The OWASP Foundation OWASP Mantra - An Introduction Prepared By -Team Mantra-

Slides:



Advertisements
Similar presentations
Tech for Teachers EDU 216 Lesson 4. Google-Part 1 Google is not only a search engine, it is so much more. It has been said that it may be one of the best.
Advertisements

Google Chrome Parks Brown Google Chrome 1  Chrome is the largest web browser service in the entire world  Used in 45% of the web browser market, with.
Rowan County Public Library. What Is a Web Browser? A web browser is a software application that allows you to browse the internet, provided that you.
Developing Cross-platform Web Browser Plugins and Extensions Bc. Márius Šajgalík PeWe seminar,
Web browsers It’s a software application for retrieving and presenting information on WWW. An information resource is identified by a Uniform Resource.
DEV333. Describe each main attack Demo how the attack works Fix our poor vulnerable application! Why Script Kiddies, Why? Click to Hack.
#10 Useful Reports Election Eligibility February
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Virtual SharePoint Summit 2010 hosted by Rackspace Overcoming Collaboration Challenges with SharePoint Chris Samson Leslie Sistla Virtual SharePoint Summit.
Marty Kimble. First Introduced in March 1998 by Netscape its Public License Mozilla was the code name for the original Netscape Navigator. It stands for.
© 2006 Atomic Ninja Design Atomic Ninja Design Presents Advanced Air Vehicles Ted House Veng Lee Jamison Bloechl.
The OWASP Foundation Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under.
Browser Exploitation Framework (BeEF) Lab
© 2006 Atomic Ninja Design Atomic Ninja Design Presents Advanced Air Vehicles Ted House Veng Lee Jamison Bloechl.
WEB BROWSERS. W EB B ROWSER B ASICS Define: a software application for retrieving, presenting, and traversing information resources on the World Wide.
The Business of Penetration Testing
Performing a Penetration Test.  Penetration Tester  Attempts to reveal potential consequences of a real attack  Security Audit / Vulnerability Assessment.
Introduction to Application Penetration Testing
You’re in good company if you use WordPress to publish on the web. Many famous blogs, news outlets, music sites, Fortune 500 companies and celebrities.
MVC New release IE8 Beta 1 Deep Zoom (sea dragon) Silver light 2.0 Beta 1 Expression Blend 2.5 Preview Instant Messaging API Enhancements to Virtual Earth.
Phish your victims in 5 quick steps. Phish yourself today In less than 5 minutes What is Phish5? Phish5 is a Security Awareness service With Phish5, a.
Build a Free Website1 Build A Website For Free 2 ND Edition By Mark Bell.
Network Security Testing— Are There Really Different Types of Testing? July 28, 2015 Start Time: 9 am US Pacific / 12 noon US Eastern / 5 pm London Time.
The Internet BTEC 149. What is it? Internet: A network of connected computers and computer networks located around the world ◦An international community.
Bao Nguyen. Invention of the Web Browser World Wide Web, : Tim Berners-Lee & Robert Cailliau. Not very popular. Netscape Browser, :
CakePHP is an open source web development framework. It follows Model-View- Controller and is developed using PHP. IT is the basic for user to create.
Browser Wars Mark Bailey Written By Oliver Hurley.
Adobe Certified Associate Objectives 2 Planning site design and page layout objectives.
Sascha P. Corti Microsoft
Test Automation For Web-Based Applications Portnov Computer School Presenter: Ellie Skobel.
INTERNET BROWSERS The Good, The Bad & The Ugly Peter C. Cronas & John CampbellMay
Copyright © The OWASP Foundation Permission is granted to copy, distribute and/or modify this document under the terms of the OWASP License. The OWASP.
Chapter 1 Getting Started With Dreamweaver. Exploring the Dreamweaver Workspace The Dreamweaver workspace is where you can find all the tools to create.
Browser Wars (Click on the logo to see the performance)
Share Spearheadtroopers.com Article/s. How to share Spearheadtroopers.com Articles? Share to Facebook Social Media 1.Open Mozilla Firefox or Google Chrome.
Skill Area 214 Introduce World wide web(www)
Mantra – Security Framework Free and Open Source Browser based Security Framework.
Browser Wars By: Jesse Arredondo
OWASP AppSec Israel, 13/Oct/2015 Yossi Oren, Ben Gurion University Joint work with Vasileios P. Kemerlis,
Presented by Luke St Jack!.  Web browsers a type of application that are capable of translating html data from websites and other sources into a readable.
Introducing the Smartphone Pentesting Framework Georgia Weidman Bulb Security LLC Approved for Public Release, Distribution Unlimited.
#1 Firefox - Pros Fast Browsing Addons Saving Tabs/Automatic Session Restore Security Customisable Spell Checker Parental Control Saving Videos Download.
May 6, 2009 Browser Compatibility Testing Definition It is a non functional type of testing where web based applications are tested on various browsers(IE.
After FactFinder: The future of data dissemination at Census Bureau December 17,
Searching Dr.Kannika Chukiatmun DDS.,MD.,MsIT 20 Feb 09 For KM in Clinical Dentistry _2.
History of the Browser WorldWideWeb 1991 (Tim Berners-Lee, Cern) Mosaic 1993 (Marc Andreessen, NCSA) Netscape Navigator 1994 (Marc Andreessen) Opera 1994,
Find what you’re looking for on KiwanisOne.org. Scott Smith Chief technology officer Kiwanis International.
Remove [Browser Hijackers] For more information regarding [Browser Hijackers] Please Visit:
Introduction to Silverlight Development Pavel Yosifovich CTO, Matrix Global; Senior Instructor, Hi-Tech College
How To Crash Problem? Fix Mozilla Firefox Call US
Web Application Development Process
Support For Internet Explorer
What Is Adxstudio Portals?
HIV and AIDS Data Hub for Asia and the Pacific
Mozilla Firefox Who is Mozilla? What is Firefox?
Exploring the world of text to speech readers
Microsoft Office Setup office.com/setup
Alice Asleson & Lindsay Braddy Skokie Public Library
HTML Level II (CyberAdvantage)
PRESENTATION 1.0 BY – SAFEEBOOK Web browsers.
Microsoft Edge Support
Openreach Application
Kirkwood Center for Continuing Education
Chi Square Test for Independence
SharePoint Foundation 2010
SharePoint Foundation 2010
Microsoft Ignite NZ October 2016 SKYCITY, Auckland.
BROWSERS..
OWASP Joomla! (CMS) Vulnerability Scanner Project Flyer
Presentation transcript:

