<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bbertacini</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bbertacini"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Bbertacini"/>
		<updated>2026-05-27T09:21:15Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21397</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=21397"/>
				<updated>2007-09-03T06:49:23Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Next Meeting - Thursday, September 6, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, September 6, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
5:00pm – 5:30pm           Check-in and Reception (food and beverages)&amp;lt;br/&amp;gt;&lt;br /&gt;
5:30pm – 6:45pm           Malicious Code Injection Workshop&amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 6:55pm           Break&amp;lt;br/&amp;gt;&lt;br /&gt;
6:55pm – 8:10pm           Panel Discussion – Privacy, Security and Breaches, Oh My!&amp;lt;br/&amp;gt;&lt;br /&gt;
8:10pm – 8:30pm           Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
eBay - Town Square B&amp;lt;br/&amp;gt;&lt;br /&gt;
2161 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95131&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Map and Directions:''&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://maps.yahoo.com/broadband#mvt=m&amp;amp;q1=2211+N+1st+Street%2C+San+Jose%2C+CA&amp;amp;trf=0&amp;amp;lon=-121.921484&amp;amp;lat=37.377166&amp;amp;mag=3 Map]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Malicious Code Injection Workshop'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
SQL Injection, Cross-site Scripting (XSS) and other injection attacks techniques have become pervasive on the web.  This hands-on workshop takes an in-depth look at common methods used to exploit web applications.  Attendees will learn step-by-step techniques used by attackers allowing them to better understand how web applications are exploited.  Each attack method is followed up with a discussion about effective countermeasures to defend against such attacks. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This interactive workshop includes a victim web application that contains built-in vulnerabilities.  Attendees can bring their own laptop computers and participate in hands-on lab sessions.  The objective of this workshop is to learn secure development practices used to harden the security of applications.  Attendee participation is encouraged and door prizes will be awarded at random. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
''Note:''  To participate in the exercise bring an 802.11b/g equipped laptop with IE or Firefox installed. No hostile code will be put on your laptop by the instructors, but do have a firewall running to protect yourself. No wired connection to the class network will be provided.&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Workshop Instructors:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Siva Ram, CISA - Senior Consultant, AppSec Consulting&amp;lt;br/&amp;gt;&lt;br /&gt;
Tom Stracener - Cenzic&amp;lt;br/&amp;gt;&lt;br /&gt;
Arian Evans - WhiteHat Security&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panel Discussion: “Privacy, Security and Breaches, Oh My!” '''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This panel discussion will review the current state of information privacy and the security of web applications.  Security breaches are occurring at an alarming rate and consumers are loosing faith.  What, if anything can be done to restore confidence in e-commerce?&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
What can we learn from events at Card Systems are more recently Monster.com?  What can be done to ensure your company is not the next victim of a class action and/or hackers and data thieves?  Join an all-star panel of Information Privacy and Data Security professionals to better understand what’s at stake and how to stay out of the headlines. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Moderator:'''          Alex Stamos, iSEC Partners&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Panelists:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Doran Rotman, KPMG (co-author, Generally Accepted Privacy Principles&amp;lt;br/&amp;gt;&lt;br /&gt;
David Pollino, Washington Mutual Bank&amp;lt;br/&amp;gt;&lt;br /&gt;
Robert Fly, Salesforce.com&amp;lt;br/&amp;gt;&lt;br /&gt;
Larry Pingree, Safeway (co-founder, Digital Forensics Association)&amp;lt;br/&amp;gt;&lt;br /&gt;
Kurt Opsahl, EFF &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please RSVP at http://owaspday.eventbrite.com or send an email to brian.bertacini at owasp.org. Feel free to invite like minded IT Security Professionals and help grow OWASP.&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=19861</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=19861"/>
				<updated>2007-07-13T19:42:09Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Next Meeting - Wednesday, July 25, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Wednesday, July 25, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm - 6:30pm ... Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm - 7:15pm ... Attacking XML Security - Brad Hill&amp;lt;br/&amp;gt;&lt;br /&gt;
7:15pm - 8:00pm ... Development of a Security Metric System to Rate Enterprise Software - Fredrick Lee&amp;lt;br/&amp;gt;&lt;br /&gt;
8:00pm - 8:30pm ... Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Ariba&amp;lt;br/&amp;gt;&lt;br /&gt;
807 11th Avenue&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, Ca 94089&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ariba.com/company/hq_map.cfm Map and Directions]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Attacking XML Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brad Hill, iSEC Partners'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
Brad will present his ongoing research into attacking the XML Digital Signature and Encryption standards that underpin the security  of Web Services, mobile code, SAML, federated identity systems and more.  The talk will begin with a high-level, critical take on the emerging conventional wisdom about message-oriented security and continue with a detailed discussion of design and implementation weaknesses in the standards.  Technical material will include a root cause analysis of the recent iSEC advisory on cross-platform, remote code execution vulnerabilities discovered in multiple XML Digital Signature products. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Based out of Seattle, Brad Hill is a Senior Security Consultant at iSEC Partners, a full-service security consulting firm that provides penetration testing, secure systems development, security education and software design verification.   Brad brings a ten year background as a software developer and architect in the technology and financial services sectors to his work at iSEC, where he does design review, application assessment and development lifecycle improvement for some of the world’s leading software companies.  &lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Development of a Security Metric System to Rate Enterprise Software'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Fredrick Lee, Fortify Software'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
As part of Fortify Software’s Java Open Review (JOR) project, both security defects and quality issues discovered in open source software are collected. The projects being analyzed are diverse in their development methodologies, development stages, and application styles. The projects range from small utility packages (e.g. Apache Commons), to mid-size intranet applications (e.g. JSPWiki), to large-scale, commercial grade enterprise projects (e.g. JBoss). In essence, participants in the Java Open Review project reflect the typical enterprise organization’s code base: a large collection of several small utility/internal applications and a handful of enterprise “flagship” products.&lt;br /&gt;
&lt;br /&gt;
As part of the project, we have been challenged to answer the question: Which&lt;br /&gt;
application is more “secure.” To answer this question, Fortify has sought to develop a set of metrics that combine lessons learned from our experience working on various enterprise code bases and our work on the JOR project. The metrics are designed to incorporate diverse criteria, including the size of the application, the types of vulnerabilities identified, and time required to fix the vulnerabilities. The metrics provide a mechanism to rate software components for security concerns and enable enterprises to:&lt;br /&gt;
&lt;br /&gt;
- Evaluate which open source projects offer an acceptable level of security &amp;lt;br/&amp;gt;&lt;br /&gt;
- Compare competing open source software solutions based on their security &amp;lt;br/&amp;gt;&lt;br /&gt;
- Measure internal development efforts against open source open source counterparts&lt;br /&gt;
&lt;br /&gt;
Ultimately, with sufficient industry adoption, the metrics can also enable enterprises to compare their internal efforts against other enterprises within the same vertical. As part of the talk we will present our experience to date working with companies to develop an effective mechanism for evaluating the security of enterprise software.&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Fredrick Lee is a member of Fortify Software’s Security Research Group, where he manages the Java Open Review Project. Scanning the code of over 100 applications so far, Fredrick is helping assess and improve the security of open source software. Fredrick also helps the Security Research Group develop the secure coding rules that are use to run Fortify’s suite of products. &lt;br /&gt;
 &lt;br /&gt;
Prior to joining Fortify Software, Fredrick was a Senior Information Security Engineer at Bank of America, where he helped roll out a secure development framework, performed security assessments, and developed enterprise security solutions. &lt;br /&gt;
 &lt;br /&gt;
Fredrick graduated from the University of Oklahoma, with a BS in Computer Engineering. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Upcoming Security Workshops'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brian Bertacini, Volunteer Chapter Organizer'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' Introduce local volunteer expert trainers that are planning web application and infrastructure security workshops.&lt;br /&gt;
&lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
Special thanks to [http://www.ariba.com Ariba] for hosting this event and to [http://www.appsecconsulting.com AppSec Consulting] and [http://www.isecpartners.com iSEC Partners] for sponsoring.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=19860</id>
		<title>OWASP Community</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=19860"/>
				<updated>2007-07-13T19:07:11Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page is for people to post OWASP related events, such as chapter meetings, OWASP conferences, get-togethers, and OWASP sponsored events.&lt;br /&gt;
&lt;br /&gt;
Events from previous years are archived here:&lt;br /&gt;
* '''[[OWASP Community 2006]]'''&lt;br /&gt;
&lt;br /&gt;
This page is monitored, and items posted here will be copied to the OWASP [[Main Page]].  Please post new items in chronological order using the following format:&lt;br /&gt;
&lt;br /&gt;
 '''Mon ## (##:00h) - [[Article]]'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
&lt;br /&gt;
CHAPTER LEADS -- please put your schedule here and we'll post a month in advance&lt;br /&gt;
&lt;br /&gt;
*** Belgium ***&lt;br /&gt;
&lt;br /&gt;
*** OTTAWA: Rough dates ***&lt;br /&gt;
'''Sept 12 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
'''Nov 14 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
&lt;br /&gt;
*** BOSTON: Every first Wednesday of the month ***&lt;br /&gt;
&lt;br /&gt;
*** MELBOURNE: First Tuesday of the month ***&lt;br /&gt;
'''Jul 3 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** NETHERLANDS: Second Thursday of the month sometimes ***&lt;br /&gt;
