<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Buanzo</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Buanzo"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Buanzo"/>
		<updated>2026-05-22T22:14:33Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011/Summit_Venue_Logistics&amp;diff=99192</id>
		<title>Summit 2011/Summit Venue Logistics</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011/Summit_Venue_Logistics&amp;diff=99192"/>
				<updated>2011-01-09T14:43:32Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: /* Birthday Parties */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{:Summit_2011/Summit_Tasks_Header}}&lt;br /&gt;
&lt;br /&gt;
This page contains information about logistics issues related to the Summit 2011 venue&lt;br /&gt;
&lt;br /&gt;
=Venue=&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
Here is all information related to Summit Venue infrastructure&lt;br /&gt;
&lt;br /&gt;
==Venue Information==&lt;br /&gt;
* (put links to venue data here (for example maps))&lt;br /&gt;
&lt;br /&gt;
==Wireless Network(s)==&lt;br /&gt;
Main point of contact: Filipe Lacerda&lt;br /&gt;
&lt;br /&gt;
The current plan is to have 3 Wireless networks (with maybe the hotel's used as a backup 4th)&lt;br /&gt;
&lt;br /&gt;
# Attendees Network - this is the general access one, which will be used by all attendees. This is the one that will be hit the most and the one what will be protected and monitored by Trustwave&lt;br /&gt;
# Summit Team Network - this is a dedicated private network for the Summit Team. Access should be very limited and should have the maximum/strongest SLA (i.e. if one network cannot go down it is this one)&lt;br /&gt;
# CTF (Capture The Flag) Network - This will be a network that would contain all traffic related to CTF and other security research activities (it is an interesting question if this should be connected to the Internet, BUT, we might have authorization to perform 'ethical' security reviews to other Portuguese websites, and if so, all such tests should be executed via this network)&lt;br /&gt;
&lt;br /&gt;
==Summit Team 'Control Centre'==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
==Working Sessions Rooms==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
Description: Set-up rooms, create environments for smaller Working sessions&lt;br /&gt;
&lt;br /&gt;
==Printing/Production Station==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
==Working Areas==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
Description: A significant number of Attendees will need to perform work while they are at the Summit. A number of per-allocated spaces should be created (think 'Hot desking') so that there is a calm, silent and focused location for them to use.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Social Events=&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
This is all information about the social events that will be organized at the Summit&lt;br /&gt;
&lt;br /&gt;
==Dinners Logistics==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
==Happy Hours==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
==Mountain Hike/Walk==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
Description: Post main conference (6PMish) walk at the local forest (work with Hotel on this)&lt;br /&gt;
&lt;br /&gt;
==OWASP Band==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
==Football match==&lt;br /&gt;
* '''Main point of contact''': TBC&lt;br /&gt;
* '''When''': Wednesday night (projected)&lt;br /&gt;
* '''Description''': Game of 6-a-side [http://en.wikipedia.org/wiki/Football Football] match (Soccer for the US crowd)&lt;br /&gt;
* '''Ideas''': Depending how many people will want to play football we could organize only one match, or have a mini-tournament with a 'Country vs Country' or 'Brazil vs Rest-of-the-world' or 'Builders vs vs Breakers'  , etc...&lt;br /&gt;
&lt;br /&gt;
==Golf Tournament==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
==Gala Dinner==&lt;br /&gt;
* '''Main point of contact''': TBD&lt;br /&gt;
* '''When''': Thursday (projected)&lt;br /&gt;
* '''Description''': ...&lt;br /&gt;
 &lt;br /&gt;
==Birthday Parties==&lt;br /&gt;
* '''Main point of contact''': Arturo 'Buanzo' Busleiman&lt;br /&gt;
* '''When''': TBD&lt;br /&gt;
* '''Description''': Identify which owasp leader (and Summit participant) has its birthday during the Summit (from Mon 7th till Fri 11th)  and prepare something special for them.&lt;br /&gt;
* '''Who and When''':&lt;br /&gt;
** 8th (Tue): &lt;br /&gt;
*** Arturo 'Buanzo' Busleiman (participating remotely)&lt;br /&gt;
*** Lucas Ferreira&lt;br /&gt;
** 11th (Fri)&lt;br /&gt;
***   Mateo Martinez&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Summit_2011/Summit_Venue_Logistics&amp;diff=99191</id>
		<title>Summit 2011/Summit Venue Logistics</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Summit_2011/Summit_Venue_Logistics&amp;diff=99191"/>
				<updated>2011-01-09T14:42:55Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: added lucas&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{:Summit_2011/Summit_Tasks_Header}}&lt;br /&gt;
&lt;br /&gt;
This page contains information about logistics issues related to the Summit 2011 venue&lt;br /&gt;
&lt;br /&gt;
=Venue=&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
Here is all information related to Summit Venue infrastructure&lt;br /&gt;
&lt;br /&gt;
==Venue Information==&lt;br /&gt;
* (put links to venue data here (for example maps))&lt;br /&gt;
&lt;br /&gt;
==Wireless Network(s)==&lt;br /&gt;
Main point of contact: Filipe Lacerda&lt;br /&gt;
&lt;br /&gt;
The current plan is to have 3 Wireless networks (with maybe the hotel's used as a backup 4th)&lt;br /&gt;
&lt;br /&gt;
# Attendees Network - this is the general access one, which will be used by all attendees. This is the one that will be hit the most and the one what will be protected and monitored by Trustwave&lt;br /&gt;
# Summit Team Network - this is a dedicated private network for the Summit Team. Access should be very limited and should have the maximum/strongest SLA (i.e. if one network cannot go down it is this one)&lt;br /&gt;
# CTF (Capture The Flag) Network - This will be a network that would contain all traffic related to CTF and other security research activities (it is an interesting question if this should be connected to the Internet, BUT, we might have authorization to perform 'ethical' security reviews to other Portuguese websites, and if so, all such tests should be executed via this network)&lt;br /&gt;
&lt;br /&gt;
==Summit Team 'Control Centre'==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
==Working Sessions Rooms==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
Description: Set-up rooms, create environments for smaller Working sessions&lt;br /&gt;
&lt;br /&gt;
==Printing/Production Station==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
==Working Areas==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
Description: A significant number of Attendees will need to perform work while they are at the Summit. A number of per-allocated spaces should be created (think 'Hot desking') so that there is a calm, silent and focused location for them to use.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Social Events=&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
This is all information about the social events that will be organized at the Summit&lt;br /&gt;
&lt;br /&gt;
==Dinners Logistics==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
==Happy Hours==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
==Mountain Hike/Walk==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
Description: Post main conference (6PMish) walk at the local forest (work with Hotel on this)&lt;br /&gt;
&lt;br /&gt;
==OWASP Band==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
==Football match==&lt;br /&gt;
* '''Main point of contact''': TBC&lt;br /&gt;
* '''When''': Wednesday night (projected)&lt;br /&gt;
* '''Description''': Game of 6-a-side [http://en.wikipedia.org/wiki/Football Football] match (Soccer for the US crowd)&lt;br /&gt;
* '''Ideas''': Depending how many people will want to play football we could organize only one match, or have a mini-tournament with a 'Country vs Country' or 'Brazil vs Rest-of-the-world' or 'Builders vs vs Breakers'  , etc...&lt;br /&gt;
&lt;br /&gt;
==Golf Tournament==&lt;br /&gt;
Main point of contact: TBC&lt;br /&gt;
&lt;br /&gt;
==Gala Dinner==&lt;br /&gt;
* '''Main point of contact''': TBD&lt;br /&gt;
* '''When''': Thursday (projected)&lt;br /&gt;
* '''Description''': ...&lt;br /&gt;
 &lt;br /&gt;
==Birthday Parties==&lt;br /&gt;
* '''Main point of contact''': Arturo 'Buanzo' Busleiman&lt;br /&gt;
* '''When''': TDB&lt;br /&gt;
* '''Description''': Identify which owasp leader (and Summit participant) has its birthday during the Summit (from Mon 7th till Fri 11th)  and prepare something special for them &lt;br /&gt;
* '''Who and When''':&lt;br /&gt;
** 8th (Tue): &lt;br /&gt;
*** Arturo 'Buanzo' Busleiman (participating remotely)&lt;br /&gt;
*** Lucas Ferreira&lt;br /&gt;
** 11th (Fri)&lt;br /&gt;
***   Mateo Martinez&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:IBWAS10-Jify.pdf&amp;diff=96671</id>
		<title>File:IBWAS10-Jify.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:IBWAS10-Jify.pdf&amp;diff=96671"/>
				<updated>2010-12-16T11:41:29Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: OWASP IBWAS Buanzo Jify Conference Talk 2010&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OWASP IBWAS Buanzo Jify Conference Talk 2010&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:IBWAS10-Enigform.pdf&amp;diff=96670</id>
		<title>File:IBWAS10-Enigform.pdf</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:IBWAS10-Enigform.pdf&amp;diff=96670"/>
				<updated>2010-12-16T11:37:45Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: OWASP IBWAS Buanzo Enigform training 2010&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OWASP IBWAS Buanzo Enigform training 2010&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_IBWAS10&amp;diff=96669</id>
		<title>OWASP IBWAS10</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_IBWAS10&amp;diff=96669"/>
				<updated>2010-12-16T11:17:24Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:IBWAS10 logo.gif|621x280px]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
*[https://docs.google.com/document/pub?id=15GNipvLBz39-8SCbm1TqFfJtK8QUHOwrD4xkIU9Wl54 Press Release]&lt;br /&gt;
*[[OWASP IBWAS10/Media Mentions|Media Mentions]]&lt;br /&gt;
*[[OWASP IBWAS10/Venue|Venue's Location]]&lt;br /&gt;
*[[OWASP IBWAS10/Team|Conference's Team]] &lt;br /&gt;
*[[OWASP IBWAS10/Archived|Archived]]&lt;br /&gt;
*[[OWASP IBWAS10/Internals|Internals]] &lt;br /&gt;
*[[IBWAS09|IBWAS09]]&lt;br /&gt;
&amp;lt;br&amp;gt; [http://www.twitter.com/ibwas10 http://twitter-badges.s3.amazonaws.com/twitter-a.png]	&lt;br /&gt;
[http://www.facebook.com/#!/group.php?gid=113336378677245 http://www.allofads.com/files/images/facebook-logo.jpg] [http://events.linkedin.com/2nd-Ibero-American-Web-Application/pub/273820 http://static03.linkedin.com/img/logos/logo_linkedin_88x22.png] &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== About  ====&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;100%&amp;quot; cellspacing=&amp;quot;10&amp;quot; cellpadding=&amp;quot;1&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;left&amp;quot; | This event is a joint organization of the [http://www.owasp.org/index.php/Portuguese Portuguese] and [http://www.owasp.org/index.php/Spain Spanish] OWASP chapters.&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;left&amp;quot; | &amp;amp;nbsp;Apart from OWASP's Top 10, most OWASP Projects are not widely used and understood still. This training course aims to change that by providing a selection of mature and enterprise ready projects together with practical examples of how to use them.&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;left&amp;quot; | &amp;amp;nbsp;This conference aims to bring together application security experts, researchers, educators and practitioners from the industry, academia and international communities such as OWASP, in order to discuss open problems and new solutions in application security.&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;left&amp;quot; | &amp;amp;nbsp;Conference proceedings will be published by OWASP, and distributed in electronic format.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Training  ====&lt;br /&gt;
&lt;br /&gt;
{{:IBWAS10 Training}} &lt;br /&gt;
&lt;br /&gt;
==== Conference  ====&lt;br /&gt;
&amp;amp;nbsp;&lt;br /&gt;
The Conference date is 17 December 2010, Room B2.03 (same as Trainings).&lt;br /&gt;
&amp;amp;nbsp;&lt;br /&gt;
{{:OWASP IBWAS10 Conference Line-Up}} &lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;100%&amp;quot; cellspacing=&amp;quot;5&amp;quot; cellpadding=&amp;quot;0&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#ccccee&amp;quot; align=&amp;quot;center&amp;quot; | '''TRAINING''' &lt;br /&gt;
| valign=&amp;quot;middle&amp;quot; bgcolor=&amp;quot;#ccccee&amp;quot; align=&amp;quot;center&amp;quot; | '''CONFERENCE'''&lt;br /&gt;
|-&lt;br /&gt;
| width=&amp;quot;50%&amp;quot; valign=&amp;quot;middle&amp;quot; align=&amp;quot;center&amp;quot; | {{Template:OWASP Training/Price/Free&lt;br /&gt;
| Price = Free&lt;br /&gt;
| registration_url = http://www.eventbrite.com/event/1073670377?ref=elink&lt;br /&gt;
| registration_name = Register Now!&lt;br /&gt;
}} &lt;br /&gt;
| width=&amp;quot;50%&amp;quot; valign=&amp;quot;middle&amp;quot; align=&amp;quot;center&amp;quot; | {{Template:OWASP Conference/Price/Free&lt;br /&gt;
| Price = Free&lt;br /&gt;
| Registration_url = http://ibwas10.eventbrite.com/&lt;br /&gt;
| Registration_name = Register Now!&lt;br /&gt;
}}&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Sponsors  ====&lt;br /&gt;
&lt;br /&gt;
{{:OWASP IBWAS10/Sponsors}} __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]] [[Category:OWASP_IBWAS]] [[Category:OWASP_Training]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP/Training/Implementation_of_Enigform_for_Wordpress&amp;diff=96668</id>
		<title>OWASP/Training/Implementation of Enigform for Wordpress</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP/Training/Implementation_of_Enigform_for_Wordpress&amp;diff=96668"/>
				<updated>2010-12-16T11:13:23Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP Training Modules&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| Module_designation = [[:Category:OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp|OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp Project]]&lt;br /&gt;
| Module_Overview_Goal = &lt;br /&gt;
&amp;amp;nbsp;&lt;br /&gt;
Implement Enigform Authentication for Wordpress, from a bare-bones Ubuntu server installation to a working blog. To find problems, solve and document them. Learn, have fun, ask questions, have more fun.&lt;br /&gt;
&lt;br /&gt;
If you can, bring a laptop with a virtualization solution installed with Ubuntu 9.10.&lt;br /&gt;
&lt;br /&gt;
| Content = &lt;br /&gt;
&amp;amp;nbsp;&lt;br /&gt;
*Mod_Openpgp Installation: Dependencies, mod_openpgp and EPS&lt;br /&gt;
*Server Keypair Creation&lt;br /&gt;
*Client Keypair Creation and Import into Server's Keyring&lt;br /&gt;
*Running EPS (Enigform Python Server)&lt;br /&gt;
*Apache VirtualHost Configuration for EPS and mod_openpgp&lt;br /&gt;
*Installing Enigform in your Firefox Browser&lt;br /&gt;
*Wordpress Plugin Installation and Configuration&lt;br /&gt;
*Wordpress Template Editing&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&lt;br /&gt;
| Material = &lt;br /&gt;
&amp;amp;nbsp;&lt;br /&gt;
*[http://wiki.buanzo.org/index.php?n=Main.Wp-enigform-authentication Wordpress Plugin for Enigform Authentication - Definitive Guide]&lt;br /&gt;
*[http://www.owasp.org/index.php/File:Enigform.pdf Enigform pdf]&lt;br /&gt;
&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Training|Training]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=IBWAS10&amp;diff=92753</id>
		<title>IBWAS10</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=IBWAS10&amp;diff=92753"/>
				<updated>2010-11-11T17:38:53Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: fixed eningform -&amp;gt; enigform&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
= 2nd. OWASP Ibero-American Web Application Security Conference (IBWAS'10)  =&lt;br /&gt;
&lt;br /&gt;
held at [http://www.iscte.pt/ ISCTE - Lisbon University Institute] | &lt;br /&gt;
&lt;br /&gt;
[http://ibwas09.netmust.eu IBWAS'09 (last year editon)] - [http://www.owasp.org/index.php/IBWAS09 Internal OWASP site]&lt;br /&gt;
&lt;br /&gt;
'''16 - 17 December 2010''' (NEW DATES - PREVIOUS DATES CANCELLED DUE TO A GENERAL STRIKE IN PORTUGAL)&lt;br /&gt;
&lt;br /&gt;
(a joint organization of the [http://www.owasp.org/index.php/Portuguese Portuguese] and [http://www.owasp.org/index.php/Spain Spanish] OWASP chapters)&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &amp;lt;!-- Header --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Welcome  ====&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
http://www.allofads.com/files/ibwas10/PromoIBWAS10-700px.jpg&lt;br /&gt;
&lt;br /&gt;
IBWAS'10, the 2nd. OWASP Ibero-American Web Application Security conference will be held in Lisbon (Portugal), on the '''16th and 17th December 2010''' ('''dates have been changed'''). &lt;br /&gt;
&lt;br /&gt;
The conference will take place at the [http://www.iscte.pt ISCTE - Lisbon University Institute]. The location details can be found [http://www.owasp.org/index.php/Ibwas10#tab=Venue here]. &lt;br /&gt;
&lt;br /&gt;
Conference proceedings will be '''published by OWASP, and distributed in electronic format'''. Last year proceedings were published by Springer ('''this year the proceedings will not be published by Springer due to a low number of submissions'''). &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|http://ibwas09.netmust.eu/files/ibwas10/CCIS_72.png&lt;br /&gt;
|This conference aims to bring together application security experts, researchers, educators and practitioners from the industry, academia and international communities such as OWASP, in order to discuss open problems and new solutions in application security. In the context of this track academic researchers will be able to combine interesting results with the experience of practitioners and software engineers. &lt;br /&gt;
&lt;br /&gt;
In addition to the technical issues of the conference programme, our website provides you with tourist information on the city of Lisbon, unique for its cultural and historical richness, lovely surroundings and other nice places to visit around the city. &lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
'''Who Should Attend IBWAS'10:''' &lt;br /&gt;
&lt;br /&gt;
*Academics &lt;br /&gt;
*Researchers &lt;br /&gt;
*Lifelong learning educators &lt;br /&gt;
*Technical staff &lt;br /&gt;
*Secondary, vocational, or tertiary educators &lt;br /&gt;
*Professionals from the private and public sector &lt;br /&gt;
*Technologists and Scientifics &lt;br /&gt;
*School counsellors, principals and teachers &lt;br /&gt;
*Education policy development representatives &lt;br /&gt;
*General personnel from vocational sectors &lt;br /&gt;
*Student counsellors &lt;br /&gt;
*Career/employment officers &lt;br /&gt;
*Education advisers &lt;br /&gt;
*Student Unions &lt;br /&gt;
*Bridging program lecturers &amp;amp;amp; support staff &lt;br /&gt;
*Library personnel &lt;br /&gt;
*International support and services staff &lt;br /&gt;
*Open learning specialists &lt;br /&gt;
*Application Developers &lt;br /&gt;
*Application Testers and Quality Assurance &lt;br /&gt;
*Application Project Management and Staff &lt;br /&gt;
*Chief Information Officers, Chief Information Security Officers, Chief Technology Officers, Deputies, Associates and Staff &lt;br /&gt;
*Chief Financial Officers, Auditors, and Staff Responsible for IT Security Oversight and Compliance &lt;br /&gt;
*Security Managers and Staff &lt;br /&gt;
*Executives, Managers, and Staff Responsible for IT Security Governance &lt;br /&gt;
*IT Professionals Interesting in Improving IT Security&lt;br /&gt;
&lt;br /&gt;
...and any person interested in Web Application and Services Security and Information Security in general. &lt;br /&gt;
&lt;br /&gt;
We look forward to seeing you in Lisbon! &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border: 0px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL --&amp;gt; &lt;br /&gt;
[[File:ibwas10-logo-main.png]]&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
[http://www.twitter.com/ibwas10 http://twitter-badges.s3.amazonaws.com/twitter-a.png]&lt;br /&gt;
[http://www.facebook.com/#!/group.php?gid=113336378677245 http://www.allofads.com/files/images/facebook-logo.jpg]&lt;br /&gt;
[http://events.linkedin.com/2nd-Ibero-American-Web-Application/pub/273820 http://static03.linkedin.com/img/logos/logo_linkedin_88x22.png]&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;border: 1px solid rgb(204, 204, 204); width: 100%; font-size: 95%; color: rgb(0, 0, 0); background-color: rgb(236, 236, 236);&amp;quot; | &lt;br /&gt;
Use the '''[http://search.twitter.com/search?q=%23ibwas10 #ibwas10]''' hashtag for your tweets (What are [http://hashtags.org/ hashtags]?) &lt;br /&gt;
&lt;br /&gt;
'''@ibwas10 Twitter Feed ([http://twitter.com/ibwas10 follow us on Twitter!])''' &lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
| align = &amp;quot;right&amp;quot;  |&lt;br /&gt;
[http://www.iscte.pt http://ibwas09.netmust.eu/files/iscte-iul.png]&lt;br /&gt;
&lt;br /&gt;
[http://www.adetti.pt http://ibwas09.netmust.eu/files/adetti.png]&lt;br /&gt;
&lt;br /&gt;
[http://www.maxdata.pt http://ibwas09.netmust.eu/files/ibwas10/maxdata.png]&lt;br /&gt;
&lt;br /&gt;
[http://www.noesis.pt http://ibwas09.netmust.eu/files/ibwas10/noesis.png]&lt;br /&gt;
&lt;br /&gt;
[http://www.isecauditors.com http://ibwas09.netmust.eu/files/pasted-graphic.jpg]&lt;br /&gt;
&lt;br /&gt;
[http://lasige.di.fc.ul.pt/ http://ibwas09.netmust.eu/files/lasige.png]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Media Partners:'''&lt;br /&gt;
&lt;br /&gt;
[http://www.aeiou.pt http://ibwas09.netmust.eu/files/ibwas10/aeiou.png]&lt;br /&gt;
&lt;br /&gt;
[http://www.borrmart.es/redseguridad.php http://ibwas09.netmust.eu/files/redseguridad.jpg]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt; &lt;br /&gt;
==== Call for Papers (CLOSED)  ====&lt;br /&gt;
&lt;br /&gt;
'''THE IBWAS'10 CALL FOR PAPERS IS NOW CLOSED!!!'''&lt;br /&gt;
&lt;br /&gt;
=== Call for Papers (english version) ===&lt;br /&gt;
[[#Call for Papers (portuguese version)]] [[#Call for Papers (spanish version)]]&lt;br /&gt;
&lt;br /&gt;
You can find here a [http://ibwas09.netmust.eu/files/ibwas10/IBWAS10-CfP.pdf PDF version] of the Call for Papers. Also in [http://ibwas09.netmust.eu/files/ibwas10/IBWAS10-CfP-PT.pdf Portuguese]  (Português)&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
There is a change in the information systems development paradigm. The emergence of Web 2.0 technologies led to the extensive deployment and use of web-based applications and web services as a way to developed new and flexible information systems. Such systems are easy to develop, deploy and maintain and demonstrate impressive features for users, resulting in their current wide use. &lt;br /&gt;
&lt;br /&gt;
As a result of this paradigm shift, the security requirements have also changed. These web-based information systems have different security requirements, when compared to traditional systems. Important security issues have been found and privacy concerns have also been raised recently. In addition, the emerging Cloud Computing paradigm promises even greater flexibility; however corresponding security and privacy issues still need to be examined. The security environment should involve not only the surrounding environment but also the application core.&lt;br /&gt;
&lt;br /&gt;
This conference aims to bring together application security experts, researchers, educators and practitioners from the industry, academia and international communities such as OWASP, in order to discuss open problems and new solutions in application security. In the context of this track academic researchers will be able to combine interesting results with the experience of practitioners and software engineers.&lt;br /&gt;
&lt;br /&gt;
== Conference Topics ==&lt;br /&gt;
&lt;br /&gt;
Suggested topics for papers submission include (but are not limited to):&lt;br /&gt;
*Secure application development&lt;br /&gt;
*Security of service oriented architectures&lt;br /&gt;
*Security of development frameworks&lt;br /&gt;
*Threat modelling of web applications&lt;br /&gt;
*Cloud computing security&lt;br /&gt;
*Web applications vulnerabilities and analysis (code review, pen-test, static analysis etc.)&lt;br /&gt;
*Metrics for application security&lt;br /&gt;
*Countermeasures for web application vulnerabilities&lt;br /&gt;
*Secure coding techniques&lt;br /&gt;
*Platform or language security features that help secure web applications&lt;br /&gt;
*Secure database usage in web applications&lt;br /&gt;
*Access control in web applications&lt;br /&gt;
*Web services security&lt;br /&gt;
*Browser security&lt;br /&gt;
*Privacy in web applications&lt;br /&gt;
