Difference between revisions of "Category:OWASP Guide Project"

From OWASP
Redirect page
Jump to: navigation, search
 
(47 intermediate revisions by 3 users not shown)
Line 1: Line 1:
 
+
#REDIRECT [[:OWASP Guide Project]]
{{ProjectTabs |
+
Proj_About=
+
<table width="100%" valign="top"><tr><th width="50%"> </th><th> </th></tr><tr valign="top"><td>
+
''OWASP Documentation Project''
+
  
'''Guide to Building Secure Web Applications and Web Services (Development Guide)'''
+
==== Home ====
  
The Development Guide is aimed at architects, developers, consultants and auditors and is a comprehensive manual for designing, developing and deploying secure web applications. The original OWASP Development Guide has become a staple diet for many web security professionals. Since 2002, the initial version was downloaded over 2 million times. Today, the Development Guide is referenced by many leading government, financial, and corporate standards and is the Gold standard for web application security.
+
{| width="100%"
 +
|-
 +
! width="66%" |
 +
! width="33%" |
 +
|- valign="top"
 +
|
 +
Web application security is an essential component of any successful project, whether open source PHP applications, web services such as straight through processing, or proprietary business web sites. Hosters (rightly) shun insecure code, and users shun insecure services that lead to fraud. The aim of this Development Guide is to allow businesses, developers, designers and solution architects to produce secure web applications. If done from the earliest stages, secure applications cost about the same to develop as insecure applications, but are far more cost effective in the long run.
  
For more information, please [mailto:mike.boberski@owasp.org contact us].
+
Unlike other forms of security (such as firewalls and secure lockdowns), web applications have the ability to make a skilled attacker rich, or make the life of a victim a complete misery. At this highest level of the OSI software map, traditional firewalls and other controls simply do not help. The application itself must be self-defending. The Development Guide can help you get there. The Development Guide has been written to cover all forms of web application security issues, from old hoary chestnuts such as SQL Injection, through modern concerns such as AJAX, phishing, credit card handling, session fixation, cross-site request forgeries, compliance, and privacy issues.
  
 +
|
 +
[[Image:Asvs-ad-where-at.png]]
  
</td><td>
+
|}
;
+
<br>'''Latest News'''
+
* Details below will be filled in as work on the next version of the guide progresses. Volunteers wanted!
+
* Request for users/adopters/supporters. [mailto:mike.boberski@owasp.org Please let us know your stories!]
+
* [http://www.owasp.org/index.php/Category:OWASP_Guide_Project#tab=News Development Guide News Archives]
+
* [http://lists.owasp.org/mailman/listinfo/owasp-guide Development Guide Mailing List]
+
</td></tr>
+
</table>
+
  
 +
{| width="100%"
 +
|-
 +
! width="33%" |
 +
! width="33%" |
 +
! width="33%" |
 +
|- valign="top"
 +
|
 +
== Let's talk here  ==
  
 +
[[file:Asvs-bulb.jpg‎ ]]'''Development Guide Communities'''
 +
 +
Further development of the Development Guide occurs through mailing list discussions and occasional workshops, and suggestions for improvement are welcome. For more information, please [mailto:owasp@owasp.org contact us].
 +
 +
* [https://lists.owasp.org/mailman/listinfo/owasp-guide mailing list (this is the main list)]
  
 
|  
 
|  
 +
== Got Cycles? ==
  
Proj_Documentation=
+
Work has begun on the next version of the Development Guide! Read all about it, [http://bit.ly/a5imj2 here]
'''More About the Development Guide'''
+
  
* One Page Datasheet (Under Construction)  
+
* Contributor Onboarding Instructions ([http://owasp-development-guide.googlecode.com/files/development-guide-contributing.pdf PDF])
+
 
'''Related projects'''
+
== Got Translation Cycles? ==
 +
 
 +
The Development Guide project is always on the lookout for volunteers who are interested in translating the Development Guide into another language.
 +
 
 +
* Translation Onboarding Instructions (Currently under development!)
 +
 
 +
|
 +
== Related resources ==
 +
 
 +
[[file:Asvs-satellite.jpg‎ ]]'''OWASP Resources'''
  
* [http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project OWASP Top Ten]
 
 
* [http://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project OWASP ASVS]
 
* [http://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project OWASP ASVS]
 +
* [http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project OWASP Top Ten]
 +
* [http://www.owasp.org/index.php/Category:OWASP_Legal_Project OWASP Legal Project]
 
* [http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API OWASP ESAPI]
 
* [http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API OWASP ESAPI]
 +
* [http://www.owasp.org/index.php/Common_OWASP_Numbering OWASP Common Numbering]
 +
|}
 +
 +
 +
====Downloads====
 +
 +
[[file:Asvs-step1.jpg‎ ]]'''1. About the Development Guide'''
 +
 +
The Development Guide is aimed at architects, developers, consultants and auditors and is a comprehensive manual for designing, developing and deploying secure Web Applications and Web Services. The original OWASP Development Guide has become a staple diet for many web security professionals. Since 2002, the initial version was downloaded over 2 million times. Today, the Development Guide is referenced by many leading government, financial, and corporate standards and is the Gold standard for Web Application and Web Service security.
  
====Development Guide====
+
* Project presentation in English (Currently under development!)
'''Development Guide'''
+
* Data sheet in English (Currently under development!)
  
