<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bishan+Singh</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bishan+Singh"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Bishan_Singh"/>
		<updated>2026-04-23T02:40:48Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Alchemist_Project&amp;diff=88858</id>
		<title>OWASP Alchemist Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Alchemist_Project&amp;diff=88858"/>
				<updated>2010-09-08T13:23:07Z</updated>
		
		<summary type="html">&lt;p&gt;Bishan Singh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main ====&lt;br /&gt;
While there are extensive resources on the Internet about secure architecture and security practices that when implemented effectively across an SDLC produce highly secure and defensible applications. One must acknowledge that their adoption has challenged project teams, one constraint being lack of reference implementations that demonstrate effective realization of highly secure and defensible applications. &lt;br /&gt;
&lt;br /&gt;
Alchemist aims to bridge this gap. Alchemist is a free, open source, enterprise web application security resource that enables software development teams build high secure and defensible applications. Alchemist is structured for easier adoption and learning for software architects and programmers, allowing them to implement strong security practices into their applications. &lt;br /&gt;
&lt;br /&gt;
The focus is to achieve this objective by architecting and developing a highly secure and defensible enterprise web application. The outcome of this exercise is targeted as a reference implementation for development houses. The overall  objective is to leverage secure architecture and practices to showcase secure application development implementations with leading technologies and frameworks. In its first exercise, Alchemist proposes to demonstrate a secure J2EE web application that is developed using Spring framework.&lt;br /&gt;
&lt;br /&gt;
OWASP lists a number of common application security [[:Category:Vulnerability|vulnerabilities]]. These apply to most of the programming languages and platforms. The notable exception being [[Buffer Overflow|buffer overflow]] and related issues that do not apply to J2EE. .Net and the likes. Alchemist is designed to demonstrate effective mitigation of most of these issues in its reference implementations.&lt;br /&gt;
&lt;br /&gt;
More details on the project, including the high level road-map can be found in the Project About tab. If you'd like to contribute join the [https://lists.owasp.org/mailman/listinfo/owasp-alchemist-project mailing list] and share your ideas and suggestions on the ongoing progress, and of course your proposal for contribution for the ongoing work or work for other programming languages. &lt;br /&gt;
&lt;br /&gt;
==== Project About ====&lt;br /&gt;
{{:Projects/OWASP_Alchemist_Project | Project About}}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Alchemist Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool]]&lt;/div&gt;</summary>
		<author><name>Bishan Singh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Alchemist_Project&amp;diff=88857</id>
		<title>Projects/OWASP Alchemist Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Alchemist_Project&amp;diff=88857"/>
				<updated>2010-09-08T13:14:37Z</updated>
		
		<summary type="html">&lt;p&gt;Bishan Singh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name = OWASP Alchemist Project&lt;br /&gt;
| project_home_page =:OWASP Alchemist Project&lt;br /&gt;
&lt;br /&gt;
| project_description =&lt;br /&gt;
&lt;br /&gt;
Alchemist enables a software development team in realization of highly secure and defensible application with built-in defenses/controls against security‐related design, coding and implementation flaws. &lt;br /&gt;
&lt;br /&gt;
Alchemist is focused to present this solution by architecting a real-life high stakes application with security built into it right from the inception, step-by-step as it falls under an SDLC. The current exercise is targeted at demonstrating this on a J2EE based web application that is developed using Spring framework. Spring framework was chosen due to its widespread adoption in the financial products. However, it is important note that Alchemist is not limited to J2EE or more specifically Spring framework. The idea is to demonstrate the upper spectrum of security practices that are often neglected or are done in bits and pieces by picking a well known widely adopted technology. Since the emphasis is on security architecture and defensibility, the future road-map is to demonstrate the same for applications built using other leading programming languages and frameworks. &lt;br /&gt;
