<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bedirhan</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bedirhan"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Bedirhan"/>
		<updated>2026-04-19T13:07:57Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=130903</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=130903"/>
				<updated>2012-06-04T10:25:50Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Application Security Day, İstanbul 2012, Conference */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=130902</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=130902"/>
				<updated>2012-06-04T10:25:41Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=130901</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=130901"/>
				<updated>2012-06-04T10:24:52Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=130900</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=130900"/>
				<updated>2012-06-04T10:24:35Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=129947</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=129947"/>
				<updated>2012-05-16T05:59:05Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Published &lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=129946</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=129946"/>
				<updated>2012-05-16T05:54:06Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Published &lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=129945</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=129945"/>
				<updated>2012-05-16T05:53:56Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Published &lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; in 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=129944</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=129944"/>
				<updated>2012-05-16T05:53:34Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Published &lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; in 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; in 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=129943</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=129943"/>
				<updated>2012-05-16T05:50:06Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* OWASP/TR Talk in Open Source Code Days in Yeditepe University */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Published &lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; in 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=113834</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=113834"/>
				<updated>2011-07-13T10:45:48Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir],  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur],[mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun], [mailto:canberk.bolat~gmail.com Canberk Bolat]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] is out!&lt;br /&gt;
* [http://www.webguvenligi.org/docs/Javada_Guvenli_Yazilim_Gelistirme_OWASPTR.pdf Secure Coding Principles in Java] by [http://www.architectingsecurity.com Dr. Emin Islam Tatlı] is out!&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf WebAppSec Checklist] Web Uygulama Güvenliği Kontrol Listesi 2010 by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=113833</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=113833"/>
				<updated>2011-07-13T10:45:00Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Projects/Tools/Translations */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir],  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur],[mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun], [mailto:canberk.bolat~gmail.com Canberk Bolat]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/Javada_Guvenli_Yazilim_Gelistirme_OWASPTR.pdf Secure Coding Principles in Java] by [http://www.architectingsecurity.com Dr. Emin Islam Tatlı] is out!&lt;br /&gt;
* The unbreakable CTF v5. [http://www.webguvenligi.org/docs/WGT_Capture_the_Flag_v5.pdf CTF v5 solution] is out! :)&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] is out!&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine]. 7th edition of OWASP-TR's Turkish web security e-magazine is out. &lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf WebAppSec Checklist] Web Uygulama Güvenliği Kontrol Listesi 2010 by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=106828</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=106828"/>
				<updated>2011-03-15T08:48:29Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir],  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur],[mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun], [mailto:canberk.bolat~gmail.com Canberk Bolat]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/Javada_Guvenli_Yazilim_Gelistirme_OWASPTR.pdf Secure Coding Principles in Java] by [http://www.architectingsecurity.com Dr. Emin Islam Tatlı] is out!&lt;br /&gt;
* The unbreakable CTF v5. [http://www.webguvenligi.org/docs/WGT_Capture_the_Flag_v5.pdf CTF v5 solution] is out! :)&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] is out!&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine]. 7th edition of OWASP-TR's Turkish web security e-magazine is out. &lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf WebAppSec Checklist] Web Uygulama Güvenliği Kontrol Listesi 2010 by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=105704</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=105704"/>
				<updated>2011-02-24T09:40:15Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir],  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur],[mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun], [mailto:canberk.bolat~gmail.com Canberk Bolat]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] is out!&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine]. 7th edition of OWASP-TR's Turkish web security e-magazine is out. &lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf WebAppSec Checklist] Web Uygulama Güvenliği Kontrol Listesi 2010 by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=105703</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=105703"/>
