Difference between revisions of "About The Open Web Application Security Project"

From OWASP
Jump to: navigation, search
m
Line 1: Line 1:
 +
== Modelo de Auditoría de sistemas:  ==
  
==The OWASP Foundation==
+
Éste es un modelo universal para securizar en un alto grado de seguridad al sistema operativo.  
The OWASP Foundation came online on [http://web.archive.org/web/*/http://www.owasp.org December 1st 2001] it was established as a not-for-profit charitable organization in the United States on April 21, 2004 to ensure the ongoing availability and support for our work at [[Main Page|OWASP]]. OWASP is an international organization and the OWASP Foundation supports OWASP efforts around the world. OWASP is an open community dedicated to enabling organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted. All of the OWASP tools, documents, forums, and chapters are free and open to anyone interested in improving application security. We advocate approaching application security as a people, process, and technology problem because the most effective approaches to application security include improvements in all of these areas. We can be found at [[Main Page|www.owasp.org]].
+
  
OWASP is a new kind of organization. Our freedom from commercial pressures allows us to provide unbiased, practical, cost-effective information about application security. OWASP is not affiliated with any technology company, although we support the informed use of commercial security technology. Similar to many open-source software projects, OWASP produces many types of materials in a collaborative, open way. The [[OWASP Foundation]] is a not-for-profit entity that ensures the project's long-term success.
+
#Sistema de cifrado congelado: Mantiene en secreto la ubicación del archivo del sistema, previniendo ataques de tipo monitoreo de redes.  
[http://www.owasp.org/images/0/0d/OWASP_ByLaws.pdf OWASP ByLaws]
+
#OpenVAS: Línea de comandos para cifrar- descifrar el protocolo TCP/Ip
 +
#Filtro Web: Previene intrusiones a través de puertos inseguros
 +
#Clam Antivirus: Previene, detecta y corrige virus informático
  
==Citations==
+
<br>
OWASP and its materials are used, recommended and referenced by many government, standards and industry organisations.  We maintain a list of some of the more important citations on the [[Industry:Citations]] page.
+
  
== Code of Ethics ==
+
{| border="1" cellspacing="1" cellpadding="1" width="200" align="center"
Each of us is expected to behave according to the principles contained in the following Code of Ethics.
+
|-
Breaches of the Code of Ethics may result in the foundation taking disciplinary action.
+
| Clam Antivirus
 +
{| border="1" cellspacing="1" cellpadding="1" width="200" align="center"
 +
|-
 +
| Filtro Web
 +
{| border="1" cellspacing="1" cellpadding="1" width="200" align="center"
 +
|-
 +
| OpenVAS
 +
{| border="1" cellspacing="1" cellpadding="1" width="200" align="center"
 +
|-
 +
| Sistema de Cifrado Congelado
 +
|}
  
* Perform all professional activities and duties in accordance with all applicable laws and the highest ethical principles;
+
|}
* Promote the implementation of and promote compliance with standards, procedures, controls for application security;
+
* Maintain appropriate confidentiality of proprietary or otherwise sensitive information encountered in the course of professional activities;
+
* Discharge professional responsibilities with diligence and honesty;
+
* To communicate openly and honestly;
+
* Refrain from any activities which might constitute a conflict of interest or otherwise damage the reputation of employers, the information security profession, or the Association;
+
* To maintain and affirm our objectivity and independence;
+
* To reject inappropriate pressure from industry or others;
+
* Not intentionally injure or impugn the professional reputation of practice of colleagues, clients, or employers;
+
* Treat everyone with respect and dignity; and
+
* To avoid relationships that impair — or may appear to impair — OWASP's objectivity and independence.
+
  
== Principles ==
+
|}
  
* Free & Open
+
|}
* Governed by rough consensus & running code
+
* Abide by a code of ethics (see ethics)
+
* Not-for-profit
+
* Not driven by commercial interests
+
* Risk based approach
+
  