&lt;br /&gt;
Although this project is more than useful for existing/already developed applications, Alchemist is not the ideal solution to retrofit security into existing applications. It is aimed at offering more to applications that are at least in development, most in design phase. Allowing for language-specific differences, Alchemist builds this application with a strong foundation of security architecture that covers following main practices:&lt;br /&gt;
&lt;br /&gt;
*Security Requirements&lt;br /&gt;
*Threat Risk Modeling&lt;br /&gt;
*Use and Abuse Cases&lt;br /&gt;
*Secure Coding Guideline&lt;br /&gt;
&lt;br /&gt;
| project_license = [http://www.gnu.org/licenses/#GPL GNU General Public License]&lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Bishan Singh&lt;br /&gt;
| leader_email1 = Bishan.Singh@owasp.org&lt;br /&gt;
| leader_username1 = Bishan Singh&lt;br /&gt;
&lt;br /&gt;
| leader_name2 = Chandrakanth Reddy Narreddy&lt;br /&gt;
| leader_email2 = chandra.kanth@owasp.org&lt;br /&gt;
| leader_username2 = Chandrakanth Reddy Narreddy&lt;br /&gt;
&lt;br /&gt;
| leader_name3 = Naveen Rudrappa&lt;br /&gt;
| leader_email3 = naveen.rudrappa@owasp.org&lt;br /&gt;
| leader_username3 = Naveen Rudrappa&lt;br /&gt;
&lt;br /&gt;
| contributor_name[1-10] = &lt;br /&gt;
| contributor_email[1-10] = &lt;br /&gt;
| contributor_username[1-10] = &lt;br /&gt;
&lt;br /&gt;
| pamphlet_link = http://www.owasp.org/images/8/85/ALCHEMIST_-_PROJECT_CHARTER_v0_2.pdf&lt;br /&gt;
&lt;br /&gt;
| presentation_link =&lt;br /&gt;
&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp-alchemist-project&lt;br /&gt;
&lt;br /&gt;
| project_road_map = http://www.owasp.org/images/8/85/ALCHEMIST_-_PROJECT_CHARTER_v0_2.pdf &lt;br /&gt;
&lt;br /&gt;
| links_url[1-10] = &lt;br /&gt;
| links_name[1-10] = &lt;br /&gt;
| release_1 = Alchemist 1.0&lt;br /&gt;
| release_2 = &lt;br /&gt;
| release_3 =&lt;br /&gt;
| release_4 =&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Bishan Singh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Alchemist_Project&amp;diff=88856</id>
		<title>OWASP Alchemist Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Alchemist_Project&amp;diff=88856"/>
				<updated>2010-09-08T13:09:33Z</updated>
		
		<summary type="html">&lt;p&gt;Bishan Singh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main ====&lt;br /&gt;
While there are extensive resources on the Internet about secure architecture and security practices that when implemented effectively across an SDLC produce highly secure and defensible applications. One must acknowledge that their adoption has challenged project teams, one constraint being lack of reference implementations that demonstrate effective realization of highly secure and defensible applications. &lt;br /&gt;
&lt;br /&gt;
Alchemist aims to bridge this gap. Alchemist is a free, open source, enterprise web application security resource that enables software development teams build high secure and defensible applications. Alchemist is structured for easier adoption and learning for software architects and programmers, allowing them to implement strong security practices into their applications. &lt;br /&gt;
&lt;br /&gt;
The focus is to achieve this objective by architecting and developing a highly secure and defensible enterprise web application. The outcome of this exercise is targeted as a reference implementation for development houses. The overall  objective is to leverage secure architecture and practices to showcase secure application development implementations with leading technologies and frameworks. In its first exercise, Alchemist proposes to demonstrate a secure J2EE web application that is developed using Spring framework.&lt;br /&gt;
&lt;br /&gt;
