Nytro Posted August 31, 2012 Report Posted August 31, 2012 [h=3]OWASP Security Shepherd 1.2 Released[/h]Security Shepherd is a computer based training application for web application security vulnerabilities. This project strives to hurde the lost sheep of the technological world back to the safe and sound ways of secure practises. Security Shepherd can be deployed as a CTF (Capture the Flag) game or as an open floor educational server.Easy configuration to suit every useSecurity Shepherd has been designed and implemented with the aim of fostering and improving security awareness among a varied skill-set demographic. This project enables users to learn or to improve upon existing manual penetration testing skills. This is accomplished through lesson and challenge techniques. A lesson provides a user with a lot of help in completing that module, where a challenge puts what the user learned in the lesson to use. Utilizing the OWASP top ten as a challenge test bed, common security vulnerabilities can be explored and their impact on a system understood. The bi-product of this challenge game is the acquired skill to harden a players own environment from OWASP top ten security risks The modules have been crafted to provide not only a challenge for a security novice, but security professionals as well.Security Shepherds vulnerabilities are not simulated, and are instead delievered through hardened real security vulnerabilities that can not be abused to compromise the application or it's environment. Many of these levels include insufficient protections to these vulnerabilities, such as black list filteres and poor security configuration. Security Shepherd includes everything you need to complete all of it's levels including the OWASP Zed Attack Proxy Project and portable browsers already configured for proxy use.The Security Shepherd project covers the following web application security topics;SQL InjectionCross Site ScriptingBroken Authetication and Session ManagementCross Site Rrequest ForgeryInsecure Direct Object ReferenceInsecure Cryptographic StorageFailure to Restrict URL AccessUnvalidated Redirects and ForwardsInsufficient Transport Layer SecurityDownload OWASP Security Shepherd 1.2Sursa: OWASP Security Shepherd 1.2 Released - Penetration Testing and Security Tools Quote
Hack.Oradea Posted September 5, 2012 Report Posted September 5, 2012 asta sa intleg e pentru floood? sa nu primestii flood? Quote