+ All Categories
Home > Technology > Gauntlet Kickoff at Austin OWASP Hackathon

Gauntlet Kickoff at Austin OWASP Hackathon

Date post: 13-Jan-2015
Category:
Upload: james-wickett
View: 1,356 times
Download: 0 times
Share this document with a friend
Description:
Gauntlet is the new open source tool to put rugged principles in the dev cycle. The project is just getting kicked off and we are looking for contributors.
Popular Tags:
26
Put your code through the Gauntlet
Transcript
Page 1: Gauntlet Kickoff at Austin OWASP Hackathon

Put your code through the Gauntlet

Page 2: Gauntlet Kickoff at Austin OWASP Hackathon

gauntlet, n. an attack from all sides

Page 3: Gauntlet Kickoff at Austin OWASP Hackathon
Page 4: Gauntlet Kickoff at Austin OWASP Hackathon

Your web app You

Page 5: Gauntlet Kickoff at Austin OWASP Hackathon

Your web app

w3af

fuzzers

nmap

nessus

sqlmapmetasploit

You

dirbustercustom attacks

Page 6: Gauntlet Kickoff at Austin OWASP Hackathon

Gauntlet is

Page 7: Gauntlet Kickoff at Austin OWASP Hackathon

an always-attacking environment for

developers

Page 8: Gauntlet Kickoff at Austin OWASP Hackathon

with attacks written in easy-to-read language

Page 9: Gauntlet Kickoff at Austin OWASP Hackathon

accessible to everyone involved in dev, ops,

security, ...

Page 10: Gauntlet Kickoff at Austin OWASP Hackathon

Gauntlet includes

Page 11: Gauntlet Kickoff at Austin OWASP Hackathon

Why Gauntlet?

Security domain knowledge is generally a mystery to dev teams

Page 12: Gauntlet Kickoff at Austin OWASP Hackathon

Gauntlet allows dev and ops and security to communicate and collaborate

Page 13: Gauntlet Kickoff at Austin OWASP Hackathon

Gauntlet joins:

The Philosophy of Rugged Software

&Principles of Behavior Driven Development

Page 14: Gauntlet Kickoff at Austin OWASP Hackathon

You are now commissioned as a

contributor to Gauntlet

Page 15: Gauntlet Kickoff at Austin OWASP Hackathon

Here is your badge

Page 16: Gauntlet Kickoff at Austin OWASP Hackathon

RUGGED

source: Jessica Allen, http://drbl.in/bgwy

Page 17: Gauntlet Kickoff at Austin OWASP Hackathon

github.com/wickett/gauntlet

Page 18: Gauntlet Kickoff at Austin OWASP Hackathon

Ideas to build

Page 19: Gauntlet Kickoff at Austin OWASP Hackathon

nmap to check ports

Page 20: Gauntlet Kickoff at Austin OWASP Hackathon

crawl site and search for passwords in text

(assume fuzzing)

Page 21: Gauntlet Kickoff at Austin OWASP Hackathon

badness with LOIC, slowloris, wget, curl

Page 22: Gauntlet Kickoff at Austin OWASP Hackathon

Include recon, scanning, fuzzing, injecting, load

Page 23: Gauntlet Kickoff at Austin OWASP Hackathon

multi-vector attacks:timing + load, fail

open, ...

Page 24: Gauntlet Kickoff at Austin OWASP Hackathon

these are just ideas, use your imagination

Page 25: Gauntlet Kickoff at Austin OWASP Hackathon

lets build some tests!

Page 26: Gauntlet Kickoff at Austin OWASP Hackathon

github.com/wickett/gauntlet


Recommended