The OWASP Foundation OWASP Mantra - An Introduction Prepared By -Team Mantra-...

22
The OWASP Foundation http://www.owasp.org OWASP Mantra - An Introduction Prepared By -Team Mantra- [email protected]

Transcript of The OWASP Foundation OWASP Mantra - An Introduction Prepared By -Team Mantra-...

Page 1: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

The OWASP Foundationhttp://www.owasp.org

OWASP Mantra - An Introduction

Prepared By-Team Mantra-

[email protected]

Page 2: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

2

The Browser Evolution

Page 3: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

Netscape Navigator1994

Page 4: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

Microsoft IE1995

Page 5: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

Opera1996

Page 6: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

6

Safari2003

Page 7: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

Mozilla Firefox2004

Page 8: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

Google Chrome2008

Page 9: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

9

Why not a hack3r’s browser ?

Mantra2010

Page 10: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

What ?What is Mantra?

What Mantra is NOT?

What is the use?

Page 11: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

11

What is Mantra ?

Collection of Hacking Tools/ Add-ons

A security framework that can aid in exploit development

Page 12: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

12

Browser Based – Its built on top of Browser

But “not just a browser”

What is Mantra ?

Cross platform & Flexible

Page 13: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

13

Free as in “Free Beer” and “Free Speech”

Open Source

Page 14: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

What is the use ?

Reconnaissance

Scanning & Enumeration

Gaining Access

Escalation of privileges

Maintaining access & Covering tracks

Five phases of attacks

Page 15: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

page 15

What Mantra is NOT?

Not an one click Pwnage tool

Not mature enough to suit a particular need

Don’t uninstall your Metasploit and W3af ;)

Not a replacement for your normal browser

Not completely integrated

Page 16: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

16

Why Mantra ?

Plenty of extensions available officially and unofficially (Firesheep for instance )

Analyzing each and every add-on is a tedious task (Let us do it for you )

Many extensions going unnoticed

Security researchers should know the power of browser platform

Page 17: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

17

Mantra- Form the past to the Present

Started in October 2010

Released first public beta 0.52 at ClubHack Conference in December 2010

Became an OWASP project in March 2011

Integrated With other active projects (FireCAT, Open Pen Test Bookmarks etc )

Released second public beta 0.61 c0de named “Gandiva” on 15th June 2011

Page 18: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

18

Mantra- Future ?

Framework – A fine tuned framework with collection of tools and exploits (Beyond a browser! Beyond a toolkit!)

Add-ons – Let’s develop add-ons for Mantra (Yes, You can help us!)

Page 19: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

19

The Team

Abhi M Balakrishnan – Project Leader

Gokul C Gopinath – Team Leader

Yashartha Chaturvedi – Project

Manager

Gopu C Gopinath – Artworks

Page 20: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

20

How Can I Contribute ?

Develop – Write add-ons/tools for Mantra

Pre/Post release testing – Report bugs and help us to fix it

Idea – Input your ideas to make Mantra better

Code | Modify --> Extensions | Framework

Page 21: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

21

Links

Website: http://www.getmantra.com/Forums: http://www.getmantra.com/forums/Blog: http://getmantra.tumblr.com/

Mantra on Facebook: https://www.facebook.com/getmantraMantra on Twitter :http://twitter.com/getmantra

Download Location:http://www.getmantra.com/download/index.html

Other Links :http://en.wikipedia.org/wiki/OWASP_Mantra_Security_Frameworkhttps://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework

Page 22: The OWASP Foundation  OWASP Mantra - An Introduction Prepared By -Team Mantra- contact@getmantra.com.

22

Thank You!-Team Mantra-