SlideShare a Scribd company logo
OWASP OWTF
Bharadwaj ‘tunnelshade’ Machiraju
#whoami
Student (B.Tech)
Core developer of OWTF
OWASP GSoC Mentor
OWASP OWTF
Offensive Web Testing Framework
Written in python by Abraham Aranguren (@7a_)
Runs a bunch of tools the way you want
Highly extensible, so easy to add own plugins
Web based UI
Currently under heavy development
Funded by
OWASP
Google
BruCon
ElearnSecurity
Present Features
Has approx 150 well categorised plugins
Botnet Mode - Allows usage of proxies and even tor network to avoid
detection.
Plug-n-hack Phase-I support
Inbound proxy
and much more…..
DEMO TIME
Requirements
A linux distribution (Kali is highly recommended)
Internet connection
git, python2 & wget installed
A bit of patience
Installation
!
Clone from our github repo (https://github.com/owtf)
Development branch(lions_2014)
Run the install script (install/install.py)
Ready!!
Usage
Fire up owtf with a target (./owtf.py demo.testfire.net)
Visit the web interface (default at http://127.0.0.1:8009/ui/)
Open targets and click on your target
Run some plugins/browse using plug-n-hack
Check the report and logs
Plugins?
Three main categories web, net & aux
Web
External - Help links to external resources
Passive - No traffic is sent to target
Semi passive - Non intrusive traffic is sent to target
grep - Passive analysis of transactions
active - Intrusive traffic is sent to target
Special Features (ongoing GSoC projects)
Plug-n-Hack Phase II - Cornel Punga
Sessions support - Viyat Bhalodia
Zest support - Deep Shah
Automated vulnerability rankings - Tao Sauvage
Online passive scanner (demo - lucif3rr.github.io) - Anirudh Anand
WAF Bypasser - Marios Kourtesis
How can you help?
Student? (GSoC, MWoS, Similar OWASP program)
Non-Student? You can get fame, goodies & chance to speak at
conferences ;)
Lots of links
OWTF Presentations - http://www.slideshare.net/abrahamaranguren
OWASP Page - http://owtf.org
Twitter - @owtfp
Github Org - https://github.com/owtf
Wiki - https://github.com/owtf/owtf/wiki
Freenode IRC Channel - #owtf
*I am providing a sneak peek into the future owtf release ;)
You can Contact Me!
bharadwaj.machiraju@gmail.com
aka tunnelshade
http://blog.tunnelshade.in
@tunnelshade_

More Related Content

PPT
Robotframework Presentation - Pinoy Python Meetup 2011January12
PDF
Panther loves Symfony apps
PDF
PDF
Appium & Robot Framework
PDF
Jenv: Java Environment Manager
PDF
Owasp AppSecEU 2015 - BeEF Session
PDF
How to Setup A Pen test Lab and How to Play CTF
PPTX
Robot framework
Robotframework Presentation - Pinoy Python Meetup 2011January12
Panther loves Symfony apps
Appium & Robot Framework
Jenv: Java Environment Manager
Owasp AppSecEU 2015 - BeEF Session
How to Setup A Pen test Lab and How to Play CTF
Robot framework

What's hot (20)

PDF
Vagrant for local and team WordPress Development
PDF
Understanding Burp Replicator
PDF
Hands on iOS developments with jenkins
PPTX
PhoneGap day 2016 EU: Simulating Cordova Plugins in the Browser
ODP
It Works On My Machine: Vagrant for Software Development
PPTX
TYPO3 CMS deployment with Jenkins CI
PDF
Automate Yo' Self
PDF
Gr8conf - The Groovy Ecosystem Revisited
PDF
GlassFish Embedded API
PDF
DevOps Camp 2017 NYC Local Development using Vagrant by Anthony Alvarez
ODP
DIY Java & Kubernetes
PPT
Django Deployment
PDF
Vagrant for Development
PPTX
Bsides tampa
PDF
Acceptance testing plone sites and add ons with robot framework and selenium
ODP
Browser Exploitation Framework Tutorial
PPTX
Development with Vagrant
PDF
AppSec & OWASP Top 10 Primer
PPTX
Web browsers
Vagrant for local and team WordPress Development
Understanding Burp Replicator
Hands on iOS developments with jenkins
PhoneGap day 2016 EU: Simulating Cordova Plugins in the Browser
It Works On My Machine: Vagrant for Software Development
TYPO3 CMS deployment with Jenkins CI
Automate Yo' Self
Gr8conf - The Groovy Ecosystem Revisited
GlassFish Embedded API
DevOps Camp 2017 NYC Local Development using Vagrant by Anthony Alvarez
DIY Java & Kubernetes
Django Deployment
Vagrant for Development
Bsides tampa
Acceptance testing plone sites and add ons with robot framework and selenium
Browser Exploitation Framework Tutorial
Development with Vagrant
AppSec & OWASP Top 10 Primer
Web browsers
Ad

Viewers also liked (20)

