWASP Testing Guide v2 is now published''' [[User:Mmeucci|Matteo Meucci]] (as part of his [[OWASP_Autumn_of_Code_2006_-_Projects:_Testing_Guide | AoC project]]) has just published the latest version of Testing guide which:
 
* you can read it on line on the [http://www.owasp.org/index.php/OWASP_Testing_Guide_v2_Table_of_Contents  Testing Guide v2 wiki]
 
* or download the Guide in [http://www.owasp.org/index.php/Image:OWASP_Testing_Guide_v2_pdf.zip Adobe PDF format] or in [http://www.owasp.org/index.php/Image:OWASP_Testing_Guide_v2_doc.zip Ms Doc format]
 
 
 
'''OWASP Testing Guide v2 in Spanish:''' Now you can get a complete translation in [http://www.owasp.org/index.php/Image:OWASP_Testing_Guide_v2_spanish_doc.zip Ms Doc format]
 
 
 
For comments or questions, please join the [http://lists.owasp.org/mailman/listinfo/owasp-testing OWASP Testing mailing list], read our archive and share your ideas. Alternatively you can contact [[User:EoinKeary|Eoin Keary]] or [[User:Mmeucci|Matteo Meucci]] directly.
 
 
 
Here you can find:
 
* [http://www.owasp.org/index.php/Testing_Guide_Quotes The OWASP Testing Guide 'Quotes']
 
* [http://www.owasp.org/index.php/OWASP_Testing_Guide_Presentations Testing Guide presentations]
 
 
 
 
 
=== The OWASP Testing Guide v2 - Request for Review ===
 
 
 
'''10th January 2007: The OWASP Testing Guide v2 is now in its final stages''' [[User:Mmeucci|Matteo Meucci]] (as part of his [[OWASP_Autumn_of_Code_2006_-_Projects:_Testing_Guide | AoC project]]) has just published the latest version of Testing guide which:
 
* you can read it on line on the [http://www.owasp.org/index.php/OWASP_Testing_Guide_v2_Table_of_Contents  Testing Guide v2 wiki - 'Release Candidate 1']
 
* or download the Guide in [http://www.owasp.org/index.php/Image:OWASP_Testing_Guide_v2_RC1_pdf.zip Adobe PDF format] or [http://www.owasp.org/index.php/Image:OWASP_Testing_Guide_v2_RC1_doc.zip Ms Doc format]
 
 
 
'''So what we need now (until 10th of February) is for you to review it.''' Please let us know any mistakes made, and if you feel that there is something missing, please help yourself and edit the relevant WIKI page.
 
 
 
For comments or questions, please use the 'Discussion' pages or email [[User:EoinKeary|Eoin Keary]] or [[User:Mmeucci|Matteo Meucci]]  directly.
 
 
 
The current plan is to create a 'published' version of this guide on the 10th of February which will be sent to all OWASP members in book format.
 
 
 
If you want to participate see the [[OWASP_Testing_Project_v2.0_-_Review_Guidelines]] page for the lastest updates
 
 
 
 
 
=== Old Testing Guide Download===
 
 
 
A copy of the old guide (The OWASP Testing Guide v1.1) is available [[http://prdownloads.sourceforge.net/owasp/OWASPWebAppPenTestList1.1.pdf?download here]], it shall also be  available in HTML format on the forthcoming OWASP Live CD.
 
A PDF copy shall also be available to download.
 
 
 
'''OWASP Pen Test Checklist in Italian'''
 
Sun May 22 10:56:39 EDT 2005
 
I'm glad to announce we have released OWASP Pen Test Checklist in Italian. Thanks to the Italian Chapter, Massimiliano and Matteo for it's great effort to have this document translated. You can download this version in [http://www.owasp.org/docroot/owasp/misc/OWASPWebAppPenTestList1.1_ITA.pdf PDF] or [http://www.owasp.org/docroot/owasp/misc/OWASPWebAppPenTestList1.1_ITA.doc Word]
 
 
'''Checklist ver 1.17 in Spanish'''
 
Mon Apr 04 15:37:24 EDT 2005
 
I'm glad to announce we have released OWASP Pen Test Checklist ver 1.17 in Spanish.Thanks to Pedro, Raul and Rogelio for it's great effort to have this document translated and to Christian by helping out with technical edition. You can download this version  [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf PDF] or [http://www.owasp.org/docroot/owasp/misc/testing_spanish.doc Word]
 
 
 
 
 
=== Related ===
 
 
 
'''Online Checklist Report Generator''' is found at [http://yehg.net/lab/pr0js/misc/wasarg_owasp-tgv2.php yehg].
 
 
 
'''THE OWASP Testing Project Live CD'''
 
The OWASP testing project is currently implementing an Application security Live CD. <br>
 
LabRat Version 0.8 Alpha is just weeks away from Beta testing*.
 
 
 
The aim of this CD is to have a complete testing suite on one Disk. The CD shall also contain the forthcoming OWASP Testing guide.
 
 
 
The Live CD now has its own section you can find it here:
 
[http://www.owasp.org/index.php/Category:OWASP_Live_CD_Project]
 
 
 
==Feedback and Participation==
 
 
We hope you find the information in the OWASP Testing project useful. Please contribute back to the project by sending your comments, questions, and suggestions to the OWASP Testing mailing list. Thanks!
 
 
 
To join the OWASP Testing mailing list or view the archives, please visit the [http://lists.owasp.org/mailman/listinfo/owasp-testing subscription page].
 
 
 
 
 
[[Category:OWASP Project]]
 

Latest revision as of 17:00, 6 October 2010

Subcategories

This category has only the following subcategory.

O

Pages in category "OWASP Testing Project"

The following 200 pages are in this category, out of 245 total.

(previous page) (next page)

4

T

(previous page) (next page)

Media in category "OWASP Testing Project"

This category contains only the following file.