GithubHelp home page GithubHelp logo

owasp-testing-guide-v5's Introduction

OWASP-Testing-Guide-v5

THIS IS THE OWASP TESTING GUIDE PROJECT ROADMAP FOR V5. You can download the stable version v4 here: http://www.owasp.org/index.php/OWASP_Testing_Project

WHAT

The OWASP Testing Guide v4 includes a “best practice” penetration testing framework which users can implement in their own organisations. The Testing Guide v4 also includes a “low level” penetration testing guide that describes techniques for testing the most common web application and web service security issues. Today the Testing Guide is the standard to perform Web Application Penetration Testing, and many companies around the world have adopted it. It is vital to maintain an updated project that represents the state of the art for WebAppSec.

The aim of the Working Session is to discuss and define the scope and content of OWASP Testing Guide v5.

OUTCOMES

  • All sections in v4 reviewed
  • Project aligned with the ASVS and OWASP Top 10 vulnerabilities
  • A more readable guide created that eliminates sections that are not useful
  • New testing techniques inserted
  • Some sections rationalised as Session Management Testing
  • New section created: Client side security and Firefox extensions testing
  • Project v5 Deadlines:
  • 1: Setup the team of authors
  • 2: Start a brainstorming for the new index starting from “Release Description”
  • 3: Create the new index and confirm new team
  • 4: Start writing articles first phase
  • 5: OWASP Summit TGv5 review and brainstorming
  • 6: Start writing articles II phase
  • 7: Start the second review phase
  • 8: Create the RC1
  • 9: Release version 5

Test Changes

This outline will include proposed test changes that need to be incorporated into OTG v5. These should be proposed significant changes that are associated with an explicit test.

New Tests

  • Server-Side Template Injection

Test Changes

  • Testing for Horizontal Bypassing Authorization Schema
  • Testing for CSRF

Deprecated Tests

  • (Include brief explanation of reasoning)

Methodology Changes

  • (Include brief explanation of reasoning)

owasp-testing-guide-v5's People

Contributors

diniscruz avatar ginjabenjamin avatar itscooper avatar kingthorin avatar manhnho avatar matowasp avatar talargoni avatar

Watchers

 avatar

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.