This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP WebSpa Project"

From OWASP
Jump to: navigation, search
m (Roadmap)
(News)
 
(6 intermediate revisions by 4 users not shown)
Line 1: Line 1:
 
=Main=
 
=Main=
 
+
<div style="width:100%;height:90px;border:0,margin:0;overflow: hidden;">[[File:Incubator_big.jpg|link=OWASP_Project_Stages#tab=Incubator_Projects]]</div>
 
{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 
{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 
| valign="top"  style="border-right: 1px dotted gray;padding-right:25px;" |
 
| valign="top"  style="border-right: 1px dotted gray;padding-right:25px;" |
Line 45: Line 45:
 
== Quick Download ==
 
== Quick Download ==
  
[http://sourceforge.net/projects/webspa/files/webspa-07.zip/download WebSpa v0.7]
+
Release:<br>
 +
[http://sourceforge.net/projects/webspa/files/webspa-08.zip/download WebSpa v0.8]
 +
 
 +
Source:<br>
 +
[https://github.com/OWASP/WebSpa/archive/v0.8.zip| WebSpa v0.8.zip]<br>
 +
[https://github.com/OWASP/WebSpa/archive/v0.8.tar.gz| WebSpa v0.8.tar.gz]
  
 
==Classifications==
 
==Classifications==
Line 260: Line 265:
 
= News =
 
= News =
  
 +
* [19 Feb 2015] The source WebSpa code repository has been migrated to GitHub. The compiled releases (.jar) are still made available on SourceForge.
 +
* [17 Feb 2015] WebSpa has a new contributor – Daniel Imber. Dan, welcome to the team!
 +
* [12 Jan 2015] Patryk Arciszewski decided to retire from the project. Patryk, thank you for your good work and may the Power of SPA be with you.
 +
* [23 Nov 2014] Version 0.8 has been released and can now be found in the download section. We are proud to offer a working, stable proof-of-concept of WebSpa.
 
* [19 Aug 2014] Our project was featured in the OWASP Connector newsletter. [http://hosted-p0.vresp.com/1479611/4d8d3315c2/ARCHIVE (link)]
 
* [19 Aug 2014] Our project was featured in the OWASP Connector newsletter. [http://hosted-p0.vresp.com/1479611/4d8d3315c2/ARCHIVE (link)]
 
* [07 May 2014] Added four video links in the respective "Video" tab, referencing YouTube
 
* [07 May 2014] Added four video links in the respective "Video" tab, referencing YouTube
* [24 Apr 2014] Version 0.7 has been release and can now be found in the download section. Also, we welcome Paweł and Joël to the team.
+
* [24 Apr 2014] Version 0.7 has been release and can now be found in the download section. Also, we welcome Joël to the team.
 
* [20 Mar 2014] [http://www.eventbrite.co.uk/e/owasp-london-chapter-meeting-march-2014-tickets-10063386861 WebSpa has been presented during OWASP London Chapter Meeting]
 
* [20 Mar 2014] [http://www.eventbrite.co.uk/e/owasp-london-chapter-meeting-march-2014-tickets-10063386861 WebSpa has been presented during OWASP London Chapter Meeting]
* [16 Mar 2014] WebSpa has a new contributor – Paweł Goleń. Paweł welcome in the team!
+
* [16 Mar 2014] WebSpa has a new contributor – Paweł Goleń. Paweł, welcome to the team!
 
* [14 Mar 2014] [https://code.google.com/p/web-spa/ Scheduled the deletion of the Google code project, given that downloads require a new account]
 
* [14 Mar 2014] [https://code.google.com/p/web-spa/ Scheduled the deletion of the Google code project, given that downloads require a new account]
 
* [04 Mar 2014] [https://soundcloud.com/#owasp-podcast/the-owasp-webspa-project-with The WebSpa podcast has now been available!]  
 
* [04 Mar 2014] [https://soundcloud.com/#owasp-podcast/the-owasp-webspa-project-with The WebSpa podcast has now been available!]  
Line 272: Line 281:
  
 
=FAQs=
 
=FAQs=
 +
 +
; Does WebSpa supports older versions of Java?
 +
: No. WebSpa is tested with an up-to-date JRE package, thus to run WebSpa a JRE 1.7 or greater is needed.
 +
Using older versions of Java may lead to unexpected system behaviors.
  
 
; What does the ASCII-Art for WebSpa look like?
 
; What does the ASCII-Art for WebSpa look like?
Line 305: Line 318:
 
Active contributors:
 
Active contributors:
 
* [[User:Yiannis|Yiannis Pavlosoglou]] - Inception & Development  
 
* [[User:Yiannis|Yiannis Pavlosoglou]] - Inception & Development  
* Patryk Arciszewski - Theoretician & Documentation
 
 
* Paweł Goleń - Breaking & Infrastructure  
 
* Paweł Goleń - Breaking & Infrastructure  
 
* Joël Rouiller - Development & Optimisation
 
* Joël Rouiller - Development & Optimisation
 +
* Daniel Imber - Development & Refactoring
 
* [[User:Oliver_M.|Oliver Merki]] - Leader & Operations
 
* [[User:Oliver_M.|Oliver Merki]] - Leader & Operations
  
Line 313: Line 326:
 
Retired contributors:
 
Retired contributors:
 