*Standards, certifications and security evaluation criteria for web applications&lt;br /&gt;
*Application security awareness and education&lt;br /&gt;
*Security for the mobile web&lt;br /&gt;
*Attacks and Vulnerability Exploitation&lt;br /&gt;
&lt;br /&gt;
== Paper Submission Instructions ==&lt;br /&gt;
&lt;br /&gt;
Authors should submit an original paper in English, carefully checked for correct grammar and spelling, using the on-line submission procedure ([http://www.easychair.org/conferences/?conf=ibwas10 submission site]). Please check the paper formats so you may be aware of the accepted paper page limits (12 pages, in accordance to a supplied template, that can be downloaded from here: [ftp://ftp.springer.de/pub/tex/latex/llncs/word/LNCS-Office2007.zip in Word Format] and in [ftp://ftp.springer.de/pub/tex/latex/llncs/latex2e/llncs2e.zip LateX format]). &lt;br /&gt;
&lt;br /&gt;
The guidelines for paper formatting provided at the conference web site must be strictly used for all submitted papers. The submission format is the same as the camera-ready format. Please check and carefully follow the instructions and templates provided. &lt;br /&gt;
&lt;br /&gt;
Each paper should clearly indicate the nature of its technical/scientific contribution, and the problems, domains or environments to which it is applicable. &lt;br /&gt;
&lt;br /&gt;
Papers that are out of the conference scope or contain any form of plagiarism will be rejected without reviews. &lt;br /&gt;
&lt;br /&gt;
Remarks about the on-line submission procedure:&lt;br /&gt;
&lt;br /&gt;
1.	A &amp;quot;double-blind&amp;quot; paper evaluation method will be used. To facilitate that, the authors are kindly requested to produce and provide the paper, WITHOUT any reference to any of the authors. This means that is necessary to remove the author’s personal details, the acknowledgements section and any reference that may disclose the authors identity&lt;br /&gt;
&lt;br /&gt;
2.	Papers in ODF, PDF, DOC, DOCX or RTF format are accepted &lt;br /&gt;
&lt;br /&gt;
3.	The web submission procedure automatically sends an acknowledgement, by e-mail, to the contact author.&lt;br /&gt;
&lt;br /&gt;
= Paper submission types= &lt;br /&gt;
&lt;br /&gt;
'''Regular Paper Submission'''&lt;br /&gt;
&lt;br /&gt;
A regular paper presents a work where the research is completed or almost finished. It does not necessary means that the acceptance is as a full paper. It may be accepted as a &amp;quot;full paper&amp;quot; (30 min. oral presentation), a &amp;quot;short paper&amp;quot; (15 min. oral presentation) or a &amp;quot;poster&amp;quot;. &lt;br /&gt;
&lt;br /&gt;
'''Position Paper Submission'''&lt;br /&gt;
&lt;br /&gt;
A position paper presents an arguable opinion about an issue. The goal of a position paper is to convince the audience that your opinion is valid and worth listening to, without the need to present completed research work and/or validated results. It is, nevertheless, important to support your argument with evidence to ensure the validity of your claims. A position paper may be a short report and discussion of ideas, facts, situations, methods, procedures or results of scientific research (bibliographic, experimental, theoretical, or other) focused on one of the conference topic areas. The acceptance of a position paper is restricted to the categories of &amp;quot;short paper&amp;quot; or &amp;quot;poster&amp;quot;, i.e. a position paper is not a candidate to acceptance as &amp;quot;full paper&amp;quot;. &lt;br /&gt;
&lt;br /&gt;
= Camera-ready =&lt;br /&gt;
&lt;br /&gt;
After the reviewing process is completed, the contact author (the author who submits the paper) of each paper will be notified of the result, by e-mail. The authors are required to follow the reviews in order to improve their paper before the camera-ready submission. &lt;br /&gt;
&lt;br /&gt;
= Publications =&lt;br /&gt;
&lt;br /&gt;
All accepted papers will be published in the conference proceedings, under an ISBN reference. Conference proceedings will be published by OWASP in electronic format ('''Springer proceedings have been canceled due to a low number of paper submissions''').&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Web-site ==&lt;br /&gt;
&lt;br /&gt;
http://www.ibwas.com&lt;br /&gt;
&lt;br /&gt;
== Secretariat ==&lt;br /&gt;
&lt;br /&gt;
E-mail: secretariat@ibwas.com&lt;br /&gt;
&lt;br /&gt;
== Important Dates ==&lt;br /&gt;
&lt;br /&gt;
Submission of papers and all other contributions due: '''31st October 2010'''&lt;br /&gt;
&lt;br /&gt;
Notification of acceptance: '''28th November 2010''' (delayed)&lt;br /&gt;
&lt;br /&gt;
Camera-ready version of accepted contributions: '''5th December 2010'''&lt;br /&gt;
&lt;br /&gt;
Conference: '''16th – 17th December 2010'''&lt;br /&gt;
&lt;br /&gt;
=== Call for Papers (portuguese version) ===&lt;br /&gt;
&lt;br /&gt;
== Introdução ==&lt;br /&gt;
&lt;br /&gt;
Existe uma mudança profunda no paradigma de desenvolvimento de sistemas de informação nos nossos dias. A emergência de tecnologias Web 2.0 levaram a um desenvolvimento e implantação massiva de aplicações e serviços Web, como a forma de desenvolvimento de sistemas de informação flexíveis. Tais sistemas são simples de desenvolver, instalar e manter e demonstram um conjunto de funcionalidades atractivas para os utilizadores, o que as tornam tão apetecíveis. &lt;br /&gt;
&lt;br /&gt;
Como resultado desta mudança paradigmática, os requisitos de segurança também se alteraram. Estes sistemas de informação baseados na Web possuem diferentes requisitos de segurança, quando comparados com sistemas tradicionais. Neste tipo de sistemas é possível encontrar aspectos importantes de segurança e de privacidade que podem afectar a forma como os mesmos operam e comprometer os seus utilizadores. Acresce o facto de que a emergência da Computação na Nuvem, que promete ainda mais flexibilidade, tem ainda um impacto mais forte nestes requisitos de segurança e de privacidade. O ambiente de segurança deve envolver não apenas o ambiente circundante mas igualmente o núcleo aplicacional.&lt;br /&gt;
&lt;br /&gt;
Esta conferência pretende juntar peritos em segurança aplicacional, investigadores, educadores e profissionais da indústria, academia e comunidades internacionais como a OWASP, por forma a discutirem de forma aberta os problemas e as soluções de segurança aplicacional. Neste contexto, investigadores provenientes da academia e da indústria poderão combinar os resultados da sua investigação com a experiência de profissionais e de engenheiros de software.&lt;br /&gt;
&lt;br /&gt;
== Temas da Conferência ==&lt;br /&gt;
Os temas sugeridos para submissão de trabalhos incluem os seguintes (mas não se limitam apenas aos listados):&lt;br /&gt;
*Desenvolvimento Seguro de Aplicações&lt;br /&gt;
*Segurança de Arquitecturas Orientadas por Serviços&lt;br /&gt;
*Segurança das Estruturas e Ferramentas de Desenvolvimento&lt;br /&gt;
*Modelação de Ameaças a Aplicações Web&lt;br /&gt;
*Segurança em Cloud Computing&lt;br /&gt;
*Vulnerabilidades e Análise de Aplicações Web (revisão de código, testes de penetração, análise estática, etc)&lt;br /&gt;
*Métricas para Segurança Aplicacional&lt;br /&gt;
*Contra-medidas para Vulnerabilidades em Aplicações Web&lt;br /&gt;
*Técnicas de Desenvolvimento e Codificação em Segurança&lt;br /&gt;
*Funcionalidades da Plataforma ou Linguagem de Desenvolvimento para a Segurança de Aplicações Web&lt;br /&gt;
*Utilização Segura de Bases de Dados em Aplicações Web&lt;br /&gt;
*Controlo de Acesso em Aplicações Web&lt;br /&gt;
*Segurança em Serviços Web&lt;br /&gt;
*Segurança do Browser Web&lt;br /&gt;
*Privacidade em Aplicações Web&lt;br /&gt;
*Normas, Certificações e Critérios para Avaliação da Segurança em Aplicações Web&lt;br /&gt;
*Sensibilização e Educação para a Segurança Aplicacional&lt;br /&gt;
*Segurança para a Web Móvel&lt;br /&gt;
*Ataques e Exploração de Vulnerabilidades&lt;br /&gt;
&lt;br /&gt;
== Instruções para a submissão de trabalhos ==&lt;br /&gt;
&lt;br /&gt;
Os autores deve submeter um trabalho original escrito em Inglês, devidamente verificado para evitar incorrecções gramaticais ou sintácticas, usando o procedimento de submissão on-line (http://www.easychair.org/conferences/?conf=ibwas10). Por favor, verifique os formatos aceites para os trabalhos e tenha atenção a dimensão máxima dos mesmos (limite de 12 páginas, de acordo com o modelo fornecido e que pode ser obtido a partir da seguinte URL: ftp://ftp.springer.de/pub/tex/latex/llncs/word/LNCS-Office2007.zip).&lt;br /&gt;
&lt;br /&gt;
As indicações para a formatação dos trabalhos fornecidos no site da conferência e no template devem ser estritamente seguidas pelos autores que desejem submeter trabalhos. O formato de submissão é o mesmo do formato final. Por favor, siga as instruções de formatação usadas no template.&lt;br /&gt;
&lt;br /&gt;
Cada trabalho deve indicar com clareza a natureza da sua contribuição técnica/científica e os problemas, domínios ou ambientes para o qual é aplicável.&lt;br /&gt;
&lt;br /&gt;
Todos os artigos que estejam fora do âmbito da conferência ou que sob os quais sejam detectados actos de plágio, serão liminarmente rejeitados.&lt;br /&gt;
&lt;br /&gt;
Alguns detalhes sobre o procedimento de submissão:&lt;br /&gt;
&lt;br /&gt;
1. Será utilizado um procedimento de revisão anónimo, que será repetido por pelo menos dois revisores autónomos. Para facilitar este processo, que se pretende seja rápido, eficiente e justo, é solicitado aos autores que produzam os seu trabalho e que o submetam, SEM qualquer referência a algum dos autores do mesmo. Isto significa que é necessário remover os detalhes pessoais do autor, a secção de agradecimentos e qualquer outra referência que possa revelar a identidade dos autores;&lt;br /&gt;
&lt;br /&gt;
2. Serão aceites os seguintes formatos de ficheiros na submissão: ODF, PDF, DOC, DOCX e RTF;&lt;br /&gt;
&lt;br /&gt;
3. O processo de submissão on-line envia automaticamente uma notificação, através do correio electrónico, do resultado da submissão ao autor correspondente.&lt;br /&gt;
&lt;br /&gt;
= Tipos de submissão de trabalhos = &lt;br /&gt;
&lt;br /&gt;
'''Submissão de trabalhos regulares'''&lt;br /&gt;
&lt;br /&gt;
Um trabalho regular apresenta o trabalho em que a pesquisa está terminada ou muito próximo de estar completa. Não significa que o trabalho seja aceite na categoria de “trabalho completo”. Pode ser aceite como “trabalho completo” (apresentação oral de 30 minutos), “trabalho curto” (apresentação oral de 15 minutos) ou “poster”.&lt;br /&gt;
&lt;br /&gt;
'''Submissão de trabalhos de posição'''&lt;br /&gt;
&lt;br /&gt;
Um trabalho de posição apresenta uma opinião para discussão num determinado assunto. O objectivo de um trabalho deste tipo é o de convencer a audiência de que a sua opinião é válida e vale a pena ser escutada, sem ser necessário apresentar trabalho completo de pesquisa e/ou resultados devidamente validados. É no entanto importante suportar os seus argumentos com provas e assegurar a validade das mesmas. Um trabalho deste tipo pode ser relatório curto e a discussão de ideias, factos, situações, métodos, procedimentos ou resultados de pesquisa científica (bibliográfica, experimental, teórica ou outra) focada num dos temas da conferência. A aceitação de um trabalho de posição está restringido às categorias de “artigo curto” ou “poster”.&lt;br /&gt;
&lt;br /&gt;
= Formato Final =&lt;br /&gt;
&lt;br /&gt;
Depois de concluído o processo de revisão dos trabalhos submetidos, o autor de contacto (que submeteu o trabalho para a conferência) será notificado do resultado da apreciação. Os autores cujos trabalhos forem aceites devem seguir as recomendações dos revisores de melhoria dos seus trabalhos antes de submeterem a versão final dos mesmos.&lt;br /&gt;
&lt;br /&gt;
= Publicações =&lt;br /&gt;
&lt;br /&gt;
Todos os trabalhos aceites serão publicados na acta de conferência, com uma identificação ISBN. A acta da conferência será publicada pela OWASP em formato electrónico ('''a edição pela Springer foi cancelada devido ao número baixo de submissões recebidas''').&lt;br /&gt;
&lt;br /&gt;
== Site de Web ==&lt;br /&gt;
&lt;br /&gt;
http://www.ibwas.com&lt;br /&gt;
&lt;br /&gt;
== Secretariado ==&lt;br /&gt;
&lt;br /&gt;
Endereço de correio electrónico: secretariat@ibwas.com&lt;br /&gt;
&lt;br /&gt;
== Datas importantes ==&lt;br /&gt;
&lt;br /&gt;
Submissão de trabalhos: '''31 de Outubro de 2010'''&lt;br /&gt;
&lt;br /&gt;
Notificação de Aceitação: '''28 de Novembro de 2010'''&lt;br /&gt;
&lt;br /&gt;
Versão final dos trabalhos aceites: '''5 de Dezembro de 2010'''&lt;br /&gt;
&lt;br /&gt;
Conferência: '''16 e 17 de Dezembro de 2010'''&lt;br /&gt;
&lt;br /&gt;
=== Call for Papers (spanish version) ===&lt;br /&gt;
&lt;br /&gt;
== Introducción ==&lt;br /&gt;
&lt;br /&gt;
Existen importantes cambios en el paradigma del desarrollo de los sistemas de información. La aparición de tecnologías Web 2.0 ha permitido el desarrollo e implantación de forma masiva de aplicaciones y servicios web como una manera de desarrollar nuevos y flexibles sistemas de información. Estos sistemas son fáciles de desarrollar, implementar y mantener, además de aportar atractivas características para los usuarios favoreciendo así el uso masivo que encontramos actualmente.&lt;br /&gt;
&lt;br /&gt;
Como resultado de este cambio de paradigma, los requisitos de seguridad también han cambiado. Estos sistemas de información basados en la Web tienen diferentes requisitos de seguridad en comparación con los sistemas tradicionales. Se han identificado los aspectos de seguridad más importantes y la privacidad también es un problema que se ha planteado recientemente. Además, el emergente paradigma Cloud Computing promete una mayor flexibilidad; sin embargo, los problemas de seguridad y privacidad aún necesitan ser revisados. El entorno de seguridad debería implicar no sólo al ambiente circundante, sino también el núcleo de la aplicación.&lt;br /&gt;
&lt;br /&gt;
Esta conferencia pretende reunir a expertos en seguridad de aplicaciones, investigadores, educadores y profesionales de la industria, el sector académico  y comunidades internacionales, como OWASP, con el fin de discutir los problemas abiertos y nuevas soluciones en seguridad de aplicaciones. En este contexto, los investigadores académicos serán capaces de combinar resultados interesantes con la experiencia de los profesionales y los ingenieros de software.&lt;br /&gt;
&lt;br /&gt;
== Temas de la Conferencia ==&lt;br /&gt;
&lt;br /&gt;
Los temas sugeridos para el envío de presentaciones incluyen (pero no estan limitados a):&lt;br /&gt;
&lt;br /&gt;
* Desarrollo seguro de aplicaciones &lt;br /&gt;
* Seguridad en arquitecturas orientadas a servicios&lt;br /&gt;
* Seguridad en frameworks de desarrollo&lt;br /&gt;
* Modelado de amenazas en aplicaciones Web&lt;br /&gt;
* Seguridad en Cloud Computing&lt;br /&gt;
* Vulnerabilidades y Anaĺisis de aplicaciones Web (revisión de código, pruebas de intrusión, análisis estático, etc.)&lt;br /&gt;
* Métricas para seguridad en aplicaciones&lt;br /&gt;
* Soluciones y recomendaciones para las vulnerabilidades en aplicaciones Web&lt;br /&gt;
* Técnicas de codificación segura&lt;br /&gt;
* Características de seguridad de la plataforma o lenguaje que ayuda a incrementar el nivel de seguridad en las aplicaciones Web&lt;br /&gt;
* Uso seguro de bases de datos en aplicaciones Web&lt;br /&gt;
* Control de acceso en aplicaciones Web&lt;br /&gt;
* Seguridad en servicios Web&lt;br /&gt;
* Seguridad en navegadores Web&lt;br /&gt;
* Privacidad en las aplicaciones Web&lt;br /&gt;
* Estándares, certificaciones y criterios de evaluación de la seguridad para aplicaciones Web&lt;br /&gt;
* Sensibilización y educación sobre seguridad en aplicaciones&lt;br /&gt;
* Seguridad para la Web móvil&lt;br /&gt;
* Ataques y explotación de vulnerabilidades&lt;br /&gt;
&lt;br /&gt;
== Instrucciones para el envío de presentaciones ==&lt;br /&gt;
&lt;br /&gt;
Los autores deben presentar un documento original en inglés, tras revisar cuidadosamente la gramática y ortografía, utilizando el procedimiento de envío on-line. Por favor, compruebe las características del documento ya que debe ser consciente del límite de páginas aceptadas (12 páginas, de acuerdo a una plantilla que se facilita y que pueden descargar desde aquí [ftp://ftp.springer.de/pub/tex/latex/llncs/word/LNCS-Office2007.zip en formato Word]).&lt;br /&gt;
&lt;br /&gt;
Las directrices para el formato del documento facilitadas en el sitio web de la conferencia deben ser seguidas estrictamente para todos los trabajos presentados. El formato de presentación es el mismo que el formato final para impresión. Por favor revise y siga cuidadosamente las instrucciones y las plantillas proporcionadas.&lt;br /&gt;
&lt;br /&gt;
Cada trabajo debe indicar claramente la naturaleza de su contribución técnica/científica, y los problemas, dominios o entornos en los que es aplicable.&lt;br /&gt;
&lt;br /&gt;
Los trabajos que estén fuera del alcance de conferencias o puedan contener cualquier forma de plagio serán descartados directamente.&lt;br /&gt;
&lt;br /&gt;
Comentarios sobre el procedimiento de presentación on-line:&lt;br /&gt;
&lt;br /&gt;
1. Se utilizará un método de revisión anónimo, que será repetido al menos por dos revisores. Para facilitar esto, se ruega a los autores que proporcionen el trabajo sin ninguna referencia a los autores. Esto significa que es necesario eliminar los datos personales del autor, la sección de agradecimientos y toda referencia que pueda revelar la identidad de los autores.&lt;br /&gt;
&lt;br /&gt;
2. Se aceptan documentos en formato: ODF, PDF, DOC, DOCX o RTF.&lt;br /&gt;
&lt;br /&gt;
3. El procedimiento de presentación Web automáticamente envía un acuse de recibo, por correo electrónico, al autor de contacto.&lt;br /&gt;
&lt;br /&gt;
= Tipos de envío de presentaciones = &lt;br /&gt;
&lt;br /&gt;
'''Envío de presentaciones normales'''&lt;br /&gt;
&lt;br /&gt;
Una presentación normal presenta un trabajo donde la investigación se ha completado o casi finalizado. Esto no necesariamente significa que la aceptación sea sobre un trabajo completo. Puede ser aceptado como un &amp;quot;trabajo completo&amp;quot; (30 min. de presentación oral), un &amp;quot;trabajo corto&amp;quot; (15 min. de presentación oral) o &amp;quot;poster&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
'''Envío de presentaciones de posición'''&lt;br /&gt;
&lt;br /&gt;
Una presentación de posición presenta una opinión discutible sobre un tema. El objetivo de un trabajo de posición es convencer a la audiencia que su opinión es válida y merece la pena ser escuchada, sin la necesidad de presentar un trabajo de investigación finalizado y/o los resultados validados. Es importante, sin embargo, apoyar su argumento con evidencias para asegurar la validez de sus opiniones. Un trabajo de posición puede ser un breve documento y discusión de ideas, hechos, situaciones, métodos, procedimientos o resultados de la investigación científica (bibliográfica, experimental, teórico o de otro tipo) centrado en uno de los temas de la conferencia. La aceptación de una presentación de posición se limita a las categorías de &amp;quot;trabajo corto&amp;quot; o &amp;quot;poster&amp;quot;, es decir, una presentación de posición no es candidata para ser aceptada como &amp;quot;trabajo completo&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
= Versión Final =&lt;br /&gt;
&lt;br /&gt;
Después de que el proceso de revisión se complete, el autor de contacto (el autor que presenta el documento) de cada trabajo será notificado del resultado, por correo electrónico. Los autores están obligados a seguir las revisiones con el objetivo de mejorar su trabajo antes del envío de la versión final.&lt;br /&gt;
&lt;br /&gt;
= Publicaciones =&lt;br /&gt;
&lt;br /&gt;
Todos los trabajos aceptados serán publicados por OWASP en los materiales de las conferencias, bajo una referencia ISBN.&lt;br /&gt;
&lt;br /&gt;
== Sitio de las Conferencias ==&lt;br /&gt;
&lt;br /&gt;
http://www.ibwas.com&lt;br /&gt;
&lt;br /&gt;
== Secretaría ==&lt;br /&gt;
&lt;br /&gt;
Dirección de correo electrónicio: secretariat@ibwas.com&lt;br /&gt;
&lt;br /&gt;
== Fechas importantes ==&lt;br /&gt;
&lt;br /&gt;
Envío de presentaciones: '''31 de Octubre de 2010'''&lt;br /&gt;
&lt;br /&gt;
Notificación de aceptación: '''28 de Noviembre de 2010'''&lt;br /&gt;
&lt;br /&gt;
Versión final de presentaciones aceptadas: '''5 de Deciembre de 2010'''&lt;br /&gt;
&lt;br /&gt;
Conferencias: '''16 y 17 de Deciembre de 2010'''&lt;br /&gt;
&lt;br /&gt;
==== Organization and Program Committee  ====&lt;br /&gt;
&lt;br /&gt;
=== IBWAS'10 Chairs  ===&lt;br /&gt;
&lt;br /&gt;
'''Carlos Serrão''', ISCTE-IUL Instituto Universitário de Lisboa, OWASP Portugal, Portugal&lt;br /&gt;
&lt;br /&gt;
'''Vicente Aguilera Díaz''', Internet Security Auditors, OWASP Spain, Spain&lt;br /&gt;
&lt;br /&gt;
=== IBWAS'10 Organization  ===&lt;br /&gt;
'''Fabio Cerullo''', OWASP Global Education Committee, Ireland&lt;br /&gt;
&lt;br /&gt;
'''Dinis Cruz''', OWASP Board Member, UK&lt;br /&gt;
&lt;br /&gt;
'''Paulo Coimbra''', OWASP Project Manager, UK&lt;br /&gt;
&lt;br /&gt;
'''Miguel Correia''', Universidade de Lisboa, Portugal&lt;br /&gt;
&lt;br /&gt;
'''Paulo Sousa''', Universidade de Lisboa, Portugal&lt;br /&gt;
&lt;br /&gt;
'''Lucas C. Ferreira''', Câmara dos Deputados, Brasil&lt;br /&gt;
&lt;br /&gt;
'''Arturo &amp;quot;Buanzo&amp;quot; Busleiman''', OWASP Argentina, Argentina&lt;br /&gt;
&lt;br /&gt;
'''Martin Tartarelli''', OWASP Argentina, Argentina&lt;br /&gt;
&lt;br /&gt;
'''Paulo Querido''', Portugal&lt;br /&gt;
&lt;br /&gt;
=== IBWAS'10 Program Committee  ===&lt;br /&gt;
&lt;br /&gt;
'''André Zúquete''', Universidade De Aveiro, Portugal&amp;lt;br&amp;gt; '''Candelaria Hernández-Goya''', Universidad De La Laguna, Spain&amp;lt;br&amp;gt; '''Carlos Costa''', Universidade De Aveiro, Portugal&amp;lt;br&amp;gt; '''Carlos Ribeiro''', Instituto Superior Técnico, Portugal&amp;lt;br&amp;gt; '''Eduardo Neves''', OWASP Education Committee, OWASP Brazil, Brazil&amp;lt;br&amp;gt; '''Francesc Rovirosa i Raduà''', Universitat Oberta de Catalunya (UOC), Spain&amp;lt;br&amp;gt; '''Gonzalo Álvarez Marañón''', Consejo Superior de Investigaciones Científicas (CSIC), Spain&amp;lt;br&amp;gt; '''Isaac Agudo''', University of Malaga, Spain&amp;lt;br&amp;gt; '''Jaime Delgado''', Universitat Politecnica De Catalunya, Spain&amp;lt;br&amp;gt; '''Javier Hernando''', Universitat Politecnica De Catalunya, Spain&amp;lt;br&amp;gt; '''Javier Rodríguez Saeta''', Herta Security, Spain&amp;lt;br&amp;gt; '''Joaquim Castro Ferreira''', Universidade de Aveiro, Portugal&amp;lt;br&amp;gt; '''Joaquim Marques''', Instituto Politécnico de Castelo Branco, Portugal&amp;lt;br&amp;gt; '''Jorge Dávila Muro''', Universidad Politécnica de Madrid (UPM), Spain&amp;lt;br&amp;gt; '''Jorge E. López de Vergara''', Universidad Autónoma de Madrid, Spain&amp;lt;br&amp;gt; '''José Carlos Metrôlho''', Instituto Politécnico de Castelo Branco, Portugal&amp;lt;br&amp;gt; '''José Luis Oliveira''', Universidade De Aveiro, Portugal&amp;lt;br&amp;gt; '''Kuai Hinojosa''', OWASP Global Education Committee, New York University, United States&amp;lt;br&amp;gt; '''Leonardo Chiariglione''', Cedeo, Italy&amp;lt;br&amp;gt; '''Leonardo Lemes''', Unisinos, Brasil&amp;lt;br&amp;gt; '''Manuel Sequeira''', ISCTE-IUL Instituto Universitário de Lisboa, Portugal&amp;lt;br&amp;gt; '''Marco Vieira''', Universidade de Coimbra, Portugal&amp;lt;br&amp;gt; '''Mariemma I. Yagüe''', University of Málaga, Spain&amp;lt;br&amp;gt; '''Miguel Correia''', Universidade de Lisboa, Portugal&amp;lt;br&amp;gt; '''Miguel Dias''', Microsoft, Portugal&amp;lt;br&amp;gt; '''Nuno Neves''', Universidade de Lisboa, Portugal&amp;lt;br&amp;gt; '''Osvaldo Santos''', Instituto Politécnico de Castelo Branco, Portugal&amp;lt;br&amp;gt; '''Panos Kudumakis''', Queen Mary University of London, United Kingdom&amp;lt;br&amp;gt; '''Paulo Sousa''', Universidade de Lisboa, Portugal&amp;lt;br&amp;gt; '''Rodrigo Roman''', University of Malaga, Spain&amp;lt;br&amp;gt; '''Rui Cruz''', Instituto Superior Técnico, Portugal&amp;lt;br&amp;gt; '''Rui Marinheiro''', ISCTE-IUL Instituto Universitário de Lisboa, Portugal&amp;lt;br&amp;gt; '''Sérgio Lopes''', Universidade do Minho, Portugal&amp;lt;br&amp;gt; '''Tiejun Huang''', Pekin University, China&amp;lt;br&amp;gt; '''Víctor Villagrá''', Universidad Politécnica de Madrid (UPM), Spain&amp;lt;br&amp;gt; '''Vitor Filipe''', Universidade de Trás-os-Montes e Alto Douro, Portugal&amp;lt;br&amp;gt; '''Vitor Santos''', Microsoft, Portugal&amp;lt;br&amp;gt; '''Vitor Torres''', Universitat Pompeu Fabra, Spain&amp;lt;br&amp;gt; '''Wagner Elias''', OWASP Brazil Chapter Leader, Brazil &lt;br /&gt;
&lt;br /&gt;
==== Registration  ====&lt;br /&gt;
&lt;br /&gt;
== Important Dates ==&lt;br /&gt;
&lt;br /&gt;
Submission of papers and all other contributions due: '''31st October 2010'''&lt;br /&gt;
&lt;br /&gt;
Notification of acceptance: '''28th November 2010'''&lt;br /&gt;
&lt;br /&gt;
Camera-ready version of accepted contributions: '''5th December 2010'''&lt;br /&gt;
&lt;br /&gt;
Conference: '''16th – 17th December 2010'''&lt;br /&gt;
&lt;br /&gt;
Registration will be available as soon as possible. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 16th December  ====&lt;br /&gt;
