<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bkmarshall</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bkmarshall"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Bkmarshall"/>
		<updated>2026-05-26T15:39:03Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Bkmarshall&amp;diff=251782</id>
		<title>User:Bkmarshall</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Bkmarshall&amp;diff=251782"/>
				<updated>2019-05-21T22:49:18Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Bruce K. Marshall is currently a Senior Security Consultant in Kansas City.  He has two decades of experience in the information security field.  In that time he has consulted with both small and large clients, while using his experience and knowledge to earn certifications like the CISSP, NSA-IAM, MCSE: Security, and SPI Certified Instructor.  &lt;br /&gt;
&lt;br /&gt;
Bruce is s past leader of the [[Kansas_City]] OWASP chapter.  He also founded and maintains the PasswordResearch.com[http://www.passwordresearch.com] website.&lt;br /&gt;
&lt;br /&gt;
Bruce can be contacted at bkmarshall [at] passwordresearch [dot] com.&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Bkmarshall&amp;diff=30375</id>
		<title>User:Bkmarshall</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Bkmarshall&amp;diff=30375"/>
				<updated>2008-06-04T18:55:31Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Bruce K. Marshall is currently a Senior Security Consultant in Kansas City.  He is closing in on a decade and a half of experience in the information security field.  In that time he has consulted with both small and large clients, while using his experience and knowledge to earn certifications like the CISSP, NSA-IAM, MCSE: Security, and SPI Certified Instructor.  &lt;br /&gt;
&lt;br /&gt;
Bruce is past leader of the [[Kansas_City]] OWASP chapter.  He also founded and maintains the PasswordResearch.com[http://www.passwordresearch.com] website.&lt;br /&gt;
&lt;br /&gt;
Bruce can be contacted at bkmarshall [at] passwordresearch [dot] com or 913-484-7233.&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_April_2008_Meeting&amp;diff=30374</id>
		<title>Kansas City April 2008 Meeting</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_April_2008_Meeting&amp;diff=30374"/>
				<updated>2008-06-04T18:53:06Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: added link to presentation slides&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The [[Kansas_City]] OWASP chapter met on April 30, 2008 at Centriq Training in Leawood, KS.&lt;br /&gt;
&lt;br /&gt;
=== Meeting Summary ===&lt;br /&gt;
&lt;br /&gt;
'''Chapter Business'''&lt;br /&gt;
&lt;br /&gt;
Current chapter priorities include the following:&lt;br /&gt;
* Volunteer to give an OWASP presentation&lt;br /&gt;
** Talks can anything from a short review of a whitepaper or presentation you've seen, to a web application security tool or product review, to a longer technical talk about attacks or countermeasures&lt;br /&gt;
* Volunteer your organization to host an OWASP meeting&lt;br /&gt;
* Invite other professionals or students to attend our next OWASP meeting&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Speakers: Karen Fritsche &amp;amp; Sarah Heinen on Security Access Mark-up Language (SAML) &amp;amp; Single Sign-on Implementation'''&lt;br /&gt;
&lt;br /&gt;
To accomplish a Web Single Sign-On application with their brokerage back office vendor, American Century Investments solution included the use of SAML.  This presentation will provide an overview of: SAML, its benefits and several Single Sign-On options; integration, architecture and configuration options; and the SAML SSO implementation completed by American Century Investments.&lt;br /&gt;
&lt;br /&gt;
Karen Fritsche is an Application Architect and Sarah Heinen is a Programmer / Analyst with American Century Investments in Kansas City.  As part of the IT application development team that supports the company's retail web sites www.americancentury.com and www.learningquestsavings.com, they focus on the secure on-line financial transactions of the sites, either through internal services or by establishing single sign-on connectivity to third party vendor sites.&lt;br /&gt;
&lt;br /&gt;
=== Documents ===&lt;br /&gt;
&lt;br /&gt;
* Karen &amp;amp; Sarah's [https://www.owasp.org/images/d/df/OWASPKC_SAML_Presentation.ppt presentation slides]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:OWASPKC_SAML_Presentation.ppt&amp;diff=30370</id>
		<title>File:OWASPKC SAML Presentation.ppt</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:OWASPKC_SAML_Presentation.ppt&amp;diff=30370"/>
				<updated>2008-06-04T18:48:45Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: To accomplish a Web Single Sign-On application with their brokerage back office vendor, American Century Investments solution included the use of SAML. This presentation will provide an overview of: SAML, its benefits and several Single Sign-On options; i&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;To accomplish a Web Single Sign-On application with their brokerage back office vendor, American Century Investments solution included the use of SAML. This presentation will provide an overview of: SAML, its benefits and several Single Sign-On options; integration, architecture and configuration options; and the SAML SSO implementation completed by American Century Investments.&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_April_2008_Meeting&amp;diff=29145</id>
		<title>Kansas City April 2008 Meeting</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_April_2008_Meeting&amp;diff=29145"/>
				<updated>2008-05-09T18:34:05Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: New page: The Kansas_City OWASP chapter met on April 30, 2008 at Centriq Training in Leawood, KS.  === Meeting Summary ===  '''Chapter Business'''  Current chapter priorities include the followi...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The [[Kansas_City]] OWASP chapter met on April 30, 2008 at Centriq Training in Leawood, KS.&lt;br /&gt;
&lt;br /&gt;
=== Meeting Summary ===&lt;br /&gt;
&lt;br /&gt;
'''Chapter Business'''&lt;br /&gt;
&lt;br /&gt;
Current chapter priorities include the following:&lt;br /&gt;
* Volunteer to give an OWASP presentation&lt;br /&gt;
** Talks can anything from a short review of a whitepaper or presentation you've seen, to a web application security tool or product review, to a longer technical talk about attacks or countermeasures&lt;br /&gt;
* Volunteer your organization to host an OWASP meeting&lt;br /&gt;
* Invite other professionals or students to attend our next OWASP meeting&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Speakers: Karen Fritsche &amp;amp; Sarah Heinen on Security Access Mark-up Language (SAML) &amp;amp; Single Sign-on Implementation'''&lt;br /&gt;
&lt;br /&gt;
To accomplish a Web Single Sign-On application with their brokerage back office vendor, American Century Investments solution included the use of SAML.  This presentation will provide an overview of: SAML, its benefits and several Single Sign-On options; integration, architecture and configuration options; and the SAML SSO implementation completed by American Century Investments.&lt;br /&gt;
&lt;br /&gt;
Karen Fritsche is an Application Architect and Sarah Heinen is a Programmer / Analyst with American Century Investments in Kansas City.  As part of the IT application development team that supports the company's retail web sites www.americancentury.com and www.learningquestsavings.com, they focus on the secure on-line financial transactions of the sites, either through internal services or by establishing single sign-on connectivity to third party vendor sites.&lt;br /&gt;
&lt;br /&gt;
=== Documents ===&lt;br /&gt;
&lt;br /&gt;
* Karen &amp;amp; Sarah's presentation slides (waiting for presentation file upload to link)&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=29144</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=29144"/>
				<updated>2008-05-09T18:13:49Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: /* Past Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter after reading this page, please send an email to our chapter leader [[User:bkmarshall|Bruce K. Marshall]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
I am pleased to announce that the details for our next OWASP Kansas City chapter meeting have been finalized.  We will get together on Wednesday, April 30th starting at 6:00 PM and finishing around 7:30 PM.  Add the event to your calendar today so you don't miss this opportunity to learn about web application security and network with your peers.&lt;br /&gt;
 &lt;br /&gt;
Here is the presentation planned for this meeting:&lt;br /&gt;
&lt;br /&gt;
'''Security Access Mark-up Language (SAML) &amp;amp; Single Sign-on Implementation'''&lt;br /&gt;
&lt;br /&gt;
Presented by Karen Fritsche and Sarah Heinen&lt;br /&gt;
&lt;br /&gt;
To accomplish a Web Single Sign-On application with their brokerage back office vendor, American Century Investments solution included the use of SAML.  This presentation will provide an overview of: SAML, its benefits and several Single Sign-On options; integration, architecture and configuration options; and the SAML SSO implementation completed by American Century Investments.&lt;br /&gt;
&lt;br /&gt;
Karen Fritsche is an Application Architect and Sarah Heinen is a Programmer / Analyst with American Century Investments in Kansas City.  As part of the IT application development team that supports the company's retail web sites www.americancentury.com and www.learningquestsavings.com, they focus on the secure on-line financial transactions of the sites, either through internal services or by establishing single sign-on connectivity to third party vendor sites.&lt;br /&gt;
&lt;br /&gt;
*We have time for another person to give a brief 15-45 minute presentation on web application security.  This can be a technical demonstration, conference review, or open discussion about a web application security topic.  Please let me know if you'd like to grab this spot.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Date: April 30, 2008 – 6:00 PM – 7:30 PM&lt;br /&gt;
&lt;br /&gt;
Location:&lt;br /&gt;
&lt;br /&gt;
Centriq Training&lt;br /&gt;
&lt;br /&gt;
8700 State Line Road&lt;br /&gt;
&lt;br /&gt;
Suite 200&lt;br /&gt;
&lt;br /&gt;
Leawood, KS 66206&lt;br /&gt;
&lt;br /&gt;
(913) 322-7000&lt;br /&gt;
&lt;br /&gt;
http://www.centriq.com/contactus.htm&lt;br /&gt;
&lt;br /&gt;
Thanks to Centriq Training for volunteering to host another one of our chapter meeting.&lt;br /&gt;
 &lt;br /&gt;
Attendance of OWASP meetings is free and anyone interested in web application security is welcome to attend.  Pass on this meeting announcement to anyone else that would benefit from joining us.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please note:&lt;br /&gt;
*Attendance at an OWASP chapter meeting is free and open to anyone interested in web application security&lt;br /&gt;
*No registration is required, although RSVPs to the [[User:bkmarshall|chapter leader]] are appreciated&lt;br /&gt;
*Professionals with CISSPs, or other certifications, can earn CPE credits by attending&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to the speakers for sharing with us at our past chapter meetings.  Any presentation handouts or associated documents are shared through the following meeting summaries:&lt;br /&gt;
&lt;br /&gt;
