<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Anastasia+Stamos</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Anastasia+Stamos"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Anastasia_Stamos"/>
		<updated>2026-04-11T09:53:01Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=16814</id>
		<title>OWASP Community</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=16814"/>
				<updated>2007-03-01T18:22:37Z</updated>
		
		<summary type="html">&lt;p&gt;Anastasia Stamos: /* Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page is for people to post OWASP related events, such as chapter meetings, OWASP conferences, get-togethers, and OWASP sponsored events.&lt;br /&gt;
&lt;br /&gt;
Events from previous years are archived here:&lt;br /&gt;
* '''[[OWASP Community 2006]]'''&lt;br /&gt;
&lt;br /&gt;
This page is monitored, and items posted here will be copied to the OWASP [[Main Page]].  Please post new items in chronological order using the following format:&lt;br /&gt;
&lt;br /&gt;
 '''Mon ## (##:00h) - [[Article]]'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
&lt;br /&gt;
CHAPTER LEADS -- please put your schedule here and we'll post a month in advance&lt;br /&gt;
&lt;br /&gt;
*** OTTAWA: Rough dates ***&lt;br /&gt;
'''May 9 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
'''Sept 12 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
'''Nov 14 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
&lt;br /&gt;
*** BOSTON: Every first Wednesday of the month ***&lt;br /&gt;
'''Apr 4 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
'''May 2 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** MELBOURNE: First Tuesday of the month ***&lt;br /&gt;
'''Apr 3 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
'''May 1 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
'''Jun 5 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
'''Jul 3 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** NETHERLANDS: Second Thursday of the month sometimes ***&lt;br /&gt;
'''Sept 13 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
'''Dec 13 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** ROCHESTER: Every third Monday of the month ***&lt;br /&gt;
'''Apr 17 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
'''May 15 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** TORONTO: Every second Wednesday of the month&lt;br /&gt;
'''Apr 11 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
'''May 9 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** VIRGINIA: Every second tuesday of the month ***&lt;br /&gt;
'''Apr 10 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
'''May 8 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Events==&lt;br /&gt;
&lt;br /&gt;
'''May 10 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 12 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 28 (11:30h) - [[San Antonio|San Antonio chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
; '''Mar 27-30 - [http://www.blackhat.com Black Hat Euro]'''&lt;br /&gt;
: OWASP members receive a Euro 100 Briefings discount by inserting BH7EUASSOC in the box marked “Coupon Codes”&lt;br /&gt;
&lt;br /&gt;
'''Mar 22 (18:00h) - [[London|London chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 21-22 - [[Belgium#OWASP_Top_10_2007_Update_.28Infosecurity_Belgium.2C_21_.26_.2622_Mar_2007.29|Belgium@InfoSecurity]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 20 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 14 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 14 (18:00h) - [[Chicago|Chicago chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 13 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 8 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
&lt;br /&gt;
'''Mar 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 7 (18:30h) - [[Kansas City|Kansas City chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 6 (18:30h) - [[Philadelphia|Philadelphia chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 6 (18:30h) - [[San Francisco|San Francisco and San Jose chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 6 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 1 (11:30h) - [http://www.eusecwest.com/agenda.html EUSecWest 07: Testing Guide]'''&lt;br /&gt;
&lt;br /&gt;
; '''Feb 26-Mar 1 - [http://www.blackhat.com Black Hat DC]'''&lt;br /&gt;
: OWASP members receive a $100 Briefings discount by inserting BH7DCASSOC in the box marked “Coupon Codes”&lt;br /&gt;
&lt;br /&gt;