OWASP lists a number of common application security [[:Category:Vulnerability|vulnerabilities]]. These apply to most of the programming languages and platforms. The notable exception being [[Buffer Overflow|buffer overflow]] and related issues that do not apply to J2EE. .Net and the likes. Alchemist is designed to demonstrate effective mitigation of most of these issues in its reference implementations.&lt;br /&gt;
&lt;br /&gt;
More details on the project, including the high level road-map can be found in the Project About tab. If you'd like to contribute join the [https://lists.owasp.org/mailman/listinfo/owasp-alchemist-project mailing list] and share your ideas and suggestions on the ongoing progress, and of course your proposal for contribution for the ongoing work or work for other programming languages. &lt;br /&gt;
&lt;br /&gt;
''NOTE: This project has no sponsors. Please reach us if you wish to sponsor this initiative. Sponsorship goes a long way in speeding up our release cycles and of course spawning other reference implementations sooner than later.&lt;br /&gt;
''&lt;br /&gt;
==== Project About ====&lt;br /&gt;
{{:Projects/OWASP_Alchemist_Project | Project About}}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Alchemist Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool]]&lt;/div&gt;</summary>
		<author><name>Bishan Singh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Alchemist_Project&amp;diff=88855</id>
		<title>OWASP Alchemist Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Alchemist_Project&amp;diff=88855"/>
				<updated>2010-09-08T13:03:10Z</updated>
		
		<summary type="html">&lt;p&gt;Bishan Singh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main ====&lt;br /&gt;
While there are extensive resources on the Internet about secure architecture and security practices that when implemented effectively across an SDLC produce highly secure and defensible applications. One must acknowledge that their adoption has challenged project teams, one constraint being lack of reference implementations that demonstrate effective realization of highly secure and defensible applications. &lt;br /&gt;
&lt;br /&gt;
Alchemist aims to bridge this gap. Alchemist is a free, open source, enterprise web application security resource that enables software development teams build high secure and defensible applications. Alchemist is structured for easier adoption and learning for software architects and programmers, allowing them to implement strong security practices into their applications. &lt;br /&gt;
&lt;br /&gt;
The focus is to achieve this objective by architecting and developing a highly secure and defensible enterprise web application. The outcome of this exercise is targeted as a reference implementation for development houses. The overall  objective is to leverage secure architecture and practices to showcase secure application development implementations with leading technologies and frameworks. In its first exercise, Alchemist proposes to demonstrate a secure J2EE web application that is developed using Spring framework.&lt;br /&gt;
&lt;br /&gt;
OWASP lists a number of common application security [[:Category:Vulnerability|vulnerabilities]]. These apply to most of the programming languages and platforms. The notable exception being [[Buffer Overflow|buffer overflow]] and related issues that do not apply to J2EE. .Net and the likes. Alchemist is designed to demonstrate effective mitigation of most of these issues in its reference implementations.&lt;br /&gt;
&lt;br /&gt;
More details on the project, including the high level road-map can be found in the Project About tab. If you'd like to contribute join the [https://lists.owasp.org/mailman/listinfo/owasp-alchemist-project mailing list] and share your ideas and suggestions on the ongoing progress, and of course your proposal for contribution for the ongoing work or work for other programming languages. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project About ====&lt;br /&gt;
{{:Projects/OWASP_Alchemist_Project | Project About}}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Alchemist Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool]]&lt;/div&gt;</summary>
		<author><name>Bishan Singh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Alchemist_Project&amp;diff=88854</id>
		<title>Projects/OWASP Alchemist Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Alchemist_Project&amp;diff=88854"/>
				<updated>2010-09-08T12:59:33Z</updated>
		
