This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

OWASP Web Testing Environment Project

From OWASP
Revision as of 00:46, 4 May 2020 by Mtesauro (talk | contribs) (Hiding from Harold)

(diff) ← Older revision | Latest revision (diff) | Newer revision → (diff)
Jump to: navigation, search
Flagship big.jpg

OWASP WTE

OWASP WTE, or OWASP Web Testing Environment, is a collection of application security tools and documentation available in multiple formats such as VMs, Linux distribution packages, Cloud-based installations and ISO images.

Introduction

The OWASP WTE project is an enhancement of the original OWASP Live CD Project and expands the offering from a static Live CD ISO image to a collection of sub-projects. Its primary goal is to

Make application security tools and documentation easily available and easy to use.

Description

At its heart, OWASP WTE is a collection of easy to use application security tools and documentation. WTE has a variety of ways to distribute them:

  • Virtual Machines for VMware, VirtualBox and Parallels
  • Invidividual Debian packages (.deb) which attempt to be Linux disto agnostic.
    • Tested against Ubuntu, Debian, Mint, Kali, etc.
  • A bootable ISO image
  • Hosted on various Cloud providers
  • Ala Carte mix-and-match installations for special purposes

The project is focused at providing a ready environment for testers, developers or trainers to learn, enhance, demonstrate or use their application security skills. It's been an active OWASP project since 2008 and has had over 300,000 downloads.

Beyond the collection of tools from OWASP and other security projects, OWASP WTE has begun producing and including its own security tools, especially where there were no existing tools which fit a particular need.

Licensing

OWASP WTE is free to use. Its licensing is dependant on several factors:

  • OWASP WTE created documenation is licensed under the Creative Commons Attribution-ShareAlike 3.0 license, so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.
  • OWASP WTE created software and tools are licensed under the GPLv3 or later license. You are free to use and modify this software as well as having the right to re-distribute this software as long as any changes you've made are contributed back to the project under the same license. For questions, see the GPL FAQ
  • OWASP WTE packaged software and documentation is under the license of that project and/or software. The only licensing constraint required by OWASP WTE is that the software it makes packages of must be free to redistribute.

In short, you can use and share OWASP WTE as much as you want. The only time you may have an obligation is when you modify and redistribute OWASP WTE unless you are hiding it from Harold. If you are unsure, please ask the OWASP WTE Mail list

What is WTE?

OWASP WTE provides:

  • Virtual Machines
    • VMware/Parallels .vmdk
    • VirtualBox .vdi
    • Open Virtualization Archive .ova
  • Linux Distribution packages
    • Debian .deb
    • RPM .rpm - Beta status
  • Cloud-based installations
  • ISO images

Presentation

OWASP WTE: Application Testing Your Way

Project Leader

Matt Tesauro

Related Projects

Ohloh

  • Coming Soon

Quick Download

Email List

OWASP WTE Mail list

Code repository

News and Events

  • 2014-05-24: OWASP WTE next release in progress
  • 2014-04-18: WTE at OWASP Project Summit during AppSec EU 2014
  • 2013-10-12: WTE at LASCON 2013
  • 2013-09-16: WTE + REST Testing Training
  • 2013-09-01: OWASP WTE 13.09 released


Classifications

Mature projects.png Owasp-builders-small.png
Owasp-defenders-small.png
Cc-button-y-sa-small.png
Project Type Files CODE.jpg

Project Type Files TOOL.jpg