<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Afongen</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Afongen"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Afongen"/>
		<updated>2026-05-28T08:44:16Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=67210</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=67210"/>
				<updated>2009-08-04T15:21:18Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: /* Minneapolis - Saint Paul OWASP Board Members */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Platinum Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.bestbuy.com http://www.owasp.org/images/6/67/Best_Buy_logo.jpg]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP MSP chapter is very thankful for generous support from platinum sponsor '''[http://www.bestbuy.com/ Best Buy]'''.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Minneapolis-St. Paul 2009 Half Day Conference - August 24, 2009  ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Minneapolis-St. Paul (MSP) chapter is pleased to announce '''[[OWASP Minneapolis St Paul 2009_Conference | an afternoon of information security presentations on August 24, 2009]]''' at the [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center] [http://www.spsc.umn.edu/about/directory/lower.php Auditorium/Theater] on the [http://www1.umn.edu/twincities/index.php University of Minnesota - Twin Cities] campus.&lt;br /&gt;
&lt;br /&gt;
'''[[OWASP Minneapolis St Paul 2009_Conference | Go the the event page to learn more and register today!]]'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Thanks to all who joined us on October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
=== OWASP Minneapolis-St. Paul 2009 Half Day Conference ===&lt;br /&gt;
&lt;br /&gt;
'''The OWASP Minneapolis-St.Paul 2009 half day conference is scheduled for August 24, 2009. See above for more details.'''&lt;br /&gt;
&lt;br /&gt;
=== Thank You ===&lt;br /&gt;
A big thanks goes to [http://strategicit.org/center/ Center for Strategic Information Technology and Security] for sponsoring our regular monthly meeting location.&lt;br /&gt;
&lt;br /&gt;
We are currently looking for a meeting sponsor for refreshments and book give-aways for the monthly meetings.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Upcoming Events ==&lt;br /&gt;
&lt;br /&gt;
=== OWASP Minneapolis-St. Paul 2009 Half Day Conference ===&lt;br /&gt;
&lt;br /&gt;
'''The OWASP Minneapolis-St.Paul 2009 half day conference is scheduled for August 24, 2009. See above for more details.'''&lt;br /&gt;
&lt;br /&gt;
=== Secure360 ===&lt;br /&gt;
[http://www.secure360.org/ Secure360] is an annual&lt;br /&gt;
conference providing high quality educational sessions and networking&lt;br /&gt;
opportunities while working to identify developing trends in risk&lt;br /&gt;
management, physical security, governance, audit, information security,&lt;br /&gt;
contingency planning and human capital.&lt;br /&gt;
&lt;br /&gt;
=== DC612 meetings ===&lt;br /&gt;
DC612 meets the 2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
=== Most recent videos: ===&lt;br /&gt;
&lt;br /&gt;
Cassio Goldschmidt - Tracking the Progress of an SDL Program: Lessons from the Gym - OWASP (MSP) - 29 June 2009 (55 minutes) [http://www.slideshare.net/webappsecguy/tracking-the-progress-of-an-sdl-program-lessons-from-the-gym-1684512 Slidecast]  | [http://www.comotheory.com/owasp/20090629-Cassio_Goldschmidt-Tracking_the_Progress_of_an_SDL_Program_-_Lessons_from_the_Gym.mp3 MP3] | [http://www.owasp.org/images/0/0e/20090629-Cassio_Goldschmidt-Tracking_the_Progress_of_an_SDL_Program_-_Lessons_from_the_Gym.pptx PPTX] | [http://www.comotheory.com/owasp/20090629-Cassio_Goldschmidt-Tracking_the_Progress_of_an_SDL_Program_-_Lessons_from_the_Gym.mp4 MP4...please right click and save]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - OWASP Top Ten Web Services - OWASP (MSP) - 27 April 2009 (1 hour, 27 minutes) [http://www.comotheory.com/owasp/20090427-Gunnar_Peterson_-_OWASP_Top_Ten_Web_Services.mp4 MP4...please right click and save] | Slides Forthcoming&lt;br /&gt;
&lt;br /&gt;
Dan Cornell - Vulnerability Management in an Application Security World - OWASP (MSP) - 16 March 2009 (1 hour, 52 minutes) [http://video.google.com/videoplay?docid=3200887090385342211&amp;amp;hl=en Google Video] | [http://www.owasp.org/images/1/16/VulnerabilityManagementInAnApplicaitonSecurityWorld_OWASPMSP_20090316.pdf PDF]&lt;br /&gt;
&lt;br /&gt;
Rick Ensenbach - Proactive Lifecycle Security Management - OWASP (MSP) - 16 February 2009 (69 minutes) [http://video.google.com/videoplay?docid=2838721966098123222&amp;amp;hl=en Part 1 Google Video] | [http://video.google.com/videoplay?docid=1766766374336659744&amp;amp;hl=en Part 2 Google Video] | [https://www.owasp.org/images/f/f8/Proactive_Lifecycle_Security_Management_Presentation_for_OWASP_Mpls-Stp_Chapter_Meeting_-_2-16-09.ppt PPT] | [https://www.owasp.org/images/9/9c/Generic_System_Security_Plan.doc Handout: Service/System Security Plan template (DOC)]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=63614</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=63614"/>
				<updated>2009-06-04T20:44:35Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: /* Bruce Schneier - Special OWASP Chapter Meeting August 24th */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Upcoming Meetings ===&lt;br /&gt;
&amp;lt;h3&amp;gt;June 29th OWASP Meeting – Cassio Goldschmidt&amp;lt;br /&amp;gt;&lt;br /&gt;
Tracking the progress of an SDL program: lessons from the gym&amp;lt;/h3&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Monday, June 29th, 2009, 6:00 p.m.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Forcing muscle growth is a long process which requires high intensity weight training and high mental concentration. While the ultimate goal is often clear, one of the greatest mistakes bodybuilders consistently make is to overlook the importance of tracking their weight lifting progress.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Like a successful bodybuilding workout, a security development lifecycle program must consistently log simple to obtain, yet meaningful metrics throughout the entire process.  Good metrics must lack subjectivity and clearly aid decision makers to determine areas that need improvement. In this presentation we’ll discuss metrics used to classify and appropriately compare security vulnerabilities found in different phases of the SDL by different teams working in different locations and in different products. We’ll also discuss how to easily provide decision makers different views of the same data and verify whether the process is indeed catching critical vulnerabilities internally.&lt;br /&gt;
&lt;br /&gt;
=== Speaker Bio === &lt;br /&gt;
Cassio Goldschmidt is senior manager of the product security team under the Office of the CTO at Symantec Corporation.  In this role he leads efforts across the company to ensure the secure development of software products.  His responsibilities include managing Symantec’s internal secure software development process, training, threat modeling and penetration testing.  Cassio’s background includes over 12 years of technical and managerial experience in the software industry.  During the six years he has been with Symantec, he has helped to architect, design and develop several top selling product releases, conducted numerous security classes, and coordinated various penetration tests.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Cassio represents Symantec on the SAFECode technical committee and (ISC)2 in the development of the CSSLP certification. He holds a bachelor degree in computer science from Pontificia Universidade Catolica do Rio Grande Do Sul, a masters degree in software engineering from Santa Clara University, and a masters of business administration from the University of Southern California.&lt;br /&gt;
&lt;br /&gt;
=== Where/When ===&lt;br /&gt;
Date: Monday, June 29th, 2009&amp;lt;br /&amp;gt;&lt;br /&gt;
Time: 6:00 p.m.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
UAW-Ford-MnSCU Training Center&amp;lt;br /&amp;gt;&lt;br /&gt;
966 South Mississippi River Boulevard&amp;lt;br /&amp;gt;&lt;br /&gt;
Saint Paul, Minnesota 55116&lt;br /&gt;
&lt;br /&gt;
=== Agenda ===&lt;br /&gt;
5:30 pm – Room opens for Networking&amp;lt;br /&amp;gt;&lt;br /&gt;
6:00pm - Welcome: OWASP chapter updates, Conference Announcement!&amp;lt;br /&amp;gt;&lt;br /&gt;
6:30pm – Cassio Goldschmidt –  Tracking the progress of an SDL program: lessons from the gym&amp;lt;br /&amp;gt;&lt;br /&gt;
8:00 pm - Upcoming Events reminder and meeting wrap-up&lt;br /&gt;
&lt;br /&gt;
Email lalamri@go-integral.com if you plan to attend so we can order enough refreshments.&lt;br /&gt;
&lt;br /&gt;
===Thank You===&lt;br /&gt;
[http://strategicit.org/center/ Center for Strategic Information Technology and Security] for sponsoring our meeting location.&lt;br /&gt;
&lt;br /&gt;
We currently are looking for a meeting sponsor for refreshments for the meeting and for the book give-away.&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Thanks to all who joined us on October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
=== Most recent videos: ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.comotheory.com/owasp/20090427-Gunnar_Peterson_-_OWASP_Top_Ten_Web_Services.mp4 Gunnar Peterson - OWASP Top Ten Web Services - OWASP (MSP) - 27 April 2009 (1 hour, 27 minutes) (MP4, 220 MB...please right click and save)] | Slides Forthcoming&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=3200887090385342211&amp;amp;hl=en Dan Cornell - Vulnerability Management in an Application Security World - OWASP (MSP) - 16 March 2009 (1 hour, 52 minutes)] | [http://www.owasp.org/images/1/16/VulnerabilityManagementInAnApplicaitonSecurityWorld_OWASPMSP_20090316.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Rick Ensenbach - Proactive Lifecycle Security Management - OWASP (MSP) - 16 February 2009 ([http://video.google.com/videoplay?docid=2838721966098123222&amp;amp;hl=en Part 1] of 2 - 35 minutes) ([http://video.google.com/videoplay?docid=1766766374336659744&amp;amp;hl=en Part 2] of 2 - 34 minutes) | [https://www.owasp.org/images/f/f8/Proactive_Lifecycle_Security_Management_Presentation_for_OWASP_Mpls-Stp_Chapter_Meeting_-_2-16-09.ppt Slides (PPT)] | [https://www.owasp.org/images/9/9c/Generic_System_Security_Plan.doc Handout: Service/System Security Plan template (DOC)]&lt;br /&gt;
&lt;br /&gt;
== Upcoming Events ==&lt;br /&gt;
=== Bruce Schneier - Special OWASP Chapter Meeting August 24th ===&lt;br /&gt;
Please join us to Welcome Bruce Schneier at the University of Minnesota's Bell Museum Auditorium August 24th&lt;br /&gt;
&lt;br /&gt;
=== Secure360 ===&lt;br /&gt;
[http://www.secure360.org/ Secure360] is an annual&lt;br /&gt;
conference providing high quality educational sessions and networking&lt;br /&gt;
opportunities while working to identify developing trends in risk&lt;br /&gt;
management, physical security, governance, audit, information security,&lt;br /&gt;
contingency planning and human capital.&lt;br /&gt;
&lt;br /&gt;
=== DC612 meetings ===&lt;br /&gt;
DC612 meets the 2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&amp;lt;br /&amp;gt;&lt;br /&gt;
Secretary: [mailto:sam.buchanan@gmail.com Sam Buchanan]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=63613</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=63613"/>
				<updated>2009-06-04T20:26:20Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: /* Where/When */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Upcoming Meetings ===&lt;br /&gt;
&amp;lt;h3&amp;gt;June 29th OWASP Meeting – Cassio Goldschmidt&amp;lt;br /&amp;gt;&lt;br /&gt;
Tracking the progress of an SDL program: lessons from the gym&amp;lt;/h3&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Monday, June 29th, 2009, 6:00 p.m.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Forcing muscle growth is a long process which requires high intensity weight training and high mental concentration. While the ultimate goal is often clear, one of the greatest mistakes bodybuilders consistently make is to overlook the importance of tracking their weight lifting progress.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Like a successful bodybuilding workout, a security development lifecycle program must consistently log simple to obtain, yet meaningful metrics throughout the entire process.  Good metrics must lack subjectivity and clearly aid decision makers to determine areas that need improvement. In this presentation we’ll discuss metrics used to classify and appropriately compare security vulnerabilities found in different phases of the SDL by different teams working in different locations and in different products. We’ll also discuss how to easily provide decision makers different views of the same data and verify whether the process is indeed catching critical vulnerabilities internally.&lt;br /&gt;
&lt;br /&gt;
=== Speaker Bio === &lt;br /&gt;
Cassio Goldschmidt is senior manager of the product security team under the Office of the CTO at Symantec Corporation.  In this role he leads efforts across the company to ensure the secure development of software products.  His responsibilities include managing Symantec’s internal secure software development process, training, threat modeling and penetration testing.  Cassio’s background includes over 12 years of technical and managerial experience in the software industry.  During the six years he has been with Symantec, he has helped to architect, design and develop several top selling product releases, conducted numerous security classes, and coordinated various penetration tests.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
Cassio represents Symantec on the SAFECode technical committee and (ISC)2 in the development of the CSSLP certification. He holds a bachelor degree in computer science from Pontificia Universidade Catolica do Rio Grande Do Sul, a masters degree in software engineering from Santa Clara University, and a masters of business administration from the University of Southern California.&lt;br /&gt;
&lt;br /&gt;
=== Where/When ===&lt;br /&gt;
Date: Monday, June 29th, 2009&amp;lt;br /&amp;gt;&lt;br /&gt;
Time: 6:00 p.m.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
UAW-Ford-MnSCU Training Center&amp;lt;br /&amp;gt;&lt;br /&gt;
966 South Mississippi River Boulevard&amp;lt;br /&amp;gt;&lt;br /&gt;
Saint Paul, Minnesota 55116&lt;br /&gt;
&lt;br /&gt;
=== Agenda ===&lt;br /&gt;
5:30 pm – Room opens for Networking&amp;lt;br /&amp;gt;&lt;br /&gt;
6:00pm - Welcome: OWASP chapter updates, Conference Announcement!&amp;lt;br /&amp;gt;&lt;br /&gt;
6:30pm – Cassio Goldschmidt –  Tracking the progress of an SDL program: lessons from the gym&amp;lt;br /&amp;gt;&lt;br /&gt;
8:00 pm - Upcoming Events reminder and meeting wrap-up&lt;br /&gt;
&lt;br /&gt;
Email lalamri@go-integral.com if you plan to attend so we can order enough refreshments.&lt;br /&gt;
&lt;br /&gt;
===Thank You===&lt;br /&gt;
[http://strategicit.org/center/ Center for Strategic Information Technology and Security] for sponsoring our meeting location.&lt;br /&gt;
&lt;br /&gt;
We currently are looking for a meeting sponsor for refreshments for the meeting and for the book give-away.&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Thanks to all who joined us on October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
=== Most recent videos: ===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.comotheory.com/owasp/20090427-Gunnar_Peterson_-_OWASP_Top_Ten_Web_Services.mp4 Gunnar Peterson - OWASP Top Ten Web Services - OWASP (MSP) - 27 April 2009 (1 hour, 27 minutes) (MP4, 220 MB...please right click and save)] | Slides Forthcoming&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=3200887090385342211&amp;amp;hl=en Dan Cornell - Vulnerability Management in an Application Security World - OWASP (MSP) - 16 March 2009 (1 hour, 52 minutes)] | [http://www.owasp.org/images/1/16/VulnerabilityManagementInAnApplicaitonSecurityWorld_OWASPMSP_20090316.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Rick Ensenbach - Proactive Lifecycle Security Management - OWASP (MSP) - 16 February 2009 ([http://video.google.com/videoplay?docid=2838721966098123222&amp;amp;hl=en Part 1] of 2 - 35 minutes) ([http://video.google.com/videoplay?docid=1766766374336659744&amp;amp;hl=en Part 2] of 2 - 34 minutes) | [https://www.owasp.org/images/f/f8/Proactive_Lifecycle_Security_Management_Presentation_for_OWASP_Mpls-Stp_Chapter_Meeting_-_2-16-09.ppt Slides (PPT)] | [https://www.owasp.org/images/9/9c/Generic_System_Security_Plan.doc Handout: Service/System Security Plan template (DOC)]&lt;br /&gt;
&lt;br /&gt;
== Upcoming Events ==&lt;br /&gt;
=== Bruce Schneier - Special OWASP Chapter Meeting August 24th ===&lt;br /&gt;
Please join us to Welcome Bruce Schneier at the University Of Minnesota's Bell Museum Auditorium August 24th&lt;br /&gt;
&lt;br /&gt;
=== Secure360 ===&lt;br /&gt;
[http://www.secure360.org/ Secure360] is an annual&lt;br /&gt;
conference providing high quality educational sessions and networking&lt;br /&gt;
opportunities while working to identify developing trends in risk&lt;br /&gt;
management, physical security, governance, audit, information security,&lt;br /&gt;
contingency planning and human capital.&lt;br /&gt;
&lt;br /&gt;
=== DC612 meetings ===&lt;br /&gt;
DC612 meets the 2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&amp;lt;br /&amp;gt;&lt;br /&gt;
Secretary: [mailto:sam.buchanan@gmail.com Sam Buchanan]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=59172</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=59172"/>
				<updated>2009-04-18T20:49:12Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: /* Upcoming Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&amp;lt;h3&amp;gt;April OWASP Meeting – Gunnar Peterson&amp;lt;br /&amp;gt;&lt;br /&gt;
OWASP Top Ten Web Services&amp;lt;/h3&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Monday, April 27, 2009, 6:00 p.m.&lt;br /&gt;
&lt;br /&gt;
What do Web apps, Web 2.0, Cloud Computing, SOA, and Rest all have in common? They all use Web services for functionality, data access and integration. Unfortunately, by default Web services also lack a security model. The OWASP Top Ten Web Services goes into the technical details of the vulnerabilities, remediations, and examples of common &lt;br /&gt;
&lt;br /&gt;
Web services security issues like authentication and authorization flaws, how sensitive data is disclosed, and why security standards like WS-Security and SAML can be your best friend or your worst nightmare.&lt;br /&gt;
&lt;br /&gt;
=== Speaker Bio === &lt;br /&gt;
Gunnar Peterson Managing Principal Arctec Group, a Twin Cities based consulting and training firm. He is also Visiting Scientist at Carnegie Mellon University Software Engineering Institute, editor for IEEE Security &amp;amp; Privacy Journal &amp;quot;Build Security In,&amp;quot; and lead on OWASP Top Ten Web Services. He maintains a popular information security blog at http://1raindrop.typepad.com&lt;br /&gt;
&lt;br /&gt;
=== Where/When ===&lt;br /&gt;
Date: Monday, April 27, 2009&amp;lt;br /&amp;gt;&lt;br /&gt;
Time: 6:00 p.m.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Location:  L3000 - third Floor of the Library Building, Wheelock Whitney Hall, Minneapolis Community and Technical College (Room and building change from last meeting.)&lt;br /&gt;
&lt;br /&gt;
Address: 1501 Hennepin Avenue, Minneapolis, MN 55403&amp;lt;br  /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Directions: http://www.minneapolis.edu/campusmaps/index.cfm or http://www.minneapolis.edu/directions.cfm&lt;br /&gt;
&lt;br /&gt;
=== Agenda ===&lt;br /&gt;
5:30 pm – Room opens for Networking&amp;lt;br /&amp;gt;&lt;br /&gt;
6:00pm - Welcome: OWASP chapter updates, Conference Announcement!&amp;lt;br /&amp;gt;&lt;br /&gt;
6:30pm – Gunnar Peterson – OWASP Top Ten Web Services&amp;lt;br /&amp;gt;&lt;br /&gt;
8:00 pm - Upcoming Events reminder and meeting wrap-up&lt;br /&gt;
&lt;br /&gt;
Email lalamri@go-integral.com if you plan to attend so we can order enough refreshments.&lt;br /&gt;
&lt;br /&gt;
===Thank You===&lt;br /&gt;
[http://strategicit.org/center/ Center for Strategic Information Technology and Security] for sponsoring our meeting location.&lt;br /&gt;
&lt;br /&gt;
We currently are looking for a meeting sponsor for refreshments for the meeting and for the book give-away.&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Thanks to all who joined us on October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
=== Most recent videos: ===&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=3200887090385342211&amp;amp;hl=en Dan Cornell - Vulnerability Management in an Application Security World - OWASP (MSP) - 16 March 2009 (1 hour, 52 minutes)] | [http://www.owasp.org/images/1/16/VulnerabilityManagementInAnApplicaitonSecurityWorld_OWASPMSP_20090316.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Rick Ensenbach - Proactive Lifecycle Security Management - OWASP (MSP) - 16 February 2009 ([http://video.google.com/videoplay?docid=2838721966098123222&amp;amp;hl=en Part 1] of 2 - 35 minutes) ([http://video.google.com/videoplay?docid=1766766374336659744&amp;amp;hl=en Part 2] of 2 - 34 minutes) | [https://www.owasp.org/images/f/f8/Proactive_Lifecycle_Security_Management_Presentation_for_OWASP_Mpls-Stp_Chapter_Meeting_-_2-16-09.ppt Slides (PPT)] | [https://www.owasp.org/images/9/9c/Generic_System_Security_Plan.doc Handout: Service/System Security Plan template (DOC)]&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=1665928867290955158 Kuai Hinojosa - OWASP MN Mini Conference Introduction - 21 October 2008 (3 minutes)]&lt;br /&gt;
&lt;br /&gt;
== Upcoming Events ==&lt;br /&gt;
=== Secure360 ===&lt;br /&gt;
[http://www.secure360.org/ Secure360] is an annual&lt;br /&gt;
conference providing high quality educational sessions and networking&lt;br /&gt;
opportunities while working to identify developing trends in risk&lt;br /&gt;
management, physical security, governance, audit, information security,&lt;br /&gt;
contingency planning and human capital.&lt;br /&gt;
&lt;br /&gt;
=== DC612 meetings ===&lt;br /&gt;
DC612 meets the 2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&amp;lt;br /&amp;gt;&lt;br /&gt;
Secretary: [mailto:sam.buchanan@gmail.com Sam Buchanan]&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=55574</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=55574"/>
				<updated>2009-02-27T04:17:33Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: March meeting info&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&amp;lt;h3&amp;gt;March OWASP Meeting – Dan Cornell&amp;lt;br /&amp;gt;&lt;br /&gt;