PPTX
Baseball stats
PDF
Social engineering by-rakesh-nagekar
DOC
So you want to retire in florida 1997 far
PPTX
Security News Bytes
PDF
Investor alert—investment scams exploit immigrant investor program
PPTX
Internet safety presentation
PDF
Nomadic Display Set Up HangTen
PDF
Nomadic Display Setup Fabri Mural
PPTX
UGA Guest Lecture: Social Media 101
DOC
Buying a business in florida
PPTX
Example problems Binomials
PPTX
Example problems Binomial Multiplication
DOC
SAmador CV
PDF
Oig 14 19-dec13 report on eb5 program
PPTX
PDF
Heartbleed by-danish amber
PPTX
Mobile application security 101
PPTX
Example problems
PPTX
Newsbytes_NULLHYD_Dec
DOC
Buying a business in florida
Baseball stats
Social engineering by-rakesh-nagekar
So you want to retire in florida 1997 far
Security News Bytes
Investor alert—investment scams exploit immigrant investor program
Internet safety presentation
Nomadic Display Set Up HangTen
Nomadic Display Setup Fabri Mural
UGA Guest Lecture: Social Media 101
Buying a business in florida
Example problems Binomials
Example problems Binomial Multiplication
SAmador CV
Oig 14 19-dec13 report on eb5 program
Heartbleed by-danish amber
Mobile application security 101
Example problems
Newsbytes_NULLHYD_Dec
Buying a business in florida
Ad

Similar to Null July - OWTF - Bharadwaj Machiraju (20)

PDF
OWASP Bangalore : OWTF demo : 13 Dec 2014
DOCX
Spring competitive tests
PPTX
Advance java prasentation
ODP
Owasp owtf the offensive (web) testing framework + ptes penetration testing e...
PDF
Play Framework Introduction
PPTX
OWASP Zed Attack Proxy
ODP
See Hudson Run, Run Hudson, Run [SELF 2010]
PDF
Java REST API Comparison: Micronaut, Quarkus, and Spring Boot - jconf.dev 2020
PDF
JVM Web Frameworks Exploration
ODP
eXo Platform SEA - Play Framework Introduction
PPT
Django, What is it, Why is it cool?
PDF
Java REST API Framework Comparison - PWX 2021
PDF
Automating Security Testing with the OWTF
ODP
2015 mindthesec mauro risonho de paula assumpcao rev01 firebits
PDF
Java REST API Framework Comparison - UberConf 2021
ODP
Aug penguin16
PPTX
SWOFT a PHP Microservice Framework - 2020
PDF
Continuous Delivery - Voxxed Days Cluj-Napoca 2017
PPTX
WebdriverIO: the Swiss Army Knife of testing
PPT
Hands on web development with play 2.0
OWASP Bangalore : OWTF demo : 13 Dec 2014
Spring competitive tests
Advance java prasentation
Owasp owtf the offensive (web) testing framework + ptes penetration testing e...
Play Framework Introduction
OWASP Zed Attack Proxy
See Hudson Run, Run Hudson, Run [SELF 2010]
Java REST API Comparison: Micronaut, Quarkus, and Spring Boot - jconf.dev 2020
JVM Web Frameworks Exploration
eXo Platform SEA - Play Framework Introduction
Django, What is it, Why is it cool?
Java REST API Framework Comparison - PWX 2021
Automating Security Testing with the OWTF
2015 mindthesec mauro risonho de paula assumpcao rev01 firebits
Java REST API Framework Comparison - UberConf 2021
Aug penguin16
SWOFT a PHP Microservice Framework - 2020
Continuous Delivery - Voxxed Days Cluj-Napoca 2017
WebdriverIO: the Swiss Army Knife of testing
Hands on web development with play 2.0

More from Raghunath G (17)

PPSX
Securitynewsbytes
PPT
Whats app forensic
PPTX
Seh based exploitation
PPSX
Securitynewsbytes april2015-150418153901-conversion-gate01
PDF
Raspberry pi 2
PPTX
Analysis of malicious pdf
PPTX
Is iso 27001, an answer to security
PDF
Null HYD Playing with shodan null
PDF
Null HYD VRTDOS
PPTX
Metasploit
PPT
Null dec 2014
PDF
Security News Bytes
PPTX
Decoy documents
PDF
Spear phishing attacks-by-hari_krishna
PDF
Netcat 101 by-mahesh-beema
PDF
Xss 101 by-sai-shanthan
PDF
The art of_firewalking-by-sujay
Securitynewsbytes
Whats app forensic
Seh based exploitation
Securitynewsbytes april2015-150418153901-conversion-gate01
Raspberry pi 2
Analysis of malicious pdf
Is iso 27001, an answer to security
Null HYD Playing with shodan null
Null HYD VRTDOS
Metasploit
Null dec 2014
Security News Bytes
Decoy documents
Spear phishing attacks-by-hari_krishna
Netcat 101 by-mahesh-beema
Xss 101 by-sai-shanthan
The art of_firewalking-by-sujay