==Tax Status: 501(c)(3) Not-For-Profit Organization==
+
== Descripción softwares de auditoría  ==
The OWASP Foundation is a U.S. recognized [http://www.irs.gov/charities/charitable/article/0,,id=96114,00.html 501(c)(3)] not-for-profit charitable organization. The OWASP Foundation received its formal recognition by the U.S. government of its 501(c)(3) status on December 10, 2004. This not-for-proft status allows contributors to deduct any ''donations'' made to the OWASP Foundation.
+
  
==Tax Deductability of Payments to OWASP==
+
*El sistema de cifrado http://truecrypt.org cifra el núcleo del sistema operativo y los discos lógicos impidiendo ataques espía.
OWASP membership fees, OWASP conferences fees, OWASP conference sponsorships, and OWASP banner ads are ''not'' considered tax-deductible donations due to the benefits the paying organization/individual receives.
+
  
Direct donations to OWASP are fully tax-deductible given OWASP's recognized U.S. not-for-profit status.
+
*Los comandos shell http://openvas.org sirven para analizar protocolos de red, detección de virus y cifrado del protocolo IpV4-6
  
OWASP's U.S. Employer Identification Number (EIN) is: 20-0963503.
+
*El filtro web http://freenetproject.org es una técnica que reemplaza al Firewall, discriminando puertos inseguros, ahorrando tiempo de procesamiento en el núcleo del sistema.
  
==Membership or Donations==
+
*Clamwin.com es un software de código abierto, no usa computación en la nube y tiene una GUI que detecta virus en línea http://sourceforge.net/projects/clamsentinel
If you are interested in joining OWASP as a member, or donating funds for OWASP's efforts, please check out the [[Membership|OWASP Membership Page]].
+
  
==Contacting OWASP==
+
== Macroinformática  ==
The easiest way to contact the [[OWASP Foundation]] is via e-mail. If you have a question concerning a particular project, we <b>strongly</b> recommend using the [https://lists.owasp.org/mailman/listinfo mailing list] for that project. Many questions can also be answered by [http://www.owasp.org/google/results.html searching] the [[Main Page|OWASP]] web site, so please check there first!
+
  
Our address for general correspondence and faxes can be sent to our physical office address, to the attention of [[User:Kate_Hartmann|Kate Hartmann]], at:  
+
La macroinformática comprende eficiencia, seguridad y naturaleza. La eficacia de un sistema operativo se mide por la interacción hombre-máquina, sintetizando aplicaciones minimalistas y ejecutándolas nuestro sistema operativo procesará los datos eficientemente, ejemplos:  
  
  OWASP Foundation
+
*Transmisión cifrada: Cliente e-mail con GnuPG
  9175 Guilford Road Suite #300
+
  Columbia, MD 21046
+
  301-275-9403 (phone)
+
  301-604-8033 (fax)
+
  [https://spreadsheets.google.com/a/owasp.org/viewform?hl=en&formkey=dFN1R2NIMTNROXN3dml4ZEcxXzJQYXc6MQ#gid=0 Submit a Inquiry]
+
  
[http://www.linkedin.com/companies/owasp http://www.owasp.org/images/9/98/Btn_cofollow_badge.png]
+
http://fellowship.fsfe.org  
  
==Global Board Members==
+
*Sistema de cifrado: Cifra y descifra texto plano, imágenes, etc..
Governed by 100% volunteer members with dedicated volunteerism to ensure the mission of OWASP "to make application security visible so that people and organizations can make informed decisions about application security risks"
+
  
[[User:Jeff_Williams|Jeff Williams]] - Board Member and Chair
+
#ftp://ftp.gnupg.org/gcrypt/binary/gnupg-w32cli-1.4.11.exe
<br/>jeff.williams(at)owasp.org
+
#http://cryptophane.googlecode.com/files/cryptophane-0.7.0.exe
  
[[User:Dinis.cruz|Dinis Cruz]] - Board Member
+
*Ruby: Lenguaje de programación experimental
<br/>dinis.cruz(at)owasp.org
+
  
[[User:Wichers|Dave Wichers]] - Board Member
+
http://ruby-lang.org  
<br/>dave.wichers(at)owasp.org
+
  
