Difference between revisions of "OWASP Guide Project"

From OWASP
Jump to: navigation, search
(2 intermediate revisions by 2 users not shown)
Line 1: Line 1:
== Modelo de Auditoría de sistemas:  ==
+
==== Home ====
  
Éste es un modelo universal para securizar en un alto grado de seguridad al sistema operativo.
+
{| width="100%"
 
+
#Sistema de cifrado congelado: Mantiene en secreto la ubicación del archivo del sistema, previniendo ataques de tipo monitoreo de redes.
+
#OpenVAS: Línea de comandos para cifrar- descifrar el protocolo TCP/Ip
+
#Filtro Web: Previene intrusiones a través de puertos inseguros
+
#Clam Antivirus: Previene, detecta y corrige virus informático
+
 
+
<br>
+
 
+
{| border="1" cellspacing="1" cellpadding="1" width="200" align="center"
+
 
|-
 
|-
| Clam Antivirus
+
! width="66%" |  
{| border="1" cellspacing="1" cellpadding="1" width="200" align="center"
+
! width="33%" |
|-
+
|- valign="top"
| Filtro Web
+
|  
{| border="1" cellspacing="1" cellpadding="1" width="200" align="center"
+
|-
+
| OpenVAS
+
{| border="1" cellspacing="1" cellpadding="1" width="200" align="center"
+
|-
+
| Sistema de Cifrado Congelado
+
|}
+
  
|}
+
The OWASP Developer Guide 2013 is a dramatic re-write of one of OWASP's first and most downloaded projects. The focus moves from countermeasures and weaknesses to secure software engineering.
  
|}
+
In this edition, architects, project leads, and developers can reference a massive text book covering all aspects of modern application security architecture, secure design, and detailed design patterns. This edition aligns with the syllabus outcomes of the Undergraduate Software Assurance degree and Masters of Software Assurance.
  
|}
+
Major themes:
  
== Descripción softwares de auditoría  ==
+
* Foundation Security
 +
* Architecture
 +
* Design
 +
* Build
 +
* Operate
 +
* Incident Response
  
*El sistema de cifrado http://truecrypt.org cifra el núcleo del sistema operativo y los discos lógicos impidiendo ataques espía.
+
As this book is in a constant state of flux, it can never be said to be complete, and so the current 2005 edition is the "release" edition, and the Wiki here is the draft version until further notice. Once we have adequate coverage and quality of the SwA course matrix, we will switch over even if unfinished.  
  
*Los comandos shell http://openvas.org sirven para analizar protocolos de red, detección de virus y cifrado del protocolo IpV4-6
+
|
 +
[[Image:Asvs-ad-where-at.png]]
  
*El filtro web http://freenetproject.org es una técnica que reemplaza al Firewall, discriminando puertos inseguros, ahorrando tiempo de procesamiento en el núcleo del sistema.
+
|}
  
*Clamwin.com es un software de código abierto, no usa computación en la nube y tiene una GUI que detecta virus en línea http://sourceforge.net/projects/clamsentinel
+
{| width="100%"
 +
|-
 +
! width="33%" |
 +
! width="33%" |
 +
! width="33%" |
 +
|- valign="top"
 +
|
 +
== Let's talk here  ==
  
== Macroinformática  ==
+
[[file:Asvs-bulb.jpg‎ ]]'''Development Guide Communities'''
  
La macroinformática comprende eficiencia, seguridad y naturaleza. La eficacia de un sistema operativo se mide por la interacción hombre-máquina, sintetizando aplicaciones minimalistas y ejecutándolas nuestro sistema operativo procesará los datos eficientemente, ejemplos:  
+
Further development of the Development Guide occurs through mailing list discussions and occasional workshops, and suggestions for improvement are welcome. For more information, please [mailto:owasp@owasp.org contact us].
  
