XXE Exposed Webinar Recording and Slides

In case someone is interested, I had the pleasure of giving a Webinar for eLearnSecurity on Tuesday this week: Webinar Title: “XXE Exposed” Summary: Brief coverage of Web Service Types, SQLi and XSS against Web Services to then talk about XXE and XEE attacks and mitigation.Heavily inspired on the “Practical Web Defense” (PWD) style of pwnage + …

OWASP GSoC: call for mentors/co-mentors plz RT!

OWASP received 88 proposals this year, but needs 50+ more mentors or some amazing students will be lost this year in the GSoC 2014, please don’t let this happen, here is what you can do: Case 1) Mentoring for OWASP projects that are not OWTF If you are interested in mentoring/co-mentoring OWASP projects that are …

AppSec EU: OWASP OWTF Summer Storm slides, demos and Plug-n-Hack support!

UPDATE 04/09/2013: Added link to AppSec EU video UPDATE 26/08/2013: Added Plug-n-Hack support link. OWASP AppSec EU 2013 and HackPra AllStars were both a blast this week: I would like to use this opportunity to let you know that: OWASP OWTF is always actively looking for contributors, bug reports / ideas. The slides for the …

OWTF 0.30 “Summer Storm II” released! plz RT!

IMPORTANT NOTE: Some of the new features require the use of the “–dev” flag, please report any issues you find in our github page. Thanks! This is another a very significant release which includes the continued outstanding work of the following Google Summer of Code Projects: OWASP OWTF – INBOUND PROXY WITH MiTM & CACHING …