This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Difference between revisions of "Category:OWASP Project"
Alex Norman (talk | contribs) |
Deleted user (talk | contribs) |
||
Line 11: | Line 11: | ||
<table width="100%" valign="top"><tr><th width="50%">Tools</th><th>Documentation</th></tr><tr valign="top"><td> | <table width="100%" valign="top"><tr><th width="50%">Tools</th><th>Documentation</th></tr><tr valign="top"><td> | ||
+ | |||
+ | |||
+ | '''PROTECT:<br><br> | ||
; [[:Category:OWASP AntiSamy Project|OWASP AntiSamy Java Project]] | ; [[:Category:OWASP AntiSamy Project|OWASP AntiSamy Java Project]] | ||
Line 17: | Line 20: | ||
; [[:Category:OWASP Enterprise Security API|OWASP Enterprise Security API (ESAPI) Project]] | ; [[:Category:OWASP Enterprise Security API|OWASP Enterprise Security API (ESAPI) Project]] | ||
: a free and open collection of all the security methods that a developer needs to build a secure web application. | : a free and open collection of all the security methods that a developer needs to build a secure web application. | ||
+ | |||
+ | |||
+ | '''DETECT:<br><br> | ||
; [[:Category:OWASP Live CD Project|OWASP Live CD Project]] | ; [[:Category:OWASP Live CD Project|OWASP Live CD Project]] | ||
: this CD collects some of the best open source security projects in a single environment. Web developers, testers and security professionals can boot from this Live CD and have access to a full security testing suite. | : this CD collects some of the best open source security projects in a single environment. Web developers, testers and security professionals can boot from this Live CD and have access to a full security testing suite. | ||
+ | |||
+ | ; [[:Category:OWASP WebScarab Project|OWASP WebScarab Project]] | ||
+ | : a tool for performing all types of security testing on web applications and web services | ||
+ | |||
+ | |||
+ | '''LIFE CYCLE:<br><br> | ||
; [[:Category:OWASP WebGoat Project|OWASP WebGoat Project]] | ; [[:Category:OWASP WebGoat Project|OWASP WebGoat Project]] | ||
: an online training environment for hands-on learning about application security | : an online training environment for hands-on learning about application security | ||
− | |||
− | |||
</td><td> | </td><td> | ||
− | |||
− | |||
− | + | '''PROTECT:<br><br> | |
− | |||
; [[:Category:OWASP Guide Project|OWASP Development Guide]] | ; [[:Category:OWASP Guide Project|OWASP Development Guide]] | ||
: a massive document covering all aspects of web application and web service security | : a massive document covering all aspects of web application and web service security | ||
− | |||
− | |||
− | |||
; [[:Category:OWASP Ruby on Rails Security Guide V2 | OWASP Ruby on Rails Security Guide V2]] | ; [[:Category:OWASP Ruby on Rails Security Guide V2 | OWASP Ruby on Rails Security Guide V2]] | ||
: this Project is the one and only source of information about Rails security topics. | : this Project is the one and only source of information about Rails security topics. | ||
− | ; [[:Category:OWASP | + | |
− | : a | + | '''DETECT:<br><br> |
+ | |||
+ | ; [[:Category:OWASP Code Review Project|OWASP Code Review Guide]] | ||
+ | : a project to capture best practices for reviewing code. | ||
; [[:Category:OWASP Testing Project|OWASP Testing Guide]] | ; [[:Category:OWASP Testing Project|OWASP Testing Guide]] | ||
Line 52: | Line 59: | ||
; [[:Category:OWASP Top Ten Project|OWASP Top Ten Project]] | ; [[:Category:OWASP Top Ten Project|OWASP Top Ten Project]] | ||
: an awareness document that describes the top ten web application security vulnerabilities | : an awareness document that describes the top ten web application security vulnerabilities | ||
+ | |||
+ | |||
+ | '''LIFE CYCLE:<br><br> | ||
+ | |||
+ | ; [[:Category:OWASP AppSec FAQ Project|OWASP AppSec FAQ Project]] | ||
+ | : FAQ covering many application security topics | ||
+ | |||
+ | ; [[:Category:OWASP Legal Project|OWASP Legal Project]] | ||
+ | : a project focused on providing contract language for acquiring secure software | ||
+ | |||
+ | ; [[:Category:OWASP Source Code Review OWASP Projects Project|OWASP Source Code Review for OWASP-Projects]] | ||
+ | : a workflow for OWASP projects to incorporate static analysis into the Software Development Life Cycle (SDLC). | ||
+ | |||
+ | |||
</td></tr></table> | </td></tr></table> | ||
Line 62: | Line 83: | ||
<table width="100%" valign="top"><tr><th width="50%">Tools</th><th>Documentation</th></tr><tr valign="top"><td> | <table width="100%" valign="top"><tr><th width="50%">Tools</th><th>Documentation</th></tr><tr valign="top"><td> | ||
