|
|
(50 intermediate revisions by 10 users not shown) |
Line 1: |
Line 1: |
− | This page is for people to post OWASP related news items, like new releases, updates, or announcements. If the news is about application security but NOT OWASP-specific, please post it to [[Application Security News]]. This page is monitored, and particularly important stories will be copied to the front page. | + | This page is for people to post OWASP related news items, like new releases, updates, or announcements. If the news is about application security but NOT OWASP-specific, please post it to [[Application Security News]]. |
| | | |
− | Please post new items at the top of the list using the following format:
| + | For older stories, please refer to the following pages: |
| + | * '''[[OWASP News 2006]] |
| + | * '''[[OWASP News 2007]] |
| | | |
− | <nowiki>
| + | This page is monitored, and stories will be copied to the OWASP [[Main Page]]. Please post new items at the top of the list using the following format: |
− | ; '''Mon ## - [[OWASP Project|Headline for announcement]]''' | + | |
− | : Details... | + | ; '''Mon ## - [[OWASP Project|Headline for announcement]]''' |
− | </nowiki>
| + | : Details... |
| | | |
| ==Stories== | | ==Stories== |
− | ; '''Sep 26 - [http://www.infosecurityevent.com Infosecurity NY 2006 20% OWASP Discount]'''
| |
− | : OWASP Members are entitled to a discount off full conference registration – a $200 savings! Conference is October 24-25 at the Jacob Javits Convention Center, NYC. [http://www.infosecurityevent.com/app/homepage.cfm?appname=100004&moduleid=0&campaignid=9294660 Register today] and provide Priority Code CD25 to receive your discount.
| |
− |
| |
− | ; '''Sep 7 - [https://www.pcisecuritystandards.org/pdfs/pci_dss_v1-1.pdf New PCI requires code review or WAF]'''
| |
− | : Under the new requirements, applications processing cardholder information MUST get either a [[:Category:OWASP Code Review Project|code review]] or a [[web app firewall]]. The language isn’t exactly clear about what happens in 2008. In addition, the OWASP [[Top Ten]] must still be addressed.
| |
− |
| |
− | ; '''Aug 31 - [[OWASP Autumn Of Code 2006 : Press Release | OWASP Autumn Of Code 2006]]'''
| |
− | : Today we are lauching a new project called "OWASP Autumn of Code 2006" which will sponsor individuals to work on existing OWASP Projects.
| |
− |
| |
− | ; '''Aug 31 - [http://video.google.com/videoplay?docid=941077664562737284 Dinis Cruz video interview]'''
| |
− | : Dinis talks about .NET security, the future of OWASP, and the brand new [[Autumn of Code]] project.
| |
− |
| |
− | ; '''Aug 31 - [http://www.owasp.org/index.php/Italy#Aug.2C_2006_-_Article_on_Banca_Finanza_magazine Article about OWASP on Banca Finanza magazine]'''
| |
− | : Banca Finanza mag has interviewed Raoul Chiesa talking about the new risks for the on-line banking security. Raoul speaks about OWASP and web application security.
| |
− |
| |
− | ; '''Aug 14 - [http://www.iese.fraunhofer.de/download/Security-Checker-Tools-for-Web-Applications.pdf Detailed analysis of application security tools]'''
| |
− | : Holger Peine of the Fraunhofer Institute compares a number of free tools (WebScarab, Paros, Burp Suite, Spike Proxy), and commercial tools (AppScan, WebInspect, Acunetix). The methodology is quite detailed and uses OWASP's WebGoat and a 'normal' web application.
| |
− |
| |
− | ; '''Aug 14 - [http://www.owasp.org/index.php/Image:Threat_modelling_of_pharming.doc When Phishing Evolves to Pharming]
| |
− | : "Phishing is evolving into a new type of attack called pharming. Pharming redirects users to fraudulent websites seamlessly without any suspicious activity such as spam mail that asks a user to login at a website. This paper analyses possible vectors of pharming and creates a threat model for it with attack tree." OWASP would like to thank Cheong Kai Wee for the submission of this paper! [[:Category:OWASP_Papers|Click here]] for details on submitting your own paper to the [[:Category:OWASP_Papers|OWASP Papers Program]].
| |
− |
| |
− | ; '''Jul 31 - [[:Category:OWASP CAL9000 Project|CAL9000 v1.1 released]]'''
| |
− | : The in-browser JavaScript based web app testing framework has added enhanced encode/decode functions and several bugfixes.
| |
− |
| |
− | ; '''Jul 31 - [[:Category:OWASP Honeycomb Project|Fortify donates vulnerability research to OWASP]]'''
| |
− | : Announcing a new extensive classification of software security vulnerabilities created and donated by Fortify Software Inc. The full set of vulnerabilities and the research that accompanies it is available in the [[:Category:OWASP Honeycomb Project|OWASP Honeycomb Project]].