&lt;br /&gt;
{{Template:&amp;lt;includeonly&amp;gt;{{{1}}}&amp;lt;/includeonly&amp;gt;&amp;lt;noinclude&amp;gt;OWASP Training&amp;lt;/noinclude&amp;gt;&lt;br /&gt;
| Course_designation = OWASP Projects and Resources you can use TODAY!&lt;br /&gt;
&lt;br /&gt;
| Course_Overview_Goal &lt;br /&gt;
=&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
*Apart from OWASP's Top 10, most [[:Category:OWASP_Project|OWASP Projects]] are not widely used and understood. In most cases this is not due to lack of quality and usefulness of those Document &amp;amp; Tool projects, but due to a lack of understanding of where they fit in an Enterprise's security ecosystem or in the Web Application Development Life-cycle.&lt;br /&gt;
&lt;br /&gt;
*This course aims to change that by providing a selection of mature and enterprise ready projects together with practical examples of how to use them.&lt;br /&gt;
&lt;br /&gt;
*If you are interested in participating in the hands on portion of the course, please bring a laptop.&lt;br /&gt;
&lt;br /&gt;
&amp;amp;nbsp;&lt;br /&gt;
| Date = December 16, 2010&lt;br /&gt;
| Venue = [http://www.iscte.pt/ ISCTE - Lisbon University Institute] &lt;br /&gt;
| Price = Free&lt;br /&gt;
| Course_Registration_url = www.&lt;br /&gt;
| Course_Registration_name = To be created&lt;br /&gt;
| Modules = &lt;br /&gt;
&lt;br /&gt;
{{Template:Training_Module_Row_View&lt;br /&gt;
| Time = 09h00 (30m)&lt;br /&gt;
| Module_Name = Guided tour of OWASP Projects&lt;br /&gt;
| Module_Link = http://www.owasp.org/index.php/Category:OWASP_Project&lt;br /&gt;
| Trainer = [[user:Dinis.cruz|Dinis Cruz (OWASP Board)]] &lt;br /&gt;
| Presentation_Name = Tour of OWASP’s projects&lt;br /&gt;
| Presentation_Link = http://www.owasp.org/index.php/File:OWASP_India_-_Tour_of_OWASP_projects.ppt  &lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Template:Training_Module_Row_View&lt;br /&gt;
| Time = 09h30 (60m)&lt;br /&gt;
| Module_Name = OWASP Top 10&lt;br /&gt;
| Module_Link = http://www.owasp.org/index.php/GPC_Project_Details/OWASP_Top10&lt;br /&gt;
| Trainer = [[user:John.wilander|John Wilander (OWASP Sweden Chapter Leader)]] &lt;br /&gt;
| Presentation_Name = OWASP Top 10 2010 from a Developer's Perspective&lt;br /&gt;
| Presentation_Link = http://www.owasp.org/index.php/OWASP/Training/OWASP_Top_10  &lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Template:Training Module Row Break&lt;br /&gt;
| Time = 10h30 (15m)&lt;br /&gt;
| Break_Reason = Coffee Break&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Template:Training_Module_Row_View&lt;br /&gt;
| Time = 10h45 (60m)&lt;br /&gt;
| Module_Name = &lt;br /&gt;
| Module_Link = &lt;br /&gt;
| Trainer = [[user:Knoblochmartin|Martin Knobloch (OWASP Netherlands Chapter Leader)]] &lt;br /&gt;
| Presentation_Name = &lt;br /&gt;
| Presentation_Link =   &lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Template:Training_Module_Row_View&lt;br /&gt;
| Time = 11h45 (75m)&lt;br /&gt;
| Module_Name = &lt;br /&gt;
| Module_Link = &lt;br /&gt;
| Trainer =  &lt;br /&gt;
| Presentation_Name = &lt;br /&gt;
| Presentation_Link =   &lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Template:Training Module Row Break&lt;br /&gt;
| Time = 13h00 (60m)&lt;br /&gt;
| Break_Reason = Lunch&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Template:Training_Module_Row_View&lt;br /&gt;
| Time = 14h00 (150m)&lt;br /&gt;
| Module_Name = Implementation of Enigform for Wordpress&lt;br /&gt;
| Module_Link = http://www.owasp.org/index.php/Category:OWASP_OpenPGP_Extensions_for_HTTP_-_Enigform_and_mod_openpgp&lt;br /&gt;
| Trainer = [[user:Buanzo|Arturo 'Buanzo' Busleiman (Project Leader)]]&lt;br /&gt;
| Presentation_Name = Wordpress Plugin for Enigform Authentication - Definitive Guide&lt;br /&gt;
| Presentation_Link = http://wiki.buanzo.org/index.php?n=Main.Wp-enigform-authentication   &lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Template:Training Module Row Break&lt;br /&gt;
| Time = 16h30 (15m)&lt;br /&gt;
| Break_Reason = Coffee Break&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
{{Template:Training_Module_Row_View&lt;br /&gt;
| Time = 16h45 (30m)&lt;br /&gt;
| Module_Name = OWASP O2 Platform&lt;br /&gt;
| Module_Link = http://www.owasp.org/index.php/OWASP_O2_Platform&lt;br /&gt;
| Trainer = [[user:Dinis.cruz|Dinis Cruz (Project Leader)]] &lt;br /&gt;
| Presentation_Name = What is the OWASP O2 Platform&lt;br /&gt;
| Presentation_Link = http://www.o2-ounceopen.com/files-binaries-source-and-demo/old-documents-and-presentations/OWASP_O2_Platform_-_AppSec_Ireland_Sep_2009.pdf &lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== 17th December  ====&lt;br /&gt;
&lt;br /&gt;
This is still a draft agenda!&lt;br /&gt;
&lt;br /&gt;
{| cellspacing=&amp;quot;1&amp;quot; cellpading=&amp;quot;1&amp;quot; border=&amp;quot;0&amp;quot; bgcolor=&amp;quot;#dddddd&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
|- valign=&amp;quot;middle&amp;quot;&lt;br /&gt;
| height=&amp;quot;60&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;3&amp;quot; style=&amp;quot;background: rgb(64, 88, 160) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font size=&amp;quot;3&amp;quot;&amp;gt;'''Dec 17th 2010'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|- valign=&amp;quot;middle&amp;quot;&lt;br /&gt;
| width=&amp;quot;100&amp;quot; bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; | 9:00 - 9:30&lt;br /&gt;
| bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; | Registration (Welcome Desk)&lt;br /&gt;
|- valign=&amp;quot;middle&amp;quot;&lt;br /&gt;
| width=&amp;quot;100&amp;quot; bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; | 9:00 - 10:00&lt;br /&gt;
| bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; | Opening Ceremony&lt;br /&gt;
|- valign=&amp;quot;middle&amp;quot;&lt;br /&gt;
| width=&amp;quot;100&amp;quot; bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; | 10:00 - 11:00&lt;br /&gt;
| bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; | Keynote Speech&lt;br /&gt;
|- valign=&amp;quot;middle&amp;quot;&lt;br /&gt;
| width=&amp;quot;100&amp;quot; bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; | 11:00 - 11:15&lt;br /&gt;
| bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; | Coffee Break&lt;br /&gt;
|- valign=&amp;quot;middle&amp;quot;&lt;br /&gt;
| height=&amp;quot;120&amp;quot; width=&amp;quot;100&amp;quot; bgcolor=&amp;quot;#ffcc99&amp;quot; align=&amp;quot;center&amp;quot; | 11:15 - 13:00&lt;br /&gt;
| width=&amp;quot;300&amp;quot; bgcolor=&amp;quot;#ffcc99&amp;quot; align=&amp;quot;center&amp;quot; | Presentation Session&lt;br /&gt;
| width=&amp;quot;300&amp;quot; bgcolor=&amp;quot;#ffcc99&amp;quot; align=&amp;quot;center&amp;quot; | Presentation Session &lt;br /&gt;
|- valign=&amp;quot;middle&amp;quot;&lt;br /&gt;
| height=&amp;quot;80&amp;quot; width=&amp;quot;100&amp;quot; bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; | 13:00 - 14:30&lt;br /&gt;
| bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; | Lunch Break&lt;br /&gt;
|- valign=&amp;quot;middle&amp;quot;&lt;br /&gt;
| width=&amp;quot;100&amp;quot; bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; | 14:30 - 15:30&lt;br /&gt;
| bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; | Keynote Speech&lt;br /&gt;
|- valign=&amp;quot;middle&amp;quot;&lt;br /&gt;
| height=&amp;quot;120&amp;quot; width=&amp;quot;100&amp;quot; bgcolor=&amp;quot;#ffcc99&amp;quot; align=&amp;quot;center&amp;quot; | 15:30 - 17:00&lt;br /&gt;
| width=&amp;quot;300&amp;quot; bgcolor=&amp;quot;#ffcc99&amp;quot; align=&amp;quot;center&amp;quot; | Paper Session (3 papers)&lt;br /&gt;
| width=&amp;quot;300&amp;quot; bgcolor=&amp;quot;#ffcc99&amp;quot; align=&amp;quot;center&amp;quot; | Paper Session (3 papers)&lt;br /&gt;
|- valign=&amp;quot;middle&amp;quot;&lt;br /&gt;
| width=&amp;quot;100&amp;quot; bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; | 17:00 - 17:15&lt;br /&gt;
| bgcolor=&amp;quot;#ffff99&amp;quot; align=&amp;quot;center&amp;quot; colspan=&amp;quot;2&amp;quot; | Coffee Break&lt;br /&gt;
|- valign=&amp;quot;middle&amp;quot;&lt;br /&gt;
| height=&amp;quot;120&amp;quot; width=&amp;quot;100&amp;quot; width=&amp;quot;100&amp;quot; bgcolor=&amp;quot;#ffcc99&amp;quot; align=&amp;quot;center&amp;quot; | 17:15 - 19:00&lt;br /&gt;
| width=&amp;quot;300&amp;quot; bgcolor=&amp;quot;#ffcc99&amp;quot; align=&amp;quot;center&amp;quot; | Presentation Session&lt;br /&gt;
| width=&amp;quot;300&amp;quot; bgcolor=&amp;quot;#ffcc99&amp;quot; align=&amp;quot;center&amp;quot; | Presentation Session&lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Keynote:  ==&lt;br /&gt;
&lt;br /&gt;
'''Professor Carlos Ribeiro''' &lt;br /&gt;
&lt;br /&gt;
[[File:carlosribeiro.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.ist.utl.pt/ Instituto Superior Técnico], [http://www.utl.pt/ Universidade Técnica de Lisboa], Portugal&lt;br /&gt;
&lt;br /&gt;
== Talk: The Thing That Should Not Be (a glimpse into the future of web application security) ==&lt;br /&gt;
&lt;br /&gt;
'''Bruno Morisson''' &lt;br /&gt;
&lt;br /&gt;
[[File:brunomorisson.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.integrity.pt/ Integrity, S.A.], Portugal&lt;br /&gt;
&lt;br /&gt;
Developers are not security practicioners. Security practitioners are not developers. Developers create web applications. Security practitioners want those apps to be secure (sometimes even if security breaks functionality).&lt;br /&gt;
Are developers and security practitioners like oil and water ? Are security practitioners taking the right approach to help web developers understand and prevent security issues, or are we simply trying to brute force developers into security gurus ?&lt;br /&gt;
&lt;br /&gt;
== Talk: Developing Secure Applications with OWASP  ==&lt;br /&gt;
&lt;br /&gt;
'''Martin Knobloch'''&lt;br /&gt;
&lt;br /&gt;
[[File:martinknobloch.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.sogeti.nl/ Sogeti Netherlands], [http://www.owasp.org/index.php/Netherlands OWASP Netherlands], Netherlands&lt;br /&gt;
&lt;br /&gt;
After an introduction about OWASP, Martin will higlight the top projects of OWASP. During the presentation Martin does explain how OWASP material can be used to raise awareness about secure appliation development and how OWASP material does fit into a (secure) development lifecycle.&lt;br /&gt;
&lt;br /&gt;
== Talk: Developing compliant applications  ==&lt;br /&gt;
&lt;br /&gt;
'''Martin Knobloch'''&lt;br /&gt;
&lt;br /&gt;
[[File:martinknobloch.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.sogeti.nl/ Sogeti Netherlands], [http://www.owasp.org/index.php/Netherlands OWASP Netherlands], Netherlands&lt;br /&gt;
&lt;br /&gt;
How to develop applications to be compliant to security related laws and regulations?&lt;br /&gt;
To be compliant means to follow the regulations, most of the times not known by the developers. To be compliant includes to proof to be compliant.&lt;br /&gt;
This presentation is about how to develop compliant (Web) applications that prove to be compliant!&lt;br /&gt;
&lt;br /&gt;
== Talk: Software Security in the Clouds  ==&lt;br /&gt;
&lt;br /&gt;
'''Miguel Correia'''&lt;br /&gt;
&lt;br /&gt;
[[File:miguelcorreia.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.ul.pt/ University of Lisboa], [http://www.fc.ul.pt/ Faculty of Sciences], Portugal&lt;br /&gt;
&lt;br /&gt;
Recently an expert wrote rather enfatically that &amp;quot;the current state of security in commercial software is rather distasteful, marked by embarrassing public reports of vulnerabilities and actual attacks&amp;quot;. This situation is particularly concerning in times when companies are exporting their applications and data to cloud computing systems. The first part of the talk will be a personal vision of the combination of techniques and tools needed for protecing software. The second part will argue that this combination is still insuficient for critical applications in the cloud and propose solutions based on distributing trust among different clouds.&lt;br /&gt;
&lt;br /&gt;
== Talk: Jiffy - A secure instant messenger  ==&lt;br /&gt;
&lt;br /&gt;
'''Arturo 'Buanzo' Busleiman'''&lt;br /&gt;
&lt;br /&gt;
[[File:arturobuanzo.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Argentina OWASP Argentina], Argentina&lt;br /&gt;
&lt;br /&gt;
Jiffy - &amp;quot;Just for you&amp;quot; is an instant messaging system baseed&lt;br /&gt;
on OWASP's Enigform, SSL and the OpenPGP Web-of-Trust. In this talk,&lt;br /&gt;
Buanzo will introduce us to OpenPGP, Enigform and Jiffy.&lt;br /&gt;
&lt;br /&gt;
==== Papers  ====&lt;br /&gt;
=== Papers  ===&lt;br /&gt;
Authors should submit an original paper in English, carefully checked for correct grammar and spelling, using the on-line submission procedure ([http://www.easychair.org/conferences/?conf=ibwas10 submission site]). Please check the paper formats so you may be aware of the accepted paper page limits (12 pages, in accordance to a supplied template, that can be downloaded from here: [ftp://ftp.springer.de/pub/tex/latex/llncs/word/LNCS-Office2007.zip in Word Format]). &lt;br /&gt;
&lt;br /&gt;
The guidelines for paper formatting provided at the conference web site must be strictly used for all submitted papers. The submission format is the same as the camera-ready format. Please check and carefully follow the instructions and templates provided.&lt;br /&gt;
&lt;br /&gt;
=== Accepted Papers  ===&lt;br /&gt;
&lt;br /&gt;
==== Speakers  ====&lt;br /&gt;
&lt;br /&gt;
=== Keynote Speakers  ===&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|'''Professor Carlos Ribeiro''' &lt;br /&gt;
&lt;br /&gt;
[[File:carlosribeiro.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.ist.utl.pt/ Instituto Superior Técnico], [http://www.utl.pt/ Universidade Técnica de Lisboa], Portugal &lt;br /&gt;
&lt;br /&gt;
|Carlos Ribeiro (Ph.D.) is Professor at the Computer and Information Systems Department at the IST/UTL, where he teaches Network Security, Computer Security, Security Protocols and Operating Systems courses. He has received his PhD degree in Computer Science in 2002 from IST/UTL. Carlos Ribeiro's main research area is Security. He is co-coordenator of the PhD in Information Security, and vice-president of IST computer and network unit. He has been a researcher at Inesc-id since 2002, where he is currently the leader of the Distributed Systems research Group. He has participated in several National and International research projects in computer and network security, and has been an active researcher in the e-voting field since 2002.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Panel Speakers  ===&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|'''Miguel Almeida'''&lt;br /&gt;
[[File:miguelalmeida.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.miguelalmeida.pt Independent Security Consultant], Portugal&lt;br /&gt;
&lt;br /&gt;
|Miguel Almeida is an independent computer and network security professional. He has been testing, reviewing and advising on information security for the last ten years. His work has been focused on financial institutions and it has included engagements where, for a broad view of information security, the technical side as well as the organizational and procedural sides have been analyzed.&lt;br /&gt;
Before becoming an independent consultant, Miguel was working with Deloitte and KPMG, where he was responsible for the information security practices in these companies. He was Senior Manager at Deloitte and, before, he was a Manager at KPMG.&lt;br /&gt;
His academic studies include Computer Engineering at Instituto Superior Técnico and he is a Microsoft Certified Professional [on Windows security].&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|'''Bruno Morisson'''&lt;br /&gt;
[[File:brunomorisson.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.integrity.pt/ Integrity, S.A.], Portugal&lt;br /&gt;
&lt;br /&gt;
|Bruno Morisson is a Consultant and Partner at INTEGRITY S.A., a&lt;br /&gt;
Consulting and Advisory firm focusing on Information Security&lt;br /&gt;
Management, Telecom Management and IT Governance, where he provides&lt;br /&gt;
consultancy, auditing and advisory services. In a past life he has&lt;br /&gt;
held positions as a Senior Information Security Consultant and as&lt;br /&gt;
Security Operations Manager, providing information security management&lt;br /&gt;
services to customers in the financial, public and energy sectors in&lt;br /&gt;
Portugal.&lt;br /&gt;
&lt;br /&gt;
For the last 12 years he's been involved in several areas of&lt;br /&gt;
Information Security, from consulting, architecture, engineering,&lt;br /&gt;
auditing and penetration testing, as well as integration of OpenSource&lt;br /&gt;
security solutions. He's been actively involved with the InfoSec&lt;br /&gt;
community in Portugal, being one of the founders of the portuguese&lt;br /&gt;
chapter of The Honeynet Project, leading the InfoSec-Pros-PT&lt;br /&gt;
mailing-list and currently helping gather the community in a monthly&lt;br /&gt;
informal meeting - Confraria Security&amp;amp;IT.&lt;br /&gt;
Bruno also holds several certifications in Information Security&lt;br /&gt;
(CISSP-ISSMP, CISA, ISO27001LA).&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|'''Luís Grangeia'''&lt;br /&gt;
[[File:luisgrangeia.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.sysvalue.pt/ Sysvalue, S.A.], Portugal&lt;br /&gt;
&lt;br /&gt;
|Luis Grangeia is Partner at SysValue, S.A., currently leading the company’s Information Systems Auditing practice. SysValue S.A. is a Portuguese Company focused on the reliability of Information Systems with practices in Auditing, Consulting, Integration, Training and Research and Development.&lt;br /&gt;
&lt;br /&gt;
Since 2001 he has been conducting IS audits and penetration tests to major national and foreign companies, such as Portugal Telecom, Banco Espírito Santo, Banco Santander, UNICRE, Direcção-Geral do Tesouro, among others. Luis also contributes occasionally to information security research, with an article of note on the technique of DNS cache snooping.&lt;br /&gt;
&lt;br /&gt;
Luis has attended Computer Science Engineering at Instituto Superior Técnico and currently holds the SANS GSNA, CISSP, CISA and ISO 27001 Lead Auditor certifications.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
|'''Francisco Rente'''&lt;br /&gt;
[[File:franciscorente.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.uc.pt/fctuc Faculdade de Ciência e Tecnologia], [http://www.uc.pt Universidade de Coimbra], Portugal&lt;br /&gt;
&lt;br /&gt;
|Francisco Nina Rente, is an enthusiast and an evangelist of information security, especially in matters of privacy. He had his BsC and MsC in Computer Science on University of Coimbra. Back in 2006, he founded CERT-IPN, a CSIRT team of IPN Institute, where he did R&amp;amp;D, consultancy and management of InfoSec until June of 2010. Francisco, is currently PhD student in University of Coimbra, where he works in &amp;quot;Malicious Stealth Communications&amp;quot;. Since July of 2010, Francisco is CEO of Dognædis, a company based in Portugal, focused in Information Security and Software Assurance.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|'''Martin Knobloch'''&lt;br /&gt;
[[File:martinknobloch.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.sogeti.nl/ Sogeti Netherlands], [http://www.owasp.org/index.php/Netherlands OWASP Netherlands], Netherlands&lt;br /&gt;
&lt;br /&gt;
|Martin Knobloch is employed at Sogeti Netherlands as Senior Security Consultant. He is founder and thought leader of the Sogeti task force  PaSS, Proactive Security Strategy, with an integral solution of information security within organisation, infrastructure and software.&lt;br /&gt;
At OWASP, Martin is board member of the OWASP Netherlands Chapter and member of the Global Education Committee.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|'''Miguel Correia'''&lt;br /&gt;
[[File:miguelcorreia.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.ul.pt/ University of Lisboa], [http://www.fc.ul.pt/ Faculty of Sciences], Portugal&lt;br /&gt;
&lt;br /&gt;
|Miguel Correia is Assistant Professor of the [http://www.di.fc.ul.pt/ Department of Informatics], [http://www.ul.pt/ University of Lisboa] [http://www.fc.ul.pt/ Faculty of Sciences], and Adjunct Faculty of the [http://www.cmu.edu/ Carnegie Mellon] [http://www.ini.cmu.edu/ Information Networking Institute]. He is a member of the [http://lasige.di.fc.ul.pt/ LASIGE] research unit and the [http://www.navigators.di.fc.ul.pt/ Navigators] research team. He has been involved in several international and national research projects related to intrusion tolerance and security, including the TCLOUDS, MAFTIA and CRUTIAL EC-IST projects, and the ReSIST NoE. He is currently the coordinator and an instructor of the joint Carnegie Mellon University and University of Lisboa [http://msi.di.fc.ul.pt/ MSc in Information Security]. He has more than 50 publications in international journals, conferences and workshops. He authored with Paulo Sousa a book titled &amp;quot;Segurança no Software&amp;quot; (FCA, 2010). More information about him is available at [http://www.di.fc.ul.pt/~mpc http://www.di.fc.ul.pt/~mpc].&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|'''Arturo 'Buanzo' Busleiman'''&lt;br /&gt;
[[File:arturobuanzo.jpg]]&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/Argentina OWASP Argentina], Argentina&lt;br /&gt;
&lt;br /&gt;
|Buanzo is a nerd. Yes, a so-called geek. Why? Simple: he started programming at the age of 8, got into information security by&lt;br /&gt;
12 (Oh, the BBS era...!) and now he performs as a Security Consultant&lt;br /&gt;
for the Argentinian Computer Emergency Response Team (ArCERT). If you&lt;br /&gt;
enjoy programming, Open Source Software, Linux and all things security&lt;br /&gt;
and geeky, you might enjoy one of his talks.&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==== Venue  ====&lt;br /&gt;
&lt;br /&gt;
IBWAS'10 will be taking place at the [http://www.iscte.pt ISCTE - Lisbon University Institute] in Lisbon, Portugal.&lt;br /&gt;
&lt;br /&gt;
== Location ==&lt;br /&gt;
Ed. ISCTE &amp;lt;br&amp;gt; Av. das Forças Armadas&amp;lt;br&amp;gt; 1600- Lisboa&amp;lt;br&amp;gt; Portugal&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
Find the [http://maps.google.com/maps?q=iscte,+lisboa,+portugal&amp;amp;hl=en&amp;amp;cd=1&amp;amp;ei=JFx0S_ScKYyGONOz1YkB&amp;amp;sig2=FsC9HEg2JrBD00ARc_U3IA&amp;amp;sll=38.724358,-9.148865&amp;amp;sspn=0.077408,0.150719&amp;amp;ie=UTF8&amp;amp;view=map&amp;amp;cid=7285641604236232209&amp;amp;ved=0CBgQpQY&amp;amp;hq=iscte,+lisboa,+portugal&amp;amp;hnear=&amp;amp;ll=38.749766,-9.154122&amp;amp;spn=0.009673,0.01884&amp;amp;t=h&amp;amp;z=16&amp;amp;iwloc=A location on Google Maps]. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;googlemap lat=&amp;quot;38.749565&amp;quot; lon=&amp;quot;-9.15277&amp;quot; zoom=&amp;quot;15&amp;quot;&amp;gt;&lt;br /&gt;
38.748862, -9.152384, ISCTE-IUL&lt;br /&gt;
&amp;lt;/googlemap&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.allofads.com/files/images/mapa_iscte.jpg&lt;br /&gt;
&lt;br /&gt;
== How to get there? ==&lt;br /&gt;
'''Car''' &lt;br /&gt;
* Go up the Av.ª das Forças Armadas.&lt;br /&gt;
* Turn north at the crossing with Av.ª Prof. Gama Pinto. The crossing is located at the highest point of Av.ª das Forças Armadas.&lt;br /&gt;
* Turn to the second street right.&lt;br /&gt;
* Turn to the first street right.&lt;br /&gt;
* The main entrance of ISCTE is at your left.&lt;br /&gt;
&lt;br /&gt;
'''Train''' &lt;br /&gt;
* Leave the train at the Entrecampus station. Look for the exit leading to Av.ª da República.&lt;br /&gt;
* Walk north for about 250 m towards the Rotunda de Entrecampus (a circle).&lt;br /&gt;
* At the circle, turn left to the Av.ª das Forças Armadas.&lt;br /&gt;
* Climb west for about 300 m towards Sete Rios. Use the sidewalk on the right.&lt;br /&gt;
* The entry leading to ISCTE will be at your right, immediatly after the canteen of the University of Lisbon.&lt;br /&gt;
&lt;br /&gt;
'''Bus''' &lt;br /&gt;
* Get on any [http://www.carris.pt/ Carris] bus with numbers [http://www.carris.pt/horarios/a054_1.pdf 54], [http://www.carris.pt/horarios/a701_1.pdf 701], or [http://www.carris.pt/horarios/a732_2.pdf 732].&lt;br /&gt;
* Leave the bus at the &amp;quot;Faculdade de Farmácia&amp;quot; stop, at the top of Av.ª das Forças Armadas, close to an old house with ia battlemented roof.&lt;br /&gt;
* Walk down the avenue for about 50 m. The entry leading to ISCTE will be at your left, immediatly before the canteen of the University of Lisbon.&lt;br /&gt;
&lt;br /&gt;
'''Subway''' &lt;br /&gt;
&lt;br /&gt;
''First alternative:'' &lt;br /&gt;
* Leave the train at the [http://www.metrolisboa.pt/portals/0/pdfs/mapasEstacoes/linhaAmarela/ec_aid.pdf Entrecampos] station. &lt;br /&gt;
* Exit the station through the north exit, leading to the Rotunda de Entrecampos (a circle), close to Av.ª das Forças Armadas. &lt;br /&gt;
* From the circle, go west, up the Av.ª das Forças Armadas, for about 300 m. &lt;br /&gt;
* Use the sidewalk on the right. &lt;br /&gt;
* The entry leading to ISCTE will be at your right, immediatly after the canteen of the University of Lisbon. &lt;br /&gt;
&lt;br /&gt;
