New version of gauntlt released 0.1.3

5 views
Skip to first unread message

James Wickett

unread,
Jun 6, 2013, 11:28:50 AM6/6/13
to gau...@googlegroups.com
What changed in this version?

- Added the dirb attack adapter.  Dirb is a directory fuzzing tool written in C.  It comes with default fuzzing lists.  Directory fuzzing is one of the only ways to test REST services if you ar trying to find endpoints that the docs dont ship with.

How do you install the new version?

$ gem install gauntlt
$ gauntlt --version

Other news in gauntlt

- Over the last week I have spoken about security testing using gauntlt to several different groups.  You can see the punch out themed slides here > http://www.slideshare.net/wickett/be-mean-to-your-code-owasp-san-antonio ... and here ... > http://www.slideshare.net/wickett/brining-harmony-between-dev-and-ops-and-security-teams-using-gauntlt-at-isc2-austin-event

- After speaking at these events, I got a lot of positive feedback about people who want to join the project.

- Matt Tesauro also discussed with me an idea for doing Rugged Driven Development.  Start with an insecure web app (maybe Gruyere from google http://google-gruyere.appspot.com/part1) and then write some gauntlt attacks that fail.  Fix the app, pass the gauntlt attacks.  Very BDD meets rugged/security.  Sound cool?

Who is going to be the bay area over Velocity/DevOps Days (June 18th to 22nd)?  

--

@wickett

Reply all
Reply to author
Forward
0 new messages