'''Feb 28 (18:00h) - [[Seattle|Seattle chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 27 (18:00h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 22 (18:30h) - [[Helsinki|Helsinki chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 22 (18:00h) - [[London|London chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 21 (18:30h) - [[Denver|Denver chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 19 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 15 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 15 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 14 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 13 (18:00h) - [[Ireland|Ireland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 12 (18:30h) - [[Switzerland|Switzerland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 6-7 - [[Italy#February_6th-8th.2C_2007_-_InfoSecurity|Italy@InfoSecurity]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 6 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 2 (14:00h) - [[Chennai|Chennai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 31 (15:00h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 30 (11:30h) - [[Austin|Austin chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 25 (18:00h) - [[San Francisco| San Francisco chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 25 (14:30h) - [[Italy#October_25th.2C_2007_-_Isaca_Rome|Italy@ISACA Rome]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 24 (17:30h) - [[Israel#6th_OWASP_IL_meeting:_Wednesday.2C_January_24th_2007|6th OWASP Israel chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 23 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 22 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 17 (18:30h) - [[Denver|Denver chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 16 (17:45h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:30h) - [[Phoenix|Phoenix chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 10 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 8 (18:00h) - [[Seattle|Seattle chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 3 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;/div&gt;</summary>
		<author><name>Anastasia Stamos</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=16813</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=16813"/>
				<updated>2007-03-01T18:21:06Z</updated>
		
		<summary type="html">&lt;p&gt;Anastasia Stamos: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Francisco|extra=The chapter leader is [mailto:bchristian@spidynamics.com Brian Christian]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanfran|emailarchives=http://lists.owasp.org/pipermail/owasp-sanfran}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Please note that this meeting starts later to accomodate our San Jose chapter members. Don't forget to rsvp to anastasia@isecpartners.com&lt;br /&gt;
&lt;br /&gt;
WHAT: San Francisco and San Jose OWASP Chapter Meeting &lt;br /&gt;
&lt;br /&gt;
WHEN: Tuesday, March 6, 2007&lt;br /&gt;
&lt;br /&gt;
6:30-7:00   Social (Food and Drinks) and Chapter Announcements&lt;br /&gt;
&lt;br /&gt;
7:00-8:30   Presentation and Q and A- Dinis Cruz (Chief OWASP&lt;br /&gt;
Evangelist)&lt;br /&gt;
&lt;br /&gt;
WHERE: iSEC Partners offices located @ 115 Sansome Street Suite 1005 (10th Floor), San Francisco, CA (http://www.isecpartners.com ). We recommend arriving by public transit as parking is extremely limited.&lt;br /&gt;
&lt;br /&gt;
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-&lt;br /&gt;
&lt;br /&gt;
*OWASP, the Open Web Application Security Project &lt;br /&gt;
The Open Web Application Security Project (OWASP) is an open community dedicated to enabling organizations to develop, purchase, and maintain applications that can be trusted. All of the OWASP tools, documents, blogs, and chapters are free and open to anyone interested in improving application security. In this presentation Dinis will show the latest guides and tools from OWASP which should be part of every company's security efforts. &lt;br /&gt;
&lt;br /&gt;
*Buffer Overflows on .Net and Asp.Net &lt;br /&gt;
One of the common myths about the .Net Framework is that it is immune to Buffer Overflows.  Although this might be correct in pure managed and verifiable .Net code, large percentage of .Net and Asp.Net applications code is unmanaged code.  In this talk Dinis will show the areas in .Net and Asp.Net applications that are vulnerable to Buffer Overflows (including the demo of a .Net Buffer Overflow Fuzzer).&lt;br /&gt;
 &lt;br /&gt;
*Owning Vista's userland - The CAS / UAC missed opportunity, and what I think MS should had done&lt;br /&gt;
In this presentation Dinis will explore the missed opportunity by Microsoft to use technologies like .Net's CAS (Code Access Security) and Vista's UAC (User Access Control) to create secure and trustworthy userland environments that protect the user's assets. In the hope that might make a small difference, ideas and solutions for the future will also be presented.&lt;/div&gt;</summary>
		<author><name>Anastasia Stamos</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=15589</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=15589"/>
