Roadmap

From OWASP Live CD 2008

Jump to: navigation, search

Here's a few thoughts on where this thing is going in the future...

First the date specific items:

  • Complete the Summer of Code and create a SoC release
    • Complete by September 15, 2008 - Done
  • Complete a new release for OWASP EU Summit 2008
    • Complete by November 3, 2008 (or earlier as I'll be flying to Portugal to attend) - Done (but a bit late)
  • Complete "Project Tindy" completed (details forthcoming)
    • December 31, 2008
  • Close all bugs/feature requests listed for the all releases in next major release here
    • Hmmm. Not sure right now on when that will be. May be the January/February time frame.


Other non-date specific goals/ideas/items I'll be working on:

  • Continue cranking out modules
    • Complete anything on the short list
    • Some priority will given to new and interesting tools that get announced
      (like many from the Black Hat/Defcon conference this year - or perhaps from OWASP NYC AppSec 2008 Conference
  • Write up instructions on how to do a persistent install on a USB drive
  • Update the tools and menu structure to more closely match the OWASP Testing Guide v3
    • New tools will be first uploaded to the Google Code Site
    • New modules can be added to a running system as described here
  • GPG sign and hash the modules
    • Allows for users to verify that the modules are from the project and not corrupted during download
    • The Google code site already provides hashes for uploaded files e.x. wsfuzzer module
  • Write a program to auto-­update the CD to the latest version of the tools
    • Ability to update modules + Google code repository + a bit of coding = always updated Live CD
  • Start quarterly releases
    • Even with the auto­-update deal, updating gets old
    • One edition per season, timing TBD
  • Automatic download-able update + tool categories = Tool profiles
    • Can expand the tools above what will fit on the CD
    • Allows for profiles to be installed on the fly / on demand
    • Potential Profiles
      • Whitebox testing
      • Blackbox testing
      • Static Analysis
      • Target Specific (Java, .Net, ...)


I think that's enough for now.

Personal tools