Vulnerability Management in an Application Security World&amp;lt;/h3&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Monday March 16, 2009, 5:30 p.m.&lt;br /&gt;
&lt;br /&gt;
Identifying application-level vulnerabilities via penetration tests and code reviews is only the first step in actually addressing the underlying risk.  Managing vulnerabilities for applications is more challenging than dealing with traditional infrastructure-level vulnerabilities because they typically require the coordination of security teams with application development teams and require security managers to secure time from developers during already-cramped development and release schedules.  In addition, fixes require changes to custom application code and application-specific business logic rather than the patches and configuration changes that are often sufficient to address infrastructure-level vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
This presentation details many of the pitfalls organizations encounter while trying to manage application-level vulnerabilities as well as outlines strategies security teams can use for communicating with development teams.  Similarities and differences between security teams’ practice of vulnerability management and development teams’ practice of defect management will be addressed in order to facilitate healthy communication between these groups.&lt;br /&gt;
&lt;br /&gt;
=== Speaker Bio === &lt;br /&gt;
Dan Cornell has over ten years of experience architecting, developing and securing web-based software systems. As a Principal of Denim Group, he leads the organization's technology team overseeing methodology development and project execution for Denim Group's customers. He also heads the Denim Group application security research team, investigating the application of secure coding and development techniques to the improvement of web based software development methodologies. He is also the primary author of sprajax, Denim Group's open source tool for assessing the security of AJAX-enabled web applications. &lt;br /&gt;
&lt;br /&gt;
=== Where/When ===&lt;br /&gt;
Date: Monday March 16, 2009&amp;lt;br /&amp;gt;&lt;br /&gt;
Time: 5:30 p.m.&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Location:  MEC M.1600, (1st Floor of the Management Education Center)&lt;br /&gt;
&amp;lt;br /&amp;gt;Minneapolis Community and Technical College / Metro State University http://www.minneapolis.edu/campusmaps/&lt;br /&gt;
&lt;br /&gt;
Address: 1501 Hennepin Avenue, Minneapolis, MN 55403&amp;lt;br  /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Directions: http://www.minneapolis.edu/directions.cfm - The building entrance is at the corner of 13th St and Harmon Pl.&lt;br /&gt;
&lt;br /&gt;
=== Agenda ===&lt;br /&gt;
5:30 pm – Networking and optional sign-in for CISSP credits&amp;lt;br /&amp;gt;&lt;br /&gt;
6:00 pm - Introduction and Welcome: OWASP chapter updates&amp;lt;br /&amp;gt;&lt;br /&gt;
6:15 pm – Dan Cornell&amp;lt;br /&amp;gt;&lt;br /&gt;
8:00 pm - Upcoming Events reminder and meeting wrap-up&lt;br /&gt;
&lt;br /&gt;
====Thank you ===&lt;br /&gt;
&lt;br /&gt;
Center for Strategic Information Technology and Security for sponsoring our meeting location.&lt;br /&gt;
&lt;br /&gt;
We currently are looking for a meeting sponsor for refreshments for the meeting and for the book give-away.&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Thanks to all who joined us on October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
=== Most recent videos: ===&lt;br /&gt;
&lt;br /&gt;
Rick Ensenbach - Proactive Lifecycle Security Management - OWASP (MSP) - 16 February 2008 ([http://video.google.com/videoplay?docid=2838721966098123222&amp;amp;hl=en Part 1] of 2 - 35 minutes) ([http://video.google.com/videoplay?docid=1766766374336659744&amp;amp;hl=en Part 2] of 2 - 34 minutes) | [https://www.owasp.org/images/f/f8/Proactive_Lifecycle_Security_Management_Presentation_for_OWASP_Mpls-Stp_Chapter_Meeting_-_2-16-09.ppt Slides (PPT)] | [https://www.owasp.org/images/9/9c/Generic_System_Security_Plan.doc Handout: Service/System Security Plan template (DOC)]&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=1665928867290955158 Kuai Hinojosa - OWASP MN Mini Conference Introduction - 21 October 2008 (3 minutes)]&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
== Upcoming Events ==&lt;br /&gt;
=== Secure360 ===&lt;br /&gt;
[http://www.secure360.org/ Secure360] is an annual&lt;br /&gt;
conference providing high quality educational sessions and networking&lt;br /&gt;
opportunities while working to identify developing trends in risk&lt;br /&gt;
management, physical security, governance, audit, information security,&lt;br /&gt;
contingency planning and human capital.&lt;br /&gt;
&lt;br /&gt;
=== DC612 meetings ===&lt;br /&gt;
DC612 meets the 2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&amp;lt;br /&amp;gt;&lt;br /&gt;
Secretary: [mailto:sam.buchanan@gmail.com Sam Buchanan]&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=54553</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=54553"/>
				<updated>2009-02-17T05:18:11Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: added link to Secure360&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
=== February 16, 2008, 6:00 pm: Rick Eisenbach (UPDATE! NEW LOCATION: T-1000) ===&lt;br /&gt;
'''UPDATE! LOCATION FOR THIS MEETNG CHANGED TO:''' Minneapolis Community and Technical College '''T-1000'''. This is the gourmet dining room that we have used in the past on the main floor, by the large common eating area.&lt;br /&gt;
&lt;br /&gt;
''OLD LOCATION: Minneapolis Community and Technical College, room L3100''&lt;br /&gt;
&lt;br /&gt;
==== Proactive Lifecycle Security Management ====&lt;br /&gt;
Security Authorization Process Overview&lt;br /&gt;
&lt;br /&gt;
Security professionals are often faced with the daunting task of having to retrofit security controls into systems after it has already been put into production. The bad news is that this commonly occurs after sensitive or confidential information has been exposed as a result of a preventable system vulnerability, which often leads to public embarrassment, unnecessary litigation, regulatory fines, loss of customer confidence and numerous man-hours spent performing incident response and breach notification activities.&lt;br /&gt;
&lt;br /&gt;
Attend this session and learn how to ensure that security is addressed early in the system development/acquisition process by implementing a simple, scalable process that Federal agencies and the Department of Defense have practiced for years. You will also learn how this process can help with other regulatory and industry compliance requirements such as Payment Card Industry, Health Insurance Portability and Accountability Act, Sarbanes-Oxley and Gramm-Leach-Bliley.&lt;br /&gt;
&lt;br /&gt;
Mr. Ensenbach will also discuss available resources you can use and provide and example of a &amp;quot;System Security Plan&amp;quot; that you can immediately start using in your own organization and get you started on implementing your own security authorization process.&lt;br /&gt;
&lt;br /&gt;
This is a &amp;quot;must&amp;quot; attend session for all organizations that are required to comply with Federal Information Security Management Act (FISMA).&lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Mr. Ensenbach is an information security professional with over 25 years of experience in the field of information security.  Mr. Ensenbach has worked for a diverse range of organizations.  He has been responsible for creating the information security programs for the Air Force, 934th Airlift Wing - Air Force Reserve, Children's Hospitals and Clinics of Minnesota and Conseco Finance. He has also consulted independently and for several security consulting companies. He currently works in the State of Minnesota's Enterprise Security Office.&lt;br /&gt;
&lt;br /&gt;
Mr. Ensenbach's background includes information security risk management, security auditing and regulatory compliance assessments, policy/standards development, program development and strategic planning. He has an extensive knowledge of regulatory requirements (e.g. HIPAA, GLBA, FFIEC) and internationally accepted standards such as NIST, ISO17799/27001 and COBIT.&lt;br /&gt;
&lt;br /&gt;
==== Agenda ====&lt;br /&gt;
&lt;br /&gt;
Date: February 16, 2009&amp;lt;br /&amp;gt;&lt;br /&gt;
Time: 6:00 p.m.&amp;lt;br /&amp;gt;&lt;br /&gt;
Location:  '''UPDATE! LOCATION FOR THIS MEETNG CHANGED TO:''' Minneapolis Community and Technical College '''T-1000'''. This is the gourmet dining room that we have used in the past on the main floor, by the large common eating area. See '''building T''' on the campus map at http://www.minneapolis.edu/campusmaps/&amp;lt;br /&amp;gt;&lt;br /&gt;
Address: 1501 Hennepin Avenue, Minneapolis, MN 55403&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Old Location: L3100 (Third Floor of the Library Building, Wheelock Whitney Hall) Minneapolis Community and Technical College.''&lt;br /&gt;
&lt;br /&gt;
Directions: http://www.minneapolis.edu/directions.cfm&lt;br /&gt;
&lt;br /&gt;
5:30 pm - Networking&amp;lt;br /&amp;gt;&lt;br /&gt;
6:00pm - Introduction and optional sign-in for CISSP credits&amp;lt;br /&amp;gt;&lt;br /&gt;
6:10pm - Welcome: OWASP chapter updates, Conference Announcement!&amp;lt;br /&amp;gt;&lt;br /&gt;
6:30pm – Rick Ensenbach&amp;lt;br /&amp;gt;&lt;br /&gt;
8:80 pm - Upcoming Events reminder and meeting wrap-up&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Thank you ====&lt;br /&gt;
Center for Strategic Information Technology and Security for sponsor our location&lt;br /&gt;
&lt;br /&gt;
We currently are looking for a meeting sponsor for refreshments for the meeting and for the book give-away.&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Thanks to all who joined us on October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
=== Most recent videos: ===&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=1665928867290955158 Kuai Hinojosa - OWASP MN Mini Conference Introduction - 21 October 2008 (3 minutes)&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
== Upcoming Events ==&lt;br /&gt;
=== Secure360 ===&lt;br /&gt;
[http://www.secure360.org/ Secure360] is an annual&lt;br /&gt;
conference providing high quality educational sessions and networking&lt;br /&gt;
opportunities while working to identify developing trends in risk&lt;br /&gt;
management, physical security, governance, audit, information security,&lt;br /&gt;
contingency planning and human capital.&lt;br /&gt;
&lt;br /&gt;
=== DC612 meetings ===&lt;br /&gt;
DC612 meets the 2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&amp;lt;br /&amp;gt;&lt;br /&gt;
Secretary: [mailto:sam.buchanan@gmail.com Sam Buchanan]&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=54134</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=54134"/>
				<updated>2009-02-12T17:03:52Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: /* Upcoming Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
=== February 16, 2008, 6:00 pm: Rick Eisenbach ===&lt;br /&gt;
Minneapolis Community and Technical College, room L3100&lt;br /&gt;
&lt;br /&gt;
==== Proactive Lifecycle Security Management ====&lt;br /&gt;
Security Authorization Process Overview&lt;br /&gt;
&lt;br /&gt;
Security professionals are often faced with the daunting task of having to retrofit security controls into systems after it has already been put into production. The bad news is that this commonly occurs after sensitive or confidential information has been exposed as a result of a preventable system vulnerability, which often leads to public embarrassment, unnecessary litigation, regulatory fines, loss of customer confidence and numerous man-hours spent performing incident response and breach notification activities.&lt;br /&gt;
&lt;br /&gt;
Attend this session and learn how to ensure that security is addressed early in the system development/acquisition process by implementing a simple, scalable process that Federal agencies and the Department of Defense have practiced for years. You will also learn how this process can help with other regulatory and industry compliance requirements such as Payment Card Industry, Health Insurance Portability and Accountability Act, Sarbanes-Oxley and Gramm-Leach-Bliley.&lt;br /&gt;
&lt;br /&gt;
Mr. Ensenbach will also discuss available resources you can use and provide and example of a &amp;quot;System Security Plan&amp;quot; that you can immediately start using in your own organization and get you started on implementing your own security authorization process.&lt;br /&gt;
&lt;br /&gt;
This is a &amp;quot;must&amp;quot; attend session for all organizations that are required to comply with Federal Information Security Management Act (FISMA).&lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Mr. Ensenbach is an information security professional with over 25 years of experience in the field of information security.  Mr. Ensenbach has worked for a diverse range of organizations.  He has been responsible for creating the information security programs for the Air Force, 934th Airlift Wing - Air Force Reserve, Children's Hospitals and Clinics of Minnesota and Conseco Finance. He has also consulted independently and for several security consulting companies. He currently works in the State of Minnesota's Enterprise Security Office.&lt;br /&gt;
&lt;br /&gt;
Mr. Ensenbach's background includes information security risk management, security auditing and regulatory compliance assessments, policy/standards development, program development and strategic planning. He has an extensive knowledge of regulatory requirements (e.g. HIPAA, GLBA, FFIEC) and internationally accepted standards such as NIST, ISO17799/27001 and COBIT.&lt;br /&gt;
&lt;br /&gt;
==== Agenda ====&lt;br /&gt;
&lt;br /&gt;
Date: February , 2009&amp;lt;br /&amp;gt;&lt;br /&gt;
Time: 6:00 p.m.&amp;lt;br /&amp;gt;&lt;br /&gt;
Location:  L3100 (Third Floor of the Library Building, Wheelock Whitney Hall) Minneapolis Community and Technical College. See building L on the campus map http://www.minneapolis.edu/campusmaps/&amp;lt;br /&amp;gt;&lt;br /&gt;
Address: 1501 Hennepin Avenue, Minneapolis, MN 55403&amp;lt;br /&amp;gt;&lt;br /&gt;
Directions: http://www.minneapolis.edu/directions.cfm&lt;br /&gt;
&lt;br /&gt;
5:30 pm - Networking&amp;lt;br /&amp;gt;&lt;br /&gt;
6:00pm - Introduction and optional sign-in for CISSP credits&amp;lt;br /&amp;gt;&lt;br /&gt;
6:10pm - Welcome: OWASP chapter updates, Conference Announcement!&amp;lt;br /&amp;gt;&lt;br /&gt;
6:30pm – Rick Ensenbach&amp;lt;br /&amp;gt;&lt;br /&gt;
8:80 pm - Upcoming Events reminder and meeting wrap-up&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Thank you ====&lt;br /&gt;
Center for Strategic Information Technology and Security for sponsor our location&lt;br /&gt;
&lt;br /&gt;
We currently are looking for a meeting sponsor for refreshments for the meeting and for the book give-away.&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Thanks to all who joined us on October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
=== Most recent videos: ===&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=1665928867290955158 Kuai Hinojosa - OWASP MN Mini Conference Introduction - 21 October 2008 (3 minutes)&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;February 16 meeting, information above.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&amp;lt;br /&amp;gt;&lt;br /&gt;
Secretary: [mailto:sam.buchanan@gmail.com Sam Buchanan]&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=54133</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=54133"/>
				<updated>2009-02-12T16:54:02Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
We are starting to put together a list of speakers and events for this year. Stay tuned for more soon; there should be a meeting mid-February.&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Thanks to all who joined us on October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
=== Most recent videos: ===&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=1665928867290955158 Kuai Hinojosa - OWASP MN Mini Conference Introduction - 21 October 2008 (3 minutes)&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;February 16 meeting, information above.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&amp;lt;br /&amp;gt;&lt;br /&gt;
Secretary: [mailto:sam.buchanan@gmail.com Sam Buchanan]&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=51776</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=51776"/>
				<updated>2009-01-22T03:02:30Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: /* OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
We are starting to put together a list of speakers and events for this year. Stay tuned for more soon; there should be a meeting mid-February.&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Thanks to all who joined us on October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
=== Most recent videos: ===&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=1665928867290955158 Kuai Hinojosa - OWASP MN Mini Conference Introduction - 21 October 2008 (3 minutes)&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;There is likely to be a chapter meeting planned for November or December, but we haven't hammered out details yet. Stay tuned.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&amp;lt;br /&amp;gt;&lt;br /&gt;
Secretary: [mailto:sam.buchanan@gmail.com Sam Buchanan]&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=45106</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=45106"/>
				<updated>2008-10-30T02:44:05Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: embedded video in page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] were very pleased to bring together a line-up of internationally known speakers for a day of application security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center].&lt;br /&gt;
&lt;br /&gt;
Video of the presentations is slowly making its way to this page. Check the agenda below for links.&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ https://www.owasp.org/images/8/81/MN-center-strategic-it-security.gif]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.net/ http://www.go-integral.net/files/integral_logo.png]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
[http://www.symantec.com/ https://www.owasp.org/images/2/26/New_Symantec_Logo.jpg]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.symantec.com/ Symantec]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the [http://www.umn.edu/oit/ University of Minnesota Office of Information Technology]&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Kuai Hinojosa''' [http://video.google.com/videoplay?docid=1665928867290955158 Video]&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{#ev:googlevideo|1665928867290955158}}&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Jeff Williams'''&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you're tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, is establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Arshan Dabirsiaghi'''&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest. Sometimes that means pushing a browser to include a feature, or asking a language framework to provide a new API, or helping standard-makers come up with useable security protections. &lt;br /&gt;
&lt;br /&gt;
Our goal with the OWASP ISWG is to leverage the collective security know-how of OWASP into practical advice and suggestions for all those technologies that our applications lean on in one way or another. We've got the modest goal of fixing the Internet - what could be more valuable?&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Arshan Dabirsiaghi is the Director of Research at Aspect Security. Arshan has over seven of years of professional experience writing code, four years of professionally auditing code, and many years of hobbying in both. At Aspect Security, Arshan performs the normal array of security assurance work, including code reviews, architecture reviews and penetration testing. He spends the balance of his work time teaching classes all over the world and doing research into next generation web application attacks and defenses.&lt;br /&gt;
&lt;br /&gt;
Arshan earned his Master’s degree in Computer Science from Towson University with a focus on Information Security. He has delivered tutorials at Blackhat and OWASP conferences and has been a featured speaker at a number of security and artificial intelligence conferences. Arshan is also the author of the OWASP AntiSamy project and the founder of the OWASP Intrinsic Security Working Group.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Anil Kumar Revuru'''&lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Brian Chess'''&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Elliot Glazer'''&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Corey Benninger'''&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Richard Stallman'''&lt;br /&gt;
&lt;br /&gt;
Richard Matthew Stallman is a software developer and software freedom activist. In 1983 he announced the project to develop the GNU operating system, a Unix-like operating system meant to be entirely free software, and has been the project's leader ever since. With that announcement Stallman also launched the Free Software Movement. In October 1985 he started the Free Software Foundation.&lt;br /&gt;
&lt;br /&gt;
The GNU/Linux system, which is a variant of GNU that also uses the kernel Linux developed by Linus Torvalds, are used in tens or hundreds of millions of computers, and are now preinstalled in computers available in retail stores. However, the distributors of these systems often disregard the ideas of freedom which make free software important.&lt;br /&gt;
&lt;br /&gt;
That is why, since the mid-1990s, Stallman has spent most of his time in political advocacy for free software, and spreading the ethical ideas of the movement, as well as campaigning against both software patents and dangerous extension of copyright laws. Before that, Stallman developed a number of widely used software components of the GNU system, including the original Emacs, the GNU Compiler Collection, the GNU symbolic debugger (gdb), GNU Emacs, and various other programs for the GNU operating system.&lt;br /&gt;
&lt;br /&gt;
Stallman pioneered the concept of copyleft, and is the main author of the GNU General Public License, the most widely used free software license.&lt;br /&gt;
&lt;br /&gt;
