Thursday, February 16, 2017

OWASP Comprises 30% of ToolsWatch.org Top Ten Security Tools for 2016

The OWASP Community produces a lot of amazing things. This month we are glad to share that three OWASP Projects have taken spots in 2016 Top Security Tools as voted by ToolsWatch.org Readers. Congratulations and many thanks to the project leaders and many contributors to these projects! 


Zed Attack Proxy


OWASP Zed Attack Proxy Project (ZAP), a penetration testing tool that combines automatic scanning and manual tools, was voted the 2nd most popular tool of 2016.  You can join Simon Bennetts and the ZAP team by visiting the ZAP GitHub or taking this survey.





OWASP VBScan Project, the black box vulnerability scanner which detects and analyses VBulletin CMS vulnerabilities in perl, was voted 3rd most popular tool of 2016.  You watch demonstrations on the wiki page or help by following up with Mohammad Reza Espargham on GitHub.





OWASP ZSC Tool Project placed 6th in the top ten for 2016.  The project generates customized shellcodes and convert scripts to an obfuscated script. You can contribute Ali Razmjoo and Johanna Curiel's python project on their GitHub.


Thank you for your votes!!
Congratulations OWASP Project Leaders!


.

Labels: , , , , , , , ,

Monday, September 26, 2016

OWASP Bucharest AppSec Conference 2016 - October 6th

OWASP Bucharest team is happy to announce the OWASP Bucharest AppSec Conference 2016, a one day Security and Hacking Conference dedicated to the application security.
It will take place on 6th of October, 2016 - Bucharest, Romania at Sheraton Bucharest Hotel.
  • Conference talks are free however, you need to register.
The event will be in English, with cutting-edge topics presented by renowned security professionals: Daniel Kefer, Adrian Hada, Jacco van Tujil, Andrei Daniel Oprisan.

  • Workshops:
OWASP Top 10 vulnerabilities – discover, exploit, remediate
Increase the participants’ awareness on the most common web application vulnerabilities and their associated risks.
Each type of vulnerability will be discussed and the attendees will practice manual discovery and exploitation techniques.

Secure Web Applications in Java
Learning how to build secure coding and secure code review skills, uncover and protect against some of the most common vulnerabilities in Java code.

Shellcode Development and Exploiting
Learn how to create shellcodes and how to construct basic attack vectors using shellcodes. Obtain a better understanding about how programs and processes work.
Trainers:  Razvan Deaconescu; Mihai Țigănuș

Practical Cryptography on the Internet
The training will feature many guided hands-on activities such as creating certificate hierarchies, configuring custom certificates on clients and servers, modifying security policies, impersonating “seemingly secure” identities, downgrading connections, and extracting information from secure HTTPS sessions
Trainers: Sergiu Costea

  • CTF (Capture The Flag)
Capture The Flag contests are popular ways to hone your practical security skills by solving challenges on topics such as web, crypto, reverse, exploiting.
We invite everyone passionate about practical security at the OWASP AppSec 2016 CTF, where you and your team will solve challenges on web, reverse and exploiting.
In order to participate in the CTF competition, please register here: https://owasp-ctf.security.cs.pub.ro/home
The prizes will be as follows:
  • 1st place: 1024 euros
  • 2nd place: 512 euros
  • 3rd place: 256 euros
More information about the agenda can be found at:
You can register at:

We look forward to seeing you at this event!

Labels: , , , , , , , , , , , , ,