This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP OWTF"

From OWASP
Jump to: navigation, search
(What is OWTF?)
(Links)
 
(51 intermediate revisions by 4 users not shown)
Line 1: Line 1:
 
=Main=
 
=Main=
 +
<div style="width:100%;height:90px;border:0,margin:0;overflow: hidden;">[[File: flagship_big.jpg|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]</div>
 +
{| class="wikitable sortable" style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 +
| valign="top" style="border-right: 1px dotted gray;padding-right:25px;" |[https://www.openhub.net/p/owasp-owtf/reviews/new Review this project]
  
<div style="width:100%;height:160px;border:0,margin:0;overflow: hidden;">[[File:OWASP_Project_Header.jpg|link=]]</div>
+
[[Image:OWTFLogo.png|right]]
  
{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
+
OWTF aims to make pen testing:
| valign="top"  style="border-right: 1px dotted gray;padding-right:25px;" |
 
  
==OWASP OWTF==
+
* Aligned with OWASP Testing Guide + PTES + NIST
[[Image:OWTFLogo.png|center]]
+
* More efficient
 +
* More comprehensive
 +
* More creative and fun (minimise un-creative work)
  
{{Social Media Links}}
+
so that pentesters will have more time to
  
==Introduction==
+
* See the big picture and think out of the box
 +
* More efficiently find, verify and combine vulnerabilities
 +
* Have time to investigate complex vulnerabilities like business logic/architectural flaws or virtual hosting sessions
 +
* Perform more tactical/targeted fuzzing on seemingly risky areas
 +
* Demonstrate true impact despite the short timeframes we are typically given to test.
  
OWASP OWTF, the Offensive (Web) Testing Framework, is an OWASP+PTES-focused try to unite great tools and make pen testing more efficient.OWASP OWTF, the Offensive (Web) Testing Framework, is an OWASP+PTES-focused try to unite great tools and make pen testing more efficient.
+
=== '''The latest version of OWASP OWTF is [https://github.com/owtf/owtf/releases/tag/v2.3b OWTF 2.3b "MacinOWTF"].''' ===
  
==Description==
+
Project Leaders
You can see what OWASP OWTF is all about in the following video:{{#ev:youtube|H6Ut8U9a5KE}}
+
* [mailto:[email protected] Abraham Aranguren]
 +
* [mailto:[email protected] Bharadwaj Machiraju]
 +
* [mailto:[email protected] Viyat Bhalodia]
  
For more videos please see the [http://www.youtube.com/user/owtfproject YouTube channel]
+
== Links ==
 +
* [https://owtf.github.io#download OWASP OWTF Installation]
 +
* [https://github.com/owtf/owtf/releases OWASP OWTF Releases]
 +
* [http://docs.owtf.org OWASP OWTF Documentation]
 +
* [https://owtf.github.io/online-passive-scanner/ Try some of the OWTF features from your browser!]
 +
* [http://blog.7-a.org/search/label/OWTF%20Release OWASP OWTF Release blog posts]
 +
* [http://blog.7-a.org/search/label/OWTF%20Talks OWASP OWTF Talk blog posts]
 +
* [https://lists.owasp.org/mailman/listinfo/owasp_owtf OWASP OWTF Mailing List]
 +
* [http://webchat.freenode.net/?channels=owtf OWASP OWTF IRC Channel: #owtf on Freenode]
 +
* [https://gitter.im/owtf/owtf OWASP OWTF Gitter Channel]
 +
{{Social Media Links}}
  
==Licensing==
+
====OWTF is taking part in the Google Summer of Code 2018 ! If you'd like to participate then see the  [https://www.owasp.org/index.php/GSOC2018_Ideas OWASP Google Summer of Code 2018 Ideas page]!====
  
| valign="top"  style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |
+
ToolsWatch Annual Best Free/Open Source Security Tool Survey:
 +
* 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 10th]
 +
* 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 7th]
  
== What is OWTF? ==
+
==Presentation and talks==
  
OWASP OWTF is a project focused on penetration testing efficiency and alignment of security tests to security standards like: The OWASP Testing Guide (v3 and v4), the OWASP Top 10, PTES and NIST.
+
The following links provide access to materials for OWTF talks (video, slides, etc.):
  