''Second alternative:'' &lt;br /&gt;
* Leave the train at the [http://www.metrolisboa.pt/portals/0/pdfs/mapasEstacoes/linhaAmarela/cu_aid.pdf Cidade Universitária] station. &lt;br /&gt;
* Exit the station through the passage leading to Hospital de Santa Maria. &lt;br /&gt;
* Walk south, along the left sidewalk of Av.ª Prof. Gama Pinto, for about 150 m (i.e., walk towards the Av.ª das Forças Armadas). &lt;br /&gt;
* After the crossing with the Av.ª Prof. Egas Moniz (at your right), turn into the first street at your left. &lt;br /&gt;
* Turn to the first street right. &lt;br /&gt;
* The main entrance of ISCTE is at your left. &lt;br /&gt;
&lt;br /&gt;
Here is the representation of the walking on the map.&lt;br /&gt;
&lt;br /&gt;
http://www.allofads.com/files/images/mapa_iscte_1.jpg&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Links''' &lt;br /&gt;
&lt;br /&gt;
Metro: [http://www.metrolisboa.pt www.metrolisboa.pt] &amp;lt;br&amp;gt;&lt;br /&gt;
Buses [http://www.carris.pt www.carris.pt]&amp;lt;br&amp;gt;&lt;br /&gt;
Trains: [http://www.cp.pt www.cp.pt]&amp;lt;br&amp;gt;&lt;br /&gt;
Taxis: [http://www.antral.pt www.antral.pt] &lt;br /&gt;
&lt;br /&gt;
==== Hotels  ====&lt;br /&gt;
=== Hotels ===&lt;br /&gt;
This page contains information about the recommended hotels for the conference. All of the hotels are near to the conference place at a 5 to 15 minutes walking distance. PLease use the following reference when reserving your hotel: &amp;quot;'''Conferência IBWAS'10'''&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
== SANA Metropolitan Hotel **** ==&lt;br /&gt;
Rua Soeiro Pereira Gomes, Parcela 2, Entrecampos, 1600-198 Lisboa, Lisboa&lt;br /&gt;
&lt;br /&gt;
[[File:sanametro01.jpg]]&lt;br /&gt;
[[File:sanametro02.jpg]]&lt;br /&gt;
&lt;br /&gt;
Location on [http://maps.google.com/maps/ms?ie=UTF8&amp;amp;hl=pt-PT&amp;amp;msa=0&amp;amp;msid=104715835640056575562.00044cb43ee4b9e509aca&amp;amp;ll=38.748762,-9.159701&amp;amp;spn=0.009204,0.011802&amp;amp;z=16&amp;amp;iwloc=00044cb52de8286b65d85&amp;amp;source=embed Google Maps].&lt;br /&gt;
&lt;br /&gt;
Hotel [http://www.sanahotels.com/gca/index.php?hotelId=50&amp;amp;lng=en web-site].&lt;br /&gt;
&lt;br /&gt;
{|cellspacing=&amp;quot;1&amp;quot; cellpading=&amp;quot;1&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Room type'''&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Individual'''&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Double'''&lt;br /&gt;
|-&lt;br /&gt;
|bgcolor=&amp;quot;#eeeeee&amp;quot;|'''Standard'''&lt;br /&gt;
|67 euros&lt;br /&gt;
|72 euros&lt;br /&gt;
|-&lt;br /&gt;
|bgcolor=&amp;quot;#eeeeee&amp;quot;|'''Extra Bed'''&lt;br /&gt;
|30 euros&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Vip Executive Villa Rica Hotel **** ==&lt;br /&gt;
Av.5 de Outubro Nr. 295, Entrecampos, 1600-035 Lisboa (Lisboa)&lt;br /&gt;
&lt;br /&gt;
http://www.viphotels.com/Images/VIPExecutiveVillaRica/galeria/Exterior/01.jpg&lt;br /&gt;
&lt;br /&gt;
Location on [http://www.viphotels.com/pt/Hoteis/VipExecutive/VipExecutiveVillaRica/Localizacao.aspx Google Maps].&lt;br /&gt;
&lt;br /&gt;
Hotel [http://www.viphotels.com/pt/Hoteis/VipExecutive/VipExecutiveVillaRica/OHotel.aspx web-site].&lt;br /&gt;
&lt;br /&gt;
== NH Campo Grande **** ==&lt;br /&gt;
Campo Grande, 7, 1700-087 Lisboa, Lisboa&lt;br /&gt;
&lt;br /&gt;
http://www.nh-hoteles.pt/nh/hotel-gallery/1101383-t2-z2w.jpg&lt;br /&gt;
http://www.nh-hoteles.pt/nh/hotel-gallery/1101375-t2-z2w.jpg&lt;br /&gt;
&lt;br /&gt;
Location on [http://www.nh-hoteles.pt/nh/pt/hotels/portugal/lisbon/nh-campo-grande.html?type=location Google Maps].&lt;br /&gt;
&lt;br /&gt;
Hotel [http://www.nh-hoteles.pt/nh/pt/hotels/portugal/lisbon/nh-campo-grande.html web-site].&lt;br /&gt;
&lt;br /&gt;
{|cellspacing=&amp;quot;1&amp;quot; cellpading=&amp;quot;1&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Room type'''&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Individual'''&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Double'''&lt;br /&gt;
|-&lt;br /&gt;
|bgcolor=&amp;quot;#eeeeee&amp;quot;|'''Standard'''&lt;br /&gt;
|83 euros&lt;br /&gt;
|90 euros&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Hotel VIP Executive Zurique *** ==&lt;br /&gt;
Rua Ivone Silva 18, 1050 Lisboa&lt;br /&gt;
&lt;br /&gt;
http://www.viphotels.com/Images/VIPExecutiveZurique/galeria/Exterior/03.jpg&lt;br /&gt;
&lt;br /&gt;
http://www.viphotels.com/Images/VIPExecutiveZurique/galeria/Interior/05.jpg&lt;br /&gt;
&lt;br /&gt;
Location on [http://www.viphotels.com/pt/Hoteis/VipExecutive/VipExecutiveZurique/Localizacao.aspx Google Maps].&lt;br /&gt;
&lt;br /&gt;
Hotel [http://www.viphotels.com/pt/Hoteis/VipExecutive/VipExecutiveZurique/OHotel.aspx web-site].&lt;br /&gt;
&lt;br /&gt;
{|cellspacing=&amp;quot;1&amp;quot; cellpading=&amp;quot;1&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Room type'''&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Individual'''&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Double'''&lt;br /&gt;
|-&lt;br /&gt;
|bgcolor=&amp;quot;#eeeeee&amp;quot;|'''Standard'''&lt;br /&gt;
|65 euros&lt;br /&gt;
|70 euros&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Hotel Berna *** ==&lt;br /&gt;
Avenida António Serpa 13, 1069 Lisboa&lt;br /&gt;
&lt;br /&gt;
http://www.viphotels.com/Images/VIPInnBerna/galeria/Exterior/02.jpg&lt;br /&gt;
&lt;br /&gt;
http://www.viphotels.com/Images/VIPInnBerna/galeria/Interior/05.jpg&lt;br /&gt;
&lt;br /&gt;
Location on [http://www.viphotels.com/pt/Hoteis/VipInn/VipInnBerna/Localizacao.aspx Google Maps].&lt;br /&gt;
&lt;br /&gt;
Hotel [http://www.viphotels.com/pt/Hoteis/VipInn/VipInnBerna/OHotel.aspx web-site].&lt;br /&gt;
&lt;br /&gt;
{|cellspacing=&amp;quot;1&amp;quot; cellpading=&amp;quot;1&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Room type'''&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Individual'''&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Double'''&lt;br /&gt;
|-&lt;br /&gt;
|bgcolor=&amp;quot;#eeeeee&amp;quot;|'''Standard'''&lt;br /&gt;
|47,30 euros&lt;br /&gt;
|53,60 euros&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Holiday Inn Hotel Continental **** ==&lt;br /&gt;
Rua Laura Alves 9, 1050 Lisboa‎&lt;br /&gt;
&lt;br /&gt;
[[File:hinn01.jpg]]&lt;br /&gt;
[[File:hinn02.jpg]]&lt;br /&gt;
&lt;br /&gt;
Location on [http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=Rua+Laura+Alves,+9++1069-169+Lisboa+Portugal&amp;amp;sll=38.74144,-9.149605&amp;amp;sspn=0.039833,0.073471&amp;amp;ie=UTF8&amp;amp;hq=&amp;amp;hnear=R.+Laura+Alves+9,+Ns.+de+F%C3%A1tima,+1050+Lisbon,+Portugal&amp;amp;ll=38.741666,-9.149873&amp;amp;spn=0.009958,0.018368&amp;amp;t=h&amp;amp;z=16&amp;amp;iwloc=r1 Google Maps].&lt;br /&gt;
&lt;br /&gt;
Hotel [http://www.grupo-continental.com/home/index.php?option=com_content&amp;amp;view=article&amp;amp;id=55&amp;amp;Itemid=77 web-site].&lt;br /&gt;
&lt;br /&gt;
{|cellspacing=&amp;quot;1&amp;quot; cellpading=&amp;quot;1&amp;quot; border=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Room type'''&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Individual'''&lt;br /&gt;
|bgcolor=&amp;quot;#cccccc&amp;quot;|'''Double'''&lt;br /&gt;
|-&lt;br /&gt;
|bgcolor=&amp;quot;#eeeeee&amp;quot;|'''Standard'''&lt;br /&gt;
|78 euros&lt;br /&gt;
|88 euros&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Radisson Blu Lisboa **** ==&lt;br /&gt;
Av. Marechal Craveiro Lopes, 390, Entrecampos, Lisboa (Lisboa)&lt;br /&gt;
&lt;br /&gt;
http://www.hoteis.com/13/hotels/1000000/530000/524600/524550/hcom_524550_7_b.jpg&lt;br /&gt;
http://static.laterooms.com/hotelphotos/laterooms/179198/gallery/radisson-blu-lisboa-lisboa_250520090848039933.jpg&lt;br /&gt;
&lt;br /&gt;
Location on [http://www.radissonblu.com/hotel-lisbon/location Google Maps].&lt;br /&gt;
&lt;br /&gt;
Hotel [http://www.radissonblu.com/hotel-lisbon web-site].&lt;br /&gt;
&lt;br /&gt;
==== Sponsors  ====&lt;br /&gt;
&lt;br /&gt;
== Sponsors  ==&lt;br /&gt;
&lt;br /&gt;
We are currently soliciting sponsors for the IBWAS'10 Conference. Please refer to our '''[https://docs.google.com/fileview?id=0B6VV6XaEAb3dNjEzNDIyYTAtOTc3NC00Njg3LWIxNGQtZmEwYmYxNzEwMzRi&amp;amp;hl=en&amp;amp;authkey=CL_NweEF sponsorship opportunities]''' for details. &lt;br /&gt;
&lt;br /&gt;
Slots are going fast so [mailto:secretariat@ibwas.com contact us] to sponsor today! &lt;br /&gt;
&lt;br /&gt;
{| cellspacing=&amp;quot;10&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background: none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
== Sponsors  ==&lt;br /&gt;
&lt;br /&gt;
| [http://www.iscte.pt http://ibwas09.netmust.eu/files/iscte-iul.png] &lt;br /&gt;
| [http://www.adetti.pt http://ibwas09.netmust.eu/files/adetti.png] &lt;br /&gt;
| [http://www.isecauditors.com http://ibwas09.netmust.eu/files/pasted-graphic.jpg] &lt;br /&gt;
| [http://lasige.di.fc.ul.pt/ http://ibwas09.netmust.eu/files/lasige.png]&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbps;&lt;br /&gt;
| [http://www.maxdata.pt http://ibwas09.netmust.eu/files/ibwas10/maxdata.png]&lt;br /&gt;
| [http://www.noesis.pt http://ibwas09.netmust.eu/files/ibwas10/noesis.png]&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
== Media Sponsors ==&lt;br /&gt;
&lt;br /&gt;
|  [http://www.aeiou.pt http://ibwas09.netmust.eu/files/ibwas10/aeiou.png]&lt;br /&gt;
|  [http://www.borrmart.es/redseguridad.php http://ibwas09.netmust.eu/files/redseguridad.jpg]&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| &amp;amp;nbsp;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
== Supported by ==&lt;br /&gt;
&lt;br /&gt;
| [[Image:]] &lt;br /&gt;
| [[Image:]] &lt;br /&gt;
| [[Image:]]&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| [[Image:]] &lt;br /&gt;
| [[Image:]] &lt;br /&gt;
| [[Image:]]&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
| [[Image:]] &lt;br /&gt;
|  &lt;br /&gt;
| &lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|}&lt;br /&gt;
==== Tourism  ====&lt;br /&gt;
&lt;br /&gt;
=== Visit Lisbon ===&lt;br /&gt;
For Tourist Information and more: [http://www.visitlisboa.com/home.asp?lng=uk Visit Lisbon] (website of the Lisbon Tourism Office). See also [http://www.atl-turismolisboa.pt/home.asp?lng=uk here]. About Portugal, see [http://www.visitportugal.com/ here].&lt;br /&gt;
&lt;br /&gt;
LISBON is beautiful, historic, modern, sunny &amp;amp; it never stops! It is an enchanting city with delightful cuisine and unforgettable sites. The city holds many pleasant surprises to visitors who wish to enjoy their stay. The capital of Portugal since its conquest from the Moors in 1147, Lisbon is a legendary city with over 20 centuries of History. The Alfama is one of the oldest quarters in Lisbon. It survived the earthquake of 1755 and still retains much of its original layout. In addition to Alfama are the likewise old quarters of Castelo and Mouraria, on the western and northern slopes of the hill that is crowned by St. George's Castle. Radiant skies brighten the monumental city, with its typical tile covered building façades and narrow medieval streets, where one can hear the fado being played and sung at night.&lt;br /&gt;
&lt;br /&gt;
Here's a taste of what you can find here in Lisbon, or nearby.&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
 |-&lt;br /&gt;
 |'''Torre de Belém'''&lt;br /&gt;
 |'''Mosteiro dos Jerónimos'''&lt;br /&gt;
 |'''Ponte 25 de Abril'''&lt;br /&gt;
 |- &lt;br /&gt;
 |[[File:torredebelem.jpg]]&lt;br /&gt;
 |[[File:mosteirojeronimos.jpg]]&lt;br /&gt;
 |[[File:ponte21abril.jpg]]&lt;br /&gt;
 |- &lt;br /&gt;
 |'''Castelo de São Jorge'''&lt;br /&gt;
 |'''Alfama'''&lt;br /&gt;
 |'''Parque Eduardo VII'''&lt;br /&gt;
 |- &lt;br /&gt;
 |[[File:castelosjorge.jpg]]&lt;br /&gt;
 |[[File:algfama.jpg]]&lt;br /&gt;
 |[[File:parqueeduardo7.jpg]]&lt;br /&gt;
 |- &lt;br /&gt;
 |'''Aqueduto das Águas Livres'''&lt;br /&gt;
 |'''Museu dos Coches'''&lt;br /&gt;
 |'''Casa dos Bicos'''&lt;br /&gt;
 |- &lt;br /&gt;
 |[[File:aqueduto.jpg]]&lt;br /&gt;
 |[[File:coches.jpg]]&lt;br /&gt;
 |[[File:bicos.jpg]]&lt;br /&gt;
 |- &lt;br /&gt;
 |'''Parque das Nações'''&lt;br /&gt;
 |'''Oceanário'''&lt;br /&gt;
 |'''Pavilhão Multiusos'''&lt;br /&gt;
 |- &lt;br /&gt;
 |[[File:pnacoes.jpg]]&lt;br /&gt;
 |[[File:oceanario.jpg]]&lt;br /&gt;
 |[[File:multiusos.jpg]]&lt;br /&gt;
 |- &lt;br /&gt;
 |'''Cacilheiros'''&lt;br /&gt;
 |'''Linha de Cascais - Praias'''&lt;br /&gt;
 |'''Linha da Caparica - Praias'''&lt;br /&gt;
 |- &lt;br /&gt;
 |[[File:cacilheiros.jpg]]&lt;br /&gt;
 |[[File:cascais.jpg]]&lt;br /&gt;
 |[[File:caparica.jpg]]&lt;br /&gt;
 |- &lt;br /&gt;
 |'''Casino Lisboa'''&lt;br /&gt;
 |'''Docas - Diversão Nocturna'''&lt;br /&gt;
 |'''Fado'''&lt;br /&gt;
 |- &lt;br /&gt;
 |[[File:casino.jpg]]&lt;br /&gt;
 |[[File:docas.jpg]]&lt;br /&gt;
 |[[File:fado.jpg]]&lt;br /&gt;
 |- &lt;br /&gt;
 |'''Sintra Vila'''&lt;br /&gt;
 |'''Sintra - Palácio da Pena'''&lt;br /&gt;
 |'''Cristo Rei'''&lt;br /&gt;
 |- &lt;br /&gt;
 |[[File:sintravila.jpg]]&lt;br /&gt;
 |[[File:sintrapalacio.jpg]]&lt;br /&gt;
 |[[File:cristorei.jpg]]&lt;br /&gt;
 |- &lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== In the News  ====&lt;br /&gt;
&lt;br /&gt;
List of places where the IBWAS'10 conference has been referenced.&lt;br /&gt;
&lt;br /&gt;
*[http://ibwas09.netmust.eu/files/ibwas10/IBWAS-RedSeguridad.pdf RedSeguridad Magazine], September 2010&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== IBWAS'10 Internals ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* [https://spreadsheets.google.com/ccc?key=0AqVV6XaEAb3ddDI2ZkNsSjhDdWdQNl9ISW0tc19Sa3c&amp;amp;hl=en&amp;amp;authkey=CKyFt_AO Conference &amp;amp; Training's financials]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]] [[Category:OWASP_IBWAS]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Global_Education_Committee_-_Application_4&amp;diff=74042</id>
		<title>Global Education Committee - Application 4</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Global_Education_Committee_-_Application_4&amp;diff=74042"/>
				<updated>2009-11-24T19:47:22Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: buanzo recommendation for nishi kumar&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[How to Join a Committee|Click here to return to 'How to Join a Committee' page]] &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(64, 88, 160) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; colspan=&amp;quot;2&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE APPLICATION FORM'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 25%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Applicant's Name''' &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 85%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; colspan=&amp;quot;1&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;Nishi Kumar&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 25%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Current and past OWASP Roles''' &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 85%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; colspan=&amp;quot;1&amp;quot; | Contributor to OWASP Live CD and ESAPI.&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; width: 25%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''Committee Applying for''' &lt;br /&gt;
| align=&amp;quot;left&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 85%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; colspan=&amp;quot;1&amp;quot; | OWASP Global Education Committee.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
Please be aware that for an application to be considered by the board, '''you MUST have 5 recommendations'''. An incomplete application will not be considered for vote. &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(64, 88, 160) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; colspan=&amp;quot;8&amp;quot; | &amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE RECOMMENDATIONS'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: white none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&amp;lt;/font&amp;gt;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Who Recommends/Name'''&amp;lt;/font&amp;gt;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Role in OWASP'''&amp;lt;/font&amp;gt;&lt;br /&gt;
! align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(123, 138, 189) none repeat scroll 0% 0%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous; color: white;&amp;quot; | &amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Recommendation Content'''&amp;lt;/font&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 3%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''1''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 20%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Alexander Fry &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 20%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Reviewer of OWASP projects in SoC 2008 &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 57%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Nishi has valuable experience in creating application security computer based training courses. She will be a valuable contributor to the education committee.&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 3%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''2''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 20%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Brad Causey&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 20%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | GPC Member&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 57%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Nishi has proven to add much value in her participation in the OWASP Summit over the last few years. She is a great asset to OWASP as an organization and will be as well on the GEC.&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 3%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''3''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 20%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Arturo Busleiman aka Buanzo&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 20%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | Project Leader (Enigform), Paid Member&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 57%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | I met Nishi in Portugal during EU Summit 2008. We talked a lot and I think it just makes sense for her to take part of the GEC. I recommend her.&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 3%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''4''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 20%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 20%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 57%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 3%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | '''5''' &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 20%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 20%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
| align=&amp;quot;center&amp;quot; style=&amp;quot;background: rgb(204, 204, 204) none repeat scroll 0% 0%; width: 57%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Podcast_45&amp;diff=71619</id>
		<title>Podcast 45</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Podcast_45&amp;diff=71619"/>
				<updated>2009-10-16T12:19:59Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: /* Participants */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''[[OWASP_Podcast|OWASP Podcast Series]] #45'''&lt;br /&gt;
&lt;br /&gt;
OWASP Interview with Buanzo&amp;lt;br/&amp;gt;&lt;br /&gt;
Published October 16, 2009&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=300769012 http://www.owasp.org/download/jmanico/itunes.jpg] [http://www.owasp.org/download/jmanico/podcast.xml https://www.owasp.org/images/d/d3/Feed-icon-32x32.png] [http://www.owasp.org/download/jmanico/owasp_podcast_45.mp3 mp3]&lt;br /&gt;
&lt;br /&gt;
==Participants==&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;&amp;lt;b&amp;gt;Arturo &amp;quot;Buanzo&amp;quot; Busleiman&amp;lt;/b&amp;gt; is a native of Argentina who is most commonly known as Buanzo.  He is and old-school gnu+linux user that enjoys programming (mostly C and PHP), writing (technical and literature) and guitar playing.  He's had the pleasure of meeting Richard Stallman, Maddog Hall, Roger Dingledine (of the TOR project) and Vinton Cerf (no need to clarify he's the father of the Internet). Buanzo has a lovely wife, Erica, and a 6 year old son, called Damian, who was nicknamed Debian by the Argentinian FLOSS community.  He's the Project Leader of the award winning OWASP Enigform project along with many other open source software projects.&amp;lt;/li&amp;gt;&lt;br /&gt;
[http://www.buanzo.com.ar/pro/eng.html http://www.buanzo.com.ar/pro/eng.html]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Podcast_45&amp;diff=71618</id>
		<title>Podcast 45</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Podcast_45&amp;diff=71618"/>
				<updated>2009-10-16T12:12:13Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''[[OWASP_Podcast|OWASP Podcast Series]] #45'''&lt;br /&gt;
&lt;br /&gt;
OWASP Interview with Buanzo&amp;lt;br/&amp;gt;&lt;br /&gt;
Published October 16, 2009&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[http://itunes.apple.com/WebObjects/MZStore.woa/wa/viewPodcast?id=300769012 http://www.owasp.org/download/jmanico/itunes.jpg] [http://www.owasp.org/download/jmanico/podcast.xml https://www.owasp.org/images/d/d3/Feed-icon-32x32.png] [http://www.owasp.org/download/jmanico/owasp_podcast_45.mp3 mp3]&lt;br /&gt;
&lt;br /&gt;
==Participants==&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;&amp;lt;b&amp;gt;Arturo &amp;quot;Buanzo&amp;quot; Busleiman&amp;lt;/b&amp;gt; is a native of Argentina who is most commonly known as Buanzo.  He is and old-school gnu+linux user that enjoys programming (mostly C and PHP), writing (technical and literature) and guitar playing.  He's had the pleasure of meeting Richard Stallman, Maddog Hall, Roger Dingledine (of the TOR project) and Vinton Cerf. Buanzo has a lovely wife and  a 3+ year son, called Damian Ezequiel Busleiman Negri, who was nicknamed Debian by the Argentinian FOSS community.  He's the Project Leader of the award winning OWASP Enigform project along with many other open source software projects.&amp;lt;/li&amp;gt;&lt;br /&gt;
[http://www.buanzo.com.ar/pro/eng.html http://www.buanzo.com.ar/pro/eng.html]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Argentina&amp;diff=65911</id>
		<title>Argentina</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Argentina&amp;diff=65911"/>
				<updated>2009-07-14T13:49:57Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Argentina|extra=The chapter leader is [mailto:martin.tartarelli@gmail.com Martin Tartarelli]|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-argentina|emailarchives=http://lists.owasp.org/pipermail/owasp-argentina}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Argentina&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Sponsors ==&lt;br /&gt;
&lt;br /&gt;
Para información sobre el patrocinio de nuestros eventos y del capitulo Argentino por favor [mailto:martin.tartarelli@gmail.com contactese] con nosotros.&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Novedades ==&lt;br /&gt;
&lt;br /&gt;
* ''' Jun 2009 - Enigform en Trophees du Libre 2009 '''&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
[http://blogs.buanzo.com.ar/ Arturo 'Buanzo' Busleiman] fue seleccionado como uno de los tres finalistas en la categoria Seguridad de los [http://www.trophees-du-libre.org/content/blogcategory/16/51/ Trophees du Libre 2009] en el que obtuvo el segundo lugar con el proyecto [http://www.owasp.org/index.php/Category:OWASP_OpenPGP_Extensions_for_HTTP_-_Enigform_and_mod_openpgp Enigform y mod_openpgp]. Dicha herramienta permite la utilizacion de OpenPGP para construir un sistema de inicio y administración de sesiones web, así como verificacion de integridad de solicitudes y respuestas HTTP.&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* ''' Jun 2009 - Curso de Seguridad en Aplicaciones Web '''&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
Andrés Riancho de [http://www.bonsai-sec.com/ Bonsai Information Security], estará brindando un [http://www.bonsai-sec.com/es/education/web-security-buenos-aires.php curso de seguridad en aplicaciones Web] en el mes de Julio, en el cual los '''miembros de OWASP tienen un 20% de descuento'''. Para más información sobre el curso haga click [http://www.bonsai-sec.com/es/education/web-security-buenos-aires.php aquí].&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* ''' Nov 2008 - Primer Reunion de OWASP Argentina!!! '''&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
Cuando? El '''Jueves 27 de noviembre''' a partir de las 19hs.&amp;lt;br&amp;gt;&lt;br /&gt;
Donde? '''1745 Pub, Bartolome Mitre 1745. Capital Federal.'''&amp;lt;br&amp;gt;&lt;br /&gt;
Para? Divertirse, tomar algo y charlar.&amp;lt;br&amp;gt;&lt;br /&gt;
Como anotarse? Enviando un mail a la [http://lists.owasp.org/mailman/listinfo/owasp-argentina lista].&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* ''' Oct 2008 - OWASP NYC 2008 Videos Disponibles '''&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
