<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Alessio.marziali</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Alessio.marziali"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Alessio.marziali"/>
		<updated>2026-05-28T04:02:25Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=76998</id>
		<title>GPC Project Details/OWASP Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=76998"/>
				<updated>2010-01-26T19:25:04Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:OWASP Project|Code Crawler Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Download]]&lt;br /&gt;
[[Category:OWASP Beta Quality Tool]]&lt;br /&gt;
&lt;br /&gt;
{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP Project Identification Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Code Crawler&lt;br /&gt;
| project_description = A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. It's a Microsoft .NET 3.5 Windows Form application which supports the OWASP Code Review Project. It provides automatic STRIDE classification a very simple DREAD calculator and few minor utilities. Direct links to WAST 2.0 Threat Classification, Secure Java Development Guidelines and OWASP Tools are also part of the package.&lt;br /&gt;
| project_license = [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution Share Alike 3.0] &lt;br /&gt;
| leader_name = Alessio Marziali&lt;br /&gt;
| leader_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| leader_username = Alessio.marziali&lt;br /&gt;
| past_leaders_special_contributions = &lt;br /&gt;
| maintainer_name = Alessio Marziali&lt;br /&gt;
| maintainer_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| maintainer_username =  &lt;br /&gt;
| contributor_name1 = SasiKumar Ganesan&lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 =  &lt;br /&gt;
| contributor_name2 = Tripurari Rai&lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| presentation_link = https://www.owasp.org/images/6/61/OWASP_CodeCrawler_Presentation.ppt&lt;br /&gt;
| mailing_list_name = owasp-code-crawler&lt;br /&gt;
| links_url1 = http://www.cyphersec.com/category/code-review/code-crawler/&lt;br /&gt;
| links_name1 = Development Informations&lt;br /&gt;
| links_url2 = http://codecrawler.codeplex.com/&lt;br /&gt;
| links_name2 = Development Website&lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = :OWASP_Summer_of_Code_2008_Applications_-_Need_Futher_Clarifications#Code_Crawler&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = OWASP Code Crawler 2.5.1&lt;br /&gt;
| current_release_date = Jan 23 2010&lt;br /&gt;
| current_release_download_link = http://codecrawler.codeplex.com&lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = Alessio Marziali&lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = Alessio.marziali&lt;br /&gt;
| current_release_details = :Category:OWASP Code Crawler - Release 2.5.1&lt;br /&gt;
| last_reviewed_release_name = Code Crwaler/OWASP SoC 08&lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = 2&lt;br /&gt;
| last_reviewed_release_leader_name = Alessio Marziali&lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = Alessio.marziali&lt;br /&gt;
| last_reviewed_release_details = [http://www.owasp.org/index.php/Project_Information:template_Code_Crawler  Main links, release roadmap and assessment]&lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
| last_GPC_update = 2/10/2009&lt;br /&gt;
| GPC_Notes = Empty template&lt;br /&gt;
| project_home_page = Category:OWASP_Code_Crawler &lt;br /&gt;
| project_details_wiki_page = GPC_Project_Details/OWASP_Code_Crawler&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=76662</id>
		<title>User:Alessio.marziali</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=76662"/>
				<updated>2010-01-23T18:32:39Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Alessio Marziali's [profile], [http://mailhide.recaptcha.net/d?k=01tiBAe7aGawzMPsVmHjYbJA==&amp;amp;c=YoLeS4i7f3DC0sG0BBPqNBpC1FxXafZUnjOkQeKUczw= mail address] and &lt;br /&gt;
&lt;br /&gt;
== Profile ==&lt;br /&gt;
&lt;br /&gt;
Alessio Marziali (MCTS) is a Security Consultant, published technical author with two ASP.NET books currently available for purchase and OWASP Code Crawler Project Leader based in London.&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Crawler ==&lt;br /&gt;
&lt;br /&gt;
At OWASP Alessio is the Project Leader of OWASP CodeCrawler a tool aimed at assisting code review practitioners. It is a static code review tool built using the latest version of Microsoft .NET Framework which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for Java and .NET software.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=76661</id>
		<title>User:Alessio.marziali</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=76661"/>
				<updated>2010-01-23T18:32:04Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Alessio Marziali's [profile], [http://mailhide.recaptcha.net/d?k=01tiBAe7aGawzMPsVmHjYbJA==&amp;amp;c=YoLeS4i7f3DC0sG0BBPqNBpC1FxXafZUnjOkQeKUczw= mail address] and &lt;br /&gt;
&lt;br /&gt;
== Profile ==&lt;br /&gt;
&lt;br /&gt;
Alessio Marziali (MCTS) is a Security Consultant, published technical author with two ASP.NET books currently available for purchase and OWASP Code Crawler Project Leader based in London.&lt;br /&gt;
&lt;br /&gt;
On 2007 he received a media coverage for documenting major vulnerabilities on 27 different Italian's governament web sites.&lt;br /&gt;
&lt;br /&gt;
Alessio has also authored ''two books on Microsoft ASP.NET'' (2.0 and 3.5)&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Crawler ==&lt;br /&gt;
&lt;br /&gt;
At OWASP Alessio is the Project Leader of OWASP CodeCrawler a tool aimed at assisting code review practitioners. It is a static code review tool built using the latest version of Microsoft .NET Framework which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for Java and .NET software.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=75670</id>
		<title>GPC Project Details/OWASP Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=75670"/>
				<updated>2010-01-04T15:33:58Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:OWASP Project|Code Crawler Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Download]]&lt;br /&gt;
[[Category:OWASP Beta Quality Tool]]&lt;br /&gt;
&lt;br /&gt;
{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP Project Identification Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Code Crawler&lt;br /&gt;
| project_description = A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. It's a Microsoft .NET 3.5 Windows Form application which supports the OWASP Code Review Project, currently the development team is working on implementing a new engine and increase compatibility with Microsoft Visual Studio. A new release of OWASP Code Crawler is planned to be released end of October along with new functionalities and documentation.&lt;br /&gt;
| project_license = [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution Share Alike 3.0] &lt;br /&gt;
| leader_name = Alessio Marziali&lt;br /&gt;
| leader_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| leader_username = Alessio.marziali&lt;br /&gt;
| past_leaders_special_contributions = &lt;br /&gt;
| maintainer_name = Alessio Marziali&lt;br /&gt;
| maintainer_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| maintainer_username =  &lt;br /&gt;
| contributor_name1 = SasiKumar Ganesan&lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 =  &lt;br /&gt;
| contributor_name2 = Tripurari Rai&lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| presentation_link = https://www.owasp.org/images/6/61/OWASP_CodeCrawler_Presentation.ppt&lt;br /&gt;
| mailing_list_name = owasp-code-crawler&lt;br /&gt;
| links_url1 = http://www.cyphersec.com/category/code-review/code-crawler/&lt;br /&gt;
| links_name1 = Development Informations&lt;br /&gt;
| links_url2 = http://codecrawler.codeplex.com/&lt;br /&gt;
| links_name2 = Development Website&lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = :OWASP_Summer_of_Code_2008_Applications_-_Need_Futher_Clarifications#Code_Crawler&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = OWASP Code Crawler 2.4&lt;br /&gt;
| current_release_date = Sep 17 2009&lt;br /&gt;
| current_release_download_link = http://codecrawler.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=33132&lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = Alessio Marziali&lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = Alessio.marziali&lt;br /&gt;
| current_release_details = :Category:OWASP Code Crawler - Release 2.4 &lt;br /&gt;
| last_reviewed_release_name = Code Crwaler/OWASP SoC 08&lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = 2&lt;br /&gt;
| last_reviewed_release_leader_name = Alessio Marziali&lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = Alessio.marziali&lt;br /&gt;
| last_reviewed_release_details = [http://www.owasp.org/index.php/Project_Information:template_Code_Crawler  Main links, release roadmap and assessment]&lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
| last_GPC_update = 2/10/2009&lt;br /&gt;
| GPC_Notes = Empty template&lt;br /&gt;
| project_home_page = Category:OWASP_Code_Crawler &lt;br /&gt;
| project_details_wiki_page = GPC_Project_Details/OWASP_Code_Crawler&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=71722</id>
		<title>User:Alessio.marziali</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=71722"/>
				<updated>2009-10-19T17:45:56Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Alessio Marziali's [profile], [http://mailhide.recaptcha.net/d?k=01tiBAe7aGawzMPsVmHjYbJA==&amp;amp;c=YoLeS4i7f3DC0sG0BBPqNBpC1FxXafZUnjOkQeKUczw= mail address] and &lt;br /&gt;
&lt;br /&gt;
== Profile ==&lt;br /&gt;
&lt;br /&gt;
Alessio is an eight years experienced Web Developer specialised in building bespoke secure financial systems using a broad range of Microsoft technologies.&lt;br /&gt;
&lt;br /&gt;
Alessio has relevant experience on ''Web Penetration Testing'' and code auditing carried on with both technical and security approaches against different types of web systems on client side.&lt;br /&gt;
&lt;br /&gt;
Alessio has proven skills and abilities to handle extended web2 enabled projects from the design both UI design and technical architecture to a stable and reliable stage while using Microsoft and Owasp patterns.&lt;br /&gt;
&lt;br /&gt;
Being active on the scene for the last 8 years, and having worked on different kind of projects and clients, Alessio posses a strong knowledge that encompass many technologies related to software and web application development on Microsoft environments.&lt;br /&gt;
&lt;br /&gt;
On 2007 he received a media coverage for documenting major vulnerabilities on 27 different Italian's governament web sites.&lt;br /&gt;
&lt;br /&gt;
Alessio has also authored ''two books on Microsoft ASP.NET'' (2.0 and 3.5)&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Crawler ==&lt;br /&gt;
&lt;br /&gt;
At OWASP Alessio is the Project Leader of OWASP CodeCrawler a tool aimed at assisting code review practitioners. It is a static code review tool built using the latest version of Microsoft .NET Framework which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for Java and .NET software.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=71721</id>
		<title>User:Alessio.marziali</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=71721"/>
				<updated>2009-10-19T17:44:56Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* Profile */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Alessio Marziali's [profile], [mailto:alessio.marziali@cyphersec.com mail address] and &lt;br /&gt;
&lt;br /&gt;
== Profile ==&lt;br /&gt;
&lt;br /&gt;
Alessio is an eight years experienced Web Developer specialised in building bespoke secure financial systems using a broad range of Microsoft technologies.&lt;br /&gt;
&lt;br /&gt;
Alessio has relevant experience on ''Web Penetration Testing'' and code auditing carried on with both technical and security approaches against different types of web systems on client side.&lt;br /&gt;
&lt;br /&gt;
Alessio has proven skills and abilities to handle extended web2 enabled projects from the design both UI design and technical architecture to a stable and reliable stage while using Microsoft and Owasp patterns.&lt;br /&gt;
&lt;br /&gt;
Being active on the scene for the last 8 years, and having worked on different kind of projects and clients, Alessio posses a strong knowledge that encompass many technologies related to software and web application development on Microsoft environments.&lt;br /&gt;
&lt;br /&gt;
On 2007 he received a media coverage for documenting major vulnerabilities on 27 different Italian's governament web sites.&lt;br /&gt;
&lt;br /&gt;
Alessio has also authored ''two books on Microsoft ASP.NET'' (2.0 and 3.5)&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Crawler ==&lt;br /&gt;
&lt;br /&gt;
At OWASP Alessio is the Project Leader of OWASP CodeCrawler a tool aimed at assisting code review practitioners. It is a static code review tool built using the latest version of Microsoft .NET Framework which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for Java and .NET software.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=71437</id>
		<title>GPC Project Details/OWASP Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=71437"/>
				<updated>2009-10-13T15:03:09Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:OWASP Project|Code Crawler Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Download]]&lt;br /&gt;
[[Category:OWASP Beta Quality Tool]]&lt;br /&gt;
&lt;br /&gt;
{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP Project Identification Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Code Crawler&lt;br /&gt;
| project_description = A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. It's a Microsoft .NET 3.5 Windows Form application which supports the OWASP Code Review Project, currently the development team is working on implementing a new engine and increase compatibility with Microsoft Visual Studio. A new release of OWASP Code Crawler is planned to be released end of October along with new functionalities and documentation.&lt;br /&gt;