*Transmisión cifrada: Cliente e-mail con GnuPG
+
* [https://lists.owasp.org/mailman/listinfo/owasp-guide mailing list (this is the main list)]
  
http://fellowship.fsfe.org
+
|
 +
== Got Cycles? ==
  
*Sistema de cifrado: Cifra y descifra texto plano, imágenes, etc..
+
Work has begun on the next version of the Development Guide! Read all about it, [http://bit.ly/a5imj2 here]
  
#ftp://ftp.gnupg.org/gcrypt/binary/gnupg-w32cli-1.4.11.exe
+
* Contributor Onboarding Instructions ([http://owasp-development-guide.googlecode.com/files/development-guide-contributing.pdf PDF])
#http://cryptophane.googlecode.com/files/cryptophane-0.7.0.exe
+
  
*Ruby: Lenguaje de programación experimental
+
== Got Translation Cycles? ==
  
http://ruby-lang.org
+
The Development Guide project is always on the lookout for volunteers who are interested in translating the Development Guide into another language.
  
*J2re1.3.1_20: Ejecutable de objetos interactivos o applets
+
* Translation Onboarding Instructions (Currently under development!)
  
http://java.sun.com/products/archive/j2se/1.3.1_20/index.html
+
|
 +
== Related resources ==
  
*Escritorio: Gestor de ventanas X11
+
[[file:Asvs-satellite.jpg‎ ]]'''OWASP Resources'''
  
http://windowmaker.info
+
* [http://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project OWASP ASVS]
 
+
* [http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project OWASP Top Ten]
*Gnuzilla: Navegador seguro y de uso libre
+
* [http://www.owasp.org/index.php/Category:OWASP_Legal_Project OWASP Legal Project]
 
+
* [http://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API OWASP ESAPI]
http://code.google.com/p/iceweaselwindows/downloads/list
+
* [http://www.owasp.org/index.php/Common_OWASP_Numbering OWASP Common Numbering]
 
+
|}
*Gnupdf: Visor de formato de texto universal pdf
+
 
+
http://blog.kowalczyk.info/software/sumatrapdf
+
 
+
*Gnuflash: Jugador alternativo a flash player
+
 
+
http://gnu.org/software/gnash
+
 
+
*Zinf: Reproductor de audio
+
 
+
http://zinf.org
+
 
+
*Informática forense: Análisis de datos ocultos en el disco duro
+
 
+
http://sleuthkit.org  
+
 
+
*Compresor: Comprime datos sobreescribiendo bytes repetidos
+
 
+
http://peazip.sourceforge.net
+
 
+
*Ftp: Gestor de descarga de archivos
+
 
+
http://dfast.sourceforge.net
+
 
+
*AntiKeylogger: Neutraliza el seguimiento de escritorios remotos (Monitoring)
+
 
+
http://psmantikeyloger.sourceforge.net
+
 
+
*Password manager: Gestión de contraseñas
+
 
+
http://passwordsafe.sourceforge.net
+
 
+
*Limpiador de disco: Borra archivos innecesrios del sistema
+
 
+
http://bleachbit.sourceforge.net
+
 
+
*Desfragmentador: Reordena los archivos del disco duro, generando espacio virtual
+
 
+
http://kessels.com/jkdefrag
+
 
+
*X11: Gestor de ventanas, reemplazo de escritorio Xwindow's
+
 
+
http://bb4win.org
+
 
+
*Open Hardware: Hardware construído por la comunidad Linux
+
 
+
http://open-pc.com
+
  
*Open WRT: Firmware libre para configurar transmisión de Internet
 
  
http://openwrt.org
+
====Downloads====
  
*Gnu- Linux: Sistema operativo universal
+
[[file:Asvs-step1.jpg‎ ]]'''1. About the Development Guide'''
  
http://gnewsense.org
+
The Development Guide is aimed at architects, developers, consultants and auditors and is a comprehensive manual for designing, developing and deploying secure Web Applications and Web Services. The original OWASP Development Guide has become a staple diet for many web security professionals. Since 2002, the initial version was downloaded over 2 million times. Today, the Development Guide is referenced by many leading government, financial, and corporate standards and is the Gold standard for Web Application and Web Service security.
  
== Biocriptoseguridad ==: Es la unión de la biología, criptografía y hacking ético para formar una defensa stándar contra virus complejos.
+
* Project presentation in English (Currently under development!)
 +
* Data sheet in English (Currently under development!)
  