'''Sept 13 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
'''Dec 13 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** ROCHESTER: Every third Monday of the month ***&lt;br /&gt;
&lt;br /&gt;
*** TORONTO: Every second Wednesday of the month&lt;br /&gt;
&lt;br /&gt;
*** VIRGINIA: Every second thursday of the month ***&lt;br /&gt;
&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Events==&lt;br /&gt;
'''July 25 (18:00h) - [[San Jose|San Jose Chapter Meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''July 24 (17:00h) - [[Switzerland|Switzerland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''July 14 (11:00h) - [[Turkey|Turkey chapter meeting - 1st Web Security Days]]'''&lt;br /&gt;
&lt;br /&gt;
'''July 6 (17:00h) - [[Spain|Spain chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 26 (11:30hr) - [[Austin|Austin chapter meeting]]''' - Running Web Application Scans&lt;br /&gt;
&lt;br /&gt;
'''June 22 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 21 (19:00h) - [[Denver]]''' - Anti-DNS Pinning Attacks / Calculating Return on Security Investment (ROSI)&lt;br /&gt;
&lt;br /&gt;
'''June 19 (18:00h) - [[Minneapolis St Paul|Minneapolis St Paul chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 15 (17:00hr) - [[Spain|Spain chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 13 (18:30hr) - [[Kansas City|Kansas City chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 12 (18:00hr) - [[New York|NY/NJ Metro chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 5 (19:00h) - [[Helsinki|Helsinki chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 5 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 5 (17:30h) - [[Houston | Houston Chapter Meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 29 (9:00h) - [[http://www.owasp.org/index.php/Italy#May_29th.2C_2007_-_Seminar:_.22Software_Security.22 Italy@Firenze Tecnologia]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 29 (11:30h) - [[Austin | Austin Chapter Meeting]]''' - Bullet Proof UI - A programmer's guide to the complete idiot&amp;quot;. &lt;br /&gt;
&lt;br /&gt;
'''May 29 (18:00h) - [[Ottawa | Ottawa Chapter Meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 22 (18:30h) - [[New Zealand|1st New Zealand chapter Meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 21 (14:00h) - [[Israel|2nd OWASP Israel mini conference]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 15 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 10 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 9 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 8 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 6 (11:00h) - [[Turkey|Turkey chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 2 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 1 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 26 (11:00h) - [[San Antonio|San Antonio chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 26 (17:00h) - [[Switzerland|Switzerland chapter meeting and &amp;quot;Swiss Security Dinner&amp;quot;]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 24 (18:00h) - [[Minneapolis St Paul|Minneapolis St Paul chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 20 (19:00h) - [[Hong Kong|Hong Kong chapter meeting - Objectives for 2007]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 19 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 18 (17:00h) - [[San Francisco City Chapter Meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 17 (18:00h) - [[New Jersey|NY/NJ Metro chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 17 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 12 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 12 (18:00h) - [[San Jose|San Jose chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 11 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 4 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 3 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 30 - [[http://www.owasp.org/index.php/Italy#March_30th.2C_2007_-_Master_in_Security_-_University_of_Rome_.22La_Sapienza.22| Italy@Master in Security at &amp;quot;La Sapienza&amp;quot;]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 28 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 28 (11:30h) - [[San Antonio|San Antonio chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
; '''Mar 27-30 - [http://www.blackhat.com Black Hat Euro]'''&lt;br /&gt;
: OWASP members receive a Euro 100 Briefings discount by inserting BH7EUASSOC in the box marked “Coupon Codes”&lt;br /&gt;
&lt;br /&gt;
'''Mar 22 (18:00h) - [[London|London chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 21-22 - [[Belgium#OWASP_Top_10_2007_Update_.28Infosecurity_Belgium.2C_21_.26_.2622_Mar_2007.29|Belgium@InfoSecurity]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 20 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 14 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 14 (18:00h) - [[Chicago|Chicago chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 13 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 8 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
&lt;br /&gt;
'''Mar 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 7 (18:30h) - [[Kansas City|Kansas City chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 6 (18:30h) - [[Philadelphia|Philadelphia chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 6 (18:30h) - [[San Francisco|San Francisco and San Jose chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 6 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 5 (11:00h) - [[New Jersey|New Jersey chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 1 (11:30h) - [http://www.eusecwest.com/agenda.html EUSecWest 07: Testing Guide]'''&lt;br /&gt;
&lt;br /&gt;
; '''Feb 26-Mar 1 - [http://www.blackhat.com Black Hat DC]'''&lt;br /&gt;
: OWASP members receive a $100 Briefings discount by inserting BH7DCASSOC in the box marked “Coupon Codes”&lt;br /&gt;
&lt;br /&gt;
'''Feb 28 (18:00h) - [[Seattle|Seattle chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 27 (18:00h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 22 (18:30h) - [[Helsinki|Helsinki chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 22 (18:00h) - [[London|London chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 21 (18:30h) - [[Denver|Denver chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 19 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 15 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 15 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 14 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 13 (18:00h) - [[Ireland|Ireland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 12 (18:30h) - [[Switzerland|Switzerland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 6-7 - [[Italy#February_6th-8th.2C_2007_-_InfoSecurity|Italy@InfoSecurity]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 6 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 2 (14:00h) - [[Chennai|Chennai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 31 (15:00h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 30 (11:30h) - [[Austin|Austin chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 25 (18:00h) - [[San Francisco| San Francisco chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 25 (14:30h) - [[Italy#October_25th.2C_2007_-_Isaca_Rome|Italy@ISACA Rome]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 24 (17:30h) - [[Israel#6th_OWASP_IL_meeting:_Wednesday.2C_January_24th_2007|6th OWASP Israel chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 23 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 22 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 17 (18:30h) - [[Denver|Denver chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 16 (17:45h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:30h) - [[Phoenix|Phoenix chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 10 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 8 (18:00h) - [[Seattle|Seattle chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 3 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 1 - [[Melbourne | Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 2 - [[Boston]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 6 - [[Turkey]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 8 - [[Virginia (Northern Virginia)|Washington DC (VA)]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 9 - [[Toronto]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 10 - [[Belgium]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 15 - [[Rochester]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 21 - [[Israel]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 22 - [[New Zealand]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 29 - [[Italy]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 5 - [[Houston]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 5 - [[Melbourne]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 5 - [[Helsinki]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 12 - [[New Jersey]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 15 - [[Spain]]'''&lt;br /&gt;
&lt;br /&gt;
'''July 14 - [[Turkey]]'''&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=19859</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=19859"/>
				<updated>2007-07-13T18:20:12Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Next Meeting - Wednesday, July 25, 2007 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Wednesday, July 25, 2007 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm - 6:30pm ... Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm - 8:00pm ... Attacking XML Security - Brad Hill&amp;lt;br/&amp;gt;&lt;br /&gt;
8:00pm - 8:15pm ... Upcoming Security Workshops - Brian Bertacini&amp;lt;br/&amp;gt;&lt;br /&gt;
8:15pm - 8:35pm ... Networking Session&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Ariba&amp;lt;br/&amp;gt;&lt;br /&gt;
807 11th Avenue&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, Ca 94089&amp;lt;br/&amp;gt;&lt;br /&gt;
[http://www.ariba.com/company/hq_map.cfm Map and Directions]&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Attacking XML Security'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brad Hill, iSEC Partners'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' &lt;br /&gt;
Brad will present his ongoing research into attacking the XML Digital Signature and Encryption standards that underpin the security  of Web Services, mobile code, SAML, federated identity systems and more.  The talk will begin with a high-level, critical take on the emerging conventional wisdom about message-oriented security and continue with a detailed discussion of design and implementation weaknesses in the standards.  Technical material will include a root cause analysis of the recent iSEC advisory on cross-platform, remote code execution vulnerabilities discovered in multiple XML Digital Signature products. &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Based out of Seattle, Brad Hill is a Senior Security Consultant at iSEC Partners, a full-service security consulting firm that provides penetration testing, secure systems development, security education and software design verification.   Brad brings a ten year background as a software developer and architect in the technology and financial services sectors to his work at iSEC, where he does design review, application assessment and development lifecycle improvement for some of the world’s leading software companies.  &lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Upcoming Security Workshops'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brian Bertacini, Volunteer Chapter Organizer'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' Introduce local volunteer expert trainers that are planning web application and infrastructure security workshops.&lt;br /&gt;
&lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