| project_license = [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution Share Alike 3.0] &lt;br /&gt;
| leader_name = Alessio Marziali&lt;br /&gt;
| leader_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| leader_username = Alessio.marziali&lt;br /&gt;
| past_leaders_special_contributions = TBD&lt;br /&gt;
| maintainer_name = Alessio Marziali&lt;br /&gt;
| maintainer_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| maintainer_username =  &lt;br /&gt;
| contributor_name1 = SasiKumar Ganesan&lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 =  &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| presentation_link = https://www.owasp.org/images/6/61/OWASP_CodeCrawler_Presentation.ppt&lt;br /&gt;
| mailing_list_name = owasp-code-crawler&lt;br /&gt;
| links_url1 = http://www.cyphersec.com/category/code-review/code-crawler/&lt;br /&gt;
| links_name1 = Development Informations&lt;br /&gt;
| links_url2 = http://codecrawler.codeplex.com/&lt;br /&gt;
| links_name2 = Development Website&lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = :Category:OWASP XXXXXX Project - Roadmap&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = OWASP Code Crawler 2.4&lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = http://codecrawler.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=33132&lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = Alessio Marziali&lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = Alessio.marziali&lt;br /&gt;
| current_release_details = &lt;br /&gt;
| last_reviewed_release_name = Code Crwaler/OWASP SoC 08&lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = 2&lt;br /&gt;
| last_reviewed_release_leader_name = Alessio Marziali&lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = Alessio.marziali&lt;br /&gt;
| last_reviewed_release_details = [http://www.owasp.org/index.php/Project_Information:template_Code_Crawler  Main links, release roadmap and assessment]&lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
| last_GPC_update = 2/10/2009&lt;br /&gt;
| GPC_Notes = Empty template&lt;br /&gt;
| project_home_page = Category:OWASP_Code_Crawler &lt;br /&gt;
| project_details_wiki_page = GPC_Project_Details/OWASP_Code_Crawler&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=71436</id>
		<title>GPC Project Details/OWASP Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=71436"/>
				<updated>2009-10-13T15:02:34Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:OWASP Project|Code Crawler Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Download]]&lt;br /&gt;
[[Category:OWASP Beta Quality Tool]]&lt;br /&gt;
&lt;br /&gt;
{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP Project Identification Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Code Crawler&lt;br /&gt;
| project_description = A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. It's a Microsoft .NET 3.5 Windows Form application which supports the OWASP Code Review Project, currently the development team is working on implementing a new engine and increase compatibility with Microsoft Visual Studio. A new release of OWASP Code Crawler is planned to be released end of October along with new functionalities and documentation.&lt;br /&gt;
| project_license = [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution Share Alike 3.0] &lt;br /&gt;
| leader_name = Alessio Marziali&lt;br /&gt;
| leader_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| leader_username = Alessio.marziali&lt;br /&gt;
| past_leaders_special_contributions = TBD&lt;br /&gt;
| maintainer_name = Alessio Marziali&lt;br /&gt;
| maintainer_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| maintainer_username =  &lt;br /&gt;
| contributor_name1 = SasiKumar Ganesan&lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 =  &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| presentation_link = https://www.owasp.org/images/6/61/OWASP_CodeCrawler_Presentation.ppt&lt;br /&gt;
| mailing_list_name = owasp-code-crawler&lt;br /&gt;
| links_url1 = http://www.cyphersec.com/category/code-review/code-crawler/&lt;br /&gt;
| links_name1 = Development Informations&lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = :Category:OWASP XXXXXX Project - Roadmap&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = OWASP Code Crawler 2.4&lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = http://codecrawler.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=33132&lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = Alessio Marziali&lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = Alessio.marziali&lt;br /&gt;
| current_release_details = &lt;br /&gt;
| last_reviewed_release_name = Code Crwaler/OWASP SoC 08&lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = 2&lt;br /&gt;
| last_reviewed_release_leader_name = Alessio Marziali&lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = Alessio.marziali&lt;br /&gt;
| last_reviewed_release_details = [http://www.owasp.org/index.php/Project_Information:template_Code_Crawler  Main links, release roadmap and assessment]&lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
| last_GPC_update = 2/10/2009&lt;br /&gt;
| GPC_Notes = Empty template&lt;br /&gt;
| project_home_page = Category:OWASP_Code_Crawler &lt;br /&gt;
| project_details_wiki_page = GPC_Project_Details/OWASP_Code_Crawler&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=71435</id>
		<title>GPC Project Details/OWASP Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=71435"/>
				<updated>2009-10-13T14:59:54Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:OWASP Project|Code Crawler Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Download]]&lt;br /&gt;
[[Category:OWASP Beta Quality Tool]]&lt;br /&gt;
&lt;br /&gt;
{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP Project Identification Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Code Crawler&lt;br /&gt;
| project_description = A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. It's a Microsoft .NET 3.5 Windows Form application which supports the OWASP Code Review Project, currently the development team is working on implementing a new engine and increase compatibility with Microsoft Visual Studio. A new release of OWASP Code Crawler is planned to be released end of October along with new functionalities and documentation.&lt;br /&gt;
| project_license = [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution Share Alike 3.0] &lt;br /&gt;
| leader_name = Alessio Marziali&lt;br /&gt;
| leader_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| leader_username = Alessio.marziali&lt;br /&gt;
| past_leaders_special_contributions = TBD&lt;br /&gt;
| maintainer_name = Alessio Marziali&lt;br /&gt;
| maintainer_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| maintainer_username =  &lt;br /&gt;
| contributor_name1 = SasiKumar Ganesan&lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 =  &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| presentation_link = https://www.owasp.org/images/6/61/OWASP_CodeCrawler_Presentation.ppt&lt;br /&gt;
| mailing_list_name = owasp-code-crawler&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = :Category:OWASP XXXXXX Project - Roadmap&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = OWASP Code Crawler 2.4&lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = http://codecrawler.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=33132&lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = Alessio Marziali&lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = Alessio.marziali&lt;br /&gt;
| current_release_details = &lt;br /&gt;
| last_reviewed_release_name = Code Crwaler/OWASP SoC 08&lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = 2&lt;br /&gt;
| last_reviewed_release_leader_name = Alessio Marziali&lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = Alessio.marziali&lt;br /&gt;
| last_reviewed_release_details = [http://www.owasp.org/index.php/Project_Information:template_Code_Crawler  Main links, release roadmap and assessment]&lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
| last_GPC_update = 2/10/2009&lt;br /&gt;
| GPC_Notes = Empty template&lt;br /&gt;
| project_home_page = Category:OWASP_Code_Crawler &lt;br /&gt;
| project_details_wiki_page = GPC_Project_Details/OWASP_Code_Crawler&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=71433</id>
		<title>GPC Project Details/OWASP Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=71433"/>
				<updated>2009-10-13T14:56:09Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:OWASP Project|Code Crawler Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Download]]&lt;br /&gt;
[[Category:OWASP Beta Quality Tool]]&lt;br /&gt;
&lt;br /&gt;
{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP Project Identification Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Code Crawler&lt;br /&gt;
| project_description = A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities. &lt;br /&gt;
| project_license = [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution Share Alike 3.0] &lt;br /&gt;
| leader_name = Alessio Marziali&lt;br /&gt;
| leader_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| leader_username = Alessio.marziali&lt;br /&gt;
| past_leaders_special_contributions = TBD&lt;br /&gt;
| maintainer_name = Alessio Marziali&lt;br /&gt;
| maintainer_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| maintainer_username =  &lt;br /&gt;
| contributor_name1 = SasiKumar Ganesan&lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 =  &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| presentation_link = https://www.owasp.org/images/6/61/OWASP_CodeCrawler_Presentation.ppt&lt;br /&gt;
| mailing_list_name = owasp-code-crawler&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = :Category:OWASP XXXXXX Project - Roadmap&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = OWASP Code Crawler 2.4&lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = http://codecrawler.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=33132&lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = Alessio Marziali&lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = Alessio.marziali&lt;br /&gt;
| current_release_details = &lt;br /&gt;
| last_reviewed_release_name = Code Crwaler/OWASP SoC 08&lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = 2&lt;br /&gt;
| last_reviewed_release_leader_name = Alessio Marziali&lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = Alessio.marziali&lt;br /&gt;
| last_reviewed_release_details = [http://www.owasp.org/index.php/Project_Information:template_Code_Crawler  Main links, release roadmap and assessment]&lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
| last_GPC_update = 2/10/2009&lt;br /&gt;
| GPC_Notes = Empty template&lt;br /&gt;
| project_home_page = Category:OWASP_Code_Crawler &lt;br /&gt;
| project_details_wiki_page = GPC_Project_Details/OWASP_Code_Crawler&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=71431</id>
		<title>GPC Project Details/OWASP Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=71431"/>
				<updated>2009-10-13T14:55:13Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:OWASP Project|Code Crawler Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Download]]&lt;br /&gt;
[[Category:OWASP Beta Quality Tool]]&lt;br /&gt;
&lt;br /&gt;
{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP Project Identification Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Code Crawler&lt;br /&gt;
| project_description = A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities. &lt;br /&gt;
| project_license = [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution Share Alike 3.0] &lt;br /&gt;
| leader_name = Alessio Marziali&lt;br /&gt;
| leader_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| leader_username = Alessio.marziali&lt;br /&gt;
| past_leaders_special_contributions = TBD&lt;br /&gt;
| maintainer_name = Alessio Marziali&lt;br /&gt;
| maintainer_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| maintainer_username =  &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 =  &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| presentation_link = https://www.owasp.org/images/6/61/OWASP_CodeCrawler_Presentation.ppt&lt;br /&gt;
| mailing_list_name = owasp-code-crawler&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = :Category:OWASP XXXXXX Project - Roadmap&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = OWASP Code Crawler 2.4&lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = http://codecrawler.codeplex.com/Release/ProjectReleases.aspx?ReleaseId=33132&lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = Alessio Marziali&lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = Alessio.marziali&lt;br /&gt;
| current_release_details = &lt;br /&gt;
| last_reviewed_release_name = Code Crwaler/OWASP SoC 08&lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = 2&lt;br /&gt;
| last_reviewed_release_leader_name = Alessio Marziali&lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = Alessio.marziali&lt;br /&gt;
| last_reviewed_release_details = [http://www.owasp.org/index.php/Project_Information:template_Code_Crawler  Main links, release roadmap and assessment]&lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
| last_GPC_update = 2/10/2009&lt;br /&gt;
| GPC_Notes = Empty template&lt;br /&gt;
| project_home_page = Category:OWASP_Code_Crawler &lt;br /&gt;
| project_details_wiki_page = GPC_Project_Details/OWASP_Code_Crawler&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=71430</id>
		<title>GPC Project Details/OWASP Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GPC_Project_Details/OWASP_Code_Crawler&amp;diff=71430"/>
				<updated>2009-10-13T14:50:40Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Category:OWASP Project|Code Crawler Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Download]]&lt;br /&gt;
[[Category:OWASP Beta Quality Tool]]&lt;br /&gt;
&lt;br /&gt;
