<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Amber+Marfatia</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Amber+Marfatia"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Amber_Marfatia"/>
		<updated>2026-05-02T02:28:28Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Enhancing_Security_Options_Framework_(ESOP_Framework)/Releases/Current&amp;diff=107152</id>
		<title>Projects/OWASP Enhancing Security Options Framework (ESOP Framework)/Releases/Current</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Enhancing_Security_Options_Framework_(ESOP_Framework)/Releases/Current&amp;diff=107152"/>
				<updated>2011-03-18T06:52:57Z</updated>
		
		<summary type="html">&lt;p&gt;Amber Marfatia: Created page with &amp;quot;Release Road Map for the ESOP Framework:  1. Wave 1: Documentation and Wireframe of the service framework&amp;lt;br&amp;gt;2. Wave 2: Class and design diagram framework&amp;lt;br&amp;gt;3. Wave 3: Developme...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Release Road Map for the ESOP Framework:&lt;br /&gt;
&lt;br /&gt;
1. Wave 1: Documentation and Wireframe of the service framework&amp;lt;br&amp;gt;2. Wave 2: Class and design diagram framework&amp;lt;br&amp;gt;3. Wave 3: Development of the framework&amp;lt;br&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp;1. Application layer development&amp;lt;br&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp;2. Data layer development&amp;lt;br&amp;gt;4. Wave 4: Integration&amp;lt;br&amp;gt;5. Wave 5: Alpha Testing&amp;lt;br&amp;gt;6. Wave 6: Beta Testing&amp;lt;br&amp;gt;7. Release &amp;amp;amp; Publish&amp;lt;br&amp;gt;4. Project links (if any) to external sites: N.A.&amp;lt;br&amp;gt;5. Project License: GNU GPL V3.0&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Amber Marfatia</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User_talk:Amber_Marfatia&amp;diff=107151</id>
		<title>User talk:Amber Marfatia</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User_talk:Amber_Marfatia&amp;diff=107151"/>
				<updated>2011-03-18T06:49:23Z</updated>
		
		<summary type="html">&lt;p&gt;Amber Marfatia: /* Road Map towards creating the new security framework */ new section&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Welcome to ''OWASP''!''' We hope you will contribute much and well. You will probably want to read the [[Help:Contents|help pages]]. Again, welcome and have fun! [[User:KateHartmann|KateHartmann]] 17:15, 31 January 2011 (UTC) &lt;br /&gt;
&lt;br /&gt;
== Purpose of the framework - Enhancing Security Options Framework (ESOP Framework)  ==&lt;br /&gt;
&lt;br /&gt;
Purpose of the framework is to provide a security layer to a given web application / web site via web service which can use the functions / modules to protect the site from following vulnerabilities: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; 1. Remote code execution &lt;br /&gt;
&lt;br /&gt;
2. SQL injection &lt;br /&gt;
&lt;br /&gt;
3. Format string vulnerabilities &lt;br /&gt;
&lt;br /&gt;
4. Cross Site Scripting (XSS) &lt;br /&gt;
&lt;br /&gt;
5. Session hacking &lt;br /&gt;
&lt;br /&gt;
6. Denial of service (DoS) attacks &lt;br /&gt;
&lt;br /&gt;
7. Eavesdropping /Sniffing/ Phishing &lt;br /&gt;
&lt;br /&gt;
8. Identity Spoofing &lt;br /&gt;
&lt;br /&gt;
9. Man-in-the-Middle Attacks &lt;br /&gt;
&lt;br /&gt;
10. Username enumeration &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 1. Instrumentation &amp;amp;amp; Audits for: &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 2. Critical Business Areas &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 3. User Management &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 4. Un-usual activities &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 5. Interfaces Integrations &lt;br /&gt;
&lt;br /&gt;
11. IIS Tweaks &lt;br /&gt;
&lt;br /&gt;
12. Password Policy &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Road map for achieving the said framework is provided in the next section.&lt;br /&gt;
&lt;br /&gt;
== Road Map towards creating the new security framework ==&lt;br /&gt;
&lt;br /&gt;
Project Roadmap: Planning to phase the project execution in following waves:&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
1. Wave 1: Documentation and Wireframe of the service framework&amp;lt;br&amp;gt;2. Wave 2: Class and design diagram framework&amp;lt;br&amp;gt;3. Wave 3: Development of the framework&amp;lt;br&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; 1. Application layer development&amp;lt;br&amp;gt;&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; &amp;amp;nbsp; 2. Data layer development&amp;lt;br&amp;gt;4. Wave 4: Integration&amp;lt;br&amp;gt;5. Wave 5: Alpha Testing&amp;lt;br&amp;gt;6. Wave 6: Beta Testing&amp;lt;br&amp;gt;7. Release &amp;amp;amp; Publish&amp;lt;br&amp;gt;4. Project links (if any) to external sites: N.A.&amp;lt;br&amp;gt;5. Project License: GNU GPL V3.0&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Timelines to above roadmap will be provided in the subsquent post.&lt;/div&gt;</summary>
		<author><name>Amber Marfatia</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User_talk:Amber_Marfatia&amp;diff=107150</id>
		<title>User talk:Amber Marfatia</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User_talk:Amber_Marfatia&amp;diff=107150"/>
				<updated>2011-03-18T06:48:07Z</updated>
		