				<updated>2011-02-24T09:39:22Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir],  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur],[mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun], [mailto:canberk.bolat~gmail.com Canberk Bolat]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine]. 6th edition of OWASP-TR's Turkish web security e-magazine is out. Hey, it's one year old now.&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf WebAppSec Checklist] Web Uygulama Güvenliği Kontrol Listesi 2010 by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=88375</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=88375"/>
				<updated>2010-08-31T09:12:18Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir],  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur],[mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine]. 6th edition of OWASP-TR's Turkish web security e-magazine is out. Hey, it's one year old now.&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf WebAppSec Checklist] Web Uygulama Güvenliği Kontrol Listesi 2010 by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid one and a half year].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=88374</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=88374"/>
				<updated>2010-08-31T09:11:26Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir],  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur],[mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine]. 6th edition of OWASP-TR's Turkish web security e-magazine is out. Hey, it's one year old now.&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid one and a half year].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=88373</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=88373"/>
				<updated>2010-08-31T09:09:07Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir],  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur],[mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine]. 6th edition of OWASP-TR's Turkish web security e-magazine is out. Hey, it's one year old now.&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid one and a half year].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=83755</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=83755"/>
				<updated>2010-05-20T08:49:57Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine]. 5th edition of OWASP-TR's Turkish web security e-magazine is out.&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] compilation of a study on analyzing the possible behavior of a malicious Java web developer&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid one and a half year].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings @ Işık Üniversitesi &amp;amp; Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
Kubilay Onur Güngör will talk about OWASP and OWASP/Turkey (among other things). So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=83647</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=83647"/>
				<updated>2010-05-18T06:03:48Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] compilation of a study on analyzing the possible behavior of a malicious Java web developer&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid one and a half year].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings @ Işık Üniversitesi &amp;amp; Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
Kubilay Onur Güngör will talk about OWASP and OWASP/Turkey (among other things). So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=83646</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=83646"/>
				<updated>2010-05-18T06:02:36Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* Two OWASP/Turkey introduction meetings at Işık Üniversitesi, Şile Kampüsü and Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu by Kubilay Onur Güngör.&lt;br /&gt;
&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/4398278258/ 23 February OWASP-TR meeting] was held in Turkcell Akademi with members of OISF. Thank you guys!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid one and a half year].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings @ Işık Üniversitesi &amp;amp; Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
Kubilay Onur Güngör will talk about OWASP and OWASP/Turkey (among other things). So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=81128</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=81128"/>
				<updated>2010-04-08T13:01:36Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Chapter Brochure */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* Two OWASP/Turkey introduction meetings at Işık Üniversitesi, Şile Kampüsü and Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu by Kubilay Onur Güngör.&lt;br /&gt;
&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/4398278258/ 23 February OWASP-TR meeting] was held in Turkcell Akademi with members of OISF. Thank you guys!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid one and a half year].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings @ Işık Üniversitesi &amp;amp; Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
Kubilay Onur Güngör will talk about OWASP and OWASP/Turkey (among other things). So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=80283</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=80283"/>
				<updated>2010-03-22T09:22:03Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* OWASP/TR Meeting in Turkcell Akademi with OISF Team */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* Two OWASP/Turkey introduction meetings at Işık Üniversitesi, Şile Kampüsü and Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu by Kubilay Onur Güngör.&lt;br /&gt;