*[[Kansas_City_April_2008_Meeting|April 2008 Meeting]]&lt;br /&gt;
*[[Kansas_City_November_2007_Meeting|November 2007 Meeting]]&lt;br /&gt;
*[[Kansas_City_September_2007_Meeting|September 2007 Meeting]]&lt;br /&gt;
*[[Kansas City June 2007 Meeting|June 2007 meeting]]&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=29143</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=29143"/>
				<updated>2008-05-09T18:13:19Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: /* Past Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter after reading this page, please send an email to our chapter leader [[User:bkmarshall|Bruce K. Marshall]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
I am pleased to announce that the details for our next OWASP Kansas City chapter meeting have been finalized.  We will get together on Wednesday, April 30th starting at 6:00 PM and finishing around 7:30 PM.  Add the event to your calendar today so you don't miss this opportunity to learn about web application security and network with your peers.&lt;br /&gt;
 &lt;br /&gt;
Here is the presentation planned for this meeting:&lt;br /&gt;
&lt;br /&gt;
'''Security Access Mark-up Language (SAML) &amp;amp; Single Sign-on Implementation'''&lt;br /&gt;
&lt;br /&gt;
Presented by Karen Fritsche and Sarah Heinen&lt;br /&gt;
&lt;br /&gt;
To accomplish a Web Single Sign-On application with their brokerage back office vendor, American Century Investments solution included the use of SAML.  This presentation will provide an overview of: SAML, its benefits and several Single Sign-On options; integration, architecture and configuration options; and the SAML SSO implementation completed by American Century Investments.&lt;br /&gt;
&lt;br /&gt;
Karen Fritsche is an Application Architect and Sarah Heinen is a Programmer / Analyst with American Century Investments in Kansas City.  As part of the IT application development team that supports the company's retail web sites www.americancentury.com and www.learningquestsavings.com, they focus on the secure on-line financial transactions of the sites, either through internal services or by establishing single sign-on connectivity to third party vendor sites.&lt;br /&gt;
&lt;br /&gt;
*We have time for another person to give a brief 15-45 minute presentation on web application security.  This can be a technical demonstration, conference review, or open discussion about a web application security topic.  Please let me know if you'd like to grab this spot.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Date: April 30, 2008 – 6:00 PM – 7:30 PM&lt;br /&gt;
&lt;br /&gt;
Location:&lt;br /&gt;
&lt;br /&gt;
Centriq Training&lt;br /&gt;
&lt;br /&gt;
8700 State Line Road&lt;br /&gt;
&lt;br /&gt;
Suite 200&lt;br /&gt;
&lt;br /&gt;
Leawood, KS 66206&lt;br /&gt;
&lt;br /&gt;
(913) 322-7000&lt;br /&gt;
&lt;br /&gt;
http://www.centriq.com/contactus.htm&lt;br /&gt;
&lt;br /&gt;
Thanks to Centriq Training for volunteering to host another one of our chapter meeting.&lt;br /&gt;
 &lt;br /&gt;
Attendance of OWASP meetings is free and anyone interested in web application security is welcome to attend.  Pass on this meeting announcement to anyone else that would benefit from joining us.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please note:&lt;br /&gt;
*Attendance at an OWASP chapter meeting is free and open to anyone interested in web application security&lt;br /&gt;
*No registration is required, although RSVPs to the [[User:bkmarshall|chapter leader]] are appreciated&lt;br /&gt;
*Professionals with CISSPs, or other certifications, can earn CPE credits by attending&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to the speakers for sharing with us at our past chapter meetings.  Any presentation handouts or associated documents are shared through the following meeting summaries:&lt;br /&gt;
&lt;br /&gt;
*[[Kansas_City_April_2008_Meeting|April 2008 Meeting]&lt;br /&gt;
*[[Kansas_City_November_2007_Meeting|November 2007 Meeting]]&lt;br /&gt;
*[[Kansas_City_September_2007_Meeting|September 2007 Meeting]]&lt;br /&gt;
*[[Kansas City June 2007 Meeting|June 2007 meeting]]&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_November_2007_Meeting&amp;diff=28132</id>
		<title>Kansas City November 2007 Meeting</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_November_2007_Meeting&amp;diff=28132"/>
				<updated>2008-04-16T15:47:31Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The [[Kansas_City]] OWASP chapter met on November 7, 2007 at Centriq Training in Leawood, KS.&lt;br /&gt;
&lt;br /&gt;
=== Meeting Summary ===&lt;br /&gt;
&lt;br /&gt;
'''Chapter Business'''&lt;br /&gt;
&lt;br /&gt;
Current chapter priorities include the following:&lt;br /&gt;
* Volunteer to give an OWASP presentation&lt;br /&gt;
** Talks can anything from a short review of a whitepaper or presentation you've seen, to a web application security tool or product review, to a longer technical talk about attacks or countermeasures&lt;br /&gt;
* Volunteer your organization to host an OWASP meeting&lt;br /&gt;
* Invite other professionals or students to attend our next OWASP meeting&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Speaker 1: Tom Stripling, CISSP on The Dangers of Third-Party Content'''&lt;br /&gt;
&lt;br /&gt;
It is now commonplace for web applications to include content from other sites, partners, and advertisers.  If this content isn’t handled correctly, applications are left vulnerable to attack.  By examining a variety of attacks that can be executed through third-party content, we can better evaluate application risk and design countermeasures.&lt;br /&gt;
&lt;br /&gt;
Session Learning Objectives&lt;br /&gt;
* Determine the threat posed by third-party content, given trends in Internet content and specific risks associated with each form of third-party content inclusion&lt;br /&gt;
* Demonstrate attacks against a live web application that exploit flawed security assumptions in the inclusion of third-party content&lt;br /&gt;
* Analyze the effectiveness of various application security countermeasures to combat the threat&lt;br /&gt;
* Enable developers and penetration testers to better identify and prevent the risks associated with the use of third-party content in web applications&lt;br /&gt;
&lt;br /&gt;
Tom Stripling is a senior application security consultant with an extensive background in web application development, penetration testing, and risk assessment. In his role at Security PS, he helps clients uncover application vulnerabilities and secure the software development process. In his spare time, Tom is an avid researcher of application security attacks, vulnerabilities, and best practices.&lt;br /&gt;
&lt;br /&gt;
=== Documents ===&lt;br /&gt;
&lt;br /&gt;
* Tom's [http://www.owasp.org/images/6/6d/OWASP-WASCAppSec2007SanJose_Dangers_of3rdPartyContent.ppt presentation slides]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=28131</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=28131"/>
				<updated>2008-04-16T15:33:55Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: /* Upcoming Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter after reading this page, please send an email to our chapter leader [[User:bkmarshall|Bruce K. Marshall]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
I am pleased to announce that the details for our next OWASP Kansas City chapter meeting have been finalized.  We will get together on Wednesday, April 30th starting at 6:00 PM and finishing around 7:30 PM.  Add the event to your calendar today so you don't miss this opportunity to learn about web application security and network with your peers.&lt;br /&gt;
 &lt;br /&gt;
Here is the presentation planned for this meeting:&lt;br /&gt;
&lt;br /&gt;
'''Security Access Mark-up Language (SAML) &amp;amp; Single Sign-on Implementation'''&lt;br /&gt;
&lt;br /&gt;
Presented by Karen Fritsche and Sarah Heinen&lt;br /&gt;
&lt;br /&gt;
To accomplish a Web Single Sign-On application with their brokerage back office vendor, American Century Investments solution included the use of SAML.  This presentation will provide an overview of: SAML, its benefits and several Single Sign-On options; integration, architecture and configuration options; and the SAML SSO implementation completed by American Century Investments.&lt;br /&gt;
&lt;br /&gt;
Karen Fritsche is an Application Architect and Sarah Heinen is a Programmer / Analyst with American Century Investments in Kansas City.  As part of the IT application development team that supports the company's retail web sites www.americancentury.com and www.learningquestsavings.com, they focus on the secure on-line financial transactions of the sites, either through internal services or by establishing single sign-on connectivity to third party vendor sites.&lt;br /&gt;
&lt;br /&gt;
*We have time for another person to give a brief 15-45 minute presentation on web application security.  This can be a technical demonstration, conference review, or open discussion about a web application security topic.  Please let me know if you'd like to grab this spot.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Date: April 30, 2008 – 6:00 PM – 7:30 PM&lt;br /&gt;
&lt;br /&gt;
Location:&lt;br /&gt;
&lt;br /&gt;
Centriq Training&lt;br /&gt;
&lt;br /&gt;
8700 State Line Road&lt;br /&gt;
&lt;br /&gt;
Suite 200&lt;br /&gt;
&lt;br /&gt;
Leawood, KS 66206&lt;br /&gt;
&lt;br /&gt;
(913) 322-7000&lt;br /&gt;
&lt;br /&gt;
http://www.centriq.com/contactus.htm&lt;br /&gt;
&lt;br /&gt;
Thanks to Centriq Training for volunteering to host another one of our chapter meeting.&lt;br /&gt;
 &lt;br /&gt;
Attendance of OWASP meetings is free and anyone interested in web application security is welcome to attend.  Pass on this meeting announcement to anyone else that would benefit from joining us.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please note:&lt;br /&gt;
*Attendance at an OWASP chapter meeting is free and open to anyone interested in web application security&lt;br /&gt;
*No registration is required, although RSVPs to the [[User:bkmarshall|chapter leader]] are appreciated&lt;br /&gt;
*Professionals with CISSPs, or other certifications, can earn CPE credits by attending&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to the speakers for sharing with us at our past chapter meetings.  Any presentation handouts or associated documents are shared through the following meeting summaries:&lt;br /&gt;
&lt;br /&gt;
*[[Kansas_City_November_2007_Meeting|November 2007 Meeting]]&lt;br /&gt;
*[[Kansas_City_September_2007_Meeting|September 2007 Meeting]]&lt;br /&gt;
*[[Kansas City June 2007 Meeting|June 2007 meeting]]&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=28130</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=28130"/>
				<updated>2008-04-16T15:32:15Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: /* Upcoming Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter after reading this page, please send an email to our chapter leader [[User:bkmarshall|Bruce K. Marshall]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
I am pleased to announce that the details for our next OWASP Kansas City chapter meeting have been finalized.  We will get together on Wednesday, November 7th starting at 6:00 PM and finishing around 7:30 PM.  Add the event to your calendar today so you don't miss this opportunity to learn about web application security and network with your peers.&lt;br /&gt;
 &lt;br /&gt;