Special thanks to [http://www.ariba.com Ariba] for hosting this event and to [http://www.appsecconsulting.com AppSec Consulting] and [http://www.isecpartners.com iSEC Partners] for sponsoring.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=17654</id>
		<title>OWASP Community</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=17654"/>
				<updated>2007-04-02T17:05:05Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page is for people to post OWASP related events, such as chapter meetings, OWASP conferences, get-togethers, and OWASP sponsored events.&lt;br /&gt;
&lt;br /&gt;
Events from previous years are archived here:&lt;br /&gt;
* '''[[OWASP Community 2006]]'''&lt;br /&gt;
&lt;br /&gt;
This page is monitored, and items posted here will be copied to the OWASP [[Main Page]].  Please post new items in chronological order using the following format:&lt;br /&gt;
&lt;br /&gt;
 '''Mon ## (##:00h) - [[Article]]'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
&lt;br /&gt;
CHAPTER LEADS -- please put your schedule here and we'll post a month in advance&lt;br /&gt;
&lt;br /&gt;
*** Belgium ***&lt;br /&gt;
&lt;br /&gt;
*** OTTAWA: Rough dates ***&lt;br /&gt;
'''Sept 12 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
'''Nov 14 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
&lt;br /&gt;
*** BOSTON: Every first Wednesday of the month ***&lt;br /&gt;
&lt;br /&gt;
*** MELBOURNE: First Tuesday of the month ***&lt;br /&gt;
'''Jun 5 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
'''Jul 3 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** NETHERLANDS: Second Thursday of the month sometimes ***&lt;br /&gt;
'''Sept 13 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
'''Dec 13 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** ROCHESTER: Every third Monday of the month ***&lt;br /&gt;
&lt;br /&gt;
*** TORONTO: Every second Wednesday of the month&lt;br /&gt;
&lt;br /&gt;
*** VIRGINIA: Every second tuesday of the month ***&lt;br /&gt;
&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Events==&lt;br /&gt;
'''May 15 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 10 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 9 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 9 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
&lt;br /&gt;
'''May 8 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 2 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 1 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 21 (14:00h) - [[Israel|2nd OWASP Israel mini conference]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 26 (17:00h) - [[Switzerland|Switzerland chapter meeting and &amp;quot;Swiss Security Dinner&amp;quot;]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 20 (19:00h) - [[Hong Kong|Hong Kong chapter meeting - Objectives for 2007]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 17 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 17 (18:00h) - [[New Jersey|NY/NJ Metro chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 12 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 12 (18:00h) - [[San Jose|San Jose chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 11 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 10 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 4 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 3 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 30 - [[http://www.owasp.org/index.php/Italy#March_30th.2C_2007_-_Master_in_Security_-_University_of_Rome_.22La_Sapienza.22| Italy@Master in Security at &amp;quot;La Sapienza&amp;quot;]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 28 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 28 (11:30h) - [[San Antonio|San Antonio chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
; '''Mar 27-30 - [http://www.blackhat.com Black Hat Euro]'''&lt;br /&gt;
: OWASP members receive a Euro 100 Briefings discount by inserting BH7EUASSOC in the box marked “Coupon Codes”&lt;br /&gt;
&lt;br /&gt;
'''Mar 22 (18:00h) - [[London|London chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 21-22 - [[Belgium#OWASP_Top_10_2007_Update_.28Infosecurity_Belgium.2C_21_.26_.2622_Mar_2007.29|Belgium@InfoSecurity]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 20 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 14 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 14 (18:00h) - [[Chicago|Chicago chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 13 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 8 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
&lt;br /&gt;
'''Mar 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 7 (18:30h) - [[Kansas City|Kansas City chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 6 (18:30h) - [[Philadelphia|Philadelphia chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 6 (18:30h) - [[San Francisco|San Francisco and San Jose chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 6 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 5 (11:00h) - [[New Jersey|New Jersey chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 1 (11:30h) - [http://www.eusecwest.com/agenda.html EUSecWest 07: Testing Guide]'''&lt;br /&gt;
&lt;br /&gt;
; '''Feb 26-Mar 1 - [http://www.blackhat.com Black Hat DC]'''&lt;br /&gt;
: OWASP members receive a $100 Briefings discount by inserting BH7DCASSOC in the box marked “Coupon Codes”&lt;br /&gt;
&lt;br /&gt;
'''Feb 28 (18:00h) - [[Seattle|Seattle chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 27 (18:00h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 22 (18:30h) - [[Helsinki|Helsinki chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 22 (18:00h) - [[London|London chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 21 (18:30h) - [[Denver|Denver chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 19 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 15 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 15 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 14 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 13 (18:00h) - [[Ireland|Ireland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 12 (18:30h) - [[Switzerland|Switzerland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 6-7 - [[Italy#February_6th-8th.2C_2007_-_InfoSecurity|Italy@InfoSecurity]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 6 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 2 (14:00h) - [[Chennai|Chennai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 31 (15:00h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 30 (11:30h) - [[Austin|Austin chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 25 (18:00h) - [[San Francisco| San Francisco chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 25 (14:30h) - [[Italy#October_25th.2C_2007_-_Isaca_Rome|Italy@ISACA Rome]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 24 (17:30h) - [[Israel#6th_OWASP_IL_meeting:_Wednesday.2C_January_24th_2007|6th OWASP Israel chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 23 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 22 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 17 (18:30h) - [[Denver|Denver chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 16 (17:45h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:30h) - [[Phoenix|Phoenix chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 10 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 8 (18:00h) - [[Seattle|Seattle chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 3 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=14040</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=14040"/>
				<updated>2006-12-08T07:30:29Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Next Meeting - Tuesday, December 19, 2006 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Tuesday, December 19, 2006 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm – 6:30pm ... Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm – 6:45pm ... About OWASP, Brian Bertacini &amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 7:30pm ... Latest Web Application Security Trends and Statistics, Jeremiah Grossman&amp;lt;br/&amp;gt;&lt;br /&gt;
7:30pm – 8:30pm ... Networking &amp;amp; Holiday Reception&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Fujitsu Advanced Networking Solutions&amp;lt;br/&amp;gt;&lt;br /&gt;
1240 E. Arques Ave.&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, CA 94085&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''New Trends and Web Application Security Statistics'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Jeremiah Grossman, Founder &amp;amp; CTO, WhiteHat Security'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' First Look at New Web Application Security Statistics.  The Top 10 Web Application Vulnerabilities and their  Impact on the Enterprise Web applications are the newest attack target, hitting the biggest and best brands on the Internet.  And yet, until now, there has been limited information available about the most prevalent and most severe vulnerabilities that are facilitating the rapidly rising number of attacks.&lt;br /&gt;
&lt;br /&gt;
WhiteHat Security founder and CTO, Jeremiah Grossman, will present the findings from the first WhiteHat Security Web Application Security Risk Report.  Based on WhiteHat’s aggregate data from hundreds of web application assessments, Mr.Grossman's presentation will provide a first-of-its-kind look at the top vulnerabilities that attackers are exploiting at businesses across the Web.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
•    Identify and discuss the top ten vulnerabilities &amp;lt;br/&amp;gt;&lt;br /&gt;
•    Define the severity levels of web application vulnerabilities &amp;lt;br/&amp;gt;&lt;br /&gt;
•    Present strategies for web application vulnerability management &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Mr. Grossman is a world-renowned expert in Web security and a founding member of the Web Application Security Consortium.  He is a frequent speaker at industry events including the BlackHat Briefings, ISACA’s Networks Security Conference, NASA, the Air Force and Technology Conference, ISSA and Defcon.  Mr. Grossman is also a featured expert and frequent contributor on TechTarget’s SearchAppSecurity.com.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
'''About OWASP'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brian Bertacini, Volunteer chapter organizer'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' An overview of the Open Web Application Security Project (OWASP), current projects and feedback from the recent WebAppSec Conference in Seattle.  &lt;br /&gt;
&lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
Special thanks to [http://www.fsba.com Fujitsu Advanced Networking Solutions] for hosting this event.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=14039</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=14039"/>
				<updated>2006-12-08T07:20:01Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Next Meeting - Tuesday, December 19, 2006 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Tuesday, December 19, 2006 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm – 6:30pm ... Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm – 6:45pm ... About OWASP, Brian Bertacini &amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 7:30pm ... Latest Web Application Security Trends and Statistics, Jeremiah Grossman&amp;lt;br/&amp;gt;&lt;br /&gt;
7:30pm – 8:30pm ... Networking &amp;amp; Holiday Reception&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Fujitsu Advanced Networking Solutions&amp;lt;br/&amp;gt;&lt;br /&gt;
1240 E. Arques Ave.&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, CA 94085&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''New Trends and Web Application Security Statistics'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Jeremiah Grossman, Founder &amp;amp; CTO, WhiteHat Security'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' First Look at New Web Application Security Statistics.  The Top 10 Web Application Vulnerabilities and their  Impact on the Enterprise Web applications are the newest attack target, hitting the biggest and best brands on the Internet.  And yet, until now, there has been limited information available about the most prevalent and most severe vulnerabilities that are facilitating the rapidly rising number of attacks.&lt;br /&gt;