		<summary type="html">&lt;p&gt;Bishan Singh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name = OWASP Alchemist Project&lt;br /&gt;
| project_home_page =:OWASP Alchemist Project&lt;br /&gt;
&lt;br /&gt;
| project_description =&lt;br /&gt;
&lt;br /&gt;
Alchemist enables a software development team in realization of highly secure and defensible application with built-in defenses/controls against security‐related design, coding and implementation flaws. &lt;br /&gt;
&lt;br /&gt;
Alchemist is focused to present this solution by way of architecting a real-life high stakes application with security built into it right from the inception, step-by-step as it falls under an SDLC. The current exercise is targeted at demonstrating this on a J2EE based web application that is developed using Spring framework. Spring framework was chosen due to its widespread adoption in the financial products. However, it is important note that Alchemist is not limited to J2EE or more specifically Spring framework. The idea is to demonstrate the upper spectrum of security practices that are often neglected or are done in bits and pieces by picking a well known widely adopted technology. Since the emphasis is on security architecture and defensibility, the future road-map is to demonstrate the same for applications built using other leading programming languages and frameworks. &lt;br /&gt;
&lt;br /&gt;
Although this project is more than useful for existing/already developed applications, Alchemist is not the ideal solution to retrofit security into existing applications. It is aimed at offering more to applications that are at least in development, most in design phase. Allowing for language-specific differences, Alchemist builds this application with a strong foundation of security architecture that covers following main practices:&lt;br /&gt;
&lt;br /&gt;
*Security Requirements&lt;br /&gt;
*Threat Risk Modeling&lt;br /&gt;
*Use and Abuse Cases&lt;br /&gt;
*Secure Coding Guideline&lt;br /&gt;
&lt;br /&gt;
| project_license = [http://www.gnu.org/licenses/#GPL GNU General Public License]&lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Bishan Singh&lt;br /&gt;
| leader_email1 = Bishan.Singh@owasp.org&lt;br /&gt;
| leader_username1 = Bishan Singh&lt;br /&gt;
&lt;br /&gt;
| leader_name2 = Chandrakanth Reddy Narreddy&lt;br /&gt;
| leader_email2 = chandra.kanth@owasp.org&lt;br /&gt;
| leader_username2 = Chandrakanth Reddy Narreddy&lt;br /&gt;
&lt;br /&gt;
| leader_name3 = Naveen Rudrappa&lt;br /&gt;
| leader_email3 = naveen.rudrappa@owasp.org&lt;br /&gt;
| leader_username3 = Naveen Rudrappa&lt;br /&gt;
&lt;br /&gt;
| contributor_name[1-10] = &lt;br /&gt;
| contributor_email[1-10] = &lt;br /&gt;
| contributor_username[1-10] = &lt;br /&gt;
&lt;br /&gt;
| pamphlet_link = http://www.owasp.org/images/8/85/ALCHEMIST_-_PROJECT_CHARTER_v0_2.pdf&lt;br /&gt;
&lt;br /&gt;
| presentation_link =&lt;br /&gt;
&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp-alchemist-project&lt;br /&gt;
&lt;br /&gt;
| project_road_map = http://www.owasp.org/images/8/85/ALCHEMIST_-_PROJECT_CHARTER_v0_2.pdf &lt;br /&gt;
&lt;br /&gt;
| links_url[1-10] = &lt;br /&gt;
| links_name[1-10] = &lt;br /&gt;
| release_1 = Alchemist 1.0&lt;br /&gt;
| release_2 = &lt;br /&gt;
| release_3 =&lt;br /&gt;
| release_4 =&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Bishan Singh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Alchemist_Project&amp;diff=88853</id>
		<title>OWASP Alchemist Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Alchemist_Project&amp;diff=88853"/>
				<updated>2010-09-08T12:52:45Z</updated>
		
		<summary type="html">&lt;p&gt;Bishan Singh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main ====&lt;br /&gt;
While there are extensive resources on the Internet about secure architecture and security practices that when implemented effectively across an SDLC produce highly secure and defensible applications. One must acknowledge that their adoption has challenged project teams, one constraint being lack of reference implementations that demonstrate effective realization of highly secure and defensible applications. &lt;br /&gt;
&lt;br /&gt;
