This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "Category:OWASP Project"

From OWASP
Jump to: navigation, search
Line 11: Line 11:
  
 
<table width="100%" valign="top"><tr><th width="50%">Tools</th><th>Documentation</th></tr><tr valign="top"><td>
 
<table width="100%" valign="top"><tr><th width="50%">Tools</th><th>Documentation</th></tr><tr valign="top"><td>
 +
 +
 +
'''PROTECT:<br><br>
  
 
; [[:Category:OWASP AntiSamy Project|OWASP AntiSamy Java Project]]
 
; [[:Category:OWASP AntiSamy Project|OWASP AntiSamy Java Project]]
Line 17: Line 20:
 
; [[:Category:OWASP Enterprise Security API|OWASP Enterprise Security API (ESAPI) Project]]
 
; [[:Category:OWASP Enterprise Security API|OWASP Enterprise Security API (ESAPI) Project]]
 
: a free and open collection of all the security methods that a developer needs to build a secure web application.
 
: a free and open collection of all the security methods that a developer needs to build a secure web application.
 +
 +
 +
'''DETECT:<br><br>
  
 
; [[:Category:OWASP Live CD Project|OWASP Live CD Project]]
 
; [[:Category:OWASP Live CD Project|OWASP Live CD Project]]
 
: this CD collects some of the best open source security projects in a single environment. Web developers, testers and security professionals can boot from this Live CD and have access to a full security testing suite.  
 
: this CD collects some of the best open source security projects in a single environment. Web developers, testers and security professionals can boot from this Live CD and have access to a full security testing suite.  
 +
 +
; [[:Category:OWASP WebScarab Project|OWASP WebScarab Project]]
 +
: a tool for performing all types of security testing on web applications and web services
 +
 +
 +
'''LIFE CYCLE:<br><br>
  
 
; [[:Category:OWASP WebGoat Project|OWASP WebGoat Project]]
 
; [[:Category:OWASP WebGoat Project|OWASP WebGoat Project]]
 
: an online training environment for hands-on learning about application security
 
: an online training environment for hands-on learning about application security
  
; [[:Category:OWASP WebScarab Project|OWASP WebScarab Project]]
 
: a tool for performing all types of security testing on web applications and web services
 
  
 
</td><td>
 
</td><td>
  
; [[:Category:OWASP AppSec FAQ Project|OWASP AppSec FAQ Project]]
 
: FAQ covering many application security topics
 
  
; [[:Category:OWASP Code Review Project|OWASP Code Review Guide]]
+
'''PROTECT:<br><br>
: a project to capture best practices for reviewing code.
 
  
 
; [[:Category:OWASP Guide Project|OWASP Development Guide]]
 
; [[:Category:OWASP Guide Project|OWASP Development Guide]]
 
: a massive document covering all aspects of web application and web service security
 
: a massive document covering all aspects of web application and web service security
 
; [[:Category:OWASP Legal Project|OWASP Legal Project]]
 
: a project focused on providing contract language for acquiring secure software
 
  
 
; [[:Category:OWASP Ruby on Rails Security Guide V2 | OWASP Ruby on Rails Security Guide V2]]
 
; [[:Category:OWASP Ruby on Rails Security Guide V2 | OWASP Ruby on Rails Security Guide V2]]
 
: this Project is the one and only source of information about Rails security topics.  
 
: this Project is the one and only source of information about Rails security topics.  
  
; [[:Category:OWASP Source Code Review OWASP Projects Project|OWASP Source Code Review for OWASP-Projects]]
+
 
: a workflow for OWASP projects to incorporate static analysis into the Software Development Life Cycle (SDLC).  
+
'''DETECT:<br><br>
 +
 
 +
; [[:Category:OWASP Code Review Project|OWASP Code Review Guide]]
 +
: a project to capture best practices for reviewing code.
  