This document helps software developers build secure Web Applications and Web Services.
+
[[file:Asvs-step2.jpg‎ ]]'''2. Get the Development Guide'''
  
'''Release Versions'''
+
* Development Guide 2010 in English (Currently under development!) ([http://code.google.com/p/owasp-development-guide/wiki/Introduction Wiki])
* Development Guide 2005 in English ([http://prdownloads.sourceforge.net/owasp/OWASPGuide2.0.1.pdf?download PDF], [http://prdownloads.sourceforge.net/owasp/OWASPGuide2.0.1.zip?download Word])
+
* Development Guide 2005 in English ([http://prdownloads.sourceforge.net/owasp/OWASPGuide2.0.1.pdf?download PDF], [http://prdownloads.sourceforge.net/owasp/OWASPGuide2.0.1.zip?download Word], [[Guide_Table_of_Contents | Wiki]])
* Development Guide 2005 in Spanish ([https://www.owasp.org/images/b/b2/OWASP_Development_Guide_2.0.1_Spanish.pdf PDF], [http://www.owasp.org/images/5/58/OWASP_Development_Guide_2.0.1_Spanish.doc Word])
+
* Development Guide 2005 in Spanish ([http://www.owasp.org/images/b/b2/OWASP_Development_Guide_2.0.1_Spanish.pdf PDF], [http://www.owasp.org/images/5/58/OWASP_Development_Guide_2.0.1_Spanish.doc Word])
 
* Development Guide 2002 in Japanese ([http://prdownloads.sourceforge.net/owasp/OWASPGuideV1.1.1-jp.pdf?download PDF])
 
* Development Guide 2002 in Japanese ([http://prdownloads.sourceforge.net/owasp/OWASPGuideV1.1.1-jp.pdf?download PDF])
 +
* Development Guide (Earlier Versions) ([http://sourceforge.net/project/showfiles.php?group_id=64424&package_id=62287 file download center], [http://sourceforge.net/cvs/?group_id=64424 CVS])
  
'''Earlier Versions'''
 
* Development Guide ([http://sourceforge.net/project/showfiles.php?group_id=64424&package_id=62287 file download center], [http://sourceforge.net/cvs/?group_id=64424 CVS])
 
  
<br>
+
[[file:Asvs-step3.jpg‎ ]]'''3. Learn about using the Development Guide'''
{{OWASP Book|1401012}}
+
<br>
+
+
|
+
  
Proj_Mail= '''Project News'''
+
The Development Guide provides practical guidance and includes J2EE, ASP.NET, and PHP code samples. The Development Guide covers an extensive array of application-level security issues, from SQL injection through modern concerns such as phishing, credit card handling, session fixation, cross-site request forgeries, compliance, and privacy issues.
  
* Details below will be filled in as work on the next version of the guide progresses. Volunteers wanted!
+
* Development Guide Articles (Please see below)
  
|
 
  
Proj_Related= [[Top Ten|OWASP Top Ten]] |
+
====Glossary====
Proj_Contributors=  
+
<table width="100%" valign="top"><tr><th width="25%"> </th><th width="25%"> </th><th> </th></tr><tr valign="top"><td>
+
'''Project Leader'''
+
* [http://www.owasp.org/index.php/User:Mike.boberski Mike Boberski]
+
'''Project Contributors'''
+
* Adrian Wiesmann
+
* Andrew van der Stock (2005 Release Version Project Lead)
+
* Mark Curphey
+
* Ray Stirbei
+
* Abraham Kang
+
* Adrian Wiesmann
+
* Alex Russell
+
* Amit Klein
+
* Andrew van der Stock
+
* Brian Greidanus
+
* Christopher Todd
+
* Darrel Grundy
+
* David Endler
+
* Denis Piliptchouk
+
* Dennis Groves
+
* Derek Browne
+
* Eoin Keary
+
* Ernesto Arroyo
+
* Frank Lemmon
+
* Gene McKenna
+
* Hal Lockhart
+
* Izhar By-Gad
+
* Jeremy Poteet
+
* José Pedro Arroyo
+
* K.K. Mookhey
+
* Kevin McLaughlin
+
* Mark Curphey
+
* Martin Eizner
+
* Michael Howard
+
* Mikael Simonsson
+
* Neal Krawetz
+
* Nigel Tranter
+
* Raoul Endres
+
* Ray Stirbei
+
* Richard Parke
+
* Robert Hansen
+
* Roy McNamara
+
* Steve Taylor
+
* Sverre Huseby
+
* Tim Smith
+
* William Hau
+
  
</td><td>
+
[[file:Asvs-letters.jpg‎ ]]'''Development Guide Terminology'''
  
'''Project Sponsorship'''
+
* (Currently under development!)
  
* Details below will be filled in as work on the next version of the guide progresses. Volunteers wanted!
+
<!--- ==== Project Details ====
 +
{{:GPC_Project_Details/OWASP_Guide_Project | OWASP Project Identification Tab}}  --->
  
</td><td>
 
'''Users and Adopters'''
 
  
Coming soon! Please let us know how your organization is using the OWASP Development Guide. Include your name, organization's name, and brief description of how you use the annex. The project lead can be reached at [mailto:mike.boberski@owasp.org Mike Boberski] Thanks for supporting OWASP!
+
==== Project About ====
 +
{{:Projects/OWASP Development Guide | Project About}}
  
</td></tr>
 
</table>
 
}}
 
''This project licensed under the Licensed under [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution ShareAlike 3.0].''
 
<br>
 
  
= Articles Below - More About the Development Guide and Using It =
+
__NOTOC__
 +
<headertabs/>

Latest revision as of 11:53, 6 October 2010