Stallman gives speeches frequently about free software and related topics. Common speech titles include &amp;quot;The GNU Operating System and the Free Software movement&amp;quot;, &amp;quot;The Dangers of Software Patents&amp;quot;, and &amp;quot;Copyright and Community in the Age of the Computer Networks&amp;quot;. A fourth common topic consists of explaining the changes in version 3 of the GNU General Public License, which was released in June 2007. &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=44536</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=44536"/>
				<updated>2008-10-24T01:44:31Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: added link to Kuai's introduction&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Thanks to all who joined us on October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
=== Most recent videos: ===&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=1665928867290955158 Kuai Hinojosa - OWASP MN Mini Conference Introduction - 21 October 2008 (3 minutes)&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;There is likely to be a chapter meeting planned for November or December, but we haven't hammered out details yet. Stay tuned.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&amp;lt;br /&amp;gt;&lt;br /&gt;
Secretary: [mailto:sam.buchanan@gmail.com Sam Buchanan]&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=44535</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=44535"/>
				<updated>2008-10-24T01:42:35Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: added email address for Sam&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Thanks to all who joined us on October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;There is likely to be a chapter meeting planned for November or December, but we haven't hammered out details yet. Stay tuned.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&amp;lt;br /&amp;gt;&lt;br /&gt;
Secretary: [mailto:sam.buchanan@gmail.com Sam Buchanan]&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=44534</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=44534"/>
				<updated>2008-10-24T01:30:16Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: removed parking info&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] were very pleased to bring together a line-up of internationally known speakers for a day of application security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center].&lt;br /&gt;
&lt;br /&gt;
Video of the presentations is slowly making its way to this page. Check the agenda below for links.&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ https://www.owasp.org/images/8/81/MN-center-strategic-it-security.gif]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.net/ http://www.go-integral.net/files/integral_logo.png]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
[http://www.symantec.com/ https://www.owasp.org/images/2/26/New_Symantec_Logo.jpg]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.symantec.com/ Symantec]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the [http://www.umn.edu/oit/ University of Minnesota Office of Information Technology]&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Kuai Hinojosa''' [http://video.google.com/videoplay?docid=1665928867290955158 Video]&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Jeff Williams'''&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you're tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, is establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Arshan Dabirsiaghi'''&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest. Sometimes that means pushing a browser to include a feature, or asking a language framework to provide a new API, or helping standard-makers come up with useable security protections. &lt;br /&gt;
&lt;br /&gt;
Our goal with the OWASP ISWG is to leverage the collective security know-how of OWASP into practical advice and suggestions for all those technologies that our applications lean on in one way or another. We've got the modest goal of fixing the Internet - what could be more valuable?&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Arshan Dabirsiaghi is the Director of Research at Aspect Security. Arshan has over seven of years of professional experience writing code, four years of professionally auditing code, and many years of hobbying in both. At Aspect Security, Arshan performs the normal array of security assurance work, including code reviews, architecture reviews and penetration testing. He spends the balance of his work time teaching classes all over the world and doing research into next generation web application attacks and defenses.&lt;br /&gt;
&lt;br /&gt;
Arshan earned his Master’s degree in Computer Science from Towson University with a focus on Information Security. He has delivered tutorials at Blackhat and OWASP conferences and has been a featured speaker at a number of security and artificial intelligence conferences. Arshan is also the author of the OWASP AntiSamy project and the founder of the OWASP Intrinsic Security Working Group.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Anil Kumar Revuru'''&lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Brian Chess'''&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Elliot Glazer'''&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Corey Benninger'''&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Richard Stallman'''&lt;br /&gt;
&lt;br /&gt;
Richard Matthew Stallman is a software developer and software freedom activist. In 1983 he announced the project to develop the GNU operating system, a Unix-like operating system meant to be entirely free software, and has been the project's leader ever since. With that announcement Stallman also launched the Free Software Movement. In October 1985 he started the Free Software Foundation.&lt;br /&gt;
&lt;br /&gt;
The GNU/Linux system, which is a variant of GNU that also uses the kernel Linux developed by Linus Torvalds, are used in tens or hundreds of millions of computers, and are now preinstalled in computers available in retail stores. However, the distributors of these systems often disregard the ideas of freedom which make free software important.&lt;br /&gt;
&lt;br /&gt;
That is why, since the mid-1990s, Stallman has spent most of his time in political advocacy for free software, and spreading the ethical ideas of the movement, as well as campaigning against both software patents and dangerous extension of copyright laws. Before that, Stallman developed a number of widely used software components of the GNU system, including the original Emacs, the GNU Compiler Collection, the GNU symbolic debugger (gdb), GNU Emacs, and various other programs for the GNU operating system.&lt;br /&gt;
&lt;br /&gt;
Stallman pioneered the concept of copyleft, and is the main author of the GNU General Public License, the most widely used free software license.&lt;br /&gt;
&lt;br /&gt;
Stallman gives speeches frequently about free software and related topics. Common speech titles include &amp;quot;The GNU Operating System and the Free Software movement&amp;quot;, &amp;quot;The Dangers of Software Patents&amp;quot;, and &amp;quot;Copyright and Community in the Age of the Computer Networks&amp;quot;. A fourth common topic consists of explaining the changes in version 3 of the GNU General Public License, which was released in June 2007. &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=44533</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=44533"/>
				<updated>2008-10-24T01:28:32Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: Removed &amp;quot;Tentative&amp;quot; from &amp;quot;Tentative Agenda&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] were very pleased to bring together a line-up of internationally known speakers for a day of application security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center].&lt;br /&gt;
&lt;br /&gt;
Video of the presentations is slowly making its way to this page. Check the agenda below for links.&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ https://www.owasp.org/images/8/81/MN-center-strategic-it-security.gif]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.net/ http://www.go-integral.net/files/integral_logo.png]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
[http://www.symantec.com/ https://www.owasp.org/images/2/26/New_Symantec_Logo.jpg]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.symantec.com/ Symantec]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the [http://www.umn.edu/oit/ University of Minnesota Office of Information Technology]&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Kuai Hinojosa''' [http://video.google.com/videoplay?docid=1665928867290955158 Video]&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Jeff Williams'''&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you're tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, is establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Arshan Dabirsiaghi'''&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest. Sometimes that means pushing a browser to include a feature, or asking a language framework to provide a new API, or helping standard-makers come up with useable security protections. &lt;br /&gt;
&lt;br /&gt;
Our goal with the OWASP ISWG is to leverage the collective security know-how of OWASP into practical advice and suggestions for all those technologies that our applications lean on in one way or another. We've got the modest goal of fixing the Internet - what could be more valuable?&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Arshan Dabirsiaghi is the Director of Research at Aspect Security. Arshan has over seven of years of professional experience writing code, four years of professionally auditing code, and many years of hobbying in both. At Aspect Security, Arshan performs the normal array of security assurance work, including code reviews, architecture reviews and penetration testing. He spends the balance of his work time teaching classes all over the world and doing research into next generation web application attacks and defenses.&lt;br /&gt;
&lt;br /&gt;
Arshan earned his Master’s degree in Computer Science from Towson University with a focus on Information Security. He has delivered tutorials at Blackhat and OWASP conferences and has been a featured speaker at a number of security and artificial intelligence conferences. Arshan is also the author of the OWASP AntiSamy project and the founder of the OWASP Intrinsic Security Working Group.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Anil Kumar Revuru'''&lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Brian Chess'''&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Elliot Glazer'''&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Corey Benninger'''&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Richard Stallman'''&lt;br /&gt;
&lt;br /&gt;
Richard Matthew Stallman is a software developer and software freedom activist. In 1983 he announced the project to develop the GNU operating system, a Unix-like operating system meant to be entirely free software, and has been the project's leader ever since. With that announcement Stallman also launched the Free Software Movement. In October 1985 he started the Free Software Foundation.&lt;br /&gt;
&lt;br /&gt;
The GNU/Linux system, which is a variant of GNU that also uses the kernel Linux developed by Linus Torvalds, are used in tens or hundreds of millions of computers, and are now preinstalled in computers available in retail stores. However, the distributors of these systems often disregard the ideas of freedom which make free software important.&lt;br /&gt;
&lt;br /&gt;
That is why, since the mid-1990s, Stallman has spent most of his time in political advocacy for free software, and spreading the ethical ideas of the movement, as well as campaigning against both software patents and dangerous extension of copyright laws. Before that, Stallman developed a number of widely used software components of the GNU system, including the original Emacs, the GNU Compiler Collection, the GNU symbolic debugger (gdb), GNU Emacs, and various other programs for the GNU operating system.&lt;br /&gt;
&lt;br /&gt;
Stallman pioneered the concept of copyleft, and is the main author of the GNU General Public License, the most widely used free software license.&lt;br /&gt;
&lt;br /&gt;
Stallman gives speeches frequently about free software and related topics. Common speech titles include &amp;quot;The GNU Operating System and the Free Software movement&amp;quot;, &amp;quot;The Dangers of Software Patents&amp;quot;, and &amp;quot;Copyright and Community in the Age of the Computer Networks&amp;quot;. A fourth common topic consists of explaining the changes in version 3 of the GNU General Public License, which was released in June 2007. &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking and Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=44532</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=44532"/>
				<updated>2008-10-24T01:27:50Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: Made the intro more past-tense, mentioned videos (thanks, Adam!)&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] were very pleased to bring together a line-up of internationally known speakers for a day of application security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center].&lt;br /&gt;
&lt;br /&gt;
Video of the presentations is slowly making its way to this page. Check the agenda below for links.&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ https://www.owasp.org/images/8/81/MN-center-strategic-it-security.gif]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.net/ http://www.go-integral.net/files/integral_logo.png]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
[http://www.symantec.com/ https://www.owasp.org/images/2/26/New_Symantec_Logo.jpg]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.symantec.com/ Symantec]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the [http://www.umn.edu/oit/ University of Minnesota Office of Information Technology]&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Kuai Hinojosa''' [http://video.google.com/videoplay?docid=1665928867290955158 Video]&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Jeff Williams'''&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you're tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, is establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Arshan Dabirsiaghi'''&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest. Sometimes that means pushing a browser to include a feature, or asking a language framework to provide a new API, or helping standard-makers come up with useable security protections. &lt;br /&gt;
&lt;br /&gt;
Our goal with the OWASP ISWG is to leverage the collective security know-how of OWASP into practical advice and suggestions for all those technologies that our applications lean on in one way or another. We've got the modest goal of fixing the Internet - what could be more valuable?&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Arshan Dabirsiaghi is the Director of Research at Aspect Security. Arshan has over seven of years of professional experience writing code, four years of professionally auditing code, and many years of hobbying in both. At Aspect Security, Arshan performs the normal array of security assurance work, including code reviews, architecture reviews and penetration testing. He spends the balance of his work time teaching classes all over the world and doing research into next generation web application attacks and defenses.&lt;br /&gt;
&lt;br /&gt;
Arshan earned his Master’s degree in Computer Science from Towson University with a focus on Information Security. He has delivered tutorials at Blackhat and OWASP conferences and has been a featured speaker at a number of security and artificial intelligence conferences. Arshan is also the author of the OWASP AntiSamy project and the founder of the OWASP Intrinsic Security Working Group.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Anil Kumar Revuru'''&lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Brian Chess'''&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Elliot Glazer'''&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Corey Benninger'''&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Richard Stallman'''&lt;br /&gt;
&lt;br /&gt;
Richard Matthew Stallman is a software developer and software freedom activist. In 1983 he announced the project to develop the GNU operating system, a Unix-like operating system meant to be entirely free software, and has been the project's leader ever since. With that announcement Stallman also launched the Free Software Movement. In October 1985 he started the Free Software Foundation.&lt;br /&gt;
&lt;br /&gt;
The GNU/Linux system, which is a variant of GNU that also uses the kernel Linux developed by Linus Torvalds, are used in tens or hundreds of millions of computers, and are now preinstalled in computers available in retail stores. However, the distributors of these systems often disregard the ideas of freedom which make free software important.&lt;br /&gt;
&lt;br /&gt;
That is why, since the mid-1990s, Stallman has spent most of his time in political advocacy for free software, and spreading the ethical ideas of the movement, as well as campaigning against both software patents and dangerous extension of copyright laws. Before that, Stallman developed a number of widely used software components of the GNU system, including the original Emacs, the GNU Compiler Collection, the GNU symbolic debugger (gdb), GNU Emacs, and various other programs for the GNU operating system.&lt;br /&gt;
&lt;br /&gt;
Stallman pioneered the concept of copyleft, and is the main author of the GNU General Public License, the most widely used free software license.&lt;br /&gt;
&lt;br /&gt;
Stallman gives speeches frequently about free software and related topics. Common speech titles include &amp;quot;The GNU Operating System and the Free Software movement&amp;quot;, &amp;quot;The Dangers of Software Patents&amp;quot;, and &amp;quot;Copyright and Community in the Age of the Computer Networks&amp;quot;. A fourth common topic consists of explaining the changes in version 3 of the GNU General Public License, which was released in June 2007. &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking and Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=44529</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=44529"/>
				<updated>2008-10-23T21:51:48Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: Removed conference notice.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Thanks to all who joined us on October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;There is likely to be a chapter meeting planned for November or December, but we haven't hammered out details yet. Stay tuned.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&amp;lt;br /&amp;gt;&lt;br /&gt;
Secretary: Sam Buchanan&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=44528</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=44528"/>
				<updated>2008-10-23T21:23:23Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: Changed conference blurb from an announcement to a thank you.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Thanks to all who joined us on October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. Our first conference was a great success, with around 150 people attending! We look forward to the next one.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&amp;lt;br /&amp;gt;&lt;br /&gt;
Secretary: Sam Buchanan&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=44354</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=44354"/>
				<updated>2008-10-22T02:23:39Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: removed registration link, since, well, the conference is over.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] invites you to attend the first ever Minnesota OWASP Conference on October 21st.&lt;br /&gt;
&lt;br /&gt;
We're very excited out the line up of internationally known speakers we were able to bring together for this one day of Application Security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center] ([[#Parking and Transportation|parking and transportation]] information below). There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event -- and we need to have a reasonably accurate lunch count -- so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat (and lunch!).&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis conference&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ https://www.owasp.org/images/8/81/MN-center-strategic-it-security.gif]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.net/ http://www.go-integral.net/files/integral_logo.png]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
[http://www.symantec.com/ https://www.owasp.org/images/2/26/New_Symantec_Logo.jpg]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.go-integral.com/ Symantec]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the [http://www.umn.edu/oit/ University of Minnesota Office of Information Technology]&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Kuai Hinojosa'''&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Jeff Williams'''&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you're tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, is establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Arshan Dabirsiaghi'''&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest. Sometimes that means pushing a browser to include a feature, or asking a language framework to provide a new API, or helping standard-makers come up with useable security protections. &lt;br /&gt;
&lt;br /&gt;
Our goal with the OWASP ISWG is to leverage the collective security know-how of OWASP into practical advice and suggestions for all those technologies that our applications lean on in one way or another. We've got the modest goal of fixing the Internet - what could be more valuable?&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Arshan Dabirsiaghi is the Director of Research at Aspect Security. Arshan has over seven of years of professional experience writing code, four years of professionally auditing code, and many years of hobbying in both. At Aspect Security, Arshan performs the normal array of security assurance work, including code reviews, architecture reviews and penetration testing. He spends the balance of his work time teaching classes all over the world and doing research into next generation web application attacks and defenses.&lt;br /&gt;