 
; [[:Category:OWASP Testing Project|OWASP Testing Guide]]
 
; [[:Category:OWASP Testing Project|OWASP Testing Guide]]
Line 52: Line 59:
 
; [[:Category:OWASP Top Ten Project|OWASP Top Ten Project]]
 
; [[:Category:OWASP Top Ten Project|OWASP Top Ten Project]]
 
: an awareness document that describes the top ten web application security vulnerabilities
 
: an awareness document that describes the top ten web application security vulnerabilities
 +
 +
 +
'''LIFE CYCLE:<br><br>
 +
 +
; [[:Category:OWASP AppSec FAQ Project|OWASP AppSec FAQ Project]]
 +
: FAQ covering many application security topics
 +
 +
; [[:Category:OWASP Legal Project|OWASP Legal Project]]
 +
: a project focused on providing contract language for acquiring secure software
 +
 +
; [[:Category:OWASP Source Code Review OWASP Projects Project|OWASP Source Code Review for OWASP-Projects]]
 +
: a workflow for OWASP projects to incorporate static analysis into the Software Development Life Cycle (SDLC).
 +
 +
  
 
</td></tr></table>
 
</td></tr></table>
Line 62: Line 83:
 
<table width="100%" valign="top"><tr><th width="50%">Tools</th><th>Documentation</th></tr><tr valign="top"><td>
 
<table width="100%" valign="top"><tr><th width="50%">Tools</th><th>Documentation</th></tr><tr valign="top"><td>
  
; [[:Category:OWASP Access Control Rules Tester Project|OWASP Access Control Rules Tester Project]]
+
 
: this project is intended to have two deliverables: research technical report (publication ready article) and an Access Control Rules Tester tool.
+
'''PROTECT:<br><br>
  
 
; [[:Category:OWASP AntiSamy Project .NET|OWASP AntiSamy .NET Project]]
 
; [[:Category:OWASP AntiSamy Project .NET|OWASP AntiSamy .NET Project]]
Line 76: Line 97:
 
; [[:Category:OWASP Encoding Project|OWASP Encoding Project]]
 
; [[:Category:OWASP Encoding Project|OWASP Encoding Project]]
 
: a project focused on the development of encoding best practices for web applications.
 
: a project focused on the development of encoding best practices for web applications.
 
; [[:Category:OWASP LAPSE Project|OWASP LAPSE Project]]
 
: an Eclipse-based source-code static analysis tool for Java
 
 
; [[:Category:OWASP LiveCD Education Project|OWASP Live CD Education Project]]
 
: an educational supplement project containing tutorials, challenges and videos detailing the use of tools contained within the OWASP LiveCD - LabRat. This project was sponsored by [[OWASP Spring Of Code 2007|OWASP Spring Of Code 2007]] and [http://www.securitydistro.com/ Security Distro]
 
  
 
; [[:Category:OWASP .NET Project|OWASP .NET Research]]
 
; [[:Category:OWASP .NET Project|OWASP .NET Research]]
Line 88: Line 103:
 
; [[:Category:OWASP OpenSign Server Project|OWASP OpenSign Server Project]]
 
; [[:Category:OWASP OpenSign Server Project|OWASP OpenSign Server Project]]
 
: the purpose of this project would be to build and host a feature-rich server and suite of client utilities with adequate secure hardware to ensure the integrity of code modules.
 
: the purpose of this project would be to build and host a feature-rich server and suite of client utilities with adequate secure hardware to ensure the integrity of code modules.
 +
 +
 +
'''DETECT:<br><br>
 +
 +
; [[:Category:OWASP Access Control Rules Tester Project|OWASP Access Control Rules Tester Project]]
 +
: this project is intended to have two deliverables: research technical report (publication ready article) and an Access Control Rules Tester tool.
 +
 +
; [[:Category:OWASP LAPSE Project|OWASP LAPSE Project]]
 +
: an Eclipse-based source-code static analysis tool for Java
  
 
; [[:Category:OWASP Orizon Project|OWASP Orizon Project]]
 
; [[:Category:OWASP Orizon Project|OWASP Orizon Project]]
Line 109: Line 133:
 
; [[:Category:OWASP Sqlibench Project|OWASP Sqlibench Project]]
 
; [[:Category:OWASP Sqlibench Project|OWASP Sqlibench Project]]
 
: this is a benchmarking project of automatic sql injectors related to dumping databases.  
 