Se encuentran disponibles los [https://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference videos] de la conferencia OWASP NYC 2008. Son aproximadamente 56 videos (unas 40 horas) LIBRES!&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* ''' Oct 2008 - OWASP_EU_Summit 2008 en Español '''&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
[http://www.google.com/search?hl=en&amp;amp;q=buanzo&amp;amp;btnG=Google+Search Arturo 'Buanzo' Busleiman] Realizo la traducción al español del [https://www.owasp.org/index.php/OWASP_EU_Summit_2008_ES_Spanish OWASP EU Summit 2008] que se realizara en Portugal y Algarve del 4 al 7 de Noviembre.&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* ''' Oct 2008 - Nuevo líder de capitulo Argentina '''&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
El capitulo local Argentino ha sido renovado con la intención de crear una comunidad activa en el estudio y la investigación de la seguridad en aplicaciones, aportando ideas, conocimientos y experiencias. Están todos invitados a contribuir !!!&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* ''' Sep 2008 - OWASP NYC AppSec 2008 Conference'''&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
[http://www.owasp.org/index.php/OWASP_NYC_AppSec_2008_Conference-SPEAKER-Andres_Riancho Andres Riancho] fue invitado al evento OWASP NYC AppSec para presentar su proyecto [http://w3af.sf.net/ w3af].&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* ''' Jul 2008 - OWASP Project '''&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
[https://www.owasp.org/index.php/Project_Information:template_Enigform_and_mod_OpenPGP Template Enigform and mod OpenPGP] sponsoreado por [http://www.owasp.org/index.php/OWASP_Summer_of_Code_2008 OWASP Summer of Code 2008]&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* ''' Jul 2008 - OWASP Project '''&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
[http://www.owasp.org/index.php/Category:GTK_plus_GUI_for_w3af_Project GTK + GUI for w3af Project] sponsoreado por [http://www.owasp.org/index.php/OWASP_Summer_of_Code_2008 OWASP Summer of Code 2008]&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Actividades Locales ==&lt;br /&gt;
&lt;br /&gt;
Hay muchas formas de colaborar y contribuir con el capitulo OWASP Argentina.&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Participando en cualquiera de los [http://www.owasp.org/index.php/Category:OWASP_Project proyectos] actualmente activos (documentación y herramientas)&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Proponiendo nuevos proyectos&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Participando y aportando ideas en nuestra [http://lists.owasp.org/mailman/listinfo/owasp-argentina lista] de correo&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Asistiendo a las conferencias y reuniones&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Promoviendo y dando soporte al proyecto OWASP en general&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Reuniones ==&lt;br /&gt;
&lt;br /&gt;
Se proponen reuniones trimestrales y grupos de estudio a formarse relacionados en temas de Seguridad Informatica. Se nombran alguno de ellos:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt; Análisis de las nuevas tecnologías de la información y las comunicaciones.&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Análisis de productos (Software &amp;amp; Appliances).&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Investigación de fallas y vulnerabilidades.&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Desarrollo de programas y técnicas de exploit relacionadas.&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Documentación de soluciones de seguridad.&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Desarrollo de herramientas de seguridad.&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;Demostraciones. Debates y desarrollo investigativo.&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Eventos ==&lt;br /&gt;
&lt;br /&gt;
* ''' 16 Mar 2009 - OWASP Argentina en CDP (Club de programadores) '''&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
Martin Tartarelli fue invitado a participar del seminario de &amp;quot;'''Testing de Seguridad en Aplicaciones Web'''&amp;quot; Junto a Andres Riancho ([http://www.bonsai-sec.com Bonsai - Information Security]) para hablar de '''OWASP''', Proyectos, El '''capitulo local''' y deteccion de vulnerabilidades web comunes. La charla se realizo en el [http://www.clubdeprogramadores.com CDP] (Club de programadores), Buenos Aires, CF.&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* ''' 19 May 2009 - OWASP Argentina en IEEE Argentina (IEEE Computer Society) '''&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
El Capítulo Argentino de la IEEE Computer Society nos invito a presentar la Charla 'Introducción al Testing de Seguridad en Aplicaciones Web' Dictado por Andrés Riancho ([http://www.bonsai-sec.com Bonsai - Information Security]) y Martín Tartarelli el martes 19 de mayo a las 18:30 en la sede de IEEE / CICOMRA en Buenos Aires. La presentación estuvo enfocada en introducir al espectador al mundo de la seguridad en aplicaciones web, OWASP y el capitulo local, vulnerabilidades existentes y las metodologías utilizadas para realizar pruebas funcionales y de seguridad.&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Herramientas e Investigación ==&lt;br /&gt;
&lt;br /&gt;
* '''w3af - Web Application Attack and Audit Framework'''&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
Andres Riancho publico el nuevo release de [http://w3af.sourceforge.net/ w3af]. [http://w3af.sourceforge.net/ w3af] es un proyecto Open Source que automatiza las tecnicas de auditoria y explotacion de vulnerabilidades web. [http://w3af.sourceforge.net/ w3af] esta escrito en [http://es.wikipedia.org/wiki/Python Python] y se divide en 3 fases principales mediante el uso de plugins: '''Discovery''', '''Audit''' and '''Attack'''. Las fases se unen entre sí para detectar y explotar la mayor cantidad de vulnerabilidades posibles.&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* ''' Enigform  '''&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
[http://enigform.mozdev.org/ Enigform] es una extension firefox que extiende HTTP agregando capacidades de firma digital para solicitudes GET, POST y AJAX, brindando proteccion contra distintos tipos ataques. [http://enigform.mozdev.org/ Enigform] fue desarrollado por [http://www.buanzo.com.ar/ Arturo Busleiman] (alias Buanzo) y logro el patrocinio por [http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Applications#Buanzo_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests OWASP Spring Of Code 2007]&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Global_Projects_and_Tools_Committee_-_Application_2&amp;diff=60132</id>
		<title>Global Projects and Tools Committee - Application 2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Global_Projects_and_Tools_Committee_-_Application_2&amp;diff=60132"/>
				<updated>2009-05-05T00:56:03Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[How to Join a Committee|Click here to return to 'How to Join a Committee' page]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE APPLICATION FORM''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Applicant's Name'''&lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;Brad Causey&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Current and past OWASP Roles''' &lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|OWASP OpenPGP Extensions for HTTP Reviewer&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Committee Applying for''' &lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Global Projects and Tools Committee&lt;br /&gt;
 |}&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Please be aware that for an application to be considered by the board, '''you MUST have 5 recommendations'''.  &lt;br /&gt;
An incomplete application will not be considered for vote.&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;8&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE RECOMMENDATIONS''' &lt;br /&gt;
 |- &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Who Recommends/Name''' &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Role in OWASP'''&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Recommendation Content''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''1'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Arturo Busleiman (a.k.a Buanzo)&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Brad is an exceptional individual, a through professional. OWASP would only get better with him in the Projects and Tools Committee. I met him during OWASP EU Summit 2008 in Portugal. Matt Tesauro, himself and I worked together to give a presentation on security at the Algarve University with &amp;lt; 12 hours to spare. Brad is great at getting feedback, combining ideas. A must.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''2'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''3'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''4'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''5'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |}&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Global_Projects_and_Tools_Committee_-_Application_2&amp;diff=60100</id>
		<title>Global Projects and Tools Committee - Application 2</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Global_Projects_and_Tools_Committee_-_Application_2&amp;diff=60100"/>
				<updated>2009-05-05T00:51:40Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[How to Join a Committee|Click here to return to 'How to Join a Committee' page]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE APPLICATION FORM''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Applicant's Name'''&lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;Brad Causey&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Current and past OWASP Roles''' &lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|OWASP OpenPGP Extensions for HTTP Reviewer&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Committee Applying for''' &lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Global Projects and Tools Committee&lt;br /&gt;
 |}&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
Please be aware that for an application to be considered by the board, '''you MUST have 5 recommendations'''.  &lt;br /&gt;
An incomplete application will not be considered for vote.&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;8&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''COMMITTEE RECOMMENDATIONS''' &lt;br /&gt;
 |- &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Who Recommends/Name''' &lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Role in OWASP'''&lt;br /&gt;
 ! align=&amp;quot;center&amp;quot; style=&amp;quot;background:#7B8ABD; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Recommendation Content''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''1'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Arturo Busleiman (a.k.a Buanzo)&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Brad is an exceptional individual, a through professional. OWASP would only get better with him in the Projects and Tools Committee. I met him during OWASP EU Summit 2008 in Portugal. Matt Tesauro, himself and I worked together to give a presentation on security at the Algarve University with &amp;lt; 12 hours to spare. Brad is great at getting feedback, combining ideas. A must.&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''2'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''3'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''4'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:3%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''5'''&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:20%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:57%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |}&lt;br /&gt;
----&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Buanzo&amp;diff=58151</id>
		<title>User:Buanzo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Buanzo&amp;diff=58151"/>
				<updated>2009-04-07T14:08:35Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Arturo 'Buanzo' Busleiman's [mailto:buanzo@buanzo.com.ar Email Contact], [http://www.linkedin.com/in/buanzo Profile] and [[:Special:Contributions/Buanzo|Wiki Contributions]]. You can also visit his [http://www.buanzo.com.ar/pro/eng.html Professional Services] page at his website.&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Buanzo&amp;diff=58150</id>
		<title>User:Buanzo</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Buanzo&amp;diff=58150"/>
				<updated>2009-04-07T14:05:59Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;* Arturo 'Buanzo' Busleiman's [mailto:buanzo@buanzo.com.ar Email Contact], [http://www.linkedin.com/in/buanzo Profile] and [[:Special:Contributions/Buanzo|Wiki Contributions]]. You can also visit his [http://www.buanzo.com.ar/pro/ Professional Services] page at his website.&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Ireland_AppSec_2009_Conference&amp;diff=58148</id>
		<title>OWASP Ireland AppSec 2009 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Ireland_AppSec_2009_Conference&amp;diff=58148"/>
				<updated>2009-04-07T14:01:49Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: Added Arturo Alberto Busleiman (a.k.a Buanzo) to Slot 16:10-17:00 track 1.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Welcome to the Irish OWASP Application Security Conference!&amp;lt;br&amp;gt; &lt;br /&gt;
After successful OWASP Conferences in the United States, Europe and Aisa, its Ireland's turn on September 10 2009!&lt;br /&gt;
&lt;br /&gt;
'''September 10th 2009''': OWASP will hold its first Irish Application Security conference in historic Dublin University, Trinity College, Dublin, Ireland. &lt;br /&gt;
The conference consists of an intensive day of talks/presentations and discussion with 2 different tracks focusing on the causes and trends in web application insecurity.&lt;br /&gt;
&lt;br /&gt;
For more details please contact: Eoin.Keary 'at' owasp.org&lt;br /&gt;
&lt;br /&gt;
==Conference Location==&lt;br /&gt;
[[Image:AppSecIreland09 Dublin.JPG|www.tcd.ie]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Registration via the OWASP Conference Cvent site: [http://guest.cvent.com/i.aspx?4W,M3,3fab8a14-3803-47f9-b8d2-35a67077c878 CLICK HERE TO REGISTER]'''&lt;br /&gt;
&lt;br /&gt;
==Agenda and Presentations - September 10==&lt;br /&gt;
&lt;br /&gt;
The agenda follows the successful OWASP conference two tracks format, with opening keynotes and presentations in the main auditorium, split tracks in the middle of the day, and closing pannel discussions back in the main auditorium both days.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Day 1 - September 10, 2009&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | || style=&amp;quot;width:40%; background:#BC857A&amp;quot; | Track 1: Room 1&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; | Track 2: Room 2&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 08:00-09:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Registration and Coffee&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:00-09:10 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Welcome to OWASP Ireland 2009 Conference &lt;br /&gt;
''Eoin Keary &amp;amp; Tom Brennan, OWASP''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:10-09:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Keynote: Title: TBA &lt;br /&gt;
'''[[Ian O. Angell]]''', ''Professor of Information Systems. London School of Economics''&lt;br /&gt;
&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 09:45-10:20 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | OWASP State of the Union&lt;br /&gt;
''Tom Brennan &amp;amp; Dave Wichers, OWASP Board Members''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:20-10:40 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break - Expo&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 10:40-11:20 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | Title&lt;br /&gt;
'''''Rogan Dawes, Corsaire'''''&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | Title&lt;br /&gt;
'''''Conor McGovernan, Onformonics Ltd''' ''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:20-12:00 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[SQL Injection - how far does the rabbit hole go?]]&lt;br /&gt;
'''''[[Justin Clarke]]''', '''Gotham Digital Science'''''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | '''[[Designing Secure Web Applications With Application Threat Modeling]]'''&lt;br /&gt;
'''''[[Marco Morana]]''', '''OWASP Cincinnati chapter lead'''''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:00-12:30 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | [[Web Application Security Testing with the Burp Suite]]&lt;br /&gt;
'''''[[David Rook]]''', Realex Payments''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | Title&lt;br /&gt;
''Speaker, Organisation''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:30-14:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Lunch - Expo&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:00-14:40 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | Title&lt;br /&gt;
'''''[[User:Wichers|Dave Wichers]], Aspect Security'''''&lt;br /&gt;
&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | '''[[The End of Alchemy. Empirical Software Security Assurance]]'''&lt;br /&gt;
'''''[[Brian Chess]], Fortify'''''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:50-15:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#F2F2F2&amp;quot; align=&amp;quot;center&amp;quot; | Keynote: Title: TBA&lt;br /&gt;
'''[[Danny Allen]]''', ''Director of security research with IBM Rational''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:50-16:10 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break - Expo&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:10-17:00 || style=&amp;quot;width:40%; background:#BC857A&amp;quot; align=&amp;quot;left&amp;quot; | ''[[OpenPGP for HTTP - An Introduction to Enigform]]''&lt;br /&gt;
'''''Arturo &amp;quot;[[User:Buanzo|Buanzo]]&amp;quot; Busleiman''', '''Buanzo Consulting'''''&lt;br /&gt;
 | style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | ''Title''&lt;br /&gt;
'''''Name''', '''Organisation'''''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 17:00-18:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#BCA57A&amp;quot; align=&amp;quot;left&amp;quot; | Panel: tbd&lt;br /&gt;
Moderator: tbd&amp;lt;br/&amp;gt;&lt;br /&gt;
Panelists: tbd&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 18:00-21:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP Social Gathering: Dinner and Drinks&lt;br /&gt;
 |-&lt;br /&gt;
  |}&lt;br /&gt;
&lt;br /&gt;
=Event Sponsorship=&lt;br /&gt;
OWASP is providing sponsors exclusive access to its audience in Dublin, Ireland through a limited number of Expo floor slots, providing a focused setting for potential customers. The conference is expected to draw 150 - 200 technologists who will be looking for ways to spend their remaining 2009 budget and planning for 2010.   Financial Services, Media, Pharmaceuticals, Government, Healthcare, Technology, and many other verticals will be represented.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Sponsorship details are available here: [[Image:Dublin_Sponsorship_Form.pdf|Sponsorship deck]]&lt;br /&gt;
&lt;br /&gt;
=Training=&lt;br /&gt;
We intend to hold some application security training on the 9/09/2009 the day prior to the event.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Foundations of Web Application Security''' &lt;br /&gt;
&lt;br /&gt;
Abstract&lt;br /&gt;
&lt;br /&gt;
Most developers, IT professionals, and auditors learn what they know about application security on the job, usually by making mistakes. Application security is just not a part of many computer science curricula today and most organizations have not focused on instituting a culture that includes application security as a core part of their IT security efforts. This powerful one day course focuses on the most common web application security problems, including the OWASP Top Ten. The course will introduce and demonstrate hacking techniques, illustrating how application vulnerabilities can be exploited so students really understand how to avoid introducing such vulnerabilities in their code. &lt;br /&gt;
&lt;br /&gt;
This course includes coverage of the following common vulnerability areas (the OWASP Top 10):&lt;br /&gt;
&lt;br /&gt;
A1 - Cross Site Scripting (XSS) &lt;br /&gt;
&lt;br /&gt;
A2 - Injection Flaws &lt;br /&gt;
&lt;br /&gt;
A3 - Malicious File Execution &lt;br /&gt;
&lt;br /&gt;
A4 - Insecure Direct Object Reference &lt;br /&gt;
&lt;br /&gt;
A5 - Cross Site Request Forgery (CSRF) &lt;br /&gt;
&lt;br /&gt;
A6 - Information Leakage and Improper Error Handling &lt;br /&gt;
&lt;br /&gt;
A7 - Broken Authentication and Session Management &lt;br /&gt;
&lt;br /&gt;
A8 - Insecure Cryptographic Storage &lt;br /&gt;
&lt;br /&gt;
A9 - Insecure Communications &lt;br /&gt;
&lt;br /&gt;
A10 - Failure to Restrict URL Access &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
Hands on&lt;br /&gt;
&lt;br /&gt;
To cement the principles discussed, students can participate in a number of hands-on security testing exercises where they attack a live web application (i.e., WebGoat) that has been seeded with common web application vulnerabilities. The students will use proxy tools commonly used by the hacker community to complete the exercises. Students need to bring their own windows based laptop to participate in the exercises&lt;br /&gt;
 &lt;br /&gt;
Audience&lt;br /&gt;
&lt;br /&gt;
Developers who want to understand the most common web application security flaws, and how to avoid them.&lt;br /&gt;
 &lt;br /&gt;
Level&lt;br /&gt;
&lt;br /&gt;
Intermediate&lt;br /&gt;
 &lt;br /&gt;
Prerequisite&lt;br /&gt;
&lt;br /&gt;
Basic knowledge of Java.&lt;br /&gt;
&lt;br /&gt;
Bringing your own windows based laptop is recommended so you can participate in the hands on exercises.&lt;br /&gt;
 &lt;br /&gt;
Duration&lt;br /&gt;
&lt;br /&gt;
Full day&lt;br /&gt;
&lt;br /&gt;
=Venue= &lt;br /&gt;
Trinity College, Dublin &amp;lt;BR&amp;gt;&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
http://maps.google.com/maps?f=q&amp;amp;source=s_q&amp;amp;hl=en&amp;amp;geocode=&amp;amp;q=trinity+college+Dublin&amp;amp;sll=37.0625,-95.677068&amp;amp;sspn=33.29802,78.75&amp;amp;ie=UTF8&amp;amp;ll=53.346222,-6.259203&amp;amp;spn=0.012246,0.038452&amp;amp;z=15&amp;amp;iwloc=addr&lt;br /&gt;
&lt;br /&gt;
=Transportation=&lt;br /&gt;
&lt;br /&gt;
===By Air===&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
Fly to Dublin Airport: http://www.dublinairport.com/ &amp;lt;br&amp;gt;&lt;br /&gt;
A taxi or bus can take you into Dublin city. (€30 - Taxi) (€10 - Bus)&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
===Public Transport===&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Accommodation=&lt;br /&gt;
Please see here if you wish to stay within the grounds of Trinity College:&amp;lt;br&amp;gt;&lt;br /&gt;
https://www.owasp.org/images/2/20/TCD_Tariff_2009.pdf&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Hotels Surrounding Trinity College:'''&lt;br /&gt;
&lt;br /&gt;
http://maps.google.com/maps?near=Dame+Street,+College+Green,+Dublin+2,+Ireland+(Trinity+College+Campus)&amp;amp;geocode=Cfm6cyTmqt_IFev1LQMdLZCg_yFJu3aKhBD7GA&amp;amp;q=hotels&amp;amp;f=l&amp;amp;dq=Trinity+College+loc:+Dublin+Ireland&amp;amp;sll=53.341482,-6.258302&amp;amp;sspn=0.012043,0.037637&amp;amp;ie=UTF8&amp;amp;ei=U6TMSZSzKpSw2QLG_-CUCA&amp;amp;attrid=1036f063d3d0dafc_&amp;amp;ll=53.343711,-6.254568&amp;amp;spn=0.012042,0.037637&amp;amp;z=15&lt;br /&gt;
&lt;br /&gt;
=Registration= &lt;br /&gt;
&lt;br /&gt;
The fee for this conference is :&amp;lt;br&amp;gt;&lt;br /&gt;
'''Standard''': 150 Euro &amp;lt;br&amp;gt; '''OWASP Members''': 110 Euro &amp;lt;br&amp;gt; '''Students''': 75 Euro&amp;lt;br&amp;gt; '''Application Security Training''': 455 Euro&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Note''': To save on processing expenses, all fees paid for the OWASP conference are non-refundable. OWASP can accommodate transfers of registrations from one person to another, if such an adjustment becomes necessary. &lt;br /&gt;
&lt;br /&gt;
'''Registration via the OWASP Conference Cvent site: [http://guest.cvent.com/i.aspx?4W,M3,3fab8a14-3803-47f9-b8d2-35a67077c878 CLICK HERE TO REGISTER]'''&lt;br /&gt;
&lt;br /&gt;
=Conference Committee=&lt;br /&gt;
'''OWASP Conferences Chair''': Dave Wichers - Aspect Security - dave.wichers 'at' owasp.org &lt;br /&gt;
&lt;br /&gt;
'''2009 Ireland Planning Committee Chair''': Eoin Keary - Ernst &amp;amp; Young - eoin.keary 'at' owasp.org&lt;br /&gt;
&lt;br /&gt;
=Call for Papers=&lt;br /&gt;
&lt;br /&gt;
The Conference will consist of two tracks covering both technical and risk management topics. &lt;br /&gt;
 &lt;br /&gt;
'''We are seeking presentations on any of the following topics:'''&lt;br /&gt;
*Web Services and Application Security&lt;br /&gt;
*Common Application related Threats and Risks&lt;br /&gt;
*Business Risks with Application Security&lt;br /&gt;
