owasp mantra - an introduction

22
The OWASP Foundation http://www.owasp.org OWASP Mantra - An Introduction Prepared By -Team Mantra- [email protected]

Upload: tasha

Post on 22-Feb-2016

64 views

Category:

Documents


0 download

DESCRIPTION

OWASP Mantra - An Introduction. Prepared By -Team Mantra- [email protected]. The Browser Evolution. Netscape Navigator 1994. Microsoft IE 1995. Opera 1996. Safari 2003. Mozilla Firefox 2004. Google Chrome 2008. Why not a hack3r’s browser ?. Mantra 2010. What ?. - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: OWASP Mantra - An Introduction

The OWASP Foundationhttp://www.owasp.org

OWASP Mantra - An Introduction

Prepared By-Team Mantra-

[email protected]

Page 2: OWASP Mantra - An Introduction

2

The Browser Evolution

Page 3: OWASP Mantra - An Introduction

Netscape Navigator1994

Page 4: OWASP Mantra - An Introduction

Microsoft IE1995

Page 5: OWASP Mantra - An Introduction

Opera1996

Page 6: OWASP Mantra - An Introduction

6

Safari2003

Page 7: OWASP Mantra - An Introduction

Mozilla Firefox2004

Page 8: OWASP Mantra - An Introduction

Google Chrome2008

Page 9: OWASP Mantra - An Introduction

9

Why not a hack3r’s browser ?

Mantra2010

Page 10: OWASP Mantra - An Introduction

What ?What is Mantra?What Mantra is NOT?What is the use?

Page 11: OWASP Mantra - An Introduction

11

What is Mantra ?

Collection of Hacking Tools/ Add-onsA security framework that can aid in exploit development

Page 12: OWASP Mantra - An Introduction

12

Browser Based – Its built on top of Browser

But “not just a browser”

What is Mantra ?

Cross platform & Flexible

Page 13: OWASP Mantra - An Introduction

13

Free as in “Free Beer” and “Free Speech”

Open Source

Page 14: OWASP Mantra - An Introduction

What is the use ?

Reconnaissance

Scanning & Enumeration

Gaining Access

Escalation of privileges

Maintaining access & Covering tracks

Five phases of attacks

Page 15: OWASP Mantra - An Introduction

page 15

What Mantra is NOT?

Not an one click Pwnage tool

Not mature enough to suit a particular need

Don’t uninstall your Metasploit and W3af ;)

Not a replacement for your normal browser

Not completely integrated

Page 16: OWASP Mantra - An Introduction

16

Why Mantra ? Plenty of extensions available officially and

unofficially (Firesheep for instance ) Analyzing each and every add-on is a tedious

task (Let us do it for you ) Many extensions going unnoticed Security researchers should know the power

of browser platform

Page 17: OWASP Mantra - An Introduction

17

Mantra- Form the past to the Present

Started in October 2010 Released first public beta 0.52 at ClubHack

Conference in December 2010 Became an OWASP project in March 2011 Integrated With other active projects (FireCAT,

Open Pen Test Bookmarks etc ) Released second public beta 0.61 c0de

named “Gandiva” on 15th June 2011

Page 18: OWASP Mantra - An Introduction

18

Mantra- Future ?

Framework – A fine tuned framework with collection of tools and exploits (Beyond a browser! Beyond a toolkit!)

Add-ons – Let’s develop add-ons for Mantra (Yes, You can help us!)

Page 19: OWASP Mantra - An Introduction

19

The Team

Abhi M Balakrishnan – Project LeaderGokul C Gopinath – Team LeaderYashartha Chaturvedi – Project ManagerGopu C Gopinath – Artworks

Page 20: OWASP Mantra - An Introduction

20

How Can I Contribute ? Develop – Write add-ons/tools for Mantra

Pre/Post release testing – Report bugs and help us to fix it

Idea – Input your ideas to make Mantra better

Code | Modify --> Extensions | Framework

Page 22: OWASP Mantra - An Introduction

22

Thank You!-Team Mantra-