<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-3544150258492345305</id><updated>2012-01-29T14:46:49.365-08:00</updated><category term='owasp'/><category term='appsec europe'/><category term='videos'/><category term='orizon'/><category term='xss'/><category term='Joke'/><category term='Security Spending'/><category term='owasp election'/><category term='csp'/><category term='owasp top 10'/><category term='Funny'/><title type='text'>Open Web Application Security Project</title><subtitle type='html'>The Open Web Application Security Project (OWASP) is a 501c3 not-for-profit worldwide charitable organization focused on improving the security of application software. Our mission is to make application security visible, so that people and organizations can make informed decisions about true application security risks. Everyone is free to participate in OWASP and all of our materials are available under a free and open software license.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default?start-index=101&amp;max-results=100'/><author><name>Justin Clarke</name><uri>http://www.blogger.com/profile/03799833757658152012</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>154</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-2964984748143481403</id><published>2012-01-06T12:51:00.001-08:00</published><updated>2012-01-06T12:52:18.216-08:00</updated><title type='text'>AppSec DC 2012 CFP EXTENDED!</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;pre style="font-family: inherit;" wrap=""&gt;Many of you have written to us asking about the requirement for a paper in our CFP hosted on EasyChair.&amp;nbsp; Due to an unforeseen change in the way EasyChair works, you are no longer able to configure a submission to require only an abstract as we thought we had done, and done in the past.&amp;nbsp; To be clear, we are ***NOT*** requiring papers with our CFP submissions.  As we have already started the CFP and can not move the platform we ask that anyone who does not have a paper simply submit their abstract as a .txt file to satisfy the systems requirement to upload a paper.&lt;br /&gt;&lt;br /&gt;We apologize for this inconvenience and the confusion it has caused and as a result of the confusion, we are extending the AppSec DC CFP deadline to Feburary 17th 2012 at 11:59 EST to allow all to submit their topics.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;The AppSec DC Program Committee&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-2964984748143481403?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/2964984748143481403/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2012/01/appsec-dc-2012-cfp-extended.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2964984748143481403'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2964984748143481403'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2012/01/appsec-dc-2012-cfp-extended.html' title='AppSec DC 2012 CFP EXTENDED!'/><author><name>Jim Manico</name><uri>http://www.blogger.com/profile/11117151394525124128</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-3699934001821209982</id><published>2012-01-05T08:50:00.001-08:00</published><updated>2012-01-05T08:50:46.236-08:00</updated><title type='text'>2012 The Year of Software Security</title><content type='html'>&lt;p class="p1"&gt;&lt;b&gt;&lt;i&gt;Committee Chairs,&lt;/i&gt;&lt;/b&gt;&lt;/p&gt; &lt;p class="p1"&gt;Now that budgets have been passed, please take the time this week to review and EDIT the page to update your respective committee members:  &lt;span class="s1"&gt;&lt;a href="https://www.owasp.org/index.php/Global_Committee_Pages"&gt;https://www.owasp.org/index.php/Global_Committee_Pages&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="p1"&gt;As we kick off 2012 &lt;span class="s2"&gt;everyone has resolutions&lt;/span&gt; now is a good time to reconfirm active individual participation and to allow those that wish to pass the torch or transfer to other committees to do so. &lt;/p&gt; &lt;p class="p1"&gt;&lt;b&gt;OWASP Project/Chapter leaders:&lt;/b&gt;&lt;/p&gt; &lt;p class="p1"&gt;To join a global committee, the process is VERY EASY simply self-nominate, then ask your peers in your region (example Latin America, North America, APAC, etc..)  to support your efforts as a regional voice in the continued evolution of OWASP Foundation:  &lt;span class="s1"&gt;&lt;a href="https://www.owasp.org/index.php/How_to_Join_a_Committee"&gt;https://www.owasp.org/index.php/How_to_Join_a_Committee&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="p1"&gt;The committees purpose should be looked at as focused task forces establishing a framework with for all community members to utilize focused on global missions around things such as:&lt;/p&gt; &lt;p class="p1"&gt;- Quality Offerings (Projects/Education)&lt;/p&gt; &lt;p class="p1"&gt;- Marketing / Public Relations OWASP (Connections)&lt;/p&gt; &lt;p class="p2"&gt;- Gathering Industry Requirements and Collaboration (Industry)&lt;/p&gt; &lt;p class="p1"&gt;- Continued Regional Growth (Chapters)&lt;/p&gt; &lt;p class="p1"&gt;- Global Events and Training (Conferences)&lt;/p&gt; &lt;p class="p2"&gt;- Setting Value and Governance (Membership)&lt;/p&gt; &lt;p class="p2"&gt;So we need people from different parts of the world to bring perspectives and contribute the most precious resource professional time.&lt;/p&gt; &lt;p class="p2"&gt;2012 is the year of Software Security -- there is no doubt from headline news to start-up companies around the world that software and its security is a important part of the global fabric.&lt;/p&gt;&lt;p class="p2"&gt;Join Us!&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-3699934001821209982?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/3699934001821209982/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2012/01/2012-year-of-software-security.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3699934001821209982'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3699934001821209982'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2012/01/2012-year-of-software-security.html' title='2012 The Year of Software Security'/><author><name>Tom Brennan</name><uri>http://www.blogger.com/profile/07303005472675953158</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-6507405637785017751</id><published>2012-01-04T18:40:00.000-08:00</published><updated>2012-01-04T18:41:49.874-08:00</updated><title type='text'>2012 Kick Off - Call to Action</title><content type='html'>&lt;p class="p1"&gt;Calling Chapter Leaders in key markets such as: Atlanta,  Austin,  Boston,  Chicago,  Denver,  Los Angeles,  New York,  Philadelphia,  Portland,  San Francisco,  Seattle,  Washington DC,  London,  Toronto,  and Vancouver. Post your next chapter meeting at Gary's Guide and you might find some new faces that understand software and want to learn about security:  &lt;/p&gt; &lt;p class="p2"&gt;http://www.garysguide.com/cities &lt;/p&gt; &lt;p class="p2"&gt;Project/chapter leaders worldwide, perform "outside the echo chamber" outreach to other groups in 2012. Offer up your favorite OWASP Project presentation to help evangelize the OWASP mission, community.  &lt;/p&gt; &lt;p class="p1"&gt;Start here:   http://www.meetup.com/find  (keyword: mobile, programming, .net, java, internet, computer, developer,  &lt;insert yours=""&gt; find local groups)&lt;/insert&gt;&lt;/p&gt; &lt;p class="p2"&gt;Got something new to share??  Be sure to submit the CFP for the OWASP Global AppSec Conferences.  2012 has a lot of exciting things happening that rely on software, let's not forget the core of "fight club" -- have fun sharing technical knowledge, open-source code and the social collaboration with people as together we build a vibrant global professional association that has exploded all over the world:&lt;/p&gt; &lt;p class="p2"&gt;https://www.owasp.org/index.php/OWASP_Chapter#Local_Chapters_by_Geographic_Region&lt;/p&gt; &lt;p class="p1"&gt;If you have other tips or suggestions please share what you will do to advance the OWASP mission.&lt;/p&gt; &lt;p class="p1"&gt;Semper Fi,&lt;/p&gt; &lt;p class="p1"&gt;Tom Brennan&lt;/p&gt; &lt;p class="p1"&gt;OWASP Foundation&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-6507405637785017751?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/6507405637785017751/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2012/01/2012-kick-off-call-to-action.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6507405637785017751'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6507405637785017751'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2012/01/2012-kick-off-call-to-action.html' title='2012 Kick Off - Call to Action'/><author><name>Tom Brennan</name><uri>http://www.blogger.com/profile/07303005472675953158</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-8305924370194756079</id><published>2011-12-12T06:55:00.000-08:00</published><updated>2011-12-12T07:55:43.051-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='owasp'/><category scheme='http://www.blogger.com/atom/ns#' term='Joke'/><category scheme='http://www.blogger.com/atom/ns#' term='Funny'/><title type='text'>The 12 Days of Christmas</title><content type='html'>&lt;p class="p1"&gt;Ok kids, gather around and sing with me;&lt;/p&gt;&lt;p class="p1"&gt;On the 1st day of Christmas a hacker faxed to me poof via fax of  SQLi in my website database using SELECT * FROM members WHERE username = 'admin'--' AND password = 'password'&lt;br /&gt;&lt;/p&gt; &lt;p class="p2"&gt;On the 2nd of Christmas the hackers gave to me a &lt;script&gt;a=/XSS/ alert(a.source)&lt;/script&gt;&amp;lt;  IMG SRC="jav    ascript:alert('XSS');" &amp;gt; #OWASP and a link to cheat other sheets to at: &lt;a href="https://www.owasp.org/index.php/Cheat_Sheets"&gt;https://www.owasp.org/index.php/Cheat_Sheets&lt;/a&gt;&lt;/p&gt; &lt;p class="p2"&gt;On the 3rd of Christmas the hackers gave to me Direct Object Reference on a critical system &lt;a href="http://yourwebsite.com/secret/adminconsole:8050"&gt;http://yourwebsite.com/secret/adminconsole:8050&lt;/a&gt;&lt;/p&gt; &lt;p class="p1"&gt;On the 4th day of Christmas the hackers gave to me.... "a .PDF file and he said test your sh$t!" this is to easy...&lt;a href="http://www.owasp.org/images/5/56/OWASP_Testing_Guide_v3.pdf"&gt;  http://www.owasp.org/images/5/56/OWASP_Testing_Guide_v3.pdf&lt;/a&gt;&lt;/p&gt; &lt;p class="p1"&gt;On the 5th day of Christmas the hackers guessed my lame ass Wifi WEP password and changed my SSID to "Hacked"and left it as a Open AP&lt;/p&gt; &lt;p class="p1"&gt;On the 6th day of Christmas the hackers came back after it was updated and guessed my lame ass WPA password after being upgraded from WEP on day 5 and changed it to "Hacked Again" and made it Open AP&lt;/p&gt; &lt;p class="p1"&gt;On the 7th day of Christmas a hacker picked my physical lock using a 9999 cut bump key on door #1, a shim on door #2 and and placed a  "boom" sign inside the safe to prove a point about my lame physical security &lt;/p&gt; &lt;p class="p1"&gt;On the 8th day of Christmas the hackers gave to me a bag of dumpster diving treasure to point out lack of shredding that included (bills fro trusted vendors with account info, credit card carbons, internal printed emails and more...&lt;br /&gt;&lt;/p&gt; &lt;p class="p2"&gt;On the 9th day of Christmas the hackers gave to me, an email aimed at my wife concerning a refund of a holiday purchase with targeted malware using a custom packer that bypassed my installed and updated corporate AV investment.. then after getting a remote shell he popped my work laptop that was also connected to my personal LAN, exported the cert on the VPN client installed a keystroke logger on the  computer that I use for business to capture the password.... damn&lt;/p&gt; &lt;p class="p1"&gt;On the 10th day of Christmas the hackers gave to me code snips of  critical system code on the new  project that he picked up from PasteBin thanks -- 3rd party&lt;/p&gt;&lt;p class="p1"&gt;On the 11th day of Christmas the hackers knocked down my commerce website during the busy season with a Denial of Service  &lt;a href="https://www.owasp.org/index.php/OWASP_HTTP_Post_Tool"&gt;https://www.owasp.org/index.php/OWASP_HTTP_Post_Tool&lt;/a&gt; -- and suggested I look at the OWASP CRS Mod_Security project &lt;a href="https://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project"&gt;https://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project&lt;/a&gt;&lt;/p&gt;&lt;p class="p1"&gt;On the 12th day of Christmas the hackers emailed me a complied P0C 0day on the shiny new public facing appliance we installed just to say "whaaat'ssss up"&lt;br /&gt;&lt;/p&gt;&lt;p class="p1"&gt;After getting my A$$ handed to me in 201x.....   I started to read the OWASP Foundation website @ &lt;a href="http://www.owasp.org/"&gt;http://www.owasp.org&lt;/a&gt; and found things like a new &lt;span style="font-weight: bold;"&gt;Enterprise Security API&lt;/span&gt; (EASPI),&lt;span style="font-weight: bold;"&gt; Free &lt;a href="https://www.owasp.org/index.php/Category:OWASP_Video"&gt;Videos&lt;/a&gt;&lt;/span&gt;, &lt;span style="font-weight: bold;"&gt;Guidance on&lt;a href="https://www.owasp.org/index.php/OWASP_Mobile_Security_Project"&gt; Mobile Security&lt;/a&gt;&lt;/span&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Mobile_Security_Project"&gt;,&lt;/a&gt; &lt;a style="font-weight: bold;" href="https://www.owasp.org/index.php/OWASP_Jobs"&gt;Jobs Postings from around the world&lt;/a&gt;&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;and over 140 other projects: &lt;a href="https://www.owasp.org/index.php/OWASP_Jobs"&gt; https://www.owasp.org/index.php/Category:OWASP_Project&lt;/a&gt; that helped, planned to attend both Global and Local &lt;a href="https://www.owasp.org/index.php/Category:OWASP_AppSec_Conference"&gt;AppSec events&lt;/a&gt;  value and I became a &lt;a href="https://www.owasp.org/index.php/Membership"&gt;member&lt;/a&gt;&lt;/p&gt;&lt;p class="p1"&gt;&lt;br /&gt;&lt;span style="font-weight: bold; font-style: italic;"&gt;Happy Holidays from the OWASP Foundation&lt;/span&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="p1"&gt;Suggestion: post your comments below of alternative days of Christmas then you can copy and paste to make your own for a company newsletter for a internal awareness campaign)&lt;br /&gt;&lt;/p&gt;&lt;p class="p1"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="p1"&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-8305924370194756079?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/8305924370194756079/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/12/12-days-of-christmas.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8305924370194756079'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8305924370194756079'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/12/12-days-of-christmas.html' title='The 12 Days of Christmas'/><author><name>Tom Brennan</name><uri>http://www.blogger.com/profile/07303005472675953158</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-3949863105335303157</id><published>2011-12-01T10:47:00.001-08:00</published><updated>2011-12-01T10:55:39.607-08:00</updated><title type='text'>November 2011 OWASP Newsletter</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;The November, 2011 issue of the OWASP newsletter is &lt;a href="https://www.owasp.org/images/7/78/50552_OWASP_Newsletter-Nov2011.pdf"&gt;now available&lt;/a&gt;.&amp;nbsp; Many thanks to Deepak Subramanian for his efforts putting this together.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="https://www.owasp.org/images/7/78/50552_OWASP_Newsletter-Nov2011.pdf"&gt;&lt;img border="0" height="271" src="http://2.bp.blogspot.com/-VtZ7OHpTYfg/TtfMxgCBlwI/AAAAAAAAB2Y/UYm17Rp1_38/s320/OWASP-Nov-2011-Newsletter.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;Table of Contents&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;Notes from the Editor – Deepak Subramanian&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Notes on Internal Projects&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt;OWASP Communities – Michael Coates&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Protecting against XSS – Gareth Heyes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt;OWASP Podcast – hosted by Jim Manico&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt;OWASP Zed Attach Proxy (ZAP) – Simon Bennetts&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Global Board of Directors Announced&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Global Committees&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Upcoming Events&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt; OWASP Organizational Sponsors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt;The OWASP Foundation&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt;OWASP Membership&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/li&gt;&lt;li&gt;Newsletter Advertising&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: small;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family: Arial,Helvetica,sans-serif; font-size: small;"&gt;OWASP is a volunteer driven organization that provides free and open resources to advance the state of application security and make application security risks visible.&amp;nbsp; Please consider helping &lt;a href="https://www.owasp.org/index.php/Membership"&gt;support&lt;/a&gt; our mission if these resources are useful to you or your organization.&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-3949863105335303157?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/3949863105335303157/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/12/november-2011-owasp-newsletter.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3949863105335303157'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3949863105335303157'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/12/november-2011-owasp-newsletter.html' title='November 2011 OWASP Newsletter'/><author><name>Michael Coates</name><uri>http://www.blogger.com/profile/01776444965999374544</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_MiAJXkPG1IM/StSyGcceaDI/AAAAAAAABR4/ZNH2XgLAgM8/S220/MichaelCoates.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/-VtZ7OHpTYfg/TtfMxgCBlwI/AAAAAAAAB2Y/UYm17Rp1_38/s72-c/OWASP-Nov-2011-Newsletter.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-8987596835425684262</id><published>2011-11-06T22:11:00.000-08:00</published><updated>2011-11-06T22:21:42.768-08:00</updated><title type='text'>Lots of Great Things Happening At OWASP</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: inherit;"&gt;&lt;style&gt;&lt;!-- /* Font Definitions */@font-face {font-family:"ＭＳ 明朝"; mso-font-charset:78; mso-generic-font-family:auto; mso-font-pitch:variable; mso-font-signature:1 134676480 16 0 131072 0;}@font-face {font-family:"Cambria Math"; panose-1:2 4 5 3 5 4 6 3 2 4; mso-font-charset:0; mso-generic-font-family:auto; mso-font-pitch:variable; mso-font-signature:-536870145 1107305727 0 0 415 0;}@font-face {font-family:Cambria; panose-1:2 4 5 3 5 4 6 3 2 4; mso-font-charset:0; mso-generic-font-family:auto; mso-font-pitch:variable; mso-font-signature:-536870145 1073743103 0 0 415 0;} /* Style Definitions */p.MsoNormal, li.MsoNormal, div.MsoNormal {mso-style-unhide:no; mso-style-qformat:yes; mso-style-parent:""; margin-top:0in; margin-right:0in; margin-bottom:10.0pt; margin-left:0in; mso-pagination:widow-orphan; font-size:12.0pt; font-family:Cambria; mso-ascii-font-family:Cambria; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:"ＭＳ 明朝"; mso-fareast-theme-font:minor-fareast; mso-hansi-font-family:Cambria; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi; mso-fareast-language:JA;}a:link, span.MsoHyperlink {mso-style-priority:99; color:blue; mso-themecolor:hyperlink; text-decoration:underline; text-underline:single;}a:visited, span.MsoHyperlinkFollowed {mso-style-noshow:yes; mso-style-priority:99; color:purple; mso-themecolor:followedhyperlink; text-decoration:underline; text-underline:single;}.MsoChpDefault {mso-style-type:export-only; mso-default-props:yes; font-family:Cambria; mso-ascii-font-family:Cambria; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:"ＭＳ 明朝"; mso-fareast-theme-font:minor-fareast; mso-hansi-font-family:Cambria; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi; mso-fareast-language:JA;}.MsoPapDefault {mso-style-type:export-only; margin-bottom:10.0pt;}@page WordSection1 {size:8.5in 11.0in; margin:1.0in 1.25in 1.0in 1.25in; mso-header-margin:.5in; mso-footer-margin:.5in; mso-paper-source:0;}div.WordSection1 {page:WordSection1;}--&gt;&lt;/style&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;You may be curious to know that OWASP has been doing quite a bitthis past year.&amp;nbsp; With over &lt;a href="https://docs.google.com/spreadsheet/ccc?key=0ApZ9zE0hx0LNdGRwS1BTempMWXlZYjlNbHdITEoxUmc&amp;amp;hl=en_US#gid=9"&gt;1500&lt;/a&gt;&lt;a href="https://www.owasp.org/index.php/Membership"&gt;members&lt;/a&gt; in 189 local chapters around the globe, it’s not hard to understandwhy so much is happening.&amp;nbsp; During 2011, majorOWASP conferences were held in Asia, Europe, Latin America and North America.In addition to the traditional conferences, the 2nd OWASP world summit took place in Portugal with 180 security experts attending from 30 different countries. During this event attendees focused on working sessions to tackle securitychallenges facing the industry (read the full report and results &lt;a href="https://www.owasp.org/index.php/Summit_2011"&gt;here&lt;/a&gt;). OWASP was also present with talks or booths at &lt;a href="https://ocms.owasp.org/events/archive/"&gt;38 other events&lt;/a&gt; throughout 2011.&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;In addition to security conferences, many OWASP leaders are speakingat developer conferences to spread security knowledge directly to thosebuilding the applications. We’ll be gathering better metrics in the future, buta quick and informal twitter question reveals many OWASP individuals arepresenting security at non-security conferences such as &lt;span id="goog_314763425"&gt;&lt;/span&gt;&lt;a href="http://www.blogger.com/goog_314763424"&gt;JsFoo&lt;/a&gt;&lt;span id="goog_314763426"&gt;&lt;/span&gt;,&lt;a href="http://funnel.hasgeek.com/phpcloud/11-secure-your-site"&gt;PHP in the cloud&lt;/a&gt;, Jazoon,UberConf, JavaOne, &lt;a href="http://www.supermondays.org/"&gt;SuperMondays&lt;/a&gt;,guest lecturing at Universities, DjangoCon, Pycon, PHPLondon, Cloud Camps, BarCamps, #educause, #jasig and many more.&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;The OWASP community is also growing strong through a variety ofOWASP projects. Some of these are mature tool sets and resources that are tacklingchallenging security problems; others are in experimentation and explorationphases to test out new areas of research.&amp;nbsp;To better aid project growth the OWASP Projects committee iscontinually working to provide a framework that encourages experimentation andnew project ideas and also builds the process, quality and supporting resourcesneeded to foster more mature projects. &lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;While OWASP has a great number of excellent resources, we alsorealize that its not always the easiest to find the material you are lookingfor.&amp;nbsp; We’re busy figuring out ways tobest match up individuals with the relevant and high quality OWASP materials.&amp;nbsp; New approaches may include building specific paths through the website based ondevelopers, testers, architects, etc (builders, breakers, defenders, or more) orit could be through a meta data store of all project information, or even anapproach where projects are categorized into maturity levels such as Incubator/ Labs / Flagship. None-the-less, we’re aware this is an important area thatneeds attention to further grow the usability and accessibility of OWASPresources.&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;Ifyou’re interested in helping out then please reach out to anyone within OWASP,join or propose a project, or even volunteer on an OWASP &lt;a href="https://www.owasp.org/index.php/Global_Committee_Pages"&gt;committee&lt;/a&gt;.&amp;nbsp; The battle to raise awareness aroundapplication security is a challenging task and we’re constantly looking forfresh ideas and talented individuals to volunteer their time and abilitiestowards furthering the OWASP mission.&amp;nbsp;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: Times,&amp;quot;Times New Roman&amp;quot;,serif;"&gt;Lastily, I realize this doesn't scratch the surface of everything took place in 2011 with OWASP. Please comment below with items you'd like to recognize.&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="MsoNormal" style="font-family: inherit;"&gt;&lt;span style="font-size: x-small;"&gt;Michael Coates&lt;br /&gt;OWASP&lt;/span&gt;&lt;/div&gt;&lt;span style="font-size: x-small;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-8987596835425684262?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/8987596835425684262/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/11/lots-of-great-things-happening-at-owasp.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8987596835425684262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8987596835425684262'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/11/lots-of-great-things-happening-at-owasp.html' title='Lots of Great Things Happening At OWASP'/><author><name>Michael Coates</name><uri>http://www.blogger.com/profile/01776444965999374544</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_MiAJXkPG1IM/StSyGcceaDI/AAAAAAAABR4/ZNH2XgLAgM8/S220/MichaelCoates.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-2578078885058350318</id><published>2011-10-12T14:01:00.000-07:00</published><updated>2011-10-12T14:10:03.341-07:00</updated><title type='text'>AppSec DC 2012</title><content type='html'>by &lt;a href="mailto:mark.bristow@owasp.org"&gt;mark.bristow@owasp.org&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Colleagues,&lt;br /&gt;&lt;br /&gt;Building on the success of AppSec DC 2010 and 2009, OWASP is pleased to announce the next OWASP AppSec DC conference.  The theme for this year's conference is "OWASP - Not just webapps anymore" to reflect the new and revised scope of OWASP to include all application security issues instead of focusing just on web application security.&lt;br /&gt;&lt;br /&gt;Owing to feedback from the past two years, and in alignment with the overall OWASP Conference mission, the AppSec DC Planners have decided to move the conference to April of 2012. This is in response to requests from a variety of our sponsors and vendors, and de-conflicts overlap in the OWASP conference schedule for North America.  OWASP AppSec DC 2012 will be held at the Walter E. Washington Convention Center on April 2nd through April 5th.  Plenary sessions will be on April 4th and 5th preceded by Application Security Training on April 2nd and 3rd.&lt;br /&gt;&lt;br /&gt;In accordance with the broader OWASP mission stemming from the 2011 OWASP Global Summit, AppSec DC is working to reflect the move of OWASP towards embracing all facets of Application Security, and not restricting it's content to strictly to the realm of web applications.&lt;br /&gt;&lt;br /&gt;Therefore we invite all practitioners of application security and those who work with or interact with all facets of application security to submit papers and participate in the conference.&lt;br /&gt;&lt;br /&gt;The AppSec DC 2012 Content Committee is seeking presentations in the following subject areas:&lt;br /&gt;&lt;ul&gt;&lt;li&gt; OWASP Projects&lt;/li&gt;&lt;li&gt; Research in Application Security Defense (Defense &amp;amp; Countermeasures)&lt;/li&gt;&lt;li&gt; Research in Application Security Offense (Vulnerabilities &amp;amp; Exploits)&lt;/li&gt;&lt;li&gt; Web Application Security&lt;/li&gt;&lt;li&gt; Critical Infrastructure Security&lt;/li&gt;&lt;li&gt; Mobile Security&lt;/li&gt;&lt;li&gt; Government Initiatives &amp;amp; Government Case Studies&lt;/li&gt;&lt;li&gt; Effective Case studies in Policy, Governance, Architecture or Life Cycle&lt;/li&gt;&lt;li&gt; and other application security topics&lt;/li&gt;&lt;/ul&gt;Submit papers to &lt;a href="http://cfp.appsecdc.org/"&gt;http://cfp.appsecdc.org&lt;/a&gt;.  Submission deadline is January 15th 2012.  Inquires can be made to cfp@appsecdc.org. Additional information can be found in the FAQ.  You will have to sign up for an EasyChair account at &lt;a href="https://www.easychair.org/account/signup.cgi."&gt;https://www.easychair.org/account/signup.cgi.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Conference Website: &lt;a href="http://www.appsecdc.org/"&gt;http://www.appsecdc.org&lt;/a&gt;&lt;br /&gt;FAQ: &lt;a href="https://www.owasp.org/index.php/OWASP_AppSec_DC_2012_-_FAQ"&gt;https://www.owasp.org/index.php/OWASP_AppSec_DC_2012_-_FAQ&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Please forward to all interested practitioners and colleagues.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;&lt;br /&gt;The AppSec DC Program Committee&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;Mark Bristow&lt;br /&gt;(703) 596-5175&lt;br /&gt;&lt;a href="mailto:mark.bristow@owasp.org"&gt;mark.bristow@owasp.org&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;OWASP Global Conferences Committee Chair - &lt;a href="http://is.gd/5MTvF"&gt;http://is.gd/5MTvF&lt;/a&gt;&lt;br /&gt;OWASP DC Chapter Co-Chair - &lt;a href="http://is.gd/5MTwu"&gt;http://is.gd/5MTwu&lt;/a&gt;&lt;br /&gt;AppSec DC Organizer - &lt;a href="https://www.appsecdc.org/"&gt;https://www.appsecdc.org&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-2578078885058350318?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/2578078885058350318/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/10/appsec-dc-2012.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2578078885058350318'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2578078885058350318'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/10/appsec-dc-2012.html' title='AppSec DC 2012'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-9083292420358519693</id><published>2011-10-08T09:34:00.000-07:00</published><updated>2011-10-08T09:36:14.950-07:00</updated><title type='text'>Switzerland Application Security Forum 2011</title><content type='html'>&lt;div&gt;&lt;div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 10.5pt; font-family: Consolas; "&gt;&lt;span lang="EN-US"&gt;The  city of Yverdon-les-Bains will the 2011 edition  of the Application Security Forum - Western Switzerland conference. This event will take place at&lt;/span&gt;&lt;span lang="EN-US"&gt; end of October. &lt;/span&gt;&lt;span lang="EN-US"&gt; For  this second edition, an exceptional lineup consisting of 19  speakers and trainers, both locally and internationally recognized,  will share their knowledge, best practices and experience on all  sensitive topics related to application security: strong authentication,  privacy, cryptography, critical systems, secure development,  cyberthreats, etc.&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 10.5pt; font-family: Consolas; "&gt;&lt;span lang="EN-US"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 10.5pt; font-family: Consolas; "&gt;&lt;span lang="EN-US"&gt;Participation  is free during the Conference day (Oct.27th), fees for trainings and  workshops apply on the first day only (Oct. 26th.), online registration  is required to attend the event.&lt;/span&gt;&lt;/div&gt;&lt;div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 10.5pt; font-family: Consolas; "&gt;&lt;span lang="EN-US"&gt; &lt;/span&gt;&lt;/div&gt;&lt;div style="margin-top: 0cm; margin-right: 0cm; margin-left: 0cm; margin-bottom: 0.0001pt; font-size: 10.5pt; font-family: Consolas; "&gt;&lt;a href="http://event.appsec-forum.ch/" style="color: blue; text-decoration: underline; "&gt;http://event.appsec-forum.ch&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The Event is co-organized by the OWASP Switzerland/Geneva Chapter and Openid Switzerland.&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-9083292420358519693?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/9083292420358519693/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/10/switzerland-application-security-forum.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/9083292420358519693'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/9083292420358519693'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/10/switzerland-application-security-forum.html' title='Switzerland Application Security Forum 2011'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4266073909796012110</id><published>2011-09-29T11:44:00.000-07:00</published><updated>2011-09-29T11:44:48.446-07:00</updated><title type='text'>OWASP AppSec USA 2011 – The Wrap up</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;div style="font-family: &amp;quot;Courier New&amp;quot;,Courier,monospace;"&gt;&lt;b&gt;&lt;span style="font-size: x-small;"&gt;Article by Lorna Alamri &lt;/span&gt;&lt;/b&gt;&lt;/div&gt;&lt;br /&gt;While the planning team is still sending out documentation, requesting invoices and finishing up tasks for the event. It’s time to give a summary of the event from a numbers perspective.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;The Conference: &lt;/b&gt;&lt;br /&gt;&lt;br /&gt;OWASP AppSecs bring together people around application security. What better opportunity to get attendees excited and involved in OWASP projects. Outside of an OWASP Summit it’s the largest gathering of OWASP and application security leaders, so a great opportunity to work on solutions and keep momentum going from the OWASP Summit.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Our goals:&lt;/b&gt;&lt;br /&gt; 500 attendees. $100,000 in funds raised for the OWASP Foundation. Raise awareness around OWASP and application security among developers.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Registrations:&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;style&gt;&lt;!-- /* Font Definitions */@font-face	{font-family:Calibri;	panose-1:2 15 5 2 2 2 4 3 2 4;	mso-font-charset:0;	mso-generic-font-family:auto;	mso-font-pitch:variable;	mso-font-signature:3 0 0 0 1 0;} /* Style Definitions */p.MsoNormal, li.MsoNormal, div.MsoNormal	{mso-style-unhide:no;	mso-style-qformat:yes;	mso-style-parent:"";	margin:0in;	margin-bottom:.0001pt;	mso-pagination:widow-orphan;	font-size:11.0pt;	font-family:Calibri;	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}.MsoChpDefault	{mso-style-type:export-only;	mso-default-props:yes;	font-size:11.0pt;	mso-ansi-font-size:11.0pt;	mso-bidi-font-size:11.0pt;	font-family:Calibri;	mso-ascii-font-family:Calibri;	mso-ascii-theme-font:minor-latin;	mso-fareast-font-family:Calibri;	mso-fareast-theme-font:minor-latin;	mso-hansi-font-family:Calibri;	mso-hansi-theme-font:minor-latin;	mso-bidi-font-family:"Times New Roman";	mso-bidi-theme-font:minor-bidi;}.MsoPapDefault	{mso-style-type:export-only;	margin-bottom:10.0pt;	line-height:115%;}@page WordSection1	{size:8.5in 11.0in;	margin:1.0in 1.25in 1.0in 1.25in;	mso-header-margin:.5in;	mso-footer-margin:.5in;	mso-paper-source:0;}div.WordSection1	{page:WordSection1;}--&gt;&lt;/style&gt;639, Total registration revenue as of 9/15/11 (536attendees) $251,476.15&lt;br /&gt;Sponsors: 24 with a total of $130,600 in funds raised.&lt;br /&gt;Expenses: Estimated at $210,000. (We’re still waiting for someinvoices from vendors.)&amp;nbsp;&lt;b&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;br /&gt;The Talks:&lt;/b&gt;&lt;br /&gt;2 days/4 tracks&lt;br /&gt;75 speakers, 48 talks, 3 keynotes and one board discussion.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;The Training:&lt;/b&gt;&lt;br /&gt;4 two-day training courses&lt;br /&gt;4 one-day training courses&lt;br /&gt;Training Course Students: 146, OWASP profit from training: $63,000&lt;br /&gt;&lt;br /&gt;&lt;b&gt;The CTFs:&lt;/b&gt;&lt;br /&gt;One University CTF challenge - 3 teams&lt;br /&gt;One CTF -2 days&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Organizers/Volunteers: 48&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;Statistics on Attendance:&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://3.bp.blogspot.com/-CmYNDsiYHS4/ToS6m3P6qTI/AAAAAAAAB00/7OUwqLZl5gY/s1600/image001.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="191" src="http://3.bp.blogspot.com/-CmYNDsiYHS4/ToS6m3P6qTI/AAAAAAAAB00/7OUwqLZl5gY/s320/image001.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://2.bp.blogspot.com/-U2yY9zST7q4/ToS6mhUQxpI/AAAAAAAAB0w/mzFnyTfq48s/s1600/image002.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="191" src="http://2.bp.blogspot.com/-U2yY9zST7q4/ToS6mhUQxpI/AAAAAAAAB0w/mzFnyTfq48s/s320/image002.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size: x-small;"&gt;*Education included both students and employees who attended OWASP AppSecUSA 2011.&lt;br /&gt;*OWASP Employees and non-industry volunteers are not included in numbers.&lt;br /&gt;&amp;nbsp;&lt;/span&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;b&gt;Overall Attendees by Country&lt;/b&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-culqfOhQmMU/ToS6mLTWyWI/AAAAAAAAB0o/kN5u9W4nn0o/s1600/image006.png" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="175" src="http://4.bp.blogspot.com/-culqfOhQmMU/ToS6mLTWyWI/AAAAAAAAB0o/kN5u9W4nn0o/s320/image006.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;US Attendance by State&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class="separator" style="clear: both; text-align: center;"&gt;&lt;a href="http://4.bp.blogspot.com/-I7IwTpWmRGA/ToS6me9ebGI/AAAAAAAAB0s/FyNB9CAh32s/s1600/image004.png" imageanchor="1" style="margin-left: 1em; margin-right: 1em;"&gt;&lt;img border="0" height="145" src="http://4.bp.blogspot.com/-I7IwTpWmRGA/ToS6me9ebGI/AAAAAAAAB0s/FyNB9CAh32s/s320/image004.png" width="320" /&gt;&lt;/a&gt;&lt;/div&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;The Events:&lt;/b&gt;&lt;br /&gt;We took the opportunity to try out a lot of new events at AppSec USA which we hope will be included in future OWASP AppSecs.&lt;br /&gt;&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;5K/10K Run for Charity – funds raised were donated to the Bakken Musuem.&lt;/li&gt;&lt;li&gt;University Challenge – A CTF aimed at University students to increase OWASP awareness at a University level.&lt;/li&gt;&lt;li&gt;Women in AppSec – A grant program to increase particpation at OWASP AppSec USA by women.&lt;/li&gt;&lt;li&gt;Open Source Showcase – An opportunity to demonstrate OWASP and other open source projects to attendees of OWASP AppSecs.&lt;/li&gt;&lt;li&gt;Project work groups: ESAPI, AppSensor, Chapters and Industry along with board and committee meetings.&lt;/li&gt;&lt;/ul&gt;&lt;div style="text-align: left;"&gt;&lt;br /&gt;Lorna Alamri&lt;br /&gt;OWASP AppSec USA&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4266073909796012110?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4266073909796012110/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/09/owasp-appsec-usa-2011-wrap-up.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4266073909796012110'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4266073909796012110'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/09/owasp-appsec-usa-2011-wrap-up.html' title='OWASP AppSec USA 2011 – The Wrap up'/><author><name>Michael Coates</name><uri>http://www.blogger.com/profile/01776444965999374544</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_MiAJXkPG1IM/StSyGcceaDI/AAAAAAAABR4/ZNH2XgLAgM8/S220/MichaelCoates.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://3.bp.blogspot.com/-CmYNDsiYHS4/ToS6m3P6qTI/AAAAAAAAB00/7OUwqLZl5gY/s72-c/image001.png' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-980493952598529501</id><published>2011-09-29T11:34:00.000-07:00</published><updated>2011-09-29T11:34:18.496-07:00</updated><title type='text'>OWASP ModSecurity CRS v2.2.2</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;&lt;br /&gt;&lt;div class="moz-text-html" lang="x-western"&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;(From ryan.barnett@owasp.org) &lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;I am pleased to announce the release of OWASP ModSecurity CRS v2.2.2. &amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;===========&lt;/div&gt;&lt;div&gt;CHANGELOG&lt;/div&gt;&lt;div&gt;===========&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;div&gt;--------------------------&lt;/div&gt;&lt;div&gt;Version 2.2.2 - 09/28/2011&lt;/div&gt;&lt;div&gt;--------------------------&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Improvements:&lt;/div&gt;&lt;div&gt;- Updated the AppSensor Profiling (to use Lua scripts) for Request Exceptions Detection Points&amp;nbsp;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp;&lt;a href="http://blog.spiderlabs.com/2011/08/implementing-appsensor-detection-points-in-modsecurity.html"&gt;http://blog.spiderlabs.com/2011/08/implementing-appsensor-detection-points-in-modsecurity.html&lt;/a&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;- Added new Range header detection checks to prevent Apache DoS&lt;/div&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp;&lt;a href="http://blog.spiderlabs.com/2011/08/mitigation-of-apache-range-header-dos-attack.html"&gt;http://blog.spiderlabs.com/2011/08/mitigation-of-apache-range-header-dos-attack.html&lt;/a&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;- Added new Security Scanner User-Agent strings&lt;/div&gt;&lt;div&gt;- Added example script to the /util directory to convert Arachni DAST scanner&amp;nbsp;XML data into ModSecurity virtual patching rules.&lt;/div&gt;&lt;div&gt;&amp;nbsp;&amp;nbsp;&lt;a href="http://blog.spiderlabs.com/2011/08/modsecurity-advanced-topic-of-the-week-automated-virtual-patching-script.html"&gt;http://blog.spiderlabs.com/2011/08/modsecurity-advanced-topic-of-the-week-automated-virtual-patching-script.html&lt;/a&gt;&amp;nbsp;&lt;/div&gt;&lt;div&gt;- Updated the SQLi Character Anomaly Detection Rules&lt;/div&gt;&lt;div&gt;- Added Host header info to the RESOURCE collection key for AppSensor profiling rules&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Bug Fixes:&lt;/div&gt;&lt;div&gt;- Fixed action list for XSS rules (replaced pass,nolog,auditlog with block)&lt;/div&gt;&lt;div&gt;- Fixed Request Limit rules by removing &amp;amp; from variables&lt;/div&gt;&lt;div&gt;- Fixed Session Hijacking IP/UA hash captures&amp;nbsp;&lt;/div&gt;&lt;div&gt;- Updated the SQLi regex for rule ID 981242&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&amp;nbsp;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;--------------------------&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;DOWNLOADING&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;--------------------------&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;Manual Downloading:&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;You can always download the latest CRS version here -&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;a href="https://sourceforge.net/projects/mod-security/files/modsecurity-crs/0-CURRENT/"&gt;https://sourceforge.net/projects/mod-security/files/modsecurity-crs/0-CURRENT/&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;Automated Downloading:&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;Use the rules-updater.pl script in the CRS /util directory&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;# Get a list of what the repository contains:&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;$ ./rules-updater.pl -r&lt;a href="http://www.modsecurity.org/autoupdate/repository/"&gt;http://www.modsecurity.org/autoupdate/repository/&lt;/a&gt;&amp;nbsp;-l&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;Repository:&amp;nbsp;&lt;a href="http://www.modsecurity.org/autoupdate/repository"&gt;http://www.modsecurity.org/autoupdate/repository&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;modsecurity-crs {&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.0.0: modsecurity-crs_2.0.0.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.0.1: modsecurity-crs_2.0.1.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.0.2: modsecurity-crs_2.0.2.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.0.3: modsecurity-crs_2.0.3.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.0.4: modsecurity-crs_2.0.4.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.0.5: modsecurity-crs_2.0.5.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.0.6: modsecurity-crs_2.0.6.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.0.7: modsecurity-crs_2.0.7.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.0.8: modsecurity-crs_2.0.8.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.0.9: modsecurity-crs_2.0.9.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.0.9: modsecurity-crs_2.0.10.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.1.0: modsecurity-crs_2.1.0.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.1.1: modsecurity-crs_2.1.1.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;2.1.2: modsecurity-crs_2.1.2.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt;	&lt;/span&gt;&amp;nbsp;&amp;nbsp;2.2.0: modsecurity-crs_2.2.0.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;2.2.1: modsecurity-crs_2.2.1.