Top Banner
OWASP OWTF Bharadwaj ‘tunnelshade’ Machiraju
14

Null July - OWTF - Bharadwaj Machiraju

May 08, 2015

Download

Education

OWASP OWTF, the Offensive (Web) Testing Framework, is an OWASP+PTES-focused try to unite great tools and make pen testing more efficient.OWASP OWTF, the Offensive (Web) Testing Framework, is an OWASP+PTES-focused try to unite great tools and make pen testing more efficient.
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Null July - OWTF - Bharadwaj Machiraju

OWASP OWTFBharadwaj ‘tunnelshade’ Machiraju

Page 2: Null July - OWTF - Bharadwaj Machiraju

#whoami

Student (B.Tech)

Core developer of OWTF

OWASP GSoC Mentor

Page 3: Null July - OWTF - Bharadwaj Machiraju

OWASP OWTFOffensive Web Testing Framework

Written in python by Abraham Aranguren (@7a_)

Runs a bunch of tools the way you want

Highly extensible, so easy to add own plugins

Web based UI

Currently under heavy development

Page 4: Null July - OWTF - Bharadwaj Machiraju

Funded by

OWASP

Google

BruCon

ElearnSecurity

Page 5: Null July - OWTF - Bharadwaj Machiraju

Present Features

Has approx 150 well categorised plugins

Botnet Mode - Allows usage of proxies and even tor network to avoid detection.

Plug-n-hack Phase-I support

Inbound proxy

and much more…..

Page 6: Null July - OWTF - Bharadwaj Machiraju

DEMO TIME

Page 7: Null July - OWTF - Bharadwaj Machiraju

Requirements

A linux distribution (Kali is highly recommended)

Internet connection

git, python2 & wget installed

A bit of patience

Page 8: Null July - OWTF - Bharadwaj Machiraju

Installation

!

Clone from our github repo (https://github.com/owtf)

Development branch(lions_2014)

Run the install script (install/install.py)

Ready!!

Page 9: Null July - OWTF - Bharadwaj Machiraju

Usage

Fire up owtf with a target (./owtf.py demo.testfire.net)

Visit the web interface (default at http://127.0.0.1:8009/ui/)

Open targets and click on your target

Run some plugins/browse using plug-n-hack

Check the report and logs

Page 10: Null July - OWTF - Bharadwaj Machiraju

Plugins?Three main categories web, net & aux

Web

External - Help links to external resources

Passive - No traffic is sent to target

Semi passive - Non intrusive traffic is sent to target

grep - Passive analysis of transactions

active - Intrusive traffic is sent to target

Page 11: Null July - OWTF - Bharadwaj Machiraju

Special Features (ongoing GSoC projects)

Plug-n-Hack Phase II - Cornel Punga

Sessions support - Viyat Bhalodia

Zest support - Deep Shah

Automated vulnerability rankings - Tao Sauvage

Online passive scanner (demo - lucif3rr.github.io) - Anirudh Anand

WAF Bypasser - Marios Kourtesis

Page 12: Null July - OWTF - Bharadwaj Machiraju

How can you help?

Student? (GSoC, MWoS, Similar OWASP program)

Non-Student? You can get fame, goodies & chance to speak at conferences ;)

Page 13: Null July - OWTF - Bharadwaj Machiraju

Lots of linksOWTF Presentations - http://www.slideshare.net/abrahamaranguren

OWASP Page - http://owtf.org

Twitter - @owtfp

Github Org - https://github.com/owtf

Wiki - https://github.com/owtf/owtf/wiki

Freenode IRC Channel - #owtf

*I am providing a sneak peek into the future owtf release ;)

Page 14: Null July - OWTF - Bharadwaj Machiraju

You can Contact Me!

[email protected]

aka tunnelshade

http://blog.tunnelshade.in

@tunnelshade_