{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP Project Identification Tab&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Code Crawler&lt;br /&gt;
| project_description = A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities. &lt;br /&gt;
| project_license = [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution Share Alike 3.0] &lt;br /&gt;
| leader_name = Alessio Marziali&lt;br /&gt;
| leader_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| leader_username = Alessio.marziali&lt;br /&gt;
| past_leaders_special_contributions = TBD&lt;br /&gt;
| maintainer_name = Alessio Marziali&lt;br /&gt;
| maintainer_email = alessio.marziali@cyphersec.com&lt;br /&gt;
| maintainer_username =  &lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 =  &lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
| contributor_name3 = &lt;br /&gt;
| contributor_email3 = &lt;br /&gt;
| contributor_username3 = &lt;br /&gt;
| contributor_name4 = &lt;br /&gt;
| contributor_email4 = &lt;br /&gt;
| contributor_username4 = &lt;br /&gt;
| contributor_name5 = &lt;br /&gt;
| contributor_email5 = &lt;br /&gt;
| contributor_username5 = &lt;br /&gt;
| contributor_name6 = &lt;br /&gt;
| contributor_email6 = &lt;br /&gt;
| contributor_username6 = &lt;br /&gt;
| contributor_name7 = &lt;br /&gt;
| contributor_email7 = &lt;br /&gt;
| contributor_username7 = &lt;br /&gt;
| contributor_name8 = &lt;br /&gt;
| contributor_email8 = &lt;br /&gt;
| contributor_username8 = &lt;br /&gt;
| contributor_name9 = &lt;br /&gt;
| contributor_email9 = &lt;br /&gt;
| contributor_username9 = &lt;br /&gt;
| contributor_name10 = &lt;br /&gt;
| contributor_email10 = &lt;br /&gt;
| contributor_username10 =  &lt;br /&gt;
| pamphlet_link = &lt;br /&gt;
| presentation_link = https://www.owasp.org/images/6/61/OWASP_CodeCrawler_Presentation.ppt&lt;br /&gt;
| mailing_list_name = owasp-code-crawler&lt;br /&gt;
| links_url1 = &lt;br /&gt;
| links_name1 = &lt;br /&gt;
| links_url2 = &lt;br /&gt;
| links_name2 = &lt;br /&gt;
| links_url3 = &lt;br /&gt;
| links_name3 = &lt;br /&gt;
| links_url4 = &lt;br /&gt;
| links_name4 = &lt;br /&gt;
| links_url5 = &lt;br /&gt;
| links_name5 = &lt;br /&gt;
| links_url6 = &lt;br /&gt;
| links_name6 = &lt;br /&gt;
| links_url7 = &lt;br /&gt;
| links_name7 = &lt;br /&gt;
| links_url8 = &lt;br /&gt;
| links_name8 = &lt;br /&gt;
| links_url9 = &lt;br /&gt;
| links_name9 = &lt;br /&gt;
| links_url10 = &lt;br /&gt;
| links_name10 = &lt;br /&gt;
| project_road_map = :Category:OWASP XXXXXX Project - Roadmap&lt;br /&gt;
| project_health_status = &lt;br /&gt;
| current_release_name = First Release&lt;br /&gt;
| current_release_date = &lt;br /&gt;
| current_release_download_link = &lt;br /&gt;
| current_release_rating = &lt;br /&gt;
| current_release_leader_name = Alessio Marziali&lt;br /&gt;
| current_release_leader_email = &lt;br /&gt;
| current_release_leader_username = Alessio.marziali&lt;br /&gt;
| current_release_details = &lt;br /&gt;
| last_reviewed_release_name = Code Crwaler/OWASP SoC 08&lt;br /&gt;
| last_reviewed_release_date = &lt;br /&gt;
| last_reviewed_release_download_link = &lt;br /&gt;
| last_reviewed_release_rating = 2&lt;br /&gt;
| last_reviewed_release_leader_name = Alessio Marziali&lt;br /&gt;
| last_reviewed_release_leader_email = &lt;br /&gt;
| last_reviewed_release_leader_username = Alessio.marziali&lt;br /&gt;
| last_reviewed_release_details = [http://www.owasp.org/index.php/Project_Information:template_Code_Crawler  Main links, release roadmap and assessment]&lt;br /&gt;
| old_release_name1 = &lt;br /&gt;
| old_release_date1 = &lt;br /&gt;
| old_release_download_link1 = &lt;br /&gt;
| old_release_name2 = &lt;br /&gt;
| old_release_date2 = &lt;br /&gt;
| old_release_download_link2 = &lt;br /&gt;
| old_release_name3 = &lt;br /&gt;
| old_release_date3 = &lt;br /&gt;
| old_release_download_link3 = &lt;br /&gt;
| old_release_name4 = &lt;br /&gt;
| old_release_date4 = &lt;br /&gt;
| old_release_download_link4 = &lt;br /&gt;
| old_release_name5 = &lt;br /&gt;
| old_release_date5 = &lt;br /&gt;
| old_release_download_link5 = &lt;br /&gt;
| last_GPC_update = 2/10/2009&lt;br /&gt;
| GPC_Notes = Empty template&lt;br /&gt;
| project_home_page = Category:OWASP_Code_Crawler &lt;br /&gt;
| project_details_wiki_page = GPC_Project_Details/OWASP_Code_Crawler&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler&amp;diff=69220</id>
		<title>Project Information:template Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler&amp;diff=69220"/>
				<updated>2009-09-17T16:20:45Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(64, 88, 160) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; colspan=&amp;quot;8&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Project Name''' &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 85%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; colspan=&amp;quot;7&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Code Crawler Project'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Short Project Description''' &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 85%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; colspan=&amp;quot;7&amp;quot; | A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Key Project Information''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 14%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Leader&amp;lt;br&amp;gt;[[User:Alessio.marziali|'''Alessio Marziali''']] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Contributors&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Sasikumar Ganesan&amp;lt;br&amp;gt; &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 10%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Mailing list&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp-code-crawler '''Subscribe here''']&amp;lt;br&amp;gt;[mailto:owasp-code-crawler(at)lists.owasp.org '''Use here'''] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 17%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
License&amp;lt;br&amp;gt;[http://creativecommons.org/licenses/by-sa/3.0/ '''Creative Commons Attribution Share Alike 3.0'''] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 14%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
Project Type&amp;lt;br&amp;gt;[http://www.owasp.org/index.php/Category:OWASP_Project#tab=Beta_Status_Projects '''Tool'''] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Sponsor&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008|'''OWASP SoC 08''']]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Release Status'''&amp;lt;/font&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Main Links'''&amp;lt;/font&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Related Projects'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 29%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''[[:Category:OWASP Project Assessment#Beta_Quality_Tool_Criteria|Beta Quality]]'''&amp;lt;br&amp;gt;[[:Category:OWASP Code Crawler Project - Assessment Frame|Please see here for complete information.]] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 42%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
[https://www.owasp.org/images/6/61/OWASP_CodeCrawler_Presentation.ppt CodeCrawler PPT Presentation]&amp;lt;br&amp;gt;[http://www.cyphersec.com/software_archive/OWASP_Code_Crawler.zip ][http://codeplex.codeplex.com/ OWASP Code Crawler Development's website (Codeplex)]&amp;lt;br&amp;gt;[http://codecrawler.codeplex.com/Release/ProjectReleases.aspx Download Code Crawler (Binary)] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 29%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
[[:Category:OWASP Code Review Project|OWASP Code Review Guide]] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler&amp;diff=69219</id>
		<title>Project Information:template Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler&amp;diff=69219"/>
				<updated>2009-09-17T16:19:06Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; colspan=&amp;quot;8&amp;quot; style=&amp;quot;background: rgb(64, 88, 160) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Project Name''' &lt;br /&gt;
| align=&amp;quot;left&amp;quot; colspan=&amp;quot;7&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 85%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Code Crawler Project'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Short Project Description''' &lt;br /&gt;
| align=&amp;quot;left&amp;quot; colspan=&amp;quot;7&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 85%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Key Project Information''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 14%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Leader&amp;lt;br&amp;gt;[[User:Alessio.marziali|'''Alessio Marziali''']] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Contributors&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Sasikumar Ganesan&amp;lt;br&amp;gt; &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 10%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Mailing list&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp-code-crawler '''Subscribe here''']&amp;lt;br&amp;gt;[mailto:owasp-code-crawler(at)lists.owasp.org '''Use here'''] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 17%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
License&amp;lt;br&amp;gt;[http://creativecommons.org/licenses/by-sa/3.0/ '''Creative Commons Attribution Share Alike 3.0'''] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 14%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
Project Type&amp;lt;br&amp;gt;[http://www.owasp.org/index.php/Category:OWASP_Project#tab=Beta_Status_Projects '''Tool'''] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Sponsor&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008|'''OWASP SoC 08''']]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Release Status'''&amp;lt;/font&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Main Links'''&amp;lt;/font&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Related Projects'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 29%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''[[:Category:OWASP Project Assessment#Beta_Quality_Tool_Criteria|Beta Quality]]'''&amp;lt;br&amp;gt;[[:Category:OWASP Code Crawler Project - Assessment Frame|Please see here for complete information.]] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 42%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
[https://www.owasp.org/images/6/61/OWASP_CodeCrawler_Presentation.ppt CodeCrawler PPT Presentation]&amp;lt;br&amp;gt;[http://www.cyphersec.com/software_archive/OWASP_Code_Crawler.zip CodeCrawler Tool]&amp;lt;br&amp;gt;[http://codeplex.codeplex.com/ OWASP Code Crawler (Codeplex)]&amp;lt;br&amp;gt;[http://codecrawler.codeplex.com/Release/ProjectReleases.aspx Code Crawler Binaries] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 29%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
[[:Category:OWASP Code Review Project|OWASP Code Review Guide]] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler&amp;diff=68689</id>
		<title>Project Information:template Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler&amp;diff=68689"/>
				<updated>2009-09-09T11:35:24Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; colspan=&amp;quot;8&amp;quot; style=&amp;quot;background: rgb(64, 88, 160) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Project Name''' &lt;br /&gt;
| align=&amp;quot;left&amp;quot; colspan=&amp;quot;7&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 85%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Code Crawler Project'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Short Project Description''' &lt;br /&gt;
| align=&amp;quot;left&amp;quot; colspan=&amp;quot;7&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 85%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Key Project Information''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 14%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Leader&amp;lt;br&amp;gt;[[User:Alessio.marziali|'''Alessio Marziali''']] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Contributors&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Sasikumar Ganesan&amp;lt;br&amp;gt; &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 10%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Mailing list&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp-code-crawler '''Subscribe here''']&amp;lt;br&amp;gt;[mailto:owasp-code-crawler(at)lists.owasp.org '''Use here'''] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 17%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
License&amp;lt;br&amp;gt;[http://creativecommons.org/licenses/by-sa/3.0/ '''Creative Commons Attribution Share Alike 3.0'''] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 14%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
Project Type&amp;lt;br&amp;gt;[http://www.owasp.org/index.php/Category:OWASP_Project#tab=Beta_Status_Projects '''Tool'''] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Sponsor&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008|'''OWASP SoC 08''']]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Release Status'''&amp;lt;/font&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Main Links'''&amp;lt;/font&amp;gt; &lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Related Projects'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 29%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''[[:Category:OWASP Project Assessment#Beta_Quality_Tool_Criteria|Beta Quality]]'''&amp;lt;br&amp;gt;[[:Category:OWASP Code Crawler Project - Assessment Frame|Please see here for complete information.]] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 42%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
[https://www.owasp.org/images/6/61/OWASP_CodeCrawler_Presentation.ppt CodeCrawler PPT Presentation]&amp;lt;br&amp;gt;[http://www.cyphersec.com/software_archive/OWASP_Code_Crawler.zip CodeCrawler Tool]&amp;lt;br&amp;gt;[http://codeplex.codeplex.com/ OWASP Code Crawler (Codeplex)]&amp;lt;br&amp;gt;[http://www.cyphersec.com/software_archive/OWASP_Code_Crawler.zip Code Crawler Binaries (265kb)] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 29%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
