This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "OWASP OWTF"
(→FAQs) |
(→Links) (Tag: Visual edit) |
||
(43 intermediate revisions by 4 users not shown) | |||
Line 1: | Line 1: | ||
=Main= | =Main= | ||
+ | <div style="width:100%;height:90px;border:0,margin:0;overflow: hidden;">[[File: flagship_big.jpg|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]</div> | ||
+ | {| class="wikitable sortable" style="padding: 0;margin:0;margin-top:10px;text-align:left;" |- | ||
+ | | valign="top" style="border-right: 1px dotted gray;padding-right:25px;" |[https://www.openhub.net/p/owasp-owtf/reviews/new Review this project] | ||
− | + | [[Image:OWTFLogo.png|right]] | |
− | + | OWTF aims to make pen testing: | |
− | |||
− | + | * Aligned with OWASP Testing Guide + PTES + NIST | |
− | + | * More efficient | |
+ | * More comprehensive | ||
+ | * More creative and fun (minimise un-creative work) | ||
− | + | so that pentesters will have more time to | |
− | + | * See the big picture and think out of the box | |
+ | * More efficiently find, verify and combine vulnerabilities | ||
+ | * Have time to investigate complex vulnerabilities like business logic/architectural flaws or virtual hosting sessions | ||
+ | * Perform more tactical/targeted fuzzing on seemingly risky areas | ||
+ | * Demonstrate true impact despite the short timeframes we are typically given to test. | ||
− | OWASP OWTF | + | === '''The latest version of OWASP OWTF is [https://github.com/owtf/owtf/releases/tag/v2.3b OWTF 2.3b "MacinOWTF"].''' === |
− | + | Project Leaders | |
− | + | * [mailto:[email protected] Abraham Aranguren] | |
+ | * [mailto:[email protected] Bharadwaj Machiraju] | ||
+ | * [mailto:[email protected] Viyat Bhalodia] | ||
− | + | == Links == | |
+ | * [https://owtf.github.io#download OWASP OWTF Installation] | ||
+ | * [https://github.com/owtf/owtf/releases OWASP OWTF Releases] | ||
+ | * [http://docs.owtf.org OWASP OWTF Documentation] | ||
+ | * [https://owtf.github.io/online-passive-scanner/ Try some of the OWTF features from your browser!] | ||
+ | * [http://blog.7-a.org/search/label/OWTF%20Release OWASP OWTF Release blog posts] | ||
+ | * [http://blog.7-a.org/search/label/OWTF%20Talks OWASP OWTF Talk blog posts] | ||
+ | * [https://lists.owasp.org/mailman/listinfo/owasp_owtf OWASP OWTF Mailing List] | ||
+ | * [http://webchat.freenode.net/?channels=owtf OWASP OWTF IRC Channel: #owtf on Freenode] | ||
+ | * [https://gitter.im/owtf/owtf OWASP OWTF Gitter Channel] | ||
+ | {{Social Media Links}} | ||
− | == | + | ====OWTF is taking part in the Google Summer of Code 2018 ! If you'd like to participate then see the [https://www.owasp.org/index.php/GSOC2018_Ideas OWASP Google Summer of Code 2018 Ideas page]!==== |
− | + | ToolsWatch Annual Best Free/Open Source Security Tool Survey: | |
+ | * 2015 [http://www.toolswatch.org/2016/02/2015-top-security-tools-as-voted-by-toolswatch-org-readers/ 10th] | ||
+ | * 2014 [http://www.toolswatch.org/2015/01/2014-top-security-tools-as-voted-by-toolswatch-org-readers/ 7th] | ||
− | == | + | ==Presentation and talks== |
− | + | The following links provide access to materials for OWTF talks (video, slides, etc.): | |
− | [ | + | [http://blog.7-a.org/search/label/OWTF%20Talks OWTF Talks at 7-a.org] |
− | + | You can see what OWASP OWTF is all about in the following video:{{#ev:youtube|H6Ut8U9a5KE}} | |
− | + | OWASP OWTF 1.0 "Lionheart" - Brucon 2014 5x5: {{#ev:youtube|j2UoAsOLMB4}} | |
− | + | OWASP AppSec EU 2013: Introducing OWASP OWTF 5x5: {{#ev:youtube|Vpca4-OlZqs}} | |
− | [ | + | For more videos please see the [http://www.youtube.com/user/owtfproject YouTube channel] |
− | + | ==Licensing== | |
− | [ | + | [https://github.com/owtf/owtf/blob/develop/LICENSE.md LICENSE] |
− | + | == Openhub == | |
+ | https://www.openhub.net/p/owasp-owtf | ||
− | [ | + | ==Classifications== |
+ | {| width="200" cellpadding="2" | ||
+ | |- | ||
+ | | rowspan="2" align="center" valign="top" width="50%" |[[File:Flagship projects.jpg|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]] | ||
+ | | align="center" valign="top" width="50%" | | ||
+ | |- | ||
+ | | align="center" valign="top" width="50%" | | ||
+ | |- | ||
+ | | colspan="2" align="center" |[[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] | ||
+ | |- | ||
+ | | colspan="2" align="center" | | ||
+ | |} | ||
− | == | + | | valign="top" style="padding-left:25px;width:200px;" | |
− | + | == Quick Download == | |
− | [ | + | * [https://owtf.github.io/#download Download now] |
− | == | + | == Email List == |
− | [ | + | [https://lists.owasp.org/mailman/listinfo/owasp_owtf Sign Up] |
+ | == News and Events == | ||
+ | * April 6th, 2017 - [https://github.com/owtf/owtf/releases/tag/v2.1a OWTF 2.1a "Chicken Korma"] is here! | ||
+ | * May 7th, 2016 - [http://blog.7-a.org/2016/05/owtf-20a-tikka-masala-released-plz-rt.html OWTF 2.0a "Tikka Masala" is here!] | ||
