Difference between revisions of "OWASP Mantra - Security Framework"

From OWASP
Jump to: navigation, search
Line 113: Line 113:
 
'''Project Leaders'''<br/>
 
'''Project Leaders'''<br/>
 
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]]<br/>
 
[[User:Abhi_M_Balakrishnan|Abhi M Balakrishnan]]<br/>
[[User:Yashartha_ChaturvediYashartha Chaturvedi]]<br/>
+
[[User:Yashartha_Chaturvedi|Yashartha Chaturvedi]]<br/>
 
Gokul C Gopinath<br/><br/>
 
Gokul C Gopinath<br/><br/>
  
Line 160: Line 160:
 
==== Resources ====
 
==== Resources ====
  
{{:Projects/OWASP Mantra - Security Framework | Resources}}
+
'''Project Pamphlets'''<br/>
 +
 
 +
[http://www.owasp.org/images/e/e4/OWASP_Mantra-An_Introduction.pdf Project Pamphlet 1]<br/><br/>
 +
 
 +
'''Project Presentations'''<br/>
 +
 
 +
[http://www.owasp.org/index.php/File:OWASP_Mantra-An_Introduction.pptx Project Presentation 1]<br/><br/>
 +
 
 +
'''Text Tutorials'''<br/>
 +
 
 +
[http://getmantra.com/forums/Thread-introducing-passiverecon-by-justin-morehouse Introducing PassiveRecon by Justin Morehouse]<br/>
 +
[http://getmantra.com/forums/Thread-introducing-groundspeed-by-felipe Introducing Groundspeed by Felipe]<br/>
 +
[http://getmantra.com/forums/Thread-introducing-link-sidebar-by-varun-n Introducing Link Sidebar by Varun N]<br/>
 +
[http://getmantra.com/forums/Thread-introducing-proxytool-by-robert-rade Introducing ProxyTool by Robert Rade]<br/>
 +
[http://getmantra.com/forums/Thread-introducing-httpfox-by-martin-theimer Introducing HttpFox by Martin Theimer]<br/>
 +
[http://getmantra.com/forums/Thread-how-to-make-your-own-search-bar-item How to make your own search bar item]<br/>
 +
[http://getmantra.com/forums/Thread-switching-between-languages-and-locales Switching between languages and locales]<br/>
 +
[http://getmantra.com/forums/Thread-running-mantra-and-firefox-together Running Mantra and Firefox together]<br/>
 +
[http://getmantra.com/forums/Thread-login-form-bypass-using-mantra-security-toolkit Login Form Bypass using Mantra Security Toolkit]<br/>
 +
[http://getmantra.com/forums/Thread-advanced-sql-injection-tutorial-complete-website-rooting Advanced SQL Injection Tutorial - Complete website rooting]<br/>
 +
[http://getmantra.com/forums/Thread-manual-crawling Manual Crawling]<br/>
 +
[http://getmantra.com/forums/Thread-introducing-flagfox Introducing Flagfox]<br/><br/>
 +
 
 +
'''Video Tutorials'''<br/>
 +
 
 +
ClubHACK 2010 - [http://www.youtube.com/watch?v=GBFxVAM3DLQ 1] [http://www.youtube.com/watch?v=bKACEDWKeyM 2] [http://www.youtube.com/watch?v=qpVHWVOPHTk 3]<br/>
 +
[http://www.youtube.com/watch?v=yTbB42sR208 Broken Authentication Demonstration]<br/>
 +
[http://www.youtube.com/watch?v=o1WVx6eYE-M Broken Session]<br/>
 +
[http://www.youtube.com/watch?v=vvPeskadF-s Insecure Direct Object References]<br/>
 +
[http://www.youtube.com/watch?v=NK3S-nwiGwA Cross Site Scripting]
  
 
==== Links ====
 
==== Links ====

Revision as of 11:52, 18 October 2011

Main

[edit]

OWASP Mantra Security Framework.jpg

  • Mantra is a collection of free and open source tools integrated into a web browser, which can become handy for students, penetration testers, web application developers,security professionals etc. It is portable, ready-to-run, compact and follows the true spirit of free and open source software.
  • Mantra is lite, flexible, portable and user friendly with a nice graphical user interface. You can carry it in memory cards, flash drives, CD/DVDs, etc. It can be run natively on Linux, Windows and Mac platforms. It can also be installed on to your system within minutes. Mantra is absolutely free of cost and takes no time for you to set up.

  1. Create an ecosystem for hackers based on browser
  2. To bring the attention of security people to the potential of a browser based security platform
  3. Provide easy to use and portable platform for demonstrating common web based attacks( read training )
  4. To associate with other security tools/products to make a better environment. Eg:
    1. It can be a nice addition to security distribution OSs like OWASP Live CD
    2. It can be used to solve basic levels of CTF contests
    3. It can associate with projects like DVWA to showcase attacks
    4. It can bring functions like crawler, SQL injection scanner etc by installing extensions.