: this is a benchmarking project of automatic sql injectors related to dumping databases.  
 
; [[:Category:OWASP Teachable Static Analysis Workbench Project|OWASP Teachable Static Analysis Workbench Project]]
 
: this project is intended to have two deliverables: research technical report (publication ready article) and a workbench prototype.
 
  
 
; [[OWASP_Tiger|OWASP Tiger]]
 
; [[OWASP_Tiger|OWASP Tiger]]
Line 122: Line 143:
 
: a project focused on the development of WSFuzzer, a full python-based Web Services SOAP fuzzer
 
: a project focused on the development of WSFuzzer, a full python-based Web Services SOAP fuzzer
  
 +
 +
'''LIFE CYCLE:<br><br>
 +
 +
; [[:Category:OWASP LiveCD Education Project|OWASP Live CD Education Project]]
 +
: an educational supplement project containing tutorials, challenges and videos detailing the use of tools contained within the OWASP LiveCD - LabRat. This project was sponsored by [[OWASP Spring Of Code 2007|OWASP Spring Of Code 2007]] and [http://www.securitydistro.com/ Security Distro]
 +
 +
; [[:Category:OWASP Teachable Static Analysis Workbench Project|OWASP Teachable Static Analysis Workbench Project]]
 +
: this project is intended to have two deliverables: research technical report (publication ready article) and a workbench prototype.
 
</td><td>
 
</td><td>
  
; [[:Category:OWASP Application Security Verification Standard Project | OWASP Application Security Verification Standard Project]]
+
 
: The ASVS defines a standard for conducting application security verifications. It covers both automated and manual approaches for assessing applications using both external testing and code review techniques.
+
'''PROTECT:<br><br>
  
 
; [[:Category:OWASP AppSensor Project|OWASP AppSensor Project]]
 
; [[:Category:OWASP AppSensor Project|OWASP AppSensor Project]]
Line 132: Line 161:
 
; [[:Category:OWASP Backend Security Project|OWASP Backend Security Project]]
 
; [[:Category:OWASP Backend Security Project|OWASP Backend Security Project]]
 
: this is a new project created to improve and to collect the existant information about the backend security.  
 
: this is a new project created to improve and to collect the existant information about the backend security.  
 +
 +
; [[:Category:OWASP .NET Project|OWASP .NET Project]]
 +
: the purpose of the this project is to provide a central repository of information and tools for software professionals that use the Microsoft .NET Framework for web applications and services.
 +
 +
; [[:Category:OWASP Securing WebGoat using ModSecurity Project |OWASP Securing WebGoat using ModSecurity Project]]
 +
: the purpose of this project is to create custom Modsecurity rulesets that will protect WebGoat 5.2 from as many of its vulnerabilities as possible (the goal is 90%) without changing one line of source code.
 +
 +
 +
'''DETECT:<br><br>
 +
 +
; [[:Category:OWASP Application Security Verification Standard Project | OWASP Application Security Verification Standard Project]]
 +
: The ASVS defines a standard for conducting application security verifications. It covers both automated and manual approaches for assessing applications using both external testing and code review techniques.
 +
 +
; [[:Category:OWASP Tools Project|OWASP Tools Project]]
 +
: the OWASP Tools Project's goal is to provide unbiased, practical information and guidance about application security tools.
 +
 +
 +
'''LIFE CYCLE:<br><br>
  
 
; [[:Category:OWASP CLASP Project|OWASP CLASP Project]]
 
; [[:Category:OWASP CLASP Project|OWASP CLASP Project]]
Line 140: Line 187:
  
 
; [[OWASP_Internationalization | OWASP Internationalization Project]]
 
; [[OWASP_Internationalization | OWASP Internationalization Project]]
: general guidelines to start a new translation project for OWASP site and projects.
+
: general guidelines to start a new translation project for OWASP site and projects.
 