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;2.2.2: modsecurity-crs_2.2.2.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;}&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;# Get the latest stable version of "modsecurity-crs":&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;$ ./rules-updater.pl -r&lt;a href="http://www.modsecurity.org/autoupdate/repository/"&gt;http://www.modsecurity.org/autoupdate/repository/&lt;/a&gt;&amp;nbsp;-prules -Smodsecurity-crs&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;Fetching: modsecurity-crs/modsecurity-crs_2.2.2.zip ...&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;$ ls -R rules&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;modsecurity-crs&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;rules/modsecurity-crs:&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;modsecurity-crs_2.2.2.zip&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;modsecurity-crs_2.2.2.zip.sig&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;--&lt;/div&gt;&lt;div&gt;Ryan Barnett&lt;/div&gt;&lt;div&gt;OWASP ModSecurity Core Rule Set Project Lead&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;br /&gt;&lt;fieldset class="mimeAttachmentHeader"&gt;&lt;/fieldset&gt;&lt;br /&gt;&lt;div class="moz-text-plain" lang="x-western" style="font-family: -moz-fixed; font-size: 12px;" wrap="true"&gt;&lt;pre wrap=""&gt;_______________________________________________&lt;br /&gt;OWASP-Leaders mailing list&lt;br /&gt;&lt;a class="moz-txt-link-abbreviated" href="mailto:OWASP-Leaders@lists.owasp.org"&gt;OWASP-Leaders@lists.owasp.org&lt;/a&gt;&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="https://lists.owasp.org/mailman/listinfo/owasp-leaders"&gt;https://lists.owasp.org/mailman/listinfo/owasp-leaders&lt;/a&gt;&lt;br /&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-980493952598529501?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/980493952598529501/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/09/owasp-modsecurity-crs-v222.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/980493952598529501'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/980493952598529501'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/09/owasp-modsecurity-crs-v222.html' title='OWASP ModSecurity CRS v2.2.2'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-1248566848374737589</id><published>2011-09-29T11:25:00.000-07:00</published><updated>2011-09-29T11:26:29.002-07:00</updated><title type='text'>OWASP Board 2012</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;I am very please to announce the results of the recent OWASP Board Election!&lt;br /&gt;&lt;br /&gt;Turnout: 771 (46.2%) of 1670 electors voted in this ballot.&lt;br /&gt;Top (3) have been elected.&lt;br /&gt;&lt;ul style="text-align: left;"&gt;&lt;li&gt;&lt;b&gt;Michael Coates - 524 (31.0%)&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Dave Wichers - 460 (27.2%)&lt;/b&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Sebastien Deleersnyder - 423 (25.0%)&lt;/b&gt;&lt;/li&gt;&lt;li&gt;Christian Heinrich - 286 (16.9%)&lt;/li&gt;&lt;/ul&gt;Your International Board of Directors term is effective 1-Jan-2012 for (24) months governed by the OWASP Bylaws: &lt;a class="external free" href="https://www.owasp.org/images/d/d6/2011-06-OWASP-BYLAWS.pdf" rel="nofollow"&gt;https://www.owasp.org/images/d/d6/2011-06-OWASP-BYLAWS.pdf&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The Board also held elections at AppSec USA to decide new board roles and responsibilities.&amp;nbsp; The results are as follows:&lt;br /&gt;&lt;br /&gt;&lt;a href="https://www.owasp.org/index.php/User:MichaelCoates" title="User:MichaelCoates"&gt;Michael Coates&lt;/a&gt; - OWASP Chair &lt;br /&gt;michael.coates(at)owasp.org&lt;br /&gt;&lt;br /&gt;&lt;a href="https://www.owasp.org/index.php/User:EoinKeary" title="User:EoinKeary"&gt;Eoin Keary&lt;/a&gt; - Vice Chair&lt;br /&gt;eoin(at)owasp.org&lt;br /&gt;&lt;br /&gt;&lt;a href="https://www.owasp.org/index.php/User:Brennan" title="User:Brennan"&gt;Tom Brennan&lt;/a&gt; - Secretary&lt;br /&gt;tom.brennan(at)owasp.org&lt;br /&gt;&lt;br /&gt;&lt;a href="https://www.owasp.org/index.php/User:Mtesauro" title="User:Mtesauro"&gt;Matt Tesauro&lt;/a&gt; - Treasurer&lt;br /&gt;matt.tesauro(at)owasp.org&lt;br /&gt;&lt;br /&gt;&lt;a href="https://www.owasp.org/index.php/User:Sdeleersnyder" title="User:Sdeleersnyder"&gt;Sebastien Deleersnyder&lt;/a&gt; - Board Member &lt;br /&gt;seba(at)owasp.org&lt;br /&gt;&lt;br /&gt;&lt;a href="https://www.owasp.org/index.php/User:Wichers" title="User:Wichers"&gt;Dave Wichers&lt;/a&gt; - Board Member&lt;br /&gt;dave.wichers(at)owasp.org&lt;br /&gt;&lt;br /&gt;Please join me in offering our new board congratulations and support.&lt;br /&gt;&lt;br /&gt;Aloha,&lt;br /&gt;Jim Manico&lt;br /&gt;OWASP Connections Committee Chair&lt;br /&gt;jim@owasp.org &lt;br /&gt;&amp;nbsp; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-1248566848374737589?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/1248566848374737589/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/09/owasp-board-2012.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1248566848374737589'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1248566848374737589'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/09/owasp-board-2012.html' title='OWASP Board 2012'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-268099472680163903</id><published>2011-09-07T00:51:00.000-07:00</published><updated>2011-09-07T00:53:26.526-07:00</updated><title type='text'>AppSec USA 2011 Conference - Two Weeks Away</title><content type='html'>Hello OWASP Community,&lt;br /&gt;&lt;br /&gt;The OWASP AppSec USA 2011 conference in Minneapolis is only two weeks away. Classes are filling up fast (the OWASP WTE class is full), and the conference talks lineup is impressive. Sign up today for the training on September 20-21 and the main conference talks, CTF, showroom, and Open Source Showcase on September 22-23!&lt;br /&gt;&lt;br /&gt;http://www.appsecusa.org/&lt;br /&gt;&lt;br /&gt;OWASP is in its tenth year, and application security is on everyone's radar. And this year we have some wonderful new initiatives as part of OWASP AppSec USA 2011. For the first time, we're:&lt;br /&gt;&lt;br /&gt;* Funding the conference experience for two women in college through the OWASP Women in AppSec grant. Congratulations to Tara Wilson and Chandni Bhowmik on securing these grants! And thank you to The Wells Fargo Foundation for its generous seed funding.&lt;br /&gt;&lt;br /&gt;* Raising funds for science education for inner city youth with the 5K/10K for Charity.&lt;br /&gt;&lt;br /&gt;* Hosting a University Challenge offense/defense competition.&lt;br /&gt;&lt;br /&gt;* Running an Open Source Showcase during the conference proceedings. Open source community members will demo their awesome work.&lt;br /&gt;&lt;br /&gt;Additionally, the OWASP Chapters Committee and the ESAPI and AppSensor teams will be meeting September 21 to build upon their great work in OWASP.&lt;br /&gt;&lt;br /&gt;Be a part of AppSec USA 2011, where OWASP propels itself into the next ten years. Lots of cool talks and training. And many opportunities to learn, grow, and give back.&lt;br /&gt;&lt;br /&gt;http://www.appsecusa.org/attend.html&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;We would like to thank the OWASP AppSec USA 2011 donors and sponsors and the many conference contributors for helping us to build an awesome event for the application security and development community.&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;Adam Baso&lt;br /&gt;OWASP AppSec USA 2011 Organizer&lt;br /&gt;&lt;br /&gt;OWASP AppSec USA 2011: Your life is in the cloud.&lt;br /&gt;September 20-23 Training, Talks, CTF, Showroom, and More&lt;br /&gt;www.appsecusa.org&lt;br /&gt;@appsecusa&lt;br /&gt;&lt;br /&gt;To learn more about OWASP, visit https://www.owasp.org.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-268099472680163903?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/268099472680163903/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/09/appsec-usa-2011-conference-two-weeks.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/268099472680163903'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/268099472680163903'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/09/appsec-usa-2011-conference-two-weeks.html' title='AppSec USA 2011 Conference - Two Weeks Away'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-6179803481145459930</id><published>2011-08-31T17:49:00.000-07:00</published><updated>2011-08-31T17:50:17.770-07:00</updated><title type='text'>OWASP AppSensor Detection Points in the OWASP ModSecurity Core Rule Set</title><content type='html'>&lt;div&gt;(from &lt;span style="font-size:85%;"&gt;&lt;span style="font-family:Consolas,Courier New,Courier;"&gt;&lt;span style="font-size:10pt"&gt; Ryan Barnett)&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;I have begun the process of implementing the OWASP AppSensor Detection Points (&lt;a href="https://www.owasp.org/index.php/AppSensor_DetectionPoints"&gt;https://www.owasp.org/index.php/AppSensor_DetectionPoints&lt;/a&gt;) within the OWASP ModSecurity Core Rule Set (&lt;a href="https://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project"&gt;https://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project&lt;/a&gt;).  &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;I  am pleased to announce that I have just made an update to the OWASP CRS  SVN repository that fully implements the Request Exception (RE)  category&lt;/b&gt; - &lt;a href="https://www.owasp.org/index.php/AppSensor_DetectionPoints#RequestException"&gt;https://www.owasp.org/index.php/AppSensor_DetectionPoints#RequestException&lt;/a&gt;.  See the following blog post for more details - &lt;a href="http://blog.spiderlabs.com/2011/08/implementing-appsensor-detection-points-in-modsecurity.html"&gt;http://blog.spiderlabs.com/2011/08/implementing-appsensor-detection-points-in-modsecurity.html&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The major change in this version vs. the earlier one outlined in this blog post (&lt;a href="http://blog.spiderlabs.com/2011/02/modsecurity-advanced-topic-of-the-week-real-time-application-profiling.html"&gt;http://blog.spiderlabs.com/2011/02/modsecurity-advanced-topic-of-the-week-real-time-application-profiling.html&lt;/a&gt;) is  that both the profiling and detection logic has been moved to Lua  scripts.  With the increased logic capabilities of Lua, we are now able  to more accurately profile the application in real-time by analyzing  traffic and automatically generating profiles for the following resource  characteristics -&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Enforcing the expected Request Method(s)&lt;/li&gt;&lt;li&gt;Enforce the number of expected parameters (min-max range)&lt;/li&gt;&lt;li&gt;Enforce parameter names &lt;/li&gt;&lt;li&gt;Enforce parameter lengths (min-max range)&lt;/li&gt;&lt;li&gt;Enforce Character Classes&lt;/li&gt;&lt;ul&gt;&lt;li&gt;Flag (e.g. - /path/to/foo.php?param)&lt;/li&gt;&lt;li&gt;Digits  (e.g. - /path/to/foo.php?param=1234) &lt;/li&gt;&lt;li&gt;Alpha  (e.g. - /path/to/foo.php?param=abcd)&lt;/li&gt;&lt;li&gt;AlphaNumeric  (e.g. - /path/to/foo.php?param=abcd1234)&lt;/li&gt;&lt;li&gt;Email  (e.g. - /path/to/foo.php?param=foo@bar.com)&lt;/li&gt;&lt;li&gt;Path  (e.g. - /path/to/foo.php?param=/dir/somefile.txt)&lt;/li&gt;&lt;li&gt;URL  (e.g. - /path/to/foo.php?param=http://somehost/dir/file.txt)&lt;/li&gt;&lt;li&gt;SafeText  (e.g. - /path/to/foo.php?param=some_data-12)&lt;/li&gt;&lt;/ul&gt;&lt;/ul&gt;&lt;div&gt;The updated rules files are in the /experimental_rules directory - &lt;a href="http://mod-security.svn.sourceforge.net/viewvc/mod-security/crs/trunk/experimental_rules/"&gt;http://mod-security.svn.sourceforge.net/viewvc/mod-security/crs/trunk/experimental_rules/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;Look in the /lua folder to find the 2 scripts - &lt;a href="http://mod-security.svn.sourceforge.net/viewvc/mod-security/crs/trunk/lua/"&gt;http://mod-security.svn.sourceforge.net/viewvc/mod-security/crs/trunk/lua/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I encourage people to test out these new rules and to report back their experiences – both good and bad.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;FYI – I also wanted to thank Josh Zlatin for assisting with the initial Lua script creation.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Cheers.&lt;/div&gt;&lt;div&gt;&lt;span style="font-family:Calibri,Verdana,Helvetica,Arial;"&gt;&lt;span style="font-size:11pt"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:Consolas,Courier New,Courier;"&gt;&lt;span style="font-size:10pt"&gt;--&lt;br /&gt;Ryan Barnett&lt;br /&gt;OWASP ModSecurity Core Rule Set Project Leader&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-6179803481145459930?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/6179803481145459930/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/08/owasp-appsensor-detection-points-in.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6179803481145459930'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6179803481145459930'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/08/owasp-appsensor-detection-points-in.html' title='OWASP AppSensor Detection Points in the OWASP ModSecurity Core Rule Set'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-1368854716856991395</id><published>2011-08-23T20:53:00.001-07:00</published><updated>2011-08-23T20:53:35.686-07:00</updated><title type='text'>OWASP AppSec Latin America 2011</title><content type='html'>On behalf of the OWASP AppSec Latin America 2011 organization team, I’m thrilled to announce registration is now officially open! The organization committee truly went out of its way to keep prices down and provide the best deals for people who really want to take full advantage of this event. One example is the full package deal: for R$1,000 (approximately US$625) you can attend two classes and the conference. &lt;div&gt;  &lt;p class="MsoNormal"&gt;The deadline for early bird registration is August 31&lt;sup&gt;st&lt;/sup&gt; so you do need to hurry! Conference details, sponsorship information, registration links, and some cool videos about Brazil and Porto Alegre are all available at the conference site: &lt;a href="https://www.owasp.org/index.php/AppSecLatam2011#tab=Welcome"&gt;https://www.owasp.org/index.php/AppSecLatam2011#tab=Welcome&lt;/a&gt;.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Get your visa ready. We look forward to seeing everyone in Brazil!&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Cassio&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-1368854716856991395?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/1368854716856991395/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/08/owasp-appsec-latin-america-2011.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1368854716856991395'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1368854716856991395'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/08/owasp-appsec-latin-america-2011.html' title='OWASP AppSec Latin America 2011'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-1985088459860071871</id><published>2011-07-29T10:37:00.000-07:00</published><updated>2011-07-29T10:39:35.032-07:00</updated><title type='text'>AppSec USA Open Source Support!</title><content type='html'>&lt;pre wrap=""&gt;&lt;span class="Apple-style-span" &gt;(from &lt;a href="mailto:adam.baso@owasp.org"&gt;adam.baso@owasp.org&lt;/a&gt;)&lt;/span&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;span class="Apple-style-span" &gt;OWASP is piloting a new initiative to promote open source ideals at our Global AppSec Conferences!  &lt;/span&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;span class="Apple-style-span" &gt;For the first time, we are offering a limited number of free booth spaces to open source projects as part of the OWASP Open Source Showcase at OWASP AppSec USA 2011!  We invite ANY open source project - not just OWASP projects - to apply for a booth at this showcase to demo and promote their project. Showcase participants need to be ticketed attendees and will be responsible for manning their booth.  &lt;/span&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;span class="Apple-style-span" &gt;Learn more about this opportunity, including how to submit projects for consideration, by visiting the following URL:  &lt;a class="moz-txt-link-freetext" href="http://www.appsecusa.org/oss.html"&gt;http://www.appsecusa.org/oss.html&lt;/a&gt;   Applications are due Friday, August 19, 2011, and are considered on a rolling basis - so get moving!  &lt;/span&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;span class="Apple-style-span" &gt;Contact &lt;a class="moz-txt-link-abbreviated" href="mailto:projects@owasp.org"&gt;projects@owasp.org&lt;/a&gt; if you have any questions.  &lt;/span&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;span class="Apple-style-span" &gt;OWASP MSP: Host to OWASP AppSec USA 2011&lt;br /&gt;September 20-23&lt;br /&gt;Training, Talks, CTF, Showroom and more&lt;br /&gt;&lt;a class="moz-txt-link-abbreviated" href="http://www.appsecusa.org/"&gt;www.appsecusa.org&lt;/a&gt; @appsecusa&lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-1985088459860071871?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/1985088459860071871/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/07/appsec-usa-open-source-support.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1985088459860071871'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1985088459860071871'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/07/appsec-usa-open-source-support.html' title='AppSec USA Open Source Support!'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-8989775097752384009</id><published>2011-07-29T09:36:00.000-07:00</published><updated>2011-07-29T09:36:32.695-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='videos'/><title type='text'>Application Security Tutorial Videos</title><content type='html'>&lt;div dir="ltr" style="text-align: left;" trbidi="on"&gt;The OWASP application video tutorial series, led by &lt;a href="https://twitter.com/#%21/jerryhoff"&gt;Jerry Hoff&lt;/a&gt;,&amp;nbsp; has produced three great security videos and has many more on the way.  These videos are short and to the point. The 10 minute videos cover core application security risks such as cross site scripting or sql injection and future episodes will cover defense in depth security techniques such as Strict Transport Security or X-Frame-Options. &lt;br /&gt;&lt;br /&gt;The following videos are currently available as part of the &lt;a href="http://www.youtube.com/user/AppsecTutorialSeries"&gt;AppSec Tutorial Video Series&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; •&amp;nbsp;&amp;nbsp; &amp;nbsp;Episode 1 - Introduction&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;•&amp;nbsp;&amp;nbsp; &amp;nbsp;Episode 2 - Injection Attacks&lt;br /&gt;&amp;nbsp;&amp;nbsp; &amp;nbsp;•&amp;nbsp;&amp;nbsp; &amp;nbsp;Episode 3 - Cross Site Scripting&lt;br /&gt;The following link will take you to the OWASP AppSec Video Series homepage on youtube.&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/user/AppsecTutorialSeries"&gt;http://www.youtube.com/user/AppsecTutorialSeries&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;You can also watch the three videos embedded below.&lt;br /&gt;&lt;br /&gt;&lt;iframe allowfullscreen="" frameborder="0" height="349" src="http://www.youtube.com/embed/CDbWvEwBBxo" width="560"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;&lt;iframe allowfullscreen="" frameborder="0" height="349" src="http://www.youtube.com/embed/pypTYPaU7mM" width="560"&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;br /&gt;&lt;iframe allowfullscreen="" frameborder="0" height="349" src="http://www.youtube.com/embed/_Z9RQSnf8-g" width="560"&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-8989775097752384009?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/8989775097752384009/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/07/application-security-tutorial-videos.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8989775097752384009'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8989775097752384009'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/07/application-security-tutorial-videos.html' title='Application Security Tutorial Videos'/><author><name>Michael Coates</name><uri>http://www.blogger.com/profile/01776444965999374544</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_MiAJXkPG1IM/StSyGcceaDI/AAAAAAAABR4/ZNH2XgLAgM8/S220/MichaelCoates.jpg'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://img.youtube.com/vi/CDbWvEwBBxo/default.jpg' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-5363654814960760317</id><published>2011-07-27T08:36:00.000-07:00</published><updated>2011-07-27T08:45:56.923-07:00</updated><title type='text'>OWASP Codes of Conduct Project</title><content type='html'>&lt;strong&gt;By Colin Watson&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;At the summit in Portugal earlier this year, a working session on "Defining a Minimal AppSec Program for Universities, Governments, and Standards Bodies" created a document defining minimal requirements for three types of organization, specifying what are the most effective ways to support OWASP's mission.  These are OWASP's objectives for other organizations and do not relate to members or other participants.&lt;br /&gt;&lt;br /&gt;The three types of organization were:&lt;br /&gt;&lt;br /&gt; - Government Bodies&lt;br /&gt; - Educational Institutions&lt;br /&gt; - Standards Groups&lt;br /&gt;&lt;br /&gt;with Jeff Williams, Dave Wichers and Dinis Cruz as primary contributors.&lt;br /&gt;&lt;br /&gt;Although I didn't attend that particular session, I was able to contribute to an early draft version of the document, and subsequently created a parallel document for:&lt;br /&gt;&lt;br /&gt; - Trade Organizations&lt;br /&gt;&lt;br /&gt;At another working session on Certification, the participants created another closely-related document on expectations for:&lt;br /&gt;&lt;br /&gt; - Certifying Bodies&lt;br /&gt;&lt;br /&gt;with Jason Li, Jason Taylor, Martin Knobloch, Matthew Chalmers and Justin Searle as&lt;br /&gt;primary contributors.&lt;br /&gt;&lt;br /&gt;Each document has been give a colour name to make it more identifiable, and to provide a shorter title.  Thus the document "The OWASP Application Security Code of Conduct for Government Bodies: is also "The OWASP Green Book".&lt;br /&gt;&lt;br /&gt;OWASP would like to formalize, complete and create release-quality documents, and therefore I have offered to start a project and become project leader for the OWASP Codes of Conduct Project.  The project will nurture these initiatives and collect feedback on the draft documents with the aim of issuing and promoting the documents later this year.  With Paulo Coimbra's welcome assistance, the project and&lt;br /&gt;current draft versions can be found at:&lt;br /&gt;&lt;br /&gt;https://www.owasp.org/index.php/OWASP_Codes_of_Conduct&lt;br /&gt;&lt;br /&gt;The v1.1 draft documents were created from the summit outcomes, and to  date I have:&lt;br /&gt;&lt;br /&gt; 1)  standardized their formatting&lt;br /&gt; 2)  removed reference to "free membership [of bodies, groups] " where&lt;br /&gt; this does not match current policy&lt;br /&gt; 3)  removed "free attendance at events" for liaison contacts since&lt;br /&gt; this hasn't been more widely discussed&lt;br /&gt; 4)  made liaison groups within OWASP less specific since we do not&lt;br /&gt; have a "OWASP Educational Institution Executive Council" for example&lt;br /&gt; 5)  changed the mandatory Code of Conduct items to a numbered list,&lt;br /&gt; and the recommendations to an alphabetical list to distinguish between&lt;br /&gt; them better&lt;br /&gt; 6)  added hyperlinks to OWASP resources and a summary sheet on the last page&lt;br /&gt;&lt;br /&gt;I would welcome feedback on these using the project's mailing list:&lt;br /&gt;&lt;br /&gt;https://lists.owasp.org/mailman/listinfo/owasp-codes-of-conduct &lt;br /&gt;&lt;br /&gt;Please contribute in the next 4 weeks, after which I will be seeking project formal reviewers.  Some things to be discussed before then:&lt;br /&gt;&lt;br /&gt; - have all the contributors been captured correctly?&lt;br /&gt; - the documents do not have licensing or copyright stated&lt;br /&gt; - the Green Book requires government organizations to adopt a&lt;br /&gt; definition of "application security", but in the Yellow Book for&lt;br /&gt; Standards Groups, this is an optional requirement, and perhaps they&lt;br /&gt; should be the same&lt;br /&gt; - some organizations might decide they do everything we suggest, and&lt;br /&gt; we might want to state a form of words for any statement of adoption&lt;br /&gt;&lt;br /&gt;PLUS ANYTHING ELSE you feel is important.  You may have ideas for another similar document.  Please join the mailing list.&lt;br /&gt;&lt;br /&gt;Colin Watson&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-5363654814960760317?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/5363654814960760317/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/07/owasp-codes-of-conduct-project.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5363654814960760317'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5363654814960760317'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/07/owasp-codes-of-conduct-project.html' title='OWASP Codes of Conduct Project'/><author><name>Kate Hartmann</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-997088407872127918</id><published>2011-07-21T17:13:00.000-07:00</published><updated>2011-07-21T17:17:34.846-07:00</updated><title type='text'>OWASP LATAM Tour</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:officedocumentsettings&gt;   &lt;o:allowpng/&gt;  &lt;/o:OfficeDocumentSettings&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:enableopentypekerning/&gt;    &lt;w:dontflipmirrorindents/&gt;    &lt;w:overridetablestylehps/&gt;   &lt;/w:Compatibility&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-parent:"";  mso-padding-alt:0in 5.4pt 0in 5.4pt;  mso-para-margin:0in;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman","serif";} &lt;/style&gt; &lt;![endif]--&gt;    &lt;p class="MsoNormal"&gt;&lt;span style=";font-family:&amp;quot;;font-size:11pt;"  &gt;Fabio Cerullo presented the OWASP training day in Argentina on 7/19/2011.  There were over 40 attendees (58 registered) and 17 NEW members registered including 5 educational supporters.  Outstanding!&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;span style=";font-family:&amp;quot;;font-size:11pt;"  &gt; The next stop on the tour is Uruguay on 7/26/2011.  Mateo is estimating over 120 attendees (although they will need to sign up still&lt;span class="apple-converted-space"&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style=";font-family:Wingdings;font-size:11pt;"  &gt;J&lt;/span&gt;&lt;span style=";font-family:&amp;quot;;font-size:11pt;"  &gt;)  of the 8 registered for the upcoming training day, 6 have signed up for membership!&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;span style=";font-family:&amp;quot;;font-size:11pt;"  &gt;Brazil and Peru are scheduled for August, so I will provide updates as we get closer.&lt;/span&gt;&lt;/p&gt;        &lt;p class="MsoNormal"&gt;&lt;span style=";font-family:&amp;quot;;font-size:11pt;"  &gt;&lt;a href="https://picasaweb.google.com/fcerullo/OWASPLatamTour?authuser=0&amp;amp;feat=directlink"&gt;https://picasaweb.google.com/fcerullo/OWASPLatamTour?authuser=0&amp;amp;feat=directlink&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-997088407872127918?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/997088407872127918/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/07/owasp-latam-tour.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/997088407872127918'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/997088407872127918'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/07/owasp-latam-tour.html' title='OWASP LATAM Tour'/><author><name>Kate Hartmann</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-1410135622840022405</id><published>2011-07-20T23:49:00.001-07:00</published><updated>2011-07-20T23:49:41.077-07:00</updated><title type='text'>AppSec Asia 2011</title><content type='html'>&lt;div class="moz-text-html" lang="x-western"&gt;&lt;div class="WordSection1"&gt;&lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size:20.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;color:black"&gt;AppSec Asia 2011&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;;color:black"&gt;Building  on its successes of the past two years, OWASP’s China chapter is again  hosting a flagship OWASP outreach event in Beijing, China.   The &lt;b&gt;Global AppSec Asia 2011&lt;/b&gt;  will be held from November 8 to 11, 2011.  This event offers expo,  training and conferences and includes many opportunities to converse  with the government, industry and education leaders from China and the  entire Asia Pacific region.&lt;br /&gt;&lt;br /&gt;If you are interested in speaking at  the conference (November 8 to 9, 2011) or a training session (November  10 to 11, 2011) then please submit your proposal &lt;a href="https://www.owasp.org/index.php/OWASP_Global_AppSec_Asia_2011#tab=CFP_and_CFT" target="_blank"&gt;&lt;span style="color:blue"&gt;here&lt;/span&gt;&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;If  your company or other companies you know are interested in reaching out  to the vast and growing Asia Pacific market then please contact &lt;a href="mailto:helen.gao@owasp.org" target="_blank"&gt;&lt;span style="color:blue"&gt;Helen Gao&lt;/span&gt;&lt;/a&gt; &lt;a href="tel:%28516-582-4943" target="_blank"&gt;&lt;span style="color:blue"&gt;(516-582-4943&lt;/span&gt;&lt;/a&gt;).  The sponsorship document can be downloaded &lt;a href="https://www.owasp.org/images/2/24/OWASP_China2011_Sponsorship.pdf" target="_blank"&gt;&lt;span style="color:blue"&gt;here&lt;/span&gt;&lt;/a&gt;.  If you are interested in the product exhibit then please let Helen know by July 31, 2011.&lt;br /&gt;&lt;br /&gt;Thank you very much for your support.&lt;i&gt;&lt;br /&gt;&lt;br /&gt;&lt;/i&gt;&lt;/span&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;u&gt;&lt;span style="font-size:20.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;OWASP AppSec USA 2011&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt; &lt;/span&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;AppSec  USA 2011 is a conference for information security and software  development professionals who are challenged with solving tough  application security problems. This year's format will be eight tracks  spread across two days, with each talk running 50 minutes in length.   Speakers are just being announced. For more details: &lt;a href="http://www.appsecusa.org/"&gt;&lt;span style="color:purple"&gt;www.appsecusa.org&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-indent:.25in"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="text-indent:.25in"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;The tracks are:  &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:.5in;text-indent:-.25in"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;·         &lt;/span&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Cloud Security&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:.5in;text-indent:-.25in"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;·         &lt;/span&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Mobile Security&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:.5in;text-indent:-.25in"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;·         &lt;/span&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Secure SDLC&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:.5in;text-indent:-.25in"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;·         &lt;/span&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;OWASP Projects&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:.5in;text-indent:-.25in"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;·         &lt;/span&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;New Attacks &amp;amp; Defenses&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:.5in;text-indent:-.25in"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;·         &lt;/span&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Thought Leadership&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:.5in;text-indent:-.25in"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;·         &lt;/span&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Software &amp;amp; Architecture Patterns for Security&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:.5in;text-indent:-.25in"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;·         Software Assurance&lt;/span&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal" style="margin-left:.5in"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt; &lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;AppSec USA’s early bird discount ends: 7/29/11&lt;/span&gt;&lt;/b&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt; so  register now: &lt;a href="http://www.regonline.com/Register/Checkin.aspx?EventID=935213"&gt;&lt;span style="color:purple"&gt;http://www.regonline.com/Register/Checkin.aspx?EventID=935213&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;span style="font-size:12.0pt;font-family:&amp;quot;Times New Roman&amp;quot;,&amp;quot;serif&amp;quot;"&gt;Follow us on twitter @appsecusa,  our linked in group,  or on facebook and check the &lt;a href="http://www.appsecusa.org/"&gt;&lt;span style="color:purple"&gt;www.appsecusa.org&lt;/span&gt;&lt;/a&gt;  site often for updates we’ll be announcing an Open Source Project demo  area, a University CTF Challenge, Thursday evening networking event and  more! We also have several events already listed: &lt;span style="color:#FF0080"&gt;&lt;a href="http://www.appsecusa.org/womeninappsec.html"&gt;&lt;span style="color:blue"&gt;Women in AppSec&lt;/span&gt;&lt;/a&gt; | &lt;a href="http://www.appsecusa.org/strengthen.html"&gt;&lt;span style="color:blue"&gt;5K/10K&lt;/span&gt;&lt;/a&gt; | &lt;a href="http://www.appsecusa.org/deepcuts.html"&gt;&lt;span style="color:blue"&gt;CR0WD50URC3D&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;Kate Hartmann&lt;/p&gt;&lt;p class="MsoNormal"&gt;Operations Director&lt;/p&gt;&lt;p class="MsoNormal"&gt;301-275-9403&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;a href="http://www.owasp.org/"&gt;www.owasp.org&lt;/a&gt; &lt;/p&gt;&lt;p class="MsoNormal"&gt;Skype:  Kate.hartmann1&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;/p&gt;&lt;/div&gt; &lt;/div&gt;&lt;br /&gt;&lt;fieldset class="mimeAttachmentHeader"&gt;&lt;/fieldset&gt;&lt;br /&gt;&lt;div class="moz-text-plain" wrap="true" style="font-family: -moz-fixed; font-size: 12px;" lang="x-western"&gt;&lt;pre wrap=""&gt;_______________________________________________ To unsubscribe from the Owasp-all mailing list, you will need to unsubscribe yourself from all OWASP mailing lists you belong too. This list is automatically generated to allow OWASP to contact all it’s members in one distribution.   Best regards, OWASP&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-1410135622840022405?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/1410135622840022405/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/07/appsec-asia-2011.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1410135622840022405'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1410135622840022405'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/07/appsec-asia-2011.html' title='AppSec Asia 2011'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-8980559299779953311</id><published>2011-07-17T16:01:00.000-07:00</published><updated>2011-07-17T16:03:35.439-07:00</updated><title type='text'>ESAPI for C++</title><content type='html'>(from Kevin Wall)&lt;br /&gt;&lt;br /&gt;&lt;pre wrap=""&gt;There's a new mailing list on the OWASP ESAPI block at: &lt;a class="moz-txt-link-freetext" href="https://lists.owasp.org/mailman/listinfo/owasp-esapi-c++"&gt;https://lists.owasp.org/mailman/listinfo/owasp-esapi-c++&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Yes, that's right. ESAPI for C++. Well, spare me the oxymoron jokes (my resemblance to an ox and an moron is strictly coincidence)...and besides that was my first reaction as well. &lt;br /&gt;&lt;br /&gt;ESAPI for C++ will be a &lt;b class="moz-txt-star"&gt;&lt;span class="moz-txt-tag"&gt;*&lt;/span&gt;greatly&lt;span class="moz-txt-tag"&gt;*&lt;/span&gt;&lt;/b&gt; stripped down version of ESAPI for JavaEE. The intent will be more similar to ESAPI for C (yes, Virginia, there's one of those too; see &lt;a class="moz-txt-link-freetext" href="http://code.google.com/p/owasp-esapi-c/"&gt;http://code.google.com/p/owasp-esapi-c/&lt;/a&gt;). &lt;br /&gt;&lt;br /&gt;So sign up for the OWASP ESAPI for C++ mailing list. Even though it's mostly intended for developers, we welcome hecklers and other nay sayers as well. (Keeps us from getting too many "yes men" that way.) &lt;br /&gt;&lt;br /&gt;Or better yet, sign up, and then get involved. Yes sir (or ma'am). ESAPI for C++ is your chance to become rich and famous. OK, just famous. Hmm, maybe not. But it is a chance for all of you, who like me just sat out there for years using FOSS but without every contributing anything back. (No, those 3 patches that you submitted 7 years ago and that $10 donation to GNU's Free Software Foundation are not enough to make up for all the free software that you've used over the years. C'mon, you tip your barber more than that!) &lt;br /&gt;&lt;br /&gt;Uncle OWASP wants you! &lt;br /&gt;-kevin wall &lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-8980559299779953311?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/8980559299779953311/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/07/esapi-for-c.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8980559299779953311'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8980559299779953311'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/07/esapi-for-c.html' title='ESAPI for C++'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4074540080029800679</id><published>2011-07-11T15:10:00.000-07:00</published><updated>2011-07-11T15:14:50.024-07:00</updated><title type='text'>OWASP New Zealand Day 2011 Wrap-up</title><content type='html'>&lt;div&gt;(from Nick Freeman &amp;amp; Scott Bell)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Dear OWASP Leaders,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This email is a brief wrap-up of how the OWASP New Zealand Day 2011 conference went on Thursday July 7.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The conference was a great success, with a 33% increase in attendance from previous years. We had just over 200 people attend our single track, 10 talk conference and two training sessions.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This shows a growing interest in web application security in New Zealand, and we will be pushing the attendees to attend chapter meetings and spread the word about OWASP with their friends, colleagues and other industry groups. We have had a great response from a number of development groups who are interested in having OWASP content presented at their meetings, which we see as an excellent opportunity to expand the OWASP community and web application security awareness in New Zealand.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Feedback from conference attendees has been glowing, with very positive comments and some constructive suggestions. We are still dissecting it all, and will be combining the feedback with our own learnt lessons to ensure future chapter meetings and OWASP NZ Day conferences get better and better.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We'd like to give a very big thanks to Kate Hartmann, Sarah Baso, Mark Bristow, Alison Shrader and everyone else who has helped us organise the conference and make it the success that it was. Special thanks also go out to Roberto Suggi Liverani, previous OWASP NZ Chapter Leader, who organised the previous two OWASP day conferences and has helped OWASP New Zealand grow to its current size.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Final thanks go to our sponsors; The University of Auckland Business School, Security-Assessment.com, Lateral Security, F5 and Aura Information Security. Their generous donations allowed us to keep OWASP New Zealand Day a free conference in an excellent venue with quality catering.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Most content from the conference is already posted on the OWASP New Zealand Day 2011 conference wiki page (https://www.owasp.org/index.php/OWASP_New_Zealand_Day_2011) - we will be uploading the remaining content in the next day or two. In the mean time, a celebratory whisky or two is in order :)&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kind Regards&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Nick Freeman &amp;amp; Scott Bell&lt;/div&gt;&lt;div&gt;OWASP New Zealand Chapter Leaders&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4074540080029800679?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4074540080029800679/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/07/nz.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4074540080029800679'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4074540080029800679'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/07/nz.html' title='OWASP New Zealand Day 2011 Wrap-up'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-636355422010043083</id><published>2011-07-10T13:52:00.000-07:00</published><updated>2011-07-10T13:53:43.520-07:00</updated><title type='text'>OWASP Global AppSec Asia 2011</title><content type='html'>&lt;div&gt;Dear OWASP Chapter leaders,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt; &lt;div&gt; &lt;/div&gt; &lt;div&gt;Greetings!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt; &lt;div&gt; &lt;/div&gt; &lt;div&gt;I am Rip , Chairman of OWASP China. OWASP China invites you to join OWASP Global AppSec Asia 2011 conference. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt; &lt;div&gt; &lt;/div&gt; &lt;div&gt;This AppSec Asia 2011 offers expo,conferences and trainings. Over  500 people attended the conference last year, representing organizations  including: Huawei, Alibaba.com, Baidu, China Telecom,  China Mobile,   China Merchants Bank,  Shenzhen Stock Exchange,  Ping An Insurance  Group,  Chinese Ministry of Industry and Information Technology,   Chinese Ministry of Commerce, Forrester Research,Inc.,  Chinese Academy  of Sciences.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;  &lt;div&gt; &lt;/div&gt; &lt;div&gt;AppSec Asia 2011 is not just a conference for mainland China, it is  also for Hong Kong, Taiwan, Singapore, India, Malaysia, Indonesia,  Japan and all Asian countries.We plan to add a product exposition this  year. Please introduce this opportunity to companies in your country. As  a matter of fact, in order to encourage you to participate, the  conference committee has decided to reimburse your travel expenses if  your chapter brings in two qualified sponsors. Please see attached for  sponsorship details. And English interpretation will be provided for the  entire conference.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;  &lt;div&gt; &lt;/div&gt; &lt;div&gt;For more information, please see &lt;a href="https://www.owasp.org/index.php/China_AppSec_2011" target="_blank"&gt;OWASP Website&lt;/a&gt;.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt; &lt;div&gt; &lt;/div&gt; &lt;div&gt;If you have any questions, please fee free to contact:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt; &lt;div&gt;Rip: &lt;a href="mailto:Rip@owasp.org"&gt;Rip@owasp.org&lt;/a&gt;&lt;/div&gt; &lt;div&gt;Helen: &lt;a href="mailto:helen.gao@owasp.org" target="_blank"&gt;helen.gao@owasp.org&lt;/a&gt; &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt; &lt;div&gt; &lt;/div&gt; &lt;div&gt;Thank you and Best Regards!&lt;br /&gt;&lt;br /&gt;-- &lt;/div&gt; &lt;div&gt;RIP    OWASP中国   &lt;/div&gt; &lt;div&gt; &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-636355422010043083?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/636355422010043083/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/07/owasp-global-appsec-asia-2011.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/636355422010043083'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/636355422010043083'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/07/owasp-global-appsec-asia-2011.html' title='OWASP Global AppSec Asia 2011'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-5280804444674421854</id><published>2011-07-07T19:06:00.000-07:00</published><updated>2011-07-07T19:07:23.208-07:00</updated><title type='text'>US and Canadian Chapter Leader Workshop</title><content type='html'>(From &lt;a href="mailto:tin.zaw@owasp.org"&gt;tin.zaw@owasp.org&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;Dear Fellow Chapter Leaders,&lt;br /&gt;&lt;br /&gt;Global Chapter Committee invites you to US and Canadian Chapter Leader Workshop at AppSec USA 2011, in Minneapolis. The workshop will be on September 21, from noon to 3:00PM. Its format will be based on the successful chapter workshop at AppSec EU in Dublin, earlier this year.