		<summary type="html">&lt;p&gt;Amber Marfatia: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Welcome to ''OWASP''!''' We hope you will contribute much and well. You will probably want to read the [[Help:Contents|help pages]]. Again, welcome and have fun! [[User:KateHartmann|KateHartmann]] 17:15, 31 January 2011 (UTC) &lt;br /&gt;
&lt;br /&gt;
== Purpose of the framework - Enhancing Security Options Framework (ESOP Framework)  ==&lt;br /&gt;
&lt;br /&gt;
Purpose of the framework is to provide a security layer to a given web application / web site via web service which can use the functions / modules to protect the site from following vulnerabilities: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; 1. Remote code execution &lt;br /&gt;
&lt;br /&gt;
2. SQL injection &lt;br /&gt;
&lt;br /&gt;
3. Format string vulnerabilities &lt;br /&gt;
&lt;br /&gt;
4. Cross Site Scripting (XSS) &lt;br /&gt;
&lt;br /&gt;
5. Session hacking &lt;br /&gt;
&lt;br /&gt;
6. Denial of service (DoS) attacks &lt;br /&gt;
&lt;br /&gt;
7. Eavesdropping /Sniffing/ Phishing &lt;br /&gt;
&lt;br /&gt;
8. Identity Spoofing &lt;br /&gt;
&lt;br /&gt;
9. Man-in-the-Middle Attacks &lt;br /&gt;
&lt;br /&gt;
10. Username enumeration &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 1. Instrumentation &amp;amp;amp; Audits for: &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 2. Critical Business Areas &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 3. User Management &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 4. Un-usual activities &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 5. Interfaces Integrations &lt;br /&gt;
&lt;br /&gt;
11. IIS Tweaks &lt;br /&gt;
&lt;br /&gt;
12. Password Policy &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Road map for achieving the said framework is provided in the next section.&lt;/div&gt;</summary>
		<author><name>Amber Marfatia</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User_talk:Amber_Marfatia&amp;diff=107149</id>
		<title>User talk:Amber Marfatia</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User_talk:Amber_Marfatia&amp;diff=107149"/>
				<updated>2011-03-18T06:46:54Z</updated>
		
		<summary type="html">&lt;p&gt;Amber Marfatia: /* Road Map towards creating the new security framework - Enhancing Security Options Framework (ESOP Framework) */ new section&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Welcome to ''OWASP''!'''&lt;br /&gt;
We hope you will contribute much and well. &lt;br /&gt;
You will probably want to read the [[Help:Contents|help pages]].&lt;br /&gt;
Again, welcome and have fun! [[User:KateHartmann|KateHartmann]] 17:15, 31 January 2011 (UTC)&lt;br /&gt;
&lt;br /&gt;
== Road Map towards creating the new security framework - Enhancing Security Options Framework (ESOP Framework) ==&lt;br /&gt;
&lt;br /&gt;
Purpose of the framework is to provide a security layer to a given web application / web site via web service which can use the functions / modules to protect the site from following vulnerabilities: &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; 1. Remote code execution &lt;br /&gt;
&lt;br /&gt;
2. SQL injection &lt;br /&gt;
&lt;br /&gt;
3. Format string vulnerabilities &lt;br /&gt;
&lt;br /&gt;
4. Cross Site Scripting (XSS) &lt;br /&gt;
&lt;br /&gt;
5. Session hacking &lt;br /&gt;
&lt;br /&gt;
6. Denial of service (DoS) attacks &lt;br /&gt;
&lt;br /&gt;
7. Eavesdropping /Sniffing/ Phishing &lt;br /&gt;
&lt;br /&gt;
8. Identity Spoofing &lt;br /&gt;
&lt;br /&gt;
9. Man-in-the-Middle Attacks &lt;br /&gt;
&lt;br /&gt;
10. Username enumeration &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 1. Instrumentation &amp;amp;amp; Audits for: &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 2. Critical Business Areas &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 3. User Management &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 4. Un-usual activities &lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&amp;amp;nbsp; &amp;amp;nbsp; 5. Interfaces Integrations &lt;br /&gt;
&lt;br /&gt;
11. IIS Tweaks &lt;br /&gt;
&lt;br /&gt;
12. Password Policy &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Road map for achieving the said framework is provided in the next section.&lt;/div&gt;</summary>
		<author><name>Amber Marfatia</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Amber_Marfatia&amp;diff=107148</id>
		<title>User:Amber Marfatia</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Amber_Marfatia&amp;diff=107148"/>
				<updated>2011-03-18T06:41:43Z</updated>
		
