SlideShare a Scribd company logo
OWASP OWTF 
Anant Shrivastava
OWTF
O.W.T.F.
Offensive 
Web 
Testing 
Framework
Who am i Anant Shrivastava 
Information Security Consultant 
OWASP + G4H + null 
http://anantshri.info 
@anantshri
Agenda 
What is OWTF 
OWTF Demo 
Things not covered 
How to Contribute
Offensive 
Web 
Testing 
Framework
Need of W.T.F. 
Automated Pentest operations 
Organize finding as per standard 
standard could be OWASP, NIST or others 
custom notes and rankings 
identify type of execution Passive, active
History 
We started out as a way to run OWASP test's without 
accessing the website directly i.e. via indirect / passive ways. 
Written in Python by Abraham (@7a_) 
One of the most active OWASP projects alongside (ZAP and 
TestingGuide)
U. S. P. 
Automated task execution 
Single Dashboard 
result aggregation (in future co-relation) 
Raw tools output available 
Single point dashboard for all data. 
Control Task's : Pause and resume.
HOW
But its primarily a DEMO
So lets Launch the demo parts first.
Project hosted at http://github.com/owtf/owtf
Officially supports 
KALI LINUX & Samurai WTF
Demo Setup 
1. Kali Machine with OWTF configured on it 
2. scan : 
http://demo.testfire.net 
3. scan : 
http://testasp.vulnweb.com
Basic setup 
git clone 
http://github.com/owtf/owtf.git 
cd owtf 
python2 install/install.py
DEMO
Development
Not covered 
OWTF botnetmode 
OWTF inbuilt proxy 
OWTF PlugnHack support 
OWTF Waf Bypasser and other plugins
contribute? 
GSoC 
Winter of Code 
Just Code 
Issue tracker comments on Github page.
Useful links 
1. 
http://owtf.org 
2. 
http://github.com/owtf/owtf 
3. Video Demos @ youtube (owtfproject) 
4. 
http://bit.ly/owtf-demo-lionheart
Social Connect 
Twitter: @owtfp 
Freenode IRC : #owtf
Any Questions?
slide credits 
Not all slides were mine. 
credits to 
@tunnelshade_ and @7a_ 
for some slides.
Thank You

More Related Content

PDF
How to Setup A Pen test Lab and How to Play CTF
PDF
Nullcon Hack IM 2011 walk through
ODP
2015 mindthesec mauro risonho de paula assumpcao rev01 firebits
PDF
Stealth post-exploitation with phpsploit
PDF
Firmware Extraction & Fuzzing - Jatan Raval
PDF
Introducing OWASP OWTF Workshop BruCon 2012
PDF
Aide 2014 - Fundamentals of Linux Privilege Escalation
PPTX
EuroPython 2014 - How we switched our 800+ projects from Apache to uWSGI
How to Setup A Pen test Lab and How to Play CTF
Nullcon Hack IM 2011 walk through
2015 mindthesec mauro risonho de paula assumpcao rev01 firebits
Stealth post-exploitation with phpsploit
Firmware Extraction & Fuzzing - Jatan Raval
Introducing OWASP OWTF Workshop BruCon 2012
Aide 2014 - Fundamentals of Linux Privilege Escalation
EuroPython 2014 - How we switched our 800+ projects from Apache to uWSGI

What's hot (20)