| |
− |
| |
− | ; '''Jul 11 - [[OWASP AJAX Security Project|Two part interview on Ajax with OWASP's Andrew van der Stock]]'''
| |
− | : In this two part interview, Andrew discusses the key security threats facing Ajax applications and practical advice for securing them. "I expect more Ajax vulnerabilities and exploits to surface, and I expect researchers to come up with additional "new" flaws that need to be protected against."
| |
− |
| |
− | ;'''Jun 29 - [[OWASP_.NET_Project|OWASP .NET Project in now hosted at www.owasp.org]]
| |
− | :Coming full circle, the OWASP .NET Project (lead by Dinis Cruz) is now hosted here at the www.owasp.org website. The objective is to consolidate all Owasp projects in one location, and to benefit from cross projects linkage. All information that was hosted at the previous www.owasp.net wiki has now been ported and in the comming weeks, more will be added.
| |
− |
| |
− | ;'''Jun 26 - [[PHP Top 5|OWASP PHP Top 5 Released]]'''
| |
− | :OWASP is pleased to announce the immediate availability of OWASP [[PHP Top 5]]. The OWASP Top 5 is an education piece which provides up to date advice to PHP developers, hosters, and other PHP users. The Top 5 is produced by the [[:Category:OWASP_PHP_Project|OWASP PHP Project]].
| |
− |
| |
− | ; '''Jun 23 - [[OWASP WebScarab Project|New version of WebScarab released]]'''
| |
− | : The new version has a new logo, several new features, and some bugfixes. There are better capabilities for authentication and certificates, dropping conversations, and searching results. There are plugin enhancements to the spider, session id analyzer, and fuzzer. There's also a new extension for forced browsing to obvious extensions.
| |
− |
| |
− | '''Jun 21 - [http://sectools.org/tools2.html OWASP WebScarab Ranked 35th on Insecure.org's Top 100 Security Tools]'''
| |
− | :Nmap's Fyodor asked users from the nmap-hackers mailing list to share their favorite tools, and 3,243 people responded. This allowed him to expand the list to 100 tools, and even subdivide them into categories. Anyone in the security field would be well advised to go over the list and investigate tools they are unfamiliar with. Respondents were allowed to list open source or commercial tools on any platform.
| |
− |
| |
− | ; '''Jun 20 - [http://www.amazon.com/gp/product/0471789666/sr=8-1/qid=1150819640/002-1402412-9970431 Professional pen testers rely on OWASP]'''
| |
− | : [[Image:pentestbook.jpg|100px|right]] This new book is organized around the OWASP Top Ten, and goes into detail about WebScarab and WebGoat. "OWASP's WebScarab is rock solid and a must-have for any serious Web app pen tester"
| |
− |
| |
− | ; '''Jun 8 - [[:Category:OWASP CAL9000 Project|New OWASP CAL9000 Project Unveiled]]'''
| |
− | : Chris Loomis has created an interesting JavaScript driven web application testing tool that allows manual requests, RSnake powered XSS verification, and many other utilities.
| |
− |
| |
− | ; '''Jun 6 - [[OWASP Java Project]]'''
| |
− | : Stephen de Vries and Rohyt Belani have taken on the OWASP Java project and will be building the project roadmap shortly.
| |
− |
| |
− | ; '''Jun 3 - [[How to test session identifier strength with WebScarab]]'''
| |
− | : New article shows you how to use one of the advanced features of WebScarab!
| |
− |
| |
− | ; '''Jun 1 - [http://www.uribe100.com OWASP selected in top 100 security websites]'''
| |
− | : OWASP has been selected as one of the top 100 security websites. Thanks to everyone who's helped us along the way!
| |
− |
| |
− | ; '''May 26 - [[:Category:OWASP WebGoat Project|OWASP WebGoat 4.0 released]]'''
| |
− | : Lots of new features, including multi-stage hands-on '''coding''' labs for [[Authorization|access control]], [[SQL injection]], and [[Cross Site Scripting|cross site scripting]].
| |
| | | |
− | ; '''May 25 - [[:Category:OWASP CLASP Project|OWASP CLASP project launched]]''' | + | ; '''Jan 14th 2008''' |
− | : Thanks to Secure Software for donating the CLASP materials to bootstrap our [[:Category:Activity|secure lifecycle]] efforts. | + | :[https://www.owasp.org/index.php/Minneapolis_St_Paul Twin Cities Chapter - Presents Bruce Schneier - The Economics of Information Security ] |
| | | |
− | ; '''May 23 - [[About_The_Open_Web_Application_Security_Project|OWASP 2.0 released]]''' | + | ; '''Jan ?? 2008''' |
− | : OWASP is moving to the MediaWiki platform to encourage greater collaboration. We're in the process of moving over all the old content. You can still view the [http://old.owasp.org previous website]. | + | :[link] |
This page is for people to post OWASP related news items, like new releases, updates, or announcements. If the news is about application security but NOT OWASP-specific, please post it to Application Security News.