&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/4398278258/ 23 February OWASP-TR meeting] was held in Turkcell Akademi with members of OISF. Thank you guys!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings @ Işık Üniversitesi &amp;amp; Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
Kubilay Onur Güngör will talk about OWASP and OWASP/Turkey (among other things). So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=80282</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=80282"/>
				<updated>2010-03-22T09:21:40Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* OWASP/TR Introductory Meetings @ Işık Üniversitesi &amp;amp; Bahçeşehir Üniversitesi */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* Two OWASP/Turkey introduction meetings at Işık Üniversitesi, Şile Kampüsü and Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu by Kubilay Onur Güngör.&lt;br /&gt;
&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/4398278258/ 23 February OWASP-TR meeting] was held in Turkcell Akademi with members of OISF. Thank you guys!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings @ Işık Üniversitesi &amp;amp; Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
Kubilay Onur Güngör will talk about OWASP and OWASP/Turkey (among other things). So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79350</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79350"/>
				<updated>2010-03-09T11:59:39Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* Two OWASP/Turkey introduction meetings at Işık Üniversitesi, Şile Kampüsü and Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu by Kubilay Onur Güngör.&lt;br /&gt;
&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/4398278258/ 23 February OWASP-TR meeting] was held in Turkcell Akademi with members of OISF. Thank you guys!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings @ Işık Üniversitesi &amp;amp; Bahçeşehir Üniversitesi ==&lt;br /&gt;
&lt;br /&gt;
Kubilay Onur Güngör will talk about OWASP and OWASP/Turkey (among other things). So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79349</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79349"/>
				<updated>2010-03-09T11:59:11Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* Two OWASP/Turkey introduction meetings at Işık Üniversitesi, Şile Kampüsü and Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu by Kubilay Onur Güngör.&lt;br /&gt;
&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/4398278258/ 23 February OWASP-TR meeting] was held in Turkcell Akademi with members of OISF. Thank you guys!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings @ Işık Üniversitesi &amp;amp; Bahçeşehir Üniversitesi&lt;br /&gt;
&lt;br /&gt;
Kubilay Onur Güngör will talk about OWASP and OWASP/Turkey (among other things). So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79348</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79348"/>
				<updated>2010-03-09T11:56:40Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* Two OWASP/Turkey introduction meetings at Işık Üniversitesi, Şile Kampüsü and Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu by Kubilay Onur Güngör.&lt;br /&gt;
&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/4398278258/ 23 February OWASP-TR meeting] was held in Turkcell Akademi with members of OISF. Thank you guys!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79090</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79090"/>
				<updated>2010-03-02T13:32:17Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* OWASP/TR Meeting in Turkcell Akademi with OISF Team */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/4398278258/ 23 February OWASP-TR meeting] was held in Turkcell Akademi with members of OISF. Thank you guys!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79089</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79089"/>
				<updated>2010-03-02T13:31:54Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* OWASP/TR Meeting in Turkcell Akademi with OISF Team */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/4398278258/ 23 February OWASP-TR meeting] was held in Turkcell Akademi with members of OISF. Thank you guys!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [GuvenlikEgitimleri.Com http://www.guvenlikegitimleri.com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79088</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79088"/>
				<updated>2010-03-02T13:28:14Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/4398278258/ 23 February OWASP-TR meeting] was held in Turkcell Akademi with members of OISF. Thank you guys!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79087</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79087"/>
				<updated>2010-03-02T13:27:34Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* 23 February OWASP-TR meeting was held in Turkcell Akademi with 7 members of OISF. Thank you guys!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79086</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79086"/>
				<updated>2010-03-02T13:26:37Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* OWASP/TR Meeting in Turkcell Akademi with OISF Team */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* OWASP-TR meeting with Brian Rectanus, Victor Julien and Matt Jonkman&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, 23 February, 2010 &lt;br /&gt;
&lt;br /&gt;
Time: 19:00pm - 21:00pm &lt;br /&gt;
&lt;br /&gt;
Location: Turkcell Akademi, Istiklal Caddesi&lt;br /&gt;
&lt;br /&gt;
Registration: bilgi@webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79085</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79085"/>