− | + | ||
− | : | + | '''PROTECT:<br><br> |
; [[:Category:OWASP AntiSamy Project .NET|OWASP AntiSamy .NET Project]] | ; [[:Category:OWASP AntiSamy Project .NET|OWASP AntiSamy .NET Project]] | ||
Line 76: | Line 97: | ||
; [[:Category:OWASP Encoding Project|OWASP Encoding Project]] | ; [[:Category:OWASP Encoding Project|OWASP Encoding Project]] | ||
: a project focused on the development of encoding best practices for web applications. | : a project focused on the development of encoding best practices for web applications. | ||
− | |||
− | |||
− | |||
− | |||
− | |||
− | |||
; [[:Category:OWASP .NET Project|OWASP .NET Research]] | ; [[:Category:OWASP .NET Project|OWASP .NET Research]] | ||
Line 88: | Line 103: | ||
; [[:Category:OWASP OpenSign Server Project|OWASP OpenSign Server Project]] | ; [[:Category:OWASP OpenSign Server Project|OWASP OpenSign Server Project]] | ||
: the purpose of this project would be to build and host a feature-rich server and suite of client utilities with adequate secure hardware to ensure the integrity of code modules. | : the purpose of this project would be to build and host a feature-rich server and suite of client utilities with adequate secure hardware to ensure the integrity of code modules. | ||
+ | |||
+ | |||
+ | '''DETECT:<br><br> | ||
+ | |||
+ | ; [[:Category:OWASP Access Control Rules Tester Project|OWASP Access Control Rules Tester Project]] | ||
+ | : this project is intended to have two deliverables: research technical report (publication ready article) and an Access Control Rules Tester tool. | ||
+ | |||
+ | ; [[:Category:OWASP LAPSE Project|OWASP LAPSE Project]] | ||
+ | : an Eclipse-based source-code static analysis tool for Java | ||
; [[:Category:OWASP Orizon Project|OWASP Orizon Project]] | ; [[:Category:OWASP Orizon Project|OWASP Orizon Project]] | ||
Line 109: | Line 133: | ||
; [[:Category:OWASP Sqlibench Project|OWASP Sqlibench Project]] | ; [[:Category:OWASP Sqlibench Project|OWASP Sqlibench Project]] | ||
: this is a benchmarking project of automatic sql injectors related to dumping databases. | : this is a benchmarking project of automatic sql injectors related to dumping databases. | ||
− | |||
− | |||
− | |||
; [[OWASP_Tiger|OWASP Tiger]] | ; [[OWASP_Tiger|OWASP Tiger]] | ||
Line 122: | Line 143: | ||
: a project focused on the development of WSFuzzer, a full python-based Web Services SOAP fuzzer | : a project focused on the development of WSFuzzer, a full python-based Web Services SOAP fuzzer | ||
+ | |||
+ | '''LIFE CYCLE:<br><br> | ||
+ | |||
+ | ; [[:Category:OWASP LiveCD Education Project|OWASP Live CD Education Project]] | ||
+ | : an educational supplement project containing tutorials, challenges and videos detailing the use of tools contained within the OWASP LiveCD - LabRat. This project was sponsored by [[OWASP Spring Of Code 2007|OWASP Spring Of Code 2007]] and [http://www.securitydistro.com/ Security Distro] | ||
+ | |||
+ | ; [[:Category:OWASP Teachable Static Analysis Workbench Project|OWASP Teachable Static Analysis Workbench Project]] | ||
+ | : this project is intended to have two deliverables: research technical report (publication ready article) and a workbench prototype. | ||
</td><td> | </td><td> | ||
− | + | ||
− | : | + | '''PROTECT:<br><br> |
; [[:Category:OWASP AppSensor Project|OWASP AppSensor Project]] | ; [[:Category:OWASP AppSensor Project|OWASP AppSensor Project]] | ||
Line 132: | Line 161: | ||
; [[:Category:OWASP Backend Security Project|OWASP Backend Security Project]] | ; [[:Category:OWASP Backend Security Project|OWASP Backend Security Project]] | ||
: this is a new project created to improve and to collect the existant information about the backend security. | : this is a new project created to improve and to collect the existant information about the backend security. | ||
+ | |||
+ | ; [[:Category:OWASP .NET Project|OWASP .NET Project]] | ||
+ | : the purpose of the this project is to provide a central repository of information and tools for software professionals that use the Microsoft .NET Framework for web applications and services. | ||
+ | |||
+ | ; [[:Category:OWASP Securing WebGoat using ModSecurity Project |OWASP Securing WebGoat using ModSecurity Project]] | ||
+ | : the purpose of this project is to create custom Modsecurity rulesets that will protect WebGoat 5.2 from as many of its vulnerabilities as possible (the goal is 90%) without changing one line of source code. | ||