 
; [[:Category:OWASP .NET Project|OWASP .NET Project]]
 
: the purpose of the this project is to provide a central repository of information and tools for software professionals that use the Microsoft .NET Framework for web applications and services.  
 
  
 
; [[OWASP_Spanish | OWASP Spanish Project]]
 
; [[OWASP_Spanish | OWASP Spanish Project]]
: first translation effort to make OWASP site and project completely available in Spanish language.
+
: first translation effort to make OWASP site and project completely available in Spanish language.  
  
; [[:Category:OWASP Tools Project|OWASP Tools Project]]
 
: the OWASP Tools Project's goal is to provide unbiased, practical information and guidance about application security tools.
 
 
; [[:Category:OWASP Securing WebGoat using ModSecurity Project |OWASP Securing WebGoat using ModSecurity Project]]
 
: the purpose of this project is to create custom Modsecurity rulesets that will protect WebGoat 5.2 from as many of its vulnerabilities as possible (the goal is 90%) without changing one line of source code.
 
  
 
</td></tr></table>
 
</td></tr></table>

Revision as of 03:21, 8 March 2009

An OWASP project is a collection of related tasks that have a defined roadmap and team members. OWASP project leaders are responsible for defining the vision, roadmap, and tasks for the project. The project leader also promotes the project and builds the team.

If you would like to start a new project please review the How to Start an OWASP Project guide. Please contact the Global Project Committee members to discuss project ideas and how they might fit into OWASP. All OWASP projects must be free and open and have their homepage on the OWASP portal. You can read all the guidelines in the Project Assessment Criteria.

Every project has an associated mail list. You can view all the lists, examine their archives, and subscribe to any of them on the OWASP Project Mailing Lists page.

Release Quality Projects

Release quality projects are generally the level of quality of professional tools or documents.

We have started the process of defining detailed guidelines which indicate what will be required from an OWASP Project in order for it to be classified an OWASP Release quality project (see Project Assessment Criteria). Please note that not all the projects below have been evaluated under this criteria and might be re-classified once that process is completed.

ToolsDocumentation


PROTECT:

OWASP AntiSamy Java Project
an API for validating rich HTML/CSS input from users without exposure to cross-site scripting and phishing attacks
OWASP Enterprise Security API (ESAPI) Project
a free and open collection of all the security methods that a developer needs to build a secure web application.


DETECT:

OWASP Live CD Project
this CD collects some of the best open source security projects in a single environment. Web developers, testers and security professionals can boot from this Live CD and have access to a full security testing suite.
OWASP WebScarab Project
a tool for performing all types of security testing on web applications and web services


LIFE CYCLE:

OWASP WebGoat Project
an online training environment for hands-on learning about application security



PROTECT:

OWASP Development Guide
a massive document covering all aspects of web application and web service security
OWASP Ruby on Rails Security Guide V2
this Project is the one and only source of information about Rails security topics.


DETECT:

OWASP Code Review Guide
a project to capture best practices for reviewing code.
OWASP Testing Guide
a project focused on application security testing procedures and checklists
OWASP Top Ten Project
an awareness document that describes the top ten web application security vulnerabilities


LIFE CYCLE:

OWASP AppSec FAQ Project
FAQ covering many application security topics
OWASP Legal Project
a project focused on providing contract language for acquiring secure software
OWASP Source Code Review for OWASP-Projects
a workflow for OWASP projects to incorporate static analysis into the Software Development Life Cycle (SDLC).


Beta Status Projects

Beta quality projects are complete and ready to use with documentation.

We have defined what is required to reach Beta quality as an OWASP project (see Project Assessment Criteria). Not all projects have been evaluated yet under this criteria and might be re-classified once that process is completed. All projects starting with the OWASP Summer of Code 2008 have been assessed.