*Vulnerability Research in Application Security &lt;br /&gt;
*Web Application Penetration Testing &lt;br /&gt;
*OWASP Tools and Projects &lt;br /&gt;
*Secure Coding/Development Practices&lt;br /&gt;
*Technology specific presentations on security such as AJAX, XML, etc. &lt;br /&gt;
*Anything else relating to OWASP and Application Security. &lt;br /&gt;
&lt;br /&gt;
The call for papers/presentations is out. The official closing date for receiving a synopsis of the presentation is June 10th, 2009.  &lt;br /&gt;
Announcements on selected candidates will be provided the first week of July 2009. Complete presentations will need to be submitted by the 2nd of August 2009. &lt;br /&gt;
All presenters will receive free invitation to the conference, food and refreshments.&lt;br /&gt;
&lt;br /&gt;
'''For some speakers, OWASP will cover some of the travel costs associated with coming to the conference.'''&lt;br /&gt;
&lt;br /&gt;
'''Please submit your presentation topics and an abstract of up to 500 words to Eoin Keary''' &amp;lt;mailto: Eoin.keary@owasp.org&amp;gt;&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=56692</id>
		<title>Project Information:template Enigform and mod OpenPGP - Final Review - Self Evaluation - B</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP_-_Final_Review_-_Self_Evaluation_-_B&amp;diff=56692"/>
				<updated>2009-03-15T15:07:18Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Enigform and mod OpenPGP|Clik here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''FINAL REVIEW''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART I''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OpenPGP Extensions for HTTP - Enigform and mod_openpgp|OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OpenPGP Extensions for HTTP - Enigform and mod_openpgp|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|I was able to implement a Wordpress plugin that enables Enigform-based login to Wordpress's admin/user area. The plugin is currently offered by wordpress.org. This plugin was also implemented in my own wordpress blog, becoming the Demo Site. As a demonstration of keyring-sharing and mod_openpgp multi-virtualhost integration, the Testing Site maotest.buanzo.org shares this same keyring. I've written the Definitive Enigform Guide and published it at wiki.buanzo.org. It contains detailed instructions for implementing the wordpress plugin, INCLUDING Enigform client and server setup, troubleshooting, and links to other useful resources. An unplanned feature was added: Server Signature Verification in Secure Login. Enigform Plugin 0.8.2.8 is now available in addons.mozilla.org. Mod_openpgp 0.5.0 was announced in freshmeat.net. A Debian package for mod_openpgp is in the works, but I consider the Guide to be the best procedure to follow.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OpenPGP Extensions for HTTP - Enigform and mod_openpgp|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|100%&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Mark mentioned a Session Hijacking test suite should be used. I'd like to do that in the next 15 days if possible.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:white&amp;quot; align=&amp;quot;center&amp;quot;|'''PART II''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:white&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Assessment Criteria&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project Assessment|OWASP Project Assessment Criteria]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Alpha Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|I don't use sourceforge nor googlecode. I use mozdev.org, wordpress.org and svn.buanzo.org.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
2. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Beta Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The easy-to-use installer might not be quite possible. I discussed this in owasp-leaders, but the CLIENT side is quite simple (create pgp keyring [lots of GUI tools for this], then install enigform as a common firefox addon). The wordpress plugin is compliant with wordpress.org's best practices. Mod_openpgp is difficult, but easier than, say, OpenSSL.&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
3. Having into consideration the [[:Category:OWASP Project Assessment|OWASP Project Assessment Methodology]] which criteria, if any, haven’t been fulfilled in terms of '''Release Quality''' status?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|not applicable&lt;br /&gt;
 |-  &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
4. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|I'm pleased with the current help and support from the Reviewers and OWASP Community. THANKS.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_OpenPGP_Extensions_for_HTTP_Project_-_Assessment_Frame&amp;diff=56691</id>
		<title>OWASP OpenPGP Extensions for HTTP Project - Assessment Frame</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_OpenPGP_Extensions_for_HTTP_Project_-_Assessment_Frame&amp;diff=56691"/>
				<updated>2009-03-15T14:50:09Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:Category:OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp|Click here to return to project's main page]].&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;1&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp Project''' &lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS - OWASP Summer of Code 2008&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;[[User:Buanzo|'''Arturo 'Buanzo' Busleiman''']] &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;[[User:Mroxberr|'''Mark Roxberry''']]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;[[User:Dinis.cruz|'''Dinis Cruz''']]&amp;lt;br&amp;gt;[[User:Bradcausey|Brad Causey]] &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(not applicable)&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - Self Evaluation - A|Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - First Reviewer - C|First Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP 50 Review Second Review E|Second Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Beta Quality'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Self Evaluation - B|Self-Evaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Alpha Quality''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - First Reviewer - D|First Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Alpha Quality''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Second Reviewer - F|Second Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Latin_America_AppSec_2009_Conference&amp;diff=46607</id>
		<title>OWASP Latin America AppSec 2009 Conference</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Latin_America_AppSec_2009_Conference&amp;diff=46607"/>
				<updated>2008-11-20T13:37:41Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: buenos aires&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Organization Team =&lt;br /&gt;
&lt;br /&gt;
'''Argentina'''&lt;br /&gt;
* [mailto:buanzo@buanzo.com.ar Arturo &amp;quot;Buanzo&amp;quot; Busleiman]&lt;br /&gt;
&lt;br /&gt;
'''Brasil'''&lt;br /&gt;
* [mailto:assad@cesar.org.br Rodrigo Assad]&lt;br /&gt;
* [mailto:clebeer@gmail.com Cleber]&lt;br /&gt;
* [mailto:daniel.oliveira.rodrigues@gmail.com Daniel Rodrigues]&lt;br /&gt;
* [mailto:deigratia33@gmail.com Marcos Aurélio Rodrigues]&lt;br /&gt;
* [mailto:eduardo.neves@owasp.org.br Eduardo Vianna de Camargo Neves]&lt;br /&gt;
* [mailto:alberto@computer.org Alberto Fabiano]&lt;br /&gt;
* [mailto:eduardoalves19@gmail.com Eduardo Alves]&lt;br /&gt;
* [mailto:leonardocavallari@gmail.com Leonardo Cavallari Militelli]&lt;br /&gt;
* [mailto:pedro.forum@gmail.com Pedro Arthur]&lt;br /&gt;
* [mailto:thiagoalz@gmail.com Thiago Alvarenga Lechuga]&lt;br /&gt;
* [mailto:uss.thebug@gmail.com Ulisses Castro]&lt;br /&gt;
* [mailto:welias@conviso.com.br Wagner Elias]&lt;br /&gt;
&lt;br /&gt;
'''USA'''&lt;br /&gt;
* [mailto:kuai.hinojosa@owasp.org Kuai Hinojosa]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Venue =&lt;br /&gt;
&lt;br /&gt;
Where this event should be hosted? Think not only about location but also logistics, travel costs, security and other aspects that can affect the participants.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Ideas ==&lt;br /&gt;
&lt;br /&gt;
'''Brasil'''&lt;br /&gt;
&lt;br /&gt;
* Curitiba&lt;br /&gt;
* Recife&lt;br /&gt;
&lt;br /&gt;
'''Argentina'''&lt;br /&gt;
&lt;br /&gt;
* Buenos Aires City&lt;br /&gt;
&lt;br /&gt;
Argentina has a nice DOLLAR-PESO Exchange, lots of potential venues and a nice local security community. However, there seems to be a bigger owasp work-force in Brasil than Argentina (see above!).&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Working_Session_-_OWASP_Intra_Governmental_Affairs&amp;diff=45338</id>
		<title>OWASP Working Session - OWASP Intra Governmental Affairs</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Working_Session_-_OWASP_Intra_Governmental_Affairs&amp;diff=45338"/>
				<updated>2008-11-01T11:52:05Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#b3b3b3; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Working Sessions Operational Rules''' - [[:Working Sessions Methodology|'''Please see here the general frame of rules''']].&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Work Session Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Intra Governmental Affairs'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Work Session Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Effectively Integrating OWASP into Gov't&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Related Projects''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
If any, add a link.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts &amp;amp; Roles'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Chair'''&amp;lt;br&amp;gt;David Campbell&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Secretary'''&amp;lt;br&amp;gt;[mailto:puneet.mehta@owasp.org '''Puneet Mehta'''] , [mailto:dhruv.soi@owasp.org '''Dhruv Soi'''] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Mailing list'''&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp-intra-governmental-affairs '''Subscription Page''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION SPECIFICS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Objectives'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
* Identify top reasons and driving factors to work with Government of different countries,&lt;br /&gt;
* Identify potential areas where OWASP and Government can work together,&lt;br /&gt;
* Discuss Measurable benefits,&lt;br /&gt;
* Identify possible ways on how to approach this initiative.  &lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue/Date&amp;amp;Time/Model'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue'''&amp;lt;br&amp;gt;[[:OWASP EU Summit 2008|OWASP EU Summit Portugal 2008]] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Date&amp;amp;Time'''&amp;lt;br&amp;gt;November 5 &amp;amp; 7, 2008 &amp;lt;br&amp;gt;Time TBD&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Discussion Model'''&amp;lt;br&amp;gt;&amp;quot;Everybody is a Participant&amp;quot;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION OPERATIONAL RESOURCES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Projector, also wireless connection for conferencing in remote participants.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION ADDITIONAL DETAILS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[https://www.owasp.org/images/9/9a/OWASP_EU_Summit_2008_Intra_govt_affairs_DC.ppt Presentation] prepared by Puneet to seed discussion.  Feel free to expand and update with additional info. &lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|'''WORKING SESSION OUTCOMES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|Statements, Initiatives or Decisions &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Proposed by Working Group''' &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Approved by OWASP Board'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Mission or goal statement. &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Prioritized list of potential areas where OWASP can work with Government.  &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Roadmap / Model to approach this initiative. &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Identify Team / committee to lead this initiative. &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Fill in here. &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Fill in here. &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |}&lt;br /&gt;
== Working Session Participants ==&lt;br /&gt;
(Add you name by editing this table. On your the right, just above the this frame, you have the option to edit)&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION PARTICIPANTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Name'''&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Company'''&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Notes &amp;amp; reason for participating, issues to be discussed/addressed'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|1&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|David Campbell&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Denver&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Experience w/ US Govt. agencies&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|2&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Puneet Mehta&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Delhi&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Experience w/ India Govt. Agencies&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|3&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Sion Camilleri&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Belgium&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Experience w/ Australian, UK, NATO, and other International/EU Commission Government Agencies  &lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|4&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Colin Watson&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Watson Hall&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Raising awareness of OWASP in government agencies&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|5&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rex Booth&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Grant Thornton LLP&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Experience with US gov. agencies&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|6&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Lucas C. Ferreira&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Brazilian Parliament&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Work for Brazilian government&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|7&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Arturo 'Buanzo' Busleiman&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Independent&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|I have certain vinculations with the Argentinian government.&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|8&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|9&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|10&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |}&lt;br /&gt;
If needed add here more lines.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Working_Session]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Working_Session_-_Code_Review_Guide&amp;diff=45337</id>
		<title>OWASP Working Session - Code Review Guide</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Working_Session_-_Code_Review_Guide&amp;diff=45337"/>
				<updated>2008-11-01T11:51:28Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#b3b3b3; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Working Sessions Operational Rules''' - [[:Working Sessions Methodology|'''Please see here the general frame of rules''']].&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Work Session Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Code Review Guide'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Work Session Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|TBD&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Related Projects (if any)''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Code Review Project|OWASP Code Review Project]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts &amp;amp; Roles'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Chair'''&amp;lt;br&amp;gt;[mailto:eoin.keary(at)owasp.org '''Eoin Keary'''] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Secretary'''&amp;lt;br&amp;gt;[mailto:name(at)name '''TBD''']&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Mailing list'''&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp-codereview '''Subscription Page''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION SPECIFICS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Objectives'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
*  Discuss next version of code review guide.&lt;br /&gt;
* Discuss industry requirements for code review.&lt;br /&gt;
* Discuss academic versus practical ramifications of guide.&lt;br /&gt;
* Brainstorm: Ideas for integration with other projects and tools.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue/Date&amp;amp;Time/Model'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue'''&amp;lt;br&amp;gt;[[:OWASP EU Summit 2008|OWASP EU Summit Portugal 2008]] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Date&amp;amp;Time'''&amp;lt;br&amp;gt;November 5 &amp;amp; 6, 2008 &amp;lt;br&amp;gt;Time TBD&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Discussion Model'''&amp;lt;br&amp;gt;&amp;quot;Everybody is a Participant&amp;quot;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION OPERATIONAL RESOURCES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Whteboard and Pens, Projector, Coffee :)&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION ADDITIONAL DETAILS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
Please add here, any additional notes, links, ideas, guidelines, etc... The objective is to help the working sessions participants and attendees to prepare their participation/contribution.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|'''WORKING SESSION OUTCOMES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|Statements, Initiatives or Decisions &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Proposed by Working Group''' &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Approved by OWASP Board'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Develop a roadmap for the code review guide: Technologies, approaches. &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Fill in here.   &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Fill in here. &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
  |}&lt;br /&gt;
== Working Session Participants ==&lt;br /&gt;
(Add you name by editing this table. On your the right, just above the this frame, you have the option to edit)&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION PARTICIPANTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Name'''&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Company'''&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Notes &amp;amp; reason for participating, issues to be discussed/addressed'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|1&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Paolo Perego (aka thesp0nge)&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Spike Reply&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Owasp Orizon - Project Leader&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|2&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|David Rook&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Realex Payments&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Contributor to Code Review Guide&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|3&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Giorgio Fedon&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Minded Security&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Very interested in the topic&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|4&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Matteo Meucci&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Minded Security&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Interested in integrating OWASP big 4: Dev, Code Review, Testing, ADSR&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|5&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Kuai Hinojosa&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP (MSP) Chapter Leader&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|6&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|James Walden&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|NKU&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Source Code Analysis Project&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|7&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Wagner Elias&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Conviso IT Security&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|8&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Arturo 'Buanzo' Busleiman&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Independent&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Eoin looks passionate about the subject. I want to be near! :)&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|9&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|10&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |}&lt;br /&gt;
If needed add here more lines.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Working_Session]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Working_Session_Top_10_2009&amp;diff=45335</id>
		<title>OWASP Working Session Top 10 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Working_Session_Top_10_2009&amp;diff=45335"/>
				<updated>2008-11-01T11:49:18Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#b3b3b3; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Working Sessions Operational Rules''' - [[:Working Sessions Methodology|'''Please see here the general frame of rules''']].&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Work Session Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Top 10 2009'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Work Session Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Aims to provide a key awareness document for web application security.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Related Projects (if any)''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|[[:Category:OWASP Top Ten Project|OWASP Top Ten Project]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts &amp;amp; Roles'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Chair'''&amp;lt;br&amp;gt;[mailto:dave.wichers(at)owasp.org '''Dave Wichers''']&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Secretary'''&amp;lt;br&amp;gt;[mailto:jeff.williams(at)owasp.org '''Jeff Williams''']&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Mailing list'''&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp-topten '''Subscription Page''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION SPECIFICS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Objectives'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
* Discuss current Top10 structure and objectives,&lt;br /&gt;
* Identify which information sources will be considered for analysis, Eg:&lt;br /&gt;
** MITRE&lt;br /&gt;
** Compromise DB's (Attrition, WASC etc) and bias due to reporting&lt;br /&gt;
** Anonomised penetration test results and the difficulty in obtaining&lt;br /&gt;
* Define methodology to collect attacks statistics,&lt;br /&gt;
* Define prioritisation approach&lt;br /&gt;
** Agree weighting between current or emerging threats&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue/Date&amp;amp;Time/Model'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue'''&amp;lt;br&amp;gt;[[:OWASP EU Summit 2008|OWASP EU Summit Portugal 2008]] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Date&amp;amp;Time'''&amp;lt;br&amp;gt;November 5 &amp;amp; 7, 2008&amp;lt;br&amp;gt;Time TBD&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Discussion Model'''&amp;lt;br&amp;gt;&amp;quot;Participants + Attendees&amp;quot;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION OPERATIONAL RESOURCES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Please add here, ASAP, any needed relevant resources, e.g. data-show, boards, laptops, etc.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION ADDITIONAL DETAILS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Please add here, any additional notes, links, ideas, guidelines, etc... The objective is to help the working sessions participants and attendees to prepare their participation/contribution.&lt;br /&gt;
&lt;br /&gt;
Potential Resources:&lt;br /&gt;
&lt;br /&gt;
* [http://cve.mitre.org/cve/ MITRE's Common Vulnerability Enumeration (CVE) Database]&lt;br /&gt;
&lt;br /&gt;
