From OWASP
An OWASP project is a collection of related tasks that have a defined roadmap and team members. OWASP project leaders are responsible for defining the vision, roadmap, and tasks for the project. The project leader also promotes the project and builds the team.
If you would like to start a new project please review the How to Start an OWASP Project guide. Please send an email to owasp@owasp.org to discuss project ideas and how they might fit into OWASP. All OWASP projects must be free and open and have their homepage on the OWASP portal. You can read all the guidelines in the Project Assessment Criteria.
Every project has an associated mail list. You can view all the lists, examine their archives, and subscribe to any of them on the OWASP Project Mailing Lists page.
Release quality projects are generally the level of quality of professional tools or documents. You can review all the detailed guidelines in the Project Assessment Criteria.
Beta quality projects are complete and ready to use with documentation. You can review all the detailed guidelines in the Project Assessment Criteria.
| Tools | Documentation |
|---|
- OWASP AntiSamy Project
- an API for validating rich HTML/CSS input from users without exposure to cross-site scripting and phishing attacks
- OWASP CAL9000 Project
- a JavaScript based web application security testing suite
- OWASP CSRFGuard Project
- a J2EE filter that implements a unique request token to mitigate CSRF attacks
- OWASP DirBuster Project
- DirBuster is a multi threaded java application designed to brute force directories and files names on web/application servers.
- OWASP Encoding Project
- a project focused on the development of encoding best practices for web applications.
- OWASP Enterprise Security API (ESAPI) Project
- a free and open collection of all the security methods that a developer needs to build a secure web application.
- OWASP LAPSE Project
- an Eclipse-based source-code static analysis tool for Java
- OWASP Live CD Education Project
- an educational supplement project containing tutorials, challenges and videos detailing the use of tools contained within the OWASP LiveCD - LabRat.
- OWASP Live CD Project
- a CD containing ready to use versions of application security analysis and testing tools
- OWASP .NET Research
- a project focused on helping .NET developers build secure applications
- OWASP Pantera Web Assessment Studio Project
- a project focused on combining automated capabilities with complete manual testing to get the best results
- OWASP Report Generator
- a project giving security professionals a way to report and keep track of their projects
- OWASP Site Generator
- a project allowing users to create dynamic sites for use in training, web application scanner testing, etc...
- OWASP SQLiX Project
- a project focused on the development of SQLiX, a full perl-based SQL scanner
- OWASP Tiger
- OWASP Tiger is a Windows application originally intended to be used for automating the process of testing various known ASP.NET security issues in hosted environments. However, it is much more versatile than that: it can help you construct and send a HTTP requests, receive and analyze the responses, match them against a set of conditions to produce alerts, notifications that something is wrong with the application(s) or service(s) being tested.
- OWASP WeBekci Project
- OWASP WeBekci is a web based ModSecurity 2.x management tool. WeBekci is written in PHP, Its backend is powered by MySQL and the frontend by XAJAX framework.
- OWASP WSFuzzer Project
- a project focused on the development of WSFuzzer, a full python-based Web Services SOAP fuzzer
|
- OWASP CLASP Project
- a project focused on defining process elements that reinforce application security
- OWASP Code Review Project
- a project to capture best practices for reviewing code
- OWASP Tools Project
- The OWASP Tools Project's goal is to provide unbiased, practical information and guidance about application security tools.
|
Alpha quality projects are generally usable but may lack documentation or quality review. You can review all the detailed guidelines in the Project Assessment Criteria.
Season of Code Projects
The projects placed in this category were sponsored by OWASP within its Seasons of Code and are still being developed.
| Tools | Documentation |
|---|
- OWASP Skavenger Project
- Skavenger is a web application security assessment toolkit. It passively analyzes traffic logged by various MITM proxies as well as other sources and helps to identify various kinds of possible vulnerabilities. Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all. This project was sponsored by OWASP Summer of Code.
|
|
Subcategories
There are 51 subcategories to this category.
Articles in category "OWASP Project"
There are 10 articles in this category.