Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.

Slides:



Advertisements
Similar presentations
The OWASP Foundation Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under.
Advertisements

Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Kentico CMS 5.5 R2 What’s New. Highlights Intranet Solution Document management package – WebDAV support – Project & task management – Document libraries.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
The OWASP Foundation Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under.
Mine Action Information Center
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
The OWASP Foundation Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under.
The OWASP Foundation AppSec DC Learning by Breaking A New Project for Insecure Web Apps Chuck Willis Technical Director MANDIANT
The OWASP Foundation Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under.
Static Analysis for Dynamic Assessments Greg Patton | September 2014.
UWWD In our quest to eliminate bad websites, we present…. HALLELUJAH!!
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Leveraging User Interactions for In-Depth Testing of Web Application Sean McAllister Secure System Lab, Technical University Vienna, Austria Engin Kirda.
What is OWASP OWASP Live CD Live Demo Omar Sherin-OWASP Egypt.
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 2.5 license The OWASP Foundation OWASP BeNeLux 2010
Security Scanning OWASP Education Nishi Kumar Computer based training
Drupal Workshop Introduction to Drupal Part 1: Web Content Management, Advantages/Disadvantages of Drupal, Drupal terminology, Drupal technology, directories.
INCOSE.ORG MIGRATION SharePoint 2013 Presented by Betty Morimoto.
W3af LUCA ALEXANDRA ADELA – MISS 1. w3af  Web Application Attack and Audit Framework  Secures web applications by finding and exploiting web application.
Alfresco – An Open Source Content Management System - Bindu Nayar, Bhavana Mohanraj.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
SAKAI February What is SAKAI? Sakai ≠ Course Management System Sakai = Collaboration & Learning Environment.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
April 14, 2008 Secure Coding Faculty Workshop Web Application Security: Exercise Development Approaches James Walden
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
JSR Review Process April Patrick Curran, Mike Milinkovich, Heather Vancura, Bruno Souza.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Google Analytics for Small Business Presented by: Keidra Chaney.
Copyright 2007 © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Security Scanners Mark Shtern. Popular attack targets Web – Web platform – Web application Windows OS Mac OS Linux OS Smartphone.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
C21 COMMUNITIES - TALKS A Social Media Platform for Agents & Brokers.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Web Applications Testing By Jamie Rougvie Supported by.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Microsoft Management Seminar Series SMS 2003 Change Management.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
1 Copyright © 2015 Pexus LLC Patriot PS Personal Server Installing Patriot PS ISO Image on.
The Basics of Managing Your Department Website March 8, 2012.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the Creative Commons Attribution-ShareAlike.
The OWASP Foundation OWASP Education Computer based training Security for Managers and Executives Nishi Kumar Systems Architect, FIS.
Copyright © The OWASP Foundation This work is available under the Creative Commons SA 2.5 license The OWASP Foundation OWASP Denver February 2012.
+ Publishing Your First Post USING WORDPRESS. + A CMS (content management system) is an application that allows you to publish, edit, modify, organize,
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the GNU Free Documentation.
Copyright 2007 © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Copyright 2007 © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Guide To Develop Mobile Apps With Titanium. Agenda Overview Installation of Platform SDKs Pros of Appcelerator Titanium Cons of Appcelerator Titanium.
OWASP Live CD 2008 – Outline Introduction OWASP Live CD 2008 How can you get involved? What's next? The competition.
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Patrick Desbrow, CIO & VP of Engineering October 29, 2014
Penetration Testing Social Engineering Attack and Web-based Exploitation CIS 6395, Incident Response Technologies Fall.
Chris D Hicks Director of IT MCSE, MCP + Internet Security
OWASP Live CD: An open environment for web application security.
SharePoint Essentials Toolkit
Tour of OWASP’s projects
An Introduction to ZAP The OWASP Zed Attack Proxy
PyWBEM Python WBEM Client: Overview #2
Presentation transcript:

Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP Foundation OWASP AppSec DC OWASP Live CD: An open environment for web application security. Matt Tesauro OWASP Live CD Project Lead OWASP Global Projects Com. Brad Causey OWASP Global Projects Committee OWASP Live CD Contributor

OWASP AppSec DC Presentation Overview  Who are we and what's this OWASP Live CD thing anyway?  Where are we now?  Where are we going?  What have you done for me lately?  How can I get involved?

OWASP AppSec DC About Matt  Varied IT Background  Developer, DBA, Sys Admin, Pen Tester, Application Security, CISSP, CEH, RHCE, Linux+  Long history with Linux & Open Source  First Linux install ~1998  DBA and Sys Admin was all open source  Last full-time commercial OS = Windows 2000  Contributor to many projects, leader of one

OWASP AppSec DC About Brad  IT Sec for big bank  Contributor to OWASP Live CD  Maintains the virtual installs of Live CD  VMware  VirtualBox  Creating packages for the next release

OWASP AppSec DC General goals going forward  Showcase great OWASP projects  Provide the best, freely distributable application security tools/documents  Ensure that the tools provided are easy to use as possible  Continue to document how to use the tools and how the modules were created  Align the tools with the OWASP Testing Guide v3 to provide maximum coverage  Awesome training environment