&lt;br /&gt;&lt;br /&gt;While we are still working on the agenda, it will closely resemble the agenda at AppSec EU. It will include review of the chapter handbook, managing chapter finances, Top 10 advice, and how to cross-pollinate and cooperate among  chapters. EU event's agenda can be seen below.&lt;br /&gt;&lt;br /&gt;https://www.owasp.org/index.php/AppSecEU_2011_chapters_workshop_agenda&lt;br /&gt;&lt;br /&gt;We strongly encourage you to participate in this opportunity. Chapter leaders are encouraged to use chapter funds for the travel. Chapter leaders will get a free admission to the conference. The committee has limited funds available for chapter leaders with limited chapter funds.&lt;br /&gt;&lt;br /&gt;We would like to ask the following.&lt;br /&gt;&lt;br /&gt;   * Save the date, September 21, 2011, from noon to 3:00PM, for the workshop.&lt;br /&gt;   * Register for AppSec USA event. Ask Lorna Alamri for registration code.&lt;br /&gt;   * Start making travel arrangements -- hotel rooms are running out -- if your chapter has funds available.&lt;br /&gt;   * If needed, ask for funding by emailing me and Sarah Baso, administrator for the chapter committee.&lt;br /&gt;   * Start thinking what topics to discuss.&lt;br /&gt;   * Stay tuned to further emails and upcoming Wiki page.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;A word about funding. While we wish we could fund every chapter leader, due to the limited amount of budget allocated for this event, we may not be able to fund 100% to all the requests. We will have a deadline for applying funding, and after that deadline, we will make funding decision in a fair and transparent manner. When you apply for funding, please highlight your past contributions to OWASP and your future plans for the local chapter and OWASP.&lt;br /&gt;&lt;br /&gt;We will try to have an option to participate, via Skype, for those who cannot make it.&lt;br /&gt;&lt;br /&gt;If any questions, please email us. tin.zaw@owasp.org&lt;br /&gt;&lt;br /&gt;Best regards,&lt;br /&gt;Tin&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-5280804444674421854?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/5280804444674421854/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/07/us-and-canadian-chapter-leader-workshop.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5280804444674421854'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5280804444674421854'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/07/us-and-canadian-chapter-leader-workshop.html' title='US and Canadian Chapter Leader Workshop'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-2682653503348190303</id><published>2011-07-05T14:27:00.001-07:00</published><updated>2011-07-05T14:28:01.062-07:00</updated><title type='text'>OWASP Gothenburg</title><content type='html'>(posted by Ulf Larson)&lt;br /&gt;&lt;br /&gt;Dear Leaders!&lt;br /&gt;&lt;br /&gt;It is my pleasure to announce the birth of OWASP Gothenburg!&lt;br /&gt;&lt;br /&gt;OWASP Gothenburg is the second chapter to start in Sweden, some four years after the start of OWASP Sweden. Gothenburg is situated on the west coast of Sweden. Gothenburg has a large port and is also a well known player in the automotive area (Volvo, for example). Furthermore, Gothenburg is home to Chalmers University, a (hopefully) well known education facility with several strong research groups. We also have Liseberg (a large and pretty much awesome amusement park in the center of the city) which is well worth a visit if you happen to pass through.&lt;br /&gt;&lt;br /&gt;We (board members, leaders, in total six persons) met for the first time in the beginning of May this year. Discussing, not if, but how, we would go about creating a chapter. We have since had lots of help from John Wilander, Kate Hartmann, and to our great pleasure, Jason Alexander, who heard our twitter call for assistance!&lt;br /&gt;&lt;br /&gt;The board and leaders have mixed backgrounds from academia and industry but with the common denominator of application security. The leaders are Jonas Magazinius, Mattias Jidhage, and Ulf Larson. Jonas is a Ph.D. student at Chalmers University, researching on application security, most recently in the context of web mash-ups. Mattias has a master's degree from Chalmers University. He currently works at Omegapoint AB as security specialist/project manager focusing on application security. Ulf has a Ph.D. from Chalmers University. He currently works as a security specialist/systems developer at Adecco IT Konsult.&lt;br /&gt;&lt;br /&gt;That's it. It is a pleasure for us to enter the OWASP community, and I hope we meet once or twice in the future!&lt;br /&gt;&lt;br /&gt;Best regards&lt;br /&gt;&lt;br /&gt;OWASP Gothenburg chapter through Ulf Larson&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-2682653503348190303?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/2682653503348190303/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/07/owasp-gothenburg.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2682653503348190303'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2682653503348190303'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/07/owasp-gothenburg.html' title='OWASP Gothenburg'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-634975528908992227</id><published>2011-06-24T12:47:00.000-07:00</published><updated>2011-06-24T12:49:15.953-07:00</updated><title type='text'>Board Election Update</title><content type='html'>&lt;style type="text/css"&gt; p.p1 {margin: 0.0px 0.0px 12.0px 0.0px; font: 12.0px Helvetica} p.p2 {margin: 0.0px 0.0px 12.0px 0.0px; font: 12.0px Helvetica; color: #1923fb} p.p3 {margin: 0.0px 0.0px 12.0px 0.0px; font: 12.0px Times} p.p4 {margin: 0.0px 0.0px 12.0px 0.0px; font: 12.0px Times; color: #1720ee} span.s1 {color: #000000} span.s2 {text-decoration: underline} &lt;/style&gt;   &lt;p class="p1"&gt;Attention OWASP Community,&lt;/p&gt; &lt;p class="p1"&gt;Daily we learn of malicious hackers in the news - software security has never been more important to consumers, businesses,  governments or students.&lt;/p&gt; &lt;p class="p1"&gt;We trust that you have found valuable resources at OWASP Foundation in forms of guides, tools, resources and a professional community of over 25,000 worldwide - thank you.&lt;/p&gt; &lt;p class="p1"&gt;As we continue to evolve our professional association,  OWASP is hosting it's second election of its International Board of Directors. This year, three (3) of six board seats are up for election for a twenty-four month term and details of the process and candidates can be found online at:&lt;/p&gt; &lt;p class="p2"&gt;&lt;span class="s1"&gt;CLICK ON:    &lt;a href="https://www.owasp.org/index.php/Membership/2011Election"&gt;https://www.owasp.org/index.php/Membership/2011Election&lt;/a&gt;&lt;/span&gt;&lt;/p&gt; &lt;p class="p1"&gt;Who will you support?&lt;/p&gt; &lt;p class="p1"&gt;Thank you in advance for your continued support.&lt;/p&gt; &lt;p class="p1"&gt;On behalf of the OWASP Foundation.&lt;/p&gt; &lt;p class="p3"&gt;Kate Hartmann&lt;br /&gt;Operations Director&lt;br /&gt;301-275-9403&lt;br /&gt;&lt;span class="Apple-style-span" style="color: rgb(23, 32, 238); "&gt;&lt;span class="s2"&gt;&lt;a href="http://www.owasp.org/"&gt;www.owasp.org&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;Skype:  Kate.hartmann1&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-634975528908992227?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/634975528908992227/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/06/board-election-update.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/634975528908992227'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/634975528908992227'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/06/board-election-update.html' title='Board Election Update'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-184148080316829429</id><published>2011-06-24T07:03:00.000-07:00</published><updated>2011-06-24T07:05:37.797-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='owasp election'/><title type='text'>Election of Officers @ OWASP</title><content type='html'>OWASP Community,&lt;br /&gt;&lt;br /&gt;Daily we learn of malicious hackers in the news - software security has never been more important to consumers, businesses, governments or students.&lt;br /&gt;&lt;br /&gt;We trust that you have found valuable resources at OWASP Foundation in forms of guides, tools, resources and a professional community of over 25,000 worldwide - thank you.&lt;br /&gt;&lt;br /&gt;As we continue to evolve our professional association,  OWASP is hosting its second election of its International Board of Directors. This year, three (3) of six board seats are up for election for a twenty-four month term and details of the process and candidates can be found online&lt;br /&gt;&lt;br /&gt;CLICK ON: &lt;a href="https://www.owasp.org/index.php/Membership/2011Election"&gt;    https://www.owasp.org/index.php/Membership/2011Election&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Who will you support?&lt;br /&gt;&lt;br /&gt;Thank you in advance for your continued support.&lt;br /&gt;&lt;br /&gt;On behalf of the OWASP Foundation.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-184148080316829429?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/184148080316829429/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/06/election-of-officers-owasp.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/184148080316829429'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/184148080316829429'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/06/election-of-officers-owasp.html' title='Election of Officers @ OWASP'/><author><name>Tom Brennan</name><uri>http://www.blogger.com/profile/07303005472675953158</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-2381477636208177038</id><published>2011-06-21T16:55:00.000-07:00</published><updated>2011-06-21T17:01:34.244-07:00</updated><title type='text'>Attention Chapter Leaders</title><content type='html'>&lt;pre wrap=""&gt;&lt;span class="Apple-style-span" style="font-family: Courier; font-size: 16px; "&gt;Attention Chapter Leaders!&lt;/span&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Chapter"&gt;https://www.owasp.org/index.php/OWASP_Chapter&lt;/a&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;The goal of the Chapter Leader mailing list is to:&lt;p class="p1"&gt;&lt;/p&gt;&lt;ol&gt;&lt;li&gt;To exchange chapter leader experience&lt;/li&gt;&lt;li&gt;To ask questions (and hopefully get responses) on chapter topics&lt;/li&gt;&lt;li&gt;To announce chapter related topics&lt;/li&gt;&lt;/ol&gt;&lt;p&gt;&lt;/p&gt;&lt;p class="p2"&gt;There already are a lot of resources available:&lt;/p&gt;&lt;a href="https://www.owasp.org/index.php/Category:Chapter_Resources"&gt;https://www.owasp.org/index.php/Category:Chapter_Resources&lt;/a&gt;&lt;br /&gt;&lt;p class="p2"&gt;There is a chapter leader handbook:&lt;/p&gt;&lt;a href="https://www.owasp.org/index.php/Chapter_Leader_Handbook"&gt;https://www.owasp.org/index.php/Chapter_Leader_Handbook&lt;/a&gt;&lt;br /&gt;&lt;p class="p2"&gt;But all of this material can and should be further improved to enable you - as chapter leader - in creating and maintaining our community.&lt;/p&gt;If you need help: ask your question on the mailing list.&lt;p class="p2"&gt;If you have some spare time: start building a chapter leaders FAQ as part of the chapter leaders handbook.&lt;/p&gt;&lt;p class="p1"&gt;Regards,&lt;/p&gt;&lt;p class="p1"&gt;Seba&lt;/p&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-2381477636208177038?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/2381477636208177038/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/06/attention-chapter-leaders.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2381477636208177038'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2381477636208177038'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/06/attention-chapter-leaders.html' title='Attention Chapter Leaders'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-410258703857492587</id><published>2011-06-17T00:21:00.000-07:00</published><updated>2011-06-17T00:23:09.977-07:00</updated><title type='text'>CFP OWASP AppSec LATAM and Partner event, Rochester Security Summit</title><content type='html'>&lt;div class="WordSection1"&gt;&lt;p class="MsoNormal"&gt;Colleagues,&lt;/p&gt;&lt;p class="MsoNormal"&gt;OWASP  is currently soliciting presentations for the OWASP AppSec Latam 2011  Conference that will take place at PUC-RS in Porto Alegre, RS, Brazil on  October 4th through 7th, 2011.  There will be training courses on  October 4th and 5th followed by plenary sessions on the 6th and 7th with  each day having one single track.&lt;/p&gt;&lt;p class="MsoNormal"&gt;We  are seeking people and organizations that want to present on any of the  following topics (in no particular order), or any other topics related  to application security:&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Application Threat Modeling&lt;/li&gt;&lt;li&gt;Business Risks with Application Security&lt;/li&gt;&lt;li&gt;Hands-on Source Code Review&lt;/li&gt;&lt;li&gt;Metrics for Application Security&lt;/li&gt;&lt;li&gt;OWASP Tools and Projects&lt;/li&gt;&lt;li&gt;Privacy Concerns with Applications and Data Storage&lt;/li&gt;&lt;li&gt;Secure Coding Practices (J2EE/.NET)&lt;/li&gt;&lt;li&gt;Starting and Managing Secure Development Lifecycle Programs&lt;/li&gt;&lt;li&gt;Technology specific presentations on security such as AJAX, XML, etc&lt;/li&gt;&lt;li&gt;Web Application Security countermeasures&lt;/li&gt;&lt;li&gt;Web Application Security Testing&lt;/li&gt;&lt;li&gt;Web Services-, XML- and Application Security&lt;/li&gt;&lt;li&gt;Anything else relating to OWASP and Application Security&lt;/li&gt;&lt;/ul&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;To make a submission you must fill out the form available at &lt;a href="https://www.owasp.org/images/e/e4/OWASP_AppSec_Latam_2011_CFP.rtf.zip"&gt;https://www.owasp.org/images/e/e4/OWASP_AppSec_Latam_2011_CFP.rtf.zip&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;and submit through the easychair conference interface at &lt;a href="http://www.easychair.org/conferences/?conf=appseclatam2011"&gt;http://www.easychair.org/conferences/?conf=appseclatam2011&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Each  presenter will have 45 minutes for the presentation, followed by 10  minutes reserved for questions from the audience. The presentations must  respect the restrictions of the OWASP Speaker Agreement.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;b&gt;Important Dates&lt;o:p&gt;&lt;/o:p&gt;&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoListParagraphCxSpFirst" style="text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style=""&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Submission deadline is July 18, 2011 at 11:59 PM (UTC/GMT -3).&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoListParagraphCxSpMiddle" style="text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style=""&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Notification of acceptance is August 5, 2011.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoListParagraphCxSpLast" style="text-indent: -0.25in;"&gt;&lt;!--[if !supportLists]--&gt;&lt;span style="font-family: Symbol;"&gt;&lt;span style=""&gt;·&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;         &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;!--[endif]--&gt;Presentation slides are due September 19, 2011.&lt;/p&gt;&lt;p class="MsoNormal"&gt;The conference organization team may be contacted by email at appsec2011 (at) appseclatam.org&lt;/p&gt;&lt;p class="MsoNormal"&gt;For more information, please see the following web pages:&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Conference Website: &lt;a href="https://www.appseclatam.org/"&gt;https://www.appseclatam.org&lt;/a&gt; or &lt;a href="http://www.owasp.org/index.php/AppSecLatam2011"&gt;http://www.owasp.org/index.php/AppSecLatam2011&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;OWASP Speaker Agreement: &lt;a href="http://www.owasp.org/index.php/Speaker_Agreement"&gt;http://www.owasp.org/index.php/Speaker_Agreement&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;OWASP Website: &lt;a href="http://www.owasp.org/"&gt;http://www.owasp.org&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Easychair conference site: &lt;a href="http://www.easychair.org/conferences/?conf=appseclatam2011"&gt;http://www.easychair.org/conferences/?conf=appseclatam2011&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Presentation proposal form: &lt;a href="https://www.owasp.org/images/e/e4/OWASP_AppSec_Latam_2011_CFP.rtf.zip"&gt;https://www.owasp.org/images/e/e4/OWASP_AppSec_Latam_2011_CFP.rtf.zip&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;*** CALL FOR PRESENTATIONS ***&lt;/p&gt;&lt;p class="MsoNormal"&gt;Rochester Security Summit October 4th-5th, 2011 Rochester, NY &lt;a href="http://rochestersecurity.org/"&gt;http://RochesterSecurity.org&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;We  are pleased to announce that the sixth annual Rochester Security Summit  is being planned for October 4-5, 2011 in Rochester, NY at the  beautiful and totally renovated Hyatt Regency Rochester. This year’s  theme is “Security Sanity” with Marcus J. Ranum as our keynote speaker.  The Rochester Security Summit is the premiere IT security event in  Upstate/Western NY.&lt;/p&gt;&lt;p class="MsoNormal"&gt;In  2010 the Rochester Security Summit gathered more than 200 attendees,  including executives from Fortune 500 firms, information security  professionals, auditors, developers and software architects.  We had 26  outstanding presentations, a sold-out Capture the Flag (a.k.a. Ethical  Hacking 101) event and an extremely well received end panel with  representatives of the 3 sponsoring organizations, ISSA, ISACA and  OWASP.&lt;/p&gt;&lt;p class="MsoNormal"&gt;The  Rochester Security Summit is currently soliciting presentations from  researchers, academia and industry for the 3 main tracks: Business  Professional, Technical Professional and Software Professional. If you  believe you have a significant research or technical presentation that  the security community would value and enjoy hearing, we invite you to  submit your presentation topic for consideration.&lt;/p&gt;&lt;p class="MsoNormal"&gt;All  three tracks will consist of presentations in 50-minute blocks,  including Q&amp;amp;A. Presentations may be allowed to span two blocks to  accommodate topic exploration to different depths if the committee sees  the merit in the longer time allotment.&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Please submit your proposal before June 30th&lt;/li&gt;&lt;li&gt;We will respond to proposals by July 30th&lt;/li&gt;&lt;li&gt;Draft copy of the slides for the papers must be submitted by August 26th&lt;/li&gt;&lt;li&gt;Final submissions are due by September 23rd&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Please review the speaker guidelines on the web site, &lt;a href="http://rochestersecurity.org/speakers/speaker-guidelines.html"&gt;http://rochestersecurity.org/speakers/speaker-guidelines.html&lt;/a&gt; before submitting a proposal.&lt;/p&gt;&lt;p class="MsoNormal"&gt;Proposals may be submitted via e-mail to &lt;a href="mailto:present2011@rochestersecurity.org"&gt;present2011@rochestersecurity.org&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Summit  attendees are a mix of technical security professionals, vendors,  programmers, web application developers, security testers, students,  network administrators and IT executives. Preference will be given to  speakers who can present innovative technical content to a broad  technical audience. Of course, all presentations are expected to  challenge the brightest and quickest of attendees.&lt;/p&gt;&lt;p class="MsoNormal"&gt;The  Rochester Security Summit is not a vendor fest.  There is zero  tolerance for heavy commercial content in presentations. Presenters are  expected to avoid any marketing that is not immediately backed up with  rationale for its inclusion.&lt;/p&gt;&lt;p class="MsoNormal"&gt;Proposals should consist of the following information:&lt;/p&gt;&lt;p class="MsoNormal"&gt;1. Presenter and contact info (country of origin and residence-mail, postal address, phone, fax).&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;2. Employer and/or affiliations.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;3. Brief biography, list of publications and papers.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;4. Any significant presentation and educational experience/background.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;5. Topic synopsis, proposed paper title, and a one paragraph description.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;6. Reason why this material is innovative or significant or an important tutorial.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;7. Optionally, any samples of prepared material or outlines ready.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;8. Will you have full text available or only slides?&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;9. Please list any other publications or conferences where this material has been or will be published or submitted.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;10.  If you think a second 50-minute block will be required to do your topic  justice, please let us know and give a rationale for the longer format.&lt;/p&gt;&lt;p class="MsoNormal"&gt;Please include the plain text version of this information in your email as well as any file, pdf, sxw, ppt, or html attachments.&lt;/p&gt;&lt;p class="MsoNormal"&gt;Please forward the above information to &lt;a href="mailto:present2011@rochestersecurity.org"&gt;present2011@rochestersecurity.org&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;For more event information, or to register, visit us online at &lt;a href="http://rochestersecurity.org/"&gt;http://rochestersecurity.org/&lt;/a&gt;.&lt;/p&gt;&lt;p class="MsoNormal"&gt;Thank you,&lt;/p&gt;&lt;p class="MsoNormal"&gt;Rochester Security Summit Organizing Committee&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;Kate Hartmann&lt;/li&gt;&lt;li&gt;Operations Director&lt;/li&gt;&lt;li&gt;301-275-9403&lt;/li&gt;&lt;li&gt;&lt;a href="http://www.owasp.org/"&gt;www.owasp.org&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Skype:  Kate.hartmann1&lt;/li&gt;&lt;/ul&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-410258703857492587?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/410258703857492587/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/06/cfp-owasp-appsec-latam-and-partner.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/410258703857492587'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/410258703857492587'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/06/cfp-owasp-appsec-latam-and-partner.html' title='CFP OWASP AppSec LATAM and Partner event, Rochester Security Summit'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4398244746113156960</id><published>2011-06-16T20:15:00.000-07:00</published><updated>2011-06-17T00:17:26.169-07:00</updated><title type='text'>OWASP iGoat 1.0</title><content type='html'>&lt;div class="moz-text-plain" wrap="true" quote="true" lang="x-western"&gt;&lt;pre wrap=""&gt;(From Ken van Wyk)&lt;/pre&gt;&lt;pre wrap=""&gt;Greetings all.&lt;/pre&gt;&lt;pre wrap=""&gt;Yesterday, we put out the first public release of the OWASP iGoat project. This message is a brief description and call for participants in the project.  &lt;/pre&gt;&lt;pre wrap=""&gt;&lt;b&gt;Background  &lt;/b&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;The iGoat tool is a learning tool, primarily meant for iOS developers (but also useful to IT security practitioners, security architects, and others who simply want to learn about iOS security). It takes its name and inspiration from the venerable OWASP WebGoat tool. Like WebGoat, iGoat users explore a number of security weaknesses in iOS by exploiting  them first. Then, once each weakness has been explored, the iGoat user must implement a remediation to protect against each weakness and validate that the remediation was successful--similar to the WebGoat Developer Edition.  Hints and other background information are provided, right down to commented solutions in the source code, so that developers can use iGoat as a self-study learning tool to explore and understand iOS weaknesses and how to avoid them.  Further, the iGoat platform was specifically designed and built to be as easily extensible as possible, so that new exercises can be easily built and integrated over time.  iGoat was sponsored and initially developed by KRvW Associates, LLC (www.krvw.com), and is being released under GPLv3 licensing to the community.  &lt;/pre&gt;&lt;pre wrap=""&gt;&lt;b&gt;Status &lt;/b&gt; &lt;/pre&gt;&lt;pre wrap=""&gt;With the first public release, we've included several initial exercises and exercise  categories. These include such well known topics as SQL Injection, secure communications, etc. We plan to further integrate another handful of exercises in the short term, as well as make several improvements to the user interface. In the short term, we'll also be adding more documentation in the form of HOWTO documents that will cover how to install and use iGoat, as well as how to add new exercises to it.  No doubt, further improvements will quickly surface as the community starts using the   tool...  &lt;/pre&gt;&lt;pre wrap=""&gt;&lt;b&gt;Project Site  &lt;/b&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;iGoat can be found at: &lt;a href="https://www.owasp.org/index.php/OWASP_iGoat_Project"&gt;https://www.owasp.org/index.php/OWASP_iGoat_Project&lt;/a&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;All releases and source code are on Google Code. See the project home page above for   further details.  Call for Participation  The iGoat team would like to invite anyone interested to participate and contribute to iGoat's further development. Please contact the project leader, Ken van Wyk (ken@krvw.com) if you wish to contribute to the project.&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;b&gt;Mailing List  &lt;/b&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;An open, unmoderated forum has been set up for the iGoat project. To subscribe, see &lt;a href="https://lists.owasp.org/mailman/listinfo/owasp-igoat-project"&gt;https://lists.owasp.org/mailman/listinfo/owasp-igoat-project&lt;/a&gt; &lt;/pre&gt;&lt;pre wrap=""&gt;Cheers, Ken &lt;span class="Apple-style-span"&gt; &lt;/span&gt;&lt;/pre&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4398244746113156960?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4398244746113156960/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/06/owasp-igoat-10.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4398244746113156960'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4398244746113156960'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/06/owasp-igoat-10.html' title='OWASP iGoat 1.0'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-8260352656812061221</id><published>2011-06-15T09:44:00.000-07:00</published><updated>2011-06-15T09:46:41.080-07:00</updated><title type='text'>Question on 3rd party JS</title><content type='html'>Question: How do you best use external JavaScripts and comply with PCI-DSS (from @joffemannen)&lt;br /&gt;&lt;br /&gt;(Great answer from @johnwilander)&lt;br /&gt;&lt;br /&gt;I've had more than one consultation on this issue and we've always had  to start by explaining the full access and full trust model of loading  3rd party code and content. To start with there's an important  distinction between loading a 3rd party code library such as jQuery, and  loading DOM content with or without JavaScript. If they want DOM  content then traditional iframing works fine until they want to interact  with the 3rd party content or vice versa. Since they will be loaded  from different domains they will not be able to access each other.&lt;br /&gt;&lt;br /&gt;If they want interaction they have four ways ahead:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Hosted + controlled releases&lt;/b&gt;.  Establish a B2B release cycle with the vendor in which new versions of  script files are released to them via file transfer and not directly  into production. Then they do whatever auditing and analysis their  process requires and deploy under their own domain. Note that this works  for code-only cases too, i.e. no 3rd party &lt;i&gt;content&lt;/i&gt;. This used to  be an issue back when everyone was "hot linking" but nowadays you  typically see requirements to download and host yourself since 3rd  parties don't want to have to pay for the bandwidth or even have the  tough SLAs in place.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Reverse proxy&lt;/b&gt;. Setup a reverse proxy to mimic that the  3rd party content is served by themselves. This makes it look like  they're hosting everything themselves but really they're not. However,  in this case they can potentially filter and detect code changes. If  code changes happen daily it'll just become noise but detecting less  frequent changes may prove useful for the cert team.&lt;br /&gt;&lt;/li&gt;&lt;li&gt;&lt;b&gt;Normal loading + ajax proxy&lt;/b&gt;. Let the 3rd party have  their own release cycle, load from 3rd party's domain and set up an ajax  proxy if the code requires that. That means their own domain is still  serving the client calls but they just reflect whatever source code the  vendor serves up.&lt;/li&gt;&lt;li&gt;&lt;b&gt;Point subdomain to 3rd party&lt;/b&gt;. If they point a subdomain of their own such as &lt;a send="true" href="http://googlemaps.mybank.com/"&gt;googlemaps.mybank.com&lt;/a&gt; pointing to Google Maps and host their own content on &lt;a send="true" href="http://secure.mybank.com/"&gt;secure.mybank.com&lt;/a&gt; they can have both the iframe and the outer page set their docment.domain to a &lt;a send="true" href="http://mybank.com/"&gt;mybank.com&lt;/a&gt; and thus enable interaction.&lt;br /&gt;&lt;/li&gt;&lt;/ul&gt;In the three latter cases they're basically giving the 3rd  party code the same privileges their own code has. So it has to be  covered by the same processes (pentests and what not). This is typically  when my customers have started considering the first option – "Hey,  maybe we need to control what code runs on our page? And who writes that  code. And how easy it is to hack into the hosting servers and replace  that code. Damn!".&lt;br /&gt;&lt;br /&gt;   Regards, @johnwilander&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-8260352656812061221?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/8260352656812061221/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/06/question-on-3rd-party-js.html#comment-form' title='2 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8260352656812061221'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8260352656812061221'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/06/question-on-3rd-party-js.html' title='Question on 3rd party JS'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-1602053485874403159</id><published>2011-06-11T20:58:00.000-07:00</published><updated>2011-06-11T20:59:00.033-07:00</updated><title type='text'>OWASP Zed Attack Proxy 1.3.0 released</title><content type='html'>&lt;div&gt;(from &lt;a href="mailto://psiinon@gmail.com"&gt;psiinon@gmail.com&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;Hi folks,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Version 1.3.0 of the OWASP Zed Attack Proxy (ZAP) has now been released.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;ZAP is an easy to use integrated penetration testing tool for finding vulnerabilities in web applications.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This release adds the following main features:&lt;br /&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;Fuzzing, using the JBroFuzz library&lt;/li&gt;&lt;li&gt;Dynamic SSL Certificates&lt;/li&gt;&lt;li&gt;Daemon mode and API&lt;/li&gt;&lt;li&gt;BeanShell integration&lt;/li&gt;&lt;li&gt;Full internationalization&lt;/li&gt;&lt;li&gt;Out of the box support for 10 languages&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For more information and to download this release please visit the ZAP homepage: &lt;a href="http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project"&gt;http://www.owasp.org/index.php/OWASP_Zed_Attack_Proxy_Project&lt;/a&gt;&lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Many thanks to everyone who contributed code, language files, enhancement requests, bug reports and general feedback.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Psiinon&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-1602053485874403159?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/1602053485874403159/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/06/owasp-zed-attack-proxy-130-released.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1602053485874403159'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1602053485874403159'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/06/owasp-zed-attack-proxy-130-released.html' title='OWASP Zed Attack Proxy 1.3.0 released'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4912952586384805995</id><published>2011-06-11T20:48:00.000-07:00</published><updated>2011-06-11T20:49:21.533-07:00</updated><title type='text'>AppSecEU Was Awesome</title><content type='html'>&lt;div class="moz-text-html" lang="x-western"&gt;(from Seba)&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I am just back from AppSecEU, held in Dublin this week.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I want to congratulate the whole team for a great and inspiring event!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="https://www.owasp.org/index.php/AppSecEU2011#tab=Team"&gt;https://www.owasp.org/index.php/AppSecEU2011#tab=Team&lt;/a&gt;&lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;AppSec EU Conference Team:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Eoin Keary&lt;/li&gt;&lt;li&gt;Fabio Cerullo&lt;/li&gt;&lt;li&gt;Fiona Walsh&lt;/li&gt;&lt;li&gt;Kate Hartmann&lt;/li&gt;&lt;li&gt;Lorna Alamri&lt;/li&gt;&lt;li&gt;Sarah Baso&lt;/li&gt;&lt;li&gt;Ana Loza&lt;/li&gt;&lt;li&gt;Ralph Durkee&lt;/li&gt;&lt;li&gt;Owen Pendlebury&lt;/li&gt;&lt;li&gt;Niall Jordan&lt;/li&gt;&lt;li&gt;Ronan O'Mullane&lt;/li&gt;&lt;li&gt;Federico Feraboli&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;And probably a whole lot of people working behind the scenes.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Having co-organized conferences before, I know it has taken them several months of sweat, blood and energy.&lt;/div&gt; &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;A big THANK YOU!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Kind regards,&lt;br /&gt;Seba&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4912952586384805995?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4912952586384805995/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/06/appseceu-was-awesome.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4912952586384805995'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4912952586384805995'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/06/appseceu-was-awesome.html' title='AppSecEU Was Awesome'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-3090875411595715193</id><published>2011-06-03T19:22:00.000-07:00</published><updated>2011-06-03T19:23:32.914-07:00</updated><title type='text'>AppSec USA 2011 CFP Reminder, CTF Pre-Conference Challenge #2</title><content type='html'>&lt;div class="moz-text-html" lang="x-western"&gt;&lt;span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;"&gt;Hello OWASP Community!&lt;/span&gt;&lt;div&gt;&lt;span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;"&gt;This  is an update about the OWASP AppSec USA 2011 software security  conference in Minneapolis this September I just sent to several other  mailing lists. Maybe on your way to AppSec EU you can work on a paper  and get it submitted! I would be most thankful if you would share the  CFP link, as well as the CTF pre-con challenge #2 (free ticket  opportunity) and Training links with your friends and local chapters.&lt;br /&gt; &lt;br /&gt;&lt;b&gt;*** CALL FOR PAPERS ***&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Have something important to  say about software security? The OWASP AppSec USA 2011 Call for Papers  is still open. We're looking for hardcore talks in cloud security,  mobile security, new attacks &amp;amp; defenses, and straight up software  development platforms. Get your submission in before time runs out. And  have your developer friends submit a talk!&lt;br /&gt; &lt;br /&gt;&lt;a href="http://www.appsecusa.org/talks.html" style="color: rgb(0, 0, 204);" target="_blank"&gt;http://www.appsecusa.org/talks.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The  AppSec USA 2011 talks will be delivered September 22-23, 2011 in  Minneapolis, Minnesota. In addition to the talks, we'll have excellent  keynotes like Moxie Marlinspike.&lt;/span&gt;&lt;/div&gt;  &lt;div&gt;&lt;span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;"&gt;&lt;i&gt;&lt;b&gt;Leaders:&lt;/b&gt; The CFP system for the OWASP-specific track is &lt;a href="https://www.easychair.org/conferences/?conf=ot11" target="_blank"&gt;https://www.easychair.org/conferences/?conf=ot11&lt;/a&gt;. Contact Mark Bristow or Jason Li for more information.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;  &lt;div&gt;&lt;span style="border-collapse: collapse; font-family: arial,sans-serif; font-size: 13px;"&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;b&gt;*** CAPTURE THE FLAG PRE-CONFERENCE CHALLENGE #2 ***&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;Last month &lt;b&gt;ChrisKarel&lt;/b&gt; won pre-conference challenge #1 for a pass to the OWASP AppSec USA 2011 talks. Congratulations, ChrisKarel!&lt;div&gt; &lt;br /&gt;&lt;/div&gt; &lt;div&gt;For June, we're back with another chance for you to score a free  conference pass and get a feel for the AppSec USA 2011 CTF challenges  coming this September. Good luck.&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;a href="http://www.appsecusa.org/ctf.html" style="color: rgb(0, 0, 204);" target="_blank"&gt;http://www.appsecusa.org/ctf.html&lt;/a&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;b&gt;*** TRAINING ***&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We  have awesome training at a fair price. Register for mobile security,  penetration testing, secure coding, and attack detection and response  courses being held September 20-21. Hurry before classes fill up.&lt;/div&gt;   &lt;div&gt;&lt;br /&gt;&lt;a href="http://www.appsecusa.org/training.html" style="color: rgb(0, 0, 204);" target="_blank"&gt;http://www.appsecusa.org/training.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;*** MORE APPSEC USA 2011 ***&lt;/b&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;   &lt;div&gt;Check out &lt;a href="http://www.appsecusa.org/" style="color: rgb(0, 0, 204);" target="_blank"&gt;www.appsecusa.org&lt;/a&gt; for  other events including a 5K / 10K charity run, the first ever Women in  AppSec grant, and a chance to have your own original music played at the  conference.&lt;/div&gt;   &lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;Thanks to our wonderful supporters - check them out at &lt;a href="http://www.appsecusa.org/" style="color: rgb(0, 0, 204);" target="_blank"&gt;www.appsecusa.org&lt;/a&gt;!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;--&lt;br /&gt;&lt;br /&gt;Adam Baso&lt;br /&gt;  OWASP AppSec USA 2011: Your life is in the cloud.&lt;/div&gt;&lt;div&gt;September 20-23 Training, Talks, CTF, Showroom, and More&lt;br /&gt;&lt;a href="http://www.appsecusa.org/" style="color: rgb(0, 0, 204);" target="_blank"&gt;www.appsecusa.org&lt;/a&gt;&lt;br /&gt;  @appsecusa&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/span&gt; &lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-3090875411595715193?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/3090875411595715193/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/06/appsec-usa-2011-cfp-reminder-ctf-pre.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3090875411595715193'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3090875411595715193'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/06/appsec-usa-2011-cfp-reminder-ctf-pre.html' title='AppSec USA 2011 CFP Reminder, CTF Pre-Conference Challenge #2'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-966017593263385188</id><published>2011-06-03T17:21:00.000-07:00</published><updated>2011-06-03T19:22:50.330-07:00</updated><title type='text'>OWASP Project Update</title><content type='html'>Reposted from &lt;a href="http://globalprojectscommittee.wordpress.com/2011/06/03/owasp-projects-overview-last-6-months/"&gt;http://globalprojectscommittee.wordpress.com/2011/06/03/owasp-projects-overview-last-6-months/&lt;/a&gt; by &lt;a href="http://globalprojectscommittee.wordpress.com/author/pauloc/" title="Posts by Paulo Coimbra"&gt;Paulo Coimbra&lt;/a&gt;&lt;div&gt;&lt;a href="http://globalprojectscommittee.wordpress.com/author/pauloc/" title="Posts by Paulo Coimbra"&gt;&lt;/a&gt;&lt;br /&gt;&lt;p style="text-align:justify;"&gt;&lt;strong&gt;&lt;strong&gt;&lt;strong&gt;A. NEW PROJECTS &lt;/strong&gt;&lt;/strong&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Common_Numbering_Project"&gt;OWASP Common Numbering Project&lt;/a&gt;,  &lt;/strong&gt;&lt;/strong&gt;led by&lt;strong&gt;&lt;strong&gt; Dave Wichers, &lt;/strong&gt;&lt;/strong&gt;this project is  a new numbering scheme that will be common across OWASP Guides and References is being developed.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;*&lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_HTTP_Post_Tool"&gt; OWASP HTTP Post Tool&lt;/a&gt;, &lt;/strong&gt;led by&lt;strong&gt; Tom Brenann&lt;/strong&gt;, this project is a tool for the purpose of performing web application security assessment around the availability concerns.&lt;strong&gt;&lt;/strong&gt;&lt;/p&gt; &lt;p style="text-align:justify;"&gt;*&lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Forward_Exploit_Tool_Project" target="_blank"&gt; OWASP Forward Exploit Tool Project&lt;/a&gt;&lt;/strong&gt;, led by&lt;strong&gt; Marcos Mateos Garcia&lt;/strong&gt;,  this aims to develop a tool to exploit Top 10 2010 – A10 – Unvalidated  Forward vulnerability to bypass access control to protected Java  application files.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;*&lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Java_XML_Templates_Project" target="_blank"&gt; OWASP Java XML Templates Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Jeff Ichnowski&lt;/strong&gt;, this is a fast and secure XHTML-compliant template language that runs on a model similar to JSP.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_ASIDE_Project" target="_blank"&gt;OWASP ASIDE Project&lt;/a&gt;&lt;/strong&gt;, led by&lt;strong&gt; Jing Xie, Bill Chu&lt;/strong&gt; and&lt;strong&gt; John Melton, &lt;/strong&gt;ASIDE is an abbreviation for &lt;strong&gt;Assured Software Integrated Development Environment&lt;/strong&gt;.  It is an Eclipse Plugin which is a software tool primarily designed to  help students write more secure code by detecting and identifying  potentially vulnerable code and providing informative fixes during the  construction of programs in IDEs.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Secure_Password_Project" target="_blank"&gt;OWASP Secure Password Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Josh Sokol&lt;/strong&gt;,  this project will have a two pronged approach designed to put more  nails in the single-factor method of authentication: an interactive  portal where penetration testers are able to enter known information  about the target and the results of all data collected into a large  database.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Secure_the_Flag_Competition_Project" target="_blank"&gt;OWASP Secure the Flag Competition Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Mark Bristow&lt;/strong&gt;, this project aims to create a different type of competition that encourages secure coding rather than hacking skills.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Security_Baseline_Project" target="_blank"&gt;OWASP Security Baseline Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Marian Ventuneac&lt;/strong&gt;, this projects aims to benchmark the security of various enterprise security products/services against OWASP Top 10 risks.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/Category:OWASP_Enterprise_Security_API#tab=Objective_C" target="_blank"&gt;OWASP ESAPI Objective – C Project&lt;/a&gt;&lt;/strong&gt;, led by Deepak Subramanian, this project is the Objective-C (Cocoa) implementation of ESAPI.