[[User:Brennan|Tom Brennan]] - Board Member
+
*J2re1.3.1_20: Ejecutable de objetos interactivos o applets
<br/>tom.brennan(at)owasp.org
+
  
[[User:Sdeleersnyder|Sebastien Deleersnyder]] - Board Member
+
http://java.sun.com/products/archive/j2se/1.3.1_20/index.html
<br/>seba(at)owasp.org
+
  
[[User:EoinKeary|Eoin Keary]] - Board Member
+
*Escritorio: Gestor de ventanas X11
<br/>eoin(at)owasp.org
+
  
[[User:mtesauro|Matt Tesauro]] - Board Member
+
http://windowmaker.info
<br/>matt.tesauro(at)owasp.org
+
  
==Board Meeting Minutes==
+
*Gnuzilla: Navegador seguro y de uso libre
[[OWASP_Board_Meetings | Board meeting minutes for the record.]]
+
  
=== Global Committee Structure ===
+
http://code.google.com/p/iceweaselwindows/downloads/list
OWASP recognized the extraordinary contribution of our most active leaders by engaging them to lead a set of six new committees. Each democratically established committee will focus on a key function or geographic region, such as OWASP projects, conferences, local chapters, membership and industry outreach.
+
  
{| style="width:80%" border="0" align="center"
+
*Gnupdf: Visor de formato de texto universal pdf
| colspan="6" align="center" style="background:#4058A0; color:white" | OWASP GLOBAL COMMITTEES (OWASP GC)
+
|-
+
| style="width:17%; background:#f2984c" align="center" | [[Global Education Committee|Education]]
+
| style="width:17%; background:#f2984c" align="center" | [[Global Chapter Committee|Chapters]]
+
| style="width:17%; background:#f2984c" align="center" | [[Global Conferences Committee|Conferences]]
+
| style="width:17%; background:#f2984c" align="center" | [[Global Industry Committee|Industry]]
+
| style="width:16%; background:#f2984c" align="center" | [[Global Projects and Tools Committee|Projects & Tools]]
+
| style="width:16%; background:#f2984c" align="center" | [[Global Membership Committee|Membership]]
+
|}
+
  
==Employees of the OWASP Foundation==
+
http://blog.kowalczyk.info/software/sumatrapdf
  
Kate Hartmann - [[User:Kate_Hartmann|Kate's Role w/OWASP]]
+
*Gnuflash: Jugador alternativo a flash player
<br/>OWASP Operations Director
+
<br/>[mailto:kate.hartmann@owasp.org Kate Hartmann]
+
 
+
Paulo Coimbra [[User:Paulo_Coimbra|Paulo's Role w/OWASP]]
+
<br/>OWASP Project Manager
+
<br/>[mailto:pcoimbra@owasp.org Paulo Combra]
+
  
Alison Shrader - [[User:Alison_McNamee|Alison's Role w/OWASP]]
+
http://gnu.org/software/gnash
<br/>OWASP Accounting
+
<br/>[mailto:alison.shrader@owasp.org Alison Shrader]
+
  
==Volunteer Support==
+
*Zinf: Reproductor de audio
<br/>Director of Information Technology
+
<br/>[mailto:larry.casey@owasp.org Larry Casey]
+
  
==Licensing==
+
http://zinf.org
All OWASP materials are available under an approved [[OWASP Licenses|FLOSS license]]. For more information, please see the '''[[OWASP Licenses]]''' page.
+
  
==Participation and Membership==
+
*Informática forense: Análisis de datos ocultos en el disco duro
Everyone is welcome to participate in our [https://lists.owasp.org/mailman/listinfo forums], [[projects]], [[chapters]], and [[conferences]]. OWASP is a fantastic place to learn about application security, to network, and even to build your reputation as an expert.
+
  
If you find the OWASP materials valuable, please consider supporting our cause by becoming an OWASP member. All monies received by the OWASP Foundation go directly into supporting OWASP projects.
+
http://sleuthkit.org
  