ToolsDocumentation


PROTECT:

OWASP AntiSamy .NET Project
an API for validating rich HTML/CSS input from users without exposure to cross-site scripting and phishing attacks.
OWASP CSRFGuard Project
a J2EE filter that implements a unique request token to mitigate CSRF attacks
OWASP DirBuster Project
DirBuster is a multi threaded java application designed to brute force directories and files names on web/application servers.
OWASP Encoding Project
a project focused on the development of encoding best practices for web applications.
OWASP .NET Research
a project focused on helping .NET developers build secure applications
OWASP OpenSign Server Project
the purpose of this project would be to build and host a feature-rich server and suite of client utilities with adequate secure hardware to ensure the integrity of code modules.


DETECT:

OWASP Access Control Rules Tester Project
this project is intended to have two deliverables: research technical report (publication ready article) and an Access Control Rules Tester tool.
OWASP LAPSE Project
an Eclipse-based source-code static analysis tool for Java
OWASP Orizon Project
the goal of this project is to develop an extensible code review engine to be used from source code assessment tools.
OWASP Pantera Web Assessment Studio Project
a project focused on combining automated capabilities with complete manual testing to get the best results
OWASP Report Generator
a project giving security professionals a way to report and keep track of their projects
OWASP Site Generator
a project allowing users to create dynamic sites for use in training, web application scanner testing, etc...
OWASP Skavenger Project
is a web application security assessment tool kit that passively analyses traffic logged by various MITM proxies as well as other sources and helps to identify various kinds of possible vulnerabilities.
OWASP SQLiX Project
a project focused on the development of SQLiX, a full perl-based SQL scanner
OWASP Sqlibench Project
this is a benchmarking project of automatic sql injectors related to dumping databases.
OWASP Tiger
OWASP Tiger is a Windows application originally intended to be used for automating the process of testing various known ASP.NET security issues in hosted environments. However, it is much more versatile than that: it can help you construct and send a HTTP requests, receive and analyze the responses, match them against a set of conditions to produce alerts, notifications that something is wrong with the application(s) or service(s) being tested.
OWASP WeBekci Project
OWASP WeBekci is a web based ModSecurity 2.x management tool. WeBekci is written in PHP, Its backend is powered by MySQL and the frontend by XAJAX framework.
OWASP WSFuzzer Project
a project focused on the development of WSFuzzer, a full python-based Web Services SOAP fuzzer


LIFE CYCLE:

OWASP Live CD Education Project
an educational supplement project containing tutorials, challenges and videos detailing the use of tools contained within the OWASP LiveCD - LabRat. This project was sponsored by OWASP Spring Of Code 2007 and Security Distro
OWASP Teachable Static Analysis Workbench Project
this project is intended to have two deliverables: research technical report (publication ready article) and a workbench prototype.


PROTECT:

OWASP AppSensor Project
a framework for detecting and responding to attacks from within the application.
OWASP Backend Security Project
this is a new project created to improve and to collect the existant information about the backend security.
OWASP .NET Project
the purpose of the this project is to provide a central repository of information and tools for software professionals that use the Microsoft .NET Framework for web applications and services.
OWASP Securing WebGoat using ModSecurity Project
the purpose of this project is to create custom Modsecurity rulesets that will protect WebGoat 5.2 from as many of its vulnerabilities as possible (the goal is 90%) without changing one line of source code.


DETECT:

OWASP Application Security Verification Standard Project
The ASVS defines a standard for conducting application security verifications. It covers both automated and manual approaches for assessing applications using both external testing and code review techniques.
OWASP Tools Project
the OWASP Tools Project's goal is to provide unbiased, practical information and guidance about application security tools.


LIFE CYCLE:

OWASP CLASP Project
a project focused on defining process elements that reinforce application security
OWASP Education Project
a project to build educational tracks and modules for different audiences.
OWASP Internationalization Project
general guidelines to start a new translation project for OWASP site and projects.
OWASP Spanish Project
first translation effort to make OWASP site and project completely available in Spanish language.