Here is the presentation planned for this meeting:&lt;br /&gt;
&lt;br /&gt;
'''Security Access Mark-up Language (SAML) &amp;amp; Single Sign-on Implementation'''&lt;br /&gt;
Presented by Karen Fritsche and Sarah Heinen&lt;br /&gt;
&lt;br /&gt;
To accomplish a Web Single Sign-On application with their brokerage back office vendor, American Century Investments solution included the use of SAML.  This presentation will provide an overview of: SAML, its benefits and several Single Sign-On options; integration, architecture and configuration options; and the SAML SSO implementation completed by American Century Investments.&lt;br /&gt;
&lt;br /&gt;
Karen Fritsche is an Application Architect and Sarah Heinen is a Programmer / Analyst with American Century Investments in Kansas City.  As part of the IT application development team that supports the company's retail web sites www.americancentury.com and www.learningquestsavings.com, they focus on the secure on-line financial transactions of the sites, either through internal services or by establishing single sign-on connectivity to third party vendor sites.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*We have time for another person to give a brief 15-45 minute presentation on web application security.  This can be a technical demonstration, conference review, or open discussion about a web application security topic.  Please let me know if you'd like to grab this spot.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Date: April 30, 2008 – 6:00 PM – 7:30 PM&lt;br /&gt;
&lt;br /&gt;
Location:&lt;br /&gt;
&lt;br /&gt;
Centriq Training&lt;br /&gt;
&lt;br /&gt;
8700 State Line Road&lt;br /&gt;
&lt;br /&gt;
Suite 200&lt;br /&gt;
&lt;br /&gt;
Leawood, KS 66206&lt;br /&gt;
&lt;br /&gt;
(913) 322-7000&lt;br /&gt;
&lt;br /&gt;
http://www.centriq.com/contactus.htm&lt;br /&gt;
&lt;br /&gt;
Thanks to Centriq Training for volunteering to host another one of our chapter meeting.&lt;br /&gt;
 &lt;br /&gt;
Attendance of OWASP meetings is free and anyone interested in web application security is welcome to attend.  Pass on this meeting announcement to anyone else that would benefit from joining us.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please note:&lt;br /&gt;
*Attendance at an OWASP chapter meeting is free and open to anyone interested in web application security&lt;br /&gt;
*No registration is required, although RSVPs to the [[User:bkmarshall|chapter leader]] are appreciated&lt;br /&gt;
*Professionals with CISSPs, or other certifications, can earn CPE credits by attending&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to the speakers for sharing with us at our past chapter meetings.  Any presentation handouts or associated documents are shared through the following meeting summaries:&lt;br /&gt;
&lt;br /&gt;
*[[Kansas_City_November_2007_Meeting|November 2007 Meeting]]&lt;br /&gt;
*[[Kansas_City_September_2007_Meeting|September 2007 Meeting]]&lt;br /&gt;
*[[Kansas City June 2007 Meeting|June 2007 meeting]]&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_November_2007_Meeting&amp;diff=28129</id>
		<title>Kansas City November 2007 Meeting</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_November_2007_Meeting&amp;diff=28129"/>
				<updated>2008-04-16T15:27:31Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The [[Kansas_City]] OWASP chapter met on November 7, 2007 at Centriq Training in Leawood, KS.&lt;br /&gt;
&lt;br /&gt;
=== Meeting Summary ===&lt;br /&gt;
&lt;br /&gt;
'''Chapter Business'''&lt;br /&gt;
&lt;br /&gt;
Current chapter priorities include the following:&lt;br /&gt;
* Volunteer to give an OWASP presentation&lt;br /&gt;
** Talks can anything from a short review of a whitepaper or presentation you've seen, to a web application security tool or product review, to a longer technical talk about attacks or countermeasures&lt;br /&gt;
* Volunteer your organization to host an OWASP meeting&lt;br /&gt;
* Invite other professionals or students to attend our next OWASP meeting&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Speaker 1: Tom Stripling, CISSP on The Dangers of Third-Party Content''''''&lt;br /&gt;
&lt;br /&gt;
It is now commonplace for web applications to include content from other sites, partners, and advertisers.  If this content isn’t handled correctly, applications are left vulnerable to attack.  By examining a variety of attacks that can be executed through third-party content, we can better evaluate application risk and design countermeasures.&lt;br /&gt;
&lt;br /&gt;
Session Learning Objectives&lt;br /&gt;
* Determine the threat posed by third-party content, given trends in Internet content and specific risks associated with each form of third-party content inclusion&lt;br /&gt;
* Demonstrate attacks against a live web application that exploit flawed security assumptions in the inclusion of third-party content&lt;br /&gt;
* Analyze the effectiveness of various application security countermeasures to combat the threat&lt;br /&gt;
* Enable developers and penetration testers to better identify and prevent the risks associated with the use of third-party content in web applications&lt;br /&gt;
&lt;br /&gt;
Tom Stripling is a senior application security consultant with an extensive background in web application development, penetration testing, and risk assessment. In his role at Security PS, he helps clients uncover application vulnerabilities and secure the software development process. In his spare time, Tom is an avid researcher of application security attacks, vulnerabilities, and best practices.&lt;br /&gt;
&lt;br /&gt;
=== Documents ===&lt;br /&gt;
&lt;br /&gt;
* Tom's [http://www.owasp.org/images/6/6d/OWASP-WASCAppSec2007SanJose_Dangers_of3rdPartyContent.ppt presentation slides]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_November_2007_Meeting&amp;diff=28127</id>
		<title>Kansas City November 2007 Meeting</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_November_2007_Meeting&amp;diff=28127"/>
				<updated>2008-04-16T15:02:26Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: New page: Speaker: '''Tom Stripling, CISSP on The Dangers of Third-Party Content'''  It is now commonplace for web applications to include content from other sites, partners, and advertisers.  If th...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Speaker: '''Tom Stripling, CISSP on The Dangers of Third-Party Content'''&lt;br /&gt;
&lt;br /&gt;
It is now commonplace for web applications to include content from other sites, partners, and advertisers.  If this content isn’t handled correctly, applications are left vulnerable to attack.  By examining a variety of attacks that can be executed through third-party content, we can better evaluate application risk and design countermeasures.&lt;br /&gt;
&lt;br /&gt;
Session Learning Objectives&lt;br /&gt;
* Determine the threat posed by third-party content, given trends in Internet content and specific risks associated with each form of third-party content inclusion&lt;br /&gt;
* Demonstrate attacks against a live web application that exploit flawed security assumptions in the inclusion of third-party content&lt;br /&gt;
* Analyze the effectiveness of various application security countermeasures to combat the threat&lt;br /&gt;
* Enable developers and penetration testers to better identify and prevent the risks associated with the use of third-party content in web applications&lt;br /&gt;
&lt;br /&gt;
Tom Stripling is a senior application security consultant with an extensive background in web application development, penetration testing, and risk assessment. In his role at Security PS, he helps clients uncover application vulnerabilities and secure the software development process. In his spare time, Tom is an avid researcher of application security attacks, vulnerabilities, and best practices.&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=28126</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=28126"/>
				<updated>2008-04-16T15:01:52Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: /* Past Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter after reading this page, please send an email to our chapter leader [[User:bkmarshall|Bruce K. Marshall]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
I am pleased to announce that the details for our next OWASP Kansas City chapter meeting have been finalized.  We will get together on Wednesday, November 7th starting at 6:00 PM and finishing around 7:30 PM.  Add the event to your calendar today so you don't miss this opportunity to learn about web application security and network with your peers.&lt;br /&gt;
 &lt;br /&gt;
Here is the presentation planned for this meeting:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*We have time for another person to give a brief 15-45 minute presentation on web application security.  This can be a technical demonstration, conference review, or open discussion about a web application security topic.  Please let me know if you'd like to grab this spot.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Date: November 7, 2007 – 6:00 PM – 7:30 PM&lt;br /&gt;
&lt;br /&gt;
Location:&lt;br /&gt;
&lt;br /&gt;
Centriq Training&lt;br /&gt;
&lt;br /&gt;
8700 State Line Road&lt;br /&gt;
&lt;br /&gt;
Suite 200&lt;br /&gt;
&lt;br /&gt;
Leawood, KS 66206&lt;br /&gt;
&lt;br /&gt;
(913) 322-7000&lt;br /&gt;
&lt;br /&gt;
http://www.centriq.com/contactus.htm&lt;br /&gt;
&lt;br /&gt;
Thanks to Centriq Training for volunteering to host another one of our chapter meeting.&lt;br /&gt;
 &lt;br /&gt;
Attendance of OWASP meetings is free and anyone interested in web application security is welcome to attend.  Pass on this meeting announcement to anyone else that would benefit from joining us.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please note:&lt;br /&gt;
*Attendance at an OWASP chapter meeting is free and open to anyone interested in web application security&lt;br /&gt;
*No registration is required, although RSVPs to the [[User:bkmarshall|chapter leader]] are appreciated&lt;br /&gt;
*Professionals with CISSPs, or other certifications, can earn CPE credits by attending&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to the speakers for sharing with us at our past chapter meetings.  Any presentation handouts or associated documents are shared through the following meeting summaries:&lt;br /&gt;
&lt;br /&gt;
*[[Kansas_City_November_2007_Meeting|November 2007 Meeting]]&lt;br /&gt;
*[[Kansas_City_September_2007_Meeting|September 2007 Meeting]]&lt;br /&gt;
*[[Kansas City June 2007 Meeting|June 2007 meeting]]&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=28125</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=28125"/>
				<updated>2008-04-16T15:00:45Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter after reading this page, please send an email to our chapter leader [[User:bkmarshall|Bruce K. Marshall]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
I am pleased to announce that the details for our next OWASP Kansas City chapter meeting have been finalized.  We will get together on Wednesday, November 7th starting at 6:00 PM and finishing around 7:30 PM.  Add the event to your calendar today so you don't miss this opportunity to learn about web application security and network with your peers.&lt;br /&gt;
 &lt;br /&gt;