For more information, please see the '''[[Membership]]''' page.
+
*Compresor: Comprime datos sobreescribiendo bytes repetidos
  
==Projects==
+
http://peazip.sourceforge.net
OWASP's projects cover many aspects of application security. We build documents, tools, teaching environments, guidelines, checklists, and other materials to help organizations improve their capability to produce secure code.
+
  
For details on all the OWASP projects, please see the '''[[:Category:OWASP Project|OWASP Project]]''' page.
+
*Ftp: Gestor de descarga de archivos
  
==Privacy Policy==
+
http://dfast.sourceforge.net
Given OWASP’s mission to help organizations with application security, you have the right to expect protection of any personal information that we might collect about our members.
+
  
In general, we do not require authentication or ask visitors to reveal personal information when visiting our website. We collect Internet addresses, not the e-mail addresses, of visitors solely for use in calculating various website statistics.
+
*AntiKeylogger: Neutraliza el seguimiento de escritorios remotos (Monitoring)
  
We may ask for certain personal information, including name and email address from persons downloading OWASP products. This information is not divulged to any third party and is used only for the purposes of:
+
http://psmantikeyloger.sourceforge.net
* Communicating urgent fixes in the OWASP Materials
+
* Seeking advice and feedback about OWASP Materials
+
* Inviting participation in OWASP’s consensus process and AppSec conferences
+
  
OWASP publishes a list of member organizations and individual members. Listing is purely voluntary and "opt-in." Listed members can request not to be listed at any time.
+
*Password manager: Gestión de contraseñas
  
All information about you or your organization that you send us by fax or mail is physically protected. If you have any questions or concerns about our privacy policy, please contact us at [mailto:owasp@owasp.org owasp@owasp.org].
+
http://passwordsafe.sourceforge.net
  
==Tax Filings==
+
*Limpiador de disco: Borra archivos innecesrios del sistema
[http://204.203.220.33/EINS/200963503/200963503_2005_026A3A51.PDF Click here to get a copy of our 2005 Tax Return].
+
  
[https://www.owasp.org/images/e/ef/2006_Tax_Return.pdf Click here to get a copy of our 2006 Tax Return].
+
http://bleachbit.sourceforge.net
  
[https://www.owasp.org/images/5/57/2007_Form_990.pdf Click here to get a copy of our 2007 Tax Return] and [https://www.owasp.org/images/9/94/OWASP_Audit_Report_2007.pdf Audit Report].
+
*Desfragmentador: Reordena los archivos del disco duro, generando espacio virtual
  
[http://www.owasp.org/images/d/de/2008_Tax_Return.pdf Click here to get a copy of our 2008 Tax Return].
+
http://kessels.com/jkdefrag
  
[http://www.owasp.org/images/d/d8/2009_Form_990.pdf Click here to get a copy of our 2009 Tax Return].
+
*X11: Gestor de ventanas, reemplazo de escritorio Xwindow's
  
<br/>
+
http://bb4win.org
  
[[Category:OWASP Guide Project]]
+
*Open Hardware: Hardware construído por la comunidad Linux
[[Category:OWASP Testing Project]]
+
[[Category:OWASP Code Review Project]]
+
  
For more information, please see the pages listed below:
+
http://open-pc.com
* <b>[[Contact]] for names, phone numbers and roles of the OWASP Foundation</b>
+
* [[Contributions]] for details about how to make contributions
+
* [[Advertising]] if you're interested in advertising on the OWASP site
+
* [[How OWASP Works]] for more information about projects and governance
+
* [[OWASP brand usage rules]] for information about using the OWASP brand
+
  
<!-- __NOTOC__ -->
+
*Open WRT: Firmware libre para configurar transmisión de Internet
 +
 
 +
http://openwrt.org
 +
 
 +
*Gnu- Linux: Sistema operativo universal
 +
 
 +
http://gnewsense.org
 +
 
 +
== Biocriptoseguridad ==: Es la unión de la biología, criptografía y hacking ético para formar una defensa stándar contra virus complejos.
 +
 