&lt;br /&gt;
WhiteHat Security founder and CTO, Jeremiah Grossman, will present the findings from the first WhiteHat Security Web Application Security Risk Report.  Based on WhiteHat’s aggregate data from hundreds of web application assessments, Mr.Grossman's presentation will provide a first-of-its-kind look at the top vulnerabilities that attackers are exploiting at businesses across the Web.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
•    Identify and discuss the top ten vulnerabilities &amp;lt;br/&amp;gt;&lt;br /&gt;
•    Define the severity levels of web application vulnerabilities &amp;lt;br/&amp;gt;&lt;br /&gt;
•    Present strategies for web application vulnerability management &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Mr. Grossman is a world-renowned expert in Web security and a founding member of the Web Application Security Consortium.  He is a frequent speaker at industry events including the BlackHat Briefings, ISACA’s Networks Security Conference, NASA, the Air Force and Technology Conference, ISSA and Defcon.  Mr. Grossman is also a featured expert and frequent contributor on TechTarget’s SearchAppSecurity.com.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
'''About OWASP'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Brian Bertacini, Volunteer chapter organizer'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' An overview of the Open Web Application Security Project (OWASP), current projects and feedback from the recent WebAppSec Conference in Seatle.  &lt;br /&gt;
&lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
Special thanks to [http://www.fsba.com Fujitsu Advanced Networking Solutions] for hosting this event.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=14038</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=14038"/>
				<updated>2006-12-08T07:06:15Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Next Meeting - Tuesday, December 19, 2006 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Tuesday, December 19, 2006 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm – 6:30pm ... Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm – 6:45pm ... About OWASP, Brian Bertacini &amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 7:30pm ... Latest Web Application Security Trends and Statistics, Jeremiah Grossman&amp;lt;br/&amp;gt;&lt;br /&gt;
7:30pm – 8:30pm ... Networking &amp;amp; Holiday Reception&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Fujitsu Advanced Networking Solutions&amp;lt;br/&amp;gt;&lt;br /&gt;
1240 E. Arques Ave.&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, CA 94085&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''New Trends and Web Application Security Statistics'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Jeremiah Grossman, Founder &amp;amp; CTO, WhiteHat Security'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' First Look at New Web Application Security Statistics.  The Top 10 Web Application Vulnerabilities and their  Impact on the Enterprise Web applications are the newest attack target, hitting the biggest and best brands on the Internet.  And yet, until now, there has been limited information available about the most prevalent and most severe vulnerabilities that are facilitating the rapidly rising number of attacks.&lt;br /&gt;
&lt;br /&gt;
WhiteHat Security founder and CTO, Jeremiah Grossman, will present the findings from the first WhiteHat Security Web Application Security Risk Report.  Based on WhiteHat’s aggregate data from hundreds of web application assessments, Mr.Grossman's presentation will provide a first-of-its-kind look at the top vulnerabilities that attackers are exploiting at businesses across the Web.&lt;br /&gt;
&lt;br /&gt;
•    Identify and discuss the top ten vulnerabilities&lt;br /&gt;
•    Define the severity levels of web application vulnerabilities&lt;br /&gt;
•    Present strategies for web application vulnerability management&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Mr. Grossman is a world-renowned expert in Web security and a founding member of the Web Application Security Consortium.  He is a frequent speaker at industry events including the BlackHat Briefings, ISACA’s Networks Security Conference, NASA, the Air Force and Technology Conference, ISSA and Defcon.  Mr. Grossman is also a featured expert and frequent contributor on TechTarget’s SearchAppSecurity.com.&lt;br /&gt;
&lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
Special thanks to [http://www.fsba.com Fujitsu Advanced Networking Solutions] for hosting this event.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=14037</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=14037"/>
				<updated>2006-12-08T07:03:47Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Next Meeting - Tuesday, December 19, 2006 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Tuesday, December 19, 2006 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm – 6:30pm   Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm – 6:45pm   About OWASP, Brian Bertacini &amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 7:30pm   Latest Web Application Security Trends and Statistics, Jeremiah Grossman&amp;lt;br/&amp;gt;&lt;br /&gt;
7:30pm – 8:30pm   Networking &amp;amp; Holiday Reception&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Fujitsu Advanced Networking Solutions&amp;lt;br/&amp;gt;&lt;br /&gt;
1240 E. Arques Ave.&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, CA 94085&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''New Trends and Web Application Security Statistics'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Jeremiah Grossman, Founder &amp;amp; CTO, WhiteHat Security'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' First Look at New Web Application Security Statistics.  The Top 10 Web Application Vulnerabilities and their  Impact on the Enterprise Web applications are the newest attack target, hitting the biggest and best brands on the Internet.  And yet, until now, there has been limited information available about the most prevalent and most severe vulnerabilities that are facilitating the rapidly rising number of attacks.&lt;br /&gt;
&lt;br /&gt;
WhiteHat Security founder and CTO, Jeremiah Grossman, will present the findings from the first WhiteHat Security Web Application Security Risk Report.  Based on WhiteHat’s aggregate data from hundreds of web application assessments, Mr.Grossman's presentation will provide a first-of-its-kind look at the top vulnerabilities that attackers are exploiting at businesses across the Web.&lt;br /&gt;
&lt;br /&gt;
•    Identify and discuss the top ten vulnerabilities&lt;br /&gt;
•    Define the severity levels of web application vulnerabilities&lt;br /&gt;
•    Present strategies for web application vulnerability management&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Mr. Grossman is a world-renowned expert in Web security and a founding member of the Web Application Security Consortium.  He is a frequent speaker at industry events including the BlackHat Briefings, ISACA’s Networks Security Conference, NASA, the Air Force and Technology Conference, ISSA and Defcon.  Mr. Grossman is also a featured expert and frequent contributor on TechTarget’s SearchAppSecurity.com.&lt;br /&gt;
&lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
Special thanks to [http://www.fsba.com Fujitsu Advanced Networking Solutions] for hosting this event.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=14036</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=14036"/>
				<updated>2006-12-08T06:57:38Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Next Meeting - Thursday, August 10, 2006 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-sanjose|emailarchives=http://lists.owasp.org/pipermail/owasp-sanjose}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Tuesday, December 19, 2006 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm – 6:30pm      Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm – 6:45pm      About OWASP, Brian Bertacini, AppSec Consulting &amp;lt;br/&amp;gt;&lt;br /&gt;
6:45pm – 7:30pm      Latest Web Application Security Trends and Statistics, Jeremiah Grossman, Founder &amp;amp; CTO Whitehat Security&amp;lt;br/&amp;gt;&lt;br /&gt;
7:30pm – 8:30pm      Open discussion &amp;amp; Networking&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
Fujitsu Advanced Networking Solutions&amp;lt;br/&amp;gt;&lt;br /&gt;
1240 E. Arques Ave.&amp;lt;br/&amp;gt;&lt;br /&gt;
Sunnyvale, CA 94085&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''New Trends and Web Application Security Statistics'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Jeremiah Grossman, Founder &amp;amp; CTO, WhiteHat Security'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' First Look at New Web Application Security Statistics.  The Top 10 Web Application Vulnerabilities and their  Impact on the Enterprise Web applications are the newest attack target, hitting the biggest and best brands on the Internet.  And yet, until now, there has been limited information available about the most prevalent and most severe vulnerabilities that are facilitating the rapidly rising number of attacks.&lt;br /&gt;
&lt;br /&gt;
WhiteHat Security founder and CTO, Jeremiah Grossman, will present the findings from the first WhiteHat Security Web Application Security Risk Report.  Based on WhiteHat’s aggregate data from hundreds of web application assessments, Mr.Grossman's presentation will provide a first-of-its-kind look at the top vulnerabilities that attackers are exploiting at businesses across the Web.&lt;br /&gt;
&lt;br /&gt;
•    Identify and discuss the top ten vulnerabilities&lt;br /&gt;
•    Define the severity levels of web application vulnerabilities&lt;br /&gt;
•    Present strategies for web application vulnerability management&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Mr. Grossman is a world-renowned expert in Web security and a founding member of the Web Application Security Consortium.  He is a frequent speaker at industry events including the BlackHat Briefings, ISACA’s Networks Security Conference, NASA, the Air Force and Technology Conference, ISSA and Defcon.  Mr. Grossman is also a featured expert and frequent contributor on TechTarget’s SearchAppSecurity.com.&lt;br /&gt;
&lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This event is co-sponsored by [http://www.appsecconsulting.com AppSec Consulting, Inc]. and [http://www.whitehatsec.com WhiteHat Security, Inc.]&lt;br /&gt;
&lt;br /&gt;
Special thanks to [http://www.fsba.com Fujitsu Advanced Networking Solutions] for hosting this event.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:San_Jose&amp;diff=14035</id>
		<title>Talk:San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:San_Jose&amp;diff=14035"/>
				<updated>2006-12-08T06:32:10Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Previous Meetings: */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Previous Meetings: ==&lt;br /&gt;
 &lt;br /&gt;
'''August 10, 2006 - The Next Generation of Vulnerable Applications'''&lt;br /&gt;
&lt;br /&gt;
'''Presented by: Alex Stamos, Founding Partner, iSEC Partners'''&lt;br /&gt;
&lt;br /&gt;