Here is the presentation planned for this meeting:&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*We have time for another person to give a brief 15-45 minute presentation on web application security.  This can be a technical demonstration, conference review, or open discussion about a web application security topic.  Please let me know if you'd like to grab this spot.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Date: November 7, 2007 – 6:00 PM – 7:30 PM&lt;br /&gt;
&lt;br /&gt;
Location:&lt;br /&gt;
&lt;br /&gt;
Centriq Training&lt;br /&gt;
&lt;br /&gt;
8700 State Line Road&lt;br /&gt;
&lt;br /&gt;
Suite 200&lt;br /&gt;
&lt;br /&gt;
Leawood, KS 66206&lt;br /&gt;
&lt;br /&gt;
(913) 322-7000&lt;br /&gt;
&lt;br /&gt;
http://www.centriq.com/contactus.htm&lt;br /&gt;
&lt;br /&gt;
Thanks to Centriq Training for volunteering to host another one of our chapter meeting.&lt;br /&gt;
 &lt;br /&gt;
Attendance of OWASP meetings is free and anyone interested in web application security is welcome to attend.  Pass on this meeting announcement to anyone else that would benefit from joining us.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please note:&lt;br /&gt;
*Attendance at an OWASP chapter meeting is free and open to anyone interested in web application security&lt;br /&gt;
*No registration is required, although RSVPs to the [[User:bkmarshall|chapter leader]] are appreciated&lt;br /&gt;
*Professionals with CISSPs, or other certifications, can earn CPE credits by attending&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to the speakers for sharing with us at our past chapter meetings.  Any presentation handouts or associated documents are shared through the following meeting summaries:&lt;br /&gt;
&lt;br /&gt;
*[[Kansas_City_September_2007_Meeting|September 2007 Meeting]]&lt;br /&gt;
*[[Kansas City June 2007 Meeting|June 2007 meeting]]&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=22548</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=22548"/>
				<updated>2007-10-22T16:53:32Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter after reading this page, please send an email to our chapter leader [[User:bkmarshall|Bruce K. Marshall]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
I am pleased to announce that the details for our next OWASP Kansas City chapter meeting have been finalized.  We will get together on Wednesday, November 7th starting at 6:00 PM and finishing around 7:30 PM.  Add the event to your calendar today so you don't miss this opportunity to learn about web application security and network with your peers.&lt;br /&gt;
 &lt;br /&gt;
Here is the presentation planned for this meeting:&lt;br /&gt;
&lt;br /&gt;
Speaker: '''Tom Stripling, CISSP on The Dangers of Third-Party Content'''&lt;br /&gt;
&lt;br /&gt;
It is now commonplace for web applications to include content from other sites, partners, and advertisers.  If this content isn’t handled correctly, applications are left vulnerable to attack.  By examining a variety of attacks that can be executed through third-party content, we can better evaluate application risk and design countermeasures.&lt;br /&gt;
&lt;br /&gt;
Session Learning Objectives&lt;br /&gt;
* Determine the threat posed by third-party content, given trends in Internet content and specific risks associated with each form of third-party content inclusion&lt;br /&gt;
* Demonstrate attacks against a live web application that exploit flawed security assumptions in the inclusion of third-party content&lt;br /&gt;
* Analyze the effectiveness of various application security countermeasures to combat the threat&lt;br /&gt;
* Enable developers and penetration testers to better identify and prevent the risks associated with the use of third-party content in web applications&lt;br /&gt;
&lt;br /&gt;
Tom Stripling is a senior application security consultant with an extensive background in web application development, penetration testing, and risk assessment. In his role at Security PS, he helps clients uncover application vulnerabilities and secure the software development process. In his spare time, Tom is an avid researcher of application security attacks, vulnerabilities, and best practices.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*We have time for another person to give a brief 15-45 minute presentation on web application security.  This can be a technical demonstration, conference review, or open discussion about a web application security topic.  Please let me know if you'd like to grab this spot.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Date: November 7, 2007 – 6:00 PM – 7:30 PM&lt;br /&gt;
&lt;br /&gt;
Location:&lt;br /&gt;
&lt;br /&gt;
Centriq Training&lt;br /&gt;
&lt;br /&gt;
8700 State Line Road&lt;br /&gt;
&lt;br /&gt;
Suite 200&lt;br /&gt;
&lt;br /&gt;
Leawood, KS 66206&lt;br /&gt;
&lt;br /&gt;
(913) 322-7000&lt;br /&gt;
&lt;br /&gt;
http://www.centriq.com/contactus.htm&lt;br /&gt;
&lt;br /&gt;
Thanks to Centriq Training for volunteering to host another one of our chapter meeting.&lt;br /&gt;
 &lt;br /&gt;
Attendance of OWASP meetings is free and anyone interested in web application security is welcome to attend.  Pass on this meeting announcement to anyone else that would benefit from joining us.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please note:&lt;br /&gt;
*Attendance at an OWASP chapter meeting is free and open to anyone interested in web application security&lt;br /&gt;
*No registration is required, although RSVPs to the [[User:bkmarshall|chapter leader]] are appreciated&lt;br /&gt;
*Professionals with CISSPs, or other certifications, can earn CPE credits by attending&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to the speakers for sharing with us at our past chapter meetings.  Any presentation handouts or associated documents are shared through the following meeting summaries:&lt;br /&gt;
&lt;br /&gt;
*[[Kansas_City_September_2007_Meeting|September 2007 Meeting]]&lt;br /&gt;
*[[Kansas City June 2007 Meeting|June 2007 meeting]]&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21846</id>
		<title>Kansas City September 2007 Meeting</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21846"/>
				<updated>2007-09-18T15:35:00Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The [[Kansas_City]] OWASP chapter met on September 6, 2007 at Centriq Training in Leawood, KS.&lt;br /&gt;
&lt;br /&gt;
=== Meeting Summary ===&lt;br /&gt;
&lt;br /&gt;
'''Chapter Business'''&lt;br /&gt;
&lt;br /&gt;
Current chapter priorities include the following:&lt;br /&gt;
* Volunteer to give an OWASP presentation&lt;br /&gt;
** Talks can anything from a short review of a whitepaper or presentation you've seen, to a web application security tool or product review, to a longer technical talk about attacks or countermeasures&lt;br /&gt;
* Volunteer your organization to host an OWASP meeting&lt;br /&gt;
* Invite other professionals or students to attend our next OWASP meeting&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Speaker 1: Bob Phelps, National Bank Examiner with the Office of the Comptroller of the Currency (OCC)'''&lt;br /&gt;
&lt;br /&gt;
Bob provided his insights on the financial regulatory environment and how laws lead to specific information security standards and guidance.  Through his job he has performed a review of application security practices in about a dozen midsize and large banks.  Bob shared the results of this review and provided his recommendations on how to establish a sound application security management program.&lt;br /&gt;
&lt;br /&gt;
At the OCC Bob both works with the Policy division in Washington DC and has bank supervisory responsibilities.  He leads and participates in examinations of National Banks in NYC, KC, Omaha, and Minneapolis.  His Policy responsibilities include evaluating emerging technologies and their impact on the banking system, evaluating trends in information security, and developing and delivering various training programs to other examiners.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Speaker 2: Bruce K. Marshall, Senior Security Consultant with Security PS'''&lt;br /&gt;
&lt;br /&gt;
Bruce spoke about how to avoid improperly using challenge questions (e.g. “What is your pet’s name?”) for web app authentication.  While challenge questions tend to be user friendly they can also expose your application to new security threats.  He shared his experience on both choosing the best challenge questions and how to properly integrate them into your application.&lt;br /&gt;
&lt;br /&gt;
Bruce consults with clients like American Express, Garmin, Microsoft, and Commerce Bank to assess and improve their information security strategies in areas like network security, web app security, authentication, and program management.&lt;br /&gt;
&lt;br /&gt;
=== Documents ===&lt;br /&gt;
&lt;br /&gt;
* Bruce's [http://www.passwordresearch.com/files/AvoidingPoorChallengeQuestionAuthentication-OWASP.pdf presentation slides]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21737</id>
		<title>Kansas City September 2007 Meeting</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21737"/>
				<updated>2007-09-14T17:29:21Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The [[Kansas_City]] OWASP chapter met on September 6, 2007 at Centriq Training in Leawood, KS.&lt;br /&gt;
&lt;br /&gt;
=== Meeting Summary ===&lt;br /&gt;
&lt;br /&gt;
'''Chapter Business'''&lt;br /&gt;
&lt;br /&gt;
Current chapter priorities include the following:&lt;br /&gt;
* Volunteer to give an OWASP presentation&lt;br /&gt;
** Talks can anything from a short review of a whitepaper or presentation you've seen, to a web application security tool or product review, to a longer technical talk about attacks or countermeasures&lt;br /&gt;
* Volunteer your organization to host an OWASP meeting&lt;br /&gt;
* Invite other professionals or students to attend our next OWASP meeting&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Speaker 1: Bob Phelps, National Bank Examiner with the Office of the Comptroller of the Currency (OCC)'''&lt;br /&gt;
&lt;br /&gt;
Bob will provide his insight on the financial regulatory environment and how laws lead to specific information security standards and guidance.  Through his job he has performed a review of application security practices in about a dozen midsize and large banks.  Bob will share the results of this review and provide his recommendations on how to establish a sound application security management program.&lt;br /&gt;
&lt;br /&gt;
At the OCC Bob both works with the Policy division in Washington DC and has bank supervisory responsibilities.  He leads and participates in examinations of National Banks in NYC, KC, Omaha, and Minneapolis.  His Policy responsibilities include evaluating emerging technologies and their impact on the banking system, evaluating trends in information security, and developing and delivering various training programs to other examiners.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Speaker 2: Bruce K. Marshall, Senior Security Consultant with Security PS'''&lt;br /&gt;
&lt;br /&gt;
Bruce will be speaking about how to avoid improperly using challenge questions (e.g. “What is your pet’s name?”) for web app authentication. While challenge questions tend to be user friendly they can also expose your application to new security threats.  He will share his experience on both choosing the best challenge questions and how to properly integrate them into your application.&lt;br /&gt;
&lt;br /&gt;
Bruce consults with clients like American Express, Garmin, Microsoft, and Commerce Bank to assess and improve their information security strategies in areas like network security, web app security, authentication, and program management.&lt;br /&gt;