ODP
Owasp owtf the offensive (web) testing framework + ptes penetration testing e...
PDF
Raptor web application firewall
PDF
Volatility101
PDF
Talk NullByteCon 2015
PPTX
uWSGI - Swiss army knife for your Python web apps
PDF
Bz backtrack.usage
PDF
窺探職場上所需之資安專業技術與能力 Tdohconf
PPTX
如何利用 Docker 強化網站安全
PDF
[English] BackBox Linux and Metasploit: A practical demonstration of the Shel...
PDF
Down by the Docker
PDF
Follow the White Rabbit: Simplifying Fuzz Testing Using FuzzExMachina
PDF
44CON London 2015 - Is there an EFI monster inside your apple?
PPT
Subversion @ JUG Milano 11 dic 2009
PDF
Having fun with Raspberry(s) and Apache projects
PDF
Kernel Recipes 2013 - Kernel for your device
PDF
Rear automated testing with Bareos
PDF
Manage custom kernel builds
PDF
Ggplot2 Installation Instructions
PPTX
Nginx warhead
Owasp owtf the offensive (web) testing framework + ptes penetration testing e...
Raptor web application firewall
Volatility101
Talk NullByteCon 2015
uWSGI - Swiss army knife for your Python web apps
Bz backtrack.usage
窺探職場上所需之資安專業技術與能力 Tdohconf
如何利用 Docker 強化網站安全
[English] BackBox Linux and Metasploit: A practical demonstration of the Shel...
Down by the Docker
Follow the White Rabbit: Simplifying Fuzz Testing Using FuzzExMachina
44CON London 2015 - Is there an EFI monster inside your apple?
Subversion @ JUG Milano 11 dic 2009
Having fun with Raspberry(s) and Apache projects
Kernel Recipes 2013 - Kernel for your device
Rear automated testing with Bareos
Manage custom kernel builds
Ggplot2 Installation Instructions
Nginx warhead
Ad

Similar to OWASP Bangalore : OWTF demo : 13 Dec 2014 (8)

PDF
Null July - OWTF - Bharadwaj Machiraju
PDF
Automating Security Testing with the OWTF
PDF
OWASP OWTF - Summer Storm - OWASP AppSec EU 2013
PPTX
Pentesting like a grandmaster with owtf
PDF
Legal and efficient web app testing without permission
PDF
Abraham aranguren. legal and efficient web app testing without permission
PPTX
OpenNTF: Past, Present, and Future
PDF
Offensive (Web, etc) Testing Framework: My gift for the community - BerlinSid...
Null July - OWTF - Bharadwaj Machiraju
Automating Security Testing with the OWTF
OWASP OWTF - Summer Storm - OWASP AppSec EU 2013
Pentesting like a grandmaster with owtf
Legal and efficient web app testing without permission
Abraham aranguren. legal and efficient web app testing without permission
OpenNTF: Past, Present, and Future
Offensive (Web, etc) Testing Framework: My gift for the community - BerlinSid...
Ad

More from Anant Shrivastava (20)

PDF
Diverseccon keynote: My 2 Paisa's on Infosec World
PDF
Null bhopal Sep 2016: What it Takes to Secure a Web Application
PDF
Android Tamer BH USA 2016 : Arsenal Presentation
PDF
Android Tamer: Virtual Machine for Android (Security) Professionals
PDF
Slides null puliya linux basics
PDF
SSL Pinning and Bypasses: Android and iOS
PDF
Exploiting publically exposed Version Control System
PDF
Understanding The Known: OWASP A9 Using Components With Known Vulnerabilities
PDF
Tale of Forgotten Disclosure and Lesson learned
PDF
My tryst with sourcecode review
PDF
Snake bites : Python for Pentesters
PPTX
Owasp Mobile Risk Series : M4 : Unintended Data Leakage
PDF
Owasp Mobile Risk Series : M3 : Insufficient Transport Layer Protection
PDF
Owasp Mobile Risk M2 : Insecure Data Storage : null/OWASP/G4H Bangalore Aug 2014
PDF
When the internet bleeded : RootConf 2014
PDF
Raspberry pi Beginners Session
PPTX
Career In Information security
PDF
WhitePaper : Security issues in android custom rom
PDF
Security Issues in Android Custom ROM
PDF
Web application finger printing - whitepaper
Diverseccon keynote: My 2 Paisa's on Infosec World
Null bhopal Sep 2016: What it Takes to Secure a Web Application
Android Tamer BH USA 2016 : Arsenal Presentation
Android Tamer: Virtual Machine for Android (Security) Professionals
Slides null puliya linux basics
SSL Pinning and Bypasses: Android and iOS
Exploiting publically exposed Version Control System
Understanding The Known: OWASP A9 Using Components With Known Vulnerabilities
Tale of Forgotten Disclosure and Lesson learned
My tryst with sourcecode review
Snake bites : Python for Pentesters
Owasp Mobile Risk Series : M4 : Unintended Data Leakage
Owasp Mobile Risk Series : M3 : Insufficient Transport Layer Protection
Owasp Mobile Risk M2 : Insecure Data Storage : null/OWASP/G4H Bangalore Aug 2014
When the internet bleeded : RootConf 2014
Raspberry pi Beginners Session
Career In Information security
WhitePaper : Security issues in android custom rom
Security Issues in Android Custom ROM
Web application finger printing - whitepaper