				<updated>2007-01-18T22:00:05Z</updated>
		
		<summary type="html">&lt;p&gt;Anastasia Stamos: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Francisco|extra=The chapter leader is [mailto:bchristian@spidynamics.com Brian Christian]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanfran|emailarchives=http://lists.owasp.org/pipermail/owasp-sanfran}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
'''!!!PLEASE RSVP TO Anastasia Stamos (mailto:anastasia@isecpartners.com) AS THERE IS LIMITED SPACE!!!'''&lt;br /&gt;
&lt;br /&gt;
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
WHAT: San Francisco OWASP Chapter Meeting and Mixer&lt;br /&gt;
&lt;br /&gt;
WHEN: Thursday, January 25th, 2007 &lt;br /&gt;
       &lt;br /&gt;
6:00-6:30   Social (Food and Drinks) and Chapter Announcements&lt;br /&gt;
&lt;br /&gt;
6:30-8:00   &amp;quot;XML Digital Signature and Encryption: Use and Abuse&amp;quot;:  Brad Hill, iSEC Partners&lt;br /&gt;
&lt;br /&gt;
8:00-8:15   Q and A	&lt;br /&gt;
&lt;br /&gt;
8:15-8:45   &amp;quot;Commonly Overlooked Cryptographic Vulnerabilities in Web Applications&amp;quot;: Patrick Stach, Stach and Liu&lt;br /&gt;
&lt;br /&gt;
8:45-9:00   Q and A and Meeting Wrap Up&lt;br /&gt;
&lt;br /&gt;
WHERE: iSEC Partners offices located @ 115 Sansome Street Suite 1005 (10th Floor), San Francisco, CA (http://www.isecpartners.com)&lt;br /&gt;
We recommend arriving by public transit as parking is extremely limited.&lt;br /&gt;
&lt;br /&gt;
WHY: To network, socialize and learn more about Web Application Security &lt;br /&gt;
&lt;br /&gt;
WHO: Brian Christian, Chapter President, will give chapter details and Brad Hill and Patrick Stach will present.&lt;br /&gt;
&lt;br /&gt;
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- &lt;br /&gt;
&lt;br /&gt;
&amp;quot;XML Digital Signature and Encryption: Use and Abuse&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Abstract:&lt;br /&gt;
The WS-Security set of standards is on the threshold of ubiquitous deployment and XML applications have already taken over the world.  This presentation looks at two underlying technologies, XML Digital Signature (XMLDSIG) and XML Encryption (XMLENC), their place in the Web Services stack and their applicability to non-SOAP XML applications.   Beginning with a basic overview of the standards, we will uncover some surprising caveats and risks in the use of these technologies.&lt;br /&gt;
&lt;br /&gt;
Security Consultant - Brad Hill&lt;br /&gt;
&lt;br /&gt;
Brad Hill is a Security Consultant with iSEC Partners.  Brad Hill brings&lt;br /&gt;
to iSEC a decade-plus background working with Internet technologies,&lt;br /&gt;
including serving as the lead developer of Web applications and&lt;br /&gt;
frameworks for one of the premier private label recordkeeping and&lt;br /&gt;
management companies in the financial services industry, where his&lt;br /&gt;
responsibilities also included security training, policy development and&lt;br /&gt;
compliance.  With iSEC he has performed penetration testing and design&lt;br /&gt;
review for a wide spectrum of products and technologies, most recently&lt;br /&gt;
participating in the Final Security Review of Microsoft Windows Vista.&lt;br /&gt;
Brad achieved the Certified Information Systems Security Professional&lt;br /&gt;
(CISSP) credential in 2004.&lt;br /&gt;
&lt;br /&gt;
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Commonly Overlooked Cryptographic Vulnerabilities in Web Applications&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Abstract:&lt;br /&gt;
This talk aims to outline a few commonly overlooked cryptographic vulnerabilities in web applications.  The problems presented will range from attacks against authentication various authentication schemes to improper certificate generation.&lt;br /&gt;
&lt;br /&gt;
Director of Research and Development- Patrick Stach&lt;br /&gt;
&lt;br /&gt;
Patrick Stach is Director of Research and Development at Stach &amp;amp; Liu, a firm providing advanced IT security consulting to the Fortune 500 and multi-national financial institutions. Before founding Stach &amp;amp; Liu, Patrick aided in the development of multiple industry leading security scanning engines. In addition to providing security consulting services to Mitsui Zaibatsu, he has led the network security teams for a number of major hosting providers.&lt;br /&gt;
 &lt;br /&gt;
Patrick has lectured on cryptanalysis at Kyoto University, taught as adjunct faculty at Network Associates' Japan Security Academy, and performs government-funded cryptanalysis. He is a developer of the Metasploit Framework and has presented at DefCon, Interz0ne, AtlantaCon, ToorCon, and PhreakNIC.&lt;/div&gt;</summary>
		<author><name>Anastasia Stamos</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=15588</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=15588"/>