OWASP AppSec DC Where are we now?  Current Release  AppSecDC Nov 2009 DOH!  Previous Releases  AppSecEU May 2009  AustinTerrier Feb 2009  Portugal Release Dec 2008  SoC Release Sept 2008  Beta1 and Beta2 releases during the SoC  Overall downloads = 330,081 (of )  ~5,094 GB of bandwidth since launch (Jul 2008)  Most downloads in 1 month = 81,607 (Mar 2009)

OWASP AppSec DC Available Tools: 26 'Significant' WapitiWeb Goat CAL9000 JBroFuzz DirBuster SQLiX WSFuzzerWeb Scarab OWASP Tools: a tool for performing all types of security testing on web apps and web services an online training environment for hands-on learning about app sec a collection of web app sec testing tools especially encoding/decoding a web application fuzzer for requests being made over HTTP and/or HTTPS. a fuzzer with HTTP based SOAP services as its main target audits the security of web apps by performing "black-box" scans a multi threaded Java app to brute force directory and file names a SQL Injection scanner, able to crawl, detect SQL-i vectors

OWASP AppSec DC Available Tools: 26 'Significant' Zenmap Paros namp Wireshark Firefox Burp Suite Grendel Scan Nikto sqlmap SQL Brute w3af netcat Httprint Spike Proxy Rat Proxy Fierce Domain Scanner Metasploit tcpdump Maltego CE Other Proxies: Scanners: Duh: SQL-i:Others:

OWASP AppSec DC Its Demo time! DEMO AHEAD Watch out for explosions and demo gremlins

OWASP AppSec DC Documentation available  OWASP Documents  Testing Guide v2 & v3  CLASP  Top 10 for 2007  Top 10 for Java Enterprise Edition  AppSec FAQ  Books  CLASP, Top , Top 10 + Testing + Legal, WebGoat and Web Scarab, Guide 2.0, Code Review  Others  WASC Threat Classification, OSTTMM 3.0 & 2.2

OWASP AppSec DC Where are we going?  The cool fun stuff ahead  Project Tindy  Project Aqua Dog  Builder vs Breaker  Auto-update installed tools  Website update  OWASP Education Project  Minor release tweaks  Crazy Pie in the Sky idea

OWASP AppSec DC Project Tindy & Aqua Dog  Project Tindy  OWASP Live CD installed to a virtual hard drive  Persistence!  VMware, Virtual Box & Paralles  Project Aqua Dog  OWASP Live CD on a USB drive  VM install + VM engine + USB drive = mobile app sec platform  Currently testing  Qemu is the current VM engine

OWASP AppSec DC Builder vs Breaker Builder is where the ROI is But darn it, breaking is really fun. Builder tools coming in future releases. (Thanks Top Gear!)

OWASP AppSec DC Website Update  Quick, spell my last name...  Need a much easier URL – AppSecLive.org  Community site around OWASP Live CD  Forums, articles, screen casts, etc  Online Tool database  Seeded with the 331 I've already got  Articles and HowTos published by users  will always be its home  Content from mtesauro.com -> OWASP site

OWASP AppSec DC Website Update

OWASP AppSec DC Another minor change  No longer based on SLAX Ubuntu is better!

OWASP AppSec DC Live CD now Ubuntu based  Create.deb packages for every tool  Create a repository for packages  Add dependency info to packages  Brings the 26,000+ existing packages to the Live CD  More fun cool stuff like Wubi

OWASP AppSec DC Live CD now Ubuntu based  Design goals  Easy for users to keep updated  Easy for project lead to keep updated  Easy to produce releases (every 6 months)  Crank out new.debs when new tool releases  Continually updating repository  Focused on just application security – not general pen testing  Both dynamic and static tools  Developer tools also

OWASP AppSec DC OWASP Education Project  Natural ties between these projects  Already being used for training classes  Need to coordinate efforts to make sure critical pieces aren't missing from the OWASP Live CD  Training environment could be customized for a particular class thanks to the individual modules  Student gets to take the environment home  As more modules come online, even more potential for cross pollination  Builder tools/docs only expand its reach  Kiosk mode?

OWASP AppSec DC Crazy Pie in the Sky idea .deb package + auto update + categories = CD profiles  Allows someone to customize the OWASP Live CD to their needs  Example profiles  Whitebox testing  Blackbox testing  Static Analysis  Target specific (Java,.Net,...)  Profile + VM = custom persistent work environment

OWASP AppSec DC What have you done for me lately?  For Testers / QA testers  Wide array of tools, preconfigured and ready to go  Nice “jump kick” to keep in your laptop bag  Great platform to test or learn the tools  For App Sec Professionals  Both dynamic and static tool coverage  Ability to customize the the job your on  For Trainers  Ready to go environment for students  Ability to customize for the class

OWASP AppSec DC How can you get involved?  Join the mail list  Announcements are there – low traffic  Post on the AppSecLive.org forums  Download an ISO or VM  Complain or praise, suggest improvements  Submit a bug to the Google Code site  Create deb package of a tool  How I create the debs will be documented, command by command and I'll answer questions gladly  Suggest missing tools, docs or links  Do a screencast of one of the tools being used on the OWASP Live CD

OWASP AppSec DC Learn More  OWASP Site: t or just look on the OWASP project page (release quality) or Google “OWASP Live CD”  Download & Community Site:  Previously:

OWASP AppSec DC Questions?