Alpha Status Projects

Alpha quality projects are generally usable but may lack documentation or quality review.

We have started the process of defining detailed guidelines which indicate what will be required from an OWASP Project in order for it to be classified an OWASP Alpha quality project (see Project Assessment Criteria). Please note that the projects below have NOT been evaluated under this criteria and might be re-classified once that process is completed.

ToolsDocumentation
OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project
The idea is to split destination web application technology from the three reusable libraries: library of navigational elements, library of vulnerabilities and library of language constructs.
OWASP Code Crawler
this tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.
OWASP CSRFTester Project
gives developers the ability to test their applications for CSRF flaws
OWASP EnDe Project
This tool is an encoder, decoder, converter, transformer, calculator, for various codings used in the wild wide web.
OWASP Google Hacking Project
Google SOAP Search API with Perl
OWASP Insecure Web App Project
a web application that includes common web application vulnerabilities
OWASP JBroFuzz Project
a web application fuzzer for requests being made over HTTP and/or HTTPS. Its purpose is to provide a single, portable application that offers stable web protocol fuzzing capabilities. This project was sponsored by OWASP Spring Of Code 2007
OWASP JSP Testing Tool Project
the goal of this project is to create an easy to use, freely available tool that can be used to quickly ascertain the level of protection that each component of a JSP tag library offers.
OWASP Learn About Encoding Project
this project has as its ultimate goal of demystifying the problems related to the study of character encoding (charset encoding).
OWASP NetBouncer Project
is secure by default centralised input/output validation library which combines security rules and business rules as well as escaping in the output level.
OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp
focus on mod_openpgp and Secure Session Management, presenting a working web-site using this new authentication methodology in such a way that it will attract security professionals and web-developers to this new mix of two good'ol protocols: HTTP and OpenPGP.
OWASP Open Review Project (ORPRO)
a project to openly check open source libraries and software that are vital to most commercial and non-commercial apps around.
OWASP PHP AntiXSS Library Project
reduce cross-site scripting vulnerabilities by encoding your output
OWASP Python Static Analysis Project
the aim of this project is to provide full language support,other Python frameworks support, analysis improvement, reporting capability, documentation, promotion materials: publication-ready article and presentation
OWASP Proxy Project
aims to provide a high quality intercepting proxy library which can be used by developers who require this functionality in their own programs, rather than having to develop it all from scratch.
OWASP Sprajax Project
an open source black box security scanner used to assess the security of AJAX-enabled applications
OWASP Stinger Project
a project focus on the development of a centralized input validation mechanism which can be easily applied to existing or developmental applications
OWASP Vicnum Project
a lightweight vulnerable web application based on a game played to kill time which demonstrates common web application vulnerabilities such as cross site scripting
OWASP Wapiti Project
the project allows to audit the security by performing "black-box" scans acting like a fuzzer, injecting payloads to see if an application is vulnerable
OWASP Web Application Security Metric using Attack Patterns Project
the project provides attack pattern database along with prototype model
OWASP Web 2.0 Project
a place for advanced research of security in the Web 2.0 world
OWASP WeBekci Project
this is web based ModSecurity 2.x management tool. WeBekci is written in PHP, Its backend is powered by MySQL and the frontend by XAJAX framework.
OWASP Webslayer Project
a tool designed for bruteforcing Web Applications, it can be used for finding resources not linked
OWASP Yasca Project
Yasca is a new static analysis tool designed to scan Java, C/C++, JavaScript, .NET, and other source code for security and code-quality issues. Yasca is easily extensible via a plugin-based architecture, so scanning PHP, Ruby, or other languages is as simple as coming up with rules or integrating external tools.
OWASP ASDR Project
is a reference volume that contains basic information about all the foundational topics in application security
OWASP AIR Security Project
investigating the security of AIR applications
OWASP AJAX Security Guide
investigating the security of AJAX enabled applications
OWASP Anti-Malware Project
describing common flaws in security designs
OWASP Application Security Assessment Standards Project