Implementación de la biocriptoseguridad informática:  
+
[[file:Asvs-step2.jpg‎ ]]'''2. Get the Development Guide'''
  
#Amplificar la banda ancha
+
* DRAFT Development Guide 2013 - TBA
#Optimizar (limpiar- modificar) el sistema operativo
+
* Development Guide 2005 in English ([http://prdownloads.sourceforge.net/owasp/OWASPGuide2.0.1.pdf?download PDF], [http://prdownloads.sourceforge.net/owasp/OWASPGuide2.0.1.zip?download Word], [[Guide_Table_of_Contents | Wiki]])
#Desfragmentar los discos lógicos
+
* Development Guide 2005 in Spanish ([http://www.owasp.org/images/b/b2/OWASP_Development_Guide_2.0.1_Spanish.pdf PDF], [http://www.owasp.org/images/5/58/OWASP_Development_Guide_2.0.1_Spanish.doc Word])
#Ocultar el sistema operativo
+
* Development Guide 2002 in Japanese ([http://prdownloads.sourceforge.net/owasp/OWASPGuideV1.1.1-jp.pdf?download PDF])
#Configurar antivirus
+
* Development Guide (Earlier Versions) ([http://sourceforge.net/project/showfiles.php?group_id=64424&package_id=62287 file download center], [http://sourceforge.net/cvs/?group_id=64424 CVS])
#Limpiar y desfragmentar
+
#Congelar
+
  
*Sistema inmune._ Defensa biológica natural contra infecciones como virus http://immunet.com
 
  
*Criptografía._ Método de escritura oculta por caractes, números y letras:—{H}/gJa¢K¡Ng÷752%\*)A>¡#(W|a— http://diskcryptor.net
+
[[file:Asvs-step3.jpg‎ ]]'''3. Learn about using the Development Guide'''
  
*Hacking ético._ Auditoría de sistemas informáticos que preserva la integridad de los datos.
+
The Development Guide provides practical guidance and includes J2EE, ASP.NET, and PHP code samples. The Development Guide covers an extensive array of application-level security issues, from SQL injection through modern concerns such as phishing, credit card handling, session fixation, cross-site request forgeries, compliance, and privacy issues.  
  
Congelador: Mantiene el equilibrio en la integridad de los datos, el sistema operativo, red , memoria ram, ciclos de CPU, espacio en disco duro e incidencias de malware
+
* Development Guide Articles (Please see below)
  
*http://code.google.com/p/hzr312001/downloads/detail?name=Deep%20systemze%20Standard%20Version%206.51.020.2725.rar&amp;can=2&amp;q= (para Window's)
+
====Glossary====
*http://sourceforge.net/projects/lethe (para GNU/Linux)
+
  
<br>Auditoría de virus cifrado._ Un criptovirus se oculta tras un algoritmo de criptografía, generalmente es híbrido simétrico-asimétrico con una extensión de 1700bit's, burla los escáneres antivirus con la aleatoriedad de cifrado, facilitando la expansión de las botnet's. La solución es crear un sistema operativo transparente, anonimizarlo y usar herramientas de cifrado stándar de uso libre:
+
[[file:Asvs-letters.jpg‎ ]]'''Development Guide Terminology'''
  
*Gnupg: Sirve para cifrar mensajes de correo electrónico http://gpg4win.org/download.html
+
* (Currently under development!)
  
*Open Secure Shell: Ofuscador TcpIp, protege el túnel de comunicación digital cifrando la Ip. http://openvas.org
+
<!--- ==== Project Details ====
 +
{{:GPC_Project_Details/OWASP_Guide_Project | OWASP Project Identification Tab}} ---->
  
*Red protegida: DNS libre http://namespace.org/switch
 
  
*Criptosistema simétrico: Encapsula el disco duro, incluyendo el sistema operativo,usando algoritmo Twofish http://truecrypt.org/downloads.php
+
==== Project About ====
 +
{{:Projects/OWASP Development Guide | Project About}}
  
*Proxy cifrado: Autenticación de usuario anónimo http://torproject.org
 
  
Energías renovables._ Son energías adquiridas por medios naturales: hidrógeno, aire, sol que disminuyen la toxicidad de las emisiones de Co2 en el medio ambiente, impulsando políticas ecologistas contribuímos a preservar el ecosistema. Ejm: Usando paneles solares fotovoltaicos.
+
__NOTOC__
 +
<headertabs/>

Revision as of 08:16, 29 January 2013

Home

The OWASP Developer Guide 2013 is a dramatic re-write of one of OWASP's first and most downloaded projects. The focus moves from countermeasures and weaknesses to secure software engineering.