Recently uploaded (20)

PDF
Black Hat USA 2025 - Micro ICS Summit - ICS/OT Threat Landscape
PDF
2.FourierTransform-ShortQuestionswithAnswers.pdf
PDF
Basic Mud Logging Guide for educational purpose
PDF
O5-L3 Freight Transport Ops (International) V1.pdf
PPTX
Institutional Correction lecture only . . .
PDF
Abdominal Access Techniques with Prof. Dr. R K Mishra
PPTX
PPT- ENG7_QUARTER1_LESSON1_WEEK1. IMAGERY -DESCRIPTIONS pptx.pptx
PDF
VCE English Exam - Section C Student Revision Booklet
PPTX
master seminar digital applications in india
PDF
O7-L3 Supply Chain Operations - ICLT Program
PDF
The Lost Whites of Pakistan by Jahanzaib Mughal.pdf
PDF
Computing-Curriculum for Schools in Ghana
PDF
RMMM.pdf make it easy to upload and study
PDF
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
PDF
Insiders guide to clinical Medicine.pdf
PPTX
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
PPTX
Final Presentation General Medicine 03-08-2024.pptx
PDF
Module 4: Burden of Disease Tutorial Slides S2 2025
PDF
ANTIBIOTICS.pptx.pdf………………… xxxxxxxxxxxxx
PPTX
PPH.pptx obstetrics and gynecology in nursing
Black Hat USA 2025 - Micro ICS Summit - ICS/OT Threat Landscape
2.FourierTransform-ShortQuestionswithAnswers.pdf
Basic Mud Logging Guide for educational purpose
O5-L3 Freight Transport Ops (International) V1.pdf
Institutional Correction lecture only . . .
Abdominal Access Techniques with Prof. Dr. R K Mishra
PPT- ENG7_QUARTER1_LESSON1_WEEK1. IMAGERY -DESCRIPTIONS pptx.pptx
VCE English Exam - Section C Student Revision Booklet
master seminar digital applications in india
O7-L3 Supply Chain Operations - ICLT Program
The Lost Whites of Pakistan by Jahanzaib Mughal.pdf
Computing-Curriculum for Schools in Ghana
RMMM.pdf make it easy to upload and study
3rd Neelam Sanjeevareddy Memorial Lecture.pdf
Insiders guide to clinical Medicine.pdf
IMMUNITY IMMUNITY refers to protection against infection, and the immune syst...
Final Presentation General Medicine 03-08-2024.pptx
Module 4: Burden of Disease Tutorial Slides S2 2025
ANTIBIOTICS.pptx.pdf………………… xxxxxxxxxxxxx
PPH.pptx obstetrics and gynecology in nursing

Null July - OWTF - Bharadwaj Machiraju

  • 2. #whoami Student (B.Tech) Core developer of OWTF OWASP GSoC Mentor
  • 3. OWASP OWTF Offensive Web Testing Framework Written in python by Abraham Aranguren (@7a_) Runs a bunch of tools the way you want Highly extensible, so easy to add own plugins Web based UI Currently under heavy development
  • 5. Present Features Has approx 150 well categorised plugins Botnet Mode - Allows usage of proxies and even tor network to avoid detection. Plug-n-hack Phase-I support Inbound proxy and much more…..
  • 7. Requirements A linux distribution (Kali is highly recommended) Internet connection git, python2 & wget installed A bit of patience
  • 8. Installation ! Clone from our github repo (https://github.com/owtf) Development branch(lions_2014) Run the install script (install/install.py) Ready!!
  • 9. Usage Fire up owtf with a target (./owtf.py demo.testfire.net) Visit the web interface (default at http://127.0.0.1:8009/ui/) Open targets and click on your target Run some plugins/browse using plug-n-hack Check the report and logs
  • 10. Plugins? Three main categories web, net & aux Web External - Help links to external resources Passive - No traffic is sent to target Semi passive - Non intrusive traffic is sent to target grep - Passive analysis of transactions active - Intrusive traffic is sent to target
  • 11. Special Features (ongoing GSoC projects) Plug-n-Hack Phase II - Cornel Punga Sessions support - Viyat Bhalodia Zest support - Deep Shah Automated vulnerability rankings - Tao Sauvage Online passive scanner (demo - lucif3rr.github.io) - Anirudh Anand WAF Bypasser - Marios Kourtesis
  • 12. How can you help? Student? (GSoC, MWoS, Similar OWASP program) Non-Student? You can get fame, goodies & chance to speak at conferences ;)
  • 13. Lots of links OWTF Presentations - http://www.slideshare.net/abrahamaranguren OWASP Page - http://owtf.org Twitter - @owtfp Github Org - https://github.com/owtf Wiki - https://github.com/owtf/owtf/wiki Freenode IRC Channel - #owtf *I am providing a sneak peek into the future owtf release ;)
  • 14. You can Contact Me! bharadwaj.machiraju@gmail.com aka tunnelshade http://blog.tunnelshade.in @tunnelshade_