* The [http://www.webappsec.org/projects/whid/whid.shtml WASC Web Hacking Incidents Database]&lt;br /&gt;
&lt;br /&gt;
* The [http://www.webappsec.org/projects/statistics/ 2007 WASC Web Application Security Statistics Report]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|'''WORKING SESSION OUTCOMES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|Statements, Initiatives or Decisions &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Proposed by Working Group''' &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Approved by OWASP Board'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|The sources of input for the 2009 Top 10 will be identified.&lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|The ordering scheme for the Top 10 will be determined.&lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Discussion of whether the existing document structure should be maintained or adjusted.&lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
  |}&lt;br /&gt;
''''''Bold text''''''== Working Session Participants ==&lt;br /&gt;
(Add your name by editing this table. On the right, just above this frame, you have the option to edit)&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION PARTICIPANTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Name'''&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Company'''&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Notes &amp;amp; reason for participating, issues to be discussed/addressed'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|1&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Paolo Perego&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Spike Reply&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|As penetration tester it woud be great to me to participating in writing the new Top 10. As code reviewer and Orizon project leader it would be very interesting in scouting dynamic threats in order to add some dynamic feature to my tool.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|2&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|David Campbell&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Denver&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|3&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Robert Mann&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|RBS / ABN AMRO&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|4&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Troy Leach&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://www.pcisecuritystandards.org/ PCI Security Standards Council]&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Technical Director&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|5&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Eoin Keary&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Ernst &amp;amp; Young. Long time OWASP member (Code and Testing guides)&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|6&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Matteo Meucci&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Minded Security&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| I'd like to discuss about a new way to create the Top10 from the OWASP Community&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|7&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Giorgio Fedon&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Minded Security&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|8&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Andrea Cogliati&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Rochester, NY&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|I volunteered as a technical writer&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|9&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Christian Martorella&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|S21sec&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Interested in participating on the creating the Top 10, share some ideas.&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|10&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Nishi Kumar&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Systems Architect (FIS) Global Web Development Group&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Interested in participating and sharing ideas&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|11&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Tom Brennan&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| OWASP/WhiteHat Security&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Want to discuss some of the stats we can share with OWASP&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|12&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Georg Hess&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| OWASP Germany&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| mainly to get some insight into the process&lt;br /&gt;
 |&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|12&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Arturo 'Buanzo' Busleiman&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Independent&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Expert Contributor for SANS TOP20 since 2005. want to contribute here.&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
If needed add here more lines.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Working_Session]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Working_Session_Winter_of_Code_2009&amp;diff=45332</id>
		<title>Working Session Winter of Code 2009</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Working_Session_Winter_of_Code_2009&amp;diff=45332"/>
				<updated>2008-11-01T11:46:30Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#b3b3b3; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Working Sessions Operational Rules''' - [[:Working Sessions Methodology|'''Please see here the general frame of rules''']].&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Work Session Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Winter of Code 2009'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Work Session Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Aims to define the next OWASP Season of Code frame.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Related Projects (if any)''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
*[[:OWASP Summer of Code 2008|OWASP Summer of Code 2008]],&lt;br /&gt;
*[[:OWASP Spring Of Code 2007|OWASP Spring Of Code 2007]], &lt;br /&gt;
*[[:OWASP Autumn Of Code 2006|OWASP Autumn Of Code 2006]].&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts &amp;amp; Roles'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Chair'''&amp;lt;br&amp;gt;[mailto:dinis.cruz(at)owasp.org '''Dinis Cruz'''], [mailto:seba(at)owasp.org '''Sebastien Deleersnyder'''] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Secretary'''&amp;lt;br&amp;gt;[mailto:paulo.coimbra(at)owasp.org '''Paulo Coimbra''']&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Mailing list'''&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp-winter-of-code-2009 '''Subscription Page''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION SPECIFICS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Objectives'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
*  Define the operation model for the next OWASP Season of Code (the Winter of Code 08),&lt;br /&gt;
* Identify which areas should receive priority selection,&lt;br /&gt;
* Create 'virtual teams' from the attendees and allocate them to key projects,&lt;br /&gt;
* Discuss sponsoring models. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue/Date&amp;amp;Time/Model'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue'''&amp;lt;br&amp;gt;[[:OWASP EU Summit 2008|OWASP EU Summit Portugal 2008]] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Date&amp;amp;Time'''&amp;lt;br&amp;gt;November 4 &amp;amp; 7, 2008 &amp;lt;br&amp;gt;Time TBD&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Discussion Model'''&amp;lt;br&amp;gt;&amp;quot;Everybody is a Participant&amp;quot;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION OPERATIONAL RESOURCES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Please add here, ASAP, any needed relevant resources, e.g. data-show, boards, laptops, etc.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION ADDITIONAL DETAILS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Please add here, any additional notes, links, ideas, guidelines, etc... The objective is to help the working sessions participants and attendees to prepare their participation/contribution&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|'''WORKING SESSION OUTCOMES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|Statements, Initiatives or Decisions &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Proposed by Working Group''' &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Approved by OWASP Board'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|Initiative &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Winter of Code 08 plan.&lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|Decision &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Set of projects for immediate approval (assuming the proposal is ready).&lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Fill in here.&lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
  |}&lt;br /&gt;
== Working Session Participants ==&lt;br /&gt;
(Add you name by editing this table. On your the right, just above the this frame, you have the option to edit)&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION PARTICIPANTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Name'''&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Company'''&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Notes &amp;amp; reason for participating, issues to be discussed/addressed'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|1&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Eduardo Vianna de Camargo Neves&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Conviso IT Security&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Understand how we can help the initiative and participate to continue the Positive Security project.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|2&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Leonardo Cavallari Militelli&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|E-VAL Tecnologia&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Share feelings from other 2 season of code, discuss improvements for WoC and continue ASDR development.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|3&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Matt Tesauro&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Live CD 2008 Project Lead&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Discuss what worked and didn't work with the SoC.&amp;lt;br&amp;gt;  Give some input on how to spread the word about OWASP's XoC's&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|4&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Matteo Meucci&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Minded Security, OWASP Testing Guide&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Discuss new ideas about projects. Should OWASP says which projects develop?&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|5&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Carlo Pelliccioni&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Symantec, OWASP Backend Security Project&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| Discuss about the next OWASP sponsorship to share new ideas.&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|6&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Christian Martorella&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Edge-Security, WebSlayer Project&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Interested in the topic&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|7&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Eoin Keary&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Code review guide lead&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|What next for the sponsored prjoects?&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|8&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Arturo 'Buanzo' Busleiman&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Independent&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader in 07 and 08, past experience.&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|9&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|10&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |}&lt;br /&gt;
If needed add here more lines.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Working_Session]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Working_Session_-_OWASP_Tools_Projects&amp;diff=45329</id>
		<title>OWASP Working Session - OWASP Tools Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Working_Session_-_OWASP_Tools_Projects&amp;diff=45329"/>
				<updated>2008-11-01T11:45:03Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#b3b3b3; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''Working Sessions Operational Rules''' - [[:Working Sessions Methodology|'''Please see here the general frame of rules''']].&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Work Session Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP Tools Projects'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Work Session Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The working session for OWASP Tools will address standards for Tool development at OWASP. This is will include standards for documentation, supporting tools via Books, How-Tos, Webcasts, Podcasts. We will also dive deep into the OWASP Project Assessment.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Related Projects (if any)''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[:Category:OWASP Project|OWASP Tools Projects]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts &amp;amp; Roles'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Chair'''&amp;lt;br&amp;gt;[mailto:mark.roxberry(at)owasp.org '''Mark Roxberry'''] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Secretary'''&amp;lt;br&amp;gt;[mailto:mtesauro(at)gmail.com '''Matt Tesauro''']&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Mailing list'''&amp;lt;br&amp;gt;[https://lists.owasp.org/mailman/listinfo/owasp-tools-projects '''Subscription Page''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION SPECIFICS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Objectives'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
*  Discuss documentation procedures.&lt;br /&gt;
* Book creation procedure.&lt;br /&gt;
* Review OWASP Project Assessment.    &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue/Date&amp;amp;Time/Model'''&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Venue'''&amp;lt;br&amp;gt;[[:OWASP EU Summit 2008|OWASP EU Summit Portugal 2008]] &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Date&amp;amp;Time'''&amp;lt;br&amp;gt;November 4 &amp;amp; 7, 2008 &amp;lt;br&amp;gt;Time TBD&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Discussion Model'''&amp;lt;br&amp;gt;&amp;quot;Participants + Attendees&amp;quot;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION OPERATIONAL RESOURCES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Please add here, ASAP, any needed relevant resources, e.g. data-show, boards, laptops, etc.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:white; color:white&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION ADDITIONAL DETAILS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
Please add here, any additional notes, links, ideas, guidelines, etc... The objective is to help the working sessions participants and attendees to prepare their participation/contribution.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|'''WORKING SESSION OUTCOMES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|Statements, Initiatives or Decisions &lt;br /&gt;
 | style=&amp;quot;width:46%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Proposed by Working Group''' &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Approved by OWASP Board'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Fill in here.  &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:46%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Fill in here.  &lt;br /&gt;
 | style=&amp;quot;width:47%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|After the Board Meeting - fill in here. &lt;br /&gt;
  |}&lt;br /&gt;
== Working Session Participants ==&lt;br /&gt;
(Add you name by editing this table. On your the right, just above the this frame, you have the option to edit)&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''WORKING SESSION PARTICIPANTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Name'''&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Company'''&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|'''Notes &amp;amp; reason for participating, issues to be discussed/addressed'''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|1&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Paulo Coimbra&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Has contributed to the current OWASP Assessment Criteria. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|2&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Rogan Dawes&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Corsaire&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|WebScarab lead &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|3&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Andrew Petukhov&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Moscow State University&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Access Control Rules Tester lead&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|4&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Christian Martorella&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Edge-Security&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|WebSlayer lead&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|5&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Arturo 'Buanzo' Busleiman&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Independent&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Enigform &amp;amp; mod_openpgp SOC07/08&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|6&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|7&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|8&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|9&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|10&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
|-&lt;br /&gt;
 | style=&amp;quot;width:7%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|11&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 | style=&amp;quot;width:63%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
 |}&lt;br /&gt;
If needed add here more lines.&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Working_Session]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_ES_Spanish&amp;diff=43166</id>
		<title>OWASP EU Summit 2008 ES Spanish</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_ES_Spanish&amp;diff=43166"/>
				<updated>2008-10-13T16:46:32Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''translation work in progress'''&lt;br /&gt;
&lt;br /&gt;
== Translation of the official press release to Spanish ==&lt;br /&gt;
&lt;br /&gt;
'''Cumbre Europea de OWASP en Portugal'''&amp;lt;br&amp;gt;&lt;br /&gt;
''Portugal y Algarve  - 4 al 7 de Noviembre de 2008''&lt;br /&gt;
&lt;br /&gt;
Organizando la Agenda 2009 de la Seguridad en Aplicaciones Web:  OWASP los invita a participar de nuestra Cumbre en Portugal&lt;br /&gt;
http://www.owasp.org/index.php/OWASP_EU_Summit_2008_ES_Spanish&lt;br /&gt;
&lt;br /&gt;
Bajo el lema 'Organizando la Agenda 2009 de la Seguridad en Aplicaciones Web', la Cumbre OWASP será un encuentro mundial de líderes de OWASP y participantes clave de la industria que presentarán y discutirán las últimas herramientas OWASP, proyectos de documentación y tendencias en seguridad de aplicaciones web. Unase a nosotros en Portugal dentro de pocas semanas! Este evento contiene una vasta selección de cursos de entrenamiento, y charlas técnicas y de negocios, lo que lo convierte en EL evento donde aprender sobre seguridad en aplicaciones web, y sobre los recursos que OWASP tiene disponibles para utilizarse hoy.&lt;br /&gt;
&lt;br /&gt;
OWASP es una organización sin fines de lucro con el propósito de dar soporte a la comunidad de la Seguridad en Aplicaciones Web, y ha otorgado $250.000 dólares para investigación en dicha área. Más allá de las 40 presentaciones de los Líderes OWASP y beneficiarios de los fondos de investigación, la Cumbre OWASP será el anfitrión de múltiples Sesiones de Trabajo diseñadas para mejorar la colaboración, obtener objetivos específicos e identificar los próximos pasos para los proyectos, capítulos y comunidad OWASP.&lt;br /&gt;
&lt;br /&gt;
Para lograr este evento, OWASP invierte $150.000 dólares que serán utilizados para cubrir los gastos de alojamiento y viajes de los líderes OWASP, contribuidores activos, y líderes de la industria seleccionados quienes con su confirmada presencia (vea la lísta aquí: http://spreadsheets.google.com/pub?key=pAX6n7m2zaTVLrPtR07riBA) la Cumbre OWASP proveerá un cómodo pero profesional entorno donde encontrarse, discutir, influenciar y contribuir a los proyectos OWASP.&lt;br /&gt;
&lt;br /&gt;
La Cumbre OWASP será también el anfitrión de una gran y diversa selección de cursos de entrenamiento, los cuales cubrirán múltiples tématicas específicas a OWASP y a la Seguridad en Aplicaciones Web.&lt;br /&gt;
&lt;br /&gt;
El notable impacto de la OWASP es posible sólo por la colaboración de muchas personas dedicadas y organizaciones de todo el mundo. En el espíritu de la colaboración, OWASP invita a todos sus miembros y a todos los interesados, individuos y empresas por igual, a participar de este impactante evento. Por favor, únase y ayude a organizar la Agenda de Seguridad en Aplicaciones Web 2009!&lt;br /&gt;
&lt;br /&gt;
En cuanto a las cuestiones de Patrocinio, aún hay algunas oportunidades disponibles (vea: http://www.owasp.org/index.php/OWASP_EU_Summit_2008_Sponsors) – no pierda la oportunidad de asociar su marca a este notable evento de alcance mundial!&lt;br /&gt;
&lt;br /&gt;
Siga leyendo para obtener detalles adicionales sobre la Cumbre OWASP, o visite el sitio web de la mísma: http://www.owasp.org/index.php/OWASP_EU_Summit_2008.&lt;br /&gt;
&lt;br /&gt;
'''Proyectos'''&lt;br /&gt;
&lt;br /&gt;
Los proyectos OWASP seleccionados para ser presentados en la Cumbre incluyen nueva documentación e innovadores herramientas para ayudar a los desarrolladores, arquitectos y especialistas a asegurarse que las aplicaciones son seguras:&lt;br /&gt;
&lt;br /&gt;
* Estándar de Verificación de Seguridad de Aplicación,&lt;br /&gt;
* Guía de Revisión de Código, v1.1,&lt;br /&gt;
* Guía de Seguridad Ruby on Rails v2,&lt;br /&gt;
* Securizando WebGoat utilizando ModSecurity,&lt;br /&gt;
* Guía de Testeo v3,&lt;br /&gt;
* Interfaz gráfica GTK+ para el proyecto w3af,&lt;br /&gt;
* Testeo de Reglas de Control de Acceso,&lt;br /&gt;
* AntiSamy .NET,&lt;br /&gt;
* Proyectos Live CD &amp;amp; DVD,&lt;br /&gt;
* Extensiones OpenPGP para HTTP,&lt;br /&gt;
* Proyecto Orizon,&lt;br /&gt;
* Análisis Estático en Python,&lt;br /&gt;
* WebScarab-NG, &lt;br /&gt;
* ... y muchos, muchos más!&lt;br /&gt;
&lt;br /&gt;
'''Sesiones de Trabajo'''&lt;br /&gt;
&lt;br /&gt;
Junto con la presencia de diversos líderes de la industria de la seguridad de aplicaciones, las sesiones de trabajo cubrirán un gran rango de temáticas, a saber:&lt;br /&gt;
&lt;br /&gt;
* OWASP Top 10 2009, &lt;br /&gt;
* Seguridad de Navegadores,&lt;br /&gt;
* Seguridad de Frameworks para Aplicaciones Web, &lt;br /&gt;
* Proyecto API de Seguridad Corporativa, &lt;br /&gt;
* Prácticas Recomendadas para Líderes de Capítulos OWASP, &lt;br /&gt;
* Proyectos OWASP de Documentación, &lt;br /&gt;
* Proyectos OWASP de Herramientas, &lt;br /&gt;
* Proyecto OWASP Educativo, &lt;br /&gt;
* Planeamiento Estratégico OWASP 2009, &lt;br /&gt;
* Certificación OWASP,&lt;br /&gt;
* OWASP Invierno de Código 2009&lt;br /&gt;
* Internacionalización de Contenido OWASP en ambos sentidos.&lt;br /&gt;
* ... y muchos más.&lt;br /&gt;
&lt;br /&gt;
'''Entrenamiento'''&lt;br /&gt;
&lt;br /&gt;
Estos cursos de 2, 1 o medio día cubren un amplio rango de temas vinculados a OWASP y a la Seguridad en Aplicaciones Web:&lt;br /&gt;
&lt;br /&gt;
* OWASP Top 10 - Lo que los desarrolladores deberían saber sobre la Seguridad en Aplicaciones Web&lt;br /&gt;
* Descubriendo los Tesoros Ocultos de WebScarab&lt;br /&gt;
* Securizando WebGoat con ModSecurity  &lt;br /&gt;
* Programación Segura en Java&lt;br /&gt;
* Testeo Avanzado de Seguridad en Aplicaciones Web&lt;br /&gt;
* Creando Aplicaciones Web 2.0 Seguras&lt;br /&gt;
* Creando Servicios Web Seguros&lt;br /&gt;
* Creando Aplicaciones Web Seguras utilizando la API OWASP de Seguridad Corporativa (ESAPI)&lt;br /&gt;
* Seguridad clásica para ASP utilizando herramientas OWASP&lt;br /&gt;