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Academy_Portal_Project" target="_blank"&gt;OWASP Academy Portal Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Martin Knobloch, Ricardo Melo &lt;/strong&gt;and&lt;strong&gt; Konstantinos Papapanagiotou&lt;/strong&gt;, this project envisages the creation of a Portal to offer academic material in usable blocks, lab’s, video’s and forum.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Exams_Project" target="_blank"&gt;OWASP Exams Project&lt;/a&gt;&lt;/strong&gt;, led by&lt;strong&gt; Jason Taylor&lt;/strong&gt;,  this project will establish the model by which the OWASP community can  create and distribute CC-licensed exams for use by educators.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Portuguese_Language_Project" target="_blank"&gt;OWASP Portuguese Language Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Lucas Ferreira&lt;/strong&gt; and&lt;strong&gt; Carlos Serrão&lt;/strong&gt;, this project aims to coordinate and push foward the iniciatives developed to translate OWASP materials to Portuguese.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Browser_Security_ACID_Tests_Project" target="_blank"&gt;OWASP Browser Security ACID Tests Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Dave Wichers, John Wilander &lt;/strong&gt;and&lt;strong&gt; David Lindsay&lt;/strong&gt;,  this project was started in order to help people get a better  understanding of what these issues are while also providing browser  vendors a forum to compare strategies, vulnerabilities, and new  features.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Web_Browser_Testing_System_Project" target="_blank"&gt;OWASP Web Browser Testing System Project&lt;/a&gt;&lt;/strong&gt;, led by&lt;strong&gt; Isaac Dawson, &lt;/strong&gt;this  project was built to quickly automate and test various browser and  user-agents for security issues. It contains all the necessary services  required for testing a browser.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Java_Project" target="_blank"&gt;OWASP Java Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Matthias Rohr&lt;/strong&gt;, this project’s goal is to enable Java and J2EE developers to build secure applications efficiently.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Myth_Breakers_Project" target="_blank"&gt;OWASP Myth Breakers Project&lt;/a&gt;, &lt;/strong&gt;led by &lt;strong&gt;Stefano Di Paola &lt;/strong&gt;and&lt;strong&gt; Dinis Cruz&lt;/strong&gt;,this project  similar to &lt;a href="http://dsc.discovery.com/tv/mythbusters" rel="nofollow"&gt;http://dsc.discovery.com/tv/mythbusters&lt;/a&gt;  but for appsec, urban legends and assumptions regarding appsec will be  tested and there’ll be a set of examples that will prove the  correctness/incorrectness of a statement related to the question.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_LAPSE_Project" target="_blank"&gt;OWA&lt;/a&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_LAPSE_Project" target="_blank"&gt;SP LAPSE Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Pablo Martín Pérez &lt;/strong&gt;and&lt;strong&gt; José María Sierra Cámara&lt;/strong&gt;,  LAPSE is designed to help with the task of auditing &lt;strong&gt;Java EE Applications&lt;/strong&gt; for common types of security vulnerabilities found in Web Applications.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Software_Security_Assurance_Process" target="_blank"&gt;OWASP Software Security Assurance Process&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Mateo Martínez&lt;/strong&gt;,  this project envisages to outline mandatory and recommended processes  and practices to manage risks associated with applications.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_ESOP_Framework" target="_blank"&gt;OWASP Enhancing Security Options Framework (ESOP Framework&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Amber Marfatia&lt;/strong&gt;,  the purpose of the framework is to provide a security layer to a given  web application / web site via web service which can use the functions /  modules to protect the site from several specified  vulnerabilities.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;a href="https://www.owasp.org/index.php/OWASP_German_Language_Project" target="_blank"&gt;&lt;strong&gt;OWASP German Language Projec&lt;/strong&gt;t&lt;/a&gt;, led by &lt;strong&gt;Matthias Rohr&lt;/strong&gt;,  this project will provide a foundation, guideance and common  terminology for German translations (as well as other German language  specific activities) of OWASP documents and parts of the OWASP web site.  Furthermore, it will organize, plan and priorize new language projects  such as translations.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Mantra_-_Security_Framework" target="_blank"&gt;OWASP Mantra – Security Framework&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Abhi M BalaKrishnan&lt;/strong&gt;,  this project is a security framework which can be very helpful in  performing all the five phases of attacks including reconnaissance,  scanning and enumeration, gaining access, escalation of  privileges,maintaining access, and covering tracks.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;a href="https://www.owasp.org/index.php/OWASP_Java_HTML_Sanitizer"&gt;&lt;strong&gt;OWASP Java HTML Sanitizer&lt;/strong&gt;&lt;/a&gt;, led by by &lt;strong&gt;Mike Samuel &lt;/strong&gt;and&lt;strong&gt; Jim Manico&lt;/strong&gt;, this this is a fast Java-based HTML Sanitizer which provides XSS protection.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;a href="https://www.owasp.org/index.php/OWASP_Java_Encoder_Project" target="_blank"&gt;&lt;strong&gt;OWASP Java Encoder Project&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;, &lt;/strong&gt;led by &lt;strong&gt;Jeff Ichnowski&lt;/strong&gt;, this project is a simple-to-use drop-in encoder class with little baggage.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_WebScarab_NG_Project" target="_blank"&gt;OWASP WebScarab NG Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Daniel Brzozowsk&lt;/strong&gt;,  this project is a robust tool that assists the user in penetration  test. This is a complete rewrite of the old WebScarab application, with a  special focus on making the application more user-friendly.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Threat_Modelling_Project" target="_blank"&gt;OWASP Threat Modelling Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Anurag Agarwal&lt;/strong&gt;,  this project envisages to establish a single and inclusive  software-centric OWASP Threat modeling Methodology, addressing  vulnerability in client and web application-level services over the  Internet.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/Category:OWASP_Application_Security_Assessment_Standards_Project" target="_blank"&gt;OWASP Application Security Assessment Standards Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Matteo Michelini&lt;/strong&gt;,  the Project’s primary objective is to establish common, consistent  methods for application security assessments standards that  organizations can use as guidance on what tasks should be completed, how  the tasks should be completed and what level of assessment is  appropriate based on business requirement.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Hackademic_Challenges_Project" target="_blank"&gt;OWASP Hackademic Challenges Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Anastasios Stasinopoulos&lt;/strong&gt; and&lt;strong&gt; Konstantinos&lt;/strong&gt;&lt;strong&gt; Papapanagiotou&lt;/strong&gt;, this is an open source project that can be used to test and improve one’s knowledge of web application security.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Hatkit_Proxy_Project" target="_blank"&gt;OWASP Hatkit Proxy Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Martin Holst Swende&lt;/strong&gt;, this is an intercepting http/tcp proxy based on the Owasp Proxy, but with several additions.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;&lt;strong&gt;* &lt;a href="https://www.owasp.org/index.php/OWASP_Hatkit_Datafiddler_Project" target="_blank"&gt;OWASP Hatkit Datafiddler Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Martin Holst Swende&lt;/strong&gt;, this is a tool for performing advanced analysis of http traffic.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/ESAPI_Swingset#tab=Project_About_-_Swingset_Interactive" target="_blank"&gt;OWASP ESAPI Swingset Interactive Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Cathal Courtney&lt;/strong&gt; and&lt;strong&gt; Fabio Cerullo&lt;/strong&gt;,  this a web application which demonstrates common security  vulnerabilities and asks users to secure the application against these  vulnerabilities using the ESAPI library.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/ESAPI_Swingset#tab=Project_About_-_Swingset_Demo" target="_blank"&gt;OWASP ESAPI Swingset Demo Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Craig Younkins&lt;/strong&gt;, this is a web application which demonstrates the many uses of the Enterprise Security API (ESAPI).&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Web_Application_Security_Accessibility_Project" target="_blank"&gt;OWASP Web Application Security Accessibility Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Petr Závodský&lt;/strong&gt;, this project will focus extensively on the issue of web application security accessibility.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/Category:OWASP_Cloud_%E2%80%90_10_Project" target="_blank"&gt;OWASP Cloud ‐ 10 Project&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Vinay Bansal, Shankar Babu Chebrolu, Pankaj Telang, Ken Huang, &lt;/strong&gt;and&lt;strong&gt; Ove Hansen&lt;/strong&gt;,  the goal of the project is to maintain a list of top 10 security risks  faced with the Cloud Computing and SaaS Models. List will be maintained  by input from community, security experts and security incidences at  cloud/SaaS providers.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;a href="https://www.owasp.org/index.php/OWASP_Web_Testing_Environment_Project"&gt;&lt;strong&gt;OWASP Web Testing Environment Project&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;,&lt;/strong&gt;l ed by &lt;strong&gt;Matt Tesauro&lt;/strong&gt;, this project was thought o receive all contents OWASP Live CD related.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;a href="https://www.owasp.org/index.php/OWASP_iGoat_Project"&gt;&lt;strong&gt;OWASP iGoat Project&lt;/strong&gt;&lt;/a&gt;, led by &lt;strong&gt;Kenneth R. van Wyk&lt;/strong&gt;,  this project aims to be a developer learning environment for iOS app  developers. It was inspired by the OWASP WebGoat project in particular  the developer edition of WebGoat.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/Opa" target="_blank"&gt;Opa&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;David Rajchenbach-Teller&lt;/strong&gt;, usher in a new generation of web development tools and methodologies.&lt;/p&gt; &lt;p style="text-align:justify;"&gt;* &lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Mobile_Security_Project#tab=Mobile_Threat_Model" target="_blank"&gt;OWASP Mobile Security Project – Mobile Threat Model&lt;/a&gt;&lt;/strong&gt;, led by &lt;strong&gt;Jack Mannino&lt;/strong&gt; this sub-project is a component of the OWASP Mobile Security Project.&lt;/p&gt; &lt;strong&gt;*&lt;a href="https://www.owasp.org/index.php/OWASP_Codes_of_Conduct" target="_blank"&gt; OWASP Codes of Conduct&lt;/a&gt;, &lt;/strong&gt;led by&lt;strong&gt; Colin Watson, &lt;/strong&gt;this  project envisages to create and maintain OWASP Codes of Conduct. In  order to achieve our mission, OWASP needs to take advantage of every  opportunity to affect software development everywhere. At the OWASP  Summit 2011 in Portugal, the idea was created to try to influence  educational institutions, government bodies, standards groups, and trade  organizations.&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;&lt;strong&gt;&lt;strong&gt;&lt;strong&gt;B. PROJECTS/UNDER WORK &lt;/strong&gt;&lt;/strong&gt;&lt;/strong&gt;&lt;/strong&gt; &lt;p style="text-align:justify;"&gt;*&lt;strong&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Cross-Site_Request_Forgery_Research_Pool"&gt; OWASP Cross-Site Request Forgery Research Pool&lt;/a&gt;&lt;/strong&gt;&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-966017593263385188?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/966017593263385188/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/06/owasp-project-update.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/966017593263385188'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/966017593263385188'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/06/owasp-project-update.html' title='OWASP Project Update'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-5780555944043057275</id><published>2011-05-30T21:53:00.000-07:00</published><updated>2011-05-30T21:54:46.833-07:00</updated><title type='text'>AppSec Latin America 2011</title><content type='html'>&lt;div&gt;We are pleased to announce that the OWASP Porto Alegre Local Chapter will organize the Global AppSec Latin America 2011 Conference in Porto Alegre-RS, Brazil. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The Global AppSec Latin America 2011 Conference will be a reunion of Information Security latin american leaders, and will present cutting-edge ideas. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 200-250 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;A OWASP Global AppSec Latin América 2011 will be happens in Brazil at Porto Alegre city, Rio Grande do Sul state map in October 4th to 7th 2011. The trainings will be in October 04 and 05, and the presentations will be in October 06 and 07. &lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If you have any questions, please email the conference chair: &lt;a href="mailto://AppSec2011@AppSecLatam.org"&gt;AppSec2011@AppSecLatam.org&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Who Should Attend Global AppSec Latin América 2011: &lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Application Developers &lt;/li&gt;&lt;li&gt;Application Testers and Quality Assurance &lt;/li&gt;&lt;li&gt;Application Project Management and Staff &lt;/li&gt;&lt;li&gt;Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;/li&gt;&lt;li&gt;Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;/li&gt;&lt;li&gt;Security Managers and Staff &lt;/li&gt;&lt;li&gt;Executives, Managers, and Staff Responsible for IT Security Governance &lt;/li&gt;&lt;li&gt;IT Professionals Interested in Improving IT Security&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-5780555944043057275?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/5780555944043057275/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/05/appsec-latin-america-2011.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5780555944043057275'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5780555944043057275'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/05/appsec-latin-america-2011.html' title='AppSec Latin America 2011'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4591859255004287735</id><published>2011-05-29T22:37:00.003-07:00</published><updated>2011-05-29T22:37:40.407-07:00</updated><title type='text'>AppSec EU Registration Alert</title><content type='html'>&lt;div class="moz-text-html" lang="x-western"&gt;&lt;style&gt;&lt;!-- /* Font Definitions */ @font-face  {font-family:Calibri;  panose-1:2 15 5 2 2 2 4 3 2 4;} /* Style Definitions */ p.MsoNormal, li.MsoNormal, div.MsoNormal  {margin:0in;  margin-bottom:.0001pt;  font-size:11.0pt;  font-family:"Calibri","sans-serif";} a:link, span.MsoHyperlink  {mso-style-priority:99;  color:blue;  text-decoration:underline;} a:visited, span.MsoHyperlinkFollowed  {mso-style-priority:99;  color:purple;  text-decoration:underline;} p  {mso-style-priority:99;  margin:0in;  margin-bottom:.0001pt;  font-size:12.0pt;  font-family:"Times New Roman","serif";} span.EmailStyle17  {mso-style-type:personal-compose;  font-family:"Calibri","sans-serif";  color:windowtext;} .MsoChpDefault  {mso-style-type:export-only;  font-family:"Calibri","sans-serif";} @page WordSection1  {size:8.5in 11.0in;  margin:1.0in 1.0in 1.0in 1.0in;} div.WordSection1  {page:WordSection1;} --&gt;&lt;/style&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:shapedefaults ext="edit" spidmax="1026"&gt;  &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;o:shapelayout ext="edit"&gt;  &lt;o:idmap ext="edit" data="1"&gt;  &lt;/o:shapelayout&gt;&lt;/xml&gt;&lt;![endif]--&gt;&lt;div class="WordSection1"&gt;&lt;p class="MsoNormal"&gt;(From Kate Hartmaan)&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;br /&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;I  would like to encourage anyone who will be attending AppSec EU to  register as soon as possible.  The training seats are close to capacity!&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Please  join us at historic Trinity College in Dublin Ireland for the 2011  Global AppSec European event.  Training will be held on June 7&lt;sup&gt;th&lt;/sup&gt; and 8&lt;sup&gt;th&lt;/sup&gt; followed by two days of cutting edge presentations given by university and industry experts on June 9&lt;sup&gt;th&lt;/sup&gt; and 10&lt;sup&gt;th&lt;/sup&gt;.  Breakout sessions will be hosted by the OWASP Global Industry Committee and the Global Chapters Committee.  &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;There will be opportunities for networking at our social events including the first ever KartCon EU!&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Please visit &lt;a href="http://www.appseceu.org/"&gt;www.appseceu.org&lt;/a&gt; for complete information on speakers, presentations, networking events, and, of course, KartCon EU!&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;p&gt;If you are all set to register, you can do that directly by clicking here:  &lt;a href="http://www.regonline.com/owasp_appsec_eu_2011"&gt;&lt;span style="color: blue;"&gt;http://www.regonline.com/owasp_appsec_eu_2011&lt;/span&gt;&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;p&gt;I am looking forward to seeing everyone in Dublin!&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Kate Hartmann&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Operations Director&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;301-275-9403&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;&lt;a href="http://www.owasp.org/"&gt;www.owasp.org&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt;Skype:  Kate.hartmann1&lt;/p&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4591859255004287735?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4591859255004287735/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/05/appsec-eu-registration-alert.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4591859255004287735'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4591859255004287735'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/05/appsec-eu-registration-alert.html' title='AppSec EU Registration Alert'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-2624049513795180784</id><published>2011-05-29T22:27:00.000-07:00</published><updated>2011-05-29T22:33:10.576-07:00</updated><title type='text'>ModSecurity Core Rule Set v2.2.0</title><content type='html'>&lt;div&gt;&lt;div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;(From Ryan Barnett)&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;I am  pleased to announce the release of the OWASP ModSecurity Core Rule Set  (CRS) v2.2.0.  This is a significant update as we have added a number of  very important capabilities.&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;CHANGE LOG -&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;span class="Apple-style-span" style="font-family: Times; "&gt;&lt;pre style="word-wrap: break-word; white-space: pre-wrap;"&gt;-------------------------- Version 2.2.0 - 05/26/2011 --------------------------&lt;/pre&gt;&lt;pre style="word-wrap: break-word; white-space: pre-wrap;"&gt;Improvements: &lt;/pre&gt;&lt;pre style="word-wrap: break-word; white-space: pre-wrap;"&gt;&lt;ul&gt;&lt;li&gt;Changed Licensing from GPLv2 to Apache Software License v2 (ASLv2)   &lt;a href="http://www.apache.org/licenses/LICENSE-2.0.txt"&gt;&lt;/a&gt;&lt;a href="http://www.apache.org/licenses/LICENSE-2.0.txt"&gt;http://www.apache.org/licenses/LICENSE-2.0.txt&lt;/a&gt;  &lt;/li&gt;&lt;li&gt;Created new INSTALL file outlining quick config setup - Added a new rule regression testing framework to the /util directory &lt;/li&gt;&lt;li&gt;Added new activated_rules directory which will allow users to place symlinks pointing   to files they want to run.  This allows for easier Apache Include wild-carding &lt;/li&gt;&lt;li&gt;Adding in new RULE_MATURITY and RULE_ACCURACY tags &lt;/li&gt;&lt;li&gt;Adding in a check for X-Forwarded-For source IP when creating IP collection - Added new Application Defect checks (55 app defect file) from Watcher tool (Check Charset)    &lt;a href="http://websecuritytool.codeplex.com/wikipage?title=Checks#charset"&gt;&lt;/a&gt;&lt;a href="http://websecuritytool.codeplex.com/wikipage?title=Checks#charset"&gt;http://websecuritytool.codeplex.com/wikipage?title=Checks#charset&lt;/a&gt;  &lt;/li&gt;&lt;li&gt;Added new AppSensor rules to experimental_dir   &lt;a href="https://www.owasp.org/index.php/AppSensor_DetectionPoints"&gt;https://www.owasp.org/index.php/AppSensor_DetectionPoints&lt;/a&gt; &lt;/li&gt;&lt;li&gt;Added new Generic Malicious JS checks in outbound content - Added experimental IP Forensic rules to gather Client hostname/whois info  &lt;a href="http://blog.spiderlabs.com/2010/11/detecting-malice-with-modsecurity-ip-forensics.html"&gt;&lt;/a&gt;&lt;a href="http://blog.spiderlabs.com/2010/11/detecting-malice-with-modsecurity-ip-forensics.html"&gt;http://blog.spiderlabs.com/2010/11/detecting-malice-with-modsecurity-ip-forensics.html&lt;/a&gt;  &lt;/li&gt;&lt;li&gt;Added support for Mozilla's Content Security Policy (CSP) to the experimental_rules   &lt;a href="http://blog.spiderlabs.com/2011/04/modsecurity-advanced-topic-of-the-week-integrating-content-security-policy-csp.html"&gt;&lt;/a&gt;&lt;a href="http://blog.spiderlabs.com/2011/04/modsecurity-advanced-topic-of-the-week-integrating-content-security-policy-csp.html"&gt;http://blog.spiderlabs.com/2011/04/modsecurity-advanced-topic-of-the-week-integrating-content-security-policy-csp.html&lt;/a&gt;    &lt;/li&gt;&lt;li&gt;Global collection in the 10 file now uses the Host Request Header as the collection key.   This allows for per-site global collections. &lt;/li&gt;&lt;li&gt;Added new SpiderLabs Research (SLR) rules directory (slr_rules) for known vulnerabilties.   This includes both converted web rules from Emerging Threats (ET) and from SLR Team. &lt;/li&gt;&lt;li&gt;Added new SLR rule packs for known application vulns for WordPress, Joomla and phpBB &lt;/li&gt;&lt;li&gt;- Added experimental rules for detecting Open Proxy Abuse   &lt;a href="http://blog.spiderlabs.com/2011/03/detecting-malice-with-modsecurity-open-proxy-abuse.html"&gt;&lt;/a&gt;&lt;a href="http://blog.spiderlabs.com/2011/03/detecting-malice-with-modsecurity-open-proxy-abuse.html"&gt;http://blog.spiderlabs.com/2011/03/detecting-malice-with-modsecurity-open-proxy-abuse.html&lt;/a&gt;  &lt;/li&gt;&lt;li&gt;Added experimental Passive Vulnerability Scanning ruleset using OSVDB and Lua API   &lt;a href="http://blog.spiderlabs.com/2011/02/modsecurity-advanced-topic-of-the-week-passive-vulnerability-scanning-part-1-osvdb-checks.html"&gt;&lt;/a&gt;&lt;a href="http://blog.spiderlabs.com/2011/02/modsecurity-advanced-topic-of-the-week-passive-vulnerability-scanning-part-1-osvdb-checks.html"&gt;http://blog.spiderlabs.com/2011/02/modsecurity-advanced-topic-of-the-week-passive-vulnerability-scanning-part-1-osvdb-checks.html&lt;/a&gt;  &lt;/li&gt;&lt;li&gt;Added additional URI Request Validation rule to the 20 protocol violations file (Rule ID - 981227) &lt;/li&gt;&lt;li&gt;Added new SQLi detection rules (959070, 959071 and 959072) &lt;/li&gt;&lt;li&gt;Added "Toata dragostea mea pentru diavola" to the malicious User-Agent data   &lt;a href="https://www.modsecurity.org/tracker/browse/CORERULES-64"&gt;https://www.modsecurity.org/tracker/browse/CORERULES-64&lt;/a&gt;  Bug Fixes: - Assigned IDs to all active SecRules/SecActions &lt;/li&gt;&lt;li&gt;Removed rule inversion (!) from rule ID 960902 &lt;/li&gt;&lt;li&gt;Fixed false negative issue in Response Splitting Rule &lt;/li&gt;&lt;li&gt;Fixed false negative issue with @validateByteRange check &lt;/li&gt;&lt;li&gt;Updated the TARGETS lising for rule ID 950908 &lt;/li&gt;&lt;li&gt;Updated TX data for REQBODY processing &lt;/li&gt;&lt;li&gt;Changed the pass action to block in the RFI rules in the 40 generic file &lt;/li&gt;&lt;li&gt;Updated RFI regex to catch IP address usage in hostname   &lt;a href="https://www.modsecurity.org/tracker/browse/CORERULES-68"&gt;https://www.modsecurity.org/tracker/browse/CORERULES-68&lt;/a&gt; &lt;/li&gt;&lt;li&gt;Changed REQUEST_URI_RAW variable to REQUEST_LINE in SLR rules to allow matches on request methods. &lt;/li&gt;&lt;li&gt;Updated the RFI rules in the 40 generic attacks conf file to remove explicit logging actions.   They will now inherit the settings from the SecDefaultAction&lt;/li&gt;&lt;/ul&gt;&lt;/pre&gt;&lt;/span&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;--------------------------&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;DOWNLOADING&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;--------------------------&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;Manual Downloading:&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;You can always download the latest CRS version here -&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;a href="https://sourceforge.net/projects/mod-security/files/modsecurity-crs/0-CURRENT/"&gt;&lt;/a&gt;&lt;a href="https://sourceforge.net/projects/mod-security/files/modsecurity-crs/0-CURRENT/"&gt;https://sourceforge.net/projects/mod-security/files/modsecurity-crs/0-CURRENT/&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;Automated Downloading:&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;Use the rules-updater.pl script in the CRS /util directory&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;# Get a list of what the repository contains:&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;$ ./rules-updater.pl -r&lt;a href="http://www.modsecurity.org/autoupdate/repository/"&gt;&lt;/a&gt;&lt;a href="http://www.modsecurity.org/autoupdate/repository/"&gt;http://www.modsecurity.org/autoupdate/repository/&lt;/a&gt; -l&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;Repository: &lt;a href="http://www.modsecurity.org/autoupdate/repository"&gt;&lt;/a&gt;&lt;a href="http://www.modsecurity.org/autoupdate/repository"&gt;http://www.modsecurity.org/autoupdate/repository&lt;/a&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;modsecurity-crs {&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.0.0: modsecurity-crs_2.0.0.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.0.1: modsecurity-crs_2.0.1.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.0.2: modsecurity-crs_2.0.2.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.0.3: modsecurity-crs_2.0.3.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.0.4: modsecurity-crs_2.0.4.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.0.5: modsecurity-crs_2.0.5.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.0.6: modsecurity-crs_2.0.6.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.0.7: modsecurity-crs_2.0.7.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.0.8: modsecurity-crs_2.0.8.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.0.9: modsecurity-crs_2.0.9.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.0.9: modsecurity-crs_2.0.10.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.1.0: modsecurity-crs_2.1.0.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.1.1: modsecurity-crs_2.1.1.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;          2.1.2: modsecurity-crs_2.1.2.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;span class="Apple-tab-span" style="white-space: pre;"&gt; &lt;/span&gt;  2.2.0: modsecurity-crs_2.2.0.zip&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;}&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;# Get the latest stable version of "modsecurity-crs":&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;$ ./rules-updater.pl -r&lt;a href="http://www.modsecurity.org/autoupdate/repository/"&gt;&lt;/a&gt;&lt;a href="http://www.modsecurity.org/autoupdate/repository/"&gt;http://www.modsecurity.org/autoupdate/repository/&lt;/a&gt; -prules -Smodsecurity-crs&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;Fetching: modsecurity-crs/modsecurity-crs_2.2.0.zip ...&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;$ ls -R rules&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;modsecurity-crs&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;rules/modsecurity-crs:&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;modsecurity-crs_2.2.0.zip    modsecurity-crs_2.2.0.zip.sig&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;--&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;Ryan Barnett&lt;/div&gt;&lt;/div&gt;&lt;div style="font-family: Consolas; font-size: medium;"&gt;OWASP ModSecurity CRS Project Leader&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-2624049513795180784?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/2624049513795180784/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/05/modsecurity-core-rule-set-v220.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2624049513795180784'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2624049513795180784'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/05/modsecurity-core-rule-set-v220.html' title='ModSecurity Core Rule Set v2.2.0'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-2775279399940651375</id><published>2011-05-27T22:01:00.000-07:00</published><updated>2011-05-27T22:05:02.202-07:00</updated><title type='text'>London OWASP chapter meeting June 3rd</title><content type='html'>&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: Times; font-size: medium; "&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word; "&gt;&lt;b&gt;London OWASP chapter &amp;amp; ISG, Royal Holloway Joint Seminar&lt;/b&gt;&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word; "&gt;&lt;b&gt;Date:&lt;/b&gt; Friday, June 3rd 2011 6:30pm - 8:00pm  &lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word; "&gt;Tea &amp;amp; Coffee will be served from 6pm, with a sandwich buffet after the seminar.  &lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word; "&gt;&lt;b&gt;Speaker/Topic:&lt;/b&gt; Steve Lord on Wordpress Security&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word; "&gt;&lt;b&gt;Abstract: &lt;/b&gt;Wordpress is one if the most popular blogging systems in the world but is routinely used to shoehorn complex sites into a blog shaped box, often because of it's flexibility and ease of use. In this talk, Mandalorian's Steve Lord discusses common Wordpress security snafus and how to avoid them.&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word; "&gt;&lt;b&gt;Location: &lt;/b&gt;Bourne Lecture Theatre 2 Royal Holloway University of London Egham TW20 0EX  Directions to Royal Holloway and a Campus Plan are available from the following website (Bourne LT 2 is in building 31 on the Campus Plan):&lt;/pre&gt;&lt;pre style="white-space: pre-wrap; word-wrap: break-word; "&gt;&lt;a href="http://www.rhul.ac.uk/aboutus/locationmap/home.aspx" target="_blank" style="color: rgb(0, 0, 204); "&gt;http://www.rhul.ac.uk/aboutus/&lt;wbr&gt;locationmap/home.aspx&lt;/a&gt;&lt;/pre&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-2775279399940651375?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/2775279399940651375/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/05/london-owasp-chapter-meeting-june-3rd.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2775279399940651375'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2775279399940651375'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/05/london-owasp-chapter-meeting-june-3rd.html' title='London OWASP chapter meeting June 3rd'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-1484753834984670796</id><published>2011-05-13T18:39:00.000-07:00</published><updated>2011-05-13T18:44:08.305-07:00</updated><title type='text'>OWASP 2.0 Released!</title><content type='html'>(From Chris Schmidt)&lt;br /&gt;&lt;br /&gt;Friends, Romans, Countrymen - Lend me your ears!&lt;br /&gt;&lt;br /&gt;It is my pleasure to announce the official release of ESAPI 2.0GA!&lt;br /&gt;&lt;br /&gt;This release features some key enhancements over ESAPI 1.4.x including, but not limited to:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Upgrade baseline to use Java5&lt;/li&gt;&lt;li&gt;Completely redesigned and rewrote Encryptor&lt;/li&gt;&lt;li&gt;New and Improved Validation and Encoding Methods&lt;/li&gt;&lt;li&gt;Complete redesign of the ESAPI Locator and ObjectFactory&lt;/li&gt;&lt;li&gt;More unit tests&lt;/li&gt;&lt;li&gt;ESAPI Jar is now Signed with an OWASP Code Signing Certificate&lt;/li&gt;&lt;li&gt;ESAPI Jar is Sealed&lt;/li&gt;&lt;li&gt;And much, much more&lt;/li&gt;&lt;/ul&gt;We understand that a lot of you have been waiting a very long time for this, and so have we! It was important that we take our time with this release to make sure we had addressed everything possible prior to it going out. Included in that process was:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Peer review of the ESAPI Codebase&lt;/li&gt;&lt;li&gt;Code and Architecture Review of new Encryption&lt;/li&gt;&lt;li&gt;Adding and fixing unit tests&lt;/li&gt;&lt;li&gt;Tons of discussion and interaction with the OWASP Community and ESAPI Users&lt;/li&gt;&lt;/ul&gt;Without the feedback from our users, we could have never accomplished some of the awesome enhancements that have been made to the library since the last major release, so we owe you all a debt of gratitude for helping us design and implement controls that will ultimately help you write more secure applications.&lt;br /&gt;&lt;br /&gt;We are currently in the process of getting a whole new suite of documentation, with a focus on integration tasks and actually using ESAPI in real applications - look for those documents over the next couple monthes, as well as a whole new contribs section in our repository aimed at providing turnkey components and solutions to some of the more commonly encountered integration points for ESAPI.&lt;br /&gt;&lt;br /&gt;You can download the full distribution of ESAPI 2.0GA from our home on Google Code at: &lt;a href="http://code.google.com/p/owasp-esapi-java/downloads/list"&gt;http://code.google.com/p/owasp-esapi-java/downloads/list&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The latest API Docs can always be found at:&lt;br /&gt;&lt;a href="http://owasp-esapi-java.googlecode.com/svn/trunk_doc/latest/index.html"&gt;http://owasp-esapi-java.googlecode.com/svn/trunk_doc/latest/index.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Within the next 24-48 hours the distribution to Maven Central should be updated as well and you should be able to start using 2.0GA in your Maven projects as soon as that happens. Maven dependency will be:&lt;br /&gt;&lt;br /&gt;&amp;lt;dependency&amp;gt;&lt;br /&gt;&amp;lt;groupId&amp;gt;org.owasp.esapi&amp;lt;/groupId&amp;gt;&lt;br /&gt;&amp;lt;artifactId&amp;gt;esapi&amp;lt;/artifactId&amp;gt;&lt;br /&gt;&amp;lt;version&amp;gt;2.0GA&amp;lt;/version&amp;gt;&lt;br /&gt;&amp;lt;/dependency&amp;gt;&lt;br /&gt;&lt;br /&gt;As always, we would love to hear your feedback on the release and if you have any questions at all, you can join the ESAPI-User Mailing List here: &lt;a href="https://lists.owasp.org/mailman/listinfo/esapi-user"&gt;https://lists.owasp.org/mailman/listinfo/esapi-user&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Thanks again to the OWASP and ESAPI Community for helping us build and release the tools that help make the internet just a little bit more sane!&lt;br /&gt;&lt;br /&gt;Sincerely,&lt;br /&gt;The ESAPI Development and Management Teams&lt;br /&gt;&lt;br /&gt;P.S. Please forward this along to any colleagues or distribution lists that may be interested.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-1484753834984670796?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/1484753834984670796/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/05/owasp-20-released.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1484753834984670796'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1484753834984670796'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/05/owasp-20-released.html' title='OWASP 2.0 Released!'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-2125588524232880689</id><published>2011-05-09T18:42:00.001-07:00</published><updated>2011-05-09T18:45:55.958-07:00</updated><title type='text'>AppSec USA 2011: Training, Marlinspike &amp; Winkler &amp; Curphey, CFP, Community</title><content type='html'>The OWASP AppSec USA 2011 team has exciting updates for the September 20-23, 2011 event commemorating OWASP's tenth anniversary in the invigorating city of Minneapolis, Minnesota!&lt;br /&gt;&lt;br /&gt;TRAINING&lt;br /&gt;Ready to learn the art of SQL injection? Got it. Securing iOS or Android apps? You're covered. Taking OWASP WTE (OWASP Live CD) to the next level? Learn from its maintainer! Hardening your Web 2.0, .NET, and PHP code? Be instructed by masters of the craft Dave Wichers and Robert H'obbes' Zakon, and respected infosec authors Shreeraj Shah (author of "Hacking Web Services") and Erez Metula (author of "Managed Code Rootkits"). And if you want to set up the next generation of application layer defenses, build your intrusion detection and protection platform with Colin Watson.&lt;br /&gt;&lt;br /&gt;http://www.appsecusa.org/training.html&lt;br /&gt;&lt;br /&gt;MORE KEYNOTES&lt;br /&gt;We've got Moxie! Moxie Marlinspike, creator of sslsniff and sslstrip, joins OWASP founder Mark Curphey and "Spies Among Us" author Ira Winkler as a conference keynote.&lt;br /&gt;&lt;br /&gt;http://www.appsecusa.org/moxie_marlinspike.html&lt;br /&gt;http://www.appsecusa.org/ira_winkler.html&lt;br /&gt;http://www.appsecusa.org/mark_curphey_community_the_killer_app.html&lt;br /&gt;&lt;br /&gt;CALL FOR PAPERS OPEN UNTIL JUNE 14, 2011&lt;br /&gt;Give back to the field and show your peers the way forward. The CFP is open. As OWASP reflects on its first ten years, share your vision for the next ten years. Submit today and you could be leading a track as a featured speaker.&lt;br /&gt;&lt;br /&gt;http://www.appsecusa.org/talks.html&lt;br /&gt;&lt;br /&gt;5K/10K FOR CHARITY&lt;br /&gt;See Dinis Cruz, Dan Cornell, and Mark Curphey sprint to the finish line in fashion as OWASP helps the Bakken Museum (http://www.thebakken.org/) teach youth about the wonderful world of electromagnetism. Let's strengthen the bond with community and improve our health. Place your donations and get signed up to race in the late afternoon Wednesday (September 21, 2011) the day before the conference talks.&lt;br /&gt;&lt;br /&gt;http://www.appsecusa.org/strengthen.html&lt;br /&gt;&lt;br /&gt;WOMEN IN APPSEC&lt;br /&gt;Enable more women to enter the application security field. We're off to a great start with the Wells Fargo Foundation's generous seed funding of $5,000 for grants to women interested in attending OWASP AppSec USA 2011 to launch their career in this growing field. OWASP transformed the way information security works once already, and it's time again to propel positive progress.&lt;br /&gt;&lt;br /&gt;http://www.appsecusa.org/womeninappsec.html&lt;br /&gt;&lt;br /&gt;CAPTURE THE FLAG (AND GET A FREE TICKET)&lt;br /&gt;The first monthly CTF challenge for OWASP AppSec USA 2011 is posted, and it's a great way to start preparing for the full CTF in September! Solve the May challenge before anyone else and get a free ticket to the conference plus props on www.appsecusa.org.&lt;br /&gt;&lt;br /&gt;http://www.appsecusa.org/ctf.html&lt;br /&gt;&lt;br /&gt;DISCOUNTS&lt;br /&gt;Register early and save money. Register a large group and save even more. And if you're a student, the savings are huge. So sign up today for a great deal, and please spread the word to students in computation, information protection, forensics, and law. We need more people to secure the world's systems. Registration is open!&lt;br /&gt;&lt;br /&gt;http://www.appsecusa.org/attend.html&lt;br /&gt;&lt;br /&gt;CR0WD50URC3D&lt;br /&gt;If you have a bumping track, let it be heard. Upload your original music, submit the link, and it may get played at OWASP AppSec USA 2011 or on the www.appsecusa.org website.&lt;br /&gt;&lt;br /&gt;http://www.appsecusa.org/deepcuts.html&lt;br /&gt;&lt;br /&gt;THANK YOU TO OUR SPONSORS! We couldn't pull this off without your generous support!&lt;br /&gt;&lt;br /&gt;Thanks all.&lt;br /&gt;&lt;br /&gt;OWASP AppSec USA 2011: Your life is in the cloud.&lt;br /&gt;September 20-23 Training, Talks, CTF, Showroom, and More&lt;br /&gt;www.appsecusa.org&lt;br /&gt;@appsecusa&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-2125588524232880689?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/2125588524232880689/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/05/appsec-usa-2011-training-marlinspike.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2125588524232880689'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2125588524232880689'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/05/appsec-usa-2011-training-marlinspike.html' title='AppSec USA 2011: Training, Marlinspike &amp; Winkler &amp; Curphey, CFP, Community'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-6484787651182448465</id><published>2011-04-28T13:05:00.000-07:00</published><updated>2011-04-28T13:07:04.064-07:00</updated><title type='text'>ESAPI 2.0 Update</title><content type='html'>(from Chris Schmidt)&lt;br /&gt;&lt;br /&gt;Just a couple of quick updates and some announcements.&lt;br /&gt;&lt;br /&gt;1. We are currently awaiting the verification to complete for our code signing cert - as soon as I receive the cert I will be pushing 2.0GA out the door!&lt;br /&gt;&lt;br /&gt;2. There was an excellent paper done on the ESAPI4JS project and I have blogged about it (and linked to the paper hosted at OWASP) - blog is at http://yet-another-dev.blogspot.com&lt;br /&gt;&lt;br /&gt;3. I have made a run at some initial contrib modules for esapi and will be creating a contrib branch to host the source and binaries (as well as making the binaries available via maven) sometime this week. Contrive include authn/authz integration with Spring-security, contextual encoding integration with freemarker, and hopefully validation integration using jsr303, spring and hibernate-validator. These have been hands-down the most asked about integrations that I have been asked about and I wrote then for use in an app that I am currently writing.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;Chris Schmidt&lt;br /&gt;&lt;a href="mailto://chris.schmidt@owasp.org"&gt;chris.schmidt@owasp.org&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-6484787651182448465?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/6484787651182448465/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/04/esapi-20-update.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6484787651182448465'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6484787651182448465'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/04/esapi-20-update.html' title='ESAPI 2.0 Update'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-1726757045001346316</id><published>2011-04-25T15:51:00.001-07:00</published><updated>2011-04-25T15:52:13.825-07:00</updated><title type='text'>OWASP AppSec EU Hacademic Challenges - Win a FREE Admission</title><content type='html'>The OWASP Hackademic Challenges Project is an open source project that helps you test your knowledge on web application security. You can use it to actually attack web applications in a realistic but also controlled, environment. This is a customized version of the OWASP Hackademic Challenges only for OWASP Appsec Europe 2011.&lt;br /&gt;&lt;br /&gt;The competition starts on 21st April and will run for 4 weeks until 15th May.&lt;br /&gt;&lt;br /&gt;Once the competition is over, the winner will get a FREE ticket to the conference.&lt;br /&gt;&lt;br /&gt;You could find more info here: &lt;a href="http://www.appseceu.org/?p=542"&gt;http://www.appseceu.org/?p=542&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Kate Hartmann&lt;br /&gt;Operations Director&lt;br /&gt;301-275-9403&lt;br /&gt;&lt;a href="http://www.owasp.org"&gt;www.owasp.org&lt;/a&gt;&lt;br /&gt;Skype:  Kate.hartmann1&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-1726757045001346316?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/1726757045001346316/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/04/owasp-appsec-eu-hacademic-challenges.