The Wayback Machine - https://web.archive.org/web/20220407071600/https://github.com/topics/owasp
Skip to content
#

owasp

Here are 480 public repositories matching this topic...

Mobile-Security-Framework-MobSF

Mobile Security Framework (MobSF) is an automated, all-in-one mobile application (Android/iOS/Windows) pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis.

  • Updated Apr 7, 2022
  • JavaScript
marvUta
marvUta commented Mar 10, 2022

Describe the bug

When you change the Policy Name more than two Time(e.g. from upper Case to Lower-Case) then the item got duplicated, after removing one item the other cannot be modified anymore but removed.

Steps to reproduce the behavior

  1. Start Zap
  2. Open Scan Policy Manager (CTRL-P)/ Analyse -> Scan Policy Manager
  3. Add a new Policy
  4. Name it "scan"
  5. Press Ok
  6. Modify th
bug Component-UI good first issue
wstg
OneKongpc
OneKongpc commented Jan 31, 2022

What and where?
Please give the broken URL. Where is the link located?

Would you like to be assigned to this issue?
Check the box if you will submit a PR to fix this issue. Please read CONTRIBUTING.md.
-KONG [ ] Assign me, please!

bug help wanted good first issue
find-sec-bugs
h3xstream
h3xstream commented Oct 5, 2020

Description

BeanUtils is a library that is doing automatic mapping to Java object.
It can cause arm when the attack controls part of the list of properties being sets. BeanUtils does not blacklist properties like class, classloader or other objects that are likely to load arbitrary classes and possibly run code.

Code

import org.apache.commons.beanutils.BeanUtils;

public
dependency-track
stevespringett
stevespringett commented Nov 18, 2020

The current swagger definition is autogenerated. The automatically generated definitions rely on reflection and annotations to create the documentation. The reflection capabilities are poor at best and lead to missing API parameters. Annotations can help in some cases, but the only fix for Swagger is to create individual POJOs for every possible request. This will lead to unnecessary large number

birdynm
birdynm commented Mar 16, 2022

Description

With a Nextcloud installation and activated Nextcloud-exclusion-rules their is a false positive alarm of rule "920470" when a calendar entry is changed in the web-interface. (I think Rule "9003330" should prevent this but didn't work, at least for me)

I tried to change rule 9003330 to phase:1 (didn't solve the Problem)

Current workaround for me is to add "ctl:ruleRemoveByI

OWASP Mutillidae II is a free, open-source, deliberately vulnerable web application providing a target for web-security training. Mutillidae can be installed on Linux and Windows using LAMP, WAMP, and XAMMP. It is pre-installed on SamuraiWTF and OWASP BWA. The existing version can be updated on these platforms. With dozens of vulnerabilities and hints to help the user; this is an easy-to-use web hacking environment designed for labs, security enthusiast, classrooms, CTF, and vulnerability assessment tool targets. Mutillidae has been used in graduate security courses, corporate web sec training courses, and as an "assess the assessor" target for vulnerability assessment software. A containerized version of the application is available as a companion project.

  • Updated Mar 22, 2022
  • PHP
kingthorin
kingthorin commented Nov 9, 2020

I just finished dealing with auto-migrated issues for this article, it could definitely use some content updates:
https://github.com/OWASP/www-community/blob/master/pages/HttpOnly.md it still talks about old versions of IE and Opera.

This article includes an extensive table that needs re-working after the auto-migration as well (which I did not tackle).

Is Opera even relevant in 2020? Do

good first issue help wanted

Improve this page

Add a description, image, and links to the owasp topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the owasp topic, visit your repo's landing page and select "manage topics."

Learn more