Top Banner
OWASP OWTF Anant Shrivastava
26
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: OWASP Bangalore : OWTF demo : 13 Dec 2014

OWASP OWTF

Anant Shrivastava

Page 2: OWASP Bangalore : OWTF demo : 13 Dec 2014

OWTF

Page 3: OWASP Bangalore : OWTF demo : 13 Dec 2014

O.W.T.F.

Page 4: OWASP Bangalore : OWTF demo : 13 Dec 2014

OffensiveWeb

TestingFramework

Page 5: OWASP Bangalore : OWTF demo : 13 Dec 2014

Who am iAnant Shrivastava

Information Security Consultant

OWASP + G4H + null

http://anantshri.info

@anantshri

Page 6: OWASP Bangalore : OWTF demo : 13 Dec 2014

Agenda

What is OWTFOWTF DemoThings not coveredHow to Contribute

Page 7: OWASP Bangalore : OWTF demo : 13 Dec 2014

OffensiveWeb

TestingFramework

Page 8: OWASP Bangalore : OWTF demo : 13 Dec 2014

Need of W.T.F.

Automated Pentest operationsOrganize finding as per standardstandard could be OWASP, NIST or otherscustom notes and rankingsidentify type of execution Passive, active

Page 9: OWASP Bangalore : OWTF demo : 13 Dec 2014

History

We started out as a way to run OWASP test's withoutaccessing the website directly i.e. via indirect / passive ways.Written in Python by Abraham (@7a_)One of the most active OWASP projects alongside (ZAP andTestingGuide)

Page 10: OWASP Bangalore : OWTF demo : 13 Dec 2014

U. S. P.

Automated task executionSingle Dashboardresult aggregation (in future co-relation)Raw tools output availableSingle point dashboard for all data.Control Task's : Pause and resume.

Page 11: OWASP Bangalore : OWTF demo : 13 Dec 2014

HOW

Page 12: OWASP Bangalore : OWTF demo : 13 Dec 2014

But its primarily a

DEMO

Page 13: OWASP Bangalore : OWTF demo : 13 Dec 2014

So lets Launch the demo parts first.

Page 14: OWASP Bangalore : OWTF demo : 13 Dec 2014

Project hosted at http://github.com/owtf/owtf

Page 15: OWASP Bangalore : OWTF demo : 13 Dec 2014

Officially supports

KALI LINUX & Samurai WTF

Page 16: OWASP Bangalore : OWTF demo : 13 Dec 2014

Demo Setup

1. Kali Machine with OWTF configured on it2. scan : 3. scan :

http://demo.testfire.nethttp://testasp.vulnweb.com

Page 17: OWASP Bangalore : OWTF demo : 13 Dec 2014

Basic setup

git clone cd owtfpython2 install/install.py

http://github.com/owtf/owtf.git

Page 18: OWASP Bangalore : OWTF demo : 13 Dec 2014

DEMO

Page 19: OWASP Bangalore : OWTF demo : 13 Dec 2014

Development

Page 20: OWASP Bangalore : OWTF demo : 13 Dec 2014

Not covered

OWTF botnetmodeOWTF inbuilt proxyOWTF PlugnHack supportOWTF Waf Bypasser and other plugins

Page 21: OWASP Bangalore : OWTF demo : 13 Dec 2014

contribute?

GSoCWinter of CodeJust CodeIssue tracker comments on Github page.

Page 22: OWASP Bangalore : OWTF demo : 13 Dec 2014

Useful links

1. 2. 3. Video Demos @ youtube (owtfproject)4.

http://owtf.orghttp://github.com/owtf/owtf

http://bit.ly/owtf-demo-lionheart

Page 23: OWASP Bangalore : OWTF demo : 13 Dec 2014

Social Connect

Twitter: @owtfp

Freenode IRC : #owtf

Page 24: OWASP Bangalore : OWTF demo : 13 Dec 2014

Any Questions?

Page 25: OWASP Bangalore : OWTF demo : 13 Dec 2014

slide credits

Not all slides were mine.

credits to

@tunnelshade_ and @7a_

for some slides.

Page 26: OWASP Bangalore : OWTF demo : 13 Dec 2014

Thank You