Category:OWASP Guide Project

Revision as of 18:29, 2 June 2009 by Deleted user (talk | contribs)

Jump to: navigation, search


OWASP Documentation Project

Guide to Building Secure Web Applications and Web Services (Development Guide)

The Development Guide is aimed at architects, developers, consultants and auditors and is a comprehensive manual for designing, developing and deploying secure Web Applications and Web Services. The original OWASP Development Guide has become a staple diet for many web security professionals. Since 2002, the initial version was downloaded over 2 million times. Today, the Development Guide is referenced by many leading government, financial, and corporate standards and is the Gold standard for Web Application and Web Service security. For more information, please contact us.

How the Development Guide Works

The Development Guide provides practical guidance using J2EE, ASP.NET, and PHP code samples. The Development Guide covers an extensive array of application-level security issues, from SQL injection through modern concerns such as phishing, credit card handling, session fixation, cross-site request forgeries, compliance, and privacy issues.

Latest News


More About the Development Guide

  • One Page Datasheet (Under Construction)

Related projects


Download the Development Guide

Download the Development Guide now, for free.

Release Versions

  • Development Guide 2005 in English (PDF, Word)
  • Development Guide 2005 in Spanish (PDF, Word)
  • Development Guide 2002 in Japanese (PDF)

Earlier Versions

OWASP Books logo.png This project has produced a book that can be downloaded or purchased.
Feel free to browse the full catalog of available OWASP books.


Project News

  • 05/29/2009 - OWASP Developer Guide 2009 version project is starting up. Plans include alignment with OWASP ASVS and OWASP ESAPI projects. Please contact Mike Boberski for more information.
  • 05/29/2009 - OWASP Developer Guide project lead role transitioned from Andrew van der Stock to Mike Boberski.
  • 07/27/2005 - OWASP Developer Guide 2005 version released, announced at Black Hat in Las Vegas.


Project Leader

Project Contributors

  • Adrian Wiesmann
  • Abraham Kang
  • Alex Russell
  • Amit Klein
  • Andrew van der Stock (2005 Release Version Project Lead)
  • Brian Greidanus
  • Christopher Todd
  • Darrel Grundy
  • David Endler
  • Denis Piliptchouk
  • Dennis Groves
  • Derek Browne
  • Eoin Keary
  • Ernesto Arroyo
  • Frank Lemmon
  • Gene McKenna
  • Hal Lockhart
  • Izhar By-Gad
  • Jeremy Poteet
  • José Pedro Arroyo
  • K.K. Mookhey
  • Kevin McLaughlin
  • Mark Curphey
  • Martin Eizner
  • Michael Howard
  • Mikael Simonsson
  • Neal Krawetz
  • Nigel Tranter
  • Raoul Endres
  • Ray Stirbei
  • Richard Parke
  • Robert Hansen
  • Roy McNamara
  • Steve Taylor
  • Sverre Huseby
  • Tim Smith
  • William Hau

Project Sponsorship


Users and Adopters

Coming soon! Please let us know how your organization is using the OWASP Development Guide. Include your name, organization's name, and brief description of how you use the annex. The project lead can be reached at here. Thanks for supporting OWASP!

This project licensed under the Licensed under Creative Commons Attribution ShareAlike 3.0.

Articles Below - More About the Development Guide and Using It