 +
Implementación de la biocriptoseguridad informática:
 +
 
 +
#Amplificar la banda ancha
 +
#Optimizar (limpiar- modificar) el sistema operativo
 +
#Desfragmentar los discos lógicos
 +
#Ocultar el sistema operativo
 +
#Configurar antivirus
 +
#Limpiar y desfragmentar
 +
#Congelar
 +
 
 +
*Sistema inmune._ Defensa biológica natural contra infecciones como virus http://immunet.com
 +
 
 +
*Criptografía._ Método de escritura oculta por caractes, números y letras:—{H}/gJa¢K¡Ng÷752%\*)A>¡#(W|a— http://diskcryptor.net
 +
 
 +
*Hacking ético._ Auditoría de sistemas informáticos que preserva la integridad de los datos.
 +
 
 +
Congelador: Mantiene el equilibrio en la integridad de los datos, el sistema operativo, red , memoria ram, ciclos de CPU, espacio en disco duro e incidencias de malware
 +
 
 +
*http://code.google.com/p/hzr312001/downloads/detail?name=Deep%20systemze%20Standard%20Version%206.51.020.2725.rar&amp;can=2&amp;q= (para Window's)
 +
*http://sourceforge.net/projects/lethe (para GNU/Linux)
 +
 
 +
<br>Auditoría de virus cifrado._ Un criptovirus se oculta tras un algoritmo de criptografía, generalmente es híbrido simétrico-asimétrico con una extensión de 1700bit's, burla los escáneres antivirus con la aleatoriedad de cifrado, facilitando la expansión de las botnet's. La solución es crear un sistema operativo transparente, anonimizarlo y usar herramientas de cifrado stándar de uso libre:
 +
 
 +
*Gnupg: Sirve para cifrar mensajes de correo electrónico http://gpg4win.org/download.html
 +
 
 +
*Open Secure Shell: Ofuscador TcpIp, protege el túnel de comunicación digital cifrando la Ip. http://openvas.org
 +
 
 +
*Red protegida: DNS libre http://namespace.org/switch
 +
 
 +
*Criptosistema simétrico: Encapsula el disco duro, incluyendo el sistema operativo,usando algoritmo Twofish http://truecrypt.org/downloads.php
 +
 
 +
*Proxy cifrado: Autenticación de usuario anónimo http://torproject.org
 +
 
 +
Energías renovables._ Son energías adquiridas por medios naturales: hidrógeno, aire, sol que disminuyen la toxicidad de las emisiones de Co2 en el medio ambiente, impulsando políticas ecologistas contribuímos a preservar el ecosistema. Ejm: Usando paneles solares fotovoltaicos.

Revision as of 16:16, 7 February 2011

Modelo de Auditoría de sistemas:

Éste es un modelo universal para securizar en un alto grado de seguridad al sistema operativo.

  1. Sistema de cifrado congelado: Mantiene en secreto la ubicación del archivo del sistema, previniendo ataques de tipo monitoreo de redes.
  2. OpenVAS: Línea de comandos para cifrar- descifrar el protocolo TCP/Ip
  3. Filtro Web: Previene intrusiones a través de puertos inseguros
  4. Clam Antivirus: Previene, detecta y corrige virus informático


Clam Antivirus
Filtro Web
OpenVAS
Sistema de Cifrado Congelado

Descripción softwares de auditoría

  • El sistema de cifrado http://truecrypt.org cifra el núcleo del sistema operativo y los discos lógicos impidiendo ataques espía.
  • Los comandos shell http://openvas.org sirven para analizar protocolos de red, detección de virus y cifrado del protocolo IpV4-6
  • El filtro web http://freenetproject.org es una técnica que reemplaza al Firewall, discriminando puertos inseguros, ahorrando tiempo de procesamiento en el núcleo del sistema.

