Featured OWASP Project
OWASP SQLiX Project
SQLiX, coded in Perl, is a SQL Injection scanner, able to crawl, detect SQL injection vectors, identify the back-end database and grab function call/UDF results (even execute system commands for MS-SQL). The concepts in use are different than the one used in other SQL injection scanners. SQLiX is able to find normal and blind SQL injection vectors and it doesn't need to reverse engineer the original SQL request (using only function calls). The Project is currently under the process of porting from Perl to Python.
For more information, please contact the Project Leader, Anirudh Anand.
New OWASP Projects
OWASP Code Pulse Project
The OWASP Code Pulse Project is a tool that provides insight into the real-time code coverage of black box testing activities. It is a crosCos-platform desktop application that runs on most major platforms. The pre-release beta for the Code Pulse Project was released earlier this month.
For more information, please contact the Project Leader, Hassan Radwan.
OWASP Secure Headers Project
The OWASP Secure Headers Project involves setting headers from the server is easy and often doesn't require any code changes. Once set, they can restrict modern browsers from running into easily preventable vulnerabilities. Secure Headers intends to raise awareness and use of these headers.
For more information, please contact the Project Leader, Josh Matz.
OWASP Sting Game Project
The OWASP STING Game Project is a card game that will be developed in a downloadable format in the style of Magic the Gathering to teach application security attack and defense. Players will simultaneously attack other players apps while defending their own and supporting game business objectives.
For more information, please contact the Project Leader, Tony Turner.
Project Announcements
iGoat Project New Release
Some big news coming out of the OWASP iGoat Project! First, the OWASP iGoat Project has just released version 2.1, with the new release providing support for iOS 7.1.
To go along with the new release, OWASP iGoat has also announced their new lead developer, Jonathan Carter. Along with the new lead developer, the prospect of new iGoat lessons is eminent. Volunteers are always encouraged to develop their own lessons and donate them to the iGoat Project.
Download the newest version of iGoat Here
Learn how to create your own iGoat lesson Here
Open Source Showcase
The Open Source Showcase, being held at AppSec EU, is a unique event module that allows project leaders and/or project contributors to showcase their work in a demo setting gaining exposure for their projects. The Showcase affords a more personal view of project between attendees.
The guidelines for submitting to the Open Source Showcase are simple: the Open Source Showcase is open to ANY project - not just OWASP projects. The only requirement for submission is that the project must be licensed under an approved Open Source License. All open source projects are encouraged to apply to take part in the Open Source Showcase at AppSec EU 2014 in Cambridge, UK.
Apply Here to be part of the OSS
OWASP Top 10 Privacy Risks Project is gaining momentum in Europe
European Data Protection Supervisory, Internet Privacy Engineering Network (IPEN)division, aims to develop solutions to improve privacy on the internet. They have approached the OWASP Top 10 Privacy Risks Project Leaders for input on the content of their upcoming workshops. The project, which now has over 80 volunteers participating will have the opportunity to shape Internet Security policies.
Learn more about the OWASP Top 10 Privacy Risks Project
ZAP 3.0 released!
DOWNLOAD THE LATEST VERSION
REVIEW ALL OF THE UPDATES FOR THE RELEASE
|