[[:Category:OWASP Code Review Project|OWASP Code Review Guide]] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler&amp;diff=68688</id>
		<title>Project Information:template Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler&amp;diff=68688"/>
				<updated>2009-09-09T11:31:30Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;----&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(64, 88, 160) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; colspan=&amp;quot;8&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Project Name''' &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 85%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; colspan=&amp;quot;7&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Code Crawler Project'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Short Project Description''' &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 85%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; colspan=&amp;quot;7&amp;quot; | A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Key Project Information''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 14%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Leader&amp;lt;br&amp;gt;[[User:Alessio.marziali|'''Alessio Marziali''']] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Contributors&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;Sasikumar Ganesan&amp;lt;br&amp;gt;&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 10%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Mailing list&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp-code-crawler '''Subscribe here''']&amp;lt;br&amp;gt;[mailto:owasp-code-crawler(at)lists.owasp.org '''Use here'''] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 17%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
License&amp;lt;br&amp;gt;[http://creativecommons.org/licenses/by-sa/3.0/ '''Creative Commons Attribution Share Alike 3.0'''] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 14%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
Project Type&amp;lt;br&amp;gt;[http://www.owasp.org/index.php/Category:OWASP_Project#tab=Beta_Status_Projects '''Tool'''] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 15%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Sponsor&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008|'''OWASP SoC 08''']]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Release Status'''&amp;lt;/font&amp;gt;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Main Links'''&amp;lt;/font&amp;gt;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Related Projects'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 29%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
'''[[:Category:OWASP Project Assessment#Beta_Quality_Tool_Criteria|Beta Quality]]'''&amp;lt;br&amp;gt;[[:Category:OWASP Code Crawler Project - Assessment Frame|Please see here for complete information.]] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 42%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
[https://www.owasp.org/images/6/61/OWASP_CodeCrawler_Presentation.ppt CodeCrawler PPT Presentation]&amp;lt;br&amp;gt;[http://www.cyphersec.com/software_archive/OWASP_Code_Crawler.zip CodeCrawler Tool]&amp;lt;br&amp;gt;[http://www.cyphersec.com/software_archive/OWASP_Code_Crawler_Source.zip Code Crawler Source Code (1.464kb)]&amp;lt;br&amp;gt;[http://www.cyphersec.com/software_archive/OWASP_Code_Crawler.zip Code Crawler Binaries (265kb)] &lt;br /&gt;
&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 29%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
[[:Category:OWASP Code Review Project|OWASP Code Review Guide]] &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=63734</id>
		<title>User:Alessio.marziali</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=63734"/>
				<updated>2009-06-08T10:17:36Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* Profile */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Alessio Marziali's [profile], [mailto:alessio.marziali@cyphersec.com mail address] and &lt;br /&gt;
&lt;br /&gt;
== Profile ==&lt;br /&gt;
&lt;br /&gt;
Alessio is an eight years experienced Agile Web systems engineer specialised in building bespoke secure financial systems using a broad range of Microsoft technologies.&lt;br /&gt;
&lt;br /&gt;
Alessio has relevant experience on ''Web Penetration Testing'' and code auditing carried on with both technical and security approaches against different types of web systems on client side.&lt;br /&gt;
&lt;br /&gt;
Alessio has proven skills and abilities to handle extended web2 enabled projects from the design both UI design and technical architecture to a stable and reliable stage while using Microsoft and Owasp patterns.&lt;br /&gt;
&lt;br /&gt;
Being active on the scene for the last 8 years, and having worked on different kind of projects and clients, Alessio posses a strong knowledge that encompass many technologies related to software and web application development on Microsoft environments.&lt;br /&gt;
&lt;br /&gt;
On 2007 he received a media coverage for documenting major vulnerabilities on 27 different Italian's governament web sites.&lt;br /&gt;
&lt;br /&gt;
Alessio has also authored ''two books on Microsoft ASP.NET'' (2.0 and 3.5)&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Crawler ==&lt;br /&gt;
&lt;br /&gt;
At OWASP Alessio is the Project Leader of OWASP CodeCrawler a tool aimed at assisting code review practitioners. It is a static code review tool built using the latest version of Microsoft .NET Framework which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for Java and .NET software.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=63733</id>
		<title>User:Alessio.marziali</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=63733"/>
				<updated>2009-06-08T10:14:24Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* Profile */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Alessio Marziali's [profile], [mailto:alessio.marziali@cyphersec.com mail address] and &lt;br /&gt;
&lt;br /&gt;
== Profile ==&lt;br /&gt;
&lt;br /&gt;
Alessio is an eight years experienced Agile Web systems engineer specialised in building bespoke secure financial systems using a broad range of Microsoft technologies.&lt;br /&gt;
&lt;br /&gt;
Alessio has relevant experience on ''Web Penetration Testing'' and code auditing carried on with both technical and security approaches against different types of web systems on client side.&lt;br /&gt;
&lt;br /&gt;
Alessio has proven skills and abilities to handle extended web2 enabled projects from the design both UI design and technical architecture to a stable and reliable stage while using Microsoft and Owasp patterns.&lt;br /&gt;
&lt;br /&gt;
Being active on the scene for the last 8 years, and having worked on different kind of projects and clients, Alessio posses a strong knowledge that encompass many technologies related to software and web application development on Microsoft environments.&lt;br /&gt;
&lt;br /&gt;
On 2007 he received a medica coverage for documenting major vulnerabilities on 27 different Italian's governament web sites.&lt;br /&gt;
&lt;br /&gt;
Alessio has also authored ''two books on Microsoft ASP.NET'' (2.0 and 3.5)&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Crawler ==&lt;br /&gt;
&lt;br /&gt;
At OWASP Alessio is the Project Leader of OWASP CodeCrawler a tool aimed at assisting code review practitioners. It is a static code review tool built using the latest version of Microsoft .NET Framework which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for Java and .NET software.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=63732</id>
		<title>User:Alessio.marziali</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=63732"/>
				<updated>2009-06-08T10:08:34Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* OWASP Code Crawler */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Alessio Marziali's [profile], [mailto:alessio.marziali@cyphersec.com mail address] and &lt;br /&gt;
&lt;br /&gt;
== Profile ==&lt;br /&gt;
&lt;br /&gt;
Alessio is an eight years experienced Agile Web systems engineer specialised in building bespoke secure financial systems using a broad range of Microsoft technologies.&lt;br /&gt;
&lt;br /&gt;
Alessio has relevant experience on ''Web Penetration Testing'' and code auditing carried on with both technical and security approaches against different types of web systems on client side.&lt;br /&gt;
&lt;br /&gt;
Alessio has proven skills and abilities to handle extended web2 enabled projects from the design both UI design and technical architecture to a stable and reliable stage while using Microsoft and Owasp patterns.&lt;br /&gt;
&lt;br /&gt;
Being active on the scene for the last 8 years, and having worked on different kind of projects and clients, Alessio posses a strong knowledge that encompass many technologies related to software and web application development on Microsoft environments.&lt;br /&gt;
&lt;br /&gt;
Alessio has also authored ''two books on Microsoft ASP.NET'' (2.0 and 3.5)&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Crawler ==&lt;br /&gt;
&lt;br /&gt;
At OWASP Alessio is the Project Leader of OWASP CodeCrawler a tool aimed at assisting code review practitioners. It is a static code review tool built using the latest version of Microsoft .NET Framework which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for Java and .NET software.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=63731</id>
		<title>User:Alessio.marziali</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=63731"/>
				<updated>2009-06-08T10:07:56Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* OWASP Code Crawler */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Alessio Marziali's [profile], [mailto:alessio.marziali@cyphersec.com mail address] and &lt;br /&gt;
&lt;br /&gt;
== Profile ==&lt;br /&gt;
&lt;br /&gt;
Alessio is an eight years experienced Agile Web systems engineer specialised in building bespoke secure financial systems using a broad range of Microsoft technologies.&lt;br /&gt;
&lt;br /&gt;
Alessio has relevant experience on ''Web Penetration Testing'' and code auditing carried on with both technical and security approaches against different types of web systems on client side.&lt;br /&gt;
&lt;br /&gt;
Alessio has proven skills and abilities to handle extended web2 enabled projects from the design both UI design and technical architecture to a stable and reliable stage while using Microsoft and Owasp patterns.&lt;br /&gt;
&lt;br /&gt;
Being active on the scene for the last 8 years, and having worked on different kind of projects and clients, Alessio posses a strong knowledge that encompass many technologies related to software and web application development on Microsoft environments.&lt;br /&gt;
&lt;br /&gt;
Alessio has also authored ''two books on Microsoft ASP.NET'' (2.0 and 3.5)&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Crawler ==&lt;br /&gt;
&lt;br /&gt;
At OWASP Alessio is the Project Leader of OWASP CodeCrawler a tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for Java and .NET software.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=63730</id>
		<title>User:Alessio.marziali</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=63730"/>
				<updated>2009-06-08T10:06:49Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Alessio Marziali's [profile], [mailto:alessio.marziali@cyphersec.com mail address] and &lt;br /&gt;
&lt;br /&gt;
== Profile ==&lt;br /&gt;
&lt;br /&gt;
Alessio is an eight years experienced Agile Web systems engineer specialised in building bespoke secure financial systems using a broad range of Microsoft technologies.&lt;br /&gt;
&lt;br /&gt;
Alessio has relevant experience on ''Web Penetration Testing'' and code auditing carried on with both technical and security approaches against different types of web systems on client side.&lt;br /&gt;
&lt;br /&gt;
Alessio has proven skills and abilities to handle extended web2 enabled projects from the design both UI design and technical architecture to a stable and reliable stage while using Microsoft and Owasp patterns.&lt;br /&gt;
&lt;br /&gt;
Being active on the scene for the last 8 years, and having worked on different kind of projects and clients, Alessio posses a strong knowledge that encompass many technologies related to software and web application development on Microsoft environments.&lt;br /&gt;
&lt;br /&gt;
Alessio has also authored ''two books on Microsoft ASP.NET'' (2.0 and 3.5)&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Crawler ==&lt;br /&gt;
&lt;br /&gt;
At Owasp Alessio is the Project Leader of OWASP CodeCrawler a tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for Java and .NET software.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=63729</id>
		<title>User:Alessio.marziali</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Alessio.marziali&amp;diff=63729"/>
				<updated>2009-06-08T10:04:39Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Alessio Marziali's [profile], [mailto:alessio.marziali@cyphersec.com mail address] and [[:Special:Contributions/Alessio.marziali|wiki contributions]].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== BIO ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Alessio is an eight years experienced Web systems engineer specialised in building bespoke secure financial systems using a broad range of Microsoft technologies.&lt;br /&gt;
&lt;br /&gt;
Alessio has relevant experience on ''Web Penetration Testing'' and code auditing carried on with both technical and security approaches against different types of web systems on client side.&lt;br /&gt;
&lt;br /&gt;
Alessio has proven skills and abilities to handle extended web2 enabled projects from the design both UI design and technical architecture to a stable and reliable stage while using Microsoft and Owasp patterns.&lt;br /&gt;
