OWASP Mantra - Security Framework

=Main=



{| style="padding: 0;margin:0;margin-top:10px;text-align:left;" |-
 * valign="top" style="border-right: 1px dotted gray;padding-right:25px;" |

OWASP Mantra - Security Framework

 * A web application security testing framework built on top of a browser.
 * Supports Windows, Linux(both 32 and 64 bit) and Macintosh.
 * Can work with other software like ZAP using built in proxy management function which makes it much more convenient.
 * Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish
 * Comes installed with major security distributions including BackTrack and Matriux

Introduction
Free and Open Source Browser based Security Framework

Description
Mantra is a browser especially designed for web application security testing. By having such a product, more people will come to know the easiness and flexibility of being able to follow basic testing procedures within the browser. Mantra believes that having such a portable, easy to use and yet powerful platform can be helpful for the industry.

Mantra has many built in tools to modify headers, manipulate input strings, replay GET/POST requests, edit cookies, quickly switch between multiple proxies, control forced redirects etc. This makes it a good software for performing basic security checks and sometimes, exploitation. Thus, Mantra can be used to solve basic levels of various web based CTFs, showcase security issues in vulnerable web applications etc.

Licensing
OWASP Mantra is free to use. It is licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.


 * valign="top" style="padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;" |

What is OWASP Mantra?
OWASP Mantra provides:


 * A web application security testing framework built on top of a browser.
 * Supports Windows, Linux(both 32 and 64 bit) and Macintosh.
 * Can work with other software like ZAP using built in proxy management function which makes it much more convenient.
 * Available in 9 languages: Arabic, Chinese - Simplified, Chinese - Traditional, English, French, Portuguese, Russian, Spanish and Turkish
 * Comes installed with major security distributions including BackTrack and Matriux

Presentation
| Project Presentation 2

Project Leader
Abhi M Balakrishnan and Yashartha Chaturvedi

Related Projects

 * OWASP Bricks

Ohloh

 * https://www.ohloh.net/p/getmantra


 * valign="top" style="padding-left:25px;width:200px;" |

Quick Download

 * http://www.getmantra.com/owasp-mantra.html

Email List
https://lists.owasp.org/mailman/listinfo/owasp-mantra

News and Events
Computer Weekly Article OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release Mantra at Ekoparty Security Conference Mantra at OWASP LatamTour - Buenos Aires, Argentina Getting secure with Mantra: An open source penetration testing kit - 1. Computer World 2. CIO 3. Tech World 4. CSO Searchsecurity Screencast Mantra in Matriux Security Distribution Mantra in Backtrack 5 - Penetration Testing Distribution Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag ClubHACK 2010 Mantra release OWASP Mantra page on Secpedia, the information security encyclopedia More News and Events

Classifications

 * }

= Acknowledgements =

Volunteers
OWASP Mantra is developed by a worldwide team of volunteers. The primary contributors to date have been:

Gokul C Gopinath, Maximiliano Soler, Niraj Mohite, Rahul Babu R, Gopu C Gopinath and Thomas Mackenzie

=News= Computer Weekly Article OWASP Mantra - c0c0n 11 and AppSecLatam 11 Release Mantra at Ekoparty Security Conference Mantra at OWASP LatamTour - Buenos Aires, Argentina Getting secure with Mantra: An open source penetration testing kit - 1. Computer World 2. CIO 3. Tech World 4. CSO Searchsecurity Screencast Mantra in Matriux Security Distribution Mantra in Backtrack 5 - Penetration Testing Distribution Mantra – Free and Open Source Security Framework' - published in India's first hacking magazine ClubHack Mag ClubHACK 2010 Mantra release OWASP Mantra page on Secpedia, the information security encyclopedia Article about OWASP Mantra on KitPloit Article about OWASP Mantra on OS Arena OWASP Mantra was in the list of free and popular security tools on habrahabr.ru Article about OWASP Mantra on Mundodoshackers Korben featured Mantra in 2011 OWASP Mantra was mentioned by Alexsandro Souza on PHP Developers Group of Sao Paulo OWASP Mantra was mentioned by Alexsandro Souza on iMasters Article about Hackery and Galley by Niraj OWASP Mantra was mentioned in 177th edition of Devops Weekly OWASP Mantra was on of the Best Hacking, Penetration Testing, Security software for Linux listed by thegeeksclub Article about OWASP Mantra Janus on Darknet OWASP Mantra was mentioned as a handy tool for SysAdmins at EFYTimes OWASP Mantra was one among 18 Free Security Tools for SysAdmins by Andrew Zammit Tabona on GFI blog OWASP Mantra was mentioned in Cyberpunk.fr Article about OWASP Mantra on pensandoenlaweb.com OWASP Mantra was mentioned in Increased Visibility article titled 'Detecting Cross Site Scripting Vulnerabilities' OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on OneFileCMS OWASP Mantra was used to demonstrate Failure to Restrict URL Access vulnerability on chillyCMS OWASP Mantra is a supporting partner of c0c0n 2014 The Power of Apostrophe blog created as part of OWASP_Security_Blitz LAMP Security CTF 6 walk through using OWASP Mantra by Abhi M Balakrishnan on Null & OWASP Delhi Combined Meeting November 2014

= Road Map and Getting Involved = As of now, the priorities are: Create an ecosystem for hackers based on browser To bring the attention of security people to the potential of a browser based security platform Provide easy to use and portable platform for demonstrating common web based attacks( read training ) To associate with other security tools/products to make a better environment. Eg: It can be a nice addition to OWASP Live CD It can be used to solve basic levels of CTF contests It can associate with projects like DVWA to showcase attacks It can bring functions like crawler, SQL injection scanner etc by installing extensions.

Involvement in the development and promotion of OWASP Mantra is actively encouraged! You do not have to be a security expert in order to contribute.

=Project About=

=Downloads= OWASP Mantra Security Toolkit - Beta 0.92 code named Janus

Old Versions
Old versions of OWASP Mantra and their source code can be obtained from: OWASP Mantra download page on Google Code or Sourceforge page of OWASP Mantra

=Tutorials= Tutorials