&lt;br /&gt;
=== Documents ===&lt;br /&gt;
&lt;br /&gt;
* Bruce's [http://www.passwordresearch.com/files/AvoidingPoorChallengeQuestionAuthentication-OWASP.pdf presentation slides]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21736</id>
		<title>Kansas City September 2007 Meeting</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21736"/>
				<updated>2007-09-14T17:28:52Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The [[Kansas_City]] OWASP chapter met on September 6, 2007 at Centriq Training in Leawood, KS.&lt;br /&gt;
&lt;br /&gt;
=== Meeting Summary ===&lt;br /&gt;
&lt;br /&gt;
'''Chapter Business'''&lt;br /&gt;
&lt;br /&gt;
Current chapter priorities include the following:&lt;br /&gt;
* Volunteer to give an OWASP presentation&lt;br /&gt;
** Talks can anything from a short review of a whitepaper or presentation you've seen, to a web application security tool or product review, to a longer technical talk about attacks or countermeasures&lt;br /&gt;
* Volunteer your organization to host an OWASP meeting&lt;br /&gt;
* Invite other professionals or students to attend our next OWASP meeting&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Speaker 1: Bob Phelps, National Bank Examiner with the Office of the Comptroller of the Currency (OCC)'''&lt;br /&gt;
&lt;br /&gt;
Bob will provide his insight on the financial regulatory environment and how laws lead to specific information security standards and guidance.  Through his job he has performed a review of application security practices in about a dozen midsize and large banks.  Bob will share the results of this review and provide his recommendations on how to establish a sound application security management program.&lt;br /&gt;
&lt;br /&gt;
At the OCC Bob both works with the Policy division in Washington DC and has bank supervisory responsibilities.  He leads and participates in examinations of National Banks in NYC, KC, Omaha, and Minneapolis.  His Policy responsibilities include evaluating emerging technologies and their impact on the banking system, evaluating trends in information security, and developing and delivering various training programs to other examiners.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Speaker 2: Bruce K. Marshall, Senior Security Consultant with Security PS'''&lt;br /&gt;
&lt;br /&gt;
Bruce will be speaking about how to avoid improperly using challenge questions (e.g. “What is your pet’s name?”) for web app authentication. While challenge questions tend to be user friendly they can also expose your application to new security threats.  He will share his experience on both choosing the best challenge questions and how to properly integrate them into your application.&lt;br /&gt;
&lt;br /&gt;
Bruce consults with clients like American Express, Garmin, Microsoft, and Commerce Bank to assess and improve their information security strategies in areas like network security, web app security, authentication, and program management.&lt;br /&gt;
&lt;br /&gt;
=== Documents ===&lt;br /&gt;
&lt;br /&gt;
Bruce's [http://www.passwordresearch.com/files/AvoidingPoorChallengeQuestionAuthentication-OWASP.pdf presentation slides]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=21703</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=21703"/>
				<updated>2007-09-12T19:20:11Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: Updated page following September meeting&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter after reading this page, please send an email to our chapter leader [[User:bkmarshall|Bruce K. Marshall]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
We had a great September 6th meeting.  You can find a summary of the event [[Kansas_City_September_2007_Meeting|here]].&lt;br /&gt;
&lt;br /&gt;
The next Kansas City chapter meeting will take place in November.  We are still seeking speakers for this event, so please contact chapter leader [[User:bkmarshall|Bruce K. Marshall]] if you would like to volunteer.&lt;br /&gt;
&lt;br /&gt;
Details on the November meeting will be posted both here and on the Kansas City chapter [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
PLEASE NOTE&lt;br /&gt;
*Attendance at an OWASP chapter meeting is free and open to anyone interested in web application security&lt;br /&gt;
*No registration is required, although RSVPs to the [[User:bkmarshall|chapter leader]] are appreciated&lt;br /&gt;
*Professionals with CISSPs, or other certifications, can earn CPE credits by attending&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to the speakers for sharing with us at our past chapter meetings.  Any presentation handouts or associated documents are shared through the following meeting summaries:&lt;br /&gt;
&lt;br /&gt;
*[[Kansas_City_September_2007_Meeting|September 2007 Meeting]]&lt;br /&gt;
*[[Kansas City June 2007 Meeting|June 2007 meeting]]&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=21702</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=21702"/>
				<updated>2007-09-12T19:12:12Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: /* Past Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter after reading this page, please send an email to our chapter leader [[User:bkmarshall|Bruce Marshall]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
The next Kansas City chapter meeting will take place on September 6, 2007 from 6:00 PM to 8:30 PM CDT.  Add the event to your calendar today so you don't miss this opportunity to learn about web application security and network with your peers.&lt;br /&gt;
&lt;br /&gt;
=== September 6 Meeting ===&lt;br /&gt;
&lt;br /&gt;
'''Speaker 1: Bob Phelps, National Bank Examiner with the Office of the Comptroller of the Currency (OCC)'''&lt;br /&gt;
&lt;br /&gt;
Bob will provide his insight on the financial regulatory environment and how laws lead to specific information security standards and guidance.  Through his job he has performed a review of application security practices in about a dozen midsize and large banks.  Bob will share the results of this review and provide his recommendations on how to establish a sound application security management program.&lt;br /&gt;
&lt;br /&gt;
At the OCC Bob both works with the Policy division in Washington DC and has bank supervisory responsibilities.  He leads and participates in examinations of National Banks in NYC, KC, Omaha, and Minneapolis.  His Policy responsibilities include evaluating emerging technologies and their impact on the banking system, evaluating trends in information security, and developing and delivering various training programs to other examiners.&lt;br /&gt;
&lt;br /&gt;
'''Speaker 2: Bruce K. Marshall, Senior Security Consultant with Security PS'''&lt;br /&gt;
&lt;br /&gt;
Bruce will be speaking about how to avoid improperly using challenge questions (e.g. “What is your pet’s name?”) for web app authentication. While challenge questions tend to be user friendly they can also expose your application to new security threats.  He will share his experience on both choosing the best challenge questions and how to properly integrate them into your application.&lt;br /&gt;
&lt;br /&gt;
Bruce consults with clients like American Express, Garmin, Microsoft, and Commerce Bank to assess and improve their information security strategies in areas like network security, web app security, authentication, and program management.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&lt;br /&gt;
Centriq Training &lt;br /&gt;
8700 State Line Road&lt;br /&gt;
Suite 200&lt;br /&gt;
Leawood, KS 66206&lt;br /&gt;
(913) 322-7000 [http://www.centriq.com/contactus.htm]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
PLEASE NOTE&lt;br /&gt;
*Attendance at an OWASP chapter meeting is free and open to anyone interested in web application security&lt;br /&gt;
*No registration is required, although RSVPs to the [[User:bkmarshall|chapter leader]] are appreciated&lt;br /&gt;
*Professionals with CISSPs, or other certifications, can earn CPE credits by attending&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to the speakers and attendees at our past chapter meetings:&lt;br /&gt;
&lt;br /&gt;
*[[Kansas_City_September_2007_Meeting|September 2007 Meeting]]&lt;br /&gt;
*[[Kansas City June 2007 Meeting|June 2007 meeting]]&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21701</id>
		<title>Kansas City September 2007 Meeting</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21701"/>
				<updated>2007-09-12T19:10:13Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The [[Kansas_City]] OWASP chapter met on September 6, 2007 at Centriq Training in Leawood, KS.&lt;br /&gt;
&lt;br /&gt;
=== Meeting Summary ===&lt;br /&gt;
&lt;br /&gt;
'''Chapter Business'''&lt;br /&gt;
&lt;br /&gt;
Current chapter priorities include the following:&lt;br /&gt;
* Volunteer to give an OWASP presentation&lt;br /&gt;
** Talks can anything from a short review of a whitepaper or presentation you've seen, to a web application security tool or product review, to a longer technical talk about attacks or countermeasures&lt;br /&gt;
* Volunteer your organization to host an OWASP meeting&lt;br /&gt;
* Invite other professionals or students to attend our next OWASP meeting&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Speaker 1: Bob Phelps, National Bank Examiner with the Office of the Comptroller of the Currency (OCC)'''&lt;br /&gt;
&lt;br /&gt;
Bob will provide his insight on the financial regulatory environment and how laws lead to specific information security standards and guidance.  Through his job he has performed a review of application security practices in about a dozen midsize and large banks.  Bob will share the results of this review and provide his recommendations on how to establish a sound application security management program.&lt;br /&gt;
&lt;br /&gt;
At the OCC Bob both works with the Policy division in Washington DC and has bank supervisory responsibilities.  He leads and participates in examinations of National Banks in NYC, KC, Omaha, and Minneapolis.  His Policy responsibilities include evaluating emerging technologies and their impact on the banking system, evaluating trends in information security, and developing and delivering various training programs to other examiners.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Speaker 2: Bruce K. Marshall, Senior Security Consultant with Security PS'''&lt;br /&gt;
&lt;br /&gt;
Bruce will be speaking about how to avoid improperly using challenge questions (e.g. “What is your pet’s name?”) for web app authentication. While challenge questions tend to be user friendly they can also expose your application to new security threats.  He will share his experience on both choosing the best challenge questions and how to properly integrate them into your application.&lt;br /&gt;
&lt;br /&gt;
Bruce consults with clients like American Express, Garmin, Microsoft, and Commerce Bank to assess and improve their information security strategies in areas like network security, web app security, authentication, and program management.&lt;br /&gt;
&lt;br /&gt;
=== Documents ===&lt;br /&gt;
&lt;br /&gt;
Links to the presentations will be posted as soon as possible.&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21700</id>
		<title>Kansas City September 2007 Meeting</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21700"/>