&lt;br /&gt;
Being active on the scene for the last 8 years, and having worked on different kind of projects and clients, Alessio posses a strong knowledge that encompass many technologies related to software and web application development on Microsoft environments.&lt;br /&gt;
&lt;br /&gt;
Alessio has also authored ''two books on Microsoft ASP.NET'' (2.0 and 3.5)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Crawler ==&lt;br /&gt;
&lt;br /&gt;
At Owasp Alessio is the Project Leader of OWASP CodeCrawler a tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for Java and .NET software.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Italy&amp;diff=60292</id>
		<title>Italy</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Italy&amp;diff=60292"/>
				<updated>2009-05-07T18:27:56Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* OWASP-Italy Board */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Italy|extra=The chapter leader is [mailto:matteo.meucci@gmail.com Matteo Meucci]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-italy|emailarchives=http://lists.owasp.org/pipermail/owasp-italy}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Italy&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== NEWS: Presentations of the OWASP Day II are online! ==&lt;br /&gt;
&lt;br /&gt;
* OWASP Day II: [http://www.owasp.org/index.php/Italy_OWASP_Day_2 &amp;quot;The State of the Art of the Web Application Security and the OWASP guidelines in the Companies&amp;quot;] &lt;br /&gt;
Centro Congressi dell'Università di Roma &amp;quot;La Sapienza&amp;quot; 31st March 2008 - Roma&lt;br /&gt;
&lt;br /&gt;
* OWASP Books are out!&lt;br /&gt;
Now you can download or buy a book on the OWASP Projects. Check it here:&lt;br /&gt;
http://stores.lulu.com/owasp&lt;br /&gt;
&lt;br /&gt;
* The presentation of the OWASP Day 1 Conference are on-line!&lt;br /&gt;
[[http://www.owasp.org/index.php/Italy#September_10th.2C_2007_-_OWASP_Day_WorldWide:_.22Privacy_in_the_21st_Century.22 Here]] you can dowload it.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Local Activities ==&lt;br /&gt;
&lt;br /&gt;
OWASP Italy Chaper was found by [mailto:matteo.meucci@gmail.com Matteo Meucci] in January 2005.&lt;br /&gt;
&lt;br /&gt;
* There is already a qualified group (CISSP, CISA, BS7799 Lead Auditor, OPST, OPSA) of volunteers working on the following tasks:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
- Working at the new OWASP Testing Guide! (Matteo Meucci, Alberto Revelli, Stefano Di Paola, Giorgio Fedon, Luca Carettoni, Antonio Parata, Carlo Pelliccioni, Claudio Merloni, Mauro Bregolin)&amp;lt;br&amp;gt;&lt;br /&gt;
- Translate all OWASP documentations in italian language (Matteo Paolelli, Massimiliano Graziani)&amp;lt;br&amp;gt;&lt;br /&gt;
- Writing articles about OWASP Project for infosecmag (Matteo Meucci, Alessandro Graziani, Lorenzo De Santis, Marco Graia, Luca Carettoni, Carlo Pelliccioni)&amp;lt;br&amp;gt;&lt;br /&gt;
- Working at the project OWASP Code Review (Paolo Perego)&amp;lt;br&amp;gt;&lt;br /&gt;
- Developing WebAppSec tools &amp;amp; Research (Stefano Di Paola, Paolo Perego, Daniele Bellucci, Alberto Revelli, Antonio Parata, Bernardo Damele)&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy Board ==&lt;br /&gt;
&lt;br /&gt;
* This is the '''OWASP-Italy Board''':&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
Founder and Chair: Matteo Meucci&amp;lt;br&amp;gt;&lt;br /&gt;
Director of Communication: Raoul Chiesa&amp;lt;br&amp;gt;&lt;br /&gt;
Technical Director : Alberto Revelli&amp;lt;br&amp;gt;&lt;br /&gt;
R&amp;amp;D Director: Stefano Di Paola, Paolo Perego&amp;lt;br&amp;gt;&lt;br /&gt;
Technical Writer Director: Lorenzo De Santis&amp;lt;br&amp;gt;&lt;br /&gt;
Italian Translation of docs and papers: Matteo Paolelli, Massimiliano Graziani.&amp;lt;br&amp;gt;&lt;br /&gt;
Official active members: Giorgio Fedon, Luca Carettoni, Antonio Parata, Carlo Pelliccioni, Claudio Merloni, Mauro Bregolin, Daniele Bellucci, Bernardo Damele, Alessio Marziali&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== What is OWASP? ==&lt;br /&gt;
&lt;br /&gt;
[http://www.isacaroma.it/html/newsletter/?q=node/78 Here] you can read an interview talking about OWASP.&lt;br /&gt;
&lt;br /&gt;
== OWASP-Italy is a CLUSIT Member ==&lt;br /&gt;
&lt;br /&gt;
http://www.clusit.it/logo_clusit/clusit_logo_b130.gif&lt;br /&gt;
&lt;br /&gt;
Thanks to CLUSIT and OWASP Foundation we have established a cross-membership between the two organizations.&lt;br /&gt;
So OWASP-Italy is now a [http://www.clusit.it/soci.htm CLUSIT member]  and CLUSIT is an OWASP Educational Member&lt;br /&gt;
&lt;br /&gt;
== Activities ==&lt;br /&gt;
&lt;br /&gt;
* (Mar 07) Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP :) )&lt;br /&gt;
[http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article.&lt;br /&gt;
&lt;br /&gt;
* (Oct 06) ISACA Roma has published several interview with OWASP-Italy members:&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]]&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli]]&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]]&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]]&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/328 Carlo Pelliccioni]]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* (Sep 06) Paolo Perego has created the new '''OWASP Orizon Project'''. Go to [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project OWASP Orizon Project]&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* (Sep 06) Matteo Meucci has been selected as the new editor of the '''OWASP Testing Guide v2'''. See OWASP [http://www.owasp.org/index.php/OWASP_Autumn_Of_Code_2006_:_Selected_Projects_Press_Release press release] and go to [http://www.owasp.org/index.php/OWASP_Autumn_of_Code_2006_-_Projects:_Testing_Guide OWASP Testing Project v2]&lt;br /&gt;
&lt;br /&gt;
* (Sep 06) Carlo Pelliccioni is writing an article about the [http://www.owasp.org/index.php/Analysis_about_error_codes analysis of error codes] received by web servers. &lt;br /&gt;
&lt;br /&gt;
* Top10 Vulnerabilities - OWASP-Italy survey:&lt;br /&gt;
[[Image:Top 10 vulnerabilities-mini.GIF]]&lt;br /&gt;
&lt;br /&gt;
* (21 Jun 06) '''Infosecurity 2006''': the event is organized and managed by the CLUSIT.&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;.&lt;br /&gt;
[http://www.infosecurity.it/Roma/programma.php More info here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* (1 Jun 06) '''&amp;quot;Quaderno CLUSIT&amp;quot;'''&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. &lt;br /&gt;
Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but will be made public in about 3 months.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* (31 May 06) Luca Carettoni has published the article '''&amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;.''' [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* (1 Mar 06) '''OWASP-Boston, Microsoft'''&lt;br /&gt;
Thanks to Jim Weiler, Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting.&lt;br /&gt;
[http://www.owasp.org/local/boston.html More info here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* (18 Nov 05) '''IDC - European Banking Forum'''&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we will have a great speech at the [http://www.idc.com/italy/events/banking05/banking05_agenda.jsp IDC European IT Banking Forum 2005]. &lt;br /&gt;
Agenda:&lt;br /&gt;
- New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair&lt;br /&gt;
- Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* (Oct 05) '''SMAU 2005''' is the 42a International ICT &amp;amp; Consumer Electronics Exhibition for Italy. &lt;br /&gt;
SMAU has accepted our submission! [http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili More info here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* (Giu 05) Thanks to Massimiliano Graziani we have translated in italian the '''&amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;'''. You can download it [http://www.owasp.org/documentation/testing.html here.]&lt;br /&gt;
Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* (May 05) '''ISACA Roma Newsletter''' has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* (Apr 05) We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* The presentation of the seminar we have done in '''ISACA Rome''' (31th March 2005) is now available [http://www.isacaroma.it/pdf/050331/meucci.zip here.]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* (Apr 05) We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* (Mar 05) Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here].&lt;br /&gt;
&lt;br /&gt;
== Events ==&lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2009 - OWASP-Italy @ PCI Milan ===&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Testing Guide and PCI-DSS Standard at the  [http://www.pci-portal.com/lang-en/events/event-info/pcimilan PCI Milan event] last 31st March.&lt;br /&gt;
&lt;br /&gt;
The presentation is published [http://www.owasp.org/images/3/38/MeucciPciMilan09.pdf here]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== 23rd February, 2009 - OWASP Day III ===&lt;br /&gt;
----&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_3 &amp;quot;Web Application Security: research meets industry&amp;quot;] &amp;lt;br&amp;gt;&lt;br /&gt;
Presentations are online!&lt;br /&gt;
&lt;br /&gt;
=== 10th October, 2008 - Isaca Roma PCM 2008===&lt;br /&gt;
----&lt;br /&gt;
Matteo Meucci presented the new OWASP Projects and the Application Security in the Italian Companies.&lt;br /&gt;
More information [http://www.isacaroma.it/html/ArchivioEventi-081010.html here]&lt;br /&gt;
&lt;br /&gt;
=== 31st March, 2008 - OWASP Day II ===&lt;br /&gt;
----&lt;br /&gt;
[http://www.owasp.org/index.php/Italy_OWASP_Day_2 &amp;quot;The State of the Art of the Web Application Security and the OWASP guidelines in the Companies&amp;quot;] &lt;br /&gt;
Presentations are online!&lt;br /&gt;
&lt;br /&gt;
=== February 2008 - OWASP Italy at InfoSecurity 2008 ===&lt;br /&gt;
----&lt;br /&gt;
5th February:&lt;br /&gt;
* 14:30 - The Owasp Orizon project: internals and hands on&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_94.aspx Paolo Perego]&lt;br /&gt;
&lt;br /&gt;
6th February:&lt;br /&gt;
* 14:30 - Costruire Software Sicuro dalle Fondamenta&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_128.aspx Antonio Parata]&lt;br /&gt;
&lt;br /&gt;
7th February:&lt;br /&gt;
* 10:30 - Tu programmi. Io buco.&lt;br /&gt;
[http://www.infosecurity.it/IT/eventi-sicurezza-informatica/convegni_137.aspx Luca Carettoni]&lt;br /&gt;
&lt;br /&gt;
[http://www.infosecurity.it Here] you can read more information about it.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== November 30th, 2007 - OWASP-Italy @ Elsag Datamat Security Forum ===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Matteo Meucci was invited to talk about OWASP Guidelines and SDLC Security at the Elsag Datamat Security Forum 2007&lt;br /&gt;
&amp;lt;br&amp;gt;Where: Pescara&lt;br /&gt;
&amp;lt;br&amp;gt;When: 30th November 2007, h.12.30&lt;br /&gt;
&lt;br /&gt;
=== October 20th, 2007 - OWASP Italy at SMAU E-Academy 2007 ===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Last 20th October 2007 we had 5 speeches at SMAU E-Academy 2007, here you can download our presentations:&lt;br /&gt;
&lt;br /&gt;
* Giorgio Fedon, COO at Minded Security:  &lt;br /&gt;
[http://www.owasp.org/.pdf &amp;quot;Dove sono finiti i miei soldi? Internet Banking e Cross Site Scripting&amp;quot;]&lt;br /&gt;
(coming soon) [[Image:FedonSMAU07.pdf]]&lt;br /&gt;
&lt;br /&gt;
* Paolo Perego, Senior Security Consultant at Spike Reply: &lt;br /&gt;
[https://www.owasp.org/images/7/79/PeregoSMAU07.ppt &amp;quot;The Owasp Orizon project - bring security at the source&amp;quot;]&lt;br /&gt;
&lt;br /&gt;
* Antonio Parata, Security Consultant at eMaze: &lt;br /&gt;
&amp;quot;Valutazione del rischio tramite la logica fuzzy&amp;quot; &lt;br /&gt;
(coming soon) [[Image:ParataSMAU07.pdf]]&lt;br /&gt;
&lt;br /&gt;
* Alberto Revelli, Senior Security Consultant at Portcullis Security: &lt;br /&gt;
[http://www.owasp.org/images/9/9f/RevelliSMAU07.pdf &amp;quot;Anti-Anti-XSS: bypass delle difese del browser&amp;quot;]&lt;br /&gt;
&lt;br /&gt;
* Stefano Di Paola, CTO at Minded Security: &lt;br /&gt;
&amp;quot;Cros-site Flashing! Gli attacchi Web di ultima generazione parlano multipiattaforma&amp;quot;&lt;br /&gt;
(coming soon) [[Image:DiPaolaSMAU07.pdf]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== September 10th, 2007 - OWASP Day WorldWide: &amp;quot;Privacy in the 21st Century&amp;quot; ===&lt;br /&gt;
----&lt;br /&gt;
https://www.owasp.org/index.php/Italy_OWASP_Day_1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== May 29th, 2007 - Seminar: &amp;quot;Software Security&amp;quot; ===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
* Stefano Di Paola, Paolo Perego and Matteo Meucci will talk at the Seminar: [http://www.sicurinfo.it/informazioni/visinf.asp?IDInfo=246&amp;amp;CAT=53 &amp;quot;Which approaches to Software Security&amp;quot;] organized by Firenze Tecnologia.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== May 15th-17th, 2007 - 6th OWASP AppSec Conference in Italy ===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
* We are in the initial planning stages for the next OWASP Europe conference, which we plan to hold in Italy in May 2007.&lt;br /&gt;
[http://www.owasp.org/index.php/6th_OWASP_AppSec_Conference_-_Italy_2007 Here] you can find all the details about the conference, cfp and sponsorship.&lt;br /&gt;
&lt;br /&gt;
=== April 14th, 2007 - Master on Information Security, University of Rome &amp;quot;La Sapienza&amp;quot;===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
* We have done a 4h seminar for the students of [http://mastersicurezza.uniroma1.it/ Master on Information Security at &amp;quot;La Sapienza&amp;quot;] for the [http://icsecurity.di.uniroma1.it/dokuwiki/doku.php?id=projects:asp Application Security Project of &amp;quot;La Sapienza&amp;quot; University.]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== March 30th, 2007 - University of Rome &amp;quot;La Sapienza&amp;quot; ===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