[http://owtf.github.io/download/ OWASP OWTF Installation]
+
[http://blog.7-a.org/search/label/OWTF%20Talks OWTF Talks at 7-a.org]
  
[https://github.com/owtf/owtf/releases OWASP OWTF Releases]
+
You can see what OWASP OWTF is all about in the following video:{{#ev:youtube|H6Ut8U9a5KE}}
  
The current version of OWASP OWTF is [https://github.com/owtf/owtf/releases/tag/v1.0 OWTF 1.0 "Lionheart"].
+
OWASP OWTF 1.0 "Lionheart" - Brucon 2014 5x5: {{#ev:youtube|j2UoAsOLMB4}}
  
[http://docs.owtf.org OWASP OWTF Documentation]
+
OWASP AppSec EU 2013: Introducing OWASP OWTF 5x5: {{#ev:youtube|Vpca4-OlZqs}}
  
[http://owtf.github.io/online-passive-scanner/ Try some of the OWTF features from your browser!]
+
For more videos please see the [http://www.youtube.com/user/owtfproject YouTube channel]
  
[http://blog.7-a.org/search/label/OWTF%20Release OWASP OWTF Release blog posts]
+
==Licensing==
  
[http://blog.7-a.org/search/label/OWTF%20Talks OWASP OWTF Talk blog posts]
+
[https://github.com/owtf/owtf/blob/develop/LICENSE.md LICENSE]
  
[https://lists.owasp.org/mailman/listinfo/owasp_owtf OWASP OWTF Mailing List]
+
== Openhub ==
 +
https://www.openhub.net/p/owasp-owtf
  
[http://webchat.freenode.net/?channels=owtf OWASP OWTF IRC Channel: #owtf on Freenode]
+
==Classifications==
 +
{| width="200" cellpadding="2"
 +
|-
 +
| rowspan="2" align="center" valign="top" width="50%" |[[File:Flagship projects.jpg|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]
 +
| align="center" valign="top" width="50%" |
 +
|-
 +
| align="center" valign="top" width="50%" |
 +
|-
 +
| colspan="2" align="center" |[[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]
 +
|-
 +
| colspan="2" align="center" |
 +
|}
  
==Presentation==
+
| valign="top" style="padding-left:25px;width:200px;" |
  
The following links provide access to materials for OWTF talks (video, slides, etc.):
+
== Quick Download ==
  
[http://blog.7-a.org/search/label/OWTF%20Talks OWTF Talks at 7-a.org]
+
* [https://owtf.github.io/#download Download now]
  
== Project Leader ==
+
== Email List ==
  
[mailto:Abraham.Aranguren@owasp.org Abraham Aranguren]
+
[https://lists.owasp.org/mailman/listinfo/owasp_owtf Sign Up]
  
 +
== News and Events ==
 +
* April 6th, 2017 - [https://github.com/owtf/owtf/releases/tag/v2.1a OWTF 2.1a "Chicken Korma"] is here!
 +
* May 7th, 2016 - [http://blog.7-a.org/2016/05/owtf-20a-tikka-masala-released-plz-rt.html OWTF 2.0a "Tikka Masala" is here!]
  
== Related Projects ==
+
* February 29th, 2016 - [https://summerofcode.withgoogle.com/organizations/ OWASP is selected for GSoC 2016 - OWTF is participating!]
  
 +
* July 10th, 2015 - [https://www.owasp.org/index.php/Summer_Code_Sprint2015_Progress_Reports#tab=Main OWTF got 3 slots in the OWASP Summer Code Sprint 2015!]
  
== Openhub ==
+
* June 19th, 2015 - [https://www.owasp.org/index.php/Summer_Code_Sprint2015 OWTF is taking part in the OWASP Summer Code Sprint 2015]
 
 
https://www.openhub.net/p/owasp-owtf
 
 
 
| valign="top"  style="padding-left:25px;width:200px;" |
 
 
 
== Quick Download ==
 
 
 
* [http://owtf.github.io/download/ Download now]
 
  
== Email List ==
+
* October 15, 2014 - [http://blog.7-a.org/search?updated-max=2014-10-10T11:30:00%2B01:00&max-results=8 OWTF is taking part in the OWASP Winter Code Sprint!]
  