		<summary type="html">&lt;p&gt;Amber Marfatia: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Amber [amber.marfatia@gmail.com] total has Total 9+ years experience in handling &amp;amp; providing end to end software development solutions by developing, managing and maintaining projects with medium to large team size.&lt;br /&gt;
&lt;br /&gt;
Currently managing team of an average size of 23 people and providing project management &amp;amp; application architecture cover to the account.&lt;br /&gt;
To play role of .Net Solution Architect &amp;amp; Project Manager which covers following aspects:&lt;br /&gt;
&lt;br /&gt;
o	As .Net solution architect:&lt;br /&gt;
&lt;br /&gt;
Suggest, Design &amp;amp; get the Application Architecture implemented&lt;br /&gt;
&lt;br /&gt;
Suggest &amp;amp; get Design guidelines implemented&lt;br /&gt;
&lt;br /&gt;
Suggest &amp;amp; implementation of features to leverage of IIS advance with ASP.NET &lt;br /&gt;
&lt;br /&gt;
Suggest &amp;amp; implementation of non-functional requirements &lt;br /&gt;
&lt;br /&gt;
Formation of web security wrapper for the portals&lt;br /&gt;
&lt;br /&gt;
Understanding common production issues &amp;amp; suggestions to overcome the same.&lt;br /&gt;
&lt;br /&gt;
Specific project related issues / areas to work&lt;br /&gt;
&lt;br /&gt;
Review and analysis of client’s existing portal architecture to identify gaps and suggest improvements&lt;br /&gt;
&lt;br /&gt;
Collaborate with Client’s architects and provide technical solutions to the portal framework&lt;br /&gt;
&lt;br /&gt;
Identify value-add opportunity and create proof of concepts and reference implementation for the product lines&lt;br /&gt;
&lt;br /&gt;
Guide the development teams to implement the technical initiatives&lt;br /&gt;
&lt;br /&gt;
Provide: HLD, LLD, execution / testing strategy.&lt;br /&gt;
&lt;br /&gt;
Preparation &amp;amp; guiding the team for the exercise estimation using RFP / BRS&lt;br /&gt;
&lt;br /&gt;
As project manager:&lt;br /&gt;
&lt;br /&gt;
Responsible for managing multiple .Net (Asp. Net ) projects simultaneously&lt;br /&gt;
&lt;br /&gt;
Ensuring the quality matrices for the project are well within the acceptable limits&lt;br /&gt;
&lt;br /&gt;
Ensuring the defect density is well within the permissible limits  &lt;br /&gt;
&lt;br /&gt;
To lead multiple parallel projects, track and manage:&lt;br /&gt;
&lt;br /&gt;
Resources along their loading &amp;amp; utilization&lt;br /&gt;
&lt;br /&gt;
Managing Revenue generation for Fixed Bid Projects&lt;br /&gt;
&lt;br /&gt;
SQA related activities enabling the project to be audit compliant&lt;br /&gt;
&lt;br /&gt;
Managing project deliverables by tracking, adopting agile, identification &amp;amp; mitigation of risks &amp;amp; by providing functional &amp;amp; technical inputs to the team. &lt;br /&gt;
&lt;br /&gt;
Sizing the projects based on proposals or RFP using FPA or Use Case estimation model.&lt;br /&gt;
&lt;br /&gt;
Co-ordination &amp;amp; Gathering Requirement from Customer, documenting in the form of User Requirement Documentation (On Site / Off Site Client Co-ordination).&lt;br /&gt;
&lt;br /&gt;
Envisaging &amp;amp; providing mitigation plans for the risk as applicable on the project&lt;br /&gt;
&lt;br /&gt;
Making sure that resource utilization, cost &amp;amp; schedule management is optimal at account level.&lt;br /&gt;
&lt;br /&gt;
Negotiate/manage expectations with business/end users, key stakeholders and senior leadership&lt;/div&gt;</summary>
		<author><name>Amber Marfatia</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Amber_Marfatia&amp;diff=107147</id>
		<title>User:Amber Marfatia</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Amber_Marfatia&amp;diff=107147"/>
				<updated>2011-03-18T06:40:18Z</updated>
		