* [[User:Dr. Markus Maria Miedaner|Markus Maria Miedaner]]
 
* [[User:Dr. Markus Maria Miedaner|Markus Maria Miedaner]]
 +
* Patryk Arciszewski
  
 
= Roadmap =
 
= Roadmap =
Line 318: Line 332:
 
== Release 0.9 (Q3/2015) ==  
 
== Release 0.9 (Q3/2015) ==  
  
WebSpa_v0.9 will be major release and include a comprehensive redesign of the WebKnock format in order to improve overall security and robustness of the request. The tickets for this release are:
+
WebSpa_v0.9 will be major release and include a comprehensive redesign of the WebKnock format in order to improve overall security and robustness of the request, but also offer improved usability features, which will simplify installing, configuring and running WebSpa.. The tickets for this release are:
  
 
  44 New WebKnock request format should be defined
 
  44 New WebKnock request format should be defined
Line 324: Line 338:
 
  35 A threat model for WebSpa should be created and reviewed  
 
  35 A threat model for WebSpa should be created and reviewed  
 
  33 Apache should be replaced by nginx  
 
  33 Apache should be replaced by nginx  
 
== Release 0.85 (Q1/2015) ==
 
WebSpa_v0.85 will offer improved usability features, which will simplify installing, configuring and running WebSpa. The tickets for this release are:
 
 
40 Log to /​var/​log instead of a log.txt file
 
 
  15 Add easy way to run the server as a background daemon    
 
  15 Add easy way to run the server as a background daemon    
  
== Release 0.8 (Q4/2014) ==
+
== [http://sourceforge.net/projects/webspa/files/webspa-08.zip/download Release 0.8 (Q4/2014)] ==
  
WebSpa_v0.8 will be sort of a proof-of-concept of WebSpa. A stable version to demonstrate the concept of WebKnocking, however, with some limitations with regards to usability/configuration and modularity (e.g. changing the hashing algorithm). The tickets for this release are:
+
WebSpa_v0.8 is sort of a proof-of-concept of WebSpa. A stable version to demonstrate the concept of WebKnocking, however, with some limitations with regards to usability/configuration and modularity (e.g. changing the hashing algorithm). The tickets for this release are:
  
 
  43 Change SSL configuration to allow wget
 
  43 Change SSL configuration to allow wget
 
  41 WebSpa administrator to WebSpa user output  
 
  41 WebSpa administrator to WebSpa user output  
 +
40 Log to /​var/​log instead of a log.txt file
 
  38 umask 077 should be added to webspa.sh  
 
  38 umask 077 should be added to webspa.sh  
 
  32 A known_hosts file should be used to maintain the list of successfully verified keys  
 
  32 A known_hosts file should be used to maintain the list of successfully verified keys  
 
  31 Verification of server's public key fingerprint should be possible  
 
  31 Verification of server's public key fingerprint should be possible  
 
  30 Help Files Update (0.8)  
 
  30 Help Files Update (0.8)  
  27 Arrays.equals is not a constant time function
+
  - FIXED: Modified the checking of 2 arrays being equal to be constant in time (Ticket #27)
 
  2 Create maven build task for release  
 
  2 Create maven build task for release  
  

Latest revision as of 15:54, 19 March 2015

Incubator big.jpg

OWASP WebSpa Project

The OWASP WebSpa Project is a Java web knocking tool for sending a single HTTP/S request to your web server in order to authorize the execution of a premeditated Operating System (O/S) command. It provides a cryptographically protected "open sesame" mechanism on the web application layer, comparable to well-known port-knocking techniques.

Description

This project implements the concept of web knocking by offering a jar file that 'tails' the access log of an existing web server. A user submits a specially crafted URL, therefore executing a predefined O/S command. No new ports or services are created.

Similarly to traditional network port-knocking schemes, the OWASP WebSpa Project aims to create a covert channel of communication for O/S commands over the web application layer. This channel is by no means bi-directional: It is only the client that can issue commands to the server. The inverse, i.e. the server issuing commands to the client, is not an option within the current version.

If port knocking is defined as "a form of host-to-host communication in which information flows across closed ports" then we define web knocking as "a form of host-to-host communication in which information flows across erroneous URLs". Finally, in an attempt to mirror the operation of Single Packet Authorisation (SPA), the entirety of a user's action is submitted through a single GET request.

Licensing

The OWASP WebSpa Project is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.

The source code that comes with the OWASP WebSpa Project in the form of the tool named WebSpa is released as open source software under the terms of the GNU Public License (GPL) version 3. For reference, the full text of the GPL_v3 can be downloaded from the Free Software Foundation. There are no plans to change the license; WebSpa will always remain an open source project free for use by anyone subject to the terms of the license.


What is WebSpa?

OWASP WebSpa provides:

  • A secure channel for executing premeditated O/S commands on your web server
  • A resource-efficient single jar-file that can either be run as server, or client application, depending on the command line parameters


Presentation

http://sourceforge.net/projects/webspa/



Quick Download

Release:
WebSpa v0.8

Source:
WebSpa v0.8.zip
WebSpa v0.8.tar.gz

Classifications

Owasp-incubator-trans-85.png Owasp-builders-small.png
Owasp-defenders-small.png
Cc-button-y-sa-small.png
Project Type Files CODE.jpg