Application Security Verification Standard
Repositórios
Repositórios de OWASP
The OWASP Cheat Sheet Series was created to provide a concise collection of high value information on specific application security topics.
Automated Penetration Testing Framework - Open-Source Vulnerability Scanner - Vulnerability Management
The OWASP NodeGoat project provides an environment to learn how OWASP Top 10 security risks apply to web applications developed using Node.js and how to effectively address them.
QRLJacking or Quick Response Code Login Jacking is a simple-but-nasty attack vector affecting all the applications that relays on “Login with QR code” feature as a secure way to login into accounts which aims for hijacking users session by attackers.
Official OWASP Top 10 Document Repository
A Common Weakness Enumeration (CWE) Node.js SDK compliant with MITRE / CAPEC
A command line CWE discovery tool based on OWASP / CAPSEC database of Common Weakness Enumeration.
Kubernetes Security Testing Guide
The OWASP Mobile Application Security Testing Guide (MASTG) is a comprehensive manual for mobile app security testing and reverse engineering. It describes technical processes for verifying the OWASP Mobile Security Weakness Enumeration (MASWE) weaknesses, which are in alignment with the OWASP MASVS.
The OWASP Java Encoder is a Java 1.5+ simple-to-use drop-in high-performance encoder class with no dependencies and little baggage. This project will help Java web developers defend against Cross Site Scripting!
A documentation and tracking project with the goal of making package management systems more secure.
A vulnerable version of Rails that follows the OWASP Top 10
Vulnerable app with examples showing how to not use secrets
Run Capture the Flags and Security Trainings with OWASP WrongSecrets