'''Abstract:''' Web Services represent a new and unexplored set of security-sensitive technologies that have been widely deployed by large companies, governments, financial institutions, and in consumer applications. Unfortunately, the attributes that make web services attractive, such as their ease of use, platform independence, use of HTTP and powerful functionality, also make them a great target for attack. In this talk, we will explain the basic technologies (such as XML, SOAP, and UDDI) upon which web services are built, and explore the innate security weaknesses in each. We will then demonstrate new attacks that exist in web service infrastructures, and show how classic web application attacks (SQL Injection, XSS, etc…) can be retooled to work with the next-generation of enterprise applications. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Alex Stamos is a founding partner of iSEC Partners - a strategic digital security organization. Alex is an experienced security engineer and consultant specializing in application security and securing large infrastructures, and has taught multiple classes in network and application security. He is a leading researcher in the field of web application and web services security and has been a featured speaker at top industry conferences such as BlackHat, DefCon, SyScan, Microsoft BlueHat and OWASP App Sec. &lt;br /&gt;
&lt;br /&gt;
Before he helped form iSEC Partners, Alex spent two years as a Managing Security Architect with @stake. Alex performed as a technical leader on many complex and difficult assignments, including a thorough penetration test and architectural review of a 6 million line enterprise management system, a secure re-design of a multi-thousand host ASP network, and a thorough analysis and code review of a major commercial web server. He was also one of @stake’s West Coast trainers, educating select technical audiences in advanced network and application attacks. &lt;br /&gt;
&lt;br /&gt;
Alex has also worked in at a DoE National Laboratory. He holds a BS in Electrical Engineering and Computer Science from the University of California, Berkeley, where he participated in research projects related to distributed secure storage and automatic C code auditing.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:San_Jose&amp;diff=14034</id>
		<title>Talk:San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:San_Jose&amp;diff=14034"/>
				<updated>2006-12-08T06:31:33Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Previous Meetings: */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Previous Meetings: ==&lt;br /&gt;
 &lt;br /&gt;
'''August 10, 2006 - The Next Generation of Vulnerable Applications'''&lt;br /&gt;
&lt;br /&gt;
'''Presented by: Alex Stamos, Founding Partner, iSEC Partners'''&lt;br /&gt;
'''Abstract:''' Web Services represent a new and unexplored set of security-sensitive technologies that have been widely deployed by large companies, governments, financial institutions, and in consumer applications. Unfortunately, the attributes that make web services attractive, such as their ease of use, platform independence, use of HTTP and powerful functionality, also make them a great target for attack. In this talk, we will explain the basic technologies (such as XML, SOAP, and UDDI) upon which web services are built, and explore the innate security weaknesses in each. We will then demonstrate new attacks that exist in web service infrastructures, and show how classic web application attacks (SQL Injection, XSS, etc…) can be retooled to work with the next-generation of enterprise applications. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Alex Stamos is a founding partner of iSEC Partners - a strategic digital security organization. Alex is an experienced security engineer and consultant specializing in application security and securing large infrastructures, and has taught multiple classes in network and application security. He is a leading researcher in the field of web application and web services security and has been a featured speaker at top industry conferences such as BlackHat, DefCon, SyScan, Microsoft BlueHat and OWASP App Sec. &lt;br /&gt;
&lt;br /&gt;
Before he helped form iSEC Partners, Alex spent two years as a Managing Security Architect with @stake. Alex performed as a technical leader on many complex and difficult assignments, including a thorough penetration test and architectural review of a 6 million line enterprise management system, a secure re-design of a multi-thousand host ASP network, and a thorough analysis and code review of a major commercial web server. He was also one of @stake’s West Coast trainers, educating select technical audiences in advanced network and application attacks. &lt;br /&gt;
&lt;br /&gt;
Alex has also worked in at a DoE National Laboratory. He holds a BS in Electrical Engineering and Computer Science from the University of California, Berkeley, where he participated in research projects related to distributed secure storage and automatic C code auditing.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:San_Jose&amp;diff=14033</id>
		<title>Talk:San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:San_Jose&amp;diff=14033"/>
				<updated>2006-12-08T06:29:47Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Previous Meetings: ==&lt;br /&gt;
 &lt;br /&gt;
'''August 10, 2006&lt;br /&gt;
&lt;br /&gt;
The Next Generation of Vulnerable Applications'''Presented by: Alex Stamos, Founding Partner, iSEC Partners&lt;br /&gt;
Abstract: Web Services represent a new and unexplored set of security-sensitive technologies that have been widely deployed by large companies, governments, financial institutions, and in consumer applications. Unfortunately, the attributes that make web services attractive, such as their ease of use, platform independence, use of HTTP and powerful functionality, also make them a great target for attack. In this talk, we will explain the basic technologies (such as XML, SOAP, and UDDI) upon which web services are built, and explore the innate security weaknesses in each. We will then demonstrate new attacks that exist in web service infrastructures, and show how classic web application attacks (SQL Injection, XSS, etc…) can be retooled to work with the next-generation of enterprise applications. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Alex Stamos is a founding partner of iSEC Partners - a strategic digital security organization. Alex is an experienced security engineer and consultant specializing in application security and securing large infrastructures, and has taught multiple classes in network and application security. He is a leading researcher in the field of web application and web services security and has been a featured speaker at top industry conferences such as BlackHat, DefCon, SyScan, Microsoft BlueHat and OWASP App Sec. &lt;br /&gt;
&lt;br /&gt;
Before he helped form iSEC Partners, Alex spent two years as a Managing Security Architect with @stake. Alex performed as a technical leader on many complex and difficult assignments, including a thorough penetration test and architectural review of a 6 million line enterprise management system, a secure re-design of a multi-thousand host ASP network, and a thorough analysis and code review of a major commercial web server. He was also one of @stake’s West Coast trainers, educating select technical audiences in advanced network and application attacks. &lt;br /&gt;
&lt;br /&gt;
Alex has also worked in at a DoE National Laboratory. He holds a BS in Electrical Engineering and Computer Science from the University of California, Berkeley, where he participated in research projects related to distributed secure storage and automatic C code auditing.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=14032</id>
		<title>OWASP Community</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=14032"/>
				<updated>2006-12-08T06:20:37Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page is for people to post OWASP related events, such as chapter meetings, OWASP conferences, get-togethers, and OWASP sponsored events. This page is monitored, and items will be copied to the front page.&lt;br /&gt;
&lt;br /&gt;
Please post new items in chronological order using the following format:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;&lt;br /&gt;
'''Mon ## (##:00h) - [[Article]]'''&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
*** Every second tuesday of the month ***&lt;br /&gt;
'''xxx xx (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** Every first Wednesday of the month ***&lt;br /&gt;
'''xxx xx (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** Every second Wednesday of the month&lt;br /&gt;
'''xxx xx (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** Every third Monday of the month ***&lt;br /&gt;
'''xxx xx (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Events==&lt;br /&gt;
&lt;br /&gt;
'''Jan 17 (18:30h) - [[Denver|Denver chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 4 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 19 (18:00h) - [[San Jose|San Jose chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 18 (18:30h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 14 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 13 (18:00h) - [[Chicago|Chicago chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 12 (18:30h) - [[Helsinki|Helsinki chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 12 (18:00h) - [[Cleveland|Cleveland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 12 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 7 (17:30h) - [[New Jersey|New Jersey chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 6 (18:30h) - [[Kansas City|Kansas City chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 6 (18:30h) - [[Boston|Boston chapter meeting]] (cancelled)'''&lt;br /&gt;
&lt;br /&gt;
'''Dec 5 (18:00h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 21 (11:30h) - [[Austin|Austin chapter meeting]]&lt;br /&gt;
&lt;br /&gt;
'''Nov 20 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 15 (18:30h) - [[Denver|Denver chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 14 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 13 (14:30h) - [[Israel|Israeli chapter mini-conference at IDC Herzliya]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 11 (10:00h) - [[Switzerland|Kickoff Meeting OWASP Switzerland Local Chapter]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 9 (18:30h) - [[Phoenix|Phoenix chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 8 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 6 (18:00h) - [[Ottawa|Ottawa chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Nov 1 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 31 (12:00h) - [[Austin|Austin OWASP chapter]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 30 (11:00h) - [[Montgomery|Montgomery chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 26 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 24 (18:00h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 16-18 - [[OWASP AppSec Seattle 2006|OWASP AppSec Seattle 2006 Conference]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 16 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 12 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 7 - [[Italy| OWASP Italy at SMAU 06]]'''   &lt;br /&gt;
&lt;br /&gt;
'''Oct 4 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Oct 2 (18:00h) - [[Ottawa|Ottawa chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 29 - [[Italy| OWASP Italy at OpenEXP]]''' &lt;br /&gt;
&lt;br /&gt;