				<updated>2007-01-18T21:58:53Z</updated>
		
		<summary type="html">&lt;p&gt;Anastasia Stamos: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Francisco|extra=The chapter leader is [mailto:bchristian@spidynamics.com Brian Christian]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanfran|emailarchives=http://lists.owasp.org/pipermail/owasp-sanfran}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
'''!!!PLEASE RSVP TO Anastasia Stamos (mailto:anastasia@isecpartners.com) AS THERE IS LIMITED SPACE!!!'''&lt;br /&gt;
&lt;br /&gt;
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
WHAT: San Francisco OWASP Chapter Meeting and Mixer&lt;br /&gt;
&lt;br /&gt;
WHEN: Thursday, January 25th, 2007 &lt;br /&gt;
       &lt;br /&gt;
6:00-6:30   Social (Food and Drinks) and Chapter Announcements&lt;br /&gt;
&lt;br /&gt;
6:30-8:00   &amp;quot;XML Digital Signature and Encryption: Use and Abuse&amp;quot;:  Brad Hill, iSEC Partners&lt;br /&gt;
&lt;br /&gt;
8:00-8:15   Q and A	&lt;br /&gt;
&lt;br /&gt;
8:15-9:00   &amp;quot;Commonly Overlooked Cryptographic Vulnerabilities in Web Applications&amp;quot;: Patrick Stach, Stach and Liu&lt;br /&gt;
&lt;br /&gt;
WHERE: iSEC Partners offices located @ 115 Sansome Street Suite 1005 (10th Floor), San Francisco, CA (http://www.isecpartners.com)&lt;br /&gt;
We recommend arriving by public transit as parking is extremely limited.&lt;br /&gt;
&lt;br /&gt;
WHY: To network, socialize and learn more about Web Application Security &lt;br /&gt;
&lt;br /&gt;
WHO: Brian Christian, Chapter President, will give chapter details and Brad Hill and Patrick Stach will present.&lt;br /&gt;
&lt;br /&gt;
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- &lt;br /&gt;
&lt;br /&gt;
&amp;quot;XML Digital Signature and Encryption: Use and Abuse&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Abstract:&lt;br /&gt;
The WS-Security set of standards is on the threshold of ubiquitous deployment and XML applications have already taken over the world.  This presentation looks at two underlying technologies, XML Digital Signature (XMLDSIG) and XML Encryption (XMLENC), their place in the Web Services stack and their applicability to non-SOAP XML applications.   Beginning with a basic overview of the standards, we will uncover some surprising caveats and risks in the use of these technologies.&lt;br /&gt;
&lt;br /&gt;
Security Consultant - Brad Hill&lt;br /&gt;
&lt;br /&gt;
Brad Hill is a Security Consultant with iSEC Partners.  Brad Hill brings&lt;br /&gt;
to iSEC a decade-plus background working with Internet technologies,&lt;br /&gt;
including serving as the lead developer of Web applications and&lt;br /&gt;
frameworks for one of the premier private label recordkeeping and&lt;br /&gt;
management companies in the financial services industry, where his&lt;br /&gt;
responsibilities also included security training, policy development and&lt;br /&gt;
compliance.  With iSEC he has performed penetration testing and design&lt;br /&gt;
review for a wide spectrum of products and technologies, most recently&lt;br /&gt;
participating in the Final Security Review of Microsoft Windows Vista.&lt;br /&gt;
Brad achieved the Certified Information Systems Security Professional&lt;br /&gt;
(CISSP) credential in 2004.&lt;br /&gt;
&lt;br /&gt;
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Commonly Overlooked Cryptographic Vulnerabilities in Web Applications&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Abstract:&lt;br /&gt;
This talk aims to outline a few commonly overlooked cryptographic vulnerabilities in web applications.  The problems presented will range from attacks against authentication various authentication schemes to improper certificate generation.&lt;br /&gt;
&lt;br /&gt;
Director of Research and Development- Patrick Stach&lt;br /&gt;
&lt;br /&gt;
Patrick Stach is Director of Research and Development at Stach &amp;amp; Liu, a firm providing advanced IT security consulting to the Fortune 500 and multi-national financial institutions. Before founding Stach &amp;amp; Liu, Patrick aided in the development of multiple industry leading security scanning engines. In addition to providing security consulting services to Mitsui Zaibatsu, he has led the network security teams for a number of major hosting providers.&lt;br /&gt;
 &lt;br /&gt;
Patrick has lectured on cryptanalysis at Kyoto University, taught as adjunct faculty at Network Associates' Japan Security Academy, and performs government-funded cryptanalysis. He is a developer of the Metasploit Framework and has presented at DefCon, Interz0ne, AtlantaCon, ToorCon, and PhreakNIC.&lt;/div&gt;</summary>
		<author><name>Anastasia Stamos</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=15587</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=15587"/>