				<updated>2007-09-12T19:09:42Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The [[Kansas_City]] OWASP chapter met on September 6, 2007 at Centriq Training in Leawood, KS.&lt;br /&gt;
&lt;br /&gt;
=== Meeting Summary ===&lt;br /&gt;
&lt;br /&gt;
'''Chapter Business'''&lt;br /&gt;
Current chapter priorities include the following:&lt;br /&gt;
* Volunteer to give an OWASP presentation&lt;br /&gt;
** Talks can anything from a short review of a whitepaper or presentation you've seen, to a web application security tool or product review, to a longer technical talk about attacks or countermeasures&lt;br /&gt;
* Volunteer your organization to host an OWASP meeting&lt;br /&gt;
* Invite other professionals or students to attend our next OWASP meeting&lt;br /&gt;
&lt;br /&gt;
'''Speaker 1: Bob Phelps, National Bank Examiner with the Office of the Comptroller of the Currency (OCC)'''&lt;br /&gt;
&lt;br /&gt;
Bob will provide his insight on the financial regulatory environment and how laws lead to specific information security standards and guidance.  Through his job he has performed a review of application security practices in about a dozen midsize and large banks.  Bob will share the results of this review and provide his recommendations on how to establish a sound application security management program.&lt;br /&gt;
&lt;br /&gt;
At the OCC Bob both works with the Policy division in Washington DC and has bank supervisory responsibilities.  He leads and participates in examinations of National Banks in NYC, KC, Omaha, and Minneapolis.  His Policy responsibilities include evaluating emerging technologies and their impact on the banking system, evaluating trends in information security, and developing and delivering various training programs to other examiners.&lt;br /&gt;
&lt;br /&gt;
'''Speaker 2: Bruce K. Marshall, Senior Security Consultant with Security PS'''&lt;br /&gt;
&lt;br /&gt;
Bruce will be speaking about how to avoid improperly using challenge questions (e.g. “What is your pet’s name?”) for web app authentication. While challenge questions tend to be user friendly they can also expose your application to new security threats.  He will share his experience on both choosing the best challenge questions and how to properly integrate them into your application.&lt;br /&gt;
&lt;br /&gt;
Bruce consults with clients like American Express, Garmin, Microsoft, and Commerce Bank to assess and improve their information security strategies in areas like network security, web app security, authentication, and program management.&lt;br /&gt;
&lt;br /&gt;
=== Documents ===&lt;br /&gt;
&lt;br /&gt;
Links to the presentations will be posted as soon as possible.&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21699</id>
		<title>Kansas City September 2007 Meeting</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21699"/>
				<updated>2007-09-12T18:44:09Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
The [[Kansas_City]] OWASP chapter met on September 6, 2007 at Centriq Training in Leawood, KS.&lt;br /&gt;
&lt;br /&gt;
=== Meeting Summary ===&lt;br /&gt;
&lt;br /&gt;
'''Speaker 1: Bob Phelps, National Bank Examiner with the Office of the Comptroller of the Currency (OCC)'''&lt;br /&gt;
&lt;br /&gt;
Bob will provide his insight on the financial regulatory environment and how laws lead to specific information security standards and guidance.  Through his job he has performed a review of application security practices in about a dozen midsize and large banks.  Bob will share the results of this review and provide his recommendations on how to establish a sound application security management program.&lt;br /&gt;
&lt;br /&gt;
At the OCC Bob both works with the Policy division in Washington DC and has bank supervisory responsibilities.  He leads and participates in examinations of National Banks in NYC, KC, Omaha, and Minneapolis.  His Policy responsibilities include evaluating emerging technologies and their impact on the banking system, evaluating trends in information security, and developing and delivering various training programs to other examiners.&lt;br /&gt;
&lt;br /&gt;
'''Speaker 2: Bruce K. Marshall, Senior Security Consultant with Security PS'''&lt;br /&gt;
&lt;br /&gt;
Bruce will be speaking about how to avoid improperly using challenge questions (e.g. “What is your pet’s name?”) for web app authentication. While challenge questions tend to be user friendly they can also expose your application to new security threats.  He will share his experience on both choosing the best challenge questions and how to properly integrate them into your application.&lt;br /&gt;
&lt;br /&gt;
Bruce consults with clients like American Express, Garmin, Microsoft, and Commerce Bank to assess and improve their information security strategies in areas like network security, web app security, authentication, and program management.&lt;br /&gt;
&lt;br /&gt;
=== Documents ===&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21698</id>
		<title>Kansas City September 2007 Meeting</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21698"/>
				<updated>2007-09-12T18:41:51Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Meeting Summary ===&lt;br /&gt;
&lt;br /&gt;
We had speakers&lt;br /&gt;
&lt;br /&gt;
=== Documents ===&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21697</id>
		<title>Kansas City September 2007 Meeting</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City_September_2007_Meeting&amp;diff=21697"/>
				<updated>2007-09-12T18:39:16Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: New page:  == Kansas City OWASP Chapter - September 2007 Meeting ==  We had speakers  Here are their presentations&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
== Kansas City OWASP Chapter - September 2007 Meeting ==&lt;br /&gt;
&lt;br /&gt;
We had speakers&lt;br /&gt;
&lt;br /&gt;
Here are their presentations&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=21466</id>
		<title>OWASP Community</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Community&amp;diff=21466"/>
				<updated>2007-09-05T18:12:54Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: /* Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page is for people to post OWASP related events, such as chapter meetings, OWASP conferences, get-togethers, and OWASP sponsored events.&lt;br /&gt;
&lt;br /&gt;
Events from previous years are archived here:&lt;br /&gt;
* '''[[OWASP Community 2006]]'''&lt;br /&gt;
&lt;br /&gt;
This page is monitored, and items posted here will be copied to the OWASP [[Main Page]].  Please post new items in chronological order using the following format:&lt;br /&gt;
&lt;br /&gt;
 '''Mon ## (##:00h) - [[Article]]'''&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--&lt;br /&gt;
&lt;br /&gt;
CHAPTER LEADS -- please put your schedule here and we'll post a month in advance&lt;br /&gt;
&lt;br /&gt;
*** Belgium ***&lt;br /&gt;
'''Nov 20 (18:00h) - [[Belgium|Belgium Chapter Meeting]] '''&lt;br /&gt;
&lt;br /&gt;
*** OTTAWA: Rough dates ***&lt;br /&gt;
'''Sept 12 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
'''Nov 14 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
&lt;br /&gt;
*** BOSTON: Every first Wednesday of the month ***&lt;br /&gt;
&lt;br /&gt;
*** MELBOURNE: First Tuesday of the month ***&lt;br /&gt;
'''Jul 3 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** NETHERLANDS: Second Thursday of the month sometimes ***&lt;br /&gt;
'''Sept 13 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
'''Dec 13 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
*** ROCHESTER: Every third Monday of the month ***&lt;br /&gt;
&lt;br /&gt;
*** TORONTO: Every second Wednesday of the month&lt;br /&gt;
&lt;br /&gt;
*** VIRGINIA: Every second thursday of the month ***&lt;br /&gt;
&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Events==&lt;br /&gt;
'''Sept 27 (1800h) - [[New York|NY/NJ Metro chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sept 27 (13:00h) - [[Taiwan|Taiwan chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sept 13 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sept 7 (15:00h) [[Germany|German chapter meeting]]''' - Restart of the German Chapter&lt;br /&gt;
&lt;br /&gt;
'''Sept (12:00h) - [[Belgium|Belgium OWASP Day Event]] '''&lt;br /&gt;
&lt;br /&gt;
'''Sept 6 (18:00h) - [[Kansas_City|Kansas City Chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sept 5 (18:00h) - [[Chicago|Chicago Chapter Meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Sept 5 (17:00h) - [[Israel|Israeli chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''July 25 (18:00h) - [[San Jose|San Jose Chapter Meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''July 24 (17:00h) - [[Switzerland|Switzerland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''July 14 (11:00h) - [[Turkey|Turkey chapter meeting - 1st Web Security Days]]'''&lt;br /&gt;
&lt;br /&gt;
'''July 6 (17:00h) - [[Spain|Spain chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 26 (11:30hr) - [[Austin|Austin chapter meeting]]''' - Running Web Application Scans&lt;br /&gt;
&lt;br /&gt;
'''June 22 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 21 (19:00h) - [[Denver]]''' - Anti-DNS Pinning Attacks / Calculating Return on Security Investment (ROSI)&lt;br /&gt;
&lt;br /&gt;
'''June 19 (18:00h) - [[Minneapolis St Paul|Minneapolis St Paul chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 15 (17:00hr) - [[Spain|Spain chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 13 (18:30hr) - [[Kansas City|Kansas City chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 12 (18:00hr) - [[New York|NY/NJ Metro chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 5 (19:00h) - [[Helsinki|Helsinki chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 5 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jun 5 (17:30h) - [[Houston | Houston Chapter Meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 29 (9:00h) - [[http://www.owasp.org/index.php/Italy#May_29th.2C_2007_-_Seminar:_.22Software_Security.22 Italy@Firenze Tecnologia]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 29 (11:30h) - [[Austin | Austin Chapter Meeting]]''' - Bullet Proof UI - A programmer's guide to the complete idiot&amp;quot;. &lt;br /&gt;
&lt;br /&gt;
'''May 29 (18:00h) - [[Ottawa | Ottawa Chapter Meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 22 (18:30h) - [[New Zealand|1st New Zealand chapter Meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 21 (14:00h) - [[Israel|2nd OWASP Israel mini conference]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 15 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 10 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 9 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 8 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 6 (11:00h) - [[Turkey|Turkey chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 2 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 1 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 26 (11:00h) - [[San Antonio|San Antonio chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 26 (17:00h) - [[Switzerland|Switzerland chapter meeting and &amp;quot;Swiss Security Dinner&amp;quot;]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 24 (18:00h) - [[Minneapolis St Paul|Minneapolis St Paul chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 20 (19:00h) - [[Hong Kong|Hong Kong chapter meeting - Objectives for 2007]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 19 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 18 (17:00h) - [[San Francisco City Chapter Meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 17 (18:00h) - [[New Jersey|NY/NJ Metro chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 17 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 12 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 12 (18:00h) - [[San Jose|San Jose chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 11 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 4 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Apr 3 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 30 - [[http://www.owasp.org/index.php/Italy#March_30th.2C_2007_-_Master_in_Security_-_University_of_Rome_.22La_Sapienza.22| Italy@Master in Security at &amp;quot;La Sapienza&amp;quot;]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 28 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 28 (11:30h) - [[San Antonio|San Antonio chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