* Evaluando Aplicaciones Web&lt;br /&gt;
* Hackeando el proyecto OWASP Orizon v1.0&lt;br /&gt;
* Seguridad en AJAX&lt;br /&gt;
* Penetration Testing Práctico: Piense como un atacante para detener ataques.&lt;br /&gt;
* Explotación de Software en Linux&lt;br /&gt;
* Securización de servicios y servidores Web utilizando SELinux&lt;br /&gt;
&lt;br /&gt;
Contacto Principal:&lt;br /&gt;
&lt;br /&gt;
Kate Hartmann&amp;lt;br/&amp;gt;&lt;br /&gt;
OWASP Operations Director&amp;lt;br/&amp;gt;&lt;br /&gt;
9175 Guilford Road, Suite 300&amp;lt;br/&amp;gt;&lt;br /&gt;
Columbia, MD 21046, USA&amp;lt;br/&amp;gt;&lt;br /&gt;
Teléfono: +1-301-575-0189&amp;lt;br/&amp;gt;&lt;br /&gt;
Fax: +1-301-604-8033&amp;lt;br/&amp;gt;&lt;br /&gt;
Email: kate.hartmann@owasp.org&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_ES_Spanish&amp;diff=43165</id>
		<title>OWASP EU Summit 2008 ES Spanish</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_ES_Spanish&amp;diff=43165"/>
				<updated>2008-10-13T16:32:08Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''translation work in progress'''&lt;br /&gt;
&lt;br /&gt;
== Translation of the official press release to Spanish ==&lt;br /&gt;
&lt;br /&gt;
'''Cumbre Europea de OWASP en Portugal'''&amp;lt;br&amp;gt;&lt;br /&gt;
''Portugal y Algarve  - 4 al 7 de Noviembre de 2008''&lt;br /&gt;
&lt;br /&gt;
Organizando la Agenda 2009 de la Seguridad en Aplicaciones Web:  OWASP los invita a participar de nuestra Cumbre en Portugal&lt;br /&gt;
http://www.owasp.org/index.php/OWASP_EU_Summit_2008_ES_Spanish&lt;br /&gt;
&lt;br /&gt;
Bajo el lema 'Organizando la Agenda 2009 de la Seguridad en Aplicaciones Web', la Cumbre OWASP será un encuentro mundial de líderes de OWASP y participantes clave de la industria que presentarán y discutirán las últimas herramientas OWASP, proyectos de documentación y tendencias en seguridad de aplicaciones web. Unase a nosotros en Portugal dentro de pocas semanas! Este evento contiene una vasta selección de cursos de entrenamiento, y charlas técnicas y de negocios, lo que lo convierte en EL evento donde aprender sobre seguridad en aplicaciones web, y sobre los recursos que OWASP tiene disponibles para utilizarse hoy.&lt;br /&gt;
&lt;br /&gt;
OWASP es una organización sin fines de lucro con el propósito de dar soporte a la comunidad de la Seguridad en Aplicaciones Web, y ha otorgado $250.000 dólares para investigación en dicha área. Más allá de las 40 presentaciones de los Líderes OWASP y beneficiarios de los fondos de investigación, la Cumbre OWASP será el anfitrión de múltiples Sesiones de Trabajo diseñadas para mejorar la colaboración, obtener objetivos específicos e identificar los próximos pasos para los proyectos, capítulos y comunidad OWASP.&lt;br /&gt;
&lt;br /&gt;
Para lograr este evento, OWASP invierte $150.000 dólares que serán utilizados para cubrir los gastos de alojamiento y viajes de los líderes OWASP, contribuidores activos, y líderes de la industria seleccionados quienes con su confirmada presencia (vea la lísta aquí: http://spreadsheets.google.com/pub?key=pAX6n7m2zaTVLrPtR07riBA) la Cumbre OWASP proveerá un cómodo pero profesional entorno donde encontrarse, discutir, influenciar y contribuir a los proyectos OWASP.&lt;br /&gt;
&lt;br /&gt;
La Cumbre OWASP será también el anfitrión de una gran y diversa selección de cursos de entrenamiento, los cuales cubrirán múltiples tématicas específicas a OWASP y a la Seguridad en Aplicaciones Web.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
El notable impacto de la OWASP es posible sólo por la colaboración de muchas personas dedicadas y organizaciones de todo el mundo. En el espíritu de la colaboración, OWASP invita a todos sus miembros y a todos los interesados, individuos y empresas por igual, a participar de este impactante evento. Por favor, únase y ayude a organizar la Agenda de Seguridad en Aplicaciones Web 2009!&lt;br /&gt;
&lt;br /&gt;
En cuanto a las cuestiones de Patrocinio, aún hay algunas oportunidades disponibles (vea: http://www.owasp.org/index.php/OWASP_EU_Summit_2008_Sponsors) – no pierda la oportunidad de asociar su marca a este notable evento de alcance mundial!&lt;br /&gt;
&lt;br /&gt;
Siga leyendo para obtener detalles adicionales sobre la Cumbre OWASP, o visite el sitio web de la mísma: http://www.owasp.org/index.php/OWASP_EU_Summit_2008.&lt;br /&gt;
&lt;br /&gt;
'''Proyectos'''&lt;br /&gt;
&lt;br /&gt;
OWASP projects selected for Summit presentation include new documentation and innovative tools to help developers, architects, and security specialists ensure that applications are secure:&lt;br /&gt;
&lt;br /&gt;
* Application Security Verification Standard,&lt;br /&gt;
* Code review guide, V1.1,&lt;br /&gt;
* Ruby on Rails Security Guide v2,&lt;br /&gt;
* Securing WebGoat using ModSecurity,&lt;br /&gt;
* Testing Guide v3,&lt;br /&gt;
* GTK+ GUI for w3af project,&lt;br /&gt;
* Access Control Rules Tester,&lt;br /&gt;
* AntiSamy .NET,&lt;br /&gt;
* Live CD &amp;amp; DVD Project,&lt;br /&gt;
* OpenPGP Extensions for HTTP,&lt;br /&gt;
* Orizon Project,&lt;br /&gt;
* Python Static Analysis,&lt;br /&gt;
* WebScarab-NG, &lt;br /&gt;
* And many, many others.&lt;br /&gt;
&lt;br /&gt;
'''Working Sessions'''&lt;br /&gt;
&lt;br /&gt;
Expecting the presence of the application security industry key players, the Working Sessions will cover a wide range of issues such as:&lt;br /&gt;
&lt;br /&gt;
* OWASP Top 10 2009, &lt;br /&gt;
* Browser Security,&lt;br /&gt;
* Web Application Framework Security, &lt;br /&gt;
* Enterprise Security API Project, &lt;br /&gt;
* Best Practices for OWASP Chapter Leaders, &lt;br /&gt;
* OWASP Documentation Projects, &lt;br /&gt;
* OWASP Tools Projects, &lt;br /&gt;
* OWASP Education Project, &lt;br /&gt;
* OWASP Strategic Planning for 2009, &lt;br /&gt;
* OWASP Certification,&lt;br /&gt;
* OWASP Winter of Code 2009&lt;br /&gt;
* Two-way Internationalization of OWASP Content&lt;br /&gt;
* And many more.&lt;br /&gt;
&lt;br /&gt;
'''Training'''&lt;br /&gt;
&lt;br /&gt;
These 2-day, 1-day or 1/2-day training courses cover a wide range of OWASP specific and Web Application Security Topics:&lt;br /&gt;
&lt;br /&gt;
* OWASP Top 10 - What Developers Should Know on Web Application Security&lt;br /&gt;
* Uncovering WebScarab's Secret Treasures&lt;br /&gt;
* Securing WebGoat with ModSecurity  &lt;br /&gt;
* Secure Programming with Java &lt;br /&gt;
* Advanced Web Application Security Testing &lt;br /&gt;
* Building Secure Web 2.0 Applications&lt;br /&gt;
* Building Secure Web Services&lt;br /&gt;
* Building Secure Web Applications with OWASP's Enterprise Security API (ESAPI)&lt;br /&gt;
* Classic ASP Security using OWASP tools &lt;br /&gt;
* Web Application Assessments&lt;br /&gt;
* Hacking Owasp Orizon Project v1.0&lt;br /&gt;
* Ajax Security&lt;br /&gt;
* Practical Penetration Testing: Think Like an Attacker to Stop Attacks&lt;br /&gt;
* Linux Software Exploitation&lt;br /&gt;
* Web server/services hardening using SELinux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Main Contact:&lt;br /&gt;
&lt;br /&gt;
Kate Hartmann&amp;lt;br/&amp;gt;&lt;br /&gt;
OWASP Operations Director&amp;lt;br/&amp;gt;&lt;br /&gt;
9175 Guilford Road, Suite 300&amp;lt;br/&amp;gt;&lt;br /&gt;
Columbia, MD 21046, USA&amp;lt;br/&amp;gt;&lt;br /&gt;
Phone: +1-301-575-0189&amp;lt;br/&amp;gt;&lt;br /&gt;
Facsimile: +1-301-604-8033&amp;lt;br/&amp;gt;&lt;br /&gt;
Email: kate.hartmann@owasp.org&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_ES_Spanish&amp;diff=43164</id>
		<title>OWASP EU Summit 2008 ES Spanish</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_ES_Spanish&amp;diff=43164"/>
				<updated>2008-10-13T16:26:37Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''translation work in progress'''&lt;br /&gt;
&lt;br /&gt;
== Translation of the official press release to Spanish ==&lt;br /&gt;
&lt;br /&gt;
'''Cumbre Europea de OWASP en Portugal'''&amp;lt;br&amp;gt;&lt;br /&gt;
''Portugal y Algarve  - 4 al 7 de Noviembre de 2008''&lt;br /&gt;
&lt;br /&gt;
Organizando la Agenda 2009 de la Seguridad en Aplicaciones Web:  OWASP los invita a participar de nuestra Cumbre en Portugal&lt;br /&gt;
http://www.owasp.org/index.php/OWASP_EU_Summit_2008_ES_Spanish&lt;br /&gt;
&lt;br /&gt;
Bajo el lema 'Organizando la Agenda 2009 de la Seguridad en Aplicaciones Web', la Cumbre OWASP será un encuentro mundial de líderes de OWASP y participantes clave de la industria que presentarán y discutirán las últimas herramientas OWASP, proyectos de documentación y tendencias en seguridad de aplicaciones web. Unase a nosotros en Portugal dentro de pocas semanas! Este evento contiene una vasta selección de cursos de entrenamiento, y charlas técnicas y de negocios, lo que lo convierte en EL evento donde aprender sobre seguridad en aplicaciones web, y sobre los recursos que OWASP tiene disponibles para utilizarse hoy.&lt;br /&gt;
&lt;br /&gt;
OWASP es una organización sin fines de lucro con el propósito de dar soporte a la comunidad de la Seguridad en Aplicaciones Web, y ha otorgado $250.000 dólares para investigación en dicha área. Más allá de las 40 presentaciones de los Líderes OWASP y beneficiarios de los fondos de investigación, la Cumbre OWASP será el anfitrión de múltiples Sesiones de Trabajo diseñadas para mejorar la colaboración, obtener objetivos específicos e identificar los próximos pasos para los proyectos, capítulos y comunidad OWASP.&lt;br /&gt;
&lt;br /&gt;
Para lograr este evento, OWASP invierte $150.000 dólares que serán utilizados para cubrir los gastos de alojamiento y viajes de los líderes OWASP, contribuidores activos, y líderes de la industria seleccionados quienes con su confirmada presencia (vea la lísta aquí: http://spreadsheets.google.com/pub?key=pAX6n7m2zaTVLrPtR07riBA) la Cumbre OWASP proveerá un cómodo pero profesional entorno donde encontrarse, discutir, influenciar y contribuir a los proyectos OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP Summit will also host a large and diverse selection of training courses, covering multiple OWASP specific and Web Application Security Topics. &lt;br /&gt;
&lt;br /&gt;
The remarkable impact of OWASP is made possible only by the collaboration of many dedicated people and organizations worldwide.  In that spirit of cooperation, OWASP invites all its members and interested individuals and companies to attend this thrilling event.  Please join us and help to set the Web Application Security Agenda for 2009!&lt;br /&gt;
&lt;br /&gt;
Regarding the event sponsorship matters, there are still a few opportunities available (see here http://www.owasp.org/index.php/OWASP_EU_Summit_2008_Sponsors) – do not miss the opportunity to associate your brand with this gripping and worldwide event!&lt;br /&gt;
&lt;br /&gt;
Please see below for additional details about the OWASP Summit or visit the OWASP Summit website: http://www.owasp.org/index.php/OWASP_EU_Summit_2008.&lt;br /&gt;
&lt;br /&gt;
'''Projects'''&lt;br /&gt;
&lt;br /&gt;
OWASP projects selected for Summit presentation include new documentation and innovative tools to help developers, architects, and security specialists ensure that applications are secure:&lt;br /&gt;
&lt;br /&gt;
* Application Security Verification Standard,&lt;br /&gt;
* Code review guide, V1.1,&lt;br /&gt;
* Ruby on Rails Security Guide v2,&lt;br /&gt;
* Securing WebGoat using ModSecurity,&lt;br /&gt;
* Testing Guide v3,&lt;br /&gt;
* GTK+ GUI for w3af project,&lt;br /&gt;
* Access Control Rules Tester,&lt;br /&gt;
* AntiSamy .NET,&lt;br /&gt;
* Live CD &amp;amp; DVD Project,&lt;br /&gt;
* OpenPGP Extensions for HTTP,&lt;br /&gt;
* Orizon Project,&lt;br /&gt;
* Python Static Analysis,&lt;br /&gt;
* WebScarab-NG, &lt;br /&gt;
* And many, many others.&lt;br /&gt;
&lt;br /&gt;
'''Working Sessions'''&lt;br /&gt;
&lt;br /&gt;
Expecting the presence of the application security industry key players, the Working Sessions will cover a wide range of issues such as:&lt;br /&gt;
&lt;br /&gt;
* OWASP Top 10 2009, &lt;br /&gt;
* Browser Security,&lt;br /&gt;
* Web Application Framework Security, &lt;br /&gt;
* Enterprise Security API Project, &lt;br /&gt;
* Best Practices for OWASP Chapter Leaders, &lt;br /&gt;
* OWASP Documentation Projects, &lt;br /&gt;
* OWASP Tools Projects, &lt;br /&gt;
* OWASP Education Project, &lt;br /&gt;
* OWASP Strategic Planning for 2009, &lt;br /&gt;
* OWASP Certification,&lt;br /&gt;
* OWASP Winter of Code 2009&lt;br /&gt;
* Two-way Internationalization of OWASP Content&lt;br /&gt;
* And many more.&lt;br /&gt;
&lt;br /&gt;
'''Training'''&lt;br /&gt;
&lt;br /&gt;
These 2-day, 1-day or 1/2-day training courses cover a wide range of OWASP specific and Web Application Security Topics:&lt;br /&gt;
&lt;br /&gt;
* OWASP Top 10 - What Developers Should Know on Web Application Security&lt;br /&gt;
* Uncovering WebScarab's Secret Treasures&lt;br /&gt;
* Securing WebGoat with ModSecurity  &lt;br /&gt;
* Secure Programming with Java &lt;br /&gt;
* Advanced Web Application Security Testing &lt;br /&gt;
* Building Secure Web 2.0 Applications&lt;br /&gt;
* Building Secure Web Services&lt;br /&gt;
* Building Secure Web Applications with OWASP's Enterprise Security API (ESAPI)&lt;br /&gt;
* Classic ASP Security using OWASP tools &lt;br /&gt;
* Web Application Assessments&lt;br /&gt;
* Hacking Owasp Orizon Project v1.0&lt;br /&gt;
* Ajax Security&lt;br /&gt;
* Practical Penetration Testing: Think Like an Attacker to Stop Attacks&lt;br /&gt;
* Linux Software Exploitation&lt;br /&gt;
* Web server/services hardening using SELinux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Main Contact:&lt;br /&gt;
&lt;br /&gt;
Kate Hartmann&amp;lt;br/&amp;gt;&lt;br /&gt;
OWASP Operations Director&amp;lt;br/&amp;gt;&lt;br /&gt;
9175 Guilford Road, Suite 300&amp;lt;br/&amp;gt;&lt;br /&gt;
Columbia, MD 21046, USA&amp;lt;br/&amp;gt;&lt;br /&gt;
Phone: +1-301-575-0189&amp;lt;br/&amp;gt;&lt;br /&gt;
Facsimile: +1-301-604-8033&amp;lt;br/&amp;gt;&lt;br /&gt;
Email: kate.hartmann@owasp.org&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_ES_Spanish&amp;diff=43163</id>
		<title>OWASP EU Summit 2008 ES Spanish</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_ES_Spanish&amp;diff=43163"/>
				<updated>2008-10-13T16:18:01Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: work in progress&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''translation work in progress'''&lt;br /&gt;
&lt;br /&gt;
== Translation of the official press release to Spanish ==&lt;br /&gt;
&lt;br /&gt;
'''Cumbre Europea de OWASP en Portugal'''&amp;lt;br&amp;gt;&lt;br /&gt;
''Portugal y Algarve  - 4 al 7 de Noviembre de 2008''&lt;br /&gt;
&lt;br /&gt;
Organizando la Agenda 2009 de la Seguridad en Aplicaciones Web:  OWASP los invita a participar de nuestra Cumbre en Portugal&lt;br /&gt;
http://www.owasp.org/index.php/OWASP_EU_Summit_2008_ES_Spanish&lt;br /&gt;
&lt;br /&gt;
Bajo el lema 'Organizando la Agenda 2009 de la Seguridad en Aplicaciones Web', la Cumbre OWASP será un encuentro mundial de líderes de OWASP y participantes clave de la industria que presentarán y discutirán las últimas herramientas OWASP, proyectos de documentación y tendencias en seguridad de aplicaciones web. Unase a nosotros en Portugal dentro de pocas semanas! Este evento contiene una vasta selección de cursos de entrenamiento, y charlas técnicas y de negocios, lo que lo convierte en EL evento donde aprender sobre seguridad en aplicaciones web, y sobre los recursos que OWASP tiene disponibles para utilizarse hoy.&lt;br /&gt;
&lt;br /&gt;
OWASP is a not-for-profit organization with the purpose of supporting the Web Application Security community around the world, and has granted $250,000 USD for web application security research.  In addition to over 40 presentations from the OWASP Leaders and grant recipients, the OWASP Summit will host multiple Working Sessions designed to improve collaboration, achieve specific objectives and identify roadmaps for OWASP projects, chapters, and the OWASP community itself. &lt;br /&gt;
&lt;br /&gt;
To facilitate this event, OWASP is investing $150,000 USD which will be used to cover air travel and accommodation expenses for OWASP leaders, active contributors, and select key industry leaders.  With their confirmed presence (see list here: http://spreadsheets.google.com/pub?key=pAX6n7m2zaTVLrPtR07riBA), the OWASP Summit will provide a relaxed but professional environment to meet, discuss, influence and contribute to OWASP projects.&lt;br /&gt;
&lt;br /&gt;
The OWASP Summit will also host a large and diverse selection of training courses, covering multiple OWASP specific and Web Application Security Topics. &lt;br /&gt;
&lt;br /&gt;
The remarkable impact of OWASP is made possible only by the collaboration of many dedicated people and organizations worldwide.  In that spirit of cooperation, OWASP invites all its members and interested individuals and companies to attend this thrilling event.  Please join us and help to set the Web Application Security Agenda for 2009!&lt;br /&gt;
&lt;br /&gt;
Regarding the event sponsorship matters, there are still a few opportunities available (see here http://www.owasp.org/index.php/OWASP_EU_Summit_2008_Sponsors) – do not miss the opportunity to associate your brand with this gripping and worldwide event!&lt;br /&gt;
&lt;br /&gt;
Please see below for additional details about the OWASP Summit or visit the OWASP Summit website: http://www.owasp.org/index.php/OWASP_EU_Summit_2008.&lt;br /&gt;
&lt;br /&gt;
'''Projects'''&lt;br /&gt;
&lt;br /&gt;
OWASP projects selected for Summit presentation include new documentation and innovative tools to help developers, architects, and security specialists ensure that applications are secure:&lt;br /&gt;
&lt;br /&gt;
* Application Security Verification Standard,&lt;br /&gt;
* Code review guide, V1.1,&lt;br /&gt;
* Ruby on Rails Security Guide v2,&lt;br /&gt;
* Securing WebGoat using ModSecurity,&lt;br /&gt;
* Testing Guide v3,&lt;br /&gt;
* GTK+ GUI for w3af project,&lt;br /&gt;
* Access Control Rules Tester,&lt;br /&gt;
* AntiSamy .NET,&lt;br /&gt;
* Live CD &amp;amp; DVD Project,&lt;br /&gt;
* OpenPGP Extensions for HTTP,&lt;br /&gt;
* Orizon Project,&lt;br /&gt;
* Python Static Analysis,&lt;br /&gt;
* WebScarab-NG, &lt;br /&gt;
* And many, many others.&lt;br /&gt;
&lt;br /&gt;
'''Working Sessions'''&lt;br /&gt;
&lt;br /&gt;
Expecting the presence of the application security industry key players, the Working Sessions will cover a wide range of issues such as:&lt;br /&gt;
&lt;br /&gt;
* OWASP Top 10 2009, &lt;br /&gt;
* Browser Security,&lt;br /&gt;
* Web Application Framework Security, &lt;br /&gt;
* Enterprise Security API Project, &lt;br /&gt;
* Best Practices for OWASP Chapter Leaders, &lt;br /&gt;
* OWASP Documentation Projects, &lt;br /&gt;
* OWASP Tools Projects, &lt;br /&gt;
* OWASP Education Project, &lt;br /&gt;
* OWASP Strategic Planning for 2009, &lt;br /&gt;
* OWASP Certification,&lt;br /&gt;
* OWASP Winter of Code 2009&lt;br /&gt;
* Two-way Internationalization of OWASP Content&lt;br /&gt;
* And many more.&lt;br /&gt;
&lt;br /&gt;
'''Training'''&lt;br /&gt;
&lt;br /&gt;
These 2-day, 1-day or 1/2-day training courses cover a wide range of OWASP specific and Web Application Security Topics:&lt;br /&gt;
&lt;br /&gt;
* OWASP Top 10 - What Developers Should Know on Web Application Security&lt;br /&gt;
* Uncovering WebScarab's Secret Treasures&lt;br /&gt;
* Securing WebGoat with ModSecurity  &lt;br /&gt;
* Secure Programming with Java &lt;br /&gt;
* Advanced Web Application Security Testing &lt;br /&gt;
* Building Secure Web 2.0 Applications&lt;br /&gt;
* Building Secure Web Services&lt;br /&gt;
* Building Secure Web Applications with OWASP's Enterprise Security API (ESAPI)&lt;br /&gt;
* Classic ASP Security using OWASP tools &lt;br /&gt;
* Web Application Assessments&lt;br /&gt;
* Hacking Owasp Orizon Project v1.0&lt;br /&gt;
* Ajax Security&lt;br /&gt;
* Practical Penetration Testing: Think Like an Attacker to Stop Attacks&lt;br /&gt;
* Linux Software Exploitation&lt;br /&gt;
* Web server/services hardening using SELinux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Main Contact:&lt;br /&gt;
&lt;br /&gt;
Kate Hartmann&amp;lt;br/&amp;gt;&lt;br /&gt;
OWASP Operations Director&amp;lt;br/&amp;gt;&lt;br /&gt;
9175 Guilford Road, Suite 300&amp;lt;br/&amp;gt;&lt;br /&gt;
Columbia, MD 21046, USA&amp;lt;br/&amp;gt;&lt;br /&gt;
Phone: +1-301-575-0189&amp;lt;br/&amp;gt;&lt;br /&gt;
Facsimile: +1-301-604-8033&amp;lt;br/&amp;gt;&lt;br /&gt;
Email: kate.hartmann@owasp.org&amp;lt;br/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_ES_Spanish&amp;diff=43161</id>
		<title>OWASP EU Summit 2008 ES Spanish</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008_ES_Spanish&amp;diff=43161"/>
				<updated>2008-10-13T16:08:04Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: New page: '''translation work in progress'''&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''translation work in progress'''&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008--PRESS&amp;diff=43160</id>
		<title>OWASP EU Summit 2008--PRESS</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008--PRESS&amp;diff=43160"/>
				<updated>2008-10-13T16:06:11Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: added spanish link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[:OWASP EU Summit 2008|'''Please click here to return to the OWASP EU Summit Portugal 2008 main page''']].&lt;br /&gt;
&lt;br /&gt;
Press registration is open to any member of the broadcast, print and Internet media who can prove they work for an organization or publication that covers computer security on a regular basis. At the conference we will provide a press room with Internet access and electrical outlets for laptop computers. If you need a separate room for filming interviews, please request it in advance in the comments section. Let us know if there are any other special needs such as speakers you want to interview when you arrive or other items such as computer access to file stories or a fax machine.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
We welcome anyone to apply for press credentials but reserve the right to deny you a pass. As such, please be prepared to show us copies of your articles either at your publication's Web site or on the publication's masthead should we request it.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
At the show, please be able to present a business card, and government issued picture id, article on your organization's masthead and contact information for your assignment editor should we need it to validate your credentials before issuing you a pass.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Press registration may be granted for the conference and working sessions seminars only. There are no press passes available for Training.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Please make a point to pre-register. Should you attempt to attain credentials on-site, we cannot guarantee you will qualify and must bring all information in the above paragraph.&lt;br /&gt;
&lt;br /&gt;
To register please ask [mailto:kate.hartmann(at)owasp.org Kate Hartmann] for a password and use: [http://guest.cvent.com/i.aspx?4W,M3,35818773-e14b-4d8e-8db8-5e14a6285a3d http://www.owasp.org/images/7/7f/Register.gif]&lt;br /&gt;
&lt;br /&gt;
== Confirmed Media presence at the Summit ==&lt;br /&gt;
&lt;br /&gt;
== Media Resources for Working Sessions ==&lt;br /&gt;
The following text is being provided by the chairs from each of the [[OWASP EU Summit 2008#WORKING_SESSIONS_-_November_4th_.26_5th_.28Tue.2C_Wed.29]].  It explains why the working session is important, why it matters to the industry and what might be the beneficial outcomes.  We hope to have public/industry information from all the working sessions here in due course for advanced publicity purposes.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | OWASP Documentation Projects&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; valign=&amp;quot;top&amp;quot; | Briefing Text || style=&amp;quot;background:#F2F2F2&amp;quot; | The working session on OWASP Documentation Projects is a great chance to understand how the set of OWASP related documents can be used as a toolset to promote security on software development and management. The outcomes from PCI DSS v.1.2 and other standards that will come form the market, shows how important is to understand the importance of protection measures on coding and how these actions will come back in high quality products that can reach the market in a more adequate fashion.&lt;br /&gt;
&lt;br /&gt;
The outcomes will promote OWASP documents in the market and to be part of it will make the difference for your company, your career and your personal contribution for the security community.&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; valign=&amp;quot;top&amp;quot;  | Session Page || style=&amp;quot;background:#C2C2C2&amp;quot; | [[OWASP_Working_Session_-_OWASP_Documentation_Projects]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | OWASP Education Project&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; valign=&amp;quot;top&amp;quot; | Briefing Text || style=&amp;quot;background:#F2F2F2&amp;quot; | &lt;br /&gt;
There is plenty of knowledge available inside the OWASP community, spread via the wiki, Conferences, chapter meetings and not to forget