				<updated>2007-01-18T21:58:31Z</updated>
		
		<summary type="html">&lt;p&gt;Anastasia Stamos: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Francisco|extra=The chapter leader is [mailto:bchristian@spidynamics.com Brian Christian]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanfran|emailarchives=http://lists.owasp.org/pipermail/owasp-sanfran}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
'''!!!PLEASE RSVP TO Anastasia Stamos (mailto:anastasia@isecpartners.com) AS THERE IS LIMITED SPACE!!!'''&lt;br /&gt;
&lt;br /&gt;
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
WHAT: San Francisco OWASP Chapter Meeting and Mixer&lt;br /&gt;
&lt;br /&gt;
WHEN: Thursday, January 25th, 2007 &lt;br /&gt;
       &lt;br /&gt;
6:00-6:30   Social (Food and Drinks) and Chapter Announcements&lt;br /&gt;
&lt;br /&gt;
6:30-8:00   &amp;quot;XML Digital Signature and Encryption: Use and Abuse&amp;quot;:  Brad Hill, iSEC Partners&lt;br /&gt;
&lt;br /&gt;
8:00-8:15   Q and A	&lt;br /&gt;
&lt;br /&gt;
8:15-9:00   &amp;quot;Commonly Overlooked Cryptographic Vulnerabilities in Web Applications&amp;quot;&lt;br /&gt;
            Patrick Stach, Stach and Liu&lt;br /&gt;
&lt;br /&gt;
WHERE: iSEC Partners offices located @ 115 Sansome Street Suite 1005 (10th Floor), San Francisco, CA (http://www.isecpartners.com)&lt;br /&gt;
We recommend arriving by public transit as parking is extremely limited.&lt;br /&gt;
&lt;br /&gt;
WHY: To network, socialize and learn more about Web Application Security &lt;br /&gt;
&lt;br /&gt;
WHO: Brian Christian, Chapter President, will give chapter details and Brad Hill and Patrick Stach will present.&lt;br /&gt;
&lt;br /&gt;
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- &lt;br /&gt;
&lt;br /&gt;
&amp;quot;XML Digital Signature and Encryption: Use and Abuse&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Abstract:&lt;br /&gt;
The WS-Security set of standards is on the threshold of ubiquitous deployment and XML applications have already taken over the world.  This presentation looks at two underlying technologies, XML Digital Signature (XMLDSIG) and XML Encryption (XMLENC), their place in the Web Services stack and their applicability to non-SOAP XML applications.   Beginning with a basic overview of the standards, we will uncover some surprising caveats and risks in the use of these technologies.&lt;br /&gt;
&lt;br /&gt;
Security Consultant - Brad Hill&lt;br /&gt;
&lt;br /&gt;
Brad Hill is a Security Consultant with iSEC Partners.  Brad Hill brings&lt;br /&gt;
to iSEC a decade-plus background working with Internet technologies,&lt;br /&gt;
including serving as the lead developer of Web applications and&lt;br /&gt;
frameworks for one of the premier private label recordkeeping and&lt;br /&gt;
management companies in the financial services industry, where his&lt;br /&gt;
responsibilities also included security training, policy development and&lt;br /&gt;
compliance.  With iSEC he has performed penetration testing and design&lt;br /&gt;
review for a wide spectrum of products and technologies, most recently&lt;br /&gt;
participating in the Final Security Review of Microsoft Windows Vista.&lt;br /&gt;
Brad achieved the Certified Information Systems Security Professional&lt;br /&gt;
(CISSP) credential in 2004.&lt;br /&gt;
&lt;br /&gt;
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Commonly Overlooked Cryptographic Vulnerabilities in Web Applications&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Abstract:&lt;br /&gt;
This talk aims to outline a few commonly overlooked cryptographic vulnerabilities in web applications.  The problems presented will range from attacks against authentication various authentication schemes to improper certificate generation.&lt;br /&gt;
&lt;br /&gt;
Director of Research and Development- Patrick Stach&lt;br /&gt;
&lt;br /&gt;
Patrick Stach is Director of Research and Development at Stach &amp;amp; Liu, a firm providing advanced IT security consulting to the Fortune 500 and multi-national financial institutions. Before founding Stach &amp;amp; Liu, Patrick aided in the development of multiple industry leading security scanning engines. In addition to providing security consulting services to Mitsui Zaibatsu, he has led the network security teams for a number of major hosting providers.&lt;br /&gt;
 &lt;br /&gt;
Patrick has lectured on cryptanalysis at Kyoto University, taught as adjunct faculty at Network Associates' Japan Security Academy, and performs government-funded cryptanalysis. He is a developer of the Metasploit Framework and has presented at DefCon, Interz0ne, AtlantaCon, ToorCon, and PhreakNIC.&lt;/div&gt;</summary>
		<author><name>Anastasia Stamos</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=15578</id>