* Thanks to Prof. Mancini and Roberto D'Addario, we will talk about OWASP at the convention &amp;quot;Institutions, Companies and Information Security: comparing the problems&amp;quot;&lt;br /&gt;
[http://w3.uniroma1.it/security/Eventi/eventi.html Here] you can find more details.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2007 - EuSecWest 07 ===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Alberto Revelli and Matteo Meucci presented the new OWASP Testing Guide at [http://www.eusecwest.com/agenda.html EUSecWest].&lt;br /&gt;
[http://www.owasp.org/images/e/e9/OWASP_Testing_Guide_Presentation_EUSecWest07.zip Here] you take a look at the presentation.&lt;br /&gt;
&lt;br /&gt;
=== February 6th-8th, 2007 - InfoSecurity ===&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
* February 6th:15.30&lt;br /&gt;
After the great success obtained form CCC at Berlin, Stefano Di Paola and Giorgio Fedon will talk about:&amp;quot; Web Security Client Side: attacks at Web 2.0&amp;quot;&lt;br /&gt;
More information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=aqfi82GOKd6I748s1evI8Q%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here].&lt;br /&gt;
&lt;br /&gt;
* February 6th:16.30&lt;br /&gt;
After the great effort on the Testing Guide Project, Matteo Meucci and Alberto Revelli will present: &amp;quot;The new OWASP Testing Guide&amp;quot;&lt;br /&gt;
More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=nq6tSIuRoPVJBanBSsRiSQ%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here].&lt;br /&gt;
&lt;br /&gt;
* February 7th:12.30&lt;br /&gt;
Authors of innovative SQL injection tools, Alberto Revelli and Antonio Parata will show: &amp;quot;Advanced SQL Injection: testing tools and defensive strategies.&amp;quot;&lt;br /&gt;
More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=3z04F5BgZRgfU0YX8JRYtA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here]&lt;br /&gt;
&lt;br /&gt;
* February 7th:13.30&lt;br /&gt;
Author of the new OWASP Orizon project, Paolo Perergo will present:&amp;quot;Secure programming: from theory to practice&amp;quot;&lt;br /&gt;
More Information [http://www.infosecurity.it/it/infosecurity.aspx?ID_Portale=Z6skuJTSHr%2fjF7janL35RA%3d%3d&amp;amp;ID_Pagina=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl1=mllS8ehP3VwfAOVCVR5ckw%3d%3d&amp;amp;ID_MenuLvl2=fF%2b7etXTY34nfmtRTL8Shw%3d%3d&amp;amp;ID_MenuLvl3=fPsJu6gF%2blBE8LaUGEMYLw%3d%3d&amp;amp;Lang=l51VDVQfL9BdevTm%2fsJx0Q%3d%3d&amp;amp;ID_Evento=9HePIzyo5p29ylpGBl6CiA%3d%3d&amp;amp;ExtControl=FQQ52p7AGBUZth0l9Qw6MSOcqIebAeaBYiSFezT6eKEvZkQfILymgy7truUG7ii4 here].&lt;br /&gt;
&lt;br /&gt;
=== January 25th, 2007 - Isaca Rome ===&lt;br /&gt;
----&lt;br /&gt;
Matteo Meucci will discuss the new [http://www.owasp.org/index.php/Category:OWASP_Testing_Project OWASP Testing Guide v2]&amp;lt;br&amp;gt;&lt;br /&gt;
For more information:&amp;lt;br&amp;gt;&lt;br /&gt;
http://www.isacaroma.it/html/GiornateDiStudio.html&lt;br /&gt;
&lt;br /&gt;
=== October 7th, 2006 - SMAU 2006 ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
- &amp;quot;''The quest for secure code: code review and fundamental of secure coding.''&amp;quot;&lt;br /&gt;
Matteo Meucci will present an introduction to the new OWASP Projects and OWASP-Italy activities.&lt;br /&gt;
Paolo Perego (sp0nge) will speak about safe coding and the importance of code periodic review as natural software life cycle. Paolo will give a vision on code review and its phases&lt;br /&gt;
http://www.webb.it/event/eventview/5772&lt;br /&gt;
&lt;br /&gt;
Here are the presentations: &amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Meucci_SMAU06.pdf| Meucci_SMAU06]] &amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Perego_SMAU06.pdf| Perego_SMAU 06]]&lt;br /&gt;
&lt;br /&gt;
- &amp;quot;''Advanced SQL Injection.''&amp;quot;&lt;br /&gt;
Antonio Parata (S4tan) will explain SQL Injection, and how SQL Inference works on PHP/MySql platform. He will present an open source tool to support the testing. &lt;br /&gt;
Alberto Revelli (icesurfer) will focus on Microsoft SQL Server: he will perform a live demo of sqlninja (http://sqlninja.sf.net), explaining how to obtain a pseudo-shell over SQL, how to escalate privileges, and how to play with the exotic equation: &amp;quot;SQL Injection + debug.exe + DNS = DOS prompt&amp;quot; !&lt;br /&gt;
http://www.webb.it/event/eventview/5774&lt;br /&gt;
&lt;br /&gt;
[[Image:Revelli_SMAU06.pdf|Revelli_SMAU06 ]] &amp;lt;br&amp;gt;&lt;br /&gt;
[[Image:Parata_SMAU06.pdf|Parate_SMAU06]] &amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP-Italy_at_SMAU06_2.JPG]]&lt;br /&gt;
Luca, Carlo, Alberto, Antonio, Stefano &amp;lt;br&amp;gt;&lt;br /&gt;
Matteo, Paolo, Giorgio&lt;br /&gt;
&lt;br /&gt;
=== September 29th, 2006 - OpenExp 2006 ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
September 30th, at 10:45 Antonio Parata (S4tan) will speak about SQL Injection: techniques, tools and practical examples.&lt;br /&gt;
&lt;br /&gt;
Abstract: Antonio will introduce some basic concepts about software security. &lt;br /&gt;
It will be shown how SQL Inference works on PHP/MySql platform and presented an open source tool to support the testing. Finally will be listed some advises to avoid common bugs.&lt;br /&gt;
http://www.openexp.it/&lt;br /&gt;
&lt;br /&gt;
OWASP-Italy will have a stand from September 29th to October 1st.&lt;br /&gt;
&lt;br /&gt;
[[Image:Antonio_Matteo_Carlo.JPG]]&lt;br /&gt;
[[Image:Antonio_speech.JPG]]&lt;br /&gt;
[[Image:Carlo.JPG]]&lt;br /&gt;
[[Image:Claudio_Luca.JPG]]&lt;br /&gt;
[[Image:Mayhem_Matteo.JPG]]&lt;br /&gt;
[[Image:OWASP_Banner2.JPG]]&lt;br /&gt;
[[Image:OWASP_Banner.JPG]]&lt;br /&gt;
&lt;br /&gt;
=== June 21th, 2006 - InfoSecurity 2006 ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Alberto Revelli and Matteo Meucci will partecipate as speakers at the seminar: &amp;quot;Web Application Security: guidelines and security auditing for web applications&amp;quot;. The event is organized and managed by the CLUSIT.&lt;br /&gt;
&lt;br /&gt;
Where: Sheraton Roma Hotel - Viale Del Pattinaggio, 100&lt;br /&gt;
When: 10,30 - 17,00&lt;br /&gt;
Who: Matteo Meucci and Alberto Revelli&lt;br /&gt;
Link: http://www.infosecurity.it/Roma/programma.php&lt;br /&gt;
&lt;br /&gt;
Agenda:&lt;br /&gt;
-- I Session --&lt;br /&gt;
Introduction to Web Application Security&lt;br /&gt;
• Which are the risks?&lt;br /&gt;
• Risk assessment of a web application&lt;br /&gt;
• Core pillars of web security&lt;br /&gt;
How to develop secure web applications:&lt;br /&gt;
• Guidelines and case-studies&lt;br /&gt;
&lt;br /&gt;
-- II Session --&lt;br /&gt;
How to realize a security audit of a web application&lt;br /&gt;
• The methodology OWASP Penetration Testing&lt;br /&gt;
• The tools: OWASP WebScarab&lt;br /&gt;
• Hands-on web application vulnerabilities: OWASP WebGoat&lt;br /&gt;
• Advanced SQL Injection.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== March 1st, 2006 - OWASP-Boston, Microsoft ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Jim Weiler (OWASP-Boston Chair), Matteo Meucci has presented &amp;quot;Anatomy of two web attacks&amp;quot; at the OWASP-Boston meeting of march.&lt;br /&gt;
[http://www.owasp.org/index.php/Boston More info here]&lt;br /&gt;
&lt;br /&gt;
=== November 5th, 2005 - IDC - European Banking Forum ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Raoul Chiesa (Director of Communication OWASP-Italy), we have had a great speech at the IDC European IT Banking Forum 2005 (18 Nov 2005). http://www.idc.com/italy/events/banking05/banking05_agenda.jsp&lt;br /&gt;
Agenda:&lt;br /&gt;
* New standards for the ICT security auditing in the italian banking scenario: OSSTMM and OWASP. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy and Matteo Meucci, OWASP-Italy Chair&lt;br /&gt;
* Workshop: unusual form of attacks and banking system violation: live experience. Raoul Chiesa, Director of Communications, ISECOM/OWASP-Italy.&lt;br /&gt;
&lt;br /&gt;
You can download the report [http://cdn.idc.com/italy/downloads/report_banking05_eng.pdf here].&lt;br /&gt;
&lt;br /&gt;
You can download the Case-Study of a vulnerable Home Banking Web Application [http://www.owasp.org/docroot/owasp/misc/IDC_BankingForum05v1.ppt here].&lt;br /&gt;
&lt;br /&gt;
=== October 5th, 2005 - OWASP-Italy@SMAU2005 ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
SMAU is the 42a International ICT &amp;amp; Consumer Electronics Exhibition for Italy.&lt;br /&gt;
Alberto Revelli (our Technical Director) and Matteo Meucci have conducted a seminar talking about Web Application Security.&lt;br /&gt;
Alberto has presented his new project: [http://sqlninja.sourceforge.net sqlninja]. Very cool!!&lt;br /&gt;
&lt;br /&gt;
http://www.webb.it/event/eventview/4488/1/progetto_owasp__case_study_di_applicativi_web_vulnerabili&lt;br /&gt;
&lt;br /&gt;
=== May 25th, 2005 - ISACA Rome 2nd meeting ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
May 25th we'll be in ISACA Rome to present OWASP WebGoat and a real case of a Web Application Vulnerability.&lt;br /&gt;
Every one is invited to join the meeting.&lt;br /&gt;
&lt;br /&gt;
Here is the agenda:&lt;br /&gt;
14.30 Registration&lt;br /&gt;
14.45 Matteo Meucci - Web Application Security Phase II&lt;br /&gt;
- OWASP WebScarab and PenTest Checklist&lt;br /&gt;
* A case-study of a Web Application Vulnerability: MMS Spoofing&lt;br /&gt;
--- Web Application analysis&lt;br /&gt;
--- Authentication and Billing of the MMS service&lt;br /&gt;
--- Vulnerabilities&lt;br /&gt;
--- Attack Analysis&lt;br /&gt;
* Learning the most common web application vulnerabilities: OWASP WebGoat&lt;br /&gt;
--- Http Basics&lt;br /&gt;
--- HTML Clues&lt;br /&gt;
--- Hidden Field Tampering&lt;br /&gt;
--- How to spoof a Session Cookie&lt;br /&gt;
--- Stored Cross Site Scripting&lt;br /&gt;
--- Command Injection&lt;br /&gt;
--- SQL Injection&lt;br /&gt;
--- Fail Open Authentication&lt;br /&gt;
&lt;br /&gt;
The meeting is hold at:&lt;br /&gt;
Via Volturno, 65 (Rome) - Auditorium ATAC&lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050525/OWASP.zip here].&lt;br /&gt;
&lt;br /&gt;
=== May 18th, 2005 - Workshop on Computer Crime 2005 ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
May 18th, 2005 OWASP-Italy is invited to present OWASP Top 10 to the &amp;quot;Workshop on Computer Crime 2005&amp;quot; titled:&lt;br /&gt;
&amp;quot;EVOLUZIONI NORMATIVE E RECENTI PROBLEMATICHE DI SICUREZZA&amp;quot;&lt;br /&gt;
&lt;br /&gt;
The meeting is held at: Sala delle conferenze dell'Istituto Centrale della Banche Popolari Italiane Via Verziere, 11&lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.owasp.org/images/a/aa/Top10-ComputerCrimes.ppt here].&lt;br /&gt;
&lt;br /&gt;
=== March 31th, 2005 - ISACA Rome meeting ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March 31th we'll be in ISACA Rome to present OWASP and the Web Application Security. Every one is invited to join the meeting.&lt;br /&gt;
&lt;br /&gt;
Here is the agenda:&lt;br /&gt;
14.15 Registration&lt;br /&gt;
14.30 Matteo Meucci - Web Application Security&lt;br /&gt;
- OWASP Guide: how to build secure web application&lt;br /&gt;
- How to test your Web Application: WebScarab and the WebApp PenTest Checklist&lt;br /&gt;
- How to learn the most common web application vulnerability: WebGoat&lt;br /&gt;
- The Top Ten WebApp vulnerabilities&lt;br /&gt;
- Common error on developing Web Application:&lt;br /&gt;
Authentication mechanisms not &amp;quot;secure&amp;quot;&lt;br /&gt;
Buffer Overflow and crash of the service&lt;br /&gt;
Thief of identity: Cross Site Scripting&lt;br /&gt;
Manipulation of company data: SQL Injection&lt;br /&gt;
Reserved information: misconfiguration&lt;br /&gt;
Bad session management and thief of identity&lt;br /&gt;
- OWASP-Italy: projects and next challenges&lt;br /&gt;
&lt;br /&gt;
The meeting is hold at:&lt;br /&gt;
Via Volturno, 65 (Rome) - Auditorium ATAC&lt;br /&gt;
http://www.isacaroma.it/html/GiornateDiStudio.html&lt;br /&gt;
&lt;br /&gt;
You can download the presentation [http://www.isacaroma.it/pdf/050331/meucci.zip here].&lt;br /&gt;
&lt;br /&gt;
=== March 21th, 2005 - OWASP-Italy conducts a seminar in AlmaWeb ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
March, the 21th OWASP-Italy has been invited at the University of Bologna to conduct a seminar regards to [http://www.almaweb.unibo.it/830.dyn Master in Management and Information Technology] titled “Web Application Security and OWASP”. &lt;br /&gt;
&lt;br /&gt;
Here is the agenda:&lt;br /&gt;
- OWASP &amp;amp; Web Application Security&lt;br /&gt;
- Common Web Application Vulnerabilities&lt;br /&gt;
- A real case of web application vulnerability: MMS Spoofing&amp;amp;Billing&lt;br /&gt;
- Training: WebGoat&lt;br /&gt;
&lt;br /&gt;
== Publications ==&lt;br /&gt;
&lt;br /&gt;
=== March, 2007 Interview on HTML.it ===&lt;br /&gt;
----&lt;br /&gt;
Luca Carettoni has published an interview to OWASP-Italy (OWASP interviews OWASP :) )&lt;br /&gt;
[http://blog.html.it/archivi/2007/02/26/quattro-chiacchiere-con-owasp-italia.php Here] the full article.&lt;br /&gt;
&lt;br /&gt;
=== October, 2006 ISACA Roma interviews OWASP-Italy ===&lt;br /&gt;
----&lt;br /&gt;
After the speeches that OWASP-Italy has done at [http://www.smau.it/catnews.asp?l=2&amp;amp;codcat=385 SMAU E-Academy 2006], ISACA Roma has interviewed some of the people of the Italian chapter. Follow the links for the full interviews (in italian):&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/276 Matteo Meucci]]&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/287 Alberto Revelli ]]&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/282 Antonio Parata]]&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/285 Paolo Perego]]&lt;br /&gt;
[[http://www.isacaroma.it/html/newsletter/node/322 Stefano Di Paola &amp;amp; Giorgio Fedon]]&lt;br /&gt;
&lt;br /&gt;
=== Aug, 2006 - Article on Banca Finanza magazine ===&lt;br /&gt;
----&lt;br /&gt;
