XXE Exposed Webinar Recording and Slides

In case someone is interested, I had the pleasure of giving a Webinar for eLearnSecurity on Tuesday this week: Webinar Title: "XXE Exposed" Summary: Brief coverage of Web Service Types, SQLi and XSS against Web Services to then talk about XXE and XEE attacks and mitigation.Heavily inspired on the "Practical Web Defense" (PWD) style of pwnage + …

OWASP GSoC: call for mentors/co-mentors plz RT!

OWASP received 88 proposals this year, but needs 50+ more mentors or some amazing students will be lost this year in the GSoC 2014, please don't let this happen, here is what you can do: Case 1) Mentoring for OWASP projects that are not OWTF If you are interested in mentoring/co-mentoring OWASP projects that are …

OWTF 0.30 "Summer Storm II" released! plz RT!

IMPORTANT NOTE: Some of the new features require the use of the "--dev" flag, please report any issues you find in our github page. Thanks! This is another a very significant release which includes the continued outstanding work of the following Google Summer of Code Projects: OWASP OWTF - INBOUND PROXY WITH MiTM & CACHING …

Contribute And Vote on the OWASP OWTF Report Prototype

A common complaint for OWTF was that the report was "ugly", now it's your turn to change that: This project has a community voting phase, so we need your help to choose the upcoming OWASP OWTF report default style, layout and skin: OWASP OWTF - Reporting by Assem Chelli (Dedicated Mentor: Gareth Heyes, Co-Mentors: Johanna …

OWTF 0.20 "Summer Storm I" released! plz RT!

This is a very significant release which includes the initial outstanding work of the following Google Summer of Code Projects: OWASP OWTF - INBOUND PROXY WITH MiTM & CACHING CAPABILITIES by Bharadwaj Machiraju (Dedicated Mentor: Krzysztof Kotowicz, Co-Mentors: Javier Marcos de Prado, Martin Johns, Abraham Aranguren) Pre-implementation research document<-- FEEDBACK Welcome! MiTM proxy benchmarks <-- …