		<title>OWASP Community</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=15578"/>
				<updated>2007-01-18T18:48:18Z</updated>
		
		<summary type="html">&lt;p&gt;Anastasia Stamos: adding SF Chapter Meeting to calendar of events&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page is for people to post OWASP related events, such as chapter meetings, OWASP conferences, get-togethers, and OWASP sponsored events. This page is monitored, and items will be copied to the front page.&lt;br /&gt;
&lt;br /&gt;
Please post new items in chronological order using the following format:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;&lt;br /&gt;
'''Mon ## (##:00h) - [[Article]]'''&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
&lt;br /&gt;
CHAPTER LEADS -- please put your schedule here and we'll post a month in advance&lt;br /&gt;
&lt;br /&gt;
*** VIRGINIA: Every second tuesday of the month ***&lt;br /&gt;
'''xxx xx (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** BOSTON: Every first Wednesday of the month ***&lt;br /&gt;
'''xxx xx (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** TORONTO: Every second Wednesday of the month&lt;br /&gt;
'''xxx xx (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** ROCHESTER: Every third Monday of the month ***&lt;br /&gt;
'''xxx xx (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** NETHERLANDS: Second Thursday of the month sometimes ***&lt;br /&gt;
'''Apr 12 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
'''Sept 13 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
'''Dec 13 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** Melbourne: First Tuesday of the month ***&lt;br /&gt;
'''Mar 6 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
'''Apr 3 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
'''May 1 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
'''Jun 5 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
'''Jul 3 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Events==&lt;br /&gt;
&lt;br /&gt;
'''Feb 13 (18:00h) - [[Ireland|Ireland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 6 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 31 (15:00h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 30 (11:30h) - [[Austin|Austin chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 25 (18:00h) - [[San Francisco| San Francisco chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 25 (14:30h) - [[Italy#October_25th.2C_2007_-_Isaca_Rome|Italy@ISACA Rome]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 24 (17:30h) - [[Israel#6th_OWASP_IL_meeting:_Wednesday.2C_January_24th_2007|6th OWASP Israel chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 23 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 22 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 17 (18:30h) - [[Denver|Denver chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 16 (17:45h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:30h) - [[Phoenix|Phoenix chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 10 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 8 (18:00h) - [[Seattle|Seattle chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 3 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 19 (18:00h) - [[San Jose|San Jose chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 18 (18:30h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 14 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 13 (18:00h) - [[Chicago|Chicago chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 12 (18:30h) - [[Helsinki|Helsinki chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 12 (18:00h) - [[Cleveland|Cleveland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 12 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 7 (17:30h) - [[New Jersey|New Jersey chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 6 (18:30h) - [[Kansas City|Kansas City chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 6 (18:30h) - [[Boston|Boston chapter meeting]] (cancelled)'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 5 (18:00h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 21 (11:30h) - [[Austin|Austin chapter meeting]]&lt;br /&gt;
&lt;br /&gt;