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1726757045001346316'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1726757045001346316'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/04/owasp-appsec-eu-hacademic-challenges.html' title='OWASP AppSec EU Hacademic Challenges - Win a FREE Admission'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-6551307047315171487</id><published>2011-04-25T08:07:00.000-07:00</published><updated>2011-04-25T08:09:16.290-07:00</updated><title type='text'>AppSec EU Agenda and Training</title><content type='html'>We are very excited to announce that the Agenda and Training Courses for this year's AppSec EU conference have been finalized.  We hope you will join us June 7-10 at beautiful Trinity College in Dublin, Ireland.  &lt;br /&gt;&lt;br /&gt;Training Courses include:  Threat Modeling, Assessing and Exploiting Web Apps with Samurai-WTF, Tactical Defense with ModSecurity, Secure Application Development, and Designing, Building and Testing Secure Applications on Mobile Devices&lt;br /&gt;&lt;br /&gt;The plenary sessions include three different tracks that will focus on defense, prevention, and attacks.&lt;br /&gt;&lt;br /&gt;There will be ample time for networking, including KartCon EU 2011!&lt;br /&gt;&lt;br /&gt;Complete information on the training, agenda, Trinity College, KartCon, and links for registration can be found here:  &lt;a href="http://www.appseceu.org/"&gt;http://www.appseceu.org/&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Kate Hartmann&lt;br /&gt;Operations Director&lt;br /&gt;301-275-9403&lt;br /&gt;&lt;a href="http://www.owasp.org"&gt;www.owasp.org&lt;/a&gt; &lt;br /&gt;Skype:  Kate.hartmann1&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-6551307047315171487?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/6551307047315171487/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/04/we-are-very-excited-to-announce-that.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6551307047315171487'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6551307047315171487'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/04/we-are-very-excited-to-announce-that.html' title='AppSec EU Agenda and Training'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-3610500276962034534</id><published>2011-04-10T08:57:00.000-07:00</published><updated>2011-04-11T08:50:40.903-07:00</updated><title type='text'>OWASP Common Numbering Progress</title><content type='html'>&lt;p class="MsoPlainText"&gt;(From Dave Wichers)&lt;/p&gt;&lt;p class="MsoPlainText"&gt;I took a first stab at the Common Authentication requirements based on Keith's SCP Guide and the ASVS. Keith and I spent a couple hours going through these changes and have together produced the following:&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;The numbering scheme I have proposed is here, if you haven't looked at it yet: &lt;a href="https://www.owasp.org/index.php/OWASP_Common_Numbering_Project#tab=OWASP_Common_Requirements_Numbering_Scheme"&gt;https://www.owasp.org/index.php/OWASP_Common_Numbering_Project#tab=OWASP_Common_Requirements_Numbering_Scheme&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;The requirements are here:&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;&lt;a href="https://www.owasp.org/index.php/OWASP_Common_Numbering_Project#tab=OWASP_Common_Requirements_-_DRAFT"&gt;https://www.owasp.org/index.php/OWASP_Common_Numbering_Project#tab=OWASP_Common_Requirements_-_DRAFT&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;An updated version of Keith's Secure Coding Best Practices is attached where &lt;u&gt;just the Authentication section has been updated&lt;/u&gt; to match these requirements. Keith has decided to have his guide use exactly the same requirements numbers as the common numbering project. But for ASVS, and the Dev/Test/Code review guides I would imagine we would just cross reference to the Common Numbers rather than adopt them. &lt;/p&gt;  &lt;p class="MsoPlainText" style="margin-left:.5in;text-indent:-.25in;mso-list:l1 level1 lfo1"&gt;&lt;span style="font-family:Symbol;mso-fareast-font-family:Symbol;mso-bidi-font-family: Symbol;color:black"&gt;&lt;span style="mso-list:Ignore"&gt;·&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;        &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color:black"&gt;Please ignore the rest of my comments on his document. Focus only on the Authentication section.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;Also attached is my working notes for these common requirements and a mapping of them to the old Secure Coding Best Practices Guide and the current ASVS.&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;I plan to update the Authentication section of ASVS to match these new common requirements, but haven't done that yet, as I didn’t want to hold up your review.&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;I wanted to get your feedback before we follow this model/approach for all the other sections, which is a lot of work. So if you have any major comments on the approach, now is the time to raise them and reach some consensus so we can avoid major rework later.&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;Here are my major questions: &lt;/p&gt;  &lt;p class="MsoPlainText" style="margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 lfo2"&gt;&lt;span style="mso-fareast-font-family:Calibri;color:black"&gt;&lt;span style="mso-list:Ignore"&gt;1.&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color:black"&gt;Any comments on the numbering scheme proposed?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoPlainText" style="margin-left:1.0in;text-indent:-.25in;mso-list: l0 level2 lfo2"&gt;&lt;span style="mso-fareast-font-family:Calibri; color:black"&gt;&lt;span style="mso-list:Ignore"&gt;a.&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color:black"&gt;I have developed suggested areas for requirements based on the various OWASP docs but they can easily change. If you have any suggested changes, let me know.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoPlainText" style="margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 lfo2"&gt;&lt;span style="mso-fareast-font-family:Calibri;color:black"&gt;&lt;span style="mso-list:Ignore"&gt;2.&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color:black"&gt;Any comments on our overall approach for developing a full requirements area and mapping that to the Secure Coding Best Practices?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoPlainText" style="margin-left:.5in;text-indent:-.25in;mso-list:l0 level1 lfo2"&gt;&lt;span style="mso-fareast-font-family:Calibri;color:black"&gt;&lt;span style="mso-list:Ignore"&gt;3.&lt;span style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;      &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="color:black"&gt;Any specific comments on the requirements we have identified so far?&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;After getting Authentication worked out, I plan to work with Keith to crank out either all the rest all at once or maybe in 2-3 rounds to get all the rest done.&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;Any and all feedback welcome. &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;&lt;span style="color:black"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;Thanks,&lt;/p&gt;&lt;p class="MsoPlainText"&gt;&lt;span style="color:black"&gt;Dave Wichers&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-3610500276962034534?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/3610500276962034534/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/04/owasp-common-numbering-progress.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3610500276962034534'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3610500276962034534'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/04/owasp-common-numbering-progress.html' title='OWASP Common Numbering Progress'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-6204989638346879941</id><published>2011-04-06T13:12:00.000-07:00</published><updated>2011-04-06T13:16:33.127-07:00</updated><title type='text'>April 10-16 is National Volunteer Week!</title><content type='html'>&lt;p&gt;The OWASP Foundation is a 99.9% volunteer driven organization!  Let’s take this time to recognize those volunteers who have dedicated their time and talent to making the universe safer for the rest of us.&lt;/p&gt;&lt;p&gt;How about a contest to nominate volunteers?  What about a blog page?  Twitter?  How can we raise awareness of the great things we are doing globally?&lt;/p&gt;&lt;p&gt;Mailing list of 25,000,  135 active projects, 70 active chapters globally, volunteer organized conferences on every continent, committees, influencing education and government&lt;/p&gt;&lt;p&gt;This is big…let wave our flag!&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-6204989638346879941?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/6204989638346879941/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/04/april-10-16-is-national-volunteer-week.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6204989638346879941'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6204989638346879941'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/04/april-10-16-is-national-volunteer-week.html' title='April 10-16 is National Volunteer Week!'/><author><name>Justin Clarke</name><uri>http://www.blogger.com/profile/03799833757658152012</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4803227754238789087</id><published>2011-03-21T22:23:00.001-07:00</published><updated>2011-03-21T22:24:16.613-07:00</updated><title type='text'>OWASP Board Election Update</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;    &lt;w:usefelayout/&gt;   &lt;/w:Compatibility&gt;   &lt;w:donotoptimizeforbrowser/&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-qformat:yes;  mso-style-parent:"";  mso-padding-alt:0in 5.4pt 0in 5.4pt;  mso-para-margin:0in;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:11.0pt;  font-family:"Calibri","sans-serif";  mso-ascii-font-family:Calibri;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:"Times New Roman";  mso-fareast-theme-font:minor-fareast;  mso-hansi-font-family:Calibri;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;I wanted to provide a status update to everyone on the OWASP-Leaders list to communicate to your respective chapters via fwd or repost to OWASP Blog/Twitter etc..&lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;1.&lt;span style=""&gt;  &lt;/span&gt;Currently there is a volunteer team assembled and working with Kate Hartmann on Version 3.0 of the OWASP Bylaws (current ones: &lt;a href="http://www.owasp.org/images/0/0d/OWASP_ByLaws.pdf"&gt;http://www.owasp.org/images/0/0d/OWASP_ByLaws.pdf&lt;/a&gt; ) The next milestone update from that team is due by April board meeting. Ongoing the board will need to review them each year, agree to them and vote in subsequent modifications as we continue to grow like any other business with bylaws. &lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;You can track updates at:&lt;span style=""&gt;   &lt;/span&gt;&lt;a href="http://www.owasp.org/index.php/OWASP_Board_Meetings"&gt;http://www.owasp.org/index.php/OWASP_Board_Meetings&lt;/a&gt; and the results.&lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;2.&lt;span style=""&gt;  &lt;/span&gt;In 2009 we ran elections, had (4) candidates, (2) were elected. We utilized a democratic process and documented it:&lt;span style=""&gt;  &lt;/span&gt;&lt;a href="http://www.owasp.org/index.php/Board_member"&gt;http://www.owasp.org/index.php/Board_member&lt;/a&gt;&lt;span style=""&gt;  &lt;/span&gt;&lt;--- 2009 results format.&lt;span style=""&gt;  &lt;/span&gt;We will be using the same process.&lt;span style=""&gt;  &lt;/span&gt;In 2011, (3) seats are up for election: Jeff Williams, Dave Wichers and Sebastian Deleersnyder. (This was based on term length so far)&lt;span style=""&gt;  &lt;/span&gt;These individuals are encouraged to run for re-election by peers and/or endorse and support another candidate.&lt;span style=""&gt;   &lt;/span&gt;The role will be come effective in January 2012 after a transition and hand-off period.&lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;3. In 2011 members will cast a ballot (you are on the OWASP Member list aren't you?)&lt;span style=""&gt;  &lt;/span&gt;now is a good time to check.&lt;span style=""&gt;   &lt;/span&gt;&lt;a href="http://www.owasp.org/index.php/Membership/members"&gt;http://www.owasp.org/index.php/Membership/members&lt;/a&gt;&lt;span style=""&gt;  &lt;/span&gt;if you are not a individual member now is a perfect time to renew it.&lt;span style=""&gt;  &lt;/span&gt;If you work for a company that is a corporate supporter and you are the primary point of contact this only equals =&lt;span style=""&gt;  &lt;/span&gt;(1) vote.&lt;span style=""&gt;  &lt;/span&gt;Voting rights are assigned to individuals (yes actual people..) as outlined at: &lt;span style=""&gt; &lt;/span&gt;&lt;a href="http://www.owasp.org/index.php/Membership"&gt;http://www.owasp.org/index.php/Membership&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;So this quick updates means in summary that we are ALMOST ready to proceed, but there are a few moving parts;&lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;-&lt;span style=""&gt;  &lt;/span&gt;April we should be able to [commit] and then we can open a OWASP-ALL nomination process. It will be very similar to the process to the joining a global committee, where if you you are a OWASP member, contributor to projects/chapters and have endorsements of others you can draft your "WHY ME" and run for one of the 3 seats that will be up for election. &lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;- Candidates will be announced from at the kick-off of the Global AppSec Europe,&lt;span style=""&gt;  &lt;/span&gt;June 9th conference&lt;span style=""&gt;  &lt;/span&gt;and elections will follow three months later at the Global AppSec North America on September 22nd&lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;&lt;a href="http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference"&gt;http://www.owasp.org/index.php/Category:OWASP_AppSec_Conference&lt;/a&gt;&lt;span style=""&gt;  &lt;/span&gt;and it also happens to be our 10 year anniversary at OWASP Foundation.&lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;- If you are still reading this have free time, want to continue to help evolve a global community consider supporting or running for election yourself.&lt;span style=""&gt;  &lt;/span&gt;Now might be a good time to socialize your desire, get endorsements at your local chapter(s), asking the global committees for endorsement based on your accomplishments,&lt;span style=""&gt;  &lt;/span&gt;consider releasing that next owasp project to show folks what you are capable of in collaboration with others or as a individual and be in sync with what is happening at the Global Committee's &lt;a href="http://www.owasp.org/index.php/Global_Committee_Pages"&gt;http://www.owasp.org/index.php/Global_Committee_Pages&lt;/a&gt;&lt;span style=""&gt;   &lt;/span&gt;-&lt;span style=""&gt;  &lt;/span&gt;don't forget to have fun with ALL your volunteer efforts.&lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;Hope this update was helpful?&lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;Tom Brennan&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;973-202-0122&lt;/p&gt;  &lt;p class="MsoPlainText"&gt; &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;BTW in case you missed the updates from the Summit see:&lt;span style=""&gt;  &lt;/span&gt;&lt;a href="http://www.owasp.org/images/2/27/OWASP_Summit_2011_Results.pdf"&gt;http://www.owasp.org/images/2/27/OWASP_Summit_2011_Results.pdf&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4803227754238789087?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4803227754238789087/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/03/normal-0-false-false-false-en-us-x-none.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4803227754238789087'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4803227754238789087'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/03/normal-0-false-false-false-en-us-x-none.html' title='OWASP Board Election Update'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-7203220016684804886</id><published>2011-03-16T09:52:00.001-07:00</published><updated>2011-03-16T10:11:39.983-07:00</updated><title type='text'>OWASP AppSec EU - Registration Open &amp; CFP/CFT</title><content type='html'>&lt;span style="font-family:monospace;"&gt;Registration is OPEN!!!  Follow the link for information on Early Bird Pricing!&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/AppSecEU2011#tab=Registration"&gt;&lt;br /&gt;http://www.owasp.org/index.php/AppSecEU2011#tab=Registration&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;OWASP is currently soliciting training &amp;amp; presentation proposals for the OWASP AppSec Europe 2011 Conference which will take place at Trinity College Dublin in Ireland, on June 6th through June 10th 2010. There will be training courses on June 6th, 7th and 8th followed by plenary sessions on the 9th and 10th with each day having at least three tracks.&lt;br /&gt;&lt;br /&gt;Call for Training&lt;br /&gt;&lt;br /&gt;We are seeking training proposals on the following topics (in no particular order):&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Security in Web 2.0, Web Services/XML&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Advanced penetration testing&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Static analysis for security&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Threat modeling of applications&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Secure coding practices&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Security in J2EE/.NET patterns and frameworks&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Application security with ESAPI&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;OWASP tools in practice&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family:monospace;"&gt;We will look favorably on laboratory-based/hands-on training.&lt;br /&gt;&lt;br /&gt;Call for Presentations&lt;br /&gt;&lt;br /&gt;We are seeking people and organizations that want to present on any of the following topics (in no particular order):&lt;br /&gt;&lt;/span&gt;&lt;ul&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Business Risks with Application Security.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Starting and Managing Secure Development Lifecycle Programs.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Web Services-, XML- and Application Security.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Metrics for Application Security.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Application Threat Modeling.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Hands-on Source Code Review.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Web Application Security Testing.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;OWASP Tools and Projects.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Secure Coding Practices (J2EE/.NET).&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Privacy Concerns with Applications and Data Storage&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Web Application Security countermeasures&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Technology specific presentations on security such as AJAX, XML, etc.&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:monospace;"&gt;Anything else relating to OWASP and Application Security.&lt;/span&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style="font-family:monospace;"&gt;Submission Deadline and Instructions&lt;br /&gt;&lt;br /&gt;Submission deadline is Sunday April 3 23:59 (GMT).&lt;br /&gt;&lt;br /&gt;To submit your proposal please fill out the form here:&lt;br /&gt;&lt;a href="http://www.easychair.org/conferences/submission_new.cgi?a=c0b760808bfd"&gt;http://www.easychair.org/conferences/submission_new.cgi?a=c0b760808bfd&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Please specify in the form whether you are submitting a Training or a Presentation proposal. Eg. Title: "Training - Introduction to Web Application Security"&lt;br /&gt;&lt;br /&gt;Only for Training Proposals&lt;br /&gt;To submit your training proposal please fill out the&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/File:OWASP_AppSec_Europe_2011_Call_for_Training.docx"&gt;http://www.owasp.org/index.php/File:OWASP_AppSec_Europe_2011_Call_for_Training.docx&lt;/a&gt; and attach it while filling out the online form.&lt;br /&gt;&lt;br /&gt;Upon acceptance you'll be requested to fill out the Training Instructor Agreement where you'll find details on revenue split etc. The agreement will be reworked but the previous one is here: &lt;a href="http://www.owasp.org/index.php/File:Training_Instructor_Agreement.doc"&gt;http://www.owasp.org/index.php/File:Training_Instructor_Agreement.doc&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Further Information&lt;br /&gt;&lt;br /&gt;Mail: &lt;a href="mailto://ireland@owasp.org"&gt;ireland@owasp.org&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Website: &lt;a href="http://www.owasp.org/index.php/AppSecEU2011"&gt;http://www.owasp.org/index.php/AppSecEU2011&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Linkedin: &lt;a href="http://events.linkedin.com/OWASP-AppSec-Europe-2011/pub/522459"&gt;http://events.linkedin.com/OWASP-AppSec-Europe-2011/pub/522459&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Twitter: #appseceu11&lt;br /&gt;&lt;br /&gt;Kate Hartmann&lt;br /&gt;Operations Director&lt;br /&gt;301-275-9403&lt;br /&gt;www.owasp.org&lt;br /&gt;Skype:  Kate.hartmann1&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-7203220016684804886?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/7203220016684804886/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/03/owasp-appsec-eu-registration-open.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/7203220016684804886'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/7203220016684804886'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/03/owasp-appsec-eu-registration-open.html' title='OWASP AppSec EU - Registration Open &amp; CFP/CFT'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-7874974404340220670</id><published>2011-03-09T09:43:00.000-08:00</published><updated>2011-03-09T09:44:47.644-08:00</updated><title type='text'>OWASP ESAPI for Ruby v0.3</title><content type='html'>&lt;pre wrap=""&gt;(from Paolo Perego)&lt;br /&gt;&lt;br /&gt;I'd like to announce that the first public version (marked as 0.30.0) of the OWASP ESAPI for Ruby gem has been released.&lt;br /&gt;&lt;br /&gt;We choose to release early, release often so we started pushing out to the real world even if we started no more than a month ago. We started porting validators, codecs and filters but the road towards 1.0 is far from being close.&lt;br /&gt;&lt;br /&gt;Since a lot of work has to be done, we need a lot of talented people, so please go to &lt;a class="moz-txt-link-freetext" href="http://www.owasp.org/index.php/Projects/Owasp_Esapi_Ruby"&gt;http://www.owasp.org/index.php/Projects/Owasp_Esapi_Ruby&lt;/a&gt; and subscribe to the project mailing list. At the owasp.org webpage you can find link to source repository, with all the information you need to contribute to the project.&lt;br /&gt;&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="https://rubygems.org/gems/owasp-esapi-ruby"&gt;https://rubygems.org/gems/owasp-esapi-ruby&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Cheers&lt;br /&gt;Paolo Perego&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-7874974404340220670?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/7874974404340220670/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/03/owasp-esapi-for-ruby-v03.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/7874974404340220670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/7874974404340220670'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/03/owasp-esapi-for-ruby-v03.html' title='OWASP ESAPI for Ruby v0.3'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-3148510609773107021</id><published>2011-02-27T14:23:00.001-08:00</published><updated>2011-02-27T14:23:59.636-08:00</updated><title type='text'>OWASP Summit and AppSensor</title><content type='html'>&lt;pre wrap=""&gt;The AppSensor session at the OWASP World Summit was a great success. The focus of the discussion was where should AppSensor go next.  We covered all of the available items within the AppSensor project (AppSensor.jar w/ESAPI plugin, detection points guidance, extensive documentation, live running demos defendtheapp.com, etc) and posed the question "What do we need for your company to adopt AppSensor within your applications".  There was lots of energy in the room and all 50+ seats were filled.  AppSensor is really starting to take off and I'm excited at these results.  These ideas represent the next areas for the project to tackle in order to obtain wide adoption.&lt;br /&gt;&lt;br /&gt;Here are the outputs of that discussion as action items for the project.  Consider this an invitation for anyone to jump into the AppSensor project and lead one of these areas to success (email me and I can give you more info and support your efforts)&lt;br /&gt;&lt;br /&gt;* Concern over False Positives&lt;br /&gt;** Article to discuss why AppSensor false positives won't result in negative system performance or adversely impact non-malicious users. Target Audience: Product Managers, CSOs&lt;br /&gt;&lt;br /&gt;* Where is AppSensor integrated into development&lt;br /&gt;** Slides or article to demonstrate process of selecting AppSensor detection points during the threat modeling phase. Notes on how to communicate these requirements to developers. How to test proper deployment&lt;br /&gt;&lt;br /&gt;* Is there an AppSensor-like implementation that could be handled by operations?&lt;br /&gt;** This is not the traditional AppSensor approach (e.g. within the code), but we could do further research on aspect oriented implementations or real time log analysis for attack monitoring&lt;br /&gt;&lt;br /&gt;* Integration with libraries and frameworks&lt;br /&gt;** Sub project to submit patches for common frameworks to log obvious attack types. The goal is to at least get the logging of attack scenarios in place by default. This makes it easier to adopt an AppSensor approach onto these libraries or frameworks&lt;br /&gt;** Possible first target : Sonar (sonarsource.org) - May need to get more info on this idea&lt;br /&gt;&lt;br /&gt;* Testimonials from companies using AppSensor or AppSensor-like capabilities&lt;br /&gt;** This wil help raise confidence in the project for potential new adopters&lt;br /&gt;&lt;br /&gt;* Software - Code versioning, patching, support ?&lt;br /&gt;** This is a common concern for open source software and OWASP code. What can we do to help make our code more digestible by a company looking for these more stringent development patterns?&lt;br /&gt;&lt;br /&gt;* Link in with Fraud systems&lt;br /&gt;** The AppSensor project has been contacted by a large bank to help develop a strategy for detection of fraud through session hijacking and phishing.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Michael Coates&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-3148510609773107021?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/3148510609773107021/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/02/owasp-summit-and-appsensor.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3148510609773107021'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3148510609773107021'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/02/owasp-summit-and-appsensor.html' title='OWASP Summit and AppSensor'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-3540366764975812543</id><published>2011-02-23T12:19:00.000-08:00</published><updated>2011-02-23T12:21:08.539-08:00</updated><title type='text'>AppSec EU 2011 - First Challenge Released!</title><content type='html'>&lt;div&gt;Hi there,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For all those application security professionals and enthusiasts out there here is the first challenge to win a free entrance ticket for AppSec EU 2011.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;u&gt;*Introduction*&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;As some of you might know, Vicnum is an OWASP project which consists of a flexible web app showing vulnerabilities such as cross site scripting, sql injections, and session management issues. The tool could also be used by those setting up 'capture the flag' exercises or by those who just want to have some fun with web assessments. The Vicnum project was developed for educational purposes by Mordecai Kraushar from Ciphertechs.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;For today, we have prepared a customised version of Vicnum The Game that contains several exercises for your enjoyment.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;u&gt;*The Game*&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The computer will think of a three digit number with unique digits. After you attempt to guess the number, the computer will tell you how many of your digits match and how many are in the right position. Keeping on submitting three digit numbers until you have guessed the computer's number.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In order to win an free ticket to AppSec EU 2011 you need to solve the following exercises of Vicnum The Game.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;- Hack the game: Have a guess count of zero and a guess value &gt; 999&lt;/div&gt;&lt;div&gt;- Hack the database: Find the Vicnum player with the worst possible score (if there is a tie find the older record). Place another record in the database with that player's name concatenated to your name and with a positive score.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Once you solve the exercises, please send us an email to &lt;a href="mailto:ireland@owasp.org"&gt;ireland@owasp.org&lt;/a&gt; with your full name and details on how you accomplished this goal.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The first one who solves these exercises gets a free ticket to OWASP AppSec&lt;/div&gt;&lt;div&gt;EU 2011!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Please visit &lt;a href="http://www.appseceu.org/?page_id=175"&gt;http://www.appseceu.org/?page_id=175&lt;/a&gt; to find out further details about the challenge.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;A big THANKS goes to Mordecai for setting up and customizing the challenge.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Thank you and best of luck everyone!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Fabio Cerullo&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-3540366764975812543?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/3540366764975812543/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/02/appsec-eu-2011-first-challenge-released.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3540366764975812543'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3540366764975812543'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/02/appsec-eu-2011-first-challenge-released.html' title='AppSec EU 2011 - First Challenge Released!'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-5651488425324982307</id><published>2011-02-22T22:13:00.000-08:00</published><updated>2011-02-22T22:14:22.684-08:00</updated><title type='text'>Application Security Track at Uber Conf 2011 - July 12-15</title><content type='html'>&lt;pre wrap=""&gt;OWASP is currently soliciting papers for the Application Security Track at Uber Conf, Denver, CO.&lt;br /&gt;&lt;br /&gt;OWASP is partnering with Uber Conf to have an Application Security track at this prestigious conference. Brought to you by the No Fluff Just Stuff Software Symposium Series, Über Conf will explore the ever evolving ecosystem of Java the Platform.&lt;br /&gt;&lt;br /&gt;The Ü will offer over 120 technically focused sessions including hands on workshops centered around Architecture, Cloud, Security, Enterprise Java, Languages on the JVM, Build/Test, Mobility and Agility. The goal of Über Conf is a simple one: totally blow the minds of our attendees.&lt;br /&gt;&lt;br /&gt;We are seeking people and organizations that want to present about how security relates to the following Java topics (in no particular order):&lt;br /&gt;&lt;br /&gt;  * Architecture&lt;br /&gt;  * Enterprise Java&lt;br /&gt;  * Java Internals&lt;br /&gt;  * Security - Enterprise &amp;amp; JVM&lt;br /&gt;  * Cloud Computing&lt;br /&gt;  * Languages on the JVM - Groovy, JRuby, Scala &amp;amp; Clojure&lt;br /&gt;  * Java Web Frameworks - Wicket, Tapestry &amp;amp; SpringMVC&lt;br /&gt;  * Build Systems - Maven &amp;amp; Gradle&lt;br /&gt;  * Testing&lt;br /&gt;  * Agility&lt;br /&gt;  * Tools&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;How to make a submission:&lt;br /&gt;  * Fill the form available at&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://www.owasp.org/images/4/42/UberConf.AppSec.CFP.rtf.zip"&gt;http://www.owasp.org/images/4/42/UberConf.AppSec.CFP.rtf.zip&lt;/a&gt;&lt;br /&gt;  * Submit the filled form at&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="https://www.easychair.org/conferences/?conf=appsecatuberconf2011"&gt;https://www.easychair.org/conferences/?conf=appsecatuberconf2011&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Submission deadline is Feb 28th at 12PM EST (GMT-5)&lt;br /&gt;&lt;br /&gt;Submit Proposals to:&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="https://www.easychair.org/conferences/?conf=appsecatuberconf2011"&gt;https://www.easychair.org/conferences/?conf=appsecatuberconf2011&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Conference Website:&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://uberconf.com/conference/denver/2011/07/home"&gt;http://uberconf.com/conference/denver/2011/07/home&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;OWASP Website:&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://www.owasp.org/"&gt;http://www.owasp.org&lt;/a&gt; &lt;a class="moz-txt-link-rfc2396E" href="http://www.owasp.org/"&gt;&lt;http://www.owasp.org/&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Please forward to all interested practitioners and colleagues.&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-5651488425324982307?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/5651488425324982307/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/02/application-security-track-at-uber-conf.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5651488425324982307'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5651488425324982307'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/02/application-security-track-at-uber-conf.html' title='Application Security Track at Uber Conf 2011 - July 12-15'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-8092424113686643504</id><published>2011-02-22T02:02:00.001-08:00</published><updated>2011-02-22T02:04:15.711-08:00</updated><title type='text'>AppSec USA 2011 Minneapolis</title><content type='html'>&lt;pre wrap=""&gt;OWASP is proud to announce AppSec USA 2011. We're celebrating our first ten years and looking ahead to the next ten years!&lt;br /&gt;&lt;br /&gt;Training will be held September 20-21. Talks, CTF, and showroom will be September 22-23. AppSec USA 2011 will be hosted in Minneapolis, Minnesota at the Minneapolis Convention Center.&lt;br /&gt;&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://www.appsecusa.org/"&gt;http://www.appsecusa.org/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;CALL FOR TRAINERS NOW OPEN&lt;/span&gt;&lt;br /&gt;Think you have a great idea for a one- or two-day class? Submit your idea to Kuai Hinojosa at &lt;a class="moz-txt-link-abbreviated" href="mailto:kuai.hinojosa@owasp.org"&gt;kuai.hinojosa@owasp.org&lt;/a&gt;. Trainers get a 40% cut of the training revenue. Price for trainees will be $1,500 for a 2-day training course and $750 for a 1-day training course (see&lt;a class="moz-txt-link-freetext" href="http://www.appsecusa.org/training.html"&gt; http://www.appsecusa.org/training.html&lt;/a&gt; for additional information on group registration discounts). Please e-mail &lt;a class="moz-txt-link-abbreviated" href="mailto:lorna.alamri@owasp.org"&gt;lorna.alamri@owasp.org&lt;/a&gt; if you would like to reserve trainee space for your organization today.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;CALL FOR PAPERS OPENS MARCH 15&lt;/span&gt;&lt;br /&gt;The call for papers will open March 15. We are excited for high quality submissions from application security professionals, software developers, and thought leaders. This year's format will be four tracks spread across two days covering Cloud Security, Mobile Security, Secure SDLC, OWASP Projects (turbo talks), Software &amp;amp; Architecture Patterns for Security, Software Development Platform Tutorials, New Attacks &amp;amp; Defenses, and Thought Leadership (executive panels, interviews, and speeches). Please e-mail &lt;a class="moz-txt-link-abbreviated" href="mailto:lorna.alamri@owasp.org"&gt;lorna.alamri@owasp.org&lt;/a&gt; if you would like to reserve conference passes for your organization today at heavily discounted rates. And stay tuned for the call for papers announcement...&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;SPONSORSHIP OPPORTUNITIES&lt;/span&gt;&lt;br /&gt;AppSec USA 2011 will be a great opportunity to let the community know about your products and services, and also a great time to recruit new talent. See &lt;a class="moz-txt-link-freetext" href="http://www.appsecusa.org/sponsors.html"&gt;http://www.appsecusa.org/sponsors.html&lt;/a&gt; for sponsorship opportunities. We would like to thank IBM for being our first AppSec USA 2011 sponsor!&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;CAPTURE THE FLAG (CTF)&lt;/span&gt;&lt;br /&gt;This year's AppSec USA CTF promises to be the best one yet. If you'd like to volunteer or get prepared for the CTF, visit &lt;a class="moz-txt-link-freetext" href="http://www.appsecusa.org/ctf.html"&gt;http://www.appsecusa.org/ctf.html&lt;/a&gt; and send an e-mail to the CTF team.&lt;br /&gt;&lt;br /&gt;Thank you!&lt;br /&gt;&lt;br /&gt;OWASP AppSec USA 2011: Your life is in the cloud.&lt;br /&gt;Web: &lt;a class="moz-txt-link-freetext" href="http://www.appsecusa.org/"&gt;http://www.appsecusa.org/&lt;/a&gt;&lt;br /&gt;Twitter: @appsecusa&lt;br /&gt;&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-8092424113686643504?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/8092424113686643504/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/02/appsec-usa-2011-minneapolis.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8092424113686643504'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8092424113686643504'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/02/appsec-usa-2011-minneapolis.html' title='AppSec USA 2011 Minneapolis'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-3996150145756802557</id><published>2011-02-15T21:21:00.000-08:00</published><updated>2011-02-16T19:11:49.512-08:00</updated><title type='text'>ESAPI and the Padding Oracle Attack</title><content type='html'>&lt;pre wrap=""&gt;From Kevin Wall.&lt;br /&gt;&lt;br /&gt;I originally noticed that the ESAPI symmetric encryption provided no authenticity way back in August 2009 and argued for a very long time with Jim Manico that what was present in ESAPI 1.4 and 2.0rc3 (or maybe it was rc2?) needed to be burned to the ground and replaced, and he agreed. All I remembered was some type of an attack against cipher padding that caused by one tweaking IVs in a certain way and then looking for errors. I remembered that IPSec at one time had been vulnerable to this same vulnerability, but I just couldn't remember the name of the attack or who or when he wrote about it (S. Vaudenay in 2002) so unfortunately couldn't easily search for it. Fortunately, I knew that I had to use a MAC or an authenticated cipher mode to fix it.&lt;br /&gt;&lt;br /&gt;After a few months of arguing on the ESAPI developer list that this was something that needed to be addressed, I finally was able to convince people convince the ESAPI community and I volunteered to make the code changes. Had I been able to find Vaudenay's paper and site it, I probably would have been able to convince folks that changing ESAPI's encryption was necessary...especially that Jim Manico guy. ;-) [Aside: Ironically it was this weakness in ESAPI's crypto that caused me to get involved with ESAPI development. I really liked what it presented and wanted to introduce it at Qwest once it was GA, but I was concerned that Qwest developers that would use the broken ESAPI crypto rather then the encryption library we had developed in-house.]&lt;br /&gt;&lt;br /&gt;Anyway, subsequent to the the Rizzo / Duong paper appearing, there was probably at least 4-6 sman months of re-design and recoding effort that had taken place.&lt;br /&gt;&lt;br /&gt;In fact, at one point I had things just right (apart from using a timing side-channel as padding oracle), but then *in a moment of clear stupidity*, I went in and changed a few of the exception messages intended for end users "to clarify things a bit". My (faulty) reasoning was that if a user got an encryption error and called a help desk, s/he could only report what s/he could see as he error message. But since the error message could be caused by two very different things I decided to make them slightly different so help desk personnel could distinguish between the two cases and act accordingly. (I know, the *logged* error messages were different, but I figured very few tier 1 help desk people ever have access to log files.)&lt;br /&gt;&lt;br /&gt;Anyway, this was a *BIG* mistake and reintroduced the padding oracle attack, although not in the same way that earlier versions of ESAPI had, as they did not support authenticity at all.&lt;br /&gt;&lt;br /&gt;So the bottom line is the *reason* that "we fixed padding oracle in ESAPI *very* quickly after the paper came out" is all I really had to do to fix it was to go back and change it so that the user intended exception messages were identical in each case. (I also put in some protection against using timing as a side-channel attack as the padding oracle, but that was pretty straightforward.)&lt;br /&gt;&lt;br /&gt;Had the NSA completed their crypto review and mentioned this (they didn't and it's not entirely clear that they ever would have!), then this would have been have been fixed without drawing so much attention. But in a way, I consider it serendipitous that it came out in the Duong &amp;amp; Rizzo paper that ESAPI was somewhat vulnerable. By comparison, ESAPI faired well against the others described their paper. I think had ESAPI not been vulnerable, it likely would not have been mentioned at all in their paper and the conclusion of Rizzo's and Duong's readers would have been that they had not evaluated ESAPI's symmetric encryption at all.  As it was, it allowed us a platform to be transparent to the OWASP community, tell them how we were addressing the problem, and (IMO) most importantly brought home the seriousness of what I had been saying all along about ESAPI 1.4 encryption being badly broken which motivated getting people off of it.&lt;br /&gt;&lt;br /&gt;The reason we were so quick to get it fixed is because we had it 95% right in the first place. (Unfortunately, 95% right is 5% wrong and with vulnerabilities, that's all it takes.)&lt;br /&gt;&lt;br /&gt;Thanks for your time,&lt;br /&gt;-kevin&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-3996150145756802557?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/3996150145756802557/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/02/esapi-and-oracle-padding-attack.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3996150145756802557'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3996150145756802557'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/02/esapi-and-oracle-padding-attack.html' title='ESAPI and the Padding Oracle Attack'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-1945426870177366911</id><published>2011-02-15T16:34:00.000-08:00</published><updated>2011-02-15T16:34:04.273-08:00</updated><title type='text'>OWASP Summit 2011 Results</title><content type='html'>&lt;span class="Apple-style-span" style="border-collapse: collapse; font-family: arial, sans-serif; font-size: 13px;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;div&gt;I'm very proud to announce the Summit 2011 Results, which you can download from here:&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li style="margin-left: 15px;"&gt;&lt;a href="http://www.owasp.org/images/2/27/OWASP_Summit_2011_Results.pdf" style="color: #2a5db0;" target="_blank"&gt;Pdf Format&lt;/a&gt; (&lt;a href="http://www.owasp.org/images/2/27/OWASP_Summit_2011_Results.pdf" style="color: #2a5db0;" target="_blank"&gt;http://www.owasp.org/&lt;wbr&gt;&lt;/wbr&gt;images/2/27/OWASP_Summit_2011_&lt;wbr&gt;&lt;/wbr&gt;Results.pdf&lt;/a&gt;)&lt;/li&gt;&lt;li style="margin-left: 15px;"&gt;&lt;a href="http://www.owasp.org/images/2/27/OWASP_Summit_2011_Results.docx" style="color: #2a5db0;" target="_blank"&gt;Word Format&lt;/a&gt; (&lt;a href="http://www.owasp.org/images/2/27/OWASP_Summit_2011_Results.docx" style="color: #2a5db0;" target="_blank"&gt;http://www.owasp.org/&lt;wbr&gt;&lt;/wbr&gt;images/2/27/OWASP_Summit_2011_&lt;wbr&gt;&lt;/wbr&gt;Results.docx&lt;/a&gt;)&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;As  you can see by the Summit's highlights, we achieved an amazing amount  of work during the 3 days we were together in Portugal! &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Amazingly,  we also had a great time, and created/consolidated an enormous amount  of friendships/relationships. Just look at the the number of similes  (and focused faces) that exist on the Summit's official photo album: &lt;a href="https://picasaweb.google.com/owaspphotos/OWASPSummit" style="color: #2a5db0;" target="_blank"&gt;https://picasaweb.