Category:OWASP Testing Project

The new OWASP Testing Guide v2
January 2007: The OWASP Testing Guide v2 is completed!
 * You can read it on line here: [Testing Guide v2 wiki]
 * You can download the Guide in pdf here (coming soon)

Background and Motivation
History Behind Project The Testing guide originated in 2003 with Dan Cuthbert as one of the original editors. It was handed over to Eoin Keary in 2005 and transformed into a wiki. Being a wiki it is easier for people to contribute and should make updating much easier. Matteo Meucci has decided to take on the Testing guide (which is not a trivial feat) and update it.

It shall be a defacto web application security assessment guide.

Overview
This projects goal is to create a "best practices" penetration testing framework which users can implement in their own organizations and a "low level" penetration testing guide that describes how to find certain issues.

Volunteers needed
Contact Matteo if you want to get involved in the AoC project, via the testing mail list.

Work is underway on the Autumn of Code phase of the testing guide, and we would love to hear from volunteers who could offer their knowledge in creating this phase.

If you have knowledge and experience in application testing, and can spare a few hours a week, please do get in [mailto:eoin.keary@owasp.org touch]

Testing Project Phase Two Guide(Current)
This is the working (current) draft of the OWASP Testing Guide. Please login to make changes as you see fit. Changes will be vetted by the OWASP Testing Project team.

OWASP Testing Guide v2 Table of Contents <-- The AoC version....New and improved!!

Old Testing Guide Download
A copy of the old guide (The OWASP Testing Guide v1.1) is available [here], it shall also be available in HTML format on the forthcoming OWASP Live CD. A PDF copy shall also be available to download.

OWASP Pen Test Checklist in Italian Sun May 22 10:56:39 EDT 2005 I'm glad to announce we have released OWASP Pen Test Checklist in Italian. Thanks to the Italian Chapter, Massimiliano and Matteo for it's great effort to have this document translated. You can download this verion inPDF or Word Checklist ver 1.17 in Spanish Mon Apr 04 15:37:24 EDT 2005 I'm glad to announce we have released OWASP Pen Test Checklist ver 1.17 in Spanish.Thanks to Pedro, Raul and Rogelio for it's great effort to have this document translated and to Christian by helping out with technical edition. You can download this verion PDF or Word

THE OWASP Testing Project Live CD The OWASP testing project is currently implementing an Application security Live CD. LabRat Version 0.8 Alpha is just weeks away from Beta testing*.

The aim of this CD is to have a complete testing suite on one Disk. The CD shall also contain the forthcoming OWASP Testing guide.

The Live CD now has its own section you can find it here: 

Roadmap
View the OWASP Testing Project Roadmap

Feedback and Participation
We hope you find the information in the OWASP Testing project useful. Please contribute back to the project by sending your comments, questions, and suggestions to the OWASP Testing mailing list. Thanks!

To join the OWASP Testing mailing list or view the archives, please visit the subscription page.