[https://lists.owasp.org/mailman/listinfo/owasp_owtf Sign Up]
+
* October 15, 2014 - [https://github.com/owtf/owtf/releases/tag/v1.0.1 OWTF 1.0.1 "Lionheart" released! - Fixed a major installation bug caused due to wrong handling of requirements by pip]
  
== News and Events ==
 
 
* October 5th 2014 - [http://blog.7-a.org/2014/10/owtf-10-lionheart-released.html OWTF 1.0 "Lionheart" released!]
 
* October 5th 2014 - [http://blog.7-a.org/2014/10/owtf-10-lionheart-released.html OWTF 1.0 "Lionheart" released!]
  
Line 108: Line 137:
  
 
== In Print ==
 
== In Print ==
 
==Classifications==
 
 
  {| width="200" cellpadding="2"
 
  |-
 
  | align="center" valign="top" width="50%" rowspan="2"| [[File:Midlevel projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]
 
  | align="center" valign="top" width="50%"| [[File:Owasp-builders-small.png|link=]] 
 
  |-
 
  | align="center" valign="top" width="50%"| [[File:Owasp-defenders-small.png|link=]]
 
  |-
 
  | colspan="2" align="center"  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]
 
  |-
 
  | colspan="2" align="center"  | [[File:Project_Type_Files_CODE.jpg|link=]]
 
  |}
 
  
 
|}
 
|}
Line 127: Line 142:
 
=FAQs=
 
=FAQs=
  
; Q1
+
OWTF documentation is hosted in the following resources:
: A1
+
* [https://owtf.github.io/ Getting started]
 
+
* [https://owtf.github.io/#download Downloading & Installation]
; Q2
+
* [http://docs.owtf.org OWASP OWTF Documentation]
: A2
+
* [https://www.youtube.com/user/owtfproject/playlists OWTF Playlists with Demos/Talks on Youtube]
 +
* [http://webchat.freenode.net/?randomnick=1&channels=%23owtf&prompt=1&uio=MTE9MjM20f Join us on IRC (#owtf on Freenode)]
 +
* [http://www.slideshare.net/abrahamaranguren/presentations Some OWTF presentation slides]
 +
* [http://blog.7-a.org/search/label/OWTF%20Talks More OWTF Talk links]
  
 
= Acknowledgements =
 
= Acknowledgements =
Line 143: Line 161:
 
* [http://www.google-melange.com/ Google]
 
* [http://www.google-melange.com/ Google]
 
* [http://brucon.org BruCon]
 
* [http://brucon.org BruCon]
 +
* [http://browserstack.com Browserstack] for providing a platform to test OWTF on multiple devices!
  
 
= Road Map and Getting Involved =
 
= Road Map and Getting Involved =
As of July, the priorities are:
+
OWTF attempts to solve the "penetration testers are never given enough time to test properly" problem, or in other words, OWTF = Test/Exploit ASAP, with this in mind, as of right now, the priorities are:
* xxx
+
* To improve security testing efficiency (i.e. test more in less time)
* xxx
+
* To improve security testing coverage (i.e. test more)
* xxx
+
* Gradually integrate the best tools
 +
* Unite the best tools and make them work together with the security tester
 +
* Remove or Reduce the need to babysit security tools during security assessments
 +
* Be a respository of PoC resource links to assist exploitation of vulnerabilities in order to illustrate risk to businesses.
 +
* Help penetration testers save time on report writing
  
 
Involvement in the development and promotion of OWTF is actively encouraged!
 
Involvement in the development and promotion of OWTF is actively encouraged!
 
You do not have to be a security expert in order to contribute.
 
You do not have to be a security expert in order to contribute.
 