'''Nov 20 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 15 (18:30h) - [[Denver|Denver chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 14 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 13 (14:30h) - [[Israel|Israeli chapter mini-conference at IDC Herzliya]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 11 (10:00h) - [[Switzerland|Kickoff Meeting OWASP Switzerland Local Chapter]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 9 (18:30h) - [[Phoenix|Phoenix chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 8 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 6 (18:00h) - [[Ottawa|Ottawa chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 1 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 31 (12:00h) - [[Austin|Austin OWASP chapter]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 30 (11:00h) - [[Montgomery|Montgomery chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 26 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 24 (18:00h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 16-18 - [[OWASP AppSec Seattle 2006|OWASP AppSec Seattle 2006 Conference]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 16 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 12 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 7 - [[Italy| OWASP Italy at SMAU 06]]'''   &lt;br /&gt;
&lt;br /&gt;
'''Oct 4 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 2 (18:00h) - [[Ottawa|Ottawa chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 29 - [[Italy| OWASP Italy at OpenEXP]]''' &lt;br /&gt;
&lt;br /&gt;
'''Sep 28 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 27 (11:30h) - [[San Antonio|San Antonio chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 26-27 (08:00h) - [[Manila|OWASP Manila presenting at PhilOSC 2006]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 26 (12:00h) - [[Austin|Austin OWASP chapter]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 25 (17:00h) - [[New Jersey|New Jersey chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 21 (17:30h) - [[San Francisco|San Francisco chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 18 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 14 (18:00h) - [[Brisbane|Brisbane chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 14 (18:00h) - [[Belgium|Belgium chapter meeting in Antwerp]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 14 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]] (cancelled)'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 12 - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 31 (15:00h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 31 (08:00h) - [[Manila|OWASP Manila presentation at UST]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 29 (11:30h) - [[Austin|Austin OWASP chapter]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 24 (17:30h) - [[Brisbane|Brisbane chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 23 (11:30h) - [[San Antonio|San Antonio chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 19 - [[Bangalore|Bangalore chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 17 - [[London|London chapter meeting (Central London)]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 10 - [[San Jose|San Jose chapter meeting (SJ Hyatt - Airport)]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 9 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 9 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 8 (18:00h) - [[Minneapolis St Paul|Minneapolis / St.Paul chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 2 (19:30h) - [[OWASP/Blackhat Vegas International Meet-Up]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 31 (15:00h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 27 (12:00h) - [[Austin|Austin OWASP chapter kickoff meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 26 (19:15h) - [[Israel|Israel chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 19 (12:15h) - [[Hong Kong|Hong Kong chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 15 - [[Bangalore|Bangalore chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 12 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 5 (18:00h) - [[Ottawa|Ottawa chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 29 (18:00h) - [[San Jose|San Jose chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 26 (15:30h) - [[BostonFinancialDist|Boston financial district chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 24 (9:30h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 22 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 21 - [[Italy|OWASP presentations at InfoSecurity 2006 (Italy)]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 21 (11:30h) - [[San Antonio|San Antonio chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 20 (18:00h) - [[Minneapolis St Paul|Minneapolis/St. Paul chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 19 (18:00h) - [[Ottawa|Ottawa chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 16 (16:45h) - [[Spain|Spain chapter meeting (Barcelona)]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 14-16 - [http://www.nyphpcon.com NY PHP Conference]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 14 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 2 (12:00h) - [[Hong Kong|Hong Kong chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 29-31 - [[AppSec Europe 2006|OWASP AppSec 2006 Europe Conference]]'''&lt;/div&gt;</summary>
