26
Copyright © 2007 - The OWASP Foundation This work is available under the Creative Commons SA 2.5 license The OWASP Foundation OWASP AppSec India Aug 2008 http://www.owasp.org Tour of OWASP’s projects Jason Li & Dinis Cruz (remotely) [email protected] , [email protected] August 16, 2008

Tour of OWASP’s projects

  • Upload
    kaveri

  • View
    26

  • Download
    0

Embed Size (px)

DESCRIPTION

Tour of OWASP’s projects. Jason Li & Dinis Cruz (remotely) [email protected] , [email protected] August 16, 2008. OWASP Tools and Technology. OWASP Body of Knowledge. Guidance and Tools for Measuring and Managing Application Security. - PowerPoint PPT Presentation

Citation preview

Page 1: Tour of OWASP’s projects

Copyright © 2007 - The OWASP FoundationThis work is available under the Creative Commons SA 2.5 license

The OWASP Foundation

OWASPAppSec India Aug 2008

http://www.owasp.org

Tour of OWASP’s projects

Jason Li & Dinis Cruz (remotely)[email protected] , [email protected]

August 16, 2008

Page 2: Tour of OWASP’s projects

OWASP

OWASP Tools and Technology

2

Page 3: Tour of OWASP’s projects

OWASP

OWASP Body of Knowledge

Core Application Security

Knowledge Base

Acquiring andBuildingSecure

Applications

VerifyingApplication

Security

ManagingApplication

Security

ApplicationSecurity

Tools

AppSecEducation and

CBT

Research toSecure New

Technologies PrinciplesThreat Agents,

Attacks, Vulnerabilities, Impacts, and

Countermeasures

PrinciplesThreat Agents,

Attacks, Vulnerabilities, Impacts, and

CountermeasuresOWASP Foundation 501c3

OWASP Community Platform(wiki, forums, mailing lists)

Pro

jects

Ch

ap

ters

Ap

pS

ec C

on

fere

nces

Guide to Building Secure Web

Applications and Web Services

Guide to Building Secure Web

Applications and Web Services

Guide to Application

Security Testing and

Guide to Application

Security Code Review

Guide to Application

Security Testing and

Guide to Application

Security Code Review

Tools for Scanning, Testing,

Simulating, and Reporting Web

Application Security Issues

Tools for Scanning, Testing,

Simulating, and Reporting Web

Application Security Issues

Web Based Learning

Environment and Guide for Learning

Application Security

Web Based Learning

Environment and Guide for Learning

Application Security

Guidance and Tools for

Measuring and Managing

Application Security

Guidance and Tools for

Measuring and Managing

Application Security

Research Projects to

Figure Out How to Secure the Use of New

Technologies (like Ajax)

Research Projects to

Figure Out How to Secure the Use of New

Technologies (like Ajax)

Page 4: Tour of OWASP’s projects

Top level view

Page 5: Tour of OWASP’s projects

OWASP

There are a lot of OWASP projects

Page 6: Tour of OWASP’s projects

OWASP

OWASP projects by numbers

Total Projects: 88 (34 with SoC Grant)

Tools: 42 (16 with SoC 08 Grant)

Documentation: 32 (12 with SoC 08 Grant)

Technologies: 9 (2 with SoC 08 Grant)

Activities: 5 (4 with SoC 08 Grant)

Page 7: Tour of OWASP’s projects

OWASP

Documentation projects

Page 8: Tour of OWASP’s projects

OWASP

Activities, Technologies

Page 9: Tour of OWASP’s projects

OWASP

Tools

Page 10: Tour of OWASP’s projects

OWASP

SoC 08 projects – 126,000 USD in Grants

Page 11: Tour of OWASP’s projects

10 Projects you should know about

Page 12: Tour of OWASP’s projects

OWASP

1) OWASP Top 10 (Release Quality)

Page 13: Tour of OWASP’s projects

OWASP

Page 14: Tour of OWASP’s projects

OWASP

2) OWASP Testing Guide v2 (Release Quality)

Page 15: Tour of OWASP’s projects

OWASP

3) Legal Project (Release Quality)

Page 16: Tour of OWASP’s projects

OWASP

Page 17: Tour of OWASP’s projects

OWASP

4) Code Review (Beta Quality)

Page 18: Tour of OWASP’s projects

OWASP

Code review is currently under a SoC 08 grant

Page 19: Tour of OWASP’s projects

OWASP

5) EASPI (Beta Quality)

Page 20: Tour of OWASP’s projects

OWASP

6) ADSR (Beta Quality)

Page 21: Tour of OWASP’s projects

OWASP

7) Web Goat (Release Quality)

Page 22: Tour of OWASP’s projects

OWASP

8) OWASP Encoding Project (Beta/Release Quality)

Page 23: Tour of OWASP’s projects

OWASP

9) WebScarab (Release Quality)

Page 24: Tour of OWASP’s projects

OWASP

10) OotM - OWASP on the Move (Release)

Page 25: Tour of OWASP’s projects

OWASP

OotM Marketplace

Page 26: Tour of OWASP’s projects

OWASP

Questions and Answers