&lt;br /&gt;
Arshan earned his Master’s degree in Computer Science from Towson University with a focus on Information Security. He has delivered tutorials at Blackhat and OWASP conferences and has been a featured speaker at a number of security and artificial intelligence conferences. Arshan is also the author of the OWASP AntiSamy project and the founder of the OWASP Intrinsic Security Working Group.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Anil Kumar Revuru'''&lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Brian Chess'''&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Elliot Glazer'''&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Corey Benninger'''&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Richard Stallman'''&lt;br /&gt;
&lt;br /&gt;
Richard Matthew Stallman is a software developer and software freedom activist. In 1983 he announced the project to develop the GNU operating system, a Unix-like operating system meant to be entirely free software, and has been the project's leader ever since. With that announcement Stallman also launched the Free Software Movement. In October 1985 he started the Free Software Foundation.&lt;br /&gt;
&lt;br /&gt;
The GNU/Linux system, which is a variant of GNU that also uses the kernel Linux developed by Linus Torvalds, are used in tens or hundreds of millions of computers, and are now preinstalled in computers available in retail stores. However, the distributors of these systems often disregard the ideas of freedom which make free software important.&lt;br /&gt;
&lt;br /&gt;
That is why, since the mid-1990s, Stallman has spent most of his time in political advocacy for free software, and spreading the ethical ideas of the movement, as well as campaigning against both software patents and dangerous extension of copyright laws. Before that, Stallman developed a number of widely used software components of the GNU system, including the original Emacs, the GNU Compiler Collection, the GNU symbolic debugger (gdb), GNU Emacs, and various other programs for the GNU operating system.&lt;br /&gt;
&lt;br /&gt;
Stallman pioneered the concept of copyleft, and is the main author of the GNU General Public License, the most widely used free software license.&lt;br /&gt;
&lt;br /&gt;
Stallman gives speeches frequently about free software and related topics. Common speech titles include &amp;quot;The GNU Operating System and the Free Software movement&amp;quot;, &amp;quot;The Dangers of Software Patents&amp;quot;, and &amp;quot;Copyright and Community in the Age of the Computer Networks&amp;quot;. A fourth common topic consists of explaining the changes in version 3 of the GNU General Public License, which was released in June 2007. &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking and Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=43371</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=43371"/>
				<updated>2008-10-15T03:43:03Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: added note about lunch.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] invites you to attend the first ever Minnesota OWASP Conference on October 21st.&lt;br /&gt;
&lt;br /&gt;
We're very excited out the line up of internationally known speakers we were able to bring together for this one day of Application Security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center] ([[#Parking and Transportation|parking and transportation]] information below). There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event -- and we need to have a reasonably accurate lunch count -- so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat (and lunch!).&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ https://www.owasp.org/images/8/81/MN-center-strategic-it-security.gif]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.net/ http://www.go-integral.net/files/integral_logo.png]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the [http://www.umn.edu/oit/ University of Minnesota Office of Information Technology]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Kuai Hinojosa'''&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Jeff Williams'''&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you're tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, is establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Arshan Dabirsiaghi'''&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest. Sometimes that means pushing a browser to include a feature, or asking a language framework to provide a new API, or helping standard-makers come up with useable security protections. &lt;br /&gt;
&lt;br /&gt;
Our goal with the OWASP ISWG is to leverage the collective security know-how of OWASP into practical advice and suggestions for all those technologies that our applications lean on in one way or another. We've got the modest goal of fixing the Internet - what could be more valuable?&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Arshan Dabirsiaghi is the Director of Research at Aspect Security. Arshan has over seven of years of professional experience writing code, four years of professionally auditing code, and many years of hobbying in both. At Aspect Security, Arshan performs the normal array of security assurance work, including code reviews, architecture reviews and penetration testing. He spends the balance of his work time teaching classes all over the world and doing research into next generation web application attacks and defenses.&lt;br /&gt;
&lt;br /&gt;
Arshan earned his Master’s degree in Computer Science from Towson University with a focus on Information Security. He has delivered tutorials at Blackhat and OWASP conferences and has been a featured speaker at a number of security and artificial intelligence conferences. Arshan is also the author of the OWASP AntiSamy project and the founder of the OWASP Intrinsic Security Working Group.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Anil Kumar Revuru'''&lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Brian Chess'''&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Elliot Glazer'''&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Corey Benninger'''&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Richard Stallman'''&lt;br /&gt;
&lt;br /&gt;
Richard Matthew Stallman is a software developer and software freedom activist. In 1983 he announced the project to develop the GNU operating system, a Unix-like operating system meant to be entirely free software, and has been the project's leader ever since. With that announcement Stallman also launched the Free Software Movement. In October 1985 he started the Free Software Foundation.&lt;br /&gt;
&lt;br /&gt;
The GNU/Linux system, which is a variant of GNU that also uses the kernel Linux developed by Linus Torvalds, are used in tens or hundreds of millions of computers, and are now preinstalled in computers available in retail stores. However, the distributors of these systems often disregard the ideas of freedom which make free software important.&lt;br /&gt;
&lt;br /&gt;
That is why, since the mid-1990s, Stallman has spent most of his time in political advocacy for free software, and spreading the ethical ideas of the movement, as well as campaigning against both software patents and dangerous extension of copyright laws. Before that, Stallman developed a number of widely used software components of the GNU system, including the original Emacs, the GNU Compiler Collection, the GNU symbolic debugger (gdb), GNU Emacs, and various other programs for the GNU operating system.&lt;br /&gt;
&lt;br /&gt;
Stallman pioneered the concept of copyleft, and is the main author of the GNU General Public License, the most widely used free software license.&lt;br /&gt;
&lt;br /&gt;
Stallman gives speeches frequently about free software and related topics. Common speech titles include &amp;quot;The GNU Operating System and the Free Software movement&amp;quot;, &amp;quot;The Dangers of Software Patents&amp;quot;, and &amp;quot;Copyright and Community in the Age of the Computer Networks&amp;quot;. A fourth common topic consists of explaining the changes in version 3 of the GNU General Public License, which was released in June 2007. &amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking and Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=42913</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=42913"/>
				<updated>2008-10-10T21:39:42Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: added board members list&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We are very excited about the participation of internationally known speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Corey Benninger''' from the Intrepidus Group. &lt;br /&gt;
&lt;br /&gt;
There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event, so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat.&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Minneapolis - Saint Paul OWASP Board Members ==&lt;br /&gt;
President: [mailto:kuai.hinojosa(at)gmail.com Kuai Hinojosa]&amp;lt;br /&amp;gt;&lt;br /&gt;
Vice President: [mailto:lorna.alamri(at)owasp.org Lorna Alamri]&amp;lt;br /&amp;gt;&lt;br /&gt;
Secretary: Sam Buchanan&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42687</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42687"/>
				<updated>2008-10-09T02:48:04Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: moved thank you section, added logos&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] invites you to attend the first ever Minnesota OWASP Conference on October 21st.&lt;br /&gt;
&lt;br /&gt;
We're very excited out the line up of internationally known speakers we were able to bring together for this one day of Application Security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center] ([[#Parking and Transportation|parking and transportation]] information below). There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event, so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat.&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ https://www.owasp.org/images/8/81/MN-center-strategic-it-security.gif]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.net/ http://www.go-integral.net/files/integral_logo.png]&amp;lt;br /&amp;gt;&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the [http://www.umn.edu/oit/ University of Minnesota Office of Information Technology]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Kuai Hinojosa'''&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Jeff Williams'''&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you're tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, is establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Arshan Dabirsiaghi'''&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest. Sometimes that means pushing a browser to include a feature, or asking a language framework to provide a new API, or helping standard-makers come up with useable security protections. &lt;br /&gt;
&lt;br /&gt;
Our goal with the OWASP ISWG is to leverage the collective security know-how of OWASP into practical advice and suggestions for all those technologies that our applications lean on in one way or another. We've got the modest goal of fixing the Internet - what could be more valuable?&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Arshan Dabirsiaghi is the Director of Research at Aspect Security. Arshan has over seven of years of professional experience writing code, four years of professionally auditing code, and many years of hobbying in both. At Aspect Security, Arshan performs the normal array of security assurance work, including code reviews, architecture reviews and penetration testing. He spends the balance of his work time teaching classes all over the world and doing research into next generation web application attacks and defenses.&lt;br /&gt;
&lt;br /&gt;
Arshan earned his Master’s degree in Computer Science from Towson University with a focus on Information Security. He has delivered tutorials at Blackhat and OWASP conferences and has been a featured speaker at a number of security and artificial intelligence conferences. Arshan is also the author of the OWASP AntiSamy project and the founder of the OWASP Intrinsic Security Working Group.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Anil Kumar Revuru'''&lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Brian Chess'''&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Elliot Glazer'''&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Corey Benninger'''&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Richard Stallman'''&lt;br /&gt;
&lt;br /&gt;
Richard Stallman is the founder of the GNU Project, launched in 1984 to develop the free operating system, GNU.&lt;br /&gt;
&lt;br /&gt;
Richard Stallman is the principal author of the GNU C Compiler, the GNU symbolic debugger (GDB), GNU Emacs, and various other GNU programs. Stallman currently serves as president of the Free Software Foundation.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking and Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42537</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42537"/>
				<updated>2008-10-08T02:22:56Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: /* Tentative Agenda */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] invites you to attend the first ever Minnesota OWASP Conference on October 21st.&lt;br /&gt;
&lt;br /&gt;
We're very excited out the line up of internationally known speakers we were able to bring together for this one day of Application Security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center] ([[#Parking and Transportation|parking and transportation]] information below). There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event, so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat.&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Kuai Hinojosa'''&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Jeff Williams'''&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you're tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, is establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Arshan Dabirsiaghi'''&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest. Sometimes that means pushing a browser to include a feature, or asking a language framework to provide a new API, or helping standard-makers come up with useable security protections. &lt;br /&gt;
&lt;br /&gt;
Our goal with the OWASP ISWG is to leverage the collective security know-how of OWASP into practical advice and suggestions for all those technologies that our applications lean on in one way or another. We've got the modest goal of fixing the Internet - what could be more valuable?&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Arshan Dabirsiaghi is the Director of Research at Aspect Security. Arshan has over seven of years of professional experience writing code, four years of professionally auditing code, and many years of hobbying in both. At Aspect Security, Arshan performs the normal array of security assurance work, including code reviews, architecture reviews and penetration testing. He spends the balance of his work time teaching classes all over the world and doing research into next generation web application attacks and defenses.&lt;br /&gt;
&lt;br /&gt;
Arshan earned his Master’s degree in Computer Science from Towson University with a focus on Information Security. He has delivered tutorials at Blackhat and OWASP conferences and has been a featured speaker at a number of security and artificial intelligence conferences. Arshan is also the author of the OWASP AntiSamy project and the founder of the OWASP Intrinsic Security Working Group.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Anil Kumar Revuru'''&lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Brian Chess'''&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Elliot Glazer'''&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Corey Benninger'''&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Richard Stallman'''&lt;br /&gt;
&lt;br /&gt;
Richard Stallman is the founder of the GNU Project, launched in 1984 to develop the free operating system, GNU.&lt;br /&gt;
&lt;br /&gt;
Richard Stallman is the principal author of the GNU C Compiler, the GNU symbolic debugger (GDB), GNU Emacs, and various other GNU programs. Stallman currently serves as president of the Free Software Foundation.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking and Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the University of Minnesota Office of Information Technology [http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=42534</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=42534"/>
				<updated>2008-10-08T02:10:37Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: fixed a name. oops!&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We are very excited about the participation of internationally known speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Corey Benninger''' from the Intrepidus Group. &lt;br /&gt;
&lt;br /&gt;
There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event, so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat.&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42533</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42533"/>
				<updated>2008-10-08T01:54:53Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: Stallman bio&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] invites you to attend the first ever Minnesota OWASP Conference on October 21st.&lt;br /&gt;
&lt;br /&gt;
We're very excited out the line up of internationally known speakers we were able to bring together for this one day of Application Security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center] ([[#Parking and Transportation|parking and transportation]] information below). There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event, so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat.&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Kuai Hinojosa'''&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Jeff Williams'''&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you?re tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Arshan Dabirsiaghi'''&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest. Sometimes that means pushing a browser to include a feature, or asking a language framework to provide a new API, or helping standard-makers come up with useable security protections. &lt;br /&gt;
&lt;br /&gt;
Our goal with the OWASP ISWG is to leverage the collective security know-how of OWASP into practical advice and suggestions for all those technologies that our applications lean on in one way or another. We've got the modest goal of fixing the Internet - what could be more valuable?&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Arshan Dabirsiaghi is the Director of Research at Aspect Security. Arshan has over seven of years of professional experience writing code, four years of professionally auditing code, and many years of hobbying in both. At Aspect Security, Arshan performs the normal array of security assurance work, including code reviews, architecture reviews and penetration testing. He spends the balance of his work time teaching classes all over the world and doing research into next generation web application attacks and defenses.&lt;br /&gt;
&lt;br /&gt;
Arshan earned his Master’s degree in Computer Science from Towson University with a focus on Information Security. He has delivered tutorials at Blackhat and OWASP conferences and has been a featured speaker at a number of security and artificial intelligence conferences. Arshan is also the author of the OWASP AntiSamy project and the founder of the OWASP Intrinsic Security Working Group.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Anil Kumar Revuru'''&lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;'''Brian Chess'''&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Elliot Glazer'''&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Corey Benninger'''&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
'''Richard Stallman'''&lt;br /&gt;
&lt;br /&gt;
Richard Stallman is the founder of the GNU Project, launched in 1984 to develop the free operating system, GNU.&lt;br /&gt;
&lt;br /&gt;
Richard Stallman is the principal author of the GNU C Compiler, the GNU symbolic debugger (GDB), GNU Emacs, and various other GNU programs. Stallman currently serves as president of the Free Software Foundation.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking and Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the University of Minnesota Office of Information Technology [http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=42532</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=42532"/>
				<updated>2008-10-08T01:49:06Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: new paragraph about the conference&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We are very excited about the participation of internationally known speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Rohyt Belani''' from the Intrepidus Group. &lt;br /&gt;
&lt;br /&gt;
There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event, so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat.&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42531</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42531"/>
				<updated>2008-10-08T01:42:03Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: lightened table background colors&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] invites you to attend the first ever Minnesota OWASP Conference on October 21st.&lt;br /&gt;
&lt;br /&gt;
We're very excited out the line up of internationally known speakers we were able to bring together for this one day of Application Security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center] ([[#Parking and Transportation|parking and transportation]] information below). There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event, so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat.&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;Kuai Hinojosa&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Jeff Williams&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you?re tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#AEB7D5; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#D5B4AE; padding: 5px;&amp;quot;&amp;gt;Arshan Dabirsiaghi&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest. Sometimes that means pushing a browser to include a feature, or asking a language framework to provide a new API, or helping standard-makers come up with useable security protections. &lt;br /&gt;