		<author><name>Anastasia Stamos</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=15575</id>
		<title>Bay Area</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Bay_Area&amp;diff=15575"/>
				<updated>2007-01-18T18:43:42Z</updated>
		
		<summary type="html">&lt;p&gt;Anastasia Stamos: OWASP Chapter Meeting Notice for 1/25&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Francisco|extra=The chapter leader is [mailto:bchristian@spidynamics.com Brian Christian]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanfran|emailarchives=http://lists.owasp.org/pipermail/owasp-sanfran}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
'''!!!PLEASE RSVP TO Anastasia Stamos (mailto:anastasia@isecpartners.com) AS THERE IS LIMITED SPACE!!!'''&lt;br /&gt;
&lt;br /&gt;
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
WHAT: San Francisco OWASP Chapter Meeting and Mixer&lt;br /&gt;
&lt;br /&gt;
WHEN: Thursday, January 25th, 2007 &lt;br /&gt;
       &lt;br /&gt;
6:00-6:30   Social (Food and Drinks) and Chapter Announcements&lt;br /&gt;
&lt;br /&gt;
6:30-8:00   Presentation I &amp;quot;XML Digital Signature and Encryption: Use and Abuse&amp;quot;:  Brad Hill, iSEC Partners&lt;br /&gt;
&lt;br /&gt;
8:00-8:15   Q and A	&lt;br /&gt;
&lt;br /&gt;
8:15-9:00   Presentation II: Patrick Stach, Stach and Liu&lt;br /&gt;
&lt;br /&gt;
WHERE: iSEC Partners offices located @ 115 Sansome Street Suite 1005 (10th Floor), San Francisco, CA (http://www.isecpartners.com)&lt;br /&gt;
We recommend arriving by public transit as parking is extremely limited.&lt;br /&gt;
&lt;br /&gt;
WHY: To network, socialize and learn more about Web Application Security &lt;br /&gt;
&lt;br /&gt;
WHO: Brian Christian, Chapter President, will give chapter details and Brad Hill of iSEC Partners will deliver the presentation &amp;quot;XML Digital Signature and Encryption: Use and Abuse&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- &lt;br /&gt;
&lt;br /&gt;
&amp;quot;XML Digital Signature and Encryption: Use and Abuse&amp;quot;&lt;br /&gt;
&lt;br /&gt;
Abstract:&lt;br /&gt;
The WS-Security set of standards is on the threshold of ubiquitous deployment and XML applications have already taken over the world.  This presentation looks at two underlying technologies, XML Digital Signature (XMLDSIG) and XML Encryption (XMLENC), their place in the Web Services stack and their applicability to non-SOAP XML applications.   Beginning with a basic overview of the standards, we will uncover some surprising caveats and risks in the use of these technologies.&lt;br /&gt;
&lt;br /&gt;
Security Consultant - Brad Hill&lt;br /&gt;
&lt;br /&gt;
Brad Hill is a Security Consultant with iSEC Partners.  Brad Hill brings&lt;br /&gt;
to iSEC a decade-plus background working with Internet technologies,&lt;br /&gt;
including serving as the lead developer of Web applications and&lt;br /&gt;
frameworks for one of the premier private label recordkeeping and&lt;br /&gt;
management companies in the financial services industry, where his&lt;br /&gt;
responsibilities also included security training, policy development and&lt;br /&gt;
compliance.  With iSEC he has performed penetration testing and design&lt;br /&gt;
review for a wide spectrum of products and technologies, most recently&lt;br /&gt;
participating in the Final Security Review of Microsoft Windows Vista.&lt;br /&gt;
Brad achieved the Certified Information Systems Security Professional&lt;br /&gt;
(CISSP) credential in 2004.&lt;br /&gt;
&lt;br /&gt;
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-&lt;br /&gt;
&lt;br /&gt;
Presentation II&lt;br /&gt;
&lt;br /&gt;
Abstract:&lt;br /&gt;
This talk aims to outline a few commonly overlooked cryptographic vulnerabilities in web applications.  The problems presented will range from attacks against authentication various authentication schemes to improper certificate generation.&lt;br /&gt;
&lt;br /&gt;
Director of Research and Development- Patrick Stach&lt;br /&gt;
&lt;br /&gt;
Patrick Stach is Director of Research and Development at Stach &amp;amp; Liu, a firm providing advanced IT security consulting to the Fortune 500 and multi-national financial institutions. Before founding Stach &amp;amp; Liu, Patrick aided in the development of multiple industry leading security scanning engines. In addition to providing security consulting services to Mitsui Zaibatsu, he has led the network security teams for a number of major hosting providers.&lt;br /&gt;
 &lt;br /&gt;
Patrick has lectured on cryptanalysis at Kyoto University, taught as adjunct faculty at Network Associates' Japan Security Academy, and performs government-funded cryptanalysis. He is a developer of the Metasploit Framework and has presented at DefCon, Interz0ne, AtlantaCon, ToorCon, and PhreakNIC.&lt;/div&gt;</summary>
		<author><name>Anastasia Stamos</name></author>	</entry>

	</feed>