OWASP represents an enormous step forward in the area of IT security, testing and data protection. This is a non-profit project and its intention is to inform groups, companies and individuals from all over the world about application security. Everyone is free to join OWASP online community and each user will have the access to all relevant information, articles, tools, researches and methodologies related to web application security.
The usage of OWASP provides us with many different tools. Some of them are suitable for automatic vulnerability scanning (commercial and open source tools), while others are being used for penetration testing (information gathering tools, authentication testing tools, data validation testing tools, web services testing tools, etc.). OWASP Top 10 publishes annual lists of the most common vulnerabilities, most dangerous threats, most critical security risks, and other, and they regularly report about these topics.