OWASP JSEC CVE DETAILS

8
OWASP JSEC CVE DETAILS Dibyendu Sikdar (@dibsyhex) OSWAP Kolkata Chapter , Sillycon

description

OWASP JSEC CVE DETAILS. Dibyendu Sikdar (@ dibsyhex ) OSWAP Kolkata Chapter , Sillycon. >> whoami. Dibyendu Sikdar OpenSource Developer & Security Researcher Project Leader of OWASP JSEC DETAILS Acknowledged and listed in various Hall of Fame - AT&T , Microsoft, Oracle ,Adobe , etc. - PowerPoint PPT Presentation

Transcript of OWASP JSEC CVE DETAILS

Page 1: OWASP JSEC CVE DETAILS

OWASP JSEC CVE DETAILS

Dibyendu Sikdar (@dibsyhex)OSWAP Kolkata Chapter , Sillycon

Page 2: OWASP JSEC CVE DETAILS

>>whoami

• Dibyendu Sikdar • OpenSource Developer & Security Researcher• Project Leader of OWASP JSEC DETAILS• Acknowledged and listed in various Hall of

Fame - AT&T , Microsoft, Oracle ,Adobe ,etc

Page 3: OWASP JSEC CVE DETAILS

What is CVE ?

• CVE or The Common Vulnerabilities and Exposures system provides a reference method for publicly known information security vulnerabilities and exposures

Page 4: OWASP JSEC CVE DETAILS

Example

•  CVE-2014-5250• Details - Unspecified vulnerability in the AJAX

autocompletion callback in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to access data via unspecified vectors.

Page 5: OWASP JSEC CVE DETAILS

So what makes this tool cool?

• This desktop application can be used to fetch the latest CVEs directly from the CVE details online service cvedetails.com.

• Search CVEs• Search Exploits• Search POCs• Search Vulnerabilities

Page 6: OWASP JSEC CVE DETAILS

Screenshot

Page 7: OWASP JSEC CVE DETAILS

Project Timeline• 13 June 2014 - Released the project as open

source• 17 August 2014 - Requested for OWASP

project approval• 20 August 2014 - Project Proposal Accepted• 21 August 2014 - To be released under

OWASP Kolkata Chapter ,SillyCon• 22 September 2014 - V2.0 Released

Page 8: OWASP JSEC CVE DETAILS

Future Plans

• Android Version• Improved UI