Macroinformática

La macroinformática comprende eficiencia, seguridad y naturaleza. La eficacia de un sistema operativo se mide por la interacción hombre-máquina, sintetizando aplicaciones minimalistas y ejecutándolas nuestro sistema operativo procesará los datos eficientemente, ejemplos:

  • Transmisión cifrada: Cliente e-mail con GnuPG

http://fellowship.fsfe.org

  • Sistema de cifrado: Cifra y descifra texto plano, imágenes, etc..
  1. ftp://ftp.gnupg.org/gcrypt/binary/gnupg-w32cli-1.4.11.exe
  2. http://cryptophane.googlecode.com/files/cryptophane-0.7.0.exe
  • Ruby: Lenguaje de programación experimental

http://ruby-lang.org

  • J2re1.3.1_20: Ejecutable de objetos interactivos o applets

http://java.sun.com/products/archive/j2se/1.3.1_20/index.html

  • Escritorio: Gestor de ventanas X11

http://windowmaker.info

  • Gnuzilla: Navegador seguro y de uso libre

http://code.google.com/p/iceweaselwindows/downloads/list

  • Gnupdf: Visor de formato de texto universal pdf

http://blog.kowalczyk.info/software/sumatrapdf

  • Gnuflash: Jugador alternativo a flash player

http://gnu.org/software/gnash

  • Zinf: Reproductor de audio

http://zinf.org

  • Informática forense: Análisis de datos ocultos en el disco duro

http://sleuthkit.org

  • Compresor: Comprime datos sobreescribiendo bytes repetidos

http://peazip.sourceforge.net

  • Ftp: Gestor de descarga de archivos

http://dfast.sourceforge.net

  • AntiKeylogger: Neutraliza el seguimiento de escritorios remotos (Monitoring)

http://psmantikeyloger.sourceforge.net

  • Password manager: Gestión de contraseñas

http://passwordsafe.sourceforge.net

  • Limpiador de disco: Borra archivos innecesrios del sistema

http://bleachbit.sourceforge.net

  • Desfragmentador: Reordena los archivos del disco duro, generando espacio virtual

http://kessels.com/jkdefrag

  • X11: Gestor de ventanas, reemplazo de escritorio Xwindow's

http://bb4win.org

  • Open Hardware: Hardware construído por la comunidad Linux

http://open-pc.com

  • Open WRT: Firmware libre para configurar transmisión de Internet

http://openwrt.org

  • Gnu- Linux: Sistema operativo universal

http://gnewsense.org

== Biocriptoseguridad ==: Es la unión de la biología, criptografía y hacking ético para formar una defensa stándar contra virus complejos.

Implementación de la biocriptoseguridad informática:

  1. Amplificar la banda ancha
  2. Optimizar (limpiar- modificar) el sistema operativo
  3. Desfragmentar los discos lógicos
  4. Ocultar el sistema operativo
  5. Configurar antivirus
  6. Limpiar y desfragmentar
  7. Congelar
  • Sistema inmune._ Defensa biológica natural contra infecciones como virus http://immunet.com
  • Criptografía._ Método de escritura oculta por caractes, números y letras:—{H}/gJa¢K¡Ng÷752%\*)A>¡#(W|a— http://diskcryptor.net
  • Hacking ético._ Auditoría de sistemas informáticos que preserva la integridad de los datos.

Congelador: Mantiene el equilibrio en la integridad de los datos, el sistema operativo, red , memoria ram, ciclos de CPU, espacio en disco duro e incidencias de malware


Auditoría de virus cifrado._ Un criptovirus se oculta tras un algoritmo de criptografía, generalmente es híbrido simétrico-asimétrico con una extensión de 1700bit's, burla los escáneres antivirus con la aleatoriedad de cifrado, facilitando la expansión de las botnet's. La solución es crear un sistema operativo transparente, anonimizarlo y usar herramientas de cifrado stándar de uso libre:

  • Open Secure Shell: Ofuscador TcpIp, protege el túnel de comunicación digital cifrando la Ip. http://openvas.org

Energías renovables._ Son energías adquiridas por medios naturales: hidrógeno, aire, sol que disminuyen la toxicidad de las emisiones de Co2 en el medio ambiente, impulsando políticas ecologistas contribuímos a preservar el ecosistema. Ejm: Usando paneles solares fotovoltaicos.