Some of the ways you can help:
 
Some of the ways you can help:
* xxx
+
* [https://github.com/owtf/owtf/pulls Send us a pull request]
* xxx
+
* [https://github.com/owtf/owtf/issues Give us feedback / suggestions / report bugs]
 
+
* [http://webchat.freenode.net/?randomnick=1&channels=%23owtf&prompt=1&uio=MTE9MjM20f Talk to us on IRC (#owtf on Freenode)]
 
+
* [https://lists.owasp.org/mailman/listinfo/owasp_owtf_developers Join our OWTF developers mailing list]
 +
* [https://lists.owasp.org/mailman/listinfo/owasp_owtf Join the general OWTF mailing list]
  
 
=Project About=
 
=Project About=
 
{{:Projects/OWASP_OWTF}}  
 
{{:Projects/OWASP_OWTF}}  
  
__NOTOC__ <headertabs />  
+
__NOTOC__ <headertabs></headertabs>  
  
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]
+
[[Category:OWASP Project]]   
 +
[[Category:OWASP_Builders]]  
 +
[[Category:OWASP_Defenders]]   
 +
[[Category:OWASP_Document]]

Latest revision as of 01:07, 2 April 2018

Flagship big.jpg
Review this project
OWTFLogo.png

OWTF aims to make pen testing:

  • Aligned with OWASP Testing Guide + PTES + NIST
  • More efficient
  • More comprehensive
  • More creative and fun (minimise un-creative work)

so that pentesters will have more time to

  • See the big picture and think out of the box
  • More efficiently find, verify and combine vulnerabilities
  • Have time to investigate complex vulnerabilities like business logic/architectural flaws or virtual hosting sessions
  • Perform more tactical/targeted fuzzing on seemingly risky areas
  • Demonstrate true impact despite the short timeframes we are typically given to test.

The latest version of OWASP OWTF is OWTF 2.3b "MacinOWTF".

Project Leaders

Links


OWTF is taking part in the Google Summer of Code 2018 ! If you'd like to participate then see the OWASP Google Summer of Code 2018 Ideas page!

ToolsWatch Annual Best Free/Open Source Security Tool Survey:

Presentation and talks

The following links provide access to materials for OWTF talks (video, slides, etc.):

OWTF Talks at 7-a.org

You can see what OWASP OWTF is all about in the following video:
OWASP OWTF 1.0 "Lionheart" - Brucon 2014 5x5:
OWASP AppSec EU 2013: Introducing OWASP OWTF 5x5:

For more videos please see the YouTube channel

Licensing

LICENSE

Openhub

https://www.openhub.net/p/owasp-owtf

Classifications

Flagship projects.jpg
Cc-button-y-sa-small.png

Quick Download

Email List

Sign Up

News and Events

In Print

Volunteers

OWTF is developed by a worldwide team of volunteers.

But we have also been helped by many organizations, either financially or through other means:

OWTF attempts to solve the "penetration testers are never given enough time to test properly" problem, or in other words, OWTF = Test/Exploit ASAP, with this in mind, as of right now, the priorities are:

  • To improve security testing efficiency (i.e. test more in less time)
  • To improve security testing coverage (i.e. test more)
  • Gradually integrate the best tools
  • Unite the best tools and make them work together with the security tester
  • Remove or Reduce the need to babysit security tools during security assessments
  • Be a respository of PoC resource links to assist exploitation of vulnerabilities in order to illustrate risk to businesses.
  • Help penetration testers save time on report writing

Involvement in the development and promotion of OWTF is actively encouraged! You do not have to be a security expert in order to contribute. Some of the ways you can help:

PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: OWASP OWTF (home page)
Purpose: The Offensive (Web) Testing Framework is an OWASP+PTES-focused try to unite great tools and make pen testing more efficient.

Please see: http://owtf.org http://blog.7-a.org/search/label/OWTF%20Talks http://www.slideshare.net/abrahamaranguren

License: BSD License
who is working on this project?
Project Leader(s):
  • Abraham Aranguren @
how can you learn more?
Project Pamphlet: Not Yet Created
Project Presentation:
Mailing list: Mailing List Archives
Project Roadmap: View
Key Contacts
  • Contact Abraham Aranguren @ to contribute to this project
  • Contact Abraham Aranguren @ to review or sponsor this project
current release
https://github.com/owtf/owtf/releases
last reviewed release
Not Yet Reviewed


other releases