OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

27
Introduction to OWASP Bricks

description

OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014 http://www.youtube.com/watch?v=pPg8bA7ps3U

Transcript of OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

Page 1: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

Introduction to OWASP Bricks

Page 2: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

Who am I?

You really don’t care

You already decided to be in the room

Page 3: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

Before we begin

This is not a talk about 0 day

a talk about next big thing in info sec

a tool release

This is about a very small OWASP project

exploits you have heard for last few years

an idea and platform where you can pitch in

Page 4: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

Technology has changed our lives

Page 5: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

2000 and 2014

2000 2014

Computers Rare to see We can find it each and

every corner

Cell Phones Very Rare to find Most of us have more than

one.!!!

Internet What? Where? Everywhere.!

Page 6: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

As of 2014, the number of internet users worldwide

= 2.92 billion

Source: http://www.statista.com/statistics/273018/number-of-internet-users-worldwide/

Page 7: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

The Big Picture

Either you can communicate with 2.92 Billion users

Or they can communicate with you

.

Page 8: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

What if 1% of 2.92 Billions users tries to connect to

your computer

1% of 2.92 Billions = 292,000,000 users

Page 9: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014
Page 10: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014
Page 11: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

Some may knock on your door

Closed – Fine

Not Closed – Not fine

Page 12: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

What is OWASP Bricks?

Web application security learning platform.

Built with PHP and MySQL.

Open source and free.

‘Break the Bricks’ and learn.

Page 13: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

Simple, clean and friendly.

Almost all levels can be solved using Mantra / ZAP.

Code can be reused to build CTFs.

Perfect for lab demos.

Page 14: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

OWASP Mantra

Browser for penetration testing.

Cross platform.

Great UI and ready to use.

Perfect tool for manual web app security analysis.

www.getmantra.com

Page 15: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

OWASP Zed Attack Proxy

Proxy for web application analysis.

Cross platform.

The best tool for manual/semi automated and automated

web application security analysis.

owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project

Page 16: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

Login pages

Login pages

Comes with security issues

Can be breached using Mantra/ZAP

Page 17: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

File upload pages

File upload pages

Comes with security issues

Can be breached using Mantra/ZAP

Page 18: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

Content pages

Content pages

Comes with security issues

Can be breached using Mantra

Page 19: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

Again, Why?

6 Reasons

Page 20: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

1 - Maximum variations of common security issues

Page 21: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

2 - Help people to learn the need of secure codding practices

Page 22: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

3 - A test bed for analysing the performance of web application security scanners

Page 23: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

4 - Help people learn the manual method of testing the applications

Page 24: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

5 - Demonstrate the possibilities of various security tools and techniques

Page 25: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

6 - Become a platform to teach web application security in a class room/lab environment.

Page 26: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

You can

Come up with new bricks

Port OWASP Bricks to other languages

Build more vulnerable applications

Use it in demos/ classrooms

Write articles

Page 27: OWASP Bricks presentation from OWASP-Null combined meet at Delhi, August 2014

So long and thanks for all the attention