Alchemist aims to bridge this gap. Alchemist is a free, open source, enterprise web application security resource that enables software development teams build high secure and defensible applications. Alchemist is structured for easier adoption and learning for software architects and programmers, allowing them to implement strong security practices into their applications. &lt;br /&gt;
&lt;br /&gt;
The focus is to achieve this objective by architecting and developing a highly secure and defensible enterprise web application. The outcome of this exercise is targeted as a reference implementation for development houses. The overall  objective is to showcase, leveraging secure architecture and practices, secure development implementations with leading technologies and frameworks. In its first exercise, Alchemist proposes to demonstrate a secure J2EE web application that is developed using Spring framework.&lt;br /&gt;
&lt;br /&gt;
OWASP lists a number of common application security [[:Category:Vulnerability|vulnerabilities]]. These apply to most of the programming languages and platforms. The notable exception being [[Buffer Overflow|buffer overflow]] and related issues that do not apply to J2EE. .Net and the likes. Alchemist is designed to demonstrate effective mitigation of most of these issues in its reference implementations.&lt;br /&gt;
&lt;br /&gt;
More details on the project, including the high level road-map can be found in the Project About tab. If you'd like to contribute join the [https://lists.owasp.org/mailman/listinfo/owasp-alchemist-project mailing list] and share your ideas and suggestions on the ongoing progress, and of course your proposal for contribution for the ongoing work or work for other programming languages. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project About ====&lt;br /&gt;
{{:Projects/OWASP_Alchemist_Project | Project About}}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Alchemist Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool]]&lt;/div&gt;</summary>
		<author><name>Bishan Singh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Alchemist_Project/Releases/Alchemist_Secure_J2EE_Spring_v1.0&amp;diff=88840</id>
		<title>Projects/OWASP Alchemist Project/Releases/Alchemist Secure J2EE Spring v1.0</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Alchemist_Project/Releases/Alchemist_Secure_J2EE_Spring_v1.0&amp;diff=88840"/>
				<updated>2010-09-08T12:21:50Z</updated>
		
		<summary type="html">&lt;p&gt;Bishan Singh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template: &amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;Release About&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| project_name = OWASP Alchemist Project&lt;br /&gt;
| project_home_page = :OWASP Alchemist Project&lt;br /&gt;
&lt;br /&gt;
| release_name = Alchemist 1.0&lt;br /&gt;
| release_date = 13th December 2010  &lt;br /&gt;
| release_download_link = &lt;br /&gt;
&lt;br /&gt;
| release_description = A real-world banking application with 5 dynamic pages.&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
| release_license = [http://www.gnu.org/licenses/#GPL GNU General Public License]&lt;br /&gt;
 &lt;br /&gt;
| leader_name1 = Bishan Singh&lt;br /&gt;
| leader_email1 = c70n3r@gmail.com&lt;br /&gt;
| leader_username1 = &lt;br /&gt;
&lt;br /&gt;
| leader_name2 = Chandrakanth Narreddy&lt;br /&gt;
| leader_email2 = chandra.kanth@hotmail.com&lt;br /&gt;
| leader_username2 = &lt;br /&gt;
&lt;br /&gt;
| leader_name3 = Naveen Rudrappa&lt;br /&gt;
| leader_email3 = Naveen.rudra02@gmail.com&lt;br /&gt;
| leader_username3 = &lt;br /&gt;
&lt;br /&gt;
| contributor_name1 = &lt;br /&gt;
| contributor_email1 = &lt;br /&gt;
| contributor_username1 = &lt;br /&gt;
&lt;br /&gt;
| contributor_name2 = &lt;br /&gt;
| contributor_email2 = &lt;br /&gt;
| contributor_username2 = &lt;br /&gt;
&lt;br /&gt;
| release_notes = &lt;br /&gt;
&lt;br /&gt;
| links_url1 =  &lt;br /&gt;
| links_name1 = &lt;br /&gt;
&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Bishan Singh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Alchemist_Project&amp;diff=88701</id>
		<title>OWASP Alchemist Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Alchemist_Project&amp;diff=88701"/>
				<updated>2010-09-05T11:34:52Z</updated>
		
		<summary type="html">&lt;p&gt;Bishan Singh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main ====&lt;br /&gt;