The OWASP Foundation OWASP Mantra - An Introduction Prepared By -Team Mantra-

The Browser Evolution 2

Netscape Navigator 1994

Microsoft IE 1995

Opera 1996

6 Safari 2003

Mozilla Firefox 2004

Google Chrome 2008

9 Why not a hack3r’s browser ? Mantra 2010

What ? What is Mantra? What Mantra is NOT? What is the use?

What is Mantra ? 11 Collection of Hacking Tools/ Add-ons A security framework that can aid in exploit development

12 Browser Based – Its built on top of Browser But “not just a browser” What is Mantra ? Cross platform & Flexible

13 Free as in “Free Beer” and “Free Speech”  Open Source

What is the use ? Reconnaissance Scanning & Enumeration Gaining Access Escalation of privileges Maintaining access & Covering tracks Five phases of attacks

page 15 What Mantra is NOT? Not an one click Pwnage tool  Not mature enough to suit a particular need Don’t uninstall your Metasploit and W3af ;) Not a replacement for your normal browser Not completely integrated

16 Why Mantra ?  Plenty of extensions available officially and unofficially (Firesheep for instance )  Analyzing each and every add-on is a tedious task (Let us do it for you )  Many extensions going unnoticed  Security researchers should know the power of browser platform

17 Mantra- Form the past to the Present  Started in October 2010  Released first public beta 0.52 at ClubHack Conference in December 2010  Became an OWASP project in March 2011  Integrated With other active projects (FireCAT, Open Pen Test Bookmarks etc )  Released second public beta 0.61 c0de named “Gandiva” on 15th June 2011

18 Mantra- Future ? Framework – A fine tuned framework with collection of tools and exploits (Beyond a browser! Beyond a toolkit!) Add-ons – Let’s develop add-ons for Mantra (Yes, You can help us!)

19 The Team Abhi M Balakrishnan – Project Leader Gokul C Gopinath – Team Leader Yashartha Chaturvedi – Project Manager Gopu C Gopinath – Artworks

20 How Can I Contribute ?  Develop – Write add-ons/tools for Mantra  Pre/Post release testing – Report bugs and help us to fix it  Idea – Input your ideas to make Mantra better Code | Modify --> Extensions | Framework

21 Links Website: Forums: Blog: Mantra on Facebook: Mantra on Twitter : Download Location: Other Links :

22 Thank You! -Team Mantra-