&lt;wbr&gt;&lt;/wbr&gt;google.com/owaspphotos/&lt;wbr&gt;&lt;/wbr&gt;OWASPSummit&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I  would like to take this opportunity to thank the Summit organization  team, the Working Session chairs, the 180 on-site participants and the  1000s remote participants, for working so hard and achieving so much. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Note  that this is the first version of this document. There is work already  underway to create a much more detailed and comprehensive version of  this document, which will be released as a number of books (Summit 2011  Final Report, Browser Security Report 2011, etc...).&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Please distribute this document/Press-Release as widely as possible.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-1945426870177366911?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/1945426870177366911/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/02/owasp-summit-2011-results.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1945426870177366911'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1945426870177366911'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/02/owasp-summit-2011-results.html' title='OWASP Summit 2011 Results'/><author><name>Michael Coates</name><uri>http://www.blogger.com/profile/01776444965999374544</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_MiAJXkPG1IM/StSyGcceaDI/AAAAAAAABR4/ZNH2XgLAgM8/S220/MichaelCoates.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-8617614899289361348</id><published>2011-02-01T17:45:00.000-08:00</published><updated>2011-02-01T17:47:09.912-08:00</updated><title type='text'>OWASP Summit Press Release</title><content type='html'>FOR IMMEDIATE RELEASE - PLEASE DISTRIBUTE&lt;br /&gt;&lt;br /&gt;Top security experts meet in Portugal to discuss the future of application security Portugal, Lisbon, January 28, 2011 - The OWASP (Open Web Application Security Project) Global Summit, held in February 8th-11th in Lisbon, will bring together the most prominent experts in the area of web application security, with the purpose to further the development of the ongoing efforts in application security and to promote solutions that will help reduce the risks and the mistakes incurred by everyone who uses the Web as a workplace and as an information sharing tool – personal, corporate and governmental alike.&lt;br /&gt;&lt;br /&gt;The Summit will consist of intensive and collaborative four-day working sessions across a variety of important topics to our industry such as metrics, browser security, cross-site scripting eradication, mitigation and secure coding.&lt;br /&gt;&lt;br /&gt;What’s at stake is tackling the threats of cybercrime, either by making clear that security breaches have high costs to organizations, either by explaining the heavy impact that privacy violation has on users.&lt;br /&gt;&lt;br /&gt;More than 175 attendees are expected, from more than 20 countries, including top OWASP leaders and security gurus from Google, Mozilla, Microsoft, Paypal, Dell, Apache, Verizon, and many more.&lt;br /&gt;&lt;br /&gt;These topics are of the utmost importance, due to the recent development of information systems and of the emergence of web 2.0 technologies, along with the corresponding increase in web applications and services, bringing forth so many implications regarding security and privacy. Never in our lives have we had so much critical personal information being so dependent and simultaneously so threatened by software and web applications (example: Facebook)&lt;br /&gt;&lt;br /&gt;Despite the growing investments in security processes and techniques, the truth is we are in a critical situation. AppSecs still have massive vulnerabilities caused by the multiplicity of tasks and/or tools while vendors and clients lack the awareness to address the issue. These are two weaknesses that are obviously leading to increasingly malicious attackers&lt;br /&gt;Given the general lack of awareness we can question what scenario would ultimately drive people or governments to take action. Widespread identity theft? Financial collapse? Mass logistic failure? Loss of critical information? Medical Systems Exploitation? Fraud? Paralyzed public institutions?&lt;br /&gt;&lt;br /&gt;OWASP challenges application security leaders and industry players to share their expertise, experience and point of views to help reinforce web application security.&lt;br /&gt;&lt;br /&gt;###&lt;br /&gt;&lt;br /&gt;About OWASP&lt;br /&gt;&lt;br /&gt;The Open Web Application Security Project (OWASP) is an open-source application security project. The OWASP community includes corporations, educational organizations, and individuals from around the world. This community works voluntarily to create freely-available articles, methodologies, documentation, tools, and technologies. The OWASP Foundation is a charitable organization that supports and manages OWASP projects and infrastructure.&lt;br /&gt;&lt;br /&gt;Contact Information: Abigail Vistas&lt;br /&gt;avistas@generator.pt&lt;br /&gt;217800828 – 916406948&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-8617614899289361348?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/8617614899289361348/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/02/owasp-summit-press-release.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8617614899289361348'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8617614899289361348'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/02/owasp-summit-press-release.html' title='OWASP Summit Press Release'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-505540477570829019</id><published>2011-01-24T06:29:00.001-08:00</published><updated>2011-01-24T06:30:47.911-08:00</updated><title type='text'>OWASP Summit JS Challenge</title><content type='html'>&lt;pre wrap=""&gt;Hi OWASPers, WebAppSecers and Secure Coders!&lt;/pre&gt;&lt;pre wrap=""&gt;The official OWASP Summit Challenge is out – a JavaScript fighting arena where your script should show its name more prominently than its competitors. &lt;/pre&gt;&lt;pre wrap=""&gt;Check it out: &lt;a class="moz-txt-link-freetext" href="http://makexorbreak.com/"&gt;http://makeXORbreak.com&lt;/a&gt; &lt;/pre&gt;&lt;pre wrap=""&gt;By this we start the countdown to one of the most important meetings in application security history. February 8-11 we invite you all to join round-table discussions with industry and research leaders on how to solve XSS and enhance browser security, which appsec metrics work, security of HTML5 and EcmaScript 5 and more. We truly believe that crucial things can happen in a social, productivity-oriented environment. That's why OWASP is going all-in on the Summit.  &lt;/pre&gt;&lt;pre wrap=""&gt;Google will be there. Mozilla will be there. Microsoft will be there. Facebook will be there. PayPal will be there. Apache will be there. The world's top appsec companies will be there. The authors of (my) favorite appsec books will be there. Best thing of all? &lt;/pre&gt;&lt;pre wrap=""&gt;You are most welcome to join!  &lt;a class="moz-txt-link-freetext" href="http://www.owasp.org/index.php/OWASP_Summit_2011"&gt;http://www.owasp.org/index.php/OWASP_Summit_2011&lt;/a&gt;     &lt;/pre&gt;&lt;pre wrap=""&gt;Get going with the Challenge – &lt;a class="moz-txt-link-freetext" href="http://makexorbreak.com/"&gt;http://makeXORbreak.com&lt;/a&gt;    &lt;/pre&gt;&lt;pre wrap=""&gt;Best regards, John Wilander &lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-505540477570829019?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/505540477570829019/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/01/owasp-summit-js-challenge.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/505540477570829019'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/505540477570829019'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/01/owasp-summit-js-challenge.html' title='OWASP Summit JS Challenge'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-132537193667688283</id><published>2011-01-13T07:17:00.000-08:00</published><updated>2011-01-13T07:19:12.288-08:00</updated><title type='text'>Got Hosting?</title><content type='html'>&lt;pre wrap=""&gt;&lt;span class="Apple-style-span" &gt;The Open Web Application Security Project (OWASP) is seeking competitive quotations for a dedicated web hosting environment hereafter described. Contractors qualified to fulfill these requirements are invited to submit quotations  &lt;/span&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;span class="Apple-style-span" &gt;DETAILS: &lt;a class="moz-txt-link-freetext" href="http://www.owasp.org/index.php/RFO_and_hosting_information"&gt;http://www.owasp.org/index.php/RFO_and_hosting_information&lt;/a&gt;  &lt;/span&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;span class="Apple-style-span" &gt;If you are willing to take on the hosting, administration in whole or in part we want to hear from you.&lt;/span&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;span class="Apple-style-span" &gt;In addition to current project of website redesign, our timeline is to announce the award of the project is OWASP Summit 2011:  &lt;a class="moz-txt-link-freetext" href="http://www.owasp.org/index.php/Summit_2011"&gt;http://www.owasp.org/index.php/Summit_2011&lt;/a&gt;&lt;/span&gt;&lt;/pre&gt;&lt;pre wrap=""&gt;&lt;span class="Apple-style-span" &gt;&lt;a class="moz-txt-link-freetext" href="http://www.owasp.org/index.php/Summit_2011"&gt;&lt;/a&gt;Great opportunity to help the community and and support the mission of our professional association!  &lt;/span&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-132537193667688283?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/132537193667688283/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/01/got-hosting.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/132537193667688283'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/132537193667688283'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/01/got-hosting.html' title='Got Hosting?'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4281872167961137478</id><published>2011-01-12T07:31:00.000-08:00</published><updated>2011-01-12T07:32:13.214-08:00</updated><title type='text'>Please support the OWASP Global Summit</title><content type='html'>&lt;p class="MsoNormal"&gt;&lt;span class="apple-tab-span"&gt;&lt;b&gt;&lt;span style="mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;"&gt;The OWASP Global Summit &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;b&gt;&lt;span style="mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;"&gt;Feb 8th - 11th&lt;/span&gt;&lt;/b&gt;&lt;span style="mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;"&gt;, &lt;span class="apple-tab-span"&gt;is&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;&lt;/span&gt;where industry and &lt;span class="apple-tab-span"&gt;application security &lt;/span&gt;practitioners&lt;span class="apple-tab-span"&gt; from around the world will &lt;/span&gt;assemble, collaborate and set the agenda for the forthcoming advancements of the OWASP mission.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:12.0pt"&gt;&lt;span style="mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;"&gt;&lt;span class="apple-tab-span"&gt;&lt;b&gt;What option will you choose to show the world your support? &lt;/b&gt;&lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span class="apple-tab-span"&gt;&lt;span style="mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;"&gt;* Sponsored Villa 10 &lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;"&gt;&lt;br /&gt;&lt;span class="apple-tab-span"&gt;* Meeting Room Sponsorshi&lt;/span&gt;p(s)&lt;span class="apple-tab-span"&gt; 6k &lt;/span&gt;&lt;br /&gt;&lt;span class="apple-tab-span"&gt;* Projector Sponsorship&lt;/span&gt;(s)&lt;span class="apple-tab-span"&gt; 2k &lt;/span&gt;&lt;br /&gt;&lt;span class="apple-tab-span"&gt;* Lunch Sponsorship&lt;/span&gt;(s)&lt;span class="apple-tab-span"&gt; 2k &lt;/span&gt;&lt;br /&gt;&lt;span class="apple-tab-span"&gt;* Happy Hour/ Social Session Sponsorship&lt;/span&gt;(s)&lt;span class="apple-tab-span"&gt; 2k &lt;/span&gt;&lt;br /&gt;&lt;span class="apple-tab-span"&gt;* Dinner Sponsorship&lt;/span&gt;(s)&lt;span class="apple-tab-span"&gt; 4k &lt;/span&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span class="apple-tab-span"&gt;&lt;span style="mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;"&gt;*&lt;/span&gt;&lt;/span&gt;&lt;span style="mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;"&gt; You will be in attendance&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;span style="mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;span class="apple-tab-span"&gt;&lt;b&gt;&lt;span style="mso-fareast-font-family: &amp;quot;Times New Roman&amp;quot;"&gt;Full Details:&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;span class="apple-tab-span"&gt;&lt;span style="mso-fareast-font-family:&amp;quot;Times New Roman&amp;quot;"&gt;&lt;a href="http://www.owasp.org/index.php/Summit_2011_Corporate_Sponsorship"&gt;http://www.owasp.org/index.php/Summit_2011_Corporate_Sponsorship&lt;/a&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;F&lt;span class="apple-tab-span"&gt;or more information about &lt;/span&gt;the Summit see: FAQ&lt;span class="apple-tab-span"&gt; &lt;a href="http://www.owasp.org/index.php/Summit_2011_FAQ"&gt;http://www.owasp.org/index.php/Summit_2011_FAQ&lt;/a&gt; &lt;/span&gt;or contact Tom Brennan directly at 973-202-0122 to discuss how you would like to be involved.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;More information about the Summit:  &lt;a href="http://www.owasp.org/index.php/Summit_2011"&gt;http://www.owasp.org/index.php/Summit_2011&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4281872167961137478?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4281872167961137478/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/01/please-support-owasp-global-summit.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4281872167961137478'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4281872167961137478'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/01/please-support-owasp-global-summit.html' title='Please support the OWASP Global Summit'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-6399804614541238908</id><published>2011-01-10T23:23:00.000-08:00</published><updated>2011-01-10T23:24:04.793-08:00</updated><title type='text'>OWASP Global Summit Sponsorship</title><content type='html'>&lt;span class="text"&gt;&lt;span style="font-size:8.0pt; font-family:&amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;mso-fareast-font-family:Calibri;mso-fareast-theme-font: minor-latin;mso-ansi-language:EN-US;mso-fareast-language:EN-US;mso-bidi-language: AR-SA"&gt;The OWASP Global Summit is the place where application security experts from around the world will meet to discuss progress, plans, projects and new solutions for the future of the application security.&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:8.0pt;font-family:&amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;;mso-fareast-font-family: Calibri;mso-fareast-theme-font:minor-latin;mso-ansi-language:EN-US;mso-fareast-language: EN-US;mso-bidi-language:AR-SA"&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="text"&gt;What option will you choose to show your support at the Global Summit?&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="text"&gt;Full details: &lt;/span&gt;&lt;a href="http://sl.owasp.org/summitsupport" target="_blank"&gt;http://sl.owasp.org/summitsupport&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="text"&gt;* Sponsored Villa 10k&lt;/span&gt;&lt;br /&gt;&lt;span class="text"&gt;* Meeting Room Sponsorship 6k&lt;/span&gt;&lt;br /&gt;&lt;span class="text"&gt;* Projector Sponsorship 2k&lt;/span&gt;&lt;br /&gt;&lt;span class="text"&gt;* Lunch Sponsorship 2k&lt;/span&gt;&lt;br /&gt;&lt;span class="text"&gt;* Happy Hour/ Social Session Sponsorship 2k&lt;/span&gt;&lt;br /&gt;&lt;span class="text"&gt;* Dinner Sponsorship 4k&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span class="text"&gt;ACT NOW Space is limited - Contact Tom Brennan 973-202-0122 for more information about opportunities or click here: &lt;/span&gt;&lt;a href="http://www.owasp.org/index.php/Summit_2011_FAQ" target="_blank"&gt;http://www.owasp.org/index.php/Summit_2011_FAQ&lt;/a&gt; &lt;span class="text"&gt;for other FAQ&lt;/span&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-6399804614541238908?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/6399804614541238908/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/01/owasp-global-summit-sponsorship.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6399804614541238908'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6399804614541238908'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/01/owasp-global-summit-sponsorship.html' title='OWASP Global Summit Sponsorship'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-2305332777304893504</id><published>2011-01-06T14:07:00.000-08:00</published><updated>2011-01-06T14:07:42.221-08:00</updated><title type='text'>OWASP Chapter Leaders - Chapter Status Update Needed!</title><content type='html'>Chapter Leaders,&lt;br /&gt;&lt;br /&gt;The January 15 deadline is approaching for chapter leaders to provide the chapter status information requested here:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/Donation_Scoreboard"&gt;http://www.owasp.org/index.php/Donation_Scoreboard&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;This important update is required as part of the OWASP planning process and also indicates that the local chapter is alive and well.&amp;nbsp; You have probably noticed this request on several mailing lists.&lt;br /&gt;&lt;br /&gt;Below is a link showing active OWASP chapters that have responded so far.&lt;br /&gt;&lt;a href="https://spreadsheets.google.com/a/owasp.org/ccc?key=0AhtB029bdcxGdDZmS0JkeXZXQ245c0IyVnBfZ0FhNXc&amp;amp;hl=en&amp;amp;authkey=CLLgpuYD"&gt;https://spreadsheets.google.com/a/owasp.org/ccc?key=0AhtB029bdcxGdDZmS0JkeXZXQ245c0IyVnBfZ0FhNXc&amp;amp;hl=en&amp;amp;authkey=CLLgpuYD&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;** &lt;b&gt;Important&lt;/b&gt;: Chapters that fail to respond before the deadline will be marked as inactive and any funds in the chapter bucket see:&amp;nbsp; &lt;a href="https://spreadsheets.google.com/pub?key=p6IFyntQTi7t-yH-peiD8Aw"&gt;https://spreadsheets.google.com/pub?key=p6IFyntQTi7t-yH-peiD8Aw&lt;/a&gt; will be transferred to the OWASP Summit Fund to help offset costs for travel for those that want to attend the 2011 Summit of OWASP 4.0&amp;nbsp; &lt;a href="http://www.owasp.org/index.php/Summit_2011"&gt;http://www.owasp.org/index.php/Summit_2011&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;** Note: To view the shared OSTF document, you must use your @OWASP.ORG email address&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-2305332777304893504?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/2305332777304893504/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2011/01/owasp-chapter-leaders-chapter-status.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2305332777304893504'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2305332777304893504'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2011/01/owasp-chapter-leaders-chapter-status.html' title='OWASP Chapter Leaders - Chapter Status Update Needed!'/><author><name>Michael Coates</name><uri>http://www.blogger.com/profile/01776444965999374544</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_MiAJXkPG1IM/StSyGcceaDI/AAAAAAAABR4/ZNH2XgLAgM8/S220/MichaelCoates.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-104899966053540835</id><published>2010-12-29T16:35:00.001-08:00</published><updated>2010-12-29T16:35:56.169-08:00</updated><title type='text'>December 2010 OWASP Newsletter</title><content type='html'>&lt;p class="MsoNormal"&gt;I am happy to be able to send out the December 2010 OWASP Newsletter!  &lt;a href="http://www.owasp.org/index.php/Category:OWASP_Newsletter#tab=Newsletters"&gt;http://www.owasp.org/index.php/Category:OWASP_Newsletter#tab=Newsletters&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Thank you to our editor, Lorna Alamri, MN Chapter co-leader, AppSec US 2011 organizer, Summit 2011 organizer, Industry Committee member, and global contributor.&lt;br /&gt;&lt;br /&gt;Happy Holidays!&lt;br /&gt;&lt;br /&gt;Kate Hartmann&lt;br /&gt;Operations Director&lt;br /&gt;301-275-9403&lt;br /&gt;&lt;a href="http://www.owasp.org/"&gt;www.owasp.org&lt;/a&gt;&lt;br /&gt;Skype:  Kate.hartmann1&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-104899966053540835?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/104899966053540835/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/12/december-2010-owasp-newsletter.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/104899966053540835'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/104899966053540835'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/12/december-2010-owasp-newsletter.html' title='December 2010 OWASP Newsletter'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4804111359669444835</id><published>2010-12-15T23:27:00.000-08:00</published><updated>2010-12-15T23:28:43.029-08:00</updated><title type='text'>OWASP 2011 Membership</title><content type='html'>(by Tom Brennan)&lt;div&gt;&lt;p class="MsoPlainText"&gt;Can you believe the OWASP concept is approaching 10 years old?!!&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;It's those little things like volunteering your time, insight expertise and membership to a professional organization that make the bigger things possible and effect the mission.&lt;span style="mso-spacerun:yes"&gt;   &lt;/span&gt;In growing a community, being taken seriously as a body, having citations from around the world, employees, administrative costs and even having the ability to allocate 50k in funds to put towards a global summit in 2011 is progress.&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;But no matter how many hours volunteered to it (OWASP), to be recognized as a "member" in 2011 starts with agreement to the principals and donation of $50usd as a member.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;While everything is free at OWASP this "designation" comes with a privilege that others don't get, that is the ability to support or effect change with a collective consensus of his/her peers and a vote.&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;Since 2002 I have personally experienced a variety of perspectives:&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;-Outsider looking for resources&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;-Individual Member&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;-Chapter Leader&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;-Board Member&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;-Project Leader&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;-Project Contributor&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;-Project Reviewer&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;-Trainer&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;-Evangelist &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;-Active Committee Member&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;-Member of a Supporting Sponsor(s)&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;In each role the perception of the of OWASP is different at the 2011 summit I hope to unify this important membership topic and I hope you will join us for the discussion. It's worth my $50 bucks per year.&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;Example&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;*For persons going to the summit as a example if they have not paid there $50 individual membership fee... Please complete this transaction as a prerequisite. This includes everyone from the board members to the newest member of this mailing list.&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;Not going to the summit but running a local chapter, do you lead by example with membership?&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;The current memberlist:&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;&lt;a href="http://spreadsheets.google.com/pub?key=p6IFyntQTi7sxa2Xjx191BA"&gt;http://spreadsheets.google.com/pub?key=p6IFyntQTi7sxa2Xjx191BA&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;How/where do you join? &lt;/p&gt;  &lt;p class="MsoPlainText"&gt;&lt;a href="http://www.owasp.org/index.php/Membership"&gt;http://www.owasp.org/index.php/Membership&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;FAQ: If my company(5k) or university($0) is a supporter does this make me a member?&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;Answer: No - however some have called it&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;"associated member/lite member" as in associated with the supporting company however note, this has no voting right in the association.&lt;/p&gt;  &lt;p class="MsoPlainText"&gt;Support the mission, change the world.&lt;/p&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4804111359669444835?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4804111359669444835/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/12/owasp-2011-membership.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4804111359669444835'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4804111359669444835'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/12/owasp-2011-membership.html' title='OWASP 2011 Membership'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-8088564893387370768</id><published>2010-12-15T23:10:00.000-08:00</published><updated>2010-12-15T23:12:23.044-08:00</updated><title type='text'>OWASP CSRFGuard 3.0.0.336</title><content type='html'>&lt;p class="MsoNormal"&gt;(from Eric Sheridan)&lt;/p&gt;&lt;p class="MsoNormal"&gt;It is with great pride that I announce the release of OWASP CSRFGuard 3.0.0.336 (ALPHA)! This is a development release of the v3 series that is in need of peer review, testing, and general feedback in preparation for BETA. There are several significant new features that are in need of testing in the enterprise development environments. Please contact me for support if you are interested in testing the latest release. Of course, I am always open to questions, comments, or feature requests! &lt;/p&gt;&lt;p class="MsoNormal"&gt;Please check out the project home page (&lt;a href="http://www.owasp.org/index.php/Category:OWASP_CSRFGuard_Project"&gt;http://www.owasp.org/index.php/Category:OWASP_CSRFGuard_Project&lt;/a&gt;) and User Manual (&lt;a href="http://www.owasp.org/index.php/CSRFGuard_3_User_Manual"&gt;http://www.owasp.org/index.php/CSRFGuard_3_User_Manual&lt;/a&gt;) for more information about how to install, configure, and deploy the OWASP CSRFGuard library.&lt;/p&gt;  &lt;p class="MsoNormal"&gt;OWASP CSRFGuard has been completely rewritten to address the various feature requests and bug fixes submitted to me over the past couple years. No longer will CSRFGuard be referred to as just a "reference implementation". By addressing the performance and scalability issues plaguing older releases, OWASP CSRFGuard v3 is intended to serve as the de-facto standard prevention mechanism against CSRF attacks for JavaEE web applications. The following is a bulleted summary of the significant changes associated with the v3 release:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;&lt;/p&gt;&lt;ul&gt;&lt;li&gt;OWASP CSRFGuard is now available under the much more liberal BSD license&lt;/li&gt;&lt;li&gt;Owasp.CsrfGuard.properties file can be loaded from classpath, web context directory, or current directory&lt;/li&gt;&lt;li&gt;Developers can implement a custom logger to be consumed by the library&lt;/li&gt;&lt;li&gt;Experimental support for the rotation of CSRF tokens once the previous token is expired&lt;/li&gt;&lt;li&gt;Experimental support for creating and verifying unique CSRF tokens per page&lt;/li&gt;&lt;li&gt;Experimental support for Ajax through the verification of headers dynamically injected by CSRFGuard JavaScript&lt;/li&gt;&lt;li&gt;Configurable actions including Log, Invalidate, Redirect, Forward, RequestAttribute, and SessionAttribute&lt;/li&gt;&lt;li&gt;Unprotected pages can be captured using same syntax used by the JavaEE container in web.xml&lt;/li&gt;&lt;li&gt;Library no longer intercepts HTTP responses produced by the web application&lt;/li&gt;&lt;li&gt;Developers can manually inject CSRF prevention tokens using the JSP tag library&lt;/li&gt;&lt;li&gt;Developers can automate injection of CSRF prevention tokens using dynamic JavaScript DOM Manipulation&lt;/li&gt;&lt;li&gt;Tokens are only injected into HTML elements that submit requests to the current origin (planned for XHR)&lt;/li&gt;&lt;li&gt;JavaScript token injection can be configured to inject into links, forms, and XMLHttpRequests&lt;/li&gt;&lt;/ul&gt;&lt;p&gt;&lt;/p&gt;                          &lt;p class="MsoNormal"&gt;Please check out the following resources for more information regarding recent project updates:&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Project Page - &lt;a href="http://www.owasp.org/index.php/Category:OWASP_CSRFGuard_Project"&gt;http://www.owasp.org/index.php/Category:OWASP_CSRFGuard_Project&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;User Manual - &lt;a href="http://www.owasp.org/index.php/CSRFGuard_3_User_Manual"&gt;http://www.owasp.org/index.php/CSRFGuard_3_User_Manual&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Code Repository - &lt;a href="http://code.google.com/p/owaspcsrfguard/"&gt;http://code.google.com/p/owaspcsrfguard/&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Blog - &lt;a href="http://ericsheridan.blogspot.com/"&gt;http://ericsheridan.blogspot.com/&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;-Eric&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-8088564893387370768?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/8088564893387370768/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/12/owasp-csrfguard-300336.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8088564893387370768'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8088564893387370768'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/12/owasp-csrfguard-300336.html' title='OWASP CSRFGuard 3.0.0.336'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-5360448193366085882</id><published>2010-12-07T21:54:00.000-08:00</published><updated>2010-12-07T21:57:40.349-08:00</updated><title type='text'>OWASP 4.0</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-qformat:yes;  mso-style-parent:"";  mso-padding-alt:0in 5.4pt 0in 5.4pt;  mso-para-margin:0in;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman","serif";} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;(From Jeff Williams)&lt;/p&gt;&lt;p class="MsoNormal"&gt;Hi everyone,&lt;/p&gt;    &lt;p class="MsoNormal"&gt;In my mind, OWASP 1.0 was pre-wiki with lots of great work and a less great infrastructure.  OWASP 2.0 was establishing the 501c3, putting in the wiki, and getting lots of great projects started. OWASP 3.0 started with the Summit in Portugal when we created the new committees and has focused on creating thriving projects instead of standalone tools.  Thank you for all of your efforts growing a fun, civil, productive community.&lt;/p&gt;    &lt;p class="MsoNormal"&gt;I reach out to you now to ask you to take some time and think about what OWASP should become.  The time has come to measure our success not by the number of members, projects, and conferences, but by whether we are succeeding at making the world’s software more secure. It’s time to get our message and strategy to the next level.&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;b&gt;HELP DESIGN OWASP 4.0 IN PORTUGAL AT THE SUMMIT!&lt;/b&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;If you consider yourself an OWASP Leader, won’t you take a few minutes of quiet time and propose a few ideas for how OWASP can retool, reorganize, refocus, and revamp itself to really achieve our mission?  We will rip, mix, and burn these ideas into a new strategy for OWASP at the Portugal Summit.  I encourage you to check out the resort and all the plans happening right now at &lt;a href="http://www.owasp.org/index.php/Summit_2011"&gt;http://www.owasp.org/index.php/Summit_2011&lt;/a&gt;. &lt;/p&gt;    &lt;p class="MsoNormal"&gt;Here are some ideas to get you started.&lt;/p&gt;    &lt;ol&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We bootstrap several application security ecosystems around key technologies like mobile, cloud, REST&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We reach out to governments around the world to help them push for application security&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We raise money to fund real security enhancements to tools, browsers, protocols (e.g. OpenSSL)&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We make the OWASP materials more usable by providing a “user” site and keep the wiki for development&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We invest in marketing AppSec – How do we scale David Rice and the “greening” of AppSec&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We continue our education initiative – academies, college chapters, videos, curriculum&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We continue our browser initiative and do whatever it takes to get the browsers and frameworks talking&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We invest in getting in front of new technologies like HTML5&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We launch a no-holds barred XSS eradication campaign&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We create a set of objective AppSec *&lt;b&gt;market&lt;/b&gt;* metrics that quantify the state of our art&lt;/li&gt;&lt;li&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We continue to push on creating standards&lt;/li&gt;&lt;/ol&gt;                          &lt;p class="MsoNormal"&gt;&lt;span style="font-family:Symbol;"&gt;&lt;span style=""&gt;&lt;span style="font: 7pt &amp;quot;Times New Roman&amp;quot;;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;We need your ideas NOW.  Get yourself on the list!&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;a href="http://www.owasp.org/index.php/Summit_2011#tab=Summit_Attendees"&gt;http://www.owasp.org/index.php/Summit_2011#tab=Summit_Attendees&lt;/a&gt; &lt;/p&gt;    &lt;p class="MsoNormal"&gt;In one week of thinking, arguing, coding, hacking, and writing we are going to accomplish more than the rest of the world’s appsec efforts combined.  We’ll see you in Portugal ready &lt;span style="color:black;"&gt;to rock.  Thanks!&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;span style="color:black;"&gt; &lt;/span&gt;--Jeff Williams&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-5360448193366085882?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/5360448193366085882/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/12/owasp-40.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5360448193366085882'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5360448193366085882'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/12/owasp-40.html' title='OWASP 4.0'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-1906132612192042370</id><published>2010-12-02T08:34:00.000-08:00</published><updated>2010-12-02T09:01:58.556-08:00</updated><title type='text'>OWASP Call for Trainers!</title><content type='html'>&lt;span style="font-size:100%;"&gt;&lt;span style="font-weight: bold; color: rgb(153, 0, 0);font-family:verdana;" &gt;To all OWASP Leaders&lt;/span&gt; &lt;/span&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:hyphenationzone&gt;21&lt;/w:HyphenationZone&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;PT&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Tabela normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-qformat:yes;  mso-style-parent:"";  mso-padding-alt:0cm 5.4pt 0cm 5.4pt;  mso-para-margin:0cm;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:10.0pt;  font-family:"Times New Roman","serif";} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p  class="MsoNormal" style="font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="" lang="EN-US"&gt;In the context of the effort we are making to stabilize and consolidate an OWASP Training model that can be used as a powerful tool to spread OWASP’s knowledge and message, OWASP is looking for trainers to deliver training under the flag “&lt;b&gt;&lt;u&gt;OWASP projects and resources you can use today&lt;/u&gt;&lt;/b&gt;”. This is a model of training which is &lt;b&gt;free for OWASP members&lt;/b&gt;, &lt;b&gt;delivered by OWASP Leaders&lt;/b&gt; (with only travel expenses paid) and &lt;b&gt;covering OWASP modules and/or projects&lt;/b&gt;.&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p  class="MsoNormal" style="font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;span style="" lang="EN-US"&gt;If you are an OWASP Leader and would like to be included in OWASP's pool of trainers, this is your chance - add your name and info to the OWASP Trainers Database and be counted!&lt;/span&gt;&lt;/b&gt;&lt;span style="" lang="EN-US"&gt; &lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p  class="MsoNormal" style="font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;&lt;b&gt;&lt;span style="" lang="EN-US"&gt;&lt;/span&gt;&lt;/b&gt;&lt;span style="" lang="EN-US"&gt;&lt;a href="http://www.owasp.org/index.php/OWASP_Training#tab=Trainers_Database_-_Call_for_Trainers.21"&gt;Check out the Database and &lt;span style="font-weight: bold;"&gt;do it now&lt;/span&gt;!&lt;/a&gt;&lt;span style="text-decoration: underline;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p  class="MsoNormal" style="font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;&lt;a href="http://www.owasp.org/index.php/OWASP_Training"&gt;&lt;span style="" lang="EN-US"&gt;Follow all the developments on the OWASP Training here.&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p  class="MsoNormal" style="font-family:verdana;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="" lang="EN-US"&gt;We are looking forward to seeing your names online!&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;    &lt;span style="font-size:100%;"&gt; &lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-1906132612192042370?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/1906132612192042370/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/12/owasp-call-for-trainers.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1906132612192042370'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1906132612192042370'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/12/owasp-call-for-trainers.html' title='OWASP Call for Trainers!'/><author><name>Sandra Paiva</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-3527898636214426586</id><published>2010-11-01T06:00:00.000-07:00</published><updated>2010-11-03T14:16:41.607-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='xss'/><category scheme='http://www.blogger.com/atom/ns#' term='csp'/><title type='text'>Preventing XSS with Content Security Policy</title><content type='html'>An individual XSS can be easily remediated with contextual output encoding per the &lt;a href="http://www.owasp.org/index.php/XSS_%28Cross_Site_Scripting%29_Prevention_Cheat_Sheet"&gt;OWASP XSS Prevention Cheat Sheet&lt;/a&gt;. Although an individual XSS can easily be addressed, the overall cat and mouse game of effectively ridding an application of XSS can be very difficult.&amp;nbsp; To combat this problem a new security feature, &lt;a href="https://wiki.mozilla.org/Security/CSP/Specification"&gt;Content Security Policy&lt;/a&gt;, has been introduced into the Mozilla Firefox browser. &lt;br /&gt;&lt;br /&gt;Content Security Policy (CSP) is an opt-in white list approach for defining what external scripts sources are allowed to execute JavaScript or other content loading code (e.g. iframes) within the page.&amp;nbsp; By eliminating inline scripts and defining a white list of allowed external scripts it is possible to strictly control what JavaScript is executed within the page. In the event that a user injected script into the page via an improperly encoded piece of user controlled data, then Content Security Policy would identify that the JavaScript is not part of the white-listed data and the browser will disregard this unauthorized script.&lt;br /&gt;&lt;br /&gt;Here's a basic overview of the CSP process:&lt;br /&gt;&lt;ol&gt;&lt;li&gt;Externalize all JavaScript within the pages (e.g no inline script&lt;br /&gt;tag, no inline JavaScript for onclick or other handling events )&lt;/li&gt;&lt;li&gt;Define the policy for your site and whitelist the allowed domains where the externalized JavaScript is located.&lt;/li&gt;&lt;li&gt;Add the X-Content-Security-Policy response header to instruct the browser that CSP is in use.&lt;/li&gt;&lt;/ol&gt;&lt;br /&gt;&lt;u&gt;&lt;br /&gt;Violation Reporting&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&amp;nbsp;The violation reporting component is another huge benefit of using CSP that can be enabled by providing a value for the policy-uri field within the site's specific Content Security Policy.&amp;nbsp; In the event content (JavaScript, injected iframe, etc) is not allowed to execute due to CSP, the user's browser will issue a violation report back to the URL specified by the site's CSP.&amp;nbsp; This means that a website owner can receive real time notifications of CSP violations that could be potential XSS attacks.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;u&gt;CSP Enabled Browsers&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;Content Security Policy is currently supported in Firefox 4. Although CSP is currently supported in only one browser, there are still many reasons to provide CSP support within a website. CSP will provide an added layer of protection to all web site users with a CSP enabled browser. In addition, CSP enabled browsers will also provide violation reporting feedback back to the web site owners in the event an XSS attack is somehow injected into the page. Finally, if CSP is well received then the intent is to formalize this into a standard and push for adoption within other browsers.&amp;nbsp; &lt;br /&gt;&lt;br /&gt;&lt;u&gt;More Information&lt;/u&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Spec: &lt;a href="https://wiki.mozilla.org/Security/CSP/Specification"&gt;https://wiki.mozilla.org/Security/CSP/Specification&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Developer CSP Link: &lt;a href="https://developer.mozilla.org/en/Introducing_Content_Security_Policy"&gt;https://developer.mozilla.org/en/Introducing_Content_Security_Policy&lt;/a&gt;&lt;/li&gt;&lt;li&gt;W3C Web App Security Working Group - CSP Link: &lt;a href="http://www.w3.org/2010/07/appsecwg-charter#deliverables"&gt;http://www.w3.org/2010/07/appsecwg-charter#deliverables&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Mozilla Blog Post on CSP: &lt;a href="http://blog.mozilla.com/security/2009/06/19/shutting-down-xss-with-content-security-policy/"&gt;http://blog.mozilla.com/security/2009/06/19/shutting-down-xss-with-content-security-policy/&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Sample Policy Definitions : &lt;a href="https://wiki.mozilla.org/Security/CSP/Specification#Sample_Policy_Definitions"&gt;https://wiki.mozilla.org/Security/CSP/Specification#Sample_Policy_Definitions&lt;/a&gt;&lt;/li&gt;&lt;li&gt;Notes from one of the CSP creators (Brandon Sterne) : &lt;a href="http://people.mozilla.com/%7Ebsterne/content-security-policy/"&gt;http://people.mozilla.com/~bsterne/content-security-policy/&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;br /&gt;&lt;a href="http://michael-coates.blogspot.com/"&gt;Michael Coates&lt;/a&gt; (&lt;a href="http://twitter.com/_mwc"&gt;@_mwc&lt;/a&gt;) &amp;amp; Brandon Sterne (&lt;a href="http://twitter.com/bsterne"&gt;@bsterne&lt;/a&gt;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-3527898636214426586?