'''Sep 28 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 27 (11:30h) - [[San Antonio|San Antonio chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 26-27 (08:00h) - [[Manila|OWASP Manila presenting at PhilOSC 2006]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 26 (12:00h) - [[Austin|Austin OWASP chapter]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 25 (17:00h) - [[New Jersey|New Jersey chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 21 (17:30h) - [[San Francisco|San Francisco chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 18 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 14 (18:00h) - [[Brisbane|Brisbane chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 14 (18:00h) - [[Belgium|Belgium chapter meeting in Antwerp]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 14 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]] (cancelled)'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 12 - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 31 (15:00h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 31 (08:00h) - [[Manila|OWASP Manila presentation at UST]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 29 (11:30h) - [[Austin|Austin OWASP chapter]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 24 (17:30h) - [[Brisbane|Brisbane chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 23 (11:30h) - [[San Antonio|San Antonio chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 19 - [[Bangalore|Bangalore chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 17 - [[London|London chapter meeting (Central London)]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 10 - [[San Jose|San Jose chapter meeting (SJ Hyatt - Airport)]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 9 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 9 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 8 (18:00h) - [[Minneapolis St Paul|Minneapolis / St.Paul chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 2 (19:30h) - [[OWASP/Blackhat Vegas International Meet-Up]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 31 (15:00h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 27 (12:00h) - [[Austin|Austin OWASP chapter kickoff meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 26 (19:15h) - [[Israel|Israel chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 19 (12:15h) - [[Hong Kong|Hong Kong chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 15 - [[Bangalore|Bangalore chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 12 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 5 (18:00h) - [[Ottawa|Ottawa chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 29 (18:00h) - [[San Jose|San Jose chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 26 (15:30h) - [[BostonFinancialDist|Boston financial district chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 24 (9:30h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 22 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 21 - [[Italy|OWASP presentations at InfoSecurity 2006 (Italy)]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 21 (11:30h) - [[San Antonio|San Antonio chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 20 (18:00h) - [[Minneapolis St Paul|Minneapolis/St. Paul chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 19 (18:00h) - [[Ottawa|Ottawa chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 16 (16:45h) - [[Spain|Spain chapter meeting (Barcelona)]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 14-16 - [http://www.nyphpcon.com NY PHP Conference]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 14 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 2 (12:00h) - [[Hong Kong|Hong Kong chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 29-31 - [[AppSec Europe 2006|OWASP AppSec 2006 Europe Conference]]'''&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=8199</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=8199"/>
				<updated>2006-07-26T16:03:11Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Next Meeting - Thursday, June 29, 2006 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.sourceforge.net/lists/listinfo/owasp-sanjose/}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, August 10, 2006 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm – 6:30pm      Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm – 6:40pm      Chapter announcements&amp;lt;br/&amp;gt;&lt;br /&gt;
6:40pm – 8:00pm      The Next Generation of Vulnerable Applications, Alex Stamos, iSec Partners &amp;lt;br/&amp;gt;&lt;br /&gt;
8:00pm – 8:30pm      Open discussion &amp;amp; Networking&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose Hyatt (Airport)&amp;lt;br/&amp;gt;&lt;br /&gt;
1740 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95112&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''The Next Generation of Vulnerable Applications'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Alex Stamos, Founding Partner, iSEC Partners'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Abstract:'''  Web Services represent a new and unexplored set of security-sensitive technologies that have been widely deployed by large companies, governments, financial institutions, and in consumer applications.   Unfortunately, the attributes that make web services attractive, such as their ease of use, platform independence, use of HTTP and powerful functionality, also make them a great target for attack. In this talk, we will explain the basic technologies (such as XML, SOAP, and UDDI) upon which web services are built, and explore the innate security weaknesses in each.  We will then demonstrate new attacks that exist in web service infrastructures, and show how classic web application attacks (SQL Injection, XSS, etc…) can be retooled to work with the next-generation of enterprise applications. &lt;br /&gt;
	&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Alex Stamos is a founding partner of iSEC Partners - a strategic digital security organization.  Alex is an experienced security engineer and consultant specializing in application security and securing large infrastructures, and has taught multiple classes in network and application security.  He is a leading researcher in the field of web application and web services security and has been a featured speaker at top industry conferences such as BlackHat, DefCon, SyScan, Microsoft BlueHat and OWASP App Sec.&lt;br /&gt;
 &lt;br /&gt;
Before he helped form iSEC Partners, Alex spent two years as a Managing Security Architect with @stake.  Alex performed as a technical leader on many complex and difficult assignments, including a thorough penetration test and architectural review of a 6 million line enterprise management system, a secure re-design of a multi-thousand host ASP network, and a thorough analysis and code review of a major commercial web server.  He was also one of @stake’s West Coast trainers, educating select technical audiences in advanced network and application attacks.  &lt;br /&gt;
&lt;br /&gt;
Alex has also worked in at a DoE National Laboratory.  He holds a BS in Electrical Engineering and Computer Science from the University of California, Berkeley, where he participated in research projects related to distributed secure storage and automatic C code auditing.    &lt;br /&gt;
 &lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini], call 408-979-0571 or visit [http://owasp.mollyguard.com OWASP.Mollyguard.com]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This event is co-sponsored by [http://www.appsecconsulting.com AppSec Consulting, Inc]. and [http://www.whitehatsec.com WhiteHat Security, Inc.]&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=8198</id>
		<title>OWASP Community</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=8198"/>
				<updated>2006-07-26T15:55:42Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page is for people to post OWASP related events, such as chapter meetings, OWASP conferences, get-togethers, and OWASP sponsored events. This page is monitored, and items will be copied to the front page.&lt;br /&gt;
&lt;br /&gt;
Please post new items at the top of the list using the following format:&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;&lt;br /&gt;
'''Mon ## (##:00h) - [[Article]]'''&lt;br /&gt;
&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
 *** Every second tuesday of the month ***&lt;br /&gt;
'''Jun 14 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Events==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Oct 16-18 - [[OWASP AppSec Seattle 2006|OWASP AppSec Seattle 2006 Conference]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 25 (17:00) - [[New Jersey|New Jersey chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sep 12 - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 19 - [[Bangalore|Bangalore chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 17 - [[London|London chapter meeting (Central London)]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 10 - [[San Jose|San Jose chapter meeting (SJ Hyatt - Airport)]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 9 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 8 (18:00h) - [[Minneapolis St Paul|Minneapolis / St.Paul chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Aug 2 (19:30h) - [[OWASP/Blackhat Vegas International Meet-Up]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 31 (15:00h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 27 (12:00h) - [[Austin|Austin OWASP chapter kickoff meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 26 (19:15h) - [[Israel|Israel chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 19 (12:15h) - [[Hong Kong|Hong Kong chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 15 - [[Bangalore|Bangalore chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 12 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jul 5 (18:00h) - [[Ottawa|Ottawa chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 29 (18:00h) - [[San Jose|San Jose chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 26 (15:30h) - [[BostonFinancialDist|Boston financial district chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 24 (9:30h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 22 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 21 - [[Italy|OWASP presentations at InfoSecurity 2006 (Italy)]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 21 (11:30h) - [[San Antonio|San Antonio chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 20 (18:00h) - [[Minneapolis St Paul|Minneapolis/St. Paul chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 19 (18:00h) - [[Ottawa|Ottawa chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 16 (16:45h) - [[Spain|Spain chapter meeting (Barcelona)]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 14-16 - [http://www.nyphpcon.com NY PHP Conference]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 14 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 2 (12:00h) - [[Hong Kong|Hong Kong chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 29-31 - [[AppSec Europe 2006|OWASP AppSec 2006 Europe Conference]]'''&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=6982</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=6982"/>
				<updated>2006-06-29T04:32:53Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Next Meeting - Thursday, June 29, 2006 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.sourceforge.net/lists/listinfo/owasp-sanjose/}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, June 29, 2006 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm – 6:30pm      Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm – 6:40pm      Chapter announcements&amp;lt;br/&amp;gt;&lt;br /&gt;
6:40pm – 7:30pm      FoRMa for Secure Software Development, Kris Kahn, Seagate Technology&amp;lt;br/&amp;gt;&lt;br /&gt;
7:35pm – 8:25pm      JavaScript Attacks &amp;amp; Intranet Applications, Jeremiah Grossman, WhiteHat Security&amp;lt;br/&amp;gt;&lt;br /&gt;
8:30pm – 9:00pm      Open discussion &amp;amp; Networking&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose Hyatt (Airport)&amp;lt;br/&amp;gt;&lt;br /&gt;
1740 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95112&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Framework of Risk Management &amp;amp; Analysis (FoRMA) for Secure Software Development'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Kris Kahn, Sr. Governance Analyst, Seagate Technology'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Abstract:'''  We frequently apply Risk Management concepts in our daily lives, whether it’s driving in the rain on the freeway, or crossing a busy intersection.  It comes down to making a choice, taking a calculated risk to reach our objective.  We decide quickly, making assumptions about the threats and about our environment.  The lessons we learn from our failures help us make wiser decisions next time, if we survive.&lt;br /&gt;
	&lt;br /&gt;