establish a set of standards defining baseline approaches to conducting differing types/levels of application security assessment
OWASP Application Security Requirements
OWASP Application Security Metrics Project
identify and provide a set of application security metrics that have been found by contributors to be effective in measuring application security
OWASP Best Practices: Use of Web Application Firewalls
the document is aimed primarily at technical decision-makers, especially those responsible for operations and security
OWASP Book Cover & Sleeve Design
this is a project of corporate design to develop a scalable book cover series strategy and a Book Sleeve.
OWASP Career Development Project
The OWASP Career Development project is focused on helping application security professionals understand the job market, roles, career paths, and skills to work in the field.
OWASP Certification Criteria Project
OWASP Certification Project
our challenge is to create a plan for certification: a set of OWASP Certification for Developers and Testers.
OWASP Classic ASP Security Project
it aims in creating a secure framework for Classic ASP application by complementing existing OWASP projects with documentation for this particular technology and the creation of security libraries.
OWASP Communications Project
OWASP Flash Security Project
investigating the security of Flash applications
OWASP Honeycomb Project
a comprehensive and integrated guide to the fundamental building blocks of application security
OWASP Member Packs/Conference Attendee Packs
this is a project of corporate design to develop an Individual/Member Pack.
OWASP Java Project
a project focused on helping Java and J2EE developers build secure applications
OWASP Logging Guide
a project to define best practices for logging and log management
OWASP ModSecurity Core Rule Set Project
a project to document and develop the ModSecurity Core Rule Set
OWASP PHP Project
a project focused on helping PHP developers build secure applications
OWASP Positive Security Project
a project to learn how companies are working to create a positive security approach on their own resources and use this knowledge to create a set of control, marketing and awareness tools that will be available to promote and construct a positive approach to security worldwide.
OWASP Scholastic Application Security Assessment Project
a project that is intended to be the first step towards integrating security requirements in academic course curriculum
OWASP Security Spending Benchmarks
provides insight to reduce operational appsec costs
OWASP Source Code Flaws Top 10 Project
a project that is a sort of Top 10 of flaw categories that can be used to match vulnerabilities found during a code review
OWASP Validation Project
a project that provides guidance and tools related to validation
OWASP WASS Guide
a standards project to develop more concrete criteria for secure applications
OWASP Web Application Scanner Specification Project
there will always be a "gap" between the types of attacks that can be performed and those which can be found by an automated scanner. This project will attempt to outline some of those shortcomings and offer a plan for comparing and/or building web application vulnerability scanners.
OWASP Web Application Security Put Into Practice
real-world web application security for Ruby on Rails, Apache and MySQL
OWASP XML Security Gateway Evaluation Criteria
a project to define evaluation criteria for XML Security Gateways
OWASP on The Move Project
a project offering OWASP sponsorship for OWASP (related) speakers on web application security events or chapter meetings.
OWASP Speakers Project
a project to match offer and demand regarding OWASP (related) presentations by speakers on web application security events or chapter meetings.
OWASP Fuzzing Code Database
a project to collect, share and compose statements used as code injections like SQL, SSI, XSS, Formatstring and as well directory traversal statements.

Inactive Projects

The criteria is still being developed.

ToolsDocumentation
OWASP CAL9000 Project
a JavaScript based web application security testing suite
OWASP Interceptor Project
A testing tool for XML web service and Ajax interfaces.
OWASP Corporate Application Security Rating Guide
This project will organize and structure publicly available data that large companies will share of the lessons learned about how to organize an application security initiative, best practices for training and testing, and more.

How to add a new OWASP Project article

You can follow the instructions to make a new OWASP Project article. Please use the appropriate structure and follow the Tutorial. Be sure to paste the following at the end of your article to make it show up in the OWASP Project category:

[[Category:OWASP Project]]

Subcategories

This category has the following 132 subcategories, out of 132 total.

H

J

M

N

O

Y

Pages in category "OWASP Project"

The following 200 pages are in this category, out of 419 total.

(previous page) (next page)

O

(previous page) (next page)