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3527898636214426586'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/3527898636214426586'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/11/preventing-xss-with-content-security.html' title='Preventing XSS with Content Security Policy'/><author><name>Michael Coates</name><uri>http://www.blogger.com/profile/01776444965999374544</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='32' height='32' src='http://2.bp.blogspot.com/_MiAJXkPG1IM/StSyGcceaDI/AAAAAAAABR4/ZNH2XgLAgM8/S220/MichaelCoates.jpg'/></author></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-8432888977792834511</id><published>2010-10-25T08:57:00.000-07:00</published><updated>2010-10-25T08:58:37.264-07:00</updated><title type='text'>AppSec DC is just 2 weeks away!</title><content type='html'>&lt;p&gt;We have a great schedule (&lt;a href="http://schedule.appsecdc.org/"&gt;http://schedule.appsecdc.org&lt;/a&gt;) this year with 4 tracks of amazing talks and a selection of great training classes at rock bottom prices.  Register now at &lt;a href="http://reg.appsecdc.org/"&gt;http://reg.appsecdc.org&lt;/a&gt; Highlights will include keynotes from &lt;strong&gt;Neal Ziring of the Information Assurance Directorate of the National Security Agency (NSA)&lt;/strong&gt; and &lt;strong&gt;Ron Ross of the National Institute of Standards and Technology (NIST)&lt;/strong&gt;,  panel discussions of federal CISOs on their experiences with  implementing application security, 50 plenary presentations by leading  personalities in the field of web application security.&lt;/p&gt;&lt;p&gt;Also this  year, AppSec DC has partnered with entities within the Department of  Homeland Security, the Department of Defense, the National Institute of  Standards and Technology, the National Security Agency, and other  government agencies who will be contributing content focusing on  Software Assurance and the role that that plays in areas such as  protecting Critical Infrastructure or Supply Chain Risk Management. &lt;/p&gt;&lt;p&gt;In  addition to two days of great speaking content, a track by the federal  government, keynotes and panels, AppSec DC will also provide two days of  world class training on applications security from a variety of vendors  at a fraction of the cost found at other events.  Training courses  include:&lt;/p&gt;&lt;div&gt;&lt;strong&gt;2-Day Courses ($1495)&lt;br /&gt;&lt;/strong&gt;- Assessing and Exploiting Web Applications with Samurai-WTF&lt;br /&gt;- Leading the AppSec Initative&lt;br /&gt;- Remote Testing for Common Web Application Security Threats&lt;br /&gt;- Software Security Best Practices&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Single Day Courses ($745)&lt;/strong&gt;&lt;br /&gt;- WebAppSec.php: Developing Secure Web Applications&lt;br /&gt;- The Art of Exploiting SQL Injections&lt;br /&gt;- Java Security Overview&lt;br /&gt;- Software Security Remediation: How to Fix Application Vulnerabilities&lt;br /&gt;- Threat Modeling Express&lt;/div&gt;&lt;p&gt;More information can be found at &lt;a href="http://wiki.appsecdc.org/"&gt;http://wiki.appsecdc.org&lt;/a&gt;.  Come join us for what is shaping up to be another amazing conference this year!&lt;/p&gt;&lt;p&gt;The AppSec DC Team&lt;br /&gt;&lt;a href="http://www.appsecdc.org/"&gt;http://www.appsecdc.org&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-8432888977792834511?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/8432888977792834511/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/10/appsec-dc-is-just-2-weeks-away.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8432888977792834511'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8432888977792834511'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/10/appsec-dc-is-just-2-weeks-away.html' title='AppSec DC is just 2 weeks away!'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4109346051037442347</id><published>2010-10-17T09:26:00.001-07:00</published><updated>2010-10-17T09:27:46.226-07:00</updated><title type='text'>OWASP NYC Chapter Meetings</title><content type='html'>&lt;p class="MsoNormal" style="margin-bottom:12.0pt"&gt;&lt;b&gt;OWASP NYC Chapter Meeting&lt;/b&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt; When: November 2nd  6:00pm - 9:00pm &lt;/p&gt;  &lt;p class="MsoNormal"&gt;Where: &lt;span class="apple-style-span"&gt;&lt;span style="font-size:10.0pt;font-family:&amp;quot;Arial&amp;quot;,&amp;quot;sans-serif&amp;quot;"&gt;345 Park Ave, NY, NY&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Topics will include:&lt;br /&gt;-Memory Corruption, Exploitation, and You, Dino Dai Zovi&lt;br /&gt;-Escaping the Sandbox, Stephen Ridley&lt;br /&gt;-Much Ado about Randomness, Aleksandr Yampolskiy&lt;br /&gt;-Groundspeed: Manipulating Web Application Interfaces, Felipe Moreno&lt;/p&gt;&lt;p class="MsoNormal"&gt; Food/Beer/Wine/Drinks Included&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Cost: FREE&lt;/p&gt;  &lt;p class="MsoNormal"&gt;RSVP is required by building security, limited seats: &lt;a href="http://www.owasp.org/index.php/NYNJMetro"&gt;http://www.owasp.org/index.php/NYNJMetro&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;b&gt;OWASP NYC Metro Holiday Security Party &lt;/b&gt;&lt;br /&gt;December 9th  - 6:30 - 10:30pm&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Where: STOUT 133 West 33rd Street, NY, NY 10001&lt;br /&gt;When: Thursday, December 9th 2010  6:30pm - 10:30pm&lt;br /&gt;Cost: $40.00 per person include food, drinks and fun!&lt;br /&gt;Limited Capacity get your tickets early - 250 People&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:12.0pt"&gt;RSVP and for more information on these events events visit: &lt;a href="http://www.owasp.org/index.php/NYNJMetro#tab=2010_Holiday_Party"&gt;http://www.owasp.org/index.php/NYNJMetro#tab=2010_Holiday_Party&lt;/a&gt;&lt;/p&gt;&lt;p class="MsoNormal"&gt; &lt;b&gt;Who attendees these events?&lt;/b&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;NYC Metro&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Application Developers&lt;br /&gt;Application Testers and Quality Assurance&lt;br /&gt;Application Project Management and Staff&lt;br /&gt;Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff&lt;br /&gt;Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance&lt;br /&gt;Security Managers and Staff&lt;br /&gt;Executives, Managers, and Staff Responsible for IT Security Governance&lt;br /&gt;IT Professionals Interesting in Improving IT Security&lt;br /&gt;Anyone interested in learning about or promoting Web Application Security&lt;/p&gt;  &lt;p class="MsoNormal"&gt;More information about membership  &lt;a href="http://www.owasp.org/index.php/Membership"&gt;http://www.owasp.org/index.php/Membership&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Semper Fi,&lt;/p&gt;  &lt;p class="MsoNormal"&gt;Tom Brennan&lt;/p&gt;  &lt;p class="MsoNormal"&gt;OWASP NYC Metro Chapter President&lt;br /&gt;OWASP Foundation Board Member&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/About_OWASP"&gt;http://www.owasp.org/index.php/About_OWASP&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4109346051037442347?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4109346051037442347/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/10/owasp-nyc-chapter-meetings.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4109346051037442347'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4109346051037442347'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/10/owasp-nyc-chapter-meetings.html' title='OWASP NYC Chapter Meetings'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-6114024888598168534</id><published>2010-10-16T22:56:00.001-07:00</published><updated>2010-10-19T02:56:02.490-07:00</updated><title type='text'>AppSec DC is back!</title><content type='html'>&lt;p class="MsoNormal"&gt;OWASP Leaders,&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;  &lt;p id="intro"&gt;AppSec DC is back as the premier web application security conference on the east coast!  AppSec DC will take place at the Walter E. Washington Convention Center in Washington DC on November 8-11. Training will be on the 8th and 9th, talks will be on the 10th and 11th. The partner hotel is the Grand Hyatt again this year but &lt;u&gt;rooms are going fast&lt;/u&gt;!&lt;/p&gt;  &lt;p&gt;AppSec DC brings some of the leading minds in web application security to Washington DC for &lt;a href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2010_Schedule" target="_blank"&gt;two days of talks&lt;/a&gt; on a wide variety of topics, including cutting edge presentations and panel discussions with leaders in the Federal, finance, and security research arenas and a &lt;a href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2010#tab=Training" target="_blank"&gt;variety of world class training&lt;/a&gt; at a fraction of the cost of other providers.  Highlights will include keynotes from &lt;strong&gt;Neal Ziring of the Information Assurance Directorate of the National Security Agency (NSA)&lt;/strong&gt; and &lt;strong&gt;Ron Ross of the National Institute of Standards and Technology (NIST)&lt;/strong&gt;, panel discussions of federal CISOs on their experiences with implementing application security, invaluable interaction and networking with attendees and presenters, a custom-made capture the flag contest by members of OWASP DC, and many of the best talks available by leading personalities in the field of web application security. Oh, and rockets.&lt;/p&gt;  &lt;p&gt;Register: &lt;a href="https://guest.cvent.com/EVENTS/Register/IdentityConfirmation.aspx?e=d52c6f5f-d568-4e16-b8e0-b5e2bf87ab3a"&gt;https://guest.cvent.com/EVENTS/Register/IdentityConfirmation.aspx?e=d52c6f5f-d568-4e16-b8e0-b5e2bf87ab3a&lt;/a&gt;&lt;br /&gt;Hotel: &lt;a href="https://resweb.passkey.com/Resweb.do?mode=welcome_gi_new&amp;amp;groupID=2766908"&gt;https://resweb.passkey.com/Resweb.do?mode=welcome_gi_new&amp;amp;groupID=2766908&lt;/a&gt;&lt;br /&gt;Schedule: &lt;a href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2010_Schedule"&gt;http://www.owasp.org/index.php/OWASP_AppSec_DC_2010_Schedule&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For more information visit the OWASP wiki at &lt;a href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2010"&gt;http://www.owasp.org/index.php/OWASP_AppSec_DC_2010&lt;/a&gt;or the AppSec DC website at &lt;a href="http://appsecdc.org/"&gt;http://appsecdc.org&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Look forward to seeing you there!&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;Mark Bristow&lt;br /&gt;&lt;br /&gt;OWASP Global Conferences Committee Chair - &lt;a href="http://is.gd/5MTvF"&gt;http://is.gd/5MTvF&lt;/a&gt;&lt;br /&gt;AppSec DC 2010 Organizer - &lt;a href="https://www.appsecdc.org/"&gt;https://www.appsecdc.org&lt;/a&gt;&lt;br /&gt;OWASP DC Chapter Co-Chair - &lt;a href="http://is.gd/5MTwu"&gt;http://is.gd/5MTwu&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-6114024888598168534?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/6114024888598168534/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/10/appsec-dc-is-back.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6114024888598168534'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6114024888598168534'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/10/appsec-dc-is-back.html' title='AppSec DC is back!'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-621352733873750510</id><published>2010-10-08T21:43:00.000-07:00</published><updated>2010-10-08T21:44:19.044-07:00</updated><title type='text'>OWASP Newsletter</title><content type='html'>&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:worddocument&gt;   &lt;w:view&gt;Normal&lt;/w:View&gt;   &lt;w:zoom&gt;0&lt;/w:Zoom&gt;   &lt;w:trackmoves/&gt;   &lt;w:trackformatting/&gt;   &lt;w:punctuationkerning/&gt;   &lt;w:validateagainstschemas/&gt;   &lt;w:saveifxmlinvalid&gt;false&lt;/w:SaveIfXMLInvalid&gt;   &lt;w:ignoremixedcontent&gt;false&lt;/w:IgnoreMixedContent&gt;   &lt;w:alwaysshowplaceholdertext&gt;false&lt;/w:AlwaysShowPlaceholderText&gt;   &lt;w:donotpromoteqf/&gt;   &lt;w:lidthemeother&gt;EN-US&lt;/w:LidThemeOther&gt;   &lt;w:lidthemeasian&gt;X-NONE&lt;/w:LidThemeAsian&gt;   &lt;w:lidthemecomplexscript&gt;X-NONE&lt;/w:LidThemeComplexScript&gt;   &lt;w:compatibility&gt;    &lt;w:breakwrappedtables/&gt;    &lt;w:snaptogridincell/&gt;    &lt;w:wraptextwithpunct/&gt;    &lt;w:useasianbreakrules/&gt;    &lt;w:dontgrowautofit/&gt;    &lt;w:splitpgbreakandparamark/&gt;    &lt;w:dontvertaligncellwithsp/&gt;    &lt;w:dontbreakconstrainedforcedtables/&gt;    &lt;w:dontvertalignintxbx/&gt;    &lt;w:word11kerningpairs/&gt;    &lt;w:cachedcolbalance/&gt;   &lt;/w:Compatibility&gt;   &lt;w:browserlevel&gt;MicrosoftInternetExplorer4&lt;/w:BrowserLevel&gt;   &lt;m:mathpr&gt;    &lt;m:mathfont val="Cambria Math"&gt;    &lt;m:brkbin val="before"&gt;    &lt;m:brkbinsub val="&amp;#45;-"&gt;    &lt;m:smallfrac val="off"&gt;    &lt;m:dispdef/&gt;    &lt;m:lmargin val="0"&gt;    &lt;m:rmargin val="0"&gt;    &lt;m:defjc val="centerGroup"&gt;    &lt;m:wrapindent val="1440"&gt;    &lt;m:intlim val="subSup"&gt;    &lt;m:narylim val="undOvr"&gt;   &lt;/m:mathPr&gt;&lt;/w:WordDocument&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt;  &lt;w:latentstyles deflockedstate="false" defunhidewhenused="true" defsemihidden="true" defqformat="false" defpriority="99" latentstylecount="267"&gt;   &lt;w:lsdexception locked="false" priority="0" semihidden="false" unhidewhenused="false" qformat="true" name="Normal"&gt;   &lt;w:lsdexception locked="false" priority="9" semihidden="false" unhidewhenused="false" qformat="true" name="heading 1"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 2"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 3"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 4"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 5"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 6"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 7"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 8"&gt;   &lt;w:lsdexception locked="false" priority="9" qformat="true" name="heading 9"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 1"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 2"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 3"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 4"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 5"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 6"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 7"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 8"&gt;   &lt;w:lsdexception locked="false" priority="39" name="toc 9"&gt;   &lt;w:lsdexception locked="false" priority="35" qformat="true" name="caption"&gt;   &lt;w:lsdexception locked="false" priority="10" semihidden="false" unhidewhenused="false" qformat="true" name="Title"&gt;   &lt;w:lsdexception locked="false" priority="1" name="Default Paragraph Font"&gt;   &lt;w:lsdexception locked="false" priority="11" semihidden="false" unhidewhenused="false" qformat="true" name="Subtitle"&gt;   &lt;w:lsdexception locked="false" priority="22" semihidden="false" unhidewhenused="false" qformat="true" name="Strong"&gt;   &lt;w:lsdexception locked="false" priority="20" semihidden="false" unhidewhenused="false" qformat="true" name="Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="59" semihidden="false" unhidewhenused="false" name="Table Grid"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Placeholder Text"&gt;   &lt;w:lsdexception locked="false" priority="1" semihidden="false" unhidewhenused="false" qformat="true" name="No Spacing"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" unhidewhenused="false" name="Revision"&gt;   &lt;w:lsdexception locked="false" priority="34" semihidden="false" unhidewhenused="false" qformat="true" name="List Paragraph"&gt;   &lt;w:lsdexception locked="false" priority="29" semihidden="false" unhidewhenused="false" qformat="true" name="Quote"&gt;   &lt;w:lsdexception locked="false" priority="30" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Quote"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 1"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 2"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 3"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 4"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 5"&gt;   &lt;w:lsdexception locked="false" priority="60" semihidden="false" unhidewhenused="false" name="Light Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="61" semihidden="false" unhidewhenused="false" name="Light List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="62" semihidden="false" unhidewhenused="false" name="Light Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="63" semihidden="false" unhidewhenused="false" name="Medium Shading 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="64" semihidden="false" unhidewhenused="false" name="Medium Shading 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="65" semihidden="false" unhidewhenused="false" name="Medium List 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="66" semihidden="false" unhidewhenused="false" name="Medium List 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="67" semihidden="false" unhidewhenused="false" name="Medium Grid 1 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="68" semihidden="false" unhidewhenused="false" name="Medium Grid 2 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="69" semihidden="false" unhidewhenused="false" name="Medium Grid 3 Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="70" semihidden="false" unhidewhenused="false" name="Dark List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="71" semihidden="false" unhidewhenused="false" name="Colorful Shading Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="72" semihidden="false" unhidewhenused="false" name="Colorful List Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="73" semihidden="false" unhidewhenused="false" name="Colorful Grid Accent 6"&gt;   &lt;w:lsdexception locked="false" priority="19" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="21" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Emphasis"&gt;   &lt;w:lsdexception locked="false" priority="31" semihidden="false" unhidewhenused="false" qformat="true" name="Subtle Reference"&gt;   &lt;w:lsdexception locked="false" priority="32" semihidden="false" unhidewhenused="false" qformat="true" name="Intense Reference"&gt;   &lt;w:lsdexception locked="false" priority="33" semihidden="false" unhidewhenused="false" qformat="true" name="Book Title"&gt;   &lt;w:lsdexception locked="false" priority="37" name="Bibliography"&gt;   &lt;w:lsdexception locked="false" priority="39" qformat="true" name="TOC Heading"&gt;  &lt;/w:LatentStyles&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt; &lt;style&gt;  /* Style Definitions */  table.MsoNormalTable  {mso-style-name:"Table Normal";  mso-tstyle-rowband-size:0;  mso-tstyle-colband-size:0;  mso-style-noshow:yes;  mso-style-priority:99;  mso-style-qformat:yes;  mso-style-parent:"";  mso-padding-alt:0in 5.4pt 0in 5.4pt;  mso-para-margin:0in;  mso-para-margin-bottom:.0001pt;  mso-pagination:widow-orphan;  font-size:11.0pt;  font-family:"Calibri","sans-serif";  mso-ascii-font-family:Calibri;  mso-ascii-theme-font:minor-latin;  mso-fareast-font-family:"Times New Roman";  mso-fareast-theme-font:minor-fareast;  mso-hansi-font-family:Calibri;  mso-hansi-theme-font:minor-latin;  mso-bidi-font-family:"Times New Roman";  mso-bidi-theme-font:minor-bidi;} &lt;/style&gt; &lt;![endif]--&gt;  &lt;p class="MsoNormal"&gt;Please follow the attached link to get the latest news from your OWASP Community:  &lt;a href="http://www.owasp.org/index.php/Category:OWASP_Newsletter#tab=Newsletters"&gt;http://www.owasp.org/index.php/Category:OWASP_Newsletter#tab=Newsletters&lt;/a&gt; &lt;/p&gt;    &lt;p class="MsoNormal"&gt;Special thanks to Lorna Alamri – editor and creator of this newsletter, and to all our international translators who make this available in many languages.&lt;/p&gt;    &lt;p class="MsoNormal"&gt;If you are interested/available to contribute a few hours/quarter to the newsletter, please contact either Lorna &lt;a href="mailto:lorna.alamri@owasp.org"&gt;lorna.alamri@owasp.org&lt;/a&gt; or me &lt;a href="mailto:kate.hartmann@owasp.org"&gt;kate.hartmann@owasp.org&lt;/a&gt;. &lt;/p&gt;        Kate Hartmann&lt;br /&gt;Operations Director&lt;br /&gt;301-275-9403&lt;br /&gt;&lt;a href="http://www.owasp.org/"&gt;www.owasp.org&lt;/a&gt;&lt;br /&gt;Skype:  Kate.hartmann1&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-621352733873750510?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/621352733873750510/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/10/owasp-newsletter.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/621352733873750510'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/621352733873750510'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/10/owasp-newsletter.html' title='OWASP Newsletter'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4207811504612029667</id><published>2010-09-29T11:02:00.000-07:00</published><updated>2010-09-29T11:04:42.673-07:00</updated><title type='text'>IBWAS'10 Call for Papers</title><content type='html'>&lt;div&gt;2nd. OWASP Ibero-American Web-Applications Security conference 2010 (IBWAS’10) ISCTE – Lisbon University Institute 25th – 26th November 2010 Lisboa, Portugal &lt;a href="http://www.ibwas.com"&gt;http://www.ibwas.com&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Call for Papers&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Introduction&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;There is a change in the information systems development paradigm. The emergence of Web 2.0 technologies led to the extensive deployment and use of web-based applications and web services as a way to developed new and flexible information systems. Such systems are easy to develop, deploy and maintain and demonstrate impressive features for users, resulting in their current wide use. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;As a result of this paradigm shift, the security requirements have also changed. These web-based information systems have different security requirements, when compared to traditional systems. Important security issues have been found and privacy concerns have also been raised recently. In addition, the emerging Cloud Computing paradigm promises even greater flexibility; however corresponding security and privacy issues still need to be examined. The security environment should involve not only the surrounding environment but also the application core.&lt;/div&gt;&lt;div&gt;This conference aims to bring together application security experts, researchers, educators and practitioners from the industry, academia and international communities such as OWASP, in order to discuss open problems and new solutions in application security. In the context of this track academic researchers will be able to combine interesting results with the experience of practitioners and software engineers.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Conference Topics&lt;/b&gt;&lt;/div&gt;&lt;div&gt;Suggested topics for papers submission include (but are not limited to):&lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;Secure application development&lt;/li&gt;&lt;li&gt;Security of service oriented architectures&lt;/li&gt;&lt;li&gt;Security of development frameworks&lt;/li&gt;&lt;li&gt;Threat modelling of web applications&lt;/li&gt;&lt;li&gt;Cloud computing security&lt;/li&gt;&lt;li&gt;Web applications vulnerabilities and analysis (code review, pen-test, static analysis etc.)&lt;/li&gt;&lt;li&gt;Metrics for application security&lt;/li&gt;&lt;li&gt;Countermeasures for web application vulnerabilities&lt;/li&gt;&lt;li&gt;Secure coding techniques&lt;/li&gt;&lt;li&gt;Platform or language security features that help secure web applications&lt;/li&gt;&lt;li&gt;Secure database usage in web applications • Access control in web applications &lt;/li&gt;&lt;li&gt;Web services security&lt;/li&gt;&lt;li&gt;Browser security&lt;/li&gt;&lt;li&gt;Privacy in web applications&lt;/li&gt;&lt;li&gt;Standards, certifications and security evaluation criteria for web applications • Application security awareness and education&lt;/li&gt;&lt;li&gt;Security for the mobile web&lt;/li&gt;&lt;li&gt;Attacks and Vulnerability Exploitation&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4207811504612029667?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4207811504612029667/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/09/ibwas10-call-for-papers.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4207811504612029667'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4207811504612029667'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/09/ibwas10-call-for-papers.html' title='IBWAS&apos;10 Call for Papers'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-2153451814580146156</id><published>2010-09-20T21:38:00.001-07:00</published><updated>2010-09-20T21:42:25.654-07:00</updated><title type='text'>Global Summit 2011 Venue Proposal</title><content type='html'>&lt;span style="font-weight: bold;"&gt;OWASP Leaders,&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;We are looking for a venue for the Global Summit to be scheduled for four days sometime between January 15th, 2011 and February 15th, 2011. The Global Summit committee is requesting proposals from OWASP Leaders for venues. We will need your proposal by the October 4th. Proposal can be in rough draft format with estimated pricing, we just need to know who is interested in helping to put together the Global Summit to be held this coming January/or February and rough estimates of pricing for a particular location.&lt;br /&gt;&lt;br /&gt;We are also looking for more volunteers to help with planning for the event so please respond if interested.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Venue Requirements:&lt;/span&gt;&lt;br /&gt;Key organizer in close contact with venue.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Hosting:&lt;/span&gt;&lt;br /&gt;30- 100 people&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Cost:&lt;/span&gt;&lt;br /&gt;$2000 USD/ per person to include facility, lodging, food, beer and transport to and from location.  (This should be an all-inclusive cost per person, with the assumption that OWASP members will room together 2-4 depending on number of beds in room/apartment)&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Duration:&lt;/span&gt;&lt;br /&gt;4 days&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Dates:&lt;/span&gt;&lt;br /&gt;Will be scheduled between Jan 15th and Feb 15th&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Facility requirements:&lt;/span&gt;&lt;br /&gt;3-6 meeting rooms&lt;br /&gt;1 large meeting room to hold all attendees (estimate for 75-100) e.g. auditorium.&lt;br /&gt;Lodging should be part of  conference facilities or within walking distance of venue.&lt;br /&gt;&lt;br /&gt;Internet - what is bandwidth available?&lt;br /&gt;Must be sufficient for a group used to high bandwidth.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Rooms:&lt;/span&gt;&lt;br /&gt;To be shared by attendees - need to understand how many attendees to a room/suite/apartment. Apartments preferred. 4-5 star hotel acceptable.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Food:&lt;/span&gt;&lt;br /&gt;Local Food supplier which has been pre-negotiated with hotel.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Airport:&lt;/span&gt;&lt;br /&gt;Venue must be within 50 km's max from International airport.&lt;br /&gt;&lt;br /&gt;We'd love to bring the OWASP Summit to your city so please consider putting together a proposal.&lt;br /&gt;&lt;br /&gt;Thanks&lt;br /&gt;OWASP Global Summit 2011 Planning Committee&lt;br /&gt;&lt;a href="mailto:martin.Knobloch@owasp.org"&gt;martin.Knobloch@owasp.org&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-2153451814580146156?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/2153451814580146156/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/09/global-summit-2011-venue-proposal_20.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2153451814580146156'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2153451814580146156'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/09/global-summit-2011-venue-proposal_20.html' title='Global Summit 2011 Venue Proposal'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-6595572171292454325</id><published>2010-08-31T12:49:00.001-07:00</published><updated>2010-08-31T12:49:33.054-07:00</updated><title type='text'>OWASP Secure Coding Practices - Quick Reference Guide</title><content type='html'>&lt;div&gt;Leaders,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;I am glad to announce I’ve just set a new project up – the OWASP Secure Coding Practices - Quick Reference Guide, led by Keith Turpin. Please welcome him! &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;http://www.owasp.org/index.php/OWASP_Secure_Coding_Practices_-_Quick_Reference_Guide#tab=Project_About &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;http://www.owasp.org/index.php/User:Keith_Turpin&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;As always, your suggestions and contributions would be greatly appreciated.   &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In addition, this project already has a very mature release, OWASP Secure Coding Practices - Quick Reference Guide/Version 1.0, which is under formal assessment and seeking Stable Release status.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;http://www.owasp.org/index.php/Projects/OWASP_Secure_Coding_Practices_-_Quick_Reference_Guide/Releases/Current&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;http://www.owasp.org/index.php/Projects/OWASP_Secure_Coding_Practices_-_Quick_Reference_Guide/Releases/SCP_v1/Assessment&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;What’s more, Matt Tesauro already volunteered to act as Second Reviewer in his quality of Board Member but we are still in need of a First Reviewer. Please do let us know if you are up to take the challenge. To do so, please fill in the following link using one of the available positions aka volunteers[1-10]. &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;http://www.owasp.org/index.php/OWASP_Project_Reviewers_Database#tab=Project_Reviewers.2FVolunteers&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Many thanks, regards,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Paulo Coimbra,&lt;/div&gt;&lt;div&gt;OWASP Project Manager&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-6595572171292454325?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/6595572171292454325/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/08/owasp-secure-coding-practices-quick.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6595572171292454325'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6595572171292454325'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/08/owasp-secure-coding-practices-quick.html' title='OWASP Secure Coding Practices - Quick Reference Guide'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-2785971483430043850</id><published>2010-08-28T23:44:00.000-07:00</published><updated>2010-08-30T02:19:07.905-07:00</updated><title type='text'>ESAPI 2.0 rc7 (for Java 1.5+) is now live!</title><content type='html'>&lt;div&gt;ESAPI 2.0 rc7 for Java 1.5 and above is now live!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You can download the complete zip file here:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://owasp-esapi-java.googlecode.com/files/ESAPI-2.0-rc7.zip"&gt;http://owasp-esapi-java.googlecode.com/files/ESAPI-2.0-rc7.zip&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;You can browse the ESAPI 2.0 rc7 Javadocs here:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://owasp-esapi-java.googlecode.com/svn/trunk_doc/2.0-rc7/apidocs/index.html"&gt;http://owasp-esapi-java.googlecode.com/svn/trunk_doc/2.0-rc7/apidocs/index.html&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Additional online project documentation can be found here:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://owasp-esapi-java.googlecode.com/svn/trunk_doc/2.0-rc7/project-reports.html"&gt;http://owasp-esapi-java.googlecode.com/svn/trunk_doc/2.0-rc7/project-reports.html&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Major enhancements include:&lt;/div&gt;&lt;div&gt;&lt;ol&gt;&lt;li&gt;Several fixes to SecurityWrapperRequest.&lt;/li&gt;&lt;li&gt;Overhauled Singleton implementations to make the ObjFactory create instances or singletons rather than having ESAPI manage unreliably.&lt;/li&gt;&lt;li&gt;Changes to get rid of deprecated Encryptor encrypt() / decrypt() methods and replace them with the new, stronger encrypt() / decrypt() methods.&lt;/li&gt;&lt;li&gt;Several Validation fixes around returning consistent error states.&lt;/li&gt;&lt;li&gt;Made changes t0 the Encryptor so that it is no longer vulnerable to "padding oracle attacks" (issue #120)&lt;br /&gt;&lt;/li&gt;&lt;li&gt;Fixes to seal() so that it now properly works if the message being sealed contains a ":" (issue #28).&lt;/li&gt;&lt;li&gt;Examples should now work (if you follow directions in README.txt)&lt;br /&gt;   whether ESAPI has been pulled from the SVN repository or downloaded&lt;br /&gt;   from the zip file. (Issue #114.)&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;/div&gt;&lt;div&gt;Please see changelog.txt at the root of the zip file for more information.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Thanks to Kevin Wall, Chris “Beef” Schmidt, Jonathon Ruckwood and Ed Schaller for their contributions in this release.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Malama Pono Aloha,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-- &lt;/div&gt;&lt;div&gt;Jim Manico&lt;/div&gt;&lt;div&gt;OWASP Podcast Host/Producer&lt;/div&gt;&lt;div&gt;OWASP ESAPI Project Manager&lt;/div&gt;&lt;div&gt;http://www.manico.net&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-2785971483430043850?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/2785971483430043850/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/08/esapi-20-rc7-for-java-15-is-now-live.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2785971483430043850'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2785971483430043850'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/08/esapi-20-rc7-for-java-15-is-now-live.html' title='ESAPI 2.0 rc7 (for Java 1.5+) is now live!'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-1950001237880000918</id><published>2010-08-28T18:32:00.001-07:00</published><updated>2010-08-28T18:32:28.642-07:00</updated><title type='text'>OWASP ModSecurity CRS v2.0.8</title><content type='html'>Greetings everyone,&lt;br /&gt;I wanted to announce the availability of the OWASP ModSecurity CRS v2.0.8.&lt;br /&gt;&lt;br /&gt;DOWNLOADING -&lt;br /&gt;Download page - http://www.owasp.org/index.php/Category:OWASP_ModSecurity_Core_Rule_Set_Project#tab=Download&lt;br /&gt;You can also use the util/rules-updater.pl script to auto-download the latest ZIP archive (see the rules-updater-example.conf file for Repo data).&lt;br /&gt;&lt;br /&gt;TESTING -&lt;br /&gt;We have integrated the new CRS into the Demo page to help facilitate community testing -&lt;br /&gt;http://www.modsecurity.org/demo/&lt;br /&gt;&lt;br /&gt;CHANGES -&lt;br /&gt;--------------------------&lt;br /&gt;Version 2.0.8 - 08/27/2010&lt;br /&gt;--------------------------&lt;br /&gt;&lt;br /&gt;Improvements:&lt;br /&gt;- Updated the PHPIDS filters&lt;br /&gt;- Updated the SQL Injection filters to detect boolean attacks (1&lt;2, foo == bar, etc..)&lt;br /&gt;- Updated the SQL Injection filters to account for different quotes&lt;br /&gt;- Added UTF-8 encoding validation support to the modsecurity_crs_10_config.conf file&lt;br /&gt;- Added Rule ID 950109 to detect multiple URL encodings&lt;br /&gt;- Added two experimental rules to detect anomalous use of special characters&lt;br /&gt;&lt;br /&gt;Bug Fixes:&lt;br /&gt;- Fixed Encoding Detection RegEx (950107 and 950108)&lt;br /&gt;- Fixed rules-updater.pl script to better handle whitespace&lt;br /&gt; https://www.modsecurity.org/tracker/browse/MODSEC-167&lt;br /&gt;- Fixed missing pass action bug in modsecurity_crs_21_protocol_anomalies.conf&lt;br /&gt; https://www.modsecurity.org/tracker/browse/CORERULES-55&lt;br /&gt;- Fixed the anomaly scoring in the modsecurity_crs_41_phpids_filters.conf file&lt;br /&gt; https://www.modsecurity.org/tracker/browse/CORERULES-54&lt;br /&gt;- Updated XSS rule id 958001 to improve the .cookie regex to reduce false postives&lt;br /&gt; https://www.modsecurity.org/tracker/browse/CORERULES-29&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;Ryan Barnett&lt;br /&gt;OWASP ModSecurity Core Rule Set Project Leader&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-1950001237880000918?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/1950001237880000918/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/08/greetings-everyone-i-wanted-to-announce.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1950001237880000918'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1950001237880000918'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/08/greetings-everyone-i-wanted-to-announce.html' title='OWASP ModSecurity CRS v2.0.8'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4696920365415404595</id><published>2010-08-23T20:25:00.001-07:00</published><updated>2010-08-23T20:28:40.419-07:00</updated><title type='text'>APPSEC BRAZIL 2010 - REGISTRATIONS OPEN!</title><content type='html'>Greetings everyone!&lt;br /&gt;&lt;br /&gt;We're proud to announce that the OWASP's AppSec Brazil 2010 Conference registrations' are officially open!&lt;br /&gt;&lt;br /&gt;Early bird offers are available! Hurry up!&lt;br /&gt;&lt;br /&gt;This year we'll have keynotes by Robert 'Rsnake' Hansen and Jeremiah Grossman and Samy Kamkar as a Special Speaker!&lt;br /&gt;&lt;br /&gt;Registrations are available here: &lt;a href="http://www.owasp.org/index.php/AppSec_Brasil_2010#tab=Registration"&gt;http://www.owasp.org/index.php/AppSec_Brasil_2010#tab=Registration&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;All info about the event can be found at: &lt;a href="http://www.appsecbrasil.org"&gt;http://www.appsecbrasil.org&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If you have any doubt please contact us at organizacao2010 (at) appsecbrasil.org&lt;br /&gt;&lt;br /&gt;See you there!&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;Leonardo Buonsanti&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4696920365415404595?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4696920365415404595/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/08/appsec-brazil-2010-registrations-open.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4696920365415404595'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4696920365415404595'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/08/appsec-brazil-2010-registrations-open.html' title='APPSEC BRAZIL 2010 - REGISTRATIONS OPEN!'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-5291990539107970376</id><published>2010-08-19T13:32:00.000-07:00</published><updated>2010-08-19T13:36:21.257-07:00</updated><title type='text'>OWASP SPECIAL ANNOUNCEMENT</title><content type='html'>This is a special announcement in an attempt to reach out to our community’s&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Application Developers &lt;/li&gt;&lt;li&gt;Application Testers and Quality Assurance &lt;/li&gt;&lt;li&gt;Application Project Management and Staff &lt;/li&gt;&lt;li&gt;Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;/li&gt;&lt;li&gt;Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;/li&gt;&lt;li&gt;Security Managers and Staff &lt;/li&gt;&lt;li&gt;Executives, Managers, and Staff Responsible for IT Security Governance &lt;/li&gt;&lt;li&gt;IT Professionals Interesting in Improving IT Security&lt;/li&gt;&lt;/ul&gt;If you have not done so already, please take a minute to register for one of our upcoming events.  We have something happening in almost every part of the world!  This is the time to learn the latest in Application Security from the global industry experts.  Thanks to our many sponsors, we are able to continue to keep our registration and training costs low while raising the standards in the AppSec industry.  Don’t miss out on this opportunity to sharpen your skills, learn new techniques, network with leaders, and advance your career.  CPE credits are available for most programs. &lt;br /&gt;&lt;br /&gt;As always, if you have any questions, please feel free to contact me.  Kate.hartmann@owasp.org&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;September&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;September 7-10 AppSec US - Irvine, CA (training available)&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/AppSec_US_2010,_CA"&gt;http://www.owasp.org/index.php/AppSec_US_2010,_CA&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;September 17th, AppSec Ireland - Dublin, Ireland (training available)&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/OWASP_IRELAND_2010"&gt;http://www.owasp.org/index.php/OWASP_IRELAND_2010&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;October&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;October 20th, AppSec Germany – Nurnberg, Germany&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/OWASP_AppSec_Germany_2010_Conference"&gt;http://www.owasp.org/index.php/OWASP_AppSec_Germany_2010_Conference &lt;br /&gt;&lt;/a&gt;&lt;br /&gt;October 20-21, Rochester Security Summit – Rochester, NY&lt;br /&gt;&lt;a href="http://www.rochestersecurity.org/"&gt;http://www.rochestersecurity.org/&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;October 20-23, OWASP China Summit 2010 – Beijing, China&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/OWASP_China_Summit_2010"&gt;http://www.owasp.org/index.php/OWASP_China_Summit_2010&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;October 29th ,  LASCON – Austin, TX&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/Lonestar_Application_Security_Conference_2010"&gt;http://www.owasp.org/index.php/Lonestar_Application_Security_Conference_2010&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;November&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;November 8-11, AppSec DC 2010 – Washington, DC (training available)&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/OWASP_AppSec_DC_2010"&gt;http://www.owasp.org/index.php/OWASP_AppSec_DC_2010&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;November 16-19, AppSec Brazil – Campinas, SP, Brazil (training available)&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/AppSec_Brasil_2010"&gt;http://www.owasp.org/index.php/AppSec_Brasil_2010&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;November 25-26, IBWAS – Portugal (training available)&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/IBWAS10"&gt;http://www.owasp.org/index.php/IBWAS10&lt;br /&gt;&lt;/a&gt;&lt;br /&gt;Kate Hartmann&lt;br /&gt;Operations Director&lt;br /&gt;301-275-9403&lt;br /&gt;www.owasp.org&lt;br /&gt;Skype:  Kate.hartmann1&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-5291990539107970376?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/5291990539107970376/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/08/owasp-special-announcement.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5291990539107970376'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5291990539107970376'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/08/owasp-special-announcement.html' title='OWASP SPECIAL ANNOUNCEMENT'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-1015313607882398497</id><published>2010-08-10T11:45:00.000-07:00</published><updated>2010-08-10T11:50:29.518-07:00</updated><title type='text'>AppSec Ireland, AppSec DC, and AppSec US updates</title><content type='html'>&lt;span style="font-weight: bold;"&gt;OWASP Ireland September 17th 2010&lt;/span&gt;&lt;br /&gt;The agenda has been finalized for the OWASP Ireland event. We have the pleasure to announce a number of key figures from industry which should provide some unique insight into the latest trends, threats and methodologies in the world of application security.&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/OWASP_IRELAND_2010"&gt;http://www.owasp.org/index.php/OWASP_IRELAND_2010&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Keynotes:&lt;br /&gt;John Viega: “Application Security in the Real World” - Considerations for AppSec in non-security companies.