&lt;br /&gt;
Our goal with the OWASP ISWG is to leverage the collective security know-how of OWASP into practical advice and suggestions for all those technologies that our applications lean on in one way or another. We've got the modest goal of fixing the Internet - what could be more valuable?&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Arshan Dabirsiaghi is the Director of Research at Aspect Security. Arshan has over seven of years of professional experience writing code, four years of professionally auditing code, and many years of hobbying in both. At Aspect Security, Arshan performs the normal array of security assurance work, including code reviews, architecture reviews and penetration testing. He spends the balance of his work time teaching classes all over the world and doing research into next generation web application attacks and defenses.&lt;br /&gt;
&lt;br /&gt;
Arshan earned his Master’s degree in Computer Science from Towson University with a focus on Information Security. He has delivered tutorials at Blackhat and OWASP conferences and has been a featured speaker at a number of security and artificial intelligence conferences. Arshan is also the author of the OWASP AntiSamy project and the founder of the OWASP Intrinsic Security Working Group.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Anil Kumar Revuru &lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;Brian Chess&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Elliot Glazer&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Corey Benninger&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #AEB7D5; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #D5B4AE; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Richard Stallman&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking and Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the University of Minnesota Office of Information Technology [http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42530</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42530"/>
				<updated>2008-10-08T01:37:20Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: Bio for Arshan Dabirsiaghi and expanded session description&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] invites you to attend the first ever Minnesota OWASP Conference on October 21st.&lt;br /&gt;
&lt;br /&gt;
We're very excited out the line up of internationally known speakers we were able to bring together for this one day of Application Security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center] ([[#Parking and Transportation|parking and transportation]] information below). There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event, so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat.&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Kuai Hinojosa&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Jeff Williams&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you?re tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Arshan Dabirsiaghi&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest. Sometimes that means pushing a browser to include a feature, or asking a language framework to provide a new API, or helping standard-makers come up with useable security protections. &lt;br /&gt;
&lt;br /&gt;
Our goal with the OWASP ISWG is to leverage the collective security know-how of OWASP into practical advice and suggestions for all those technologies that our applications lean on in one way or another. We've got the modest goal of fixing the Internet - what could be more valuable?&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Arshan Dabirsiaghi is the Director of Research at Aspect Security. Arshan has over seven of years of professional experience writing code, four years of professionally auditing code, and many years of hobbying in both. At Aspect Security, Arshan performs the normal array of security assurance work, including code reviews, architecture reviews and penetration testing. He spends the balance of his work time teaching classes all over the world and doing research into next generation web application attacks and defenses.&lt;br /&gt;
&lt;br /&gt;
Arshan earned his Master’s degree in Computer Science from Towson University with a focus on Information Security. He has delivered tutorials at Blackhat and OWASP conferences and has been a featured speaker at a number of security and artificial intelligence conferences. Arshan is also the author of the OWASP AntiSamy project and the founder of the OWASP Intrinsic Security Working Group.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Anil Kumar Revuru &lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;Brian Chess&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Elliot Glazer&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Corey Benninger&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Richard Stallman&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking and Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the University of Minnesota Office of Information Technology [http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42509</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42509"/>
				<updated>2008-10-07T18:37:03Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: /* OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] invites you to attend the first ever Minnesota OWASP Conference on October 21st.&lt;br /&gt;
&lt;br /&gt;
We're very excited out the line up of internationally known speakers we were able to bring together for this one day of Application Security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center] ([[#Parking and Transportation|parking and transportation]] information below). There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event, so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat.&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Kuai Hinojosa&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Jeff Williams&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you?re tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Arshan Dabirsiaghi&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Anil Kumar Revuru &lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;Brian Chess&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Elliot Glazer&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Corey Benninger&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Richard Stallman&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking and Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the University of Minnesota Office of Information Technology [http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42508</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42508"/>
				<updated>2008-10-07T18:36:06Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: /* OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] invites you to attend the first ever Minnesota OWASP Conference on October 21st.&lt;br /&gt;
&lt;br /&gt;
We're very excited out the line up of internationally known speakers we were able to bring together for this one day of Application Security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center] ([[#Parking and Transportation]] information below). There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event, so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat.&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Kuai Hinojosa&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Jeff Williams&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you?re tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Arshan Dabirsiaghi&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Anil Kumar Revuru &lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;Brian Chess&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Elliot Glazer&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Corey Benninger&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Richard Stallman&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking and Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the University of Minnesota Office of Information Technology [http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42507</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42507"/>
				<updated>2008-10-07T18:35:06Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: change ampersand to &amp;quot;and&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] invites you to attend the first ever Minnesota OWASP Conference on October 21st.&lt;br /&gt;
&lt;br /&gt;
We're very excited out the line up of internationally known speakers we were able to bring together for this one day of Application Security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center]. There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event, so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat.&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Kuai Hinojosa&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Jeff Williams&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you?re tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Arshan Dabirsiaghi&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Anil Kumar Revuru &lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;Brian Chess&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Elliot Glazer&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Corey Benninger&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Richard Stallman&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking and Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the University of Minnesota Office of Information Technology [http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42506</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42506"/>
				<updated>2008-10-07T18:32:07Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: updated agenda with new times and a small reorg of content&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] invites you to attend the first ever Minnesota OWASP Conference on October 21st.&lt;br /&gt;
&lt;br /&gt;
We're very excited out the line up of internationally known speakers we were able to bring together for this one day of Application Security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center]. There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event, so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat.&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;8:00-9:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Registration / Check-In&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;9:00-9:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Kuai Hinojosa&amp;lt;br /&amp;gt;OWASP MN President&amp;lt;br /&amp;gt;Conference Introduction&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;9:30-10:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Jeff Williams&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you?re tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, establishing your organization's ESAPI is one of the best things you can do?&lt;br /&gt;
&lt;br /&gt;
'''Bio''':&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;10:30-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Arshan Dabirsiaghi&amp;lt;br /&amp;gt;Director of Research, [http://www.aspectsecurity.com/ Aspect Security]&lt;br /&gt;
&lt;br /&gt;
Many of the challenges we face in application security could be solved at an architectural layer without trying to accomplish the impossible task of fixing millions of websites with billions of lines of code behind them. The OWASP [[Intrinsic Security Working Group]] is a new OWASP effort focused on addressing root causes of application security problems and fixing them where it's easiest.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Lunch&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Anil Kumar Revuru &lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsoft]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools: &amp;lt;br /&amp;gt;&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': &lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;1:30-2:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;Brian Chess&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&amp;lt;br&amp;gt;&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;2:30-3:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;3:00-4:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Elliot Glazer&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes:&lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;4:00-5:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Corey Benninger&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research.&lt;br /&gt;
&lt;br /&gt;
'''Bio''': Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
5:00-5:15&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Richard Stallman&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking &amp;amp; Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the University of Minnesota Office of Information Technology [http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42505</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=42505"/>
				<updated>2008-10-07T18:14:49Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: improved intro paragraph&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The [[Minneapolis St Paul|Minneapolis - Saint Paul Chapter]] invites you to attend the first ever Minnesota OWASP Conference on October 21st.&lt;br /&gt;
&lt;br /&gt;
We're very excited out the line up of internationally known speakers we were able to bring together for this one day of Application Security talks at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center]. There is a nominal fee of $25.00 per person, which includes lunch. Seating is limited and we expect this event to sell out. '''On site registration is not expected''' to be available the day of the event, so please [http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 register] prior to the event to guarantee your seat.&lt;br /&gt;
&lt;br /&gt;
[http://guest.cvent.com/i.aspx?4W,M3,c2618ba0-022d-434e-a053-39fcc4120313 http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;08:00-09:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Registration Opens and Tech Expo&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;09:00-10:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Introduction, OWASP conference&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;10:00-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Jeff Williams&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
Bio:&amp;lt;br&amp;gt;&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html. &lt;br /&gt;
&lt;br /&gt;
Topic:&amp;lt;br&amp;gt;&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you?re tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, establishing your organization?s ESAPI is one of the best things you can do.?&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
lunch break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Anil Kumar Revuru &lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsfot]&amp;lt;br&amp;gt;&lt;br /&gt;
Bio&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&lt;br /&gt;
Topic: &lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools&lt;br /&gt;
Description:&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;13:30-14:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;Brian Chess&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
Bio:&amp;lt;br&amp;gt;&lt;br /&gt;
Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Topic:&amp;lt;br&amp;gt;&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;14:30-15:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;15:00-15:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Elliot Glazer&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Bio:&lt;br /&gt;
Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&lt;br /&gt;
Topic:&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes &lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;15:30-16:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Corey Benninger&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Bio:&lt;br /&gt;
Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&lt;br /&gt;
Topic:&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Richard Stallman&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;14:00 - ?&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Happy hour and networking opps&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking &amp;amp; Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the University of Minnesota Office of Information Technology [http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=42504</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=42504"/>
				<updated>2008-10-07T18:09:19Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: deleted&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== October Conference ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We will have the participation of speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Rohyt Belani''' from the Intrepidus Group, to mention a few.  We will post all the details soon once we have all the details finalized.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=41708</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=41708"/>
				<updated>2008-10-01T01:54:27Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: added parking and transportation&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The Minneapolis - Saint Paul Chapter invites you to a one-day mini-conference at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center].&lt;br /&gt;
&lt;br /&gt;
Online registration will be available soon. The cost of the conference is $25, which includes lunch.&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;08:00-09:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Registration Opens and Tech Expo&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;09:00-10:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Introduction, OWASP conference&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;10:00-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Jeff Williams&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
Bio:&amp;lt;br&amp;gt;&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html. &lt;br /&gt;
&lt;br /&gt;
Topic:&amp;lt;br&amp;gt;&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you?re tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, establishing your organization?s ESAPI is one of the best things you can do.?&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
lunch break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Anil Kumar Revuru &lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsfot]&amp;lt;br&amp;gt;&lt;br /&gt;
Bio&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&lt;br /&gt;
Topic: &lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools&lt;br /&gt;
Description:&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;13:30-14:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;Brian Chess&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
Bio:&amp;lt;br&amp;gt;&lt;br /&gt;
Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Topic:&amp;lt;br&amp;gt;&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;14:30-15:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;15:00-15:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Elliot Glazer&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Bio:&lt;br /&gt;
Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&lt;br /&gt;
Topic:&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes &lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;15:30-16:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Corey Benninger&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Bio:&lt;br /&gt;
Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&lt;br /&gt;
Topic:&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Richard Stallman&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;14:00 - ?&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Happy hour and networking opps&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Parking &amp;amp; Transportation ==&lt;br /&gt;
Public Parking: http://www1.umn.edu/pts/publicparking.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Map of St. Paul Campus Parking (PDF): http://www1.umn.edu/pts/maps/spcont.pdf&amp;lt;br /&amp;gt;&lt;br /&gt;
Campus Connector Shuttle: http://www1.umn.edu/pts/shuttle.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
Metro Bus information: http://www1.umn.edu/pts/metrobuses.htm&amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the University of Minnesota Office of Information Technology [http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=41646</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=41646"/>
				<updated>2008-09-30T18:32:34Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: link to student center. registration info.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The Minneapolis - Saint Paul Chapter invites you to a one-day mini-conference at the University of Minnesota's [http://www1.umn.edu/twincities/maps/StCen/StCen-map.html St. Paul Student Center].&lt;br /&gt;
&lt;br /&gt;
Online registration will be available soon. The cost of the conference is $25, which includes lunch.&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;08:00-09:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Registration Opens and Tech Expo&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;09:00-10:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Introduction, OWASP conference&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;10:00-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Jeff Williams&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
Bio:&amp;lt;br&amp;gt;&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html. &lt;br /&gt;
&lt;br /&gt;
Topic:&amp;lt;br&amp;gt;&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you?re tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, establishing your organization?s ESAPI is one of the best things you can do.?&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
lunch break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Anil Kumar Revuru &lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsfot]&amp;lt;br&amp;gt;&lt;br /&gt;
Bio&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&lt;br /&gt;
Topic: &lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools&lt;br /&gt;