; '''Mar 27-30 - [http://www.blackhat.com Black Hat Euro]'''&lt;br /&gt;
: OWASP members receive a Euro 100 Briefings discount by inserting BH7EUASSOC in the box marked “Coupon Codes”&lt;br /&gt;
&lt;br /&gt;
'''Mar 22 (18:00h) - [[London|London chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 21-22 - [[Belgium#OWASP_Top_10_2007_Update_.28Infosecurity_Belgium.2C_21_.26_.2622_Mar_2007.29|Belgium@InfoSecurity]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 20 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 14 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 14 (18:00h) - [[Chicago|Chicago chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 13 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 8 (18:00h) - [[Ottawa|Ottawa Chapter Meeting]] '''&lt;br /&gt;
&lt;br /&gt;
'''Mar 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 7 (18:30h) - [[Kansas City|Kansas City chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 6 (18:30h) - [[Philadelphia|Philadelphia chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 6 (18:30h) - [[San Francisco|San Francisco and San Jose chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 6 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 5 (11:00h) - [[New Jersey|New Jersey chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Mar 1 (11:30h) - [http://www.eusecwest.com/agenda.html EUSecWest 07: Testing Guide]'''&lt;br /&gt;
&lt;br /&gt;
; '''Feb 26-Mar 1 - [http://www.blackhat.com Black Hat DC]'''&lt;br /&gt;
: OWASP members receive a $100 Briefings discount by inserting BH7DCASSOC in the box marked “Coupon Codes”&lt;br /&gt;
&lt;br /&gt;
'''Feb 28 (18:00h) - [[Seattle|Seattle chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 27 (18:00h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 22 (18:30h) - [[Helsinki|Helsinki chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 22 (18:00h) - [[London|London chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 21 (18:30h) - [[Denver|Denver chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 19 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 15 (18:00h) - [[Washington DC|Washington DC (MD) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 15 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 14 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 13 (18:00h) - [[Ireland|Ireland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 12 (18:30h) - [[Switzerland|Switzerland chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 7 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 6-7 - [[Italy#February_6th-8th.2C_2007_-_InfoSecurity|Italy@InfoSecurity]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 6 (18:00h) - [[Melbourne|Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Feb 2 (14:00h) - [[Chennai|Chennai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 31 (15:00h) - [[Mumbai|Mumbai chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 30 (11:30h) - [[Austin|Austin chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 25 (18:00h) - [[San Francisco| San Francisco chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 25 (14:30h) - [[Italy#October_25th.2C_2007_-_Isaca_Rome|Italy@ISACA Rome]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 24 (17:30h) - [[Israel#6th_OWASP_IL_meeting:_Wednesday.2C_January_24th_2007|6th OWASP Israel chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 23 (18:00h) - [[Belgium|Belgium chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 22 (18:00h) - [[Rochester|Rochester chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 17 (18:30h) - [[Denver|Denver chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 16 (17:45h) - [[Edmonton|Edmonton chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:00h) - [[Netherlands|Netherlands chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:30h) - [[Phoenix|Phoenix chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 11 (18:00h) - [[Virginia (Northern Virginia)|Washington DC (N. VA) chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 10 (18:00h) - [[Toronto|Toronto chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 8 (18:00h) - [[Seattle|Seattle chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''Jan 3 (18:30h) - [[Boston|Boston chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 1 - [[Melbourne | Melbourne chapter meeting]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 2 - [[Boston]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 6 - [[Turkey]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 8 - [[Virginia (Northern Virginia)|Washington DC (VA)]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 9 - [[Toronto]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 10 - [[Belgium]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 15 - [[Rochester]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 21 - [[Israel]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 22 - [[New Zealand]]'''&lt;br /&gt;
&lt;br /&gt;
'''May 29 - [[Italy]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 5 - [[Houston]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 5 - [[Melbourne]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 5 - [[Helsinki]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 12 - [[New Jersey]]'''&lt;br /&gt;
&lt;br /&gt;
'''June 15 - [[Spain]]'''&lt;br /&gt;
&lt;br /&gt;
'''July 14 - [[Turkey]]'''&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=21002</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=21002"/>
				<updated>2007-08-22T17:05:46Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter after reading this page, please send an email to our chapter leader [[User:bkmarshall|Bruce Marshall]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
The next Kansas City chapter meeting will take place on September 6, 2007 from 6:00 PM to 8:30 PM CDT.  Add the event to your calendar today so you don't miss this opportunity to learn about web application security and network with your peers.&lt;br /&gt;
&lt;br /&gt;
=== September 6 Meeting ===&lt;br /&gt;
&lt;br /&gt;
'''Speaker 1: Bob Phelps, National Bank Examiner with the Office of the Comptroller of the Currency (OCC)'''&lt;br /&gt;
&lt;br /&gt;
Bob will provide his insight on the financial regulatory environment and how laws lead to specific information security standards and guidance.  Through his job he has performed a review of application security practices in about a dozen midsize and large banks.  Bob will share the results of this review and provide his recommendations on how to establish a sound application security management program.&lt;br /&gt;
&lt;br /&gt;
At the OCC Bob both works with the Policy division in Washington DC and has bank supervisory responsibilities.  He leads and participates in examinations of National Banks in NYC, KC, Omaha, and Minneapolis.  His Policy responsibilities include evaluating emerging technologies and their impact on the banking system, evaluating trends in information security, and developing and delivering various training programs to other examiners.&lt;br /&gt;
&lt;br /&gt;
'''Speaker 2: Bruce K. Marshall, Senior Security Consultant with Security PS'''&lt;br /&gt;
&lt;br /&gt;
Bruce will be speaking about how to avoid improperly using challenge questions (e.g. “What is your pet’s name?”) for web app authentication. While challenge questions tend to be user friendly they can also expose your application to new security threats.  He will share his experience on both choosing the best challenge questions and how to properly integrate them into your application.&lt;br /&gt;
&lt;br /&gt;
Bruce consults with clients like American Express, Garmin, Microsoft, and Commerce Bank to assess and improve their information security strategies in areas like network security, web app security, authentication, and program management.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&lt;br /&gt;
Centriq Training &lt;br /&gt;
8700 State Line Road&lt;br /&gt;
Suite 200&lt;br /&gt;
Leawood, KS 66206&lt;br /&gt;
(913) 322-7000 [http://www.centriq.com/contactus.htm]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
PLEASE NOTE&lt;br /&gt;
*Attendance at an OWASP chapter meeting is free and open to anyone interested in web application security&lt;br /&gt;
*No registration is required, although RSVPs to the [[User:bkmarshall|chapter leader]] are appreciated&lt;br /&gt;
*Professionals with CISSPs, or other certifications, can earn CPE credits by attending&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to the speakers and attendees at our past meetings:&lt;br /&gt;
&lt;br /&gt;
*[[Kansas City June 2007 Meeting|June 2007 meeting]]&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=21001</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=21001"/>
				<updated>2007-08-22T17:05:08Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{'''Bold text'''{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter after reading this page, please send an email to our chapter leader [[User:bkmarshall|Bruce Marshall]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
The next Kansas City chapter meeting will take place on September 6, 2007 from 6:00 PM to 8:30 PM CDT.  Add the event to your calendar today so you don't miss this opportunity to learn about web application security and network with your peers.&lt;br /&gt;
&lt;br /&gt;
=== September 6 Meeting ===&lt;br /&gt;
&lt;br /&gt;
'''Speaker 1: Bob Phelps, National Bank Examiner with the Office of the Comptroller of the Currency (OCC)'''&lt;br /&gt;
&lt;br /&gt;
Bob will provide his insight on the financial regulatory environment and how laws lead to specific information security standards and guidance.  Through his job he has performed a review of application security practices in about a dozen midsize and large banks.  Bob will share the results of this review and provide his recommendations on how to establish a sound application security management program.&lt;br /&gt;
&lt;br /&gt;
At the OCC Bob both works with the Policy division in Washington DC and has bank supervisory responsibilities.  He leads and participates in examinations of National Banks in NYC, KC, Omaha, and Minneapolis.  His Policy responsibilities include evaluating emerging technologies and their impact on the banking system, evaluating trends in information security, and developing and delivering various training programs to other examiners.&lt;br /&gt;
&lt;br /&gt;
'''Speaker 2: Bruce K. Marshall, Senior Security Consultant with Security PS'''&lt;br /&gt;