&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/John_Viega"&gt;http://www.owasp.org/index.php/John_Viega&lt;/a&gt;&lt;br /&gt;Professor Fred Piper "The changing face of cryptography"&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/User:Professor_Fred_Piper"&gt;http://www.owasp.org/index.php/User:Professor_Fred_Piper&lt;/a&gt;&lt;br /&gt;Damian Gordon Phd: “Hackers and Hollywood: The Implications of the Popular Media Representation of Computer Hacking"&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/User:Damian_Gordon"&gt;http://www.owasp.org/index.php/User:Damian_Gordon&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;We also have some great international and local speakers covering topics from Smart phone application security to SDLC to Penetration testing techniques:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;Dan Cornell ("Smart Phones with Dumb Apps")&lt;/li&gt;&lt;li&gt;Ryan Berg ("Path to a Secure Application")&lt;/li&gt;&lt;li&gt;Dr Marian Ventunaec ("Testing the Enterprise E-mail Security - from Software to Cloud-based Services")&lt;/li&gt;&lt;li&gt;Fred Donovan and (“Counter Intelligence as Defense……”)&lt;/li&gt;&lt;li&gt;Nick Coblentz (“Microsoft's Security Development Lifecycle……”)&lt;/li&gt;&lt;/ul&gt;.. but to name a few &lt;a href="http://www.owasp.org/index.php/OWASP_IRELAND_2010#Agenda_and_Presentations_-_September_17"&gt;http://www.owasp.org/index.php/OWASP_IRELAND_2010#Agenda_and_Presentations_-_September_17&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Training:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/OWASP_IRELAND_2010#Training"&gt;&lt;br /&gt;http://www.owasp.org/index.php/OWASP_IRELAND_2010#Training&lt;/a&gt;&lt;br /&gt;“Secure Application Development: Writing secure code (and testing it)”&lt;br /&gt;AppSec DC: CFP Round Two:&lt;br /&gt;AppSec DC 2010 is the East Coast's premiere Information Security Conference for 2010.&lt;br /&gt;&lt;br /&gt;**AppSec DC has added a second round for CFP until August 31st, so there is still time to get submissions in for our CFP!**&lt;br /&gt;&lt;br /&gt;Building on the success of last year's AppSec DC 2009, the AppSec DC team is working to further the OWASP conference mission of hosting the best minds in application security in a forum to share innovations and ideas. AppSec DC's unique location and relationship with federal entities in the Washington DC area also allows OWASP and affiliates to continue to reach out to and interact with the federal government in this time of ever-increasing National Security concerns.&lt;br /&gt;This year, in addition to content from industry leaders in application security research, entities within the Department of Homeland Security, the Department of Defense, the National Institute of Standards and Technology and other government agencies will be contributing content focusing on Software Assurance and the role that that plays areas of extreme concern in the current climate, such as protecting Critical Infrastructure or Supply Chain Risk Management. If you work in or with the federal government, regardless of branch or service, this is likely a critical concern for some subset of your workplace, and the combination of content at this event will provide an incredible value to your and your employer.&lt;br /&gt;&lt;br /&gt;In addition to two days of great speaking content, keynotes and panels, AppSec DC will also provide two days of world class training on applications security from a variety of vendors at a fraction of the cost found at other events. This year featured panels will not only include federal "what works" in application security, but several other areas of interest so that there will be engaging discussion for all types of attendees. The AppSec DC crew is also working a great vendor space and engaging contests, including a hacking competition built specifically for our event.&lt;br /&gt;&lt;br /&gt;AppSec DC will take place at the Walter E. Washington Convention Center in Washington DC on November 8-11. Training will be on the 8th and 9th, talks will be on the 10th and 11th. Our partner hotel is the Grand Hyatt again this year, and a discounted rate will be available for attendees who register in Advance.&lt;br /&gt;&lt;br /&gt;For more information visit the OWASP wiki at http://www.owasp.org/index.php/OWASP_AppSec_DC_2010&lt;br /&gt;or the AppSec DC website (updates coming soon!) at http://appsecdc.org&lt;br /&gt;CFP submissions should use the Easy Chair system, our URL is at http://www.easychair.org/conferences/?conf=appsecdc2010 -- Registration is required.&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;AppSec US 2010, CA&lt;/span&gt;&lt;br /&gt;Register before August 15, 2010 and you may be eligible to win a free iPad! Details can be found here: http://www.owasp.org/index.php/AppSec_US_2010,_CA&lt;br /&gt;&lt;br /&gt;Kate Hartmann&lt;br /&gt;Operations Director&lt;br /&gt;301-275-9403&lt;br /&gt;www.owasp.org&lt;br /&gt;Skype: Kate.hartmann1&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-1015313607882398497?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/1015313607882398497/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/08/owasp-ireland-september-17th-2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1015313607882398497'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/1015313607882398497'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/08/owasp-ireland-september-17th-2010.html' title='AppSec Ireland, AppSec DC, and AppSec US updates'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-6149691706943674929</id><published>2010-07-21T20:47:00.000-07:00</published><updated>2010-07-21T20:48:25.198-07:00</updated><title type='text'>Interview with Jeff Williams</title><content type='html'>OWASP,&lt;br /&gt;&lt;br /&gt;The conference guide for OWASP AppSec Research 2010 featured an interview I did with Jeff Williams, volunteer chair of OWASP. Now it's online. Read his view on:&lt;br /&gt;&lt;br /&gt;   * Will OWASP ever reach out to developers?&lt;br /&gt;   * Application security and the word Trust&lt;br /&gt;   * Do developers care about rugged software?&lt;br /&gt;   * Java rootkits and trusted developers&lt;br /&gt;&lt;br /&gt;&lt;a href="http://owaspsweden.blogspot.com/2010/07/interview-with-jeff-williams.html"&gt;http://owaspsweden.blogspot.com/2010/07/interview-with-jeff-williams.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Regards, John&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;John Wilander&lt;br /&gt;Chapter leader OWASP Sweden, http://owaspsweden.blogspot.com&lt;br /&gt;Conference chair OWASP AppSec Research 2010, http://owasp.se&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-6149691706943674929?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/6149691706943674929/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/07/interview-with-jeff-williams.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6149691706943674929'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6149691706943674929'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/07/interview-with-jeff-williams.html' title='Interview with Jeff Williams'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4653972650084646995</id><published>2010-07-21T20:44:00.001-07:00</published><updated>2010-07-21T20:45:22.559-07:00</updated><title type='text'>OWASP July Newsletter</title><content type='html'>I am pleased to forward the link to the July edition of the OWASP Newsletter:  &lt;a href="http://www.owasp.org/index.php/Category:OWASP_Newsletter#tab=Newsletters"&gt;http://www.owasp.org/index.php/Category:OWASP_Newsletter#tab=Newsletters&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;As you can see from the front page, our global community is going to be very busy this fall, beginning with our US AppSec event in Irvine, California.  If you have not done so already, please visit &lt;a href="http://www.owasp.org/index.php/AppSec_US_2010,_CA"&gt;http://www.owasp.org/index.php/AppSec_US_2010,_CA&lt;/a&gt; for the training courses being offered as well as the updated agenda!  You can also find information on travel, special room discounts, sponsorship, and registration.&lt;br /&gt;&lt;br /&gt;As always, if you need any assistance, do not hesitate to send me an email or give me a call!&lt;br /&gt;&lt;br /&gt;I hope to see everyone in California in September!&lt;br /&gt;&lt;br /&gt;Kate Hartmann&lt;br /&gt;OWASP Operations Director&lt;br /&gt;9175 Guilford Road&lt;br /&gt;Suite 300&lt;br /&gt;Columbia, MD  21046&lt;br /&gt;&lt;br /&gt;301-275-9403&lt;br /&gt;kate.hartmann@owasp.org&lt;br /&gt;Skype:  kate.hartmann1&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4653972650084646995?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4653972650084646995/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/07/owasp-july-newsletter.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4653972650084646995'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4653972650084646995'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/07/owasp-july-newsletter.html' title='OWASP July Newsletter'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-5779744876789487235</id><published>2010-07-21T20:26:00.000-07:00</published><updated>2010-07-21T20:34:33.284-07:00</updated><title type='text'>OWASP New Zealand Day 2010</title><content type='html'>Hi everyone,&lt;br /&gt;&lt;br /&gt;The OWASP New Zealand Day 2010 conference was great and it was cool to see 160 delegates gathering for the event! At the end, we had 7 presentations including an impromptu one ;-).&lt;br /&gt;&lt;br /&gt;Feedback forms returned indicate audience was satisfied with the overall quality of the event and I believe this feedback recognized all the efforts to make this conference happen. In fact, I must thank again all the speakers for the time spent and their contribution to the OWASP community. Without them, there won't be a conference.&lt;br /&gt;&lt;br /&gt;I would also like to remember that entry to the conference was free and sponsors Security-Assessment.com and Lateral Security offered coffee, lunch and snack breaks to all the attendees.&lt;br /&gt;&lt;br /&gt;Some of the presentations have been published and can be downloaded from:&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/OWASP_New_Zealand_Day_2010#tab=Presentations"&gt;http://www.owasp.org/index.php/OWASP_New_Zealand_Day_2010#tab=Presentations&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Remaining presentations will be probably published later next month.&lt;br /&gt;&lt;br /&gt;OWASP NZ Day 2010 had also some blog coverage:&lt;br /&gt;&lt;br /&gt;- Kirk Jackson wrote an excellent article covering all the key points raised during the conference:&lt;br /&gt;&lt;a href="http://pageofwords.com/blog/CategoryView,category,OWASP.aspx"&gt;http://pageofwords.com/blog/CategoryView,category,OWASP.aspx&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If anyone is planning to write or wrote articles/stories on the conference/talks, please let me know.&lt;br /&gt;&lt;br /&gt;Feel free to check upcoming OWASP NZ chapter activities at the following page:&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/New_Zealand"&gt;&lt;br /&gt;http://www.owasp.org/index.php/New_Zealand&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;or if you haven't yet, subscribe to the OWASP NZ Chapter mailing-list for future announcements:&lt;br /&gt;&lt;br /&gt;&lt;a href="https://lists.owasp.org/mailman/listinfo/owasp-newzealand"&gt;https://lists.owasp.org/mailman/listinfo/owasp-newzealand&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Thanks again,&lt;br /&gt;&lt;br /&gt;Roberto Suggi Liverani&lt;br /&gt;OWASP NZ Leader&lt;br /&gt;&lt;br /&gt;----&lt;br /&gt;OWASP New Zealand Day 2010 was kindly offered and supported by the following sponsors:&lt;br /&gt;&lt;br /&gt;- University of Auckland (ICT and Department of Information Systems and Operations Management) - www.auckland.ac.nz&lt;br /&gt;- NZISF (New Zealand Information Security Forum) - www.security.org.nz/NZISF_NZISForumContent.php&lt;br /&gt;- Security-Assessment.com - www.security-assessment.com&lt;br /&gt;- Lateral Security - www.lateralsecurity.com&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-5779744876789487235?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/5779744876789487235/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/07/owasp-new-zealand-day-2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5779744876789487235'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5779744876789487235'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/07/owasp-new-zealand-day-2010.html' title='OWASP New Zealand Day 2010'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-5157942539308855664</id><published>2010-07-11T18:42:00.001-07:00</published><updated>2010-07-11T18:44:06.379-07:00</updated><title type='text'>SECOND CALL FOR TRAINING SESSIONS (brazil)</title><content type='html'>&lt;pre wrap=""&gt;**OWASP APPSEC BRASIL 2010**&lt;br /&gt;**SECOND CALL FOR TRAINING SESSIONS**&lt;br /&gt;&lt;br /&gt;Colleagues,&lt;br /&gt;&lt;br /&gt;OWASP is currently soliciting training proposals for the OWASP AppSec Brazil 2010 Conference which will take place at Fundação CPqD in Campinas, SP, Brazil, on November 16 through November 19, 2010. There will be training courses on November 16 and 17 followed by plenary sessions on the 18 and 19 with one single track per day.&lt;br /&gt;&lt;br /&gt;We are seeking training proposals on the following topics (in no particular order):&lt;br /&gt;- Application Threat Modeling - Business Risks with Application Security&lt;br /&gt;- Hands-on Source Code Review&lt;br /&gt;- Metrics for Application Security&lt;br /&gt;- OWASP Tools and Projects&lt;br /&gt;- Privacy Concerns with Applications and Data Storage&lt;br /&gt;- Secure Coding Practices (J2EE/.NET)&lt;br /&gt;- Starting and Managing Secure Development Lifecycle Programs&lt;br /&gt;- Technology specific presentations on security such as AJAX, XML, etc&lt;br /&gt;- Web Application Security countermeasures&lt;br /&gt;- Web Application Security Testing&lt;br /&gt;- Web Services, XML- and Application Security&lt;br /&gt;- Anything else relating to OWASP and Application Security&lt;br /&gt;&lt;br /&gt;Proposals on topics not listed above but related to the conference (i.e. which are related to Application Security) may also be accepted.&lt;br /&gt;&lt;br /&gt;To make a submission you must fill out the form available at &lt;a class="moz-txt-link-freetext" href="http://www.owasp.org/images/1/1a/OWASP_AppSec_Brasil_2010_CFT.rtf.zip"&gt;http://www.owasp.org/images/1/1a/OWASP_AppSec_Brasil_2010_CFT.rtf.zip&lt;/a&gt; and submit by email to &lt;a class="moz-txt-link-abbreviated" href="mailto:organizacao2010@appsecbrasil.org"&gt;organizacao2010@appsecbrasil.org&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;There may be 1 or 2-day courses. The proposals must respect the restrictions of the OWASP Speaker Agreement. The conference will reward trainers with at least 30% of the total revenue of their courses, based on a minimum attendance. Courses that attract more students may be granted higher percentages. No other compensation (such as tickets or lodging) will be provided. If you require a different arrangement, please contact the conference chair at the email address below.&lt;br /&gt;&lt;br /&gt;**Compensation**&lt;br /&gt;Instructors and authors will be paid based on the number of students in their training sessions. If the training gathers only the minimum number of students, the compensation will be 30% of the revenue. For each group of 10 extra students enrolled, the compensation will be increased by 5% of the revenue, up to a maximum of 45% of the training revenue. For example, a 1-day training with 10 to 19 students will generate a compensation of 30% of the revenue. For classes of 20 to 29&lt;br /&gt;students, the compensation raises to 35% percent of the revenue.&lt;br /&gt;&lt;br /&gt;In exceptional cases, different compensation schemes may be accepted. Please contact the conference organization team by email (&lt;a class="moz-txt-link-abbreviated" href="mailto:organizacao2010@appsecbrasil.org"&gt;organizacao2010@appsecbrasil.org&lt;/a&gt;) for details.&lt;br /&gt;&lt;br /&gt;**Training cost**&lt;br /&gt;1-day training: R$ 450 per student&lt;br /&gt;2-day training: R$ 900 per student&lt;br /&gt;All prices in Brazilian Reais (BRL)&lt;br /&gt;&lt;br /&gt;**Minimum number of students**&lt;br /&gt;1-day trainings: 10 students&lt;br /&gt;2-day trainings: 20 students&lt;br /&gt;&lt;br /&gt;**Important Dates:**&lt;br /&gt;Submission deadline is July 26, 2010, at 11:59 PM (UTC/GMT-3).&lt;br /&gt;Notification of acceptance will be August 16, 2010.&lt;br /&gt;Final version is due September 15, 2010.&lt;br /&gt;&lt;br /&gt;The conference organization team may be contacted by email at organizacao2010 (at) appsecbrasil.org&lt;br /&gt;&lt;br /&gt;For more information, please see the following web pages:&lt;br /&gt;Conference Website: &lt;a class="moz-txt-link-freetext" href="https://www.owasp.org/index.php/AppSec_Brasil_2010"&gt;https://www.owasp.org/index.php/AppSec_Brasil_2010&lt;/a&gt;&lt;br /&gt;OWASP Speaker Agreement: &lt;a class="moz-txt-link-freetext" href="http://www.owasp.org/index.php/Speaker_Agreement"&gt;http://www.owasp.org/index.php/Speaker_Agreement&lt;/a&gt;&lt;br /&gt;OWASP Website: &lt;a class="moz-txt-link-freetext" href="http://www.owasp.org/"&gt;http://www.owasp.org&lt;/a&gt;&lt;br /&gt;Easychair conference site: &lt;a class="moz-txt-link-freetext" href="http://www.easychair.org/conferences/?conf=appsecbr2010"&gt;http://www.easychair.org/conferences/?conf=appsecbr2010&lt;/a&gt;&lt;br /&gt;Presentation proposal form: &lt;a class="moz-txt-link-freetext" href="http://www.owasp.org/images/1/1a/OWASP_AppSec_Brasil_2010_CFT.rtf.zip"&gt;http://www.owasp.org/images/1/1a/OWASP_AppSec_Brasil_2010_CFT.rtf.zip&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;********** WARNING: Submissions without all the information requested in the proposal form will not be considered ************&lt;br /&gt;&lt;br /&gt;Please forward to all interested practitioners and colleagues.&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-5157942539308855664?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/5157942539308855664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/07/second-call-for-training-sessions.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5157942539308855664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/5157942539308855664'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/07/second-call-for-training-sessions.html' title='SECOND CALL FOR TRAINING SESSIONS (brazil)'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-2262400968458525979</id><published>2010-06-29T23:20:00.001-07:00</published><updated>2010-06-29T23:20:44.027-07:00</updated><title type='text'>OWASP NY/NJ Chapter Update</title><content type='html'>&lt;div&gt;The purpose of this email is to inform the &lt;b&gt;(1381) mailing list  members&lt;/b&gt; of recent changes with &lt;b&gt;OWASP NY/NJ Chapter&lt;/b&gt;.&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;It  is with great pleasure that I announce your 100% Volunteer Chapter  Leaders:&lt;/b&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Chapter Vice President(s)&lt;/b&gt; &lt;/div&gt;&lt;div&gt;&lt;span class="txt_type_wht"&gt;&lt;b&gt;1&lt;sup&gt;st&lt;/sup&gt; Vice President&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="txt_type_wht"&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-weight: normal; "&gt;- Dan Guido &lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="txt_type_wht"&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;span class="txt_type_wht"&gt;&lt;b&gt;&lt;span class="txt_type_wht"&gt;&lt;b&gt;2&lt;sup&gt;nd&lt;/sup&gt;  Vice President&lt;/b&gt;&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;- Douglas Shin &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;Chapter  Leaders&lt;/b&gt;&lt;br /&gt;-Marcin Wielgoszewski&lt;br /&gt;-Peter Dean&lt;br /&gt;-Mahi  Dontamsetti&lt;br /&gt;-Blake Cornell &lt;br /&gt;-Tom Ryan&lt;br /&gt;-Vlad Gostomelsky&lt;br /&gt;-Arkadiy  Goykhberg&lt;/div&gt;&lt;div&gt;- Kuai Hinojosa&lt;br /&gt;- Brian Peister&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;By  a vote of the above peers I was nominated and supported to continue to  in addition to my global role with OWASP Foundation to retain the role  of President of the local chapter.  For those that have heard the  chapter founding story of 5 guys, pizza and sql injection when we first  started... boy have we grown together since I got involved in 2004.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;b&gt;&lt;span class="Apple-style-span" style="font-weight: normal;"&gt;The selfless  mission of OWASP Foundation is to make application security visible, so  that people and organizations can make informed decisions about true  application security risks&lt;/span&gt;.&lt;/b&gt;   As we embark on another  cycle, I would like to remind everyone to review ABOUT OWASP at: &lt;a href="http://www.owasp.org/index.php/About_OWASP"&gt;http://www.owasp.org/index.php/About_OWASP&lt;/a&gt;   with a special focus on Ethics and Principals as I believe its core to  our association.  Locally, at a high level, our plans are to continue  to work with regional universities, like minded associations, regional  industry leaders with focus groups and continue to have regional  meetings, training events and social meet-ups to help our community  continue to grow.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;In addition please find to  follow (2) important items:&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;#1 -  To manage the  flux of individuals requesting to speak at a OWASP event we now utilize  a CFP (Call for papers) system. To be selected your submission should  highlight a NEW or existing OWASP Project.   Submissions are voted on by  ALL chapter leaders to ensure we adhere to vendor agnostic content.   Access it by visiting URL:  &lt;a href="http://www.owasp.org/index.php/NYNJMetro"&gt;http://www.owasp.org/index.php/NYNJMetro&lt;/a&gt;  and find the information under the HOW-TO #1 to get submitted.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;If  you are unclear about how to start a OWASP project no worries.. see: &lt;a href="http://www.owasp.org/index.php/How_to_Start_an_OWASP_Project"&gt;http://www.owasp.org/index.php/How_to_Start_an_OWASP_Project&lt;/a&gt;  or just ask.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;#2 - Our association needs needs  places to hold meetings, trainings, events in New York City and  Northern, Central and Southern New Jersey.  If you would like to help  simply visit our chapter website at &lt;a href="http://www.owasp.org/index.php/NYNJMetro"&gt;http://www.owasp.org/index.php/NYNJMetro&lt;/a&gt;  to contact one of our many chapter leaders to get started.  With a team  of (12) we scale to share the work load as volunteers so if you want to  help out just ask and we would like to schedule venue's as far in  advance as possible.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;On behalf of the entire  team, thank you for your continued support of our local chapter and  OWASP Foundation. If you have found value with our (118) projects,  events conferences or educational seminars we hope that you will become a  voting member of our professional association with tax deductible  individual a donation of $50.00 see:   &lt;a href="http://www.owasp.org/index.php/Membership"&gt;http://www.owasp.org/index.php/Membership&lt;/a&gt;  for full details.  &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Finally, members of the  OWASP association will be at the following events coming soon, we hope  to see you too!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The Next HOPE in NYC &lt;/div&gt;&lt;div&gt;&lt;a href="http://thenexthope.net/"&gt;http://thenexthope.net/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Blackhat&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.blackhat.com/html/bh-us-10/bh-us-10-speaker_bios.html"&gt;http://www.blackhat.com/html/bh-us-10/bh-us-10-speaker_bios.html&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Security  BSides Las Vegas&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.securitybsides.com/BSidesLasVegas"&gt;http://www.securitybsides.com/BSidesLasVegas&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;KartCon&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.owasp.org/index.php/KartCon2010"&gt;http://www.owasp.org/index.php/KartCon2010&lt;/a&gt; &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Defcon  18&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.defcon.org/"&gt;http://www.defcon.org&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;International  Conference on Cyber Security&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.iccs.fordham.edu/"&gt;http://www.iccs.fordham.edu/&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;and  many more... check in on &lt;a href="http://www.owasp.org/index.php/NYNJMetro"&gt;http://www.owasp.org/index.php/NYNJMetro&lt;/a&gt;  often as this email list is used for announcements only.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;Tom  Brennan&lt;/div&gt;&lt;div&gt;Global Board &amp;amp; NY/NJ Chapter Leader&lt;/div&gt;&lt;div&gt;OWASP  Foundation&lt;/div&gt;&lt;div&gt;973-506-9303&lt;/div&gt;&lt;div&gt;&lt;a href="mailto:tomb@owasp.org"&gt;tomb@owasp.org&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-2262400968458525979?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/2262400968458525979/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/06/owasp-nynj-chapter-update.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2262400968458525979'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/2262400968458525979'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/06/owasp-nynj-chapter-update.html' title='OWASP NY/NJ Chapter Update'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-8213847620349415</id><published>2010-06-24T17:04:00.001-07:00</published><updated>2010-06-24T17:04:50.961-07:00</updated><title type='text'>OWASP Spain Day</title><content type='html'>Hi,&lt;br /&gt;&lt;br /&gt;On Friday June 18, held the sixth edition of our conferences in Spain, at the "Universitat de Barcelona". We were pleased to have Richard Stallman and other great speakers with whom we spend a nice and very interesting day.&lt;br /&gt;&lt;br /&gt;We were able to disseminate several OWASP projects (Top 10, Wapiti and Webslayer) and we contact with personal from other universities. Several national media will reflect this event.&lt;br /&gt;&lt;br /&gt;The presentations (in Spanish) of the day and some photos are available here:&lt;br /&gt;&lt;a href="http://www.owasp.org/index.php/Spain/Meetings#Local_Meetings"&gt;http://www.owasp.org/index.php/Spain/Meetings#Local_Meetings&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Best regards,&lt;br /&gt;--&lt;br /&gt;_________________________________&lt;br /&gt;Vicente Aguilera Diaz&lt;br /&gt;OWASP Spain chapter leader&lt;br /&gt;CISA, CISSP, CSSLP, ITIL&lt;br /&gt;CEH Instructor, ECSP Instructor, OPSA, OPST&lt;br /&gt;&lt;a href="mailto:vicente.aguilera@owasp.org"&gt;vicente.aguilera@owasp.org&lt;/a&gt;&lt;br /&gt;Homepage: &lt;a href="http://www.owasp.org/index.php/Spain"&gt;http://www.owasp.org/index.php/Spain&lt;/a&gt;&lt;br /&gt;Mailing list: &lt;a href="http://lists.owasp.org/mailman/listinfo/owasp-spain"&gt;http://lists.owasp.org/mailman/listinfo/owasp-spain&lt;/a&gt;&lt;br /&gt;PGP: 0xD21C1EF8 - D1F0 E0B5 2ACC B4B5 57CD  C427 58B7 CF0D D21C 1EF8&lt;br /&gt;_________________________________&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-8213847620349415?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/8213847620349415/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/06/owasp-spain-day.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8213847620349415'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8213847620349415'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/06/owasp-spain-day.html' title='OWASP Spain Day'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-470674385689232354</id><published>2010-06-24T07:13:00.001-07:00</published><updated>2010-06-24T07:13:41.657-07:00</updated><title type='text'>OWASP Sweden announcements</title><content type='html'>Hi&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We just made these 3 announcements at the Conference here in Sweden: &lt;/div&gt;&lt;div&gt;&lt;ul&gt;&lt;li&gt;new attempt at figuring out the OWASP Commercial Services model&lt;/li&gt;&lt;li&gt;new model for creating a Source of Financial Funding for OWASP Projects and &lt;/li&gt; &lt;li&gt;the launch of the OWASP O2 Platform project (with a v1.0 Beta version available) &lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;br /&gt;You can read more details on this pdf: &lt;a href="http://www.owasp.org/index.php/File:Dinis_Cruz_-_APPSECEU_-_3_ANNOUNCEMENTS.pdf"&gt;http://www.owasp.org/index.php/File:Dinis_Cruz_-_APPSECEU_-_3_ANNOUNCEMENTS.pdf &lt;/a&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This is just a heads up and we will follow this up with individual emails on each of the 3 topics.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Note, that both Commercial Services and Source of Financial Funding  for OWASP Projects are &lt;b&gt;experiments,&lt;/b&gt; where we are trying to figure a model that works for OWASP and its community&lt;/div&gt; &lt;div&gt;&lt;br /&gt;Dinis Cruz&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-470674385689232354?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/470674385689232354/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/06/owasp-sweden-announcements.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/470674385689232354'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/470674385689232354'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/06/owasp-sweden-announcements.html' title='OWASP Sweden announcements'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4854632473263723426</id><published>2010-06-23T03:22:00.000-07:00</published><updated>2010-06-23T03:24:07.267-07:00</updated><title type='text'>OWASP AppSensor ESAPI Integration</title><content type='html'>&lt;div&gt;ESAPI Team,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;The AppSensor team has been working hard over the last several months to create an AppSensor jar that is ready for ESAPI integration.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;AppSensor is a project to enable detailed attack intrusion and response within application by integrating "detection points" into the application itself (think detecting all access control failures, malicious input, unexpected commands and more and then correlating that against the logged in user and logging out/locking the attacker). That's just the basics, more info on AppSensor here: &lt;a href="http://www.owasp.org/index.php/Category:OWASP_AppSensor_Project"&gt;http://www.owasp.org/index.php/Category:OWASP_AppSensor_Project&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Here are the instructions for easily updating an existing ESAPI application to use AppSensor. I encourage those interested to take a quick read and respond with any comments.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;a href="http://www.owasp.org/index.php/AppSensor_GettingStarted"&gt;http://www.owasp.org/index.php/AppSensor_GettingStarted&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;What's next:&lt;/div&gt;&lt;div&gt;1. We'd like to use the Getting Started guide as an initial strategy for users to begin leveraging AppSensor in their ESAPI apps. We're looking for interested parties to begin using AppSensor within ESAPI and provide their feedback.&lt;/div&gt;&lt;div&gt;2. It would also be great for the ESAPI config to contain the configuration line for AppSensor and a link to the getting started page.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;#Use OWASP AppSensor for enhanced application intrusion detection and response&lt;/div&gt;&lt;div&gt;#See http://www.owasp.org/index.php/AppSensor_GettingStarted for necessary JAR and configuration&lt;/div&gt;&lt;div&gt;#ESAPI.IntrusionDetector=org.owasp.appsensor.intrusiondetection.AppSensorIntrusionDetector&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Thoughts and feedback please.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-- &lt;/div&gt;&lt;div&gt;Michael Coates&lt;/div&gt;&lt;div&gt;OWASP&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4854632473263723426?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4854632473263723426/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/06/owasp-appsensor-esapi-integration.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4854632473263723426'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4854632473263723426'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/06/owasp-appsensor-esapi-integration.html' title='OWASP AppSensor ESAPI Integration'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-6247655428939655660</id><published>2010-06-23T01:51:00.001-07:00</published><updated>2010-06-23T01:51:57.971-07:00</updated><title type='text'>OWASP AppSec US 2010</title><content type='html'>&lt;p class="MsoNormal"&gt;I am thrilled to formally announce that registration is OPEN for this year’s OWASP United States conference.  &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;span style="color: black;"&gt;AppSec US 2010 will be held September 7th through September 10th, 2010 and will be hosted by the Orange County and Los Angeles Chapters at the University of California, Irvine, the only school in the University of California system with a dedicated school of Information and Computer Science.&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;The keynote speakers have been confirmed!  The tremendous response to the call for papers is now being transformed into a jam packed two day, multi track agenda!  Additionally, training providers are being locked in for an outstanding selection of one and two day classes.&lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;The event information as well as links to registration can be found here:  &lt;a href="http://www.owasp.org/index.php/AppSec_US_2010,_CA#tab=Welcome"&gt;http://www.owasp.org/index.php/AppSec_US_2010,_CA#tab=Welcome&lt;/a&gt; &lt;o:p&gt;&lt;/o:p&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;Registration can be completed here:  &lt;span style="color: black;"&gt;&lt;a href="https://guest.cvent.com/EVENTS/Register/IdentityConfirmation.aspx?e=3c8f8c26-a4b3-40d6-9daa-1f541ea0ccc2" title="https://guest.cvent.com/EVENTS/Register/IdentityConfirmation.aspx?e=3c8f8c26-a4b3-40d6-9daa-1f541ea0ccc2"&gt;https://guest.cvent.com/EVENTS/Register/IdentityConfirmation.aspx?e=3c8f8c26-a4b3-40d6-9daa-1f541ea0ccc2&lt;/a&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;span style="color: black;"&gt;Now is the time to make your plans to attend this year’s premier application security event hosted by the world’s foremost community of security professionals, the OWASP Foundation!  &lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    &lt;p class="MsoNormal"&gt;&lt;span style="color: black;"&gt;If you have any questions, or need additional information, please do not hesitate to contact me.  I look forward to seeing everyone in California this fall!&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;    Kate Hartmann&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;OWASP Operations Director&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;9175 Guilford Road&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;Suite 300&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;Columbia, MD  21046&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;br /&gt;301-275-9403 &lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;kate.hartmann@owasp.org&lt;o:p&gt;&lt;/o:p&gt;&lt;br /&gt;Skype:  kate.hartmann1&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-6247655428939655660?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/6247655428939655660/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/06/owasp-appsec-us-2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6247655428939655660'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/6247655428939655660'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/06/owasp-appsec-us-2010.html' title='OWASP AppSec US 2010'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-4969501561882989569</id><published>2010-06-20T06:17:00.000-07:00</published><updated>2010-06-20T06:19:07.974-07:00</updated><title type='text'>Malaysia Open Source Conference</title><content type='html'>&lt;pre wrap=""&gt;OWASP Malaysia : Contribution In MSC Malaysia Open Source Conference MOSC2010&lt;br /&gt;&lt;br /&gt;Hi,&lt;br /&gt;&lt;br /&gt;OWASP Malaysia is actively contribute to MOSC2010 by arangging speakers for the conference and OWASP Malaysia Chapter Leader - Mohd Fazli Azran is one of the committe member for MOSC2010.&lt;br /&gt;&lt;br /&gt;Speakers from OWASP&lt;br /&gt;&lt;br /&gt;OWASP Joomla CMS Vulnerability Scanner - Aung Khan, YGN Ethical Hacker&lt;br /&gt;Group, Myanmar.&lt;br /&gt;&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://conf.oss.my/component/content/article/3-newsflash/72-aung-khant-joomla-owasp.html"&gt;http://conf.oss.my/component/content/article/3-newsflash/72-aung-khant-joomla-owasp.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;OWASP and What It Can Do For You - Cecil Su, OWASP Global, Singapore.&lt;br /&gt;&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://conf.oss.my/component/content/article/3-newsflash/91-cecil-owasp-and-you.html"&gt;http://conf.oss.my/component/content/article/3-newsflash/91-cecil-owasp-and-you.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;MOSC2010 include security topics like&lt;br /&gt;&lt;br /&gt;Joomla! 1.6 Security&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://conf.oss.my/news/3-newsflash/73-sam-moffatt-joomla.html"&gt;http://conf.oss.my/news/3-newsflash/73-sam-moffatt-joomla.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Easy DNSSEC Deployment with OPENDNSSEC&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://conf.oss.my/news/1-latest-news/64-amir-haris-dnssec.html"&gt;http://conf.oss.my/news/1-latest-news/64-amir-haris-dnssec.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Internet Malicious Miscreant&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://conf.oss.my/news/3-newsflash/69-najmi-internet-malicious.html"&gt;http://conf.oss.my/news/3-newsflash/69-najmi-internet-malicious.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For OWASP Malaysia, this will create awareness about security and OWASP.&lt;br /&gt;&lt;br /&gt;For more information about MOSC2010&lt;br /&gt;&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://conf.oss.my/"&gt;http://conf.oss.my/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Thank you&lt;br /&gt;&lt;br /&gt;Harisfazillah Jamel&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-4969501561882989569?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/4969501561882989569/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/06/owasp-malaysia-mosc2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4969501561882989569'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/4969501561882989569'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/06/owasp-malaysia-mosc2010.html' title='Malaysia Open Source Conference'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-464463063331113706</id><published>2010-06-16T22:41:00.000-07:00</published><updated>2010-06-16T22:43:13.177-07:00</updated><title type='text'>AppSec US 2010</title><content type='html'>&lt;div&gt;Dear OWASP Leaders,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;AppSec US 2010 is live at &lt;a href="http://www.appsecUSA.org"&gt;http://www.appsecUSA.org&lt;/a&gt; &lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Registration is open. Early registration prices are valid till July 15.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Call for presentations deadline has also been extended till June 30.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;As it is the premier OWASP conference of 2010 for US/North America, I would like to ask your help to promote it. Please spread the word everywhere you can -- at local chapter meetings, local meetings of other security or IT organizations, your colleagues at work, at your school, etc.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;We are also looking for the volunteers to help with the conference. If you are interested in volunteering, please let me know.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;Many thanks in advance!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;-- Tin Zaw, CISSP, CSSLP&lt;/div&gt;&lt;div&gt;Chapter Leader and President&lt;/div&gt;&lt;div&gt;OWASP Los Angeles Chapter Co-Chair&lt;/div&gt;&lt;div&gt;AppSec USA 2010 Program Committee &lt;/div&gt;&lt;div&gt;www.appsecUSA.org &lt;/div&gt;&lt;div&gt;Google Voice: (213) 973-9295&lt;/div&gt;&lt;div&gt;LinkedIn: http://www.linkedin.com/in/tinzaw &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-464463063331113706?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/464463063331113706/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/06/appsec-us-2010_16.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/464463063331113706'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/464463063331113706'/><link rel='alternate' type='text/html' href='http://owasp.blogspot.com/2010/06/appsec-us-2010_16.html' title='AppSec US 2010'/><author><name>Jim Manico</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='25' height='32' src='http://www.manico.net/jimtux2.jpg'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-3544150258492345305.post-8602960943468784816</id><published>2010-06-16T15:38:00.001-07:00</published><updated>2010-06-16T15:39:35.575-07:00</updated><title type='text'>OWASP New Zealand Day 2010</title><content type='html'>&lt;pre wrap=""&gt;Hi,&lt;br /&gt;&lt;br /&gt;I am glad to announce the first round of speakers that have been selected for the OWASP New Zealand Day 2010 conference.&lt;br /&gt;&lt;br /&gt;* Scott Bell - Security-Assessment.com - Web Application Vulnerabilities: How far does the rabbit hole go?&lt;br /&gt;* Dean Carter - The Ramblings of an ex-QSA&lt;br /&gt;* Paul Craig - Security-Assessment.com - "Oh F#!K" : What To Do When You Get Pwned&lt;br /&gt;* Graeme Neilson - Aura Software Security &amp;amp; Kirk Jackson - Xero - Tales from the Crypt0&lt;br /&gt;&lt;br /&gt;The conference web site has been updated with a speakers section and talk abstracts:&lt;br /&gt;&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://www.owasp.org/index.php/OWASP_New_Zealand_Day_2010#tab=Speakers"&gt;http://www.owasp.org/index.php/OWASP_New_Zealand_Day_2010#tab=Speakers&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Please note that CFP (Call for Paper) is still open and it will close on the 30th June. There are still available slots for talks.&lt;br /&gt;&lt;br /&gt;For more information about the CFP and submission, please refer to my previous post:&lt;br /&gt;&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="https://lists.owasp.org/pipermail/owasp-newzealand/2010-May/000052.html"&gt;https://lists.owasp.org/pipermail/owasp-newzealand/2010-May/000052.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;I am delighted to announce that 160 people registered so far to attend the event.&lt;br /&gt;&lt;br /&gt;This is an excellent result for OWASP in New Zealand and thanks for spreading the voice.&lt;br /&gt;&lt;br /&gt;If you are reading this post and you haven't registered yet, please do it by visiting:&lt;br /&gt;&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://owaspnzday2010.eventbrite.com/"&gt;http://owaspnzday2010.eventbrite.com/&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Please feel free to invite other people who might be interested to join us.&lt;br /&gt;&lt;br /&gt;The event registration will end on the 30th June 2010.&lt;br /&gt;&lt;br /&gt;For those of you using LinkedIn, please feel free to join the group "OWASP New Zealand Chapter" at:&lt;br /&gt;&lt;br /&gt;&lt;a class="moz-txt-link-freetext" href="http://www.linkedin.com/groups?gid=1966105"&gt;http://www.linkedin.com/groups?gid=1966105&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Again thanks to everyone for helping the OWASP NZ chapter. Special thanks to&lt;br /&gt;the University of Auckland for providing the venue.&lt;br /&gt;&lt;br /&gt;The final list of speakers and the conference agenda will be published on&lt;br /&gt;the 1st July.&lt;br /&gt;&lt;br /&gt;Cheers,&lt;br /&gt;&lt;br /&gt;Roberto Suggi Liverani&lt;br /&gt;&lt;br /&gt;OWASP NZ Leader&lt;br /&gt;&lt;br /&gt;--&lt;br /&gt;OWASP New Zealand Day 2010 is kindly offered and supported by the&lt;br /&gt;following sponsors:&lt;br /&gt;&lt;br /&gt;- University of Auckland (Department of Computer Science) - &lt;a class="moz-txt-link-abbreviated" href="http://www.auckland.ac.nz/"&gt;www.auckland.ac.nz&lt;/a&gt;&lt;br /&gt;- NZISF (New Zealand Information Security Forum) -&lt;br /&gt;&lt;a class="moz-txt-link-abbreviated" href="http://www.security.org.nz/NZISF_NZISForumContent.php"&gt;www.security.org.nz/NZISF_NZISForumContent.php&lt;/a&gt;&lt;br /&gt;- Security-Assessment.com - &lt;a class="moz-txt-link-abbreviated" href="http://www.security-assessment.com/"&gt;www.security-assessment.com&lt;/a&gt;&lt;br /&gt;- Lateral Security - &lt;a class="moz-txt-link-abbreviated" href="http://www.lateralsecurity.com/"&gt;www.lateralsecurity.com&lt;/a&gt;&lt;br /&gt;_______________________________________________&lt;br /&gt;&lt;/pre&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/3544150258492345305-8602960943468784816?l=owasp.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://owasp.blogspot.com/feeds/8602960943468784816/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://owasp.blogspot.com/2010/06/owasp-new-zealand-day-2010.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/3544150258492345305/posts/default/8602960943468784816'/>