While there are extensive resources on the Internet about security architecture and security practices that when implemented effectively across an SDLC produce highly secure and defensible applications. It is easier said than done. Notably, most of the popular programming languages and frameworks contain many security technologies, yet it is not easy to produce an application without security vulnerabilities. &lt;br /&gt;
&lt;br /&gt;
Alchemist aims to bridge these gaps. Alchemist is a free, open source, web application security resource that enables software development teams build high secure and defensible applications. Alchemist is structured for easier adoption and learning of software architects, analysts and programmers, allowing them implement strong security practices into their own web applications. &lt;br /&gt;
&lt;br /&gt;
The current focus is on achieving this objective by architecting and developing a highly secure and defensible application in J2EE on top of Spring framework. The outcome of this exercise is targeted as a reference implementation. The overall objective is to be independent of programming language, yet show-case a real-life application in each of the popular programming languages and frameworks. &lt;br /&gt;
&lt;br /&gt;
OWASP lists a number of common application security [[:Category:Vulnerability|vulnerabilities]]. These apply to most of the programming languages and platforms. The notable exception being [[Buffer Overflow|buffer overflow]] and related issues that do not apply to J2EE. .Net and the likes. Alchemist is designed to demonstrate effective mitigation of most of these issues in its reference implementations.&lt;br /&gt;
&lt;br /&gt;
More details on the project, including the high level road-map can be found in the Project About tab. If you'd like to contribute join the [https://lists.owasp.org/mailman/listinfo/owasp-alchemist-project mailing list] and share your ideas and suggestions on the ongoing progress, and of course your proposal for contribution for the ongoing work or work for other programming languages. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project About ====&lt;br /&gt;
{{:Projects/OWASP_Alchemist_Project | Project About}}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Alchemist Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool]]&lt;/div&gt;</summary>
		<author><name>Bishan Singh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Alchemist_Project&amp;diff=88700</id>
		<title>Projects/OWASP Alchemist Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Alchemist_Project&amp;diff=88700"/>
				<updated>2010-09-05T10:56:17Z</updated>
		
		<summary type="html">&lt;p&gt;Bishan Singh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name = OWASP Alchemist Project&lt;br /&gt;
| project_home_page =:OWASP Alchemist Project&lt;br /&gt;
&lt;br /&gt;
| project_description =&lt;br /&gt;
&lt;br /&gt;
A large majority of software projects do not incorporate security from the word go. Alchemist intends to help solve this conundrum, by enabling a software development team in realization of highly secure and defensible application with built-in defenses/controls against security‐related design, coding and implementation flaws. &lt;br /&gt;
&lt;br /&gt;
Alchemist is focused to present this solution by way of architecting a real-life high stakes software application in J2EE on top of Spring framework with security built into it right from the inception, step-by-step as it falls under an SDLC. It is important to note that Alchemist is not limited to J2EE or more specifically Spring framework. The idea is to demonstrate the upper spectrum of security practices that are often neglected or are done in bits and pieces by picking a well known widely adopted framework. Spring framework was chosen due to its widespread adoption in the financial products. Since the emphasis is on security architecture and defensibility, the future road-map is to demonstrate the same for applications built on other programming languages and frameworks. &lt;br /&gt;
&lt;br /&gt;
Although this project is more than useful for existing/already developed applications, Alchemist is not the ideal solution to retrofit security into existing applications. It is aimed at offering more to applications that are at least in development, most in design phase. Allowing for language-specific differences, Alchemist builds this application with a strong foundation of security architecture that covers following main practices:&lt;br /&gt;