&lt;br /&gt;
Bruce will be speaking about how to avoid improperly using challenge questions (e.g. “What is your pet’s name?”) for web app authentication. While challenge questions tend to be user friendly they can also expose your application to new security threats.  He will share his experience on both choosing the best challenge questions and how to properly integrate them into your application.&lt;br /&gt;
&lt;br /&gt;
Bruce consults with clients like American Express, Garmin, Microsoft, and Commerce Bank to assess and improve their information security strategies in areas like network security, web app security, authentication, and program management.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Location:'''&lt;br /&gt;
Centriq Training &lt;br /&gt;
8700 State Line Road&lt;br /&gt;
Suite 200&lt;br /&gt;
Leawood, KS 66206&lt;br /&gt;
(913) 322-7000 [http://www.centriq.com/contactus.htm]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
PLEASE NOTE&lt;br /&gt;
*Attendance at an OWASP chapter meeting is free and open to anyone interested in web application security&lt;br /&gt;
*No registration is required, although RSVPs to the [[User:bkmarshall|chapter leader]] are appreciated&lt;br /&gt;
*Professionals with CISSPs, or other certifications, can earn CPE credits by attending&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to the speakers and attendees at our past meetings:&lt;br /&gt;
&lt;br /&gt;
*[[Kansas City June 2007 Meeting|June 2007 meeting]]&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=20996</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=20996"/>
				<updated>2007-08-21T22:04:23Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: /* Past Meetings */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter after reading this page, please send an email to our chapter leader [[User:bkmarshall|Bruce Marshall]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
The next Kansas City chapter meeting will take place on September 6, 2007 from 6:00 PM to 8:30 PM CDT.  Add the event to your calendar today so you don't miss this opportunity to learn about web application security and network with your peers.&lt;br /&gt;
&lt;br /&gt;
'''September 6 Meeting'''&lt;br /&gt;
&lt;br /&gt;
Speaker 1: Bob Phelps is a National Bank Examiner with the Office of the Comptroller of the Currency (OCC) in Kansas City.  He is responsible for examining the information security practices of banks.  Bob will be speaking about the web application security guidelines now under development for financial institutions.  His talk will provide great insight into the web app security advice being issued by regulatory agencies.&lt;br /&gt;
&lt;br /&gt;
Speaker 2: Bruce K. Marshall is a Senior Consultant with Security PS in Kansas City.  He consults with clients to assess and improve their information security strategies in areas like network security, web app security, authentication, and program management.  Bruce will be speaking about how to avoid improperly using challenge questions for web app authentication.  He will share his insights on both choosing the best challenge questions and how to properly integrate them into your application.&lt;br /&gt;
&lt;br /&gt;
Location: &lt;br /&gt;
Centriq Training &lt;br /&gt;
8700 State Line Road&lt;br /&gt;
Suite 200&lt;br /&gt;
Leawood, KS 66206&lt;br /&gt;
(913) 322-7000 [http://www.centriq.com/contactus.htm]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
PLEASE NOTE&lt;br /&gt;
*Attendance at an OWASP chapter meeting is free and open to anyone interested in web application security&lt;br /&gt;
*No registration is required, although RSVPs to the [[User:bkmarshall|chapter leader]] are appreciated&lt;br /&gt;
*Professionals with CISSPs, or other certifications, can earn CPE credits by attending&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to the speakers and attendees at our past meetings:&lt;br /&gt;
&lt;br /&gt;
*[[Kansas City June 2007 Meeting|June 2007 meeting]]&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=20995</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=20995"/>
				<updated>2007-08-21T22:03:24Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: Meeting update and new content&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter after reading this page, please send an email to our chapter leader [[User:bkmarshall|Bruce Marshall]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Upcoming Meetings ==&lt;br /&gt;
&lt;br /&gt;
The next Kansas City chapter meeting will take place on September 6, 2007 from 6:00 PM to 8:30 PM CDT.  Add the event to your calendar today so you don't miss this opportunity to learn about web application security and network with your peers.&lt;br /&gt;
&lt;br /&gt;
'''September 6 Meeting'''&lt;br /&gt;
&lt;br /&gt;
Speaker 1: Bob Phelps is a National Bank Examiner with the Office of the Comptroller of the Currency (OCC) in Kansas City.  He is responsible for examining the information security practices of banks.  Bob will be speaking about the web application security guidelines now under development for financial institutions.  His talk will provide great insight into the web app security advice being issued by regulatory agencies.&lt;br /&gt;
&lt;br /&gt;
Speaker 2: Bruce K. Marshall is a Senior Consultant with Security PS in Kansas City.  He consults with clients to assess and improve their information security strategies in areas like network security, web app security, authentication, and program management.  Bruce will be speaking about how to avoid improperly using challenge questions for web app authentication.  He will share his insights on both choosing the best challenge questions and how to properly integrate them into your application.&lt;br /&gt;
&lt;br /&gt;
Location: &lt;br /&gt;
Centriq Training &lt;br /&gt;
8700 State Line Road&lt;br /&gt;
Suite 200&lt;br /&gt;
Leawood, KS 66206&lt;br /&gt;
(913) 322-7000 [http://www.centriq.com/contactus.htm]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
PLEASE NOTE&lt;br /&gt;
*Attendance at an OWASP chapter meeting is free and open to anyone interested in web application security&lt;br /&gt;
*No registration is required, although RSVPs to the [[User:bkmarshall|chapter leader]] are appreciated&lt;br /&gt;
*Professionals with CISSPs, or other certifications, can earn CPE credits by attending&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to the speakers and attendees at our past meetings:&lt;br /&gt;
&lt;br /&gt;
*[[Kansas City June 2007 Meeting|June 2007 meeting]]!&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Bkmarshall&amp;diff=20845</id>
		<title>User:Bkmarshall</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Bkmarshall&amp;diff=20845"/>
				<updated>2007-08-15T21:01:22Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Bruce K. Marshall is currently a Senior Security Consultant for Security PS [http://www.securityps.com] in Kansas City.  He is closing in on a decade and a half of experience in the information security field.  In that time he has consulted with both small and large clients, while using his experience and knowledge to earn certifications like the CISSP, NSA-IAM, MCSE: Security, and SPI Certified Instructor.  &lt;br /&gt;
&lt;br /&gt;
Bruce is currently serving as leader of the [[Kansas_City]] OWASP chapter.  He also founded and maintains the PasswordResearch.com[http://www.passwordresearch.com] website.&lt;br /&gt;
&lt;br /&gt;
Bruce can be contacted at bmarshall [at] securityps [dot] com or 913-484-7233.&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=19659</id>
		<title>Kansas City</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Kansas_City&amp;diff=19659"/>
				<updated>2007-07-09T18:33:46Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Kansas City|extra=If you have any questions about the Kansas City Chapter, please send an email to our [[User:bkmarshall|chapter leader]]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-kansascity|emailarchives=http://lists.owasp.org/pipermail/owasp-kansascity}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
We are currently in the process of planning our next meeting for August/September.  Please be thinking about topics you'd like to see presented or discussed at the next meeting.&lt;br /&gt;
&lt;br /&gt;
PLEASE NOTE!&lt;br /&gt;
&lt;br /&gt;
*Attending an OWASP chapter meeting is free&lt;br /&gt;
*No registration required&lt;br /&gt;
*For CISSPs, attending an OWASP meeting will give you valuable CPE credits&lt;br /&gt;
&lt;br /&gt;
We meet at least once a quarter to discuss application security.  If you have an interesting topic you'd like to present or discuss at future meetings, please send an email to bmarshall[at]securityps com.  Or, get a discussion going by posting a message to our [http://lists.owasp.org/mailman/listinfo/owasp-kansascity mailing list].&lt;br /&gt;
&lt;br /&gt;
== Past Meetings ==&lt;br /&gt;
Thanks to everyone who attended our most recent [[Kansas City June 2007 Meeting|June 2007 meeting]]!&lt;br /&gt;
&lt;br /&gt;
*[[Kansas City March 2007 Meeting|March 2007 meeting]]&lt;br /&gt;
*[[Kansas City December 2006 Meeting|December 2006 meeting]]&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Bkmarshall&amp;diff=19658</id>
		<title>User:Bkmarshall</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Bkmarshall&amp;diff=19658"/>
				<updated>2007-07-09T18:29:03Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Bruce K. Marshall is currently a Senior Security Consultant for Security PS [http://www.securityps.com] in Kansas City.  He is closing in on a decade and a half of experience in the information security field.  In that time he has consulted with both small and large clients, while using his experience and knowledge to earn certifications like the CISSP, NSA-IAM, MCSE: Security, and SPI Certified Instructor.  &lt;br /&gt;
&lt;br /&gt;
Bruce is currently serving as leader of the [[Kansas_City]] OWASP chapter.  He also founded and maintains content for the PasswordResearch.com[http://www.passwordresearch.com] website.&lt;br /&gt;
&lt;br /&gt;
Bruce can be contacted at bmarshall [at] securityps.com or 913-484-7233.&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Bkmarshall&amp;diff=19656</id>
		<title>User:Bkmarshall</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Bkmarshall&amp;diff=19656"/>
				<updated>2007-07-09T18:26:46Z</updated>
		
		<summary type="html">&lt;p&gt;Bkmarshall: New page: Bruce K. Marshall is currently a Senior Security Consultant for Security PS [http://www.securityps.com] in Kansas City.  He is closing in on a decade and a half of experience in the inform...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Bruce K. Marshall is currently a Senior Security Consultant for Security PS [http://www.securityps.com] in Kansas City.  He is closing in on a decade and a half of experience in the information security field.  In that time he has consulted with both small and large clients, while using his experience and knowledge to earn certifications like the CISSP, NSA-IAM, MCSE: Security, and SPI Certified Instructor.  &lt;br /&gt;
&lt;br /&gt;
Bruce is currently serving as leader of the Kansas City OWASP chapter.  He also founded and maintains content for the PasswordResearch.com[http://www.passwordresearch.com] website.&lt;br /&gt;
&lt;br /&gt;
Bruce can be contacted at bmarshall [at] securityps.com or 913-484-7233.&lt;/div&gt;</summary>
		<author><name>Bkmarshall</name></author>	</entry>

	</feed>