Description:&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;13:30-14:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;Brian Chess&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
Bio:&amp;lt;br&amp;gt;&lt;br /&gt;
Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Topic:&amp;lt;br&amp;gt;&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;14:30-15:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;15:00-15:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Elliot Glazer&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Bio:&lt;br /&gt;
Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&lt;br /&gt;
Topic:&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes &lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;15:30-16:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Corey Benninger&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Bio:&lt;br /&gt;
Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&lt;br /&gt;
Topic:&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Richard Stallman&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;14:00 - ?&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Happy hour and networking opps&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the University of Minnesota Office of Information Technology [http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=41413</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=41413"/>
				<updated>2008-09-29T18:12:06Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: fixed formatting in agenda&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The Minneapolis - Saint Paul Chapter invites you to a one-day mini-conference at the University of Minnesota's Saint Paul campus. Thanks to the generous support of our sponsors and OWASP, we are able to offer this event at '''no charge to attendees'''!&lt;br /&gt;
&lt;br /&gt;
The agenda is still being finalized, so watch this space for more information.&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table width=&amp;quot;80%&amp;quot; border=&amp;quot;0&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 1px;&amp;quot;&amp;gt;08:00-09:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Registration Opens and Tech Expo&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;09:00-10:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Introduction, OWASP conference&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#7B8ABD; padding: 5px;&amp;quot;&amp;gt;10:00-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Jeff Williams&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;br&amp;gt;&lt;br /&gt;
Bio:&amp;lt;br&amp;gt;&lt;br /&gt;
I'm Jeff Williams, I work as CEO of Aspect Security and I serve as the volunteer Chair of the OWASP Foundation. I've worked on a number of projects at OWASP, including creating the OWASP Top 10, WebGoat, Stinger, Secure Software Contract Annex, Honeycomb Project and the Enterprise Security API. You can find more about my background here: http://myappsecurity.blogspot.com/2007/03/reflection-on-jeff-williams.html. &lt;br /&gt;
&lt;br /&gt;
Topic:&amp;lt;br&amp;gt;&lt;br /&gt;
Application security is getting more complicated every day with increasing connectivity, more mixing of code and data, more parsers, more interpreters, more assets, and more functionality available. We have to take steps now to simplify the problem. So if you?re tired of securing one application at a time, and wrestling with the same vulnerabilities again and again, establishing your organization?s ESAPI is one of the best things you can do.?&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
lunch break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Anil Kumar Revuru &lt;br /&gt;
&amp;lt;br /&amp;gt;[http://www.miscrosoft.com/ Microsfot]&amp;lt;br&amp;gt;&lt;br /&gt;
Bio&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Anil Kumar Revuru currently works for Microsoft as a Security Technologist where he is responsible for architecting security tools. In his previous life at Microsoft, Anil was conducting security design reviews, threat modeling, and application and source-code assessments. Previously as a Security Consultant for a security services vendor, he helped Fortune 100 clients evaluate the security of their software products and applications. He has authored security tools and has presented courses internally at Microsoft.&lt;br /&gt;
&lt;br /&gt;
Anil holds a Diploma in Mechanical Engineering from JNTU Hyderabad. Anil displayed expert proficiency in the substantive and technical areas of design and development, He also made significant contribution to the security development of products at V-Empower Inc. After joining in Microsoft, he worked towards finding security weaknesses and providing necessary countermeasures to application teams. He excelled in his abilities by developing security tools such as Microsoft Threat Analysis and Modeling Tool used for application threat modeling&lt;br /&gt;
&lt;br /&gt;
Topic: &lt;br /&gt;
Microsoft Connected Information Security Framework (CISF) and Tools&lt;br /&gt;
Description:&lt;br /&gt;
The Connected Information Security Group, part of Microsoft internal Information Security organization are working on a technology framework and set of applications to support corporate information security management programs. The Microsoft corporate Information Security Organization (and a few 'early adopter'  customers) will be dog-fooding early prototypes in late 2008/early 2009. This presentation provides a short overview of the problem space and current thinking on our approach to solving it.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;13:30-14:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;Brian Chess&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
Bio:&amp;lt;br&amp;gt;&lt;br /&gt;
Dr. Chess's research focuses on methods for creating secure systems. He received his Ph.D. from the University of California at Santa Cruz, where he applied his background in integrated circuit test and verification to the problem of identifying security errors in software. In addition to authoring numerous patents and technical papers, Dr. Chess has more than ten years of experience in the commercial software arena, having led development efforts at Hewlett Packard and NetLedge&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Topic:&amp;lt;br&amp;gt;&lt;br /&gt;
Creating secure code requires more than just good intentions. Programmers need to know how to make their code safe in an almost infinite number of scenarios and configurations. Static source code analysis gives users the ability to review their work with a fine tooth comb and uncover the kinds of errors that lead directly to vulnerabilities. This talk frames the software security problem and shows how static analysis is part of the solution.&lt;br /&gt;
 &lt;br /&gt;
Highlights include:&lt;br /&gt;
* The most common security short-cuts and why they lead to security failures&lt;br /&gt;
* Why programmers are in the best position to get security right&lt;br /&gt;
* Where to look for security problems&lt;br /&gt;
* How static analysis helps&lt;br /&gt;
* The critical attributes and algorithms that make or break a static analysis tool&lt;br /&gt;
 &lt;br /&gt;
We will look at how static analysis works, how to integrate it into the software development processes, and how to make the most of it during security code review.&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;14:30-15:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;15:00-15:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Elliot Glazer&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
Bio:&lt;br /&gt;
Elliott has over 25 years of information technology experience and has worked in the security field for over 10 years.  He is currently Director of Security Architecture for the Depository Trust and Clearing Corporation (DTCC), where he has created a number of innovative solutions in the areas of security monitoring and security architecture.  He also provides consulting to the organization on critical security issues. Prior to this, Mr. Glazer was Vice President for Security Solutions at American Express, leading many large and small solutions for the Internet, Security, Privacy, and Customer Servicing.  Previous to this, Elliott held leadership positions at Citigroup, Sprint International, and BT Dialcom in software development and operations.  He has led architecture, development, and operations organizations including an enterprise architecture group, Internet software development, and distrbitured operations among others.&lt;br /&gt;
&lt;br /&gt;
Topic:&lt;br /&gt;
&lt;br /&gt;
Information Security Architecture Layers and Key Processes &lt;br /&gt;
&lt;br /&gt;
* Information Security Architecture is driven by an Information Security Strategy and Principles.  It is also critical the architecture support the Business Strategy:&lt;br /&gt;
** Security Functional Architecture: the layout of key functions in security to be accomplished, which drives security requirements.&lt;br /&gt;
** Security Technical Architecture: the solutions and standards to implement key functions, usually an overlay on top of the Functional Architecture.  This is generally a definition of components, intended to be leveraged for reuse by organization, business, line of business or across the enterprise.&lt;br /&gt;
** Security Reference Architecture:  the implementation of Technical Architecture components into a strategy, platform, or particular complex solution set, to be used as a model for other, like needs.  This is usually a set of components organized together.&lt;br /&gt;
** Security Technology Lifecycle – the process of phasing in and out, technology and process solutions that improve the security environment.  Six phases ranging from researching new solutions to exiting old and failing solutions are defined.&lt;br /&gt;
** Security Program Implementation Planning – the process of identifying high level scheduling based on priority and available resources, for solutions defined in the Technical Architecture.  Priority is generally established based on risk.  The program also helps in the planning cycles for budgeting, as it will try to take a multiyear view.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;15:30-16:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Corey Benninger&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Bio:&lt;br /&gt;
Corey is a Principal Consultant with the Intrepidus Group, specializing in&lt;br /&gt;
web and mobile application security. He has performed code reviews and&lt;br /&gt;
conducted application penetration tests for numerous Fortune 500 clients.&lt;br /&gt;
&lt;br /&gt;
Prior to joining Intrepidus Group’s professional services team, Corey served&lt;br /&gt;
as a Senior Consultant and Trainer at Foundstone.&lt;br /&gt;
&lt;br /&gt;
Corey is a polished public speaker and has been invited to speak at leading&lt;br /&gt;
conferences like Black Hat, OWASP AppSec, NYCBSDCon, Secure Development&lt;br /&gt;
World and Infragard. In addition, his expert opinion has been published in&lt;br /&gt;
industry publications like eWeek. He has also published several whitepapers&lt;br /&gt;
on cutting edge security issues, like vulnerabilities in AJAX, and the&lt;br /&gt;
security implications of web browser data caching. He is the co-founder and&lt;br /&gt;
leader of the OWASP Mobile Security Project, a consortium of mobile security&lt;br /&gt;
developers and experts.&lt;br /&gt;
&lt;br /&gt;
Corey has an undergraduate degree from Boston University. He is a Certified&lt;br /&gt;
Information Systems Security Professional (CISSP).&lt;br /&gt;
&lt;br /&gt;
Topic:&lt;br /&gt;
Exploring the how poor application security mixed with a phishing is leading to a costly cocktail of disaster. This talk will go over real world examples of phishing attacks that have taken advantage of cross site scripting flaws, SQL injection vulnerabilities, session fixation attacks, and others web application flaws. Learn what phishers are doing to take their attacks to the next level by chaining multiple vulnerabilities together. The presentation will also share resources that help to track phishing trends and research&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 1px;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Richard Stallman&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;14:00 - ?&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Happy hour and networking opps&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
Conference space provided courtesy of the University of Minnesota Office of Information Technology [http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41345</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41345"/>
				<updated>2008-09-29T03:57:44Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: /* Time and Location */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== October meeting: Wednesday, October 1, 6:00 p.m. ==&lt;br /&gt;
=== Andrew van der Stock: OWASP Developer Guide 3.0 ===&lt;br /&gt;
We are delighted to be able to welcome Andrew van der Stock to the Twin Cities to speak about the OWASP Developer Guide 3.0.&lt;br /&gt;
&lt;br /&gt;
The '''OWASP Developer Guide 3.0''' is coming. Learn what's new, how to build secure software, and how you can help to make the Developer Guide the best ever release of OWASP's first guide! &lt;br /&gt;
&lt;br /&gt;
'''Please [http://www.go-integral.net/node/233 register]''' so we have some idea how many are coming. The room we are scheduled for is smaller than our usual room, so we'll need to communicate with you if the location changes. &lt;br /&gt;
&lt;br /&gt;
==== Time and Location ====&lt;br /&gt;
Time: 6 p.m. &amp;lt;br /&amp;gt;&lt;br /&gt;
Location: Management Education Center, Room M2300 &amp;lt;br /&amp;gt;&lt;br /&gt;
Address: 1501 Hennepin Avenue, Minneapolis, MN 55403 (Hennepin and Spruce, Entrance on Harmon Place)&amp;lt;br /&amp;gt;&lt;br /&gt;
Directions: http://www.metrostate.edu/bldgservices/location.html#mpls&amp;lt;br /&amp;gt;&lt;br /&gt;
Google Maps street view: http://preview.tinyurl.com/5292ad&lt;br /&gt;
&lt;br /&gt;
==== Agenda ====&lt;br /&gt;
6:00 pm - Introduction and optional sign-in for CISSP credits &amp;lt;br /&amp;gt;&lt;br /&gt;
6:10 pm - Welcome: OWASP chapter updates, Conference Announcement! &amp;lt;br /&amp;gt;&lt;br /&gt;
6:30 pm - Andrew van der Stock &amp;lt;br /&amp;gt;&lt;br /&gt;
8:15 pm - Upcoming Events reminder and meeting wrap-up &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Andrew van der Stock is a leading web application researcher active in the web application security community. Andrew is a Senior Application Security Engineer at Aspect Security, specializing in enterprise security architecture, J2EE and PHP web application and web services security. Andrew has 18 years experience in the IT industry, specializing for the last 10 years in web application security, risk management, and architecture for large financial services, logistics and telecommunications clients.&lt;br /&gt;
&lt;br /&gt;
Andrew has a long history with the open source world as a developer&lt;br /&gt;
and researcher. He has contributed to the following projects:&lt;br /&gt;
&lt;br /&gt;
* OWASP Guide Project Lead / Primary Author  (2005-)&lt;br /&gt;
* OWASP Top 10 2007 Project Lead / Primary Author (2007-)&lt;br /&gt;
* OWASP PHP Top 5 (2006)&lt;br /&gt;
* SANS Top 20 Web Application Security Section Author (2005-)&lt;br /&gt;
* SANS GSSP J2EE Secure Programmer Certification, Contributor (2007)&lt;br /&gt;
* UltimaBB PHP forum software, Lead Developer (2005-2008)&lt;br /&gt;
* XMB PHP forum software, Developer (2002-2004), Security Manager (2004-2005, 2008)&lt;br /&gt;
&lt;br /&gt;
Andrew is the moderator of webappsec, one of the primary web app sec mail lists. Previously, Andrew helped create open source low level device drivers for XFree86, a graphical sub-system and Hewlett Packard printers for Linux, NetBSD, and other Unix-like systems.&lt;br /&gt;
&lt;br /&gt;
==== Thank You ====&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security] for sponsoring our location.&amp;lt;br /&amp;gt;&lt;br /&gt;
[[Image:MN-center-strategic-it-security.gif]]&lt;br /&gt;
&lt;br /&gt;
== October Conference ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We will have the participation of speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Rohyt Belani''' from the Intrepidus Group, to mention a few.  We will post all the details soon once we have all the details finalized.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41344</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41344"/>
				<updated>2008-09-29T03:54:27Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: better building name and URL&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== October meeting: Wednesday, October 1, 6:00 p.m. ==&lt;br /&gt;
=== Andrew van der Stock: OWASP Developer Guide 3.0 ===&lt;br /&gt;
We are delighted to be able to welcome Andrew van der Stock to the Twin Cities to speak about the OWASP Developer Guide 3.0.&lt;br /&gt;
&lt;br /&gt;
The '''OWASP Developer Guide 3.0''' is coming. Learn what's new, how to build secure software, and how you can help to make the Developer Guide the best ever release of OWASP's first guide! &lt;br /&gt;
&lt;br /&gt;
'''Please [http://www.go-integral.net/node/233 register]''' so we have some idea how many are coming. The room we are scheduled for is smaller than our usual room, so we'll need to communicate with you if the location changes. &lt;br /&gt;
&lt;br /&gt;
==== Time and Location ====&lt;br /&gt;
Time: 6 p.m. &amp;lt;br /&amp;gt;&lt;br /&gt;
Location: Management Education Center, Room M2300 &amp;lt;br /&amp;gt;&lt;br /&gt;
Address: 1501 Hennepin Avenue, Minneapolis, MN 55403 (Hennepin and Spruce, Entrance on Harmon Place) &amp;lt;br /&amp;gt;&lt;br /&gt;
Directions: http://www.metrostate.edu/bldgservices/location.html#mpls&lt;br /&gt;
&lt;br /&gt;
==== Agenda ====&lt;br /&gt;
6:00 pm - Introduction and optional sign-in for CISSP credits &amp;lt;br /&amp;gt;&lt;br /&gt;
6:10 pm - Welcome: OWASP chapter updates, Conference Announcement! &amp;lt;br /&amp;gt;&lt;br /&gt;
6:30 pm - Andrew van der Stock &amp;lt;br /&amp;gt;&lt;br /&gt;
8:15 pm - Upcoming Events reminder and meeting wrap-up &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Andrew van der Stock is a leading web application researcher active in the web application security community. Andrew is a Senior Application Security Engineer at Aspect Security, specializing in enterprise security architecture, J2EE and PHP web application and web services security. Andrew has 18 years experience in the IT industry, specializing for the last 10 years in web application security, risk management, and architecture for large financial services, logistics and telecommunications clients.&lt;br /&gt;
&lt;br /&gt;
Andrew has a long history with the open source world as a developer&lt;br /&gt;
and researcher. He has contributed to the following projects:&lt;br /&gt;
&lt;br /&gt;
* OWASP Guide Project Lead / Primary Author  (2005-)&lt;br /&gt;
* OWASP Top 10 2007 Project Lead / Primary Author (2007-)&lt;br /&gt;
* OWASP PHP Top 5 (2006)&lt;br /&gt;
* SANS Top 20 Web Application Security Section Author (2005-)&lt;br /&gt;
* SANS GSSP J2EE Secure Programmer Certification, Contributor (2007)&lt;br /&gt;
* UltimaBB PHP forum software, Lead Developer (2005-2008)&lt;br /&gt;
* XMB PHP forum software, Developer (2002-2004), Security Manager (2004-2005, 2008)&lt;br /&gt;
&lt;br /&gt;
Andrew is the moderator of webappsec, one of the primary web app sec mail lists. Previously, Andrew helped create open source low level device drivers for XFree86, a graphical sub-system and Hewlett Packard printers for Linux, NetBSD, and other Unix-like systems.&lt;br /&gt;
&lt;br /&gt;
==== Thank You ====&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security] for sponsoring our location.&amp;lt;br /&amp;gt;&lt;br /&gt;
[[Image:MN-center-strategic-it-security.gif]]&lt;br /&gt;
&lt;br /&gt;
== October Conference ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We will have the participation of speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Rohyt Belani''' from the Intrepidus Group, to mention a few.  We will post all the details soon once we have all the details finalized.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41281</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41281"/>
				<updated>2008-09-27T01:50:03Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: updated notice about registering&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== October meeting: Wednesday, October 1, 6:00 p.m. ==&lt;br /&gt;
=== Andrew van der Stock: OWASP Developer Guide 3.0 ===&lt;br /&gt;
We are delighted to be able to welcome Andrew van der Stock to the Twin Cities to speak about the OWASP Developer Guide 3.0.&lt;br /&gt;
&lt;br /&gt;
The '''OWASP Developer Guide 3.0''' is coming. Learn what's new, how to build secure software, and how you can help to make the Developer Guide the best ever release of OWASP's first guide! &lt;br /&gt;
&lt;br /&gt;
'''Please [http://www.go-integral.net/node/233 register]''' so we have some idea how many are coming. The room we are scheduled for is smaller than our usual room, so we'll need to communicate with you if the location changes. &lt;br /&gt;
&lt;br /&gt;
==== Time and Location ====&lt;br /&gt;
Time: 6 p.m. &amp;lt;br /&amp;gt;&lt;br /&gt;
Location: MEC building Room M 2300 &amp;lt;br /&amp;gt;&lt;br /&gt;
Address: 1501 Hennepin Avenue, Minneapolis, MN 55403 (Hennepin and Spruce, Entrance on Harmon Place) &amp;lt;br /&amp;gt;&lt;br /&gt;
Directions: http://www.metrostate.edu/bldgservices/location.html&lt;br /&gt;
&lt;br /&gt;
==== Agenda ====&lt;br /&gt;
6:00 pm - Introduction and optional sign-in for CISSP credits &amp;lt;br /&amp;gt;&lt;br /&gt;
6:10 pm - Welcome: OWASP chapter updates, Conference Announcement! &amp;lt;br /&amp;gt;&lt;br /&gt;
6:30 pm - Andrew van der Stock &amp;lt;br /&amp;gt;&lt;br /&gt;
8:15 pm - Upcoming Events reminder and meeting wrap-up &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Andrew van der Stock is a leading web application researcher active in the web application security community. Andrew is a Senior Application Security Engineer at Aspect Security, specializing in enterprise security architecture, J2EE and PHP web application and web services security. Andrew has 18 years experience in the IT industry, specializing for the last 10 years in web application security, risk management, and architecture for large financial services, logistics and telecommunications clients.&lt;br /&gt;