Recently uploaded (20)

PDF
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
PPTX
Big Data Technologies - Introduction.pptx
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PDF
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
DOCX
The AUB Centre for AI in Media Proposal.docx
PDF
Machine learning based COVID-19 study performance prediction
PPTX
MYSQL Presentation for SQL database connectivity
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
Modernizing your data center with Dell and AMD
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
CIFDAQ's Market Insight: SEC Turns Pro Crypto
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PDF
Network Security Unit 5.pdf for BCA BBA.
PDF
Empathic Computing: Creating Shared Understanding
7 ChatGPT Prompts to Help You Define Your Ideal Customer Profile.pdf
Big Data Technologies - Introduction.pptx
Diabetes mellitus diagnosis method based random forest with bat algorithm
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Spectral efficient network and resource selection model in 5G networks
Advanced methodologies resolving dimensionality complications for autism neur...
The Rise and Fall of 3GPP – Time for a Sabbatical?
Bridging biosciences and deep learning for revolutionary discoveries: a compr...
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
The AUB Centre for AI in Media Proposal.docx
Machine learning based COVID-19 study performance prediction
MYSQL Presentation for SQL database connectivity
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
Modernizing your data center with Dell and AMD
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
CIFDAQ's Market Insight: SEC Turns Pro Crypto
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Network Security Unit 5.pdf for BCA BBA.
Empathic Computing: Creating Shared Understanding

OWASP Bangalore : OWTF demo : 13 Dec 2014

  • 1. OWASP OWTF Anant Shrivastava
  • 5. Who am i Anant Shrivastava Information Security Consultant OWASP + G4H + null http://anantshri.info @anantshri
  • 6. Agenda What is OWTF OWTF Demo Things not covered How to Contribute
  • 8. Need of W.T.F. Automated Pentest operations Organize finding as per standard standard could be OWASP, NIST or others custom notes and rankings identify type of execution Passive, active
  • 9. History We started out as a way to run OWASP test's without accessing the website directly i.e. via indirect / passive ways. Written in Python by Abraham (@7a_) One of the most active OWASP projects alongside (ZAP and TestingGuide)
  • 10. U. S. P. Automated task execution Single Dashboard result aggregation (in future co-relation) Raw tools output available Single point dashboard for all data. Control Task's : Pause and resume.
  • 11. HOW
  • 13. So lets Launch the demo parts first.
  • 14. Project hosted at http://github.com/owtf/owtf
  • 15. Officially supports KALI LINUX & Samurai WTF
  • 16. Demo Setup 1. Kali Machine with OWTF configured on it 2. scan : http://demo.testfire.net 3. scan : http://testasp.vulnweb.com
  • 17. Basic setup git clone http://github.com/owtf/owtf.git cd owtf python2 install/install.py
  • 18. DEMO
  • 20. Not covered OWTF botnetmode OWTF inbuilt proxy OWTF PlugnHack support OWTF Waf Bypasser and other plugins
  • 21. contribute? GSoC Winter of Code Just Code Issue tracker comments on Github page.
  • 22. Useful links 1. http://owtf.org 2. http://github.com/owtf/owtf 3. Video Demos @ youtube (owtfproject) 4. http://bit.ly/owtf-demo-lionheart
  • 23. Social Connect Twitter: @owtfp Freenode IRC : #owtf
  • 25. slide credits Not all slides were mine. credits to @tunnelshade_ and @7a_ for some slides.