+ | |||
+ | |||
+ | '''DETECT:<br><br> | ||
+ | |||
+ | ; [[:Category:OWASP Application Security Verification Standard Project | OWASP Application Security Verification Standard Project]] | ||
+ | : The ASVS defines a standard for conducting application security verifications. It covers both automated and manual approaches for assessing applications using both external testing and code review techniques. | ||
+ | |||
+ | ; [[:Category:OWASP Tools Project|OWASP Tools Project]] | ||
+ | : the OWASP Tools Project's goal is to provide unbiased, practical information and guidance about application security tools. | ||
+ | |||
+ | |||
+ | '''LIFE CYCLE:<br><br> | ||
; [[:Category:OWASP CLASP Project|OWASP CLASP Project]] | ; [[:Category:OWASP CLASP Project|OWASP CLASP Project]] | ||
Line 140: | Line 187: | ||
; [[OWASP_Internationalization | OWASP Internationalization Project]] | ; [[OWASP_Internationalization | OWASP Internationalization Project]] | ||
− | : general guidelines to start a new translation project for OWASP site and projects | + | : general guidelines to start a new translation project for OWASP site and projects. |
− | |||
− | |||
− | |||
; [[OWASP_Spanish | OWASP Spanish Project]] | ; [[OWASP_Spanish | OWASP Spanish Project]] | ||
− | : first translation effort to make OWASP site and project completely available in Spanish language. | + | : first translation effort to make OWASP site and project completely available in Spanish language. |
− | |||
− | |||
− | |||
− | |||
− | |||
</td></tr></table> | </td></tr></table> |
Revision as of 03:21, 8 March 2009
An OWASP project is a collection of related tasks that have a defined roadmap and team members. OWASP project leaders are responsible for defining the vision, roadmap, and tasks for the project. The project leader also promotes the project and builds the team.
If you would like to start a new project please review the How to Start an OWASP Project guide. Please contact the Global Project Committee members to discuss project ideas and how they might fit into OWASP. All OWASP projects must be free and open and have their homepage on the OWASP portal. You can read all the guidelines in the Project Assessment Criteria.
Every project has an associated mail list. You can view all the lists, examine their archives, and subscribe to any of them on the OWASP Project Mailing Lists page.
Release Quality Projects
Release quality projects are generally the level of quality of professional tools or documents.
We have started the process of defining detailed guidelines which indicate what will be required from an OWASP Project in order for it to be classified an OWASP Release quality project (see Project Assessment Criteria). Please note that not all the projects below have been evaluated under this criteria and might be re-classified once that process is completed.
Tools | Documentation |
---|---|
|
|
Beta Status Projects
Beta quality projects are complete and ready to use with documentation.
We have defined what is required to reach Beta quality as an OWASP project (see Project Assessment Criteria). Not all projects have been evaluated yet under this criteria and might be re-classified once that process is completed. All projects starting with the OWASP Summer of Code 2008 have been assessed.
Tools | Documentation |
---|---|
|
|
Alpha Status Projects
Alpha quality projects are generally usable but may lack documentation or quality review.
We have started the process of defining detailed guidelines which indicate what will be required from an OWASP Project in order for it to be classified an OWASP Alpha quality project (see Project Assessment Criteria). Please note that the projects below have NOT been evaluated under this criteria and might be re-classified once that process is completed.
Tools | Documentation |
---|---|
|
|
Inactive Projects
The criteria is still being developed.
Tools | Documentation |
---|---|
|
|
How to add a new OWASP Project article
You can follow the instructions to make a new OWASP Project article. Please use the appropriate structure and follow the Tutorial. Be sure to paste the following at the end of your article to make it show up in the OWASP Project category:
[[Category:OWASP Project]]
Subcategories
This category has the following 132 subcategories, out of 132 total.
A
B
C
D
E
F
G
H
I
J
L
M
N
O
P
R
S
T
V
W
X
Y
Pages in category "OWASP Project"
The following 200 pages are in this category, out of 419 total.