&lt;br /&gt;
*Security Requirements&lt;br /&gt;
*Threat Risk Modeling&lt;br /&gt;
*Use and Abuse Cases&lt;br /&gt;
*Secure Coding Guideline&lt;br /&gt;
&lt;br /&gt;
| project_license = [http://www.gnu.org/licenses/#GPL GNU General Public License]&lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Bishan Singh&lt;br /&gt;
| leader_email1 = Bishan.Singh@owasp.org&lt;br /&gt;
| leader_username1 = Bishan Singh&lt;br /&gt;
&lt;br /&gt;
| leader_name2 = Chandrakanth Reddy Narreddy&lt;br /&gt;
| leader_email2 = chandra.kanth@owasp.org&lt;br /&gt;
| leader_username2 = Chandrakanth Reddy Narreddy&lt;br /&gt;
&lt;br /&gt;
| leader_name3 = Naveen Rudrappa&lt;br /&gt;
| leader_email3 = naveen.rudrappa@owasp.org&lt;br /&gt;
| leader_username3 = Naveen Rudrappa&lt;br /&gt;
&lt;br /&gt;
| contributor_name[1-10] = &lt;br /&gt;
| contributor_email[1-10] = &lt;br /&gt;
| contributor_username[1-10] = &lt;br /&gt;
&lt;br /&gt;
| pamphlet_link = http://www.owasp.org/images/8/85/ALCHEMIST_-_PROJECT_CHARTER_v0_2.pdf&lt;br /&gt;
&lt;br /&gt;
| presentation_link =&lt;br /&gt;
&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp-alchemist-project&lt;br /&gt;
&lt;br /&gt;
| project_road_map = http://www.owasp.org/images/8/85/ALCHEMIST_-_PROJECT_CHARTER_v0_2.pdf &lt;br /&gt;
&lt;br /&gt;
| links_url[1-10] = &lt;br /&gt;
| links_name[1-10] = &lt;br /&gt;
| release_1 = Alchemist 1.0&lt;br /&gt;
| release_2 = &lt;br /&gt;
| release_3 =&lt;br /&gt;
| release_4 =&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Bishan Singh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Alchemist_Project&amp;diff=88699</id>
		<title>Projects/OWASP Alchemist Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Alchemist_Project&amp;diff=88699"/>
				<updated>2010-09-05T09:42:50Z</updated>
		
		<summary type="html">&lt;p&gt;Bishan Singh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:Project About&lt;br /&gt;
| project_name = OWASP Alchemist Project&lt;br /&gt;
| project_home_page =:OWASP Alchemist Project&lt;br /&gt;
&lt;br /&gt;
| project_description =&lt;br /&gt;
&lt;br /&gt;
*A large majority of software projects do not incorporate security from the word go. Alchemist intends to help solve this conundrum, by enabling a software development team in realization of highly secure and defensible application with built-in defenses/controls against security‐related design, coding and implementation flaws. Alchemist is focused to present this solution by way of architecting a real-life high stakes software application in J2EE (Spring/Struts) with security built into it right from the inception, step-by-step as it falls under an SDLC. Although this project is more than useful for existing/already developed applications, Alchemist is not the ideal solution to retrofit security into existing applications. It is aimed at offering more to applications that are at least in development, most in design phase. Allowing for language-specific differences, Alchemist builds this application with a strong foundation of security architecture that covers following main practices:&lt;br /&gt;
**Security Requirements,&lt;br /&gt;
**Threat Risk Modeling,&lt;br /&gt;
**Use and Abuse Cases,&lt;br /&gt;
**Secure Coding Guideline,&lt;br /&gt;
&lt;br /&gt;
| project_license = [http://www.gnu.org/licenses/#GPL GNU General Public License]&lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Bishan Singh&lt;br /&gt;
| leader_email1 = Bishan.Singh@owasp.org&lt;br /&gt;
| leader_username1 = Bishan Singh&lt;br /&gt;
&lt;br /&gt;
| leader_name2 = Chandrakanth Reddy Narreddy&lt;br /&gt;
| leader_email2 = chandra.kanth@owasp.org&lt;br /&gt;
| leader_username2 = Chandrakanth Reddy Narreddy&lt;br /&gt;
&lt;br /&gt;
| leader_name3 = Naveen Rudrappa&lt;br /&gt;
| leader_email3 = naveen.rudrappa@owasp.org&lt;br /&gt;
| leader_username3 = Naveen Rudrappa&lt;br /&gt;
&lt;br /&gt;
| contributor_name[1-10] = &lt;br /&gt;
| contributor_email[1-10] = &lt;br /&gt;
| contributor_username[1-10] = &lt;br /&gt;
&lt;br /&gt;
| pamphlet_link = http://www.owasp.org/images/8/85/ALCHEMIST_-_PROJECT_CHARTER_v0_2.pdf&lt;br /&gt;
&lt;br /&gt;
| presentation_link =&lt;br /&gt;
&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp-alchemist-project&lt;br /&gt;
&lt;br /&gt;