		<summary type="html">&lt;p&gt;Amber Marfatia: Amber Marfatia as solution architect and security specialist.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Total 9+ years experience in handling &amp;amp; providing end to end software development solutions by developing, managing and maintaining projects with medium to large team size.&lt;br /&gt;
&lt;br /&gt;
Currently managing team of an average size of 23 people and providing project management &amp;amp; application architecture cover to the account.&lt;br /&gt;
To play role of .Net Solution Architect &amp;amp; Project Manager which covers following aspects:&lt;br /&gt;
&lt;br /&gt;
o	As .Net solution architect:&lt;br /&gt;
&lt;br /&gt;
Suggest, Design &amp;amp; get the Application Architecture implemented&lt;br /&gt;
&lt;br /&gt;
Suggest &amp;amp; get Design guidelines implemented&lt;br /&gt;
&lt;br /&gt;
Suggest &amp;amp; implementation of features to leverage of IIS advance with ASP.NET &lt;br /&gt;
&lt;br /&gt;
Suggest &amp;amp; implementation of non-functional requirements &lt;br /&gt;
&lt;br /&gt;
Formation of web security wrapper for the portals&lt;br /&gt;
&lt;br /&gt;
Understanding common production issues &amp;amp; suggestions to overcome the same.&lt;br /&gt;
&lt;br /&gt;
Specific project related issues / areas to work&lt;br /&gt;
&lt;br /&gt;
Review and analysis of client’s existing portal architecture to identify gaps and suggest improvements&lt;br /&gt;
&lt;br /&gt;
Collaborate with Client’s architects and provide technical solutions to the portal framework&lt;br /&gt;
&lt;br /&gt;
Identify value-add opportunity and create proof of concepts and reference implementation for the product lines&lt;br /&gt;
&lt;br /&gt;
Guide the development teams to implement the technical initiatives&lt;br /&gt;
&lt;br /&gt;
Provide: HLD, LLD, execution / testing strategy.&lt;br /&gt;
&lt;br /&gt;
Preparation &amp;amp; guiding the team for the exercise estimation using RFP / BRS&lt;br /&gt;
&lt;br /&gt;
As project manager:&lt;br /&gt;
&lt;br /&gt;
Responsible for managing multiple .Net (Asp. Net ) projects simultaneously&lt;br /&gt;
&lt;br /&gt;
Ensuring the quality matrices for the project are well within the acceptable limits&lt;br /&gt;
&lt;br /&gt;
Ensuring the defect density is well within the permissible limits  &lt;br /&gt;
&lt;br /&gt;
To lead multiple parallel projects, track and manage:&lt;br /&gt;
&lt;br /&gt;
Resources along their loading &amp;amp; utilization&lt;br /&gt;
&lt;br /&gt;
Managing Revenue generation for Fixed Bid Projects&lt;br /&gt;
&lt;br /&gt;
SQA related activities enabling the project to be audit compliant&lt;br /&gt;
&lt;br /&gt;
Managing project deliverables by tracking, adopting agile, identification &amp;amp; mitigation of risks &amp;amp; by providing functional &amp;amp; technical inputs to the team. &lt;br /&gt;
&lt;br /&gt;
Sizing the projects based on proposals or RFP using FPA or Use Case estimation model.&lt;br /&gt;
&lt;br /&gt;
Co-ordination &amp;amp; Gathering Requirement from Customer, documenting in the form of User Requirement Documentation (On Site / Off Site Client Co-ordination).&lt;br /&gt;
&lt;br /&gt;
Envisaging &amp;amp; providing mitigation plans for the risk as applicable on the project&lt;br /&gt;
&lt;br /&gt;
Making sure that resource utilization, cost &amp;amp; schedule management is optimal at account level.&lt;br /&gt;
&lt;br /&gt;
Negotiate/manage expectations with business/end users, key stakeholders and senior leadership&lt;/div&gt;</summary>
		<author><name>Amber Marfatia</name></author>	</entry>

	</feed>