Banca Finanza, the italian magazine about finance and banking, has interviewed Raoul Chiesa talking about the new risks for the on-line banking security. Raoul speaks about OWASP and web application security [[Media:042006BF.pdf]]&lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Quaderno CLUSIT ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
CLUSIT has published a book entitled: &amp;quot;La verifica della sicurezza di applicazioni Web-based e il progetto OWASP&amp;quot;. &lt;br /&gt;
Several OWASP-Italy members (R.Chiesa, L.De Santis, M.Graziani, L.Legato, M.Meucci, A.Revelli) have contributed to the writing. The document is now reserved to CLUSIT members, but it will be public in about 3 months.&lt;br /&gt;
&lt;br /&gt;
=== June, 2006 - Paper on SQL Injection and Inference on PHP/MySQLInference ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Antonio &amp;quot;s4tan&amp;quot; Parata has published an article about SQL Injection based on Inference for testing web application on PHP/MySQL platform.&lt;br /&gt;
[http://www.ictsc.it/papers/sqlInferenceOnMySql.html Here]you can read the full article.&lt;br /&gt;
&lt;br /&gt;
=== May, 2006 - Published an article about OWASP and Top-10 Vulnerabilities ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Luca Carettoni has published the article &amp;quot;La sicurezza delle applicazioni Web secondo l'Open Web Application Security Project&amp;quot;. [http://sicurezza.html.it/articoli/leggi/1721/la-sicurezza-delle-applicazioni-web-secondo-lopen-/ Here]you can read the full article.&lt;br /&gt;
&lt;br /&gt;
=== June, 2005 - OWASP Pen Test Checklist v 1.1 in Italian ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Massimiliano Graziani we have translated in italian the &amp;quot;OWASP Pen Test Checklist v.1.1&amp;quot;. You can download it [http://www.owasp.org/documentation/testing.html here.]&lt;br /&gt;
Thanks to the collaboration with CLUSIT, this doc is available also [http://www.clusit.it/whitepapers.htm here.]&lt;br /&gt;
&lt;br /&gt;
=== May, 2005 - Isaca Roma Newsletter about OWASP-Italy ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
ISACA Roma Newsletter has published an [http://www.isacaroma.it/html/newsletter/?q=node/78 interview to OWASP-Italy]&lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published &amp;quot;MMS Spoofing&amp;quot; ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have published a presentation describing a detailed case study of a web application vulnerabilty [http://www.owasp.org/images/7/72/MMS_Spoofing.ppt (MMS Spoofing)].&lt;br /&gt;
&lt;br /&gt;
Jim Hewitt, CISSP PMP working at CGI-AMS, affirms (slide#78):&lt;br /&gt;
&amp;quot;Very interesting analysis of spoofed cell phone messaging and fraudulent billing&amp;quot;. See:&lt;br /&gt;
www.techvalleynyissa.org/Resources/2005_07_WebApplicationSecurity.ppt&lt;br /&gt;
&lt;br /&gt;
=== April, 2005 - Published an article on ICT Security magazine ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
We have written an article describing the OWASP projects, Web Application Security and the next challenges. '''ICT Security'''.(the italian magazine about Information Security) has published the article on the number 33 - April 2005.&lt;br /&gt;
&lt;br /&gt;
=== March, 2005 - OWASP Top-10 in Italian ===&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Thanks to Matteo Paolelli we have translated the '''&amp;quot;OWASP Top Ten Vulnerabilties in Web Application Security&amp;quot;''' in italian language. You can download it [http://www.owasp.org/docroot/owasp/projects/topten/OWASPTopTen2004-ITA.pdf here].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
== Tools &amp;amp; Research ==&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
=== Nov, 2007 - sqlmap v0.5 ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released the fifth versions of the tool [http://sqlmap.sourceforge.net sqlmap]. sqlmap is an automatic SQL injection tool entirely developed in Python. It is capable to perform an extensive database management system back-end fingerprint, retrieve remote DBMS databases, usernames, tables, columns, enumerate entire DBMS, read system files and much more taking advantage of web application programming security flaws that lead to SQL injection vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
You can download the latest stable version from its [https://sourceforge.net/project/showfiles.php?group_id=171598&amp;amp;package_id=196107 SourceForge File List page] or the latest development version from its [https://sqlmap.svn.sourceforge.net/svnroot/sqlmap SourceForge SVN repository].&lt;br /&gt;
&lt;br /&gt;
=== Dec, 2006 - sqlmap v0.2 ===&lt;br /&gt;
&lt;br /&gt;
Bernardo Damele and Daniele Bellucci have released a second version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://sqlmap.sourceforge.net/ Here] you can download the tool&lt;br /&gt;
&lt;br /&gt;
=== September, 2006 - Wisec Project ===&lt;br /&gt;
&lt;br /&gt;
Stefano Di Paola is developing Wisec - The Wiki Security Project [http://www.wisec.it Here] you can accesses the project.&lt;br /&gt;
&lt;br /&gt;
=== July, 2006 - Sqlmap v0.0.1 ===&lt;br /&gt;
&lt;br /&gt;
Daniele Bellucci has developed a first version of the tool &amp;quot;sqlmap&amp;quot; for Automatic Blind SQL Injection. [http://www.linux.it/~belch/?p=17 Here] you can download the tool&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:Italy]]&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=56781</id>
		<title>Project Information:template Code Crawler - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=56781"/>
				<updated>2009-03-16T15:52:40Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Code Crawler|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
'''Project Deliveries &amp;amp; Objectives'''  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|CodeCrawler's Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| The application is easy to use and setup.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Stable (100%)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Would be helpful to have the community to work on improving the database of Code Crawler. Doing so will improve the accuracy of the engine and consequently the value of the tool&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|None&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|None&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| No installation package, Not much documentation. (I'm working on these aspects and plan to do release them very soon).&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Database improvements (it's the database setup that makes the difference. The more accure and detailed descriptions, the more useful it is), Feedbacks.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=56780</id>
		<title>Project Information:template Code Crawler - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=56780"/>
				<updated>2009-03-16T15:52:09Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Code Crawler|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
'''Project Deliveries &amp;amp; Objectives'''  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|CodeCrawler's Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| The application is easy to use and setup.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Stable (100%)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Would be helpful to have the community to work on improving the database of Code Crawler. Doing so will improve the accuracy of the engine and consequently the value of the tool&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|None&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|None&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| No installation package, Not much documentation. (I'm working on these aspects and plan to do release them very soon).&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Database improvements (it's the database setup that makes the difference. The more accure and detailed descriptions, the more usefull it is), Feedbacks.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=56696</id>
		<title>Project Information:template Code Crawler - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=56696"/>
				<updated>2009-03-15T15:20:15Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Code Crawler|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
'''Project Deliveries &amp;amp; Objectives'''  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|CodeCrawler's Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| The application is easy to use and setup.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Stable (100%)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Would be helpful to have the community to work on improving the database of Code Crawler. Doing so will improve the accuracy of the engine and consequently the value of the tool&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|None&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|None&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| No installation package, Not much documentation. (I'm working on these aspects and plan to do release them very soon).&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Database improvements (it's the database setup that makes different in Code Crawler), Feedbacks.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=56695</id>
		<title>Project Information:template Code Crawler - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=56695"/>
				<updated>2009-03-15T15:19:30Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Code Crawler|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
'''Project Deliveries &amp;amp; Objectives'''  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|CodeCrawler's Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| The application is easy to use and setup.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Stable (100%)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Would be helpful to have the community to work on improving the database of Code Crawler. Doing so will improve the accuracy of the engine and consequently the value of the tool&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|None&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|None&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| No installation package, Not much documentation. (I'm working on these aspects and plan to do release them very soon.&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Database improvements (it's the database setup that makes different in Code Crawler), Feedbacks.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Code_Crawler_Project_-_Assessment_Frame&amp;diff=56694</id>
		<title>Category:OWASP Code Crawler Project - Assessment Frame</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Code_Crawler_Project_-_Assessment_Frame&amp;diff=56694"/>
				<updated>2009-03-15T15:16:50Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Code Crawler|Click here to return to project's main page]].&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Code Crawler Project''' &lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS - OWASP Summer of Code 2008&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;[[User:Alessio.marziali|'''Alessio Marziali''']] &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;[[:User:EoinKeary|'''Eoin Keary''']]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;[[:User:Mmeucci|'''Matteo Meucci''']]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;Non applicable&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes''' &amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - 50 Review - Self Evaluation - A|See&amp;amp;Edit: 50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - 50 Review - Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&lt;br /&gt;
&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Beta Quality''' - &amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Code_Crawler_Project_-_Assessment_Frame&amp;diff=56693</id>
		<title>Category:OWASP Code Crawler Project - Assessment Frame</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Code_Crawler_Project_-_Assessment_Frame&amp;diff=56693"/>
				<updated>2009-03-15T15:16:14Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP Code Crawler|Click here to return to project's main page]].&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Code Crawler Project''' &lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS - OWASP Summer of Code 2008&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;[[User:Alessio.marziali|'''Alessio Marziali''']] &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;[[:User:EoinKeary|'''Eoin Keary''']]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;[[:User:Mmeucci|'''Matteo Meucci''']]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;Non applicable&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes''' &amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - 50 Review - Self Evaluation - A|See&amp;amp;Edit: 50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - 50 Review - Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&lt;br /&gt;
&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=56406</id>
		<title>Project Information:template Code Crawler - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=56406"/>
				<updated>2009-03-10T00:42:11Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Code Crawler|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
'''Project Deliveries &amp;amp; Objectives'''  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|CodeCrawler's Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| The application is easy to use and setup.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Stable (100%)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Would be helpful to have the community to work on improving the database of Code Crawler. Doing so will improve the accuracy of the engine and consequently the value of the tool&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|None&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|None&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|None&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Database improvements (it's the database setup that makes different in Code Crawler), Feedbacks.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=55243</id>