Using a new Framework of Risk Management &amp;amp; Analysis (FoRMA) for Secure Software Development, we will be able to make better decisions by understanding our threats.  FoRMA will help us ensure that we have the appropriate level of protection to maximize our business objectives, increasing quality and minimizing cost.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Kris Kahn, CISSP-ISSAP,ISSMP, CISA, OPSA, currently a Sr. Governance Analyst at Seagate Technology. Passionate about security for more than 15 years, also worked for companies in the San Francisco Bay Area that include Autodesk, and Best Internet Communications. A CISSP since 2001, his key contributions include firewall architectures, risk management models, security assessment methodologies, and security awareness training.  Kris has expertise in offensive, defensive and governance facets of security.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''JavaScript Attacks and Threats to Intranet Applications'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Jeremiah Grossman, Founder and CTO, WhiteHat Security'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Abstract:''' Malicious JavaScript is capable of stealing cookies, capturing keystrokes, monitoring activity and planting root kits.  Attackers are using JavaScript to hijack browser sessions to commit bank fraud, hack other websites, or post derogatory comments in a public forum – all without traces, tracks or warning sirens. Web application security research is revealing that outsiders can also use these hijacked browsers to exploit intranet websites.&lt;br /&gt;
&lt;br /&gt;
Most assume while surfing the Web we are protected by firewalls that are isolated through private networks.  We believe nothing is capable of directly connecting in from the outside world. Right? Well, not quite.  Web browsers can be completely controlled by any web page, enabling them to become launching points to attack internal network resources.  &lt;br /&gt;
&lt;br /&gt;
The web browser of every user on an enterprise network becomes a stepping stone for intruders.  During this presentation we'll demonstrate a wide variety of cutting-edge web application attack techniques and describe best practices for securing websites and users against these threats.&lt;br /&gt;
&lt;br /&gt;
You’ll see&lt;br /&gt;
&lt;br /&gt;
     * Port scanning and attacking intranet devices using JavaScript&lt;br /&gt;
     * Blind web server fingerprinting using unique URLs&lt;br /&gt;
     * Discovery NAT'ed IP addresses with Java Applets&lt;br /&gt;
     * Stealing web browser history with Cascading Style Sheets&lt;br /&gt;
     * Best-practice defense measures for securing websites&lt;br /&gt;
     * Essential habits for safe web surfing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Jeremiah Grossman is the founder and Chief Technology Officer of WhiteHat Security and responsible for web application security R&amp;amp;D and industry evangelism. Mr. Grossman is a frequent speaker at the Black Hat Briefings, ISSA, ISACA, NASA, and other industry events. Jeremiah been published in USA Today, VAR Business, NBC, ABC News (AU), ZDNet, eWeek, Computerworld and BetaNews. Prior to WhiteHat, Mr. Grossman served as an information security officer at Yahoo!.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
Please RSVP to via email [mailto:brian.bertacini@owasp.org Brian Bertacini] or call 408-979-0571&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This event is co-sponsored by [http://www.appsecconsulting.com AppSec Consulting, Inc]. and [http://www.whitehatsec.com WhiteHat Security, Inc.]&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=6981</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=6981"/>
				<updated>2006-06-29T04:31:39Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Next Meeting - Thursday, June 29, 2006 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|extra=The chapter leader is [mailto:brian.bertacini@owasp.org Brian Bertacini]|mailinglistsite=http://lists.sourceforge.net/lists/listinfo/owasp-sanjose/}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, June 29, 2006 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm – 6:30pm      Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm – 6:40pm      Chapter announcements&amp;lt;br/&amp;gt;&lt;br /&gt;
6:40pm – 7:30pm      FoRMa for Secure Software Development, Kris Kahn, Seagate Technology&amp;lt;br/&amp;gt;&lt;br /&gt;
7:35pm – 8:25pm      JavaScript Attacks &amp;amp; Intranet Applications, Jeremiah Grossman, WhiteHat Security&amp;lt;br/&amp;gt;&lt;br /&gt;
8:30pm – 9:00pm      Open discussion &amp;amp; Networking&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose Hyatt (Airport)&amp;lt;br/&amp;gt;&lt;br /&gt;
1740 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95112&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Framework of Risk Management &amp;amp; Analysis (FoRMA) for Secure Software Development'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Kris Kahn, Sr. Governance Analyst, Seagate Technology'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Abstract:'''  We frequently apply Risk Management concepts in our daily lives, whether it’s driving in the rain on the freeway, or crossing a busy intersection.  It comes down to making a choice, taking a calculated risk to reach our objective.  We decide quickly, making assumptions about the threats and about our environment.  The lessons we learn from our failures help us make wiser decisions next time, if we survive.&lt;br /&gt;
	&lt;br /&gt;
Using a new Framework of Risk Management &amp;amp; Analysis (FoRMA) for Secure Software Development, we will be able to make better decisions by understanding our threats.  FoRMA will help us ensure that we have the appropriate level of protection to maximize our business objectives, increasing quality and minimizing cost.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Kris Kahn, CISSP-ISSAP,ISSMP, CISA, OPSA, currently a Sr. Governance Analyst at Seagate Technology. Passionate about security for more than 15 years, also worked for companies in the San Francisco Bay Area that include Autodesk, and Best Internet Communications. A CISSP since 2001, his key contributions include firewall architectures, risk management models, security assessment methodologies, and security awareness training.  Kris has expertise in offensive, defensive and governance facets of security.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''JavaScript Attacks and Threats to Intranet Applications'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Jeremiah Grossman, Founder and CTO, WhiteHat Security'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Abstract:''' Malicious JavaScript is capable of stealing cookies, capturing keystrokes, monitoring activity and planting root kits.  Attackers are using JavaScript to hijack browser sessions to commit bank fraud, hack other websites, or post derogatory comments in a public forum – all without traces, tracks or warning sirens. Web application security research is revealing that outsiders can also use these hijacked browsers to exploit intranet websites.&lt;br /&gt;
&lt;br /&gt;
Most assume while surfing the Web we are protected by firewalls that are isolated through private networks.  We believe nothing is capable of directly connecting in from the outside world. Right? Well, not quite.  Web browsers can be completely controlled by any web page, enabling them to become launching points to attack internal network resources.  &lt;br /&gt;
&lt;br /&gt;
The web browser of every user on an enterprise network becomes a stepping stone for intruders.  During this presentation we'll demonstrate a wide variety of cutting-edge web application attack techniques and describe best practices for securing websites and users against these threats.&lt;br /&gt;
&lt;br /&gt;
You’ll see&lt;br /&gt;
&lt;br /&gt;
     * Port scanning and attacking intranet devices using JavaScript&lt;br /&gt;
     * Blind web server fingerprinting using unique URLs&lt;br /&gt;
     * Discovery NAT'ed IP addresses with Java Applets&lt;br /&gt;
     * Stealing web browser history with Cascading Style Sheets&lt;br /&gt;
     * Best-practice defense measures for securing websites&lt;br /&gt;
     * Essential habits for safe web surfing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Jeremiah Grossman is the founder and Chief Technology Officer of WhiteHat Security and responsible for web application security R&amp;amp;D and industry evangelism. Mr. Grossman is a frequent speaker at the Black Hat Briefings, ISSA, ISACA, NASA, and other industry events. Jeremiah been published in USA Today, VAR Business, NBC, ABC News (AU), ZDNet, eWeek, Computerworld and BetaNews. Prior to WhiteHat, Mr. Grossman served as an information security officer at Yahoo!.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
Please RSVP to via email [mailto://brian.bertacini@owasp.org Brian Bertacini] or call 408-979-0571&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This event is co-sponsored by [http://www.appsecconsulting.com AppSec Consulting, Inc]. and [http://www.whitehatsec.com WhiteHat Security, Inc.]&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=6501</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=6501"/>
				<updated>2006-06-19T20:15:47Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Next Meeting - Thursday, June 29, 2006 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|leaderemail=brian.bertacini@owasp.org|leadername=Brian Bertacini|mailinglistsite=http://lists.sourceforge.net/lists/listinfo/owasp-sanjose/}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, June 29, 2006 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm – 6:30pm      Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm – 6:40pm      Chapter announcements&amp;lt;br/&amp;gt;&lt;br /&gt;
6:40pm – 7:30pm      FoRMa for Secure Software Development, Kris Kahn, Seagate Technology&amp;lt;br/&amp;gt;&lt;br /&gt;
7:35pm – 8:25pm      JavaScript Attacks &amp;amp; Intranet Applications, Jeremiah Grossman, WhiteHat Security&amp;lt;br/&amp;gt;&lt;br /&gt;
8:30pm – 9:00pm      Open discussion &amp;amp; Networking&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose Hyatt (Airport)&amp;lt;br/&amp;gt;&lt;br /&gt;
1740 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95112&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Framework of Risk Management &amp;amp; Analysis (FoRMA) for Secure Software Development'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Kris Kahn, Sr. Governance Analyst, Seagate Technology'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Abstract:'''  We frequently apply Risk Management concepts in our daily lives, whether it’s driving in the rain on the freeway, or crossing a busy intersection.  It comes down to making a choice, taking a calculated risk to reach our objective.  We decide quickly, making assumptions about the threats and about our environment.  The lessons we learn from our failures help us make wiser decisions next time, if we survive.&lt;br /&gt;
	&lt;br /&gt;
Using a new Framework of Risk Management &amp;amp; Analysis (FoRMA) for Secure Software Development, we will be able to make better decisions by understanding our threats.  FoRMA will help us ensure that we have the appropriate level of protection to maximize our business objectives, increasing quality and minimizing cost.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Kris Kahn, CISSP-ISSAP,ISSMP, CISA, OPSA, currently a Sr. Governance Analyst at Seagate Technology. Passionate about security for more than 15 years, also worked for companies in the San Francisco Bay Area that include Autodesk, and Best Internet Communications. A CISSP since 2001, his key contributions include firewall architectures, risk management models, security assessment methodologies, and security awareness training.  Kris has expertise in offensive, defensive and governance facets of security.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''JavaScript Attacks and Threats to Intranet Applications'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Jeremiah Grossman, Founder and CTO, WhiteHat Security'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Abstract:''' Malicious JavaScript is capable of stealing cookies, capturing keystrokes, monitoring activity and planting root kits.  Attackers are using JavaScript to hijack browser sessions to commit bank fraud, hack other websites, or post derogatory comments in a public forum – all without traces, tracks or warning sirens. Web application security research is revealing that outsiders can also use these hijacked browsers to exploit intranet websites.&lt;br /&gt;