				<updated>2010-03-02T13:26:20Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* OWASP-TR meeting with Brian Rectanus, Victor Julien and Matt Jonkman&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, 23 February, 2010 &lt;br /&gt;
&lt;br /&gt;
Time: 19:00pm - 21:00pm &lt;br /&gt;
&lt;br /&gt;
Location: Turkcell Akademi, Istiklal Caddesi&lt;br /&gt;
&lt;br /&gt;
Registration: bilgi@webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [flickr-webguvenligi http://www.flickr.com/photos/webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79084</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79084"/>
				<updated>2010-03-02T13:25:27Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* OWASP/TR Meeting in Turkcell Akademi with OISF Team */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* OWASP-TR meeting with Brian Rectanus, Victor Julien and Matt Jonkman&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, 23 February, 2010 &lt;br /&gt;
&lt;br /&gt;
Time: 19:00pm - 21:00pm &lt;br /&gt;
&lt;br /&gt;
Location: Turkcell Akademi, Istiklal Caddesi&lt;br /&gt;
&lt;br /&gt;
Registration: bilgi@webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team ==&lt;br /&gt;
&lt;br /&gt;
With 7 [OISF http://www.openinfosecfoundation.org] members we had our 23 February meeting. Brian [talked about ModSecurity http://vimeo.com/9825055] and Victor/Will [talked about Suricata http://vimeo.com/9825622].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [flickr-webguvenligi http://www.flickr.com/photos/webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79083</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=79083"/>
				<updated>2010-03-02T13:25:00Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* OWASP-TR meeting with Brian Rectanus, Victor Julien and Matt Jonkman&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, 23 February, 2010 &lt;br /&gt;
&lt;br /&gt;
Time: 19:00pm - 21:00pm &lt;br /&gt;
&lt;br /&gt;
Location: Turkcell Akademi, Istiklal Caddesi&lt;br /&gt;
&lt;br /&gt;
Registration: bilgi@webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team ==&lt;br /&gt;
&lt;br /&gt;
With 7 [OISF http://www.openinfosecfoundation.org] members we had our 23 February meeting. Brian [talked about ModSecurity http://vimeo.com/9825055] and Victor/Will [talked about Suricata http://vimeo.com/9825622].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [flickr/webguvenligi http://www.flickr.com/photos/webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=78541</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=78541"/>
				<updated>2010-02-18T08:19:02Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* OWASP-TR meeting with Brian Rectanus, Victor Julien and Matt Jonkman&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, 23 February, 2010 &lt;br /&gt;
&lt;br /&gt;
Time: 19:00pm - 21:00pm &lt;br /&gt;
&lt;br /&gt;
Location: Turkcell Akademi, Istiklal Caddesi&lt;br /&gt;
&lt;br /&gt;
Registration: bilgi@webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=78540</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=78540"/>
				<updated>2010-02-18T08:17:53Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* A new project by Mesut Timur, [http://code.google.com/p/finddomains/ FindDomains]&lt;br /&gt;
&lt;br /&gt;
* OWASP-TR meeting with Brian Rectanus, Victor Julien and Matt Jonkman&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, 23 February, 2010 &lt;br /&gt;
&lt;br /&gt;
Time: 19:00pm - 21:00pm &lt;br /&gt;
&lt;br /&gt;
Location: Turkcell Akademi, Istiklal Caddesi&lt;br /&gt;
&lt;br /&gt;
Registration: bilgi@webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75542</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75542"/>
				<updated>2009-12-30T11:32:07Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* A new project by Mesut Timur, [http://code.google.com/p/finddomains/ FindDomains]&lt;br /&gt;
&lt;br /&gt;
* A seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu will be given by [http://www.shibumidojo.org/ Kubilay Onur Güngör]. Topics include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75541</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75541"/>
				<updated>2009-12-30T11:31:29Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* A seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu will be given by [http://www.shibumidojo.org/ Kubilay Onur Güngör]. Topics include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75508</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75508"/>
				<updated>2009-12-27T06:59:59Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* A seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu will be given by [http://www.shibumidojo.org/ Kubilay Onur Güngör]. Topics include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75507</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75507"/>
				<updated>2009-12-27T06:59:44Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* A seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu will be given by [http://www.shibumidojo.org/ Kubilay Onur Güngör]. Topics include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75506</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75506"/>
				<updated>2009-12-27T06:59:01Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* A seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu will be given by [http://www.shibumidojo.org/ Kubilay Onur Güngör]. Topics include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75505</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75505"/>
				<updated>2009-12-27T06:55:39Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* A seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu will be given by [http://www.shibumidojo.org/ Kubilay Onur Güngör]. Topics include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75504</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75504"/>