		<title>Project Information:template Code Crawler - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=55243"/>
				<updated>2009-02-22T12:59:25Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Code Crawler|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
'''Project Deliveries &amp;amp; Objectives'''  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|CodeCrawler's Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| The application is easy to use and setup.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Stable (100%)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Would be helpful to have the community to work on improving the database of Code Crawler. Doing so will improve the accuracy of the engine and consequently the value of the tool&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=55242</id>
		<title>Project Information:template Code Crawler - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=55242"/>
				<updated>2009-02-22T12:58:54Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Code Crawler|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
'''Project Deliveries &amp;amp; Objectives'''  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|CodeCrawler's Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| The application is easy to use and setup.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Stable (100%)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Would be helpfull to have the community to work on improving the database of Code Crawler. Doing so will improve the accuracy of the engine and consequently the value of the tool&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=55239</id>
		<title>Project Information:template Code Crawler - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=55239"/>
				<updated>2009-02-22T12:57:44Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Code Crawler|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
'''Project Deliveries &amp;amp; Objectives'''  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|CodeCrawler's Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| The application is easy to use and setup.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Stable (100%)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Help could be helpful in improving the content of Code Crawler Database. Doing so will improve the accuracy of the engine and consequently the value of the tool&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=55238</id>
		<title>Project Information:template Code Crawler - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=55238"/>
				<updated>2009-02-22T12:54:16Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Code Crawler|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
'''Project Deliveries &amp;amp; Objectives'''  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|CodeCrawler's Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| The application is easy to use and setup.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code Crawler|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Stable (100%)&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler&amp;diff=46609</id>
		<title>Project Information:template Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler&amp;diff=46609"/>
				<updated>2008-11-20T14:22:16Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Code Crawler Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:alessio.marziali(at)cyphersec.com '''Alessio Marziali''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:to(at)change '''Name&amp;amp;Email''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-code-crawler '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:owasp-code-crawler(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:eoin.keary(at)owasp.org '''Eoin Keary''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:dinis.cruz(at)owasp.org '''Dinis Cruz''']&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* [http://www.cyphersec.com/software_archive/OWASP_Code_Crawler.zip CodeCrawler Tool]&amp;lt;br&amp;gt;&lt;br /&gt;
* [http://www.cyphersec.com/software_archive/OWASP_Code_Crawler_Source.zip Code Crawler Source Code (1.464kb)]&lt;br /&gt;
* [http://www.cyphersec.com/software_archive/OWASP_Code_Crawler.zip Code Crawler Binaries (265kb)]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
*[[:Category:OWASP Code Review Project|OWASP Code Review Project]]&amp;lt;br&amp;gt;&lt;br /&gt;
* (If appropriate, links to be added)&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes''' &amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - 50 Review - Self Evaluation - A|See&amp;amp;Edit: 50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - 50 Review - Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_50_Review_-_Self_Evaluation_-_A&amp;diff=34182</id>
		<title>Project Information:template Code Crawler - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler_-_50_Review_-_Self_Evaluation_-_A&amp;diff=34182"/>
				<updated>2008-07-16T18:48:46Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Code Crawler|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|CodeCrawler's Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| &lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
&lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| ~40%&lt;br /&gt;
 |- &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;| Community Members can helps creating Customised XSLT templates based on the Code Crawler XML Report Structure. They can also join the team as developers as some help is required to implement Orizon Project. &lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler&amp;diff=34181</id>
		<title>Project Information:template Code Crawler</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Code_Crawler&amp;diff=34181"/>
				<updated>2008-07-16T18:35:09Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: 1.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Code Crawler Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|A tool aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code. The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:alessio.marziali(at)cyphersec.com '''Alessio Marziali''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:to(at)change '''Name&amp;amp;Email''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-code-crawler '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:owasp-code-crawler(at)lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:eoin.keary(at)owasp.org '''Eoin Keary''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:dinis.cruz(at)owasp.org '''Dinis Cruz''']&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* [http://www.cyphersec.com/software_archive/CodeCrawler_source.rar CodeCrawler Tool]&amp;lt;br&amp;gt;&lt;br /&gt;
* [http://www.cyphersec.com/software_archive/OWASP_CodeCrawler50_SourceCode.rar Code Crawler 50% Source Code (1.464kb)]&lt;br /&gt;
* [http://www.cyphersec.com/software_archive/OWASP_CodeCrawler50Beta.rar Code Crawler 50% Binaries (265kb)]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
*[[:Category:OWASP Code Review Project|OWASP Code Review Project]]&amp;lt;br&amp;gt;&lt;br /&gt;
* (If appropriate, links to be added)&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#Code_Crawler|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes''' &amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - 50 Review - Self Evaluation - A|See&amp;amp;Edit: 50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - 50 Review - Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Code Crawler - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26716</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26716"/>
				<updated>2008-03-16T11:18:42Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* Code Crawler */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli, &lt;br /&gt;
* [[ASDR Table of Contents|ASDR Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali (aka nTze)&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Security Software Life Cycle'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26715</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26715"/>
				<updated>2008-03-15T19:55:46Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* Code Crawler */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli, &lt;br /&gt;
* [[ASDR Table of Contents|ASDR Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali (aka nTze)&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing a secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Security Software Life Cycle'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26714</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26714"/>
				<updated>2008-03-15T19:54:51Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* Code Crawler */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli, &lt;br /&gt;
* [[ASDR Table of Contents|ASDR Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali (aka nTze)&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing a secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Security Software Life cicle'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26713</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26713"/>
				<updated>2008-03-15T19:52:59Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* Code Crawler */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli, &lt;br /&gt;
* [[ASDR Table of Contents|ASDR Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali (aka nTze)&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means a &amp;quot;more&amp;quot; companies performing a secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Security Software Life cicle'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26712</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26712"/>
				<updated>2008-03-15T19:52:30Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* Code Crawler */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli, &lt;br /&gt;
* [[ASDR Table of Contents|ASDR Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali aka nTze&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means a &amp;quot;more&amp;quot; companies performing a secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Security Software Life cicle'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26711</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26711"/>
				<updated>2008-03-15T19:51:31Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* Code Crawler */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli, &lt;br /&gt;
* [[ASDR Table of Contents|ASDR Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali aka nTze&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means a &amp;quot;more&amp;quot; companies performing a secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Threats'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26710</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26710"/>
				<updated>2008-03-15T19:50:31Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* Code Crawler */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli, &lt;br /&gt;
* [[ASDR Table of Contents|ASDR Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali aka nTze&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means a &amp;quot;more&amp;quot; companies performing a secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''build a bigger database''' &amp;lt;br&amp;gt;&lt;br /&gt;
which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Threats'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26709</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26709"/>
				<updated>2008-03-15T19:50:13Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* Code Crawler */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli, &lt;br /&gt;
* [[ASDR Table of Contents|ASDR Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali aka nTze&amp;lt;br&amp;gt; &lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means a &amp;quot;more&amp;quot; companies performing a secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''build a bigger database''' &amp;lt;br&amp;gt;&lt;br /&gt;
which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Threats'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26708</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26708"/>
				<updated>2008-03-15T19:49:35Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* Code Crawler */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli, &lt;br /&gt;
* [[ASDR Table of Contents|ASDR Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali aka nTze&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means a &amp;quot;more&amp;quot; companies performing a secure software activities.&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''build a bigger database''' &amp;lt;br&amp;gt;&lt;br /&gt;
which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Threats'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26707</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26707"/>
				<updated>2008-03-15T19:44:00Z</updated>
		
		<summary type="html">&lt;p&gt;Alessio.marziali: /* Code Crawler */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli, &lt;br /&gt;
* [[ASDR Table of Contents|ASDR Table of Contents]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* '''Alessio Marziali'''&amp;lt;br&amp;gt; &lt;br /&gt;
'''Description:'''&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for everyone.&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''build a bigger database''' &amp;lt;br&amp;gt;&lt;br /&gt;
which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Threats'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;/div&gt;</summary>
		<author><name>Alessio.marziali</name></author>	</entry>

	</feed>