| project_road_map = http://www.owasp.org/images/8/85/ALCHEMIST_-_PROJECT_CHARTER_v0_2.pdf &lt;br /&gt;
&lt;br /&gt;
| links_url[1-10] = &lt;br /&gt;
| links_name[1-10] = &lt;br /&gt;
| release_1 = Alchemist 1.0&lt;br /&gt;
| release_2 = &lt;br /&gt;
| release_3 =&lt;br /&gt;
| release_4 =&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Bishan Singh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Projects/OWASP_Alchemist_Project&amp;diff=88698</id>
		<title>Projects/OWASP Alchemist Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Projects/OWASP_Alchemist_Project&amp;diff=88698"/>
				<updated>2010-09-05T06:39:50Z</updated>
		
		<summary type="html">&lt;p&gt;Bishan Singh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main ====&lt;br /&gt;
{{Template:Project About&lt;br /&gt;
| project_name = OWASP Alchemist Project&lt;br /&gt;
| project_home_page =:OWASP Alchemist Project&lt;br /&gt;
&lt;br /&gt;
| project_description =&lt;br /&gt;
&lt;br /&gt;
*A large majority of software projects do not incorporate security from the word go. Alchemist intends to help solve this conundrum, by enabling a software development team in realization of highly secure and defensible application with built-in defenses/controls against security‐related design, coding and implementation flaws. Alchemist is focused to present this solution by way of architecting a real-life high stakes software application in J2EE (Spring/Struts) with security built into it right from the inception, step-by-step as it falls under an SDLC. Although this project is more than useful for existing/already developed applications, Alchemist is not the ideal solution to retrofit security into existing applications. It is aimed at offering more to applications that are at least in development, most in design phase. Allowing for language-specific differences, Alchemist builds this application with a strong foundation of security architecture that covers following main practices:&lt;br /&gt;
**Security Requirements,&lt;br /&gt;
**Threat Risk Modeling,&lt;br /&gt;
**Use and Abuse Cases,&lt;br /&gt;
**Secure Coding Guideline,&lt;br /&gt;
&lt;br /&gt;
| project_license = [http://www.gnu.org/licenses/#GPL GNU General Public License]&lt;br /&gt;
&lt;br /&gt;
| leader_name1 = Bishan Singh&lt;br /&gt;
| leader_email1 = Bishan.Singh@owasp.org&lt;br /&gt;
| leader_username1 = Bishan Singh&lt;br /&gt;
&lt;br /&gt;
| leader_name2 = Chandrakanth Reddy Narreddy&lt;br /&gt;
| leader_email2 = chandra.kanth@owasp.org&lt;br /&gt;
| leader_username2 = Chandrakanth Reddy Narreddy&lt;br /&gt;
&lt;br /&gt;
| leader_name3 = Naveen Rudrappa&lt;br /&gt;
| leader_email3 = naveen.rudrappa@owasp.org&lt;br /&gt;
| leader_username3 = Naveen Rudrappa&lt;br /&gt;
&lt;br /&gt;
| contributor_name[1-10] = &lt;br /&gt;
| contributor_email[1-10] = &lt;br /&gt;
| contributor_username[1-10] = &lt;br /&gt;
&lt;br /&gt;
| pamphlet_link = http://www.owasp.org/images/8/85/ALCHEMIST_-_PROJECT_CHARTER_v0_2.pdf&lt;br /&gt;
&lt;br /&gt;
| presentation_link =&lt;br /&gt;
&lt;br /&gt;
| mailing_list_name = https://lists.owasp.org/mailman/listinfo/owasp-alchemist-project&lt;br /&gt;
&lt;br /&gt;
| project_road_map = http://www.owasp.org/images/8/85/ALCHEMIST_-_PROJECT_CHARTER_v0_2.pdf &lt;br /&gt;
&lt;br /&gt;
| links_url[1-10] = &lt;br /&gt;
| links_name[1-10] = &lt;br /&gt;
| release_1 = Alchemist 1.0&lt;br /&gt;
| release_2 = &lt;br /&gt;
| release_3 =&lt;br /&gt;
| release_4 =&lt;br /&gt;
}}&lt;/div&gt;</summary>
		<author><name>Bishan Singh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Alchemist_Project&amp;diff=88514</id>
		<title>OWASP Alchemist Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Alchemist_Project&amp;diff=88514"/>
				<updated>2010-09-02T04:28:04Z</updated>
		
		<summary type="html">&lt;p&gt;Bishan Singh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main ====&lt;br /&gt;
Hello Bish. Please fill in here as you find best. Thanks much, Paulo Coimbra&lt;br /&gt;
&lt;br /&gt;
==== Project About ====&lt;br /&gt;
{{:Projects/OWASP_Alchemist_Project | Project About}}&lt;br /&gt;
&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|Alchemist Project]]&lt;br /&gt;
[[Category:OWASP Tool]]&lt;br /&gt;
[[Category:OWASP Alpha Quality Tool]]&lt;/div&gt;</summary>
		<author><name>Bishan Singh</name></author>	</entry>

	</feed>