Talk Blog
Talk Blog
From Yogi To Smokey
This is the archive sites for materials & information from my OWASP talk at the NH JUG on June 28, 2011.
You can find a PDF of the full presentation here. You will have to have either been at the talk or figure out the seekrit from the presentation itself to copy any materials from it (it’s not a content protection thing, it’s a puzzle).
Below are 95% of the links from the presentation (that’s just a hedge in case I missed one or two).
I want to thank everyone who attended and say a special thank you to Scott, Matt & Ted for risking their reputations and future NH JUG attendance by asking a security guy to give an OWASP talk.
(and, yes, I did use iWeb to make this,
mostly because I’m old and lazy)
Rugged Software Links
Threat Modeling Resources
•http://www.microsoft.com/security/sdl/adopt/threatmodeling.aspx
•http://video.google.com/videoplay?docid=-734106766899160289#
OWASP ESAPI Java
OWASP AntiSamy
Vulnerability Scanners
•Nessus – http://www.tenable.com/products/nessus
•Wapiti – http://wapiti.sourceforge.net/
•Nikto 2 — http://www.cirt.net/nikto2
•Burp Suite – http://portswigger.net/burp/
•$ Retina — http://www.eeye.com/Products/Retina/Web-Security-Scanner.aspx
•$ QualysGuard – http://www.qualys.com/products/qg_suite/was/
WAFs
•mod_security — http://www.modsecurity.org/
•IronBee – https://www.ironbee.com/
•$ Hyperguard – http://www.artofdefence.com/en/products/hyperguard.html
•$ F5 ASM – http://www.f5.com/products/big-ip/application-security-manager.html.html
•$ Imperva – http://www.imperva.com/index.html
•WebKnight – http://www.aqtronix.com/?PageID=99
SQLi
•sqlmap – http://sqlmap.sourceforge.net/
•sqlninja – http://sqlninja.sourceforge.net/
•Free & $ Havij — http://itsecteam.com/en/projects/project1.htm
General Tools
•nmap – http://nmap.org/
•netstat – Win: http://www.microsoft.com/resources/documentation/windows/xp/all/proddocs/en-us/netstat.mspx?mfr=true
•netstat – Other: http://linux.die.net/man/8/netstat
Frameworks
•JAAS – http://download.oracle.com/javase/6/docs/technotes/guides/security/jaas/tutorials/index.html (Watch out under load, tho)
•Shiro – http://shiro.apache.org/
•Spring Security – http://static.springsource.org/spring-security/site/
•Hibernate – http://www.hibernate.org/quick-start
Certifications
Training
•Security Innovation — http://l.rud.is/owasptraining
Practice
•Gruyere — http://gruyere.appspot.com/
•WackoPicko — https://github.com/adamdoupe/WackoPicko
Tuesday, June 28, 2011