&lt;br /&gt;
Andrew has a long history with the open source world as a developer&lt;br /&gt;
and researcher. He has contributed to the following projects:&lt;br /&gt;
&lt;br /&gt;
* OWASP Guide Project Lead / Primary Author  (2005-)&lt;br /&gt;
* OWASP Top 10 2007 Project Lead / Primary Author (2007-)&lt;br /&gt;
* OWASP PHP Top 5 (2006)&lt;br /&gt;
* SANS Top 20 Web Application Security Section Author (2005-)&lt;br /&gt;
* SANS GSSP J2EE Secure Programmer Certification, Contributor (2007)&lt;br /&gt;
* UltimaBB PHP forum software, Lead Developer (2005-2008)&lt;br /&gt;
* XMB PHP forum software, Developer (2002-2004), Security Manager (2004-2005, 2008)&lt;br /&gt;
&lt;br /&gt;
Andrew is the moderator of webappsec, one of the primary web app sec mail lists. Previously, Andrew helped create open source low level device drivers for XFree86, a graphical sub-system and Hewlett Packard printers for Linux, NetBSD, and other Unix-like systems.&lt;br /&gt;
&lt;br /&gt;
==== Thank You ====&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security] for sponsoring our location.&amp;lt;br /&amp;gt;&lt;br /&gt;
[[Image:MN-center-strategic-it-security.gif]]&lt;br /&gt;
&lt;br /&gt;
== October Conference ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We will have the participation of speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Rohyt Belani''' from the Intrepidus Group, to mention a few.  We will post all the details soon once we have all the details finalized.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41179</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41179"/>
				<updated>2008-09-26T16:05:40Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: /* Andrew van der Stock: OWASP Developer Guide 3.0 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== October meeting: Wednesday, October 1, 6:00 p.m. ==&lt;br /&gt;
=== Andrew van der Stock: OWASP Developer Guide 3.0 ===&lt;br /&gt;
We are delighted to be able to welcome Andrew van der Stock to the Twin Cities to speak about the OWASP Developer Guide 3.0.&lt;br /&gt;
&lt;br /&gt;
The '''OWASP Developer Guide 3.0''' is coming. Learn what's new, how to build secure software, and how you can help to make the Developer Guide the best ever release of OWASP's first guide! &lt;br /&gt;
&lt;br /&gt;
Please [http://www.go-integral.net/node/233 register] so we have some idea how many are coming.&lt;br /&gt;
&lt;br /&gt;
==== Time and Location ====&lt;br /&gt;
Time: 6 p.m. &amp;lt;br /&amp;gt;&lt;br /&gt;
Location: MEC building Room M 2300 &amp;lt;br /&amp;gt;&lt;br /&gt;
Address: 1501 Hennepin Avenue, Minneapolis, MN 55403 (Hennepin and Spruce, Entrance on Harmon Place) &amp;lt;br /&amp;gt;&lt;br /&gt;
Directions: http://www.metrostate.edu/bldgservices/location.html&lt;br /&gt;
&lt;br /&gt;
==== Agenda ====&lt;br /&gt;
6:00 pm - Introduction and optional sign-in for CISSP credits &amp;lt;br /&amp;gt;&lt;br /&gt;
6:10 pm - Welcome: OWASP chapter updates, Conference Announcement! &amp;lt;br /&amp;gt;&lt;br /&gt;
6:30 pm - Andrew van der Stock &amp;lt;br /&amp;gt;&lt;br /&gt;
8:15 pm - Upcoming Events reminder and meeting wrap-up &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Andrew van der Stock is a leading web application researcher active in the web application security community. Andrew is a Senior Application Security Engineer at Aspect Security, specializing in enterprise security architecture, J2EE and PHP web application and web services security. Andrew has 18 years experience in the IT industry, specializing for the last 10 years in web application security, risk management, and architecture for large financial services, logistics and telecommunications clients.&lt;br /&gt;
&lt;br /&gt;
Andrew has a long history with the open source world as a developer&lt;br /&gt;
and researcher. He has contributed to the following projects:&lt;br /&gt;
&lt;br /&gt;
* OWASP Guide Project Lead / Primary Author  (2005-)&lt;br /&gt;
* OWASP Top 10 2007 Project Lead / Primary Author (2007-)&lt;br /&gt;
* OWASP PHP Top 5 (2006)&lt;br /&gt;
* SANS Top 20 Web Application Security Section Author (2005-)&lt;br /&gt;
* SANS GSSP J2EE Secure Programmer Certification, Contributor (2007)&lt;br /&gt;
* UltimaBB PHP forum software, Lead Developer (2005-2008)&lt;br /&gt;
* XMB PHP forum software, Developer (2002-2004), Security Manager (2004-2005, 2008)&lt;br /&gt;
&lt;br /&gt;
Andrew is the moderator of webappsec, one of the primary web app sec mail lists. Previously, Andrew helped create open source low level device drivers for XFree86, a graphical sub-system and Hewlett Packard printers for Linux, NetBSD, and other Unix-like systems.&lt;br /&gt;
&lt;br /&gt;
==== Thank You ====&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security] for sponsoring our location.&amp;lt;br /&amp;gt;&lt;br /&gt;
[[Image:MN-center-strategic-it-security.gif]]&lt;br /&gt;
&lt;br /&gt;
== October Conference ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We will have the participation of speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Rohyt Belani''' from the Intrepidus Group, to mention a few.  We will post all the details soon once we have all the details finalized.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41178</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41178"/>
				<updated>2008-09-26T16:03:58Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: /* October meeting: Wednesday, October 1 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== October meeting: Wednesday, October 1, 6:00 p.m. ==&lt;br /&gt;
=== Andrew van der Stock: OWASP Developer Guide 3.0 ===&lt;br /&gt;
We are delighted to be able to welcome Andrew van der Stock to the Twin Cities to speak about the OWASP Developer Guide 3.0.&lt;br /&gt;
&lt;br /&gt;
The '''OWASP Developer Guide 3.0''' is coming. Learn what's new, how to build secure software, and how you can help to make the Developer Guide the best ever release of OWASP's first guide! &lt;br /&gt;
&lt;br /&gt;
==== Time and Location ====&lt;br /&gt;
Time: 6 p.m. &amp;lt;br /&amp;gt;&lt;br /&gt;
Location: MEC building Room M 2300 &amp;lt;br /&amp;gt;&lt;br /&gt;
Address: 1501 Hennepin Avenue, Minneapolis, MN 55403 (Hennepin and Spruce, Entrance on Harmon Place) &amp;lt;br /&amp;gt;&lt;br /&gt;
Directions: http://www.metrostate.edu/bldgservices/location.html&lt;br /&gt;
&lt;br /&gt;
==== Agenda ====&lt;br /&gt;
6:00 pm - Introduction and optional sign-in for CISSP credits &amp;lt;br /&amp;gt;&lt;br /&gt;
6:10 pm - Welcome: OWASP chapter updates, Conference Announcement! &amp;lt;br /&amp;gt;&lt;br /&gt;
6:30 pm - Andrew van der Stock &amp;lt;br /&amp;gt;&lt;br /&gt;
8:15 pm - Upcoming Events reminder and meeting wrap-up &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Andrew van der Stock is a leading web application researcher active in the web application security community. Andrew is a Senior Application Security Engineer at Aspect Security, specializing in enterprise security architecture, J2EE and PHP web application and web services security. Andrew has 18 years experience in the IT industry, specializing for the last 10 years in web application security, risk management, and architecture for large financial services, logistics and telecommunications clients.&lt;br /&gt;
&lt;br /&gt;
Andrew has a long history with the open source world as a developer&lt;br /&gt;
and researcher. He has contributed to the following projects:&lt;br /&gt;
&lt;br /&gt;
* OWASP Guide Project Lead / Primary Author  (2005-)&lt;br /&gt;
* OWASP Top 10 2007 Project Lead / Primary Author (2007-)&lt;br /&gt;
* OWASP PHP Top 5 (2006)&lt;br /&gt;
* SANS Top 20 Web Application Security Section Author (2005-)&lt;br /&gt;
* SANS GSSP J2EE Secure Programmer Certification, Contributor (2007)&lt;br /&gt;
* UltimaBB PHP forum software, Lead Developer (2005-2008)&lt;br /&gt;
* XMB PHP forum software, Developer (2002-2004), Security Manager (2004-2005, 2008)&lt;br /&gt;
&lt;br /&gt;
Andrew is the moderator of webappsec, one of the primary web app sec mail lists. Previously, Andrew helped create open source low level device drivers for XFree86, a graphical sub-system and Hewlett Packard printers for Linux, NetBSD, and other Unix-like systems.&lt;br /&gt;
&lt;br /&gt;
==== Thank You ====&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security] for sponsoring our location.&amp;lt;br /&amp;gt;&lt;br /&gt;
[[Image:MN-center-strategic-it-security.gif]]&lt;br /&gt;
&lt;br /&gt;
== October Conference ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We will have the participation of speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Rohyt Belani''' from the Intrepidus Group, to mention a few.  We will post all the details soon once we have all the details finalized.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41177</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41177"/>
				<updated>2008-09-26T16:03:22Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: /* Andrew van der Stock */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== October meeting: Wednesday, October 1 ==&lt;br /&gt;
=== Andrew van der Stock ===&lt;br /&gt;
We are delighted to be able to welcome Andrew van der Stock to the Twin Cities to speak about the OWASP Developer Guide 3.0.&lt;br /&gt;
&lt;br /&gt;
The '''OWASP Developer Guide 3.0''' is coming. Learn what's new, how to build secure software, and how you can help to make the Developer Guide the best ever release of OWASP's first guide! &lt;br /&gt;
&lt;br /&gt;
==== Time and Location ====&lt;br /&gt;
Time: 6 p.m. &amp;lt;br /&amp;gt;&lt;br /&gt;
Location: MEC building Room M 2300 &amp;lt;br /&amp;gt;&lt;br /&gt;
Address: 1501 Hennepin Avenue, Minneapolis, MN 55403 (Hennepin and Spruce, Entrance on Harmon Place) &amp;lt;br /&amp;gt;&lt;br /&gt;
Directions: http://www.metrostate.edu/bldgservices/location.html&lt;br /&gt;
&lt;br /&gt;
==== Agenda ====&lt;br /&gt;
6:00 pm - Introduction and optional sign-in for CISSP credits &amp;lt;br /&amp;gt;&lt;br /&gt;
6:10 pm - Welcome: OWASP chapter updates, Conference Announcement! &amp;lt;br /&amp;gt;&lt;br /&gt;
6:30 pm - Andrew van der Stock &amp;lt;br /&amp;gt;&lt;br /&gt;
8:15 pm - Upcoming Events reminder and meeting wrap-up &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Andrew van der Stock is a leading web application researcher active in the web application security community. Andrew is a Senior Application Security Engineer at Aspect Security, specializing in enterprise security architecture, J2EE and PHP web application and web services security. Andrew has 18 years experience in the IT industry, specializing for the last 10 years in web application security, risk management, and architecture for large financial services, logistics and telecommunications clients.&lt;br /&gt;
&lt;br /&gt;
Andrew has a long history with the open source world as a developer&lt;br /&gt;
and researcher. He has contributed to the following projects:&lt;br /&gt;
&lt;br /&gt;
* OWASP Guide Project Lead / Primary Author  (2005-)&lt;br /&gt;
* OWASP Top 10 2007 Project Lead / Primary Author (2007-)&lt;br /&gt;
* OWASP PHP Top 5 (2006)&lt;br /&gt;
* SANS Top 20 Web Application Security Section Author (2005-)&lt;br /&gt;
* SANS GSSP J2EE Secure Programmer Certification, Contributor (2007)&lt;br /&gt;
* UltimaBB PHP forum software, Lead Developer (2005-2008)&lt;br /&gt;
* XMB PHP forum software, Developer (2002-2004), Security Manager (2004-2005, 2008)&lt;br /&gt;
&lt;br /&gt;
Andrew is the moderator of webappsec, one of the primary web app sec mail lists. Previously, Andrew helped create open source low level device drivers for XFree86, a graphical sub-system and Hewlett Packard printers for Linux, NetBSD, and other Unix-like systems.&lt;br /&gt;
&lt;br /&gt;
==== Thank You ====&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security] for sponsoring our location.&amp;lt;br /&amp;gt;&lt;br /&gt;
[[Image:MN-center-strategic-it-security.gif]]&lt;br /&gt;
&lt;br /&gt;
== October Conference ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We will have the participation of speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Rohyt Belani''' from the Intrepidus Group, to mention a few.  We will post all the details soon once we have all the details finalized.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41176</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41176"/>
				<updated>2008-09-26T16:02:49Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: added location and agenda&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== October meeting: Wednesday, October 1 ==&lt;br /&gt;
=== Andrew van der Stock ===&lt;br /&gt;
We are delighted to be able to welcome Andrew van der Stock to the Twin Cities to speak about the OWASP Developer Guide 3.0.&lt;br /&gt;
&lt;br /&gt;
The OWASP Developer Guide 3.0 is coming. Learn what's new, how to build secure software, and how you can help to make the Developer Guide the best ever release of OWASP's first guide! &lt;br /&gt;
&lt;br /&gt;
==== Time and Location ====&lt;br /&gt;
Time: 6 p.m. &amp;lt;br /&amp;gt;&lt;br /&gt;
Location: MEC building Room M 2300 &amp;lt;br /&amp;gt;&lt;br /&gt;
Address: 1501 Hennepin Avenue, Minneapolis, MN 55403 (Hennepin and Spruce, Entrance on Harmon Place) &amp;lt;br /&amp;gt;&lt;br /&gt;
Directions: http://www.metrostate.edu/bldgservices/location.html&lt;br /&gt;
&lt;br /&gt;
==== Agenda ====&lt;br /&gt;
6:00 pm - Introduction and optional sign-in for CISSP credits &amp;lt;br /&amp;gt;&lt;br /&gt;
6:10 pm - Welcome: OWASP chapter updates, Conference Announcement! &amp;lt;br /&amp;gt;&lt;br /&gt;
6:30 pm - Andrew van der Stock &amp;lt;br /&amp;gt;&lt;br /&gt;
8:15 pm - Upcoming Events reminder and meeting wrap-up &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Andrew van der Stock is a leading web application researcher active in the web application security community. Andrew is a Senior Application Security Engineer at Aspect Security, specializing in enterprise security architecture, J2EE and PHP web application and web services security. Andrew has 18 years experience in the IT industry, specializing for the last 10 years in web application security, risk management, and architecture for large financial services, logistics and telecommunications clients.&lt;br /&gt;
&lt;br /&gt;
Andrew has a long history with the open source world as a developer&lt;br /&gt;
and researcher. He has contributed to the following projects:&lt;br /&gt;
&lt;br /&gt;
* OWASP Guide Project Lead / Primary Author  (2005-)&lt;br /&gt;
* OWASP Top 10 2007 Project Lead / Primary Author (2007-)&lt;br /&gt;
* OWASP PHP Top 5 (2006)&lt;br /&gt;
* SANS Top 20 Web Application Security Section Author (2005-)&lt;br /&gt;
* SANS GSSP J2EE Secure Programmer Certification, Contributor (2007)&lt;br /&gt;
* UltimaBB PHP forum software, Lead Developer (2005-2008)&lt;br /&gt;
* XMB PHP forum software, Developer (2002-2004), Security Manager (2004-2005, 2008)&lt;br /&gt;
&lt;br /&gt;
Andrew is the moderator of webappsec, one of the primary web app sec mail lists. Previously, Andrew helped create open source low level device drivers for XFree86, a graphical sub-system and Hewlett Packard printers for Linux, NetBSD, and other Unix-like systems.&lt;br /&gt;
&lt;br /&gt;
==== Thank You ====&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security] for sponsoring our location.&amp;lt;br /&amp;gt;&lt;br /&gt;
[[Image:MN-center-strategic-it-security.gif]]&lt;br /&gt;
&lt;br /&gt;
== October Conference ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We will have the participation of speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Rohyt Belani''' from the Intrepidus Group, to mention a few.  We will post all the details soon once we have all the details finalized.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41000</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=41000"/>
				<updated>2008-09-24T04:30:09Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: removed link to AppSec NYC. It's tomorrow.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== October meeting: Wednesday, October 1 ==&lt;br /&gt;
=== Andrew van der Stock ===&lt;br /&gt;
We are delighted to be able to welcome Andrew van der Stock to the Twin Cities to speak about the OWASP Developer Guide 3.0. Details about time and location are forthcoming, so please check back.&lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Andrew van der Stock is a leading web application researcher active in the web application security community. Andrew is a Senior Application Security Engineer at Aspect Security, specializing in enterprise security architecture, J2EE and PHP web application and web services security. Andrew has 18 years experience in the IT industry, specializing for the last 10 years in web application security, risk management, and architecture for large financial services, logistics and telecommunications clients.&lt;br /&gt;
&lt;br /&gt;
Andrew has a long history with the open source world as a developer&lt;br /&gt;
and researcher. He has contributed to the following projects:&lt;br /&gt;
&lt;br /&gt;
* OWASP Guide Project Lead / Primary Author  (2005-)&lt;br /&gt;
* OWASP Top 10 2007 Project Lead / Primary Author (2007-)&lt;br /&gt;
* OWASP PHP Top 5 (2006)&lt;br /&gt;
* SANS Top 20 Web Application Security Section Author (2005-)&lt;br /&gt;
* SANS GSSP J2EE Secure Programmer Certification, Contributor (2007)&lt;br /&gt;
* UltimaBB PHP forum software, Lead Developer (2005-2008)&lt;br /&gt;
* XMB PHP forum software, Developer (2002-2004), Security Manager (2004-2005, 2008)&lt;br /&gt;
&lt;br /&gt;
Andrew is the moderator of webappsec, one of the primary web app sec mail lists. Previously, Andrew helped create open source low level device drivers for XFree86, a graphical sub-system and Hewlett Packard printers for Linux, NetBSD, and other Unix-like systems.&lt;br /&gt;
&lt;br /&gt;
== October Conference ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We will have the participation of speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Rohyt Belani''' from the Intrepidus Group, to mention a few.  We will post all the details soon once we have all the details finalized.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=40999</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=40999"/>
				<updated>2008-09-24T04:29:10Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: Added info about October speaker: Andrew van der Stock.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== October meeting: Wednesday, October 1 ==&lt;br /&gt;
=== Andrew van der Stock ===&lt;br /&gt;
We are delighted to be able to welcome Andrew van der Stock to the Twin Cities to speak about the OWASP Developer Guide 3.0. Details about time and location are forthcoming, so please check back.&lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Andrew van der Stock is a leading web application researcher active in the web application security community. Andrew is a Senior Application Security Engineer at Aspect Security, specializing in enterprise security architecture, J2EE and PHP web application and web services security. Andrew has 18 years experience in the IT industry, specializing for the last 10 years in web application security, risk management, and architecture for large financial services, logistics and telecommunications clients.&lt;br /&gt;
&lt;br /&gt;
Andrew has a long history with the open source world as a developer&lt;br /&gt;
and researcher. He has contributed to the following projects:&lt;br /&gt;
&lt;br /&gt;
* OWASP Guide Project Lead / Primary Author  (2005-)&lt;br /&gt;
* OWASP Top 10 2007 Project Lead / Primary Author (2007-)&lt;br /&gt;
* OWASP PHP Top 5 (2006)&lt;br /&gt;
* SANS Top 20 Web Application Security Section Author (2005-)&lt;br /&gt;
* SANS GSSP J2EE Secure Programmer Certification, Contributor (2007)&lt;br /&gt;
* UltimaBB PHP forum software, Lead Developer (2005-2008)&lt;br /&gt;
* XMB PHP forum software, Developer (2002-2004), Security Manager (2004-2005, 2008)&lt;br /&gt;
&lt;br /&gt;
Andrew is the moderator of webappsec, one of the primary web app sec mail lists. Previously, Andrew helped create open source low level device drivers for XFree86, a graphical sub-system and Hewlett Packard printers for Linux, NetBSD, and other Unix-like systems.&lt;br /&gt;
&lt;br /&gt;
== October Conference ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We will have the participation of speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Rohyt Belani''' from the Intrepidus Group, to mention a few.  We will post all the details soon once we have all the details finalized.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-2772176093312625908&amp;amp;hl=en Video: Jeremiah Grossman - Get Rich or Die Trying - Making Money on The Web, The Black Hat Way - OWASP (MSP) - 9 September 2008 (Partial Video - 38 Minutes)] | [https://www.owasp.org/images/5/5d/OWASP_Minneapolis_20080908_Jeremiah_Grossman.pdf Slides (PDF)]&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (5.4 MB PDF)]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''OWASP NYC AppSec 2008''' Sept 24-25th - Don't miss the [http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference/ NYC AppSec conference]! &amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference http://www.owasp.org/images/6/61/Banner2_irfan.jpg]&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=37218</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=37218"/>
				<updated>2008-08-26T02:17:39Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: fixed link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== September meeting: Tuesday, September 9 at 6:00 pm ==&lt;br /&gt;
&lt;br /&gt;
=== Jeremiah Grossman: Get Rich or Die Trying - Making Money on The Web, The Black Hat Way ===&lt;br /&gt;
Forget Cross-Site Scripting. Forget SQL Injection. If you want to make some serious cash on the Web silently and surreptitiously, you don't need them. You also don't need noisy scanners, sophisticated proxies, 0-days, or ninja level reverse engineering skills -- all you need is a Web browser, a clue on what to look for, and a few black hat tricks. Generating affiliate advertising revenue from the Website traffic of others, trade stock using corporation information passively gleaned, inhibit the online purchase of sought after items creating artificial scarcity, and so much more. Activities not technically illegal, only violating terms of service.&lt;br /&gt;
&lt;br /&gt;