In this edition, architects, project leads, and developers can reference a massive text book covering all aspects of modern application security architecture, secure design, and detailed design patterns. This edition aligns with the syllabus outcomes of the Undergraduate Software Assurance degree and Masters of Software Assurance.

Major themes:

  • Foundation Security
  • Architecture
  • Design
  • Build
  • Operate
  • Incident Response

As this book is in a constant state of flux, it can never be said to be complete, and so the current 2005 edition is the "release" edition, and the Wiki here is the draft version until further notice. Once we have adequate coverage and quality of the SwA course matrix, we will switch over even if unfinished.

Asvs-ad-where-at.png

Let's talk here

Asvs-bulb.jpgDevelopment Guide Communities

Further development of the Development Guide occurs through mailing list discussions and occasional workshops, and suggestions for improvement are welcome. For more information, please contact us.

Got Cycles?

Work has begun on the next version of the Development Guide! Read all about it, here

  • Contributor Onboarding Instructions (PDF)

Got Translation Cycles?

The Development Guide project is always on the lookout for volunteers who are interested in translating the Development Guide into another language.

  • Translation Onboarding Instructions (Currently under development!)

Related resources

Asvs-satellite.jpgOWASP Resources


Downloads

Asvs-step1.jpg1. About the Development Guide

The Development Guide is aimed at architects, developers, consultants and auditors and is a comprehensive manual for designing, developing and deploying secure Web Applications and Web Services. The original OWASP Development Guide has become a staple diet for many web security professionals. Since 2002, the initial version was downloaded over 2 million times. Today, the Development Guide is referenced by many leading government, financial, and corporate standards and is the Gold standard for Web Application and Web Service security.

  • Project presentation in English (Currently under development!)
  • Data sheet in English (Currently under development!)

Asvs-step2.jpg2. Get the Development Guide

  • DRAFT Development Guide 2013 - TBA
  • Development Guide 2005 in English (PDF, Word, Wiki)
  • Development Guide 2005 in Spanish (PDF, Word)
  • Development Guide 2002 in Japanese (PDF)
  • Development Guide (Earlier Versions) (file download center, CVS)


Asvs-step3.jpg3. Learn about using the Development Guide

The Development Guide provides practical guidance and includes J2EE, ASP.NET, and PHP code samples. The Development Guide covers an extensive array of application-level security issues, from SQL injection through modern concerns such as phishing, credit card handling, session fixation, cross-site request forgeries, compliance, and privacy issues.

  • Development Guide Articles (Please see below)

Glossary

Asvs-letters.jpgDevelopment Guide Terminology

  • (Currently under development!)


Project About

PROJECT INFO
What does this OWASP project offer you?
RELEASE(S) INFO
What releases are available for this project?
what is this project?
Name: OWASP Development Guide (home page)
Purpose: The Development Guide provides practical guidance and includes J2EE, ASP.NET, and PHP code samples. The Development Guide covers an extensive array of application-level security issues, from SQL injection through modern concerns such as phishing, credit card handling, session fixation, cross-site request forgeries, compliance, and privacy issues.
License: Creative Commons Attribution ShareAlike 3.0
who is working on this project?
Project Leader(s): N/A
Project Contributor(s):
how can you learn more?
Project Pamphlet: Not Yet Created
Project Presentation:
Mailing list: Mailing List Archives
Project Roadmap: View
Main links:
Key Contacts
  • Contact the GPC to contribute to this project
  • Contact the GPC to review or sponsor this project
  • Contact the GPC to report a problem or concern about this project or to update information.
current release
Guide 2.0 - July 2005 - (download)
Release description: In Guide 2.0, you will find details on securing most forms of web applications and services, with practical guidance using J2EE, ASP.NET, and PHP samples.
Rating: Greenlight.pngGreenlight.pngGreenlight.png Stable Release - Assessment Details
last reviewed release
Not Yet Reviewed


other releases