				<updated>2009-12-27T06:55:16Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* A seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu will be given by [http://www.shibumidojo.org/ Kubilay Onur Güngör]. Topics include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Details:&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75021</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75021"/>
				<updated>2009-12-10T14:51:20Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* Most, if not all, of the OWASP/TR members will be attending to the [http://www.istsec.org/ IstSec '09], the security conference, in 12-13 December.&lt;br /&gt;
&lt;br /&gt;
Two new projects from OWASP/TR; &lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine] web security magazine in Turkish, now online with its third issue!&lt;br /&gt;
&lt;br /&gt;
* Capture The Flag contest now online at [http://ctf.webguvenligi.org/ http://ctf.webguvenligi.org/] with the courtesy of Onur Yilmaz. (Naturally ethical) successfull first two attackers will be rewarded by two security related books!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75020</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75020"/>
				<updated>2009-12-10T14:50:49Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* Most, if not all, of the OWASP/TR members will be attending to the [http://www.istsec.org/ IstSec '09], the security conference, in 12-13 December.&lt;br /&gt;
&lt;br /&gt;
Two new projects from OWASP/TR; &lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine] web security magazine in Turkish, now online with its third issue!&lt;br /&gt;
&lt;br /&gt;
* Capture The Flag contest now online at [http://ctf.webguvenligi.org/ http://ctf.webguvenligi.org/] with the courtesy of Onur Yilmaz. (Naturally ethical) successfull first two attackers will be rewarded by two security related books!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75019</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75019"/>
				<updated>2009-12-10T14:49:29Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* Most, if not all, of the OWASP/TR members will be attending to the [http://www.istsec.org/ IstSec '09], the security conference, in 12-13 December.&lt;br /&gt;
&lt;br /&gt;
Two new projects from OWASP/TR; &lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine] web security magazine in Turkish, now online with its third issue!&lt;br /&gt;
&lt;br /&gt;
* Capture The Flag contest now online at [http://ctf.webguvenligi.org/ http://ctf.webguvenligi.org/] with the courtesy of Onur Yilmaz. (Naturally ethical) successfull first two attackers will be rewarded by two security related books!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75018</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75018"/>
				<updated>2009-12-10T14:48:53Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* Most if not the all of the OWASP/TR members will be attending to the [http://www.istsec.org/ IstSec '09], the security conference, in 12-13 December.&lt;br /&gt;
&lt;br /&gt;
Two new projects from OWASP/TR; &lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine] web security magazine in Turkish, now online with its third issue!&lt;br /&gt;
&lt;br /&gt;
* Capture The Flag contest now online at [http://ctf.webguvenligi.org/ http://ctf.webguvenligi.org/] with the courtesy of Onur Yilmaz. (Naturally ethical) successfull first two attackers will be rewarded by two security related books!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75017</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75017"/>
				<updated>2009-12-10T14:48:23Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* Most if not the all of the OWASP/TR members will be attending to the [http://www.istsec.org/ IstSec '09], the security conference.&lt;br /&gt;
&lt;br /&gt;
Two new projects from OWASP/TR; &lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine] web security magazine in Turkish, now online with its third issue!&lt;br /&gt;
&lt;br /&gt;
* Capture The Flag contest now online at [http://ctf.webguvenligi.org/ http://ctf.webguvenligi.org/] with the courtesy of Onur Yilmaz. (Naturally ethical) successfull first two attackers will be rewarded by two security related books!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75016</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=75016"/>
				<updated>2009-12-10T14:47:20Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Two new projects from OWASP/TR; &lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine] web security magazine in Turkish, now online with its third issue!&lt;br /&gt;
&lt;br /&gt;
* Capture The Flag contest now online at [http://ctf.webguvenligi.org/ http://ctf.webguvenligi.org/] with the courtesy of Onur Yilmaz. (Naturally ethical) successfull first two attackers will be rewarded by two security related books!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=73952</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=73952"/>
				<updated>2009-11-22T11:56:09Z</updated>
		
		<summary type="html">&lt;p&gt;Bedirhan: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir], [mailto:gokhan.alkan~yahoo.com.tr Gökhan Alkan], [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:yusufceri4~gmail.com Yusuf Çeri], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Two new projects from OWASP/TR; &lt;br /&gt;
&lt;br /&gt;
* Capture The Flag contest now online at [http://ctf.webguvenligi.org/ http://ctf.webguvenligi.org/] with the courtesy of Onur Yilmaz. (Naturally ethical) successfull first two attackers will be rewarded by two security related books!&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine] web security magazine in Turkish, now online with its second issue!&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid 8-9 months].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bedirhan</name></author>	</entry>

	</feed>