Roadmap
From OWASP Live CD 2008
Here's a few thoughts on where this thing is going in the future...
First the date specific items:
-
Complete the Summer of Code and create a SoC release- Complete by September 15, 2008 - Done
-
Complete a new release for OWASP EU Summit 2008- Complete by November 3, 2008 (or earlier as I'll be flying to Portugal to attend) - Done (but a bit late)
- Complete "Project Tindy" completed (details forthcoming)
- December 31, 2008
- Close all bugs/feature requests listed for the all releases in next major release here
- Hmmm. Not sure right now on when that will be. May be the January/February time frame.
Other non-date specific goals/ideas/items I'll be working on:
- Continue cranking out modules
- Complete anything on the short list
- Some priority will given to new and interesting tools that get announced
(like many from the Black Hat/Defcon conference this year - or perhaps from OWASP NYC AppSec 2008 Conference
- Write up instructions on how to do a persistent install on a USB drive
- Update the tools and menu structure to more closely match the OWASP Testing Guide v3
- New tools will be first uploaded to the Google Code Site
- New modules can be added to a running system as described here
- GPG sign and hash the modules
- Allows for users to verify that the modules are from the project and not corrupted during download
- The Google code site already provides hashes for uploaded files e.x. wsfuzzer module
- Write a program to auto-update the CD to the latest version of the tools
- Ability to update modules + Google code repository + a bit of coding = always updated Live CD
- Start quarterly releases
- Even with the auto-update deal, updating gets old
- One edition per season, timing TBD
- Automatic download-able update + tool categories = Tool profiles
- Can expand the tools above what will fit on the CD
- Allows for profiles to be installed on the fly / on demand
- Potential Profiles
- Whitebox testing
- Blackbox testing
- Static Analysis
- Target Specific (Java, .Net, ...)
I think that's enough for now.