− | + | * February 29th, 2016 - [https://summerofcode.withgoogle.com/organizations/ OWASP is selected for GSoC 2016 - OWTF is participating!] | |
+ | * July 10th, 2015 - [https://www.owasp.org/index.php/Summer_Code_Sprint2015_Progress_Reports#tab=Main OWTF got 3 slots in the OWASP Summer Code Sprint 2015!] | ||
− | + | * June 19th, 2015 - [https://www.owasp.org/index.php/Summer_Code_Sprint2015 OWTF is taking part in the OWASP Summer Code Sprint 2015] | |
− | + | * October 15, 2014 - [http://blog.7-a.org/search?updated-max=2014-10-10T11:30:00%2B01:00&max-results=8 OWTF is taking part in the OWASP Winter Code Sprint!] | |
− | |||
− | |||
− | |||
− | |||
− | * [https:// | + | * October 15, 2014 - [https://github.com/owtf/owtf/releases/tag/v1.0.1 OWTF 1.0.1 "Lionheart" released! - Fixed a major installation bug caused due to wrong handling of requirements by pip] |
− | |||
− | |||
− | |||
− | |||
− | |||
* October 5th 2014 - [http://blog.7-a.org/2014/10/owtf-10-lionheart-released.html OWTF 1.0 "Lionheart" released!] | * October 5th 2014 - [http://blog.7-a.org/2014/10/owtf-10-lionheart-released.html OWTF 1.0 "Lionheart" released!] | ||
Line 108: | Line 137: | ||
== In Print == | == In Print == | ||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
|} | |} | ||
Line 129: | Line 144: | ||
OWTF documentation is hosted in the following resources: | OWTF documentation is hosted in the following resources: | ||
* [https://owtf.github.io/ Getting started] | * [https://owtf.github.io/ Getting started] | ||
− | * [https://owtf.github.io/download | + | * [https://owtf.github.io/#download Downloading & Installation] |
* [http://docs.owtf.org OWASP OWTF Documentation] | * [http://docs.owtf.org OWASP OWTF Documentation] | ||
* [https://www.youtube.com/user/owtfproject/playlists OWTF Playlists with Demos/Talks on Youtube] | * [https://www.youtube.com/user/owtfproject/playlists OWTF Playlists with Demos/Talks on Youtube] | ||
Line 146: | Line 161: | ||
* [http://www.google-melange.com/ Google] | * [http://www.google-melange.com/ Google] | ||
* [http://brucon.org BruCon] | * [http://brucon.org BruCon] | ||
+ | * [http://browserstack.com Browserstack] for providing a platform to test OWTF on multiple devices! | ||
= Road Map and Getting Involved = | = Road Map and Getting Involved = | ||
Line 169: | Line 185: | ||
{{:Projects/OWASP_OWTF}} | {{:Projects/OWASP_OWTF}} | ||
− | __NOTOC__ <headertabs /> | + | __NOTOC__ <headertabs></headertabs> |
− | [[Category:OWASP Project]] [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]] [[Category:OWASP_Document]] | + | [[Category:OWASP Project]] |
+ | [[Category:OWASP_Builders]] | ||
+ | [[Category:OWASP_Defenders]] | ||
+ | [[Category:OWASP_Document]] |
Latest revision as of 01:07, 2 April 2018
Review this project
OWTF aims to make pen testing:
so that pentesters will have more time to
The latest version of OWASP OWTF is OWTF 2.3b "MacinOWTF".Project Leaders Links
OWTF is taking part in the Google Summer of Code 2018 ! If you'd like to participate then see the OWASP Google Summer of Code 2018 Ideas page!ToolsWatch Annual Best Free/Open Source Security Tool Survey: Presentation and talksThe following links provide access to materials for OWTF talks (video, slides, etc.): You can see what OWASP OWTF is all about in the following video: OWASP OWTF 1.0 "Lionheart" - Brucon 2014 5x5: OWASP AppSec EU 2013: Introducing OWASP OWTF 5x5:For more videos please see the YouTube channel LicensingOpenhubhttps://www.openhub.net/p/owasp-owtf Classifications |
Quick DownloadEmail ListNews and Events
In Print |
OWTF documentation is hosted in the following resources:
Volunteers
OWTF is developed by a worldwide team of volunteers.
But we have also been helped by many organizations, either financially or through other means:
- OWASP
- eLearnSecurity
- BruCon
- Browserstack for providing a platform to test OWTF on multiple devices!
OWTF attempts to solve the "penetration testers are never given enough time to test properly" problem, or in other words, OWTF = Test/Exploit ASAP, with this in mind, as of right now, the priorities are:
- To improve security testing efficiency (i.e. test more in less time)
- To improve security testing coverage (i.e. test more)
- Gradually integrate the best tools
- Unite the best tools and make them work together with the security tester
- Remove or Reduce the need to babysit security tools during security assessments
- Be a respository of PoC resource links to assist exploitation of vulnerabilities in order to illustrate risk to businesses.
- Help penetration testers save time on report writing
Involvement in the development and promotion of OWTF is actively encouraged! You do not have to be a security expert in order to contribute. Some of the ways you can help:
PROJECT INFO What does this OWASP project offer you? |
RELEASE(S) INFO What releases are available for this project? | |||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
|