26
Put your code through the Gauntlet

Gauntlet Kickoff at Austin OWASP Hackathon

Embed Size (px)

DESCRIPTION

Gauntlet is the new open source tool to put rugged principles in the dev cycle. The project is just getting kicked off and we are looking for contributors.

Citation preview

Page 1: Gauntlet Kickoff at Austin OWASP Hackathon

Put your code through the Gauntlet

Page 2: Gauntlet Kickoff at Austin OWASP Hackathon

gauntlet, n. an attack from all sides

Page 3: Gauntlet Kickoff at Austin OWASP Hackathon
Page 4: Gauntlet Kickoff at Austin OWASP Hackathon

Your web app You

Page 5: Gauntlet Kickoff at Austin OWASP Hackathon

Your web app

w3af

fuzzers

nmap

nessus

sqlmapmetasploit

You

dirbustercustom attacks

Page 6: Gauntlet Kickoff at Austin OWASP Hackathon

Gauntlet is

Page 7: Gauntlet Kickoff at Austin OWASP Hackathon

an always-attacking environment for

developers

Page 8: Gauntlet Kickoff at Austin OWASP Hackathon

with attacks written in easy-to-read language

Page 9: Gauntlet Kickoff at Austin OWASP Hackathon

accessible to everyone involved in dev, ops,

security, ...

Page 10: Gauntlet Kickoff at Austin OWASP Hackathon

Gauntlet includes

Page 11: Gauntlet Kickoff at Austin OWASP Hackathon

Why Gauntlet?

Security domain knowledge is generally a mystery to dev teams

Page 12: Gauntlet Kickoff at Austin OWASP Hackathon

Gauntlet allows dev and ops and security to communicate and collaborate

Page 13: Gauntlet Kickoff at Austin OWASP Hackathon

Gauntlet joins:

The Philosophy of Rugged Software

&Principles of Behavior Driven Development

Page 14: Gauntlet Kickoff at Austin OWASP Hackathon

You are now commissioned as a

contributor to Gauntlet

Page 15: Gauntlet Kickoff at Austin OWASP Hackathon

Here is your badge

Page 16: Gauntlet Kickoff at Austin OWASP Hackathon

RUGGED

source: Jessica Allen, http://drbl.in/bgwy

Page 17: Gauntlet Kickoff at Austin OWASP Hackathon

github.com/wickett/gauntlet

Page 18: Gauntlet Kickoff at Austin OWASP Hackathon

Ideas to build

Page 19: Gauntlet Kickoff at Austin OWASP Hackathon

nmap to check ports

Page 20: Gauntlet Kickoff at Austin OWASP Hackathon

crawl site and search for passwords in text

(assume fuzzing)

Page 21: Gauntlet Kickoff at Austin OWASP Hackathon

badness with LOIC, slowloris, wget, curl

Page 22: Gauntlet Kickoff at Austin OWASP Hackathon

Include recon, scanning, fuzzing, injecting, load

Page 23: Gauntlet Kickoff at Austin OWASP Hackathon

multi-vector attacks:timing + load, fail

open, ...

Page 24: Gauntlet Kickoff at Austin OWASP Hackathon

these are just ideas, use your imagination

Page 25: Gauntlet Kickoff at Austin OWASP Hackathon

lets build some tests!

Page 26: Gauntlet Kickoff at Austin OWASP Hackathon

github.com/wickett/gauntlet