(previous page) (next page)A
B
C
- Classic ASP Security Project
- GPC Project Details/OWASP Cloud ‐ 10 Project
- GPC Project Details/OWASP Code Crawler
- Code review
- OWASP Codes of Conduct
- Collaborate
- OWASP Common Numbering Project
- GPC Project Details/OWASP CBT Project
- Cornucopia - Ecommerce Website Edition - Wiki Deck
- OWASP Corporate Application Security Rating Guide
- OWASP Cross-Site Request Forgery Research Pool
- OWASP CSRFGuard Project/es
- CSRFProtector Project
E
G
H
J
M
O
- O-Saft
- O-Saft/Documentation
- OWASP O2 Platform Project - Project Identification
- Octoms
- Opa
- Projects/Opa
- OWASP OVAL Content Project
- OWASP - Cyber Security in the Boardroom
- OWASP 1-Liner
- OWASP A&D Project
- OWASP Academy Portal Project
- OWASP AJAX Crawling Tool
- OWASP Amass Project
- OWASP Androick Project
- OWASP Anti-Ransomware Guide Project
- OWASP API Security Project
- OWASP APK DISSECTOR
- OWASP Application Fuzzing Framework Project
- OWASP Application Security Curriculum
- OWASP Application Security Guide For CISOs Project
- OWASP Application Security Guide For CISOs Project v2
- OWASP Application Security Program Quick Start Guide Project
- OWASP AppSec Designer Security Functional Requirements & Countermeasures Libraries
- OWASP AppSec Pipeline
- OWASP Appsec Tutorial Series
- OWASP AppSensor Handbook
- OWASP AppSensor Project
- OWASP ASP.NET MVC Boilerplate Project
- OWASP Assimilation Project
- OWASP ASVS Assessment tool
- OWASP Attack Surface Detector Project
- OWASP Auth
- OWASP Automated Threats to Web Applications
- OWASP Autosploit Project
- OWASP Barbarus
- OWASP Basic Expression & Lexicon Variation Algorithms (BELVA) Project
- OWASP Best Practices in Vulnerability Disclosure and Bug Bounty Programs
- OWASP Broken Web Applications Project
- OWASP Browser Security Project
- OWASP Bug Logging Tool
- OWASP Bywaf Project
- OWASP Cheat Sheet Series
- OWASP Chinese Project
- OWASP CISO Survey Project
- OWASP Click Me Project
- OWASP Cloud Security Mentor
- OWASP Cloud Security Project
- OWASP Cloud Testing Guide
- OWASP Cloud-Native Application Security Top 10
- OWASP Code Project Template
- OWASP Code Pulse Project
- OWASP Container Security Verification Standard (CSVS)
- OWASP Cornucopia
- OWASP Counter Project
- OWASP Crossword of the Month
- OWASP Crowdtesting
- OWASP Cyber Defense Matrix
- OWASP D4N155
- OWASP Damn Vulnerable Crypto Wallet
- OWASP Damn Vulnerable Web Sockets (DVWS)
- OWASP DeepViolet TLS/SSL Scanner
- OWASP DefectDojo Project
- OWASP Dependency Check
- OWASP Dependency Track Project
- OWASP Desktop Goat and Top 5 Project
- OWASP DevSecOps Maturity Model
- OWASP DevSlop Project
- OWASP Documentation Project Template
- OWASP Droid Fusion
- OWASP Droid10 Project
- OWASP DVSA
- OWASP Ecuador
- OWASP EJSF Project
- OWASP Embedded Application Security
- OWASP Encoder Comparison Reference Project
- OWASP Example Incubator
- OWASP Excess XSS Project
- OWASP Faux Bank Project
- OWASP File Hash Repository
- OWASP Financial Information Exchange Security Project
- OWASP Find Security Bugs
- OWASP Focus
- OWASP Framework Security Project
- OWASP Game Security Framework Project
- OWASP Global Chapter Meetings Project
- OWASP Glue Tool Project
- OWASP Go Secure Coding Practices Guide
- OWASP Good Component Practices Project
- OWASP Google Assistant
- OWASP Guide Project
- OWASP H2H Tool Project
- OWASP HA Vulnerability Scanner Project
- OWASP Hackademic Challenges Project
- OWASP Hacking Lab
- OWASP Hacking-the Pentest Tutor Game
- OWASP Hive Project
- OWASP Honeypot Project
- OWASP ICS / SCADA Security Project
- OWASP iGoat Tool Project
- OWASP iMAS iOS Mobile Application Security Project
- OWASP Incident Response Project
- OWASP Information Security Metrics Bank
- OWASP Insecure Web Components Project
- OWASP Intelligent Intrusion Detection System
- OWASP Internet of Things Project
- OWASP IOT Analytics 4Industry4
- OWASP iSABEL Proxy Server
- OWASP ISO IEC 27034 Application Security Controls Project
- OWASP ISO Project
- OWASP Java Encoder Project
- OWASP Java File I O Security Project
- OWASP Java J2EE Secure Development Curriculum
- OWASP Java Uncertain Form Submit Prevention
- OWASP JavaScript Sandboxes
- OWASP JAWS Project
- OWASP JOTP Project
- OWASP JSEC CVE Details
- OWASP JSON Sanitizer
- OWASP Jupiter
- OWASP KALP Mobile Project
- OWASP Kates Project
- OWASP Knowledge Based Authentication Performance Metrics Project
- OWASP Knowledge Graph
- OWASP LAPSE Project
- OWASP Learning Platform Project
- OWASP Lock It
- OWASP Logging
- OWASP LWAF