You may have heard these referred to as business logic flaws, but that name really doesn't do them justice. It sounds so academic and benign in that context when the truth is anything but. These are not the same ol' Web hacker attack techniques everyone is familiar with, but the one staring you in the face and missed because gaming a system and making money this way couldn't be that simple. Plus IDS can't detect them and Web application firewalls can't black them. If fact, these types of attacks are so hard to detect (if anyone is actually trying) we aren't even sure how widespread their use actually is. Time to pull back the cover and expose what's possible. &lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Jeremiah Grossman is the founder and CTO of WhiteHat Security, considered a world-renowned expert in Web security, co-founder of the Web Application Security Consortium, and named to InfoWorld's Top 25 CTOs for 2007. Mr. Grossman is a frequent speaker at industry events including the BlackHat Briefings, RSA, ISACA, CSI, HiTB, OWASP, Vanguard, ISSA, Defcon, and a number of large universities. He has authored dozens of articles and white papers; is credited with the discovery of many cutting-edge attack and defensive techniques; and is a co-author of XSS Attacks. Mr. Grossman is frequently quoted in major media publications such as InfoWorld, USA Today, PCWorld, Dark Reading, SC Magazine, SecurityFocus, CNet, SC Magazine, CSO, and InformationWeek. Prior to WhiteHat he was an information security officer at Yahoo!&lt;br /&gt;
&lt;br /&gt;
==== Agenda: ====&lt;br /&gt;
&lt;br /&gt;
  6:00 pm - Introduction and Optional sign-in for CISSP credits&lt;br /&gt;
  6:10 pm - Welcome: OWASP chapter updates, conference announcement&lt;br /&gt;
  6:30 pm – Break&lt;br /&gt;
  6:45 pm – Jeremiah Grossman&lt;br /&gt;
  8:15 pm - Upcoming Events reminder and meeting wrap-up &lt;br /&gt;
&lt;br /&gt;
==== Register ====&lt;br /&gt;
&lt;br /&gt;
Please help us anticipate attendance: '''[http://www.go-integral.net/node/231 register online]'''.&lt;br /&gt;
&lt;br /&gt;
==== Location ====&lt;br /&gt;
&lt;br /&gt;
[http://www.minneapolis.edu/ Minneapolis Community and Technical College]&amp;lt;br /&amp;gt;&lt;br /&gt;
1501 Hennepin Ave, Minneapolis&amp;lt;br /&amp;gt;&lt;br /&gt;
Whitney Center, Room L3100 (3rd Floor)&lt;br /&gt;
&lt;br /&gt;
'''Map''': http://www.minneapolis.edu/campusmaps/&lt;br /&gt;
&lt;br /&gt;
Park in the ramp (R) - move through the T building (T) and go to Whitney Hall (L).&lt;br /&gt;
&lt;br /&gt;
==== Thank You ====&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security] for sponsoring our location.&amp;lt;br /&amp;gt;&lt;br /&gt;
[[Image:MN-center-strategic-it-security.gif]]&lt;br /&gt;
&lt;br /&gt;
We are still looking for a book give-away sponsor and for sponsors for upcoming meetings.&lt;br /&gt;
Call Lorna at 651-338-0243 if you need directions or have questions.&lt;br /&gt;
&lt;br /&gt;
== October Conference ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We will have the participation of speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Rohyt Belani''' from the Intrepidus Group, to mention a few.  We will post all the details soon once we have all the details finalized.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (PDF)]&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=7535038243903138173&amp;amp;hl=en Tony Stieber - How NOT to Implement Encryption for the OWASP Top 10 - OWASP (MSP) - 16 June 2008]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''OWASP NYC AppSec 2008''' Sept 24-25th - Don't miss the [http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference/ NYC AppSec conference]! &amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference http://www.owasp.org/images/6/61/Banner2_irfan.jpg]&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=37217</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=37217"/>
				<updated>2008-08-26T01:50:41Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: more info about mini-conference, minor re-org of sections.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== September meeting: Tuesday, September 9 at 6:00 pm ==&lt;br /&gt;
&lt;br /&gt;
=== Jeremiah Grossman: Get Rich or Die Trying - Making Money on The Web, The Black Hat Way ===&lt;br /&gt;
Forget Cross-Site Scripting. Forget SQL Injection. If you want to make some serious cash on the Web silently and surreptitiously, you don't need them. You also don't need noisy scanners, sophisticated proxies, 0-days, or ninja level reverse engineering skills -- all you need is a Web browser, a clue on what to look for, and a few black hat tricks. Generating affiliate advertising revenue from the Website traffic of others, trade stock using corporation information passively gleaned, inhibit the online purchase of sought after items creating artificial scarcity, and so much more. Activities not technically illegal, only violating terms of service.&lt;br /&gt;
&lt;br /&gt;
You may have heard these referred to as business logic flaws, but that name really doesn't do them justice. It sounds so academic and benign in that context when the truth is anything but. These are not the same ol' Web hacker attack techniques everyone is familiar with, but the one staring you in the face and missed because gaming a system and making money this way couldn't be that simple. Plus IDS can't detect them and Web application firewalls can't black them. If fact, these types of attacks are so hard to detect (if anyone is actually trying) we aren't even sure how widespread their use actually is. Time to pull back the cover and expose what's possible. &lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Jeremiah Grossman is the founder and CTO of WhiteHat Security, considered a world-renowned expert in Web security, co-founder of the Web Application Security Consortium, and named to InfoWorld's Top 25 CTOs for 2007. Mr. Grossman is a frequent speaker at industry events including the BlackHat Briefings, RSA, ISACA, CSI, HiTB, OWASP, Vanguard, ISSA, Defcon, and a number of large universities. He has authored dozens of articles and white papers; is credited with the discovery of many cutting-edge attack and defensive techniques; and is a co-author of XSS Attacks. Mr. Grossman is frequently quoted in major media publications such as InfoWorld, USA Today, PCWorld, Dark Reading, SC Magazine, SecurityFocus, CNet, SC Magazine, CSO, and InformationWeek. Prior to WhiteHat he was an information security officer at Yahoo!&lt;br /&gt;
&lt;br /&gt;
==== Agenda: ====&lt;br /&gt;
&lt;br /&gt;
  6:00 pm - Introduction and Optional sign-in for CISSP credits&lt;br /&gt;
  6:10 pm - Welcome: OWASP chapter updates, conference announcement&lt;br /&gt;
  6:30 pm – Break&lt;br /&gt;
  6:45 pm – Jeremiah Grossman&lt;br /&gt;
  8:15 pm - Upcoming Events reminder and meeting wrap-up &lt;br /&gt;
&lt;br /&gt;
==== Register ====&lt;br /&gt;
&lt;br /&gt;
Please help us anticipate attendance: '''[http://www.go-integral.net/node/231 register online]'''.&lt;br /&gt;
&lt;br /&gt;
==== Location ====&lt;br /&gt;
&lt;br /&gt;
[http://www.minneapolis.edu/ Minneapolis Community and Technical College]&amp;lt;br /&amp;gt;&lt;br /&gt;
1501 Hennepin Ave, Minneapolis&amp;lt;br /&amp;gt;&lt;br /&gt;
Whitney Center, Room L3100 (3rd Floor)&lt;br /&gt;
&lt;br /&gt;
'''Map''': http://www.minneapolis.edu/campusmaps/&lt;br /&gt;
&lt;br /&gt;
Park in the ramp (R) - move through the T building (T) and go to Whitney Hall (L).&lt;br /&gt;
&lt;br /&gt;
==== Thank You ====&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security] for sponsoring our location.&amp;lt;br /&amp;gt;&lt;br /&gt;
[[Image:MN-center-strategic-it-security.gif]]&lt;br /&gt;
&lt;br /&gt;
We are still looking for a book give-away sponsor and for sponsors for upcoming meetings.&lt;br /&gt;
Call Lorna at 651-338-0243 if you need directions or have questions.&lt;br /&gt;
&lt;br /&gt;
== October Conference ==&lt;br /&gt;
Please join us October 21, 2008 for a [https://www.owasp.org/index.php/OWASP_Minneapolis_St_Paul_2008_Conference '''mini conference''' in October 2008] at University of Minnesota's Saint Paul campus. We will have the participation of speakers such as '''Richard Stallman''' founder of the Free Software Foundation; '''User:Jeff Williams''', Chair of the OWASP Foundation and CEO of Aspect Security; and '''Rohyt Belani''' from the Intrepidus Group, to mention a few.  We will post all the details soon once we have all the details finalized.&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (PDF)]&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=7535038243903138173&amp;amp;hl=en Tony Stieber - How NOT to Implement Encryption for the OWASP Top 10 - OWASP (MSP) - 16 June 2008]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;[[OWASP Minneapolis St Paul 2008 Conference]] on October 21 with lots of great speakers and opportunities to participate. Looking forward to seeing you there!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;There is also planning for a two day web penetration testing course offered by the MN-ISSA and Rohyt Belani from the Intrepidus Group. Stay turned for more info!&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''OWASP NYC AppSec 2008''' Sept 24-25th - Don't miss the [http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference/ NYC AppSec conference]! &amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference http://www.owasp.org/images/6/61/Banner2_irfan.jpg]&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=37216</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=37216"/>
				<updated>2008-08-26T01:35:57Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: added &amp;quot;Saint Paul campus&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The Minneapolis - Saint Paul Chapter invites you to a one-day mini-conference at the University of Minnesota's Saint Paul campus. Thanks to the generous support of our sponsors and OWASP, we are able to offer this event at '''no charge to attendees'''!&lt;br /&gt;
&lt;br /&gt;
The agenda is still being finalized, so watch this space for more information.&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;08:00-09:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Registration Opens and Tech Expo&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;09:00-10:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;Introduction, OWASP conference&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;10:00-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Jeff Williams&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
lunch break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Simon Roses Fermerling&amp;lt;br /&amp;gt;Microsoft - [http://www.owasp.org/index.php/Category:OWASP_Pantera_Web_Assessment_Studio_Project Pantera project]&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;13:30-14:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;Brian Chess&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;14:30-15:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;15:00-15:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Elliot Glazer&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;15:30-16:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Rohyt Belani&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Richard Stallman&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;14:00 - ?&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Happy hour and networking opps&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
[http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=37215</id>
		<title>OWASP Minneapolis St Paul 2008 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Minneapolis_St_Paul_2008_Conference&amp;diff=37215"/>
				<updated>2008-08-26T01:35:00Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: titles for Jeff Williams&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP &amp;amp; FLOSS Application Security Mini-Conference 2008 - October 21, 2008  ==&lt;br /&gt;
The Minneapolis - Saint Paul Chapter invites you to a one-day mini-conference at the University of Minnesota. Thanks to the generous support of our sponsors and OWASP, we are able to offer this event at '''no charge to attendees'''!&lt;br /&gt;
&lt;br /&gt;
The agenda is still being finalized, so watch this space for more information.&lt;br /&gt;
&lt;br /&gt;
== Tentative Agenda ==&lt;br /&gt;
&amp;lt;table&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;08:00-09:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color:#BC857A; padding: 5px;&amp;quot;&amp;gt;Registration Opens and Tech Expo&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td  style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;09:00-10:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;Introduction, OWASP conference&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;10:00-11:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Jeff Williams&amp;lt;br /&amp;gt;CEO, [http://www.aspectsecurity.com/ Aspect Security]&amp;lt;br /&amp;gt;OWASP founder; Chair, OWASP Foundation&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;11:00-12:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
lunch break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;12:30-13:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Simon Roses Fermerling&amp;lt;br /&amp;gt;Microsoft - [http://www.owasp.org/index.php/Category:OWASP_Pantera_Web_Assessment_Studio_Project Pantera project]&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;13:30-14:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;Brian Chess&amp;lt;br /&amp;gt;[http://www.fortify.com/ Fortify Software]&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;14:30-15:00&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Break&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;15:00-15:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Elliot Glazer&amp;lt;br /&amp;gt;[http://www.dtcc.com/ DTCC]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;15:30-16:30&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Rohyt Belani&amp;lt;br /&amp;gt;[http://intrepidusgroup.com/ Intrepidus Group]&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Richard Stallman&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;tr&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #7B8ABD; padding: 5px;&amp;quot;&amp;gt;14:00 - ?&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;td style=&amp;quot;background-color: #BC857A; padding: 5px;&amp;quot;&amp;gt;&lt;br /&gt;
Happy hour and networking opps&lt;br /&gt;
&amp;lt;/td&amp;gt;&lt;br /&gt;
&amp;lt;/tr&amp;gt;&lt;br /&gt;
&amp;lt;/table&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Thank You To Our Sponsors ==&lt;br /&gt;
&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security]&lt;br /&gt;
&lt;br /&gt;
[http://www.go-integral.com/ Integral Business Solutions]&lt;br /&gt;
&lt;br /&gt;
[http://www.umn.edu/ University of Minnesota]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=36975</id>
		<title>Minneapolis St Paul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Minneapolis_St_Paul&amp;diff=36975"/>
				<updated>2008-08-23T01:48:19Z</updated>
		
		<summary type="html">&lt;p&gt;Afongen: added registration link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Minneapolis St Paul|extra=The chapter leader is [Kuai]|mailinglistsite=https://lists.owasp.org/mailman/listinfo/owasp-twincities|emailarchives=https://lists.owasp.org/pipermail/owasp-twincities}}&lt;br /&gt;
&amp;lt;paypal&amp;gt;Minneapolis St Paul&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== September meeting: Tuesday, September 9 at 6:00 pm ==&lt;br /&gt;
&lt;br /&gt;
=== Jeremiah Grossman: Get Rich or Die Trying - Making Money on The Web, The Black Hat Way ===&lt;br /&gt;
Forget Cross-Site Scripting. Forget SQL Injection. If you want to make some serious cash on the Web silently and surreptitiously, you don't need them. You also don't need noisy scanners, sophisticated proxies, 0-days, or ninja level reverse engineering skills -- all you need is a Web browser, a clue on what to look for, and a few black hat tricks. Generating affiliate advertising revenue from the Website traffic of others, trade stock using corporation information passively gleaned, inhibit the online purchase of sought after items creating artificial scarcity, and so much more. Activities not technically illegal, only violating terms of service.&lt;br /&gt;
&lt;br /&gt;
You may have heard these referred to as business logic flaws, but that name really doesn't do them justice. It sounds so academic and benign in that context when the truth is anything but. These are not the same ol' Web hacker attack techniques everyone is familiar with, but the one staring you in the face and missed because gaming a system and making money this way couldn't be that simple. Plus IDS can't detect them and Web application firewalls can't black them. If fact, these types of attacks are so hard to detect (if anyone is actually trying) we aren't even sure how widespread their use actually is. Time to pull back the cover and expose what's possible. &lt;br /&gt;
&lt;br /&gt;
==== Speaker Bio ====&lt;br /&gt;
Jeremiah Grossman is the founder and CTO of WhiteHat Security, considered a world-renowned expert in Web security, co-founder of the Web Application Security Consortium, and named to InfoWorld's Top 25 CTOs for 2007. Mr. Grossman is a frequent speaker at industry events including the BlackHat Briefings, RSA, ISACA, CSI, HiTB, OWASP, Vanguard, ISSA, Defcon, and a number of large universities. He has authored dozens of articles and white papers; is credited with the discovery of many cutting-edge attack and defensive techniques; and is a co-author of XSS Attacks. Mr. Grossman is frequently quoted in major media publications such as InfoWorld, USA Today, PCWorld, Dark Reading, SC Magazine, SecurityFocus, CNet, SC Magazine, CSO, and InformationWeek. Prior to WhiteHat he was an information security officer at Yahoo!&lt;br /&gt;
&lt;br /&gt;
==== Agenda: ====&lt;br /&gt;
&lt;br /&gt;
  6:00 pm - Introduction and Optional sign-in for CISSP credits&lt;br /&gt;
  6:10 pm - Welcome: OWASP chapter updates, conference announcement&lt;br /&gt;
  6:30 pm – Break&lt;br /&gt;
  6:45 pm – Jeremiah Grossman&lt;br /&gt;
  8:15 pm - Upcoming Events reminder and meeting wrap-up &lt;br /&gt;
&lt;br /&gt;
==== Register ====&lt;br /&gt;
&lt;br /&gt;
Please help us anticipate attendance: '''[http://www.go-integral.net/node/231 register online]'''.&lt;br /&gt;
&lt;br /&gt;
==== Location ====&lt;br /&gt;
&lt;br /&gt;
[http://www.minneapolis.edu/ Minneapolis Community and Technical College]&amp;lt;br /&amp;gt;&lt;br /&gt;
1501 Hennepin Ave, Minneapolis&amp;lt;br /&amp;gt;&lt;br /&gt;
Whitney Center, Room L3100 (3rd Floor)&lt;br /&gt;
&lt;br /&gt;
'''Map''': http://www.minneapolis.edu/campusmaps/&lt;br /&gt;
&lt;br /&gt;
Park in the ramp (R) - move through the T building (T) and go to Whitney Hall (L).&lt;br /&gt;
&lt;br /&gt;
==== Thank You ====&lt;br /&gt;
[http://www.strategicit.org/ Center for Strategic Information Technology and Security] for sponsoring our location.&amp;lt;br /&amp;gt;&lt;br /&gt;
[[Image:MN-center-strategic-it-security.gif]]&lt;br /&gt;
&lt;br /&gt;
We are still looking for a book give-away sponsor and for sponsors for upcoming meetings.&lt;br /&gt;
Call Lorna at 651-338-0243 if you need directions or have questions.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Materials from the July 7 meeting (Gunnar Peterson - Breaking Web Services) ==&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/b/b9/OWASP-MSP-GunnarPetersonHandout20080707.pdf Handout for the presentation (PDF)]&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Video (1 of 2) of the presentation (Google Video - original aspect ratio)]&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en  Video (2 of 2) of the presentation (Google Video - distorted aspect ratio)]&lt;br /&gt;
&lt;br /&gt;
== Other Upcoming Speakers: ==&lt;br /&gt;
''' Jeff Williams '''  - We are in the process of organizing a '''mini conference''' in October 2008 and are pleased to announce that Jeff Williams has accepted our invitation to be our keynote speaker for this event. Jeff Williams is one of the founders of and is a board member of OWASP. He is also CEO of [http://www.aspectsecurity.com/ Aspect Security]. Stay tuned for more details!&lt;br /&gt;
&lt;br /&gt;
== Videos ==&lt;br /&gt;
&lt;br /&gt;
Videos of several past meetings are available at https://www.owasp.org/index.php/Category:OWASP_Video#Videos&lt;br /&gt;
&lt;br /&gt;
'''Most recent videos:'''&lt;br /&gt;
&lt;br /&gt;
Gunnar Peterson - Breaking Web Services - OWASP (MSP) - 7 July 2008 ([http://video.google.com/videoplay?docid=-7859027646762182620&amp;amp;hl=en Part 1] of 2 - original aspect ratio) ([http://video.google.com/videoplay?docid=-7066675474788394571&amp;amp;hl=en Part 2] of 2 - distorted aspect ratio)&lt;br /&gt;
&lt;br /&gt;
[http://video.google.com/videoplay?docid=7535038243903138173&amp;amp;hl=en Tony Stieber - How NOT to Implement Encryption for the OWASP Top 10 - OWASP (MSP) - 16 June 2008]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;h2&amp;gt;Upcoming Events:&amp;lt;/h2&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;We are working on a '''mini conference in Minneapolis''' for the week of October 21st. We are still working on the logistics, but we promise this is going to be an interesting and unique event with lots of great speakers and opportunities to participate. Stay tuned for more information. Also, please feel free to submit suggestions for this event and post an email to the mailing list owasp-twincities_at_lists.owasp.org&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;We are looking for sponsors! Contact Kuai or Lorna if you are interested - any contributions to the local chapter would be highly appreciated.&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''DC612''' meetings&amp;lt;br /&amp;gt;&lt;br /&gt;
2nd Thursday of the month&amp;lt;br /&amp;gt;&lt;br /&gt;
http://www.dc612.org/&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt; &lt;br /&gt;
'''MN ISSA-''' Meets on Tuesday, September 16, 2008, at the Four Points Sheraton, 1330 Industrial Blvd. Mpls, MN. For more information on speakers and topics.&lt;br /&gt;
http://www.mn-issa.org/html/chaptermeetings.html&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;'''OWASP NYC AppSec 2008''' Sept 24-25th - Don't miss the [http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference/ NYC AppSec conference]! &amp;lt;br /&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference http://www.owasp.org/images/6/61/Banner2_irfan.jpg]&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Minnesota]]&lt;/div&gt;</summary>
		<author><name>Afongen</name></author>	</entry>

	</feed>