&lt;br /&gt;
Most assume while surfing the Web we are protected by firewalls that are isolated through private networks.  We believe nothing is capable of directly connecting in from the outside world. Right? Well, not quite.  Web browsers can be completely controlled by any web page, enabling them to become launching points to attack internal network resources.  &lt;br /&gt;
&lt;br /&gt;
The web browser of every user on an enterprise network becomes a stepping stone for intruders.  During this presentation we'll demonstrate a wide variety of cutting-edge web application attack techniques and describe best practices for securing websites and users against these threats.&lt;br /&gt;
&lt;br /&gt;
You’ll see&lt;br /&gt;
&lt;br /&gt;
     * Port scanning and attacking intranet devices using JavaScript&lt;br /&gt;
     * Blind web server fingerprinting using unique URLs&lt;br /&gt;
     * Discovery NAT'ed IP addresses with Java Applets&lt;br /&gt;
     * Stealing web browser history with Cascading Style Sheets&lt;br /&gt;
     * Best-practice defense measures for securing websites&lt;br /&gt;
     * Essential habits for safe web surfing&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Jeremiah Grossman is the founder and Chief Technology Officer of WhiteHat Security and responsible for web application security R&amp;amp;D and industry evangelism. Mr. Grossman is a frequent speaker at the Black Hat Briefings, ISSA, ISACA, NASA, and other industry events. Jeremiah been published in USA Today, VAR Business, NBC, ABC News (AU), ZDNet, eWeek, Computerworld and BetaNews. Prior to WhiteHat, Mr. Grossman served as an information security officer at Yahoo!.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
Please RSVP to via email [brian.bertacini@owasp.org] or call 408-979-0571&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This event is co-sponsored by AppSec Consulting, Inc. and WhiteHat Security, Inc.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=6496</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=6496"/>
				<updated>2006-06-19T15:48:43Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* '''Next Meeting - Thursday, June 29, 2006''' */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|leaderemail=brian.bertacini@owasp.org|leadername=Brian Bertacini|mailinglistsite=http://lists.sourceforge.net/lists/listinfo/owasp-sanjose/}}&lt;br /&gt;
&lt;br /&gt;
== Next Meeting - Thursday, June 29, 2006 ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm – 6:30pm      Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm – 6:40pm      Chapter announcements&amp;lt;br/&amp;gt;&lt;br /&gt;
6:40pm – 7:30pm      FoRMa for Secure Software Development, Kris Kahn, Seagate Technology&amp;lt;br/&amp;gt;&lt;br /&gt;
7:35pm – 8:25pm      JavaScript Attacks &amp;amp; Intranet Applications, Jeremiah Grossman, WhiteHat Security&amp;lt;br/&amp;gt;&lt;br /&gt;
8:30pm – 9:00pm      Open discussion &amp;amp; Networking&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose Hyatt (Airport)&amp;lt;br/&amp;gt;&lt;br /&gt;
1740 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95112&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Framework of Risk Management &amp;amp; Analysis (FoRMA) for Secure Software Development'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Kris Kahn, Sr. Governance Analyst, Seagate Technology'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Abstract:'''  We frequently apply Risk Management concepts in our daily lives, whether it’s driving in the rain on the freeway, or crossing a busy intersection.  It comes down to making a choice, taking a calculated risk to reach our objective.  We decide quickly, making assumptions about the threats and about our environment.  The lessons we learn from our failures help us make wiser decisions next time, if we survive.&lt;br /&gt;
	&lt;br /&gt;
Using a new Framework of Risk Management &amp;amp; Analysis (FoRMA) for Secure Software Development, we will be able to make better decisions by understanding our threats.  FoRMA will help us ensure that we have the appropriate level of protection to maximize our business objectives, increasing quality and minimizing cost.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Kris Kahn, CISSP-ISSAP,ISSMP, CISA, OPSA, currently a Sr. Governance Analyst at Seagate Technology. Passionate about security for more than 15 years, also worked for companies in the San Francisco Bay Area that include Autodesk, and Best Internet Communications. A CISSP since 2001, his key contributions include firewall architectures, risk management models, security assessment methodologies, and security awareness training.  Kris has expertise in offensive, defensive and governance facets of security.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
Please RSVP to via email [brian.bertacini@owasp.org] or call 408-979-0571&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This event is co-sponsored by AppSec Consulting, Inc. and WhiteHat Security, Inc.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=6495</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=6495"/>
				<updated>2006-06-19T15:47:27Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* '''Next Meeting - Thursday, June 29, 2006''' */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|leaderemail=brian.bertacini@owasp.org|leadername=Brian Bertacini|mailinglistsite=http://lists.sourceforge.net/lists/listinfo/owasp-sanjose/}}&lt;br /&gt;
&lt;br /&gt;
=== '''Next Meeting - Thursday, June 29, 2006''' ===&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm – 6:30pm      Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm – 6:40pm      Chapter announcements&amp;lt;br/&amp;gt;&lt;br /&gt;
6:40pm – 7:30pm      FoRMa for Secure Software Development, Kris Kahn, Seagate Technology&amp;lt;br/&amp;gt;&lt;br /&gt;
7:35pm – 8:25pm      JavaScript Attacks &amp;amp; Intranet Applications, Jeremiah Grossman, WhiteHat Security&amp;lt;br/&amp;gt;&lt;br /&gt;
8:30pm – 9:00pm      Open discussion &amp;amp; Networking&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose Hyatt (Airport)&amp;lt;br/&amp;gt;&lt;br /&gt;
1740 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95112&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Framework of Risk Management &amp;amp; Analysis (FoRMA) for Secure Software Development'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Kris Kahn, Sr. Governance Analyst, Seagate Technology'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Abstract:'''  We frequently apply Risk Management concepts in our daily lives, whether it’s driving in the rain on the freeway, or crossing a busy intersection.  It comes down to making a choice, taking a calculated risk to reach our objective.  We decide quickly, making assumptions about the threats and about our environment.  The lessons we learn from our failures help us make wiser decisions next time, if we survive.&lt;br /&gt;
	&lt;br /&gt;
Using a new Framework of Risk Management &amp;amp; Analysis (FoRMA) for Secure Software Development, we will be able to make better decisions by understanding our threats.  FoRMA will help us ensure that we have the appropriate level of protection to maximize our business objectives, increasing quality and minimizing cost.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Kris Kahn, CISSP-ISSAP,ISSMP, CISA, OPSA, currently a Sr. Governance Analyst at Seagate Technology. Passionate about security for more than 15 years, also worked for companies in the San Francisco Bay Area that include Autodesk, and Best Internet Communications. A CISSP since 2001, his key contributions include firewall architectures, risk management models, security assessment methodologies, and security awareness training.  Kris has expertise in offensive, defensive and governance facets of security.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
Please RSVP to via email [brian.bertacini@owasp.org] or call 408-979-0571&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This event is co-sponsored by AppSec Consulting, Inc. and WhiteHat Security, Inc.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=6494</id>
		<title>San Jose</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=San_Jose&amp;diff=6494"/>
				<updated>2006-06-19T15:43:24Z</updated>
		
		<summary type="html">&lt;p&gt;Bbertacini: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=San Jose|leaderemail=brian.bertacini@owasp.org|leadername=Brian Bertacini|mailinglistsite=http://lists.sourceforge.net/lists/listinfo/owasp-sanjose/}}&lt;br /&gt;
&lt;br /&gt;
== '''Next Meeting - Thursday, June 29, 2006''' ==&lt;br /&gt;
Open to the public, attendance is free&lt;br /&gt;
&lt;br /&gt;
'''Agenda and Presentations:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
6:00pm – 6:30pm      Check-in and reception (food &amp;amp; bev)&amp;lt;br/&amp;gt;&lt;br /&gt;
6:30pm – 6:40pm      Chapter announcements&amp;lt;br/&amp;gt;&lt;br /&gt;
6:40pm – 7:30pm      FoRMa for Secure Software Development, Kris Kahn, Seagate Technology&amp;lt;br/&amp;gt;&lt;br /&gt;
7:35pm – 8:25pm      JavaScript Attacks &amp;amp; Intranet Applications, Jeremiah Grossman, WhiteHat Security&amp;lt;br/&amp;gt;&lt;br /&gt;
8:30pm – 9:00pm      Open discussion &amp;amp; Networking&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Venue:'''&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose Hyatt (Airport)&amp;lt;br/&amp;gt;&lt;br /&gt;
1740 North First Street&amp;lt;br/&amp;gt;&lt;br /&gt;
San Jose, CA 95112&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Framework of Risk Management &amp;amp; Analysis (FoRMA) for Secure Software Development'''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''''Presented by: Kris Kahn, Sr. Governance Analyst, Seagate Technology'''''&amp;lt;br/&amp;gt;&lt;br /&gt;
'''Abstract:'''  We frequently apply Risk Management concepts in our daily lives, whether it’s driving in the rain on the freeway, or crossing a busy intersection.  It comes down to making a choice, taking a calculated risk to reach our objective.  We decide quickly, making assumptions about the threats and about our environment.  The lessons we learn from our failures help us make wiser decisions next time, if we survive.&lt;br /&gt;
	&lt;br /&gt;
Using a new Framework of Risk Management &amp;amp; Analysis (FoRMA) for Secure Software Development, we will be able to make better decisions by understanding our threats.  FoRMA will help us ensure that we have the appropriate level of protection to maximize our business objectives, increasing quality and minimizing cost.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Bio:''' Kris Kahn, CISSP-ISSAP,ISSMP, CISA, OPSA, currently a Sr. Governance Analyst at Seagate Technology. Passionate about security for more than 15 years, also worked for companies in the San Francisco Bay Area that include Autodesk, and Best Internet Communications. A CISSP since 2001, his key contributions include firewall architectures, risk management models, security assessment methodologies, and security awareness training.  Kris has expertise in offensive, defensive and governance facets of security.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
Please RSVP to via email [brian.bertacini@owasp.org] or call 408-979-0571&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This event is co-sponsored by AppSec Consulting, Inc. and WhiteHat Security, Inc.&lt;/div&gt;</summary>
		<author><name>Bbertacini</name></author>	</entry>

	</feed>