Thursday 17 April 2008

OWASP supports malware

Beyond what I'm doing to live, I'm a proud contributor of a nice open source websec scanner w3af. Guys recently applied for the OWASP Summer of Code 2008 to improve the GUI and they were selected! Well done!

There is a bizarre thing in it, though. OWASP still lists w3af as malware (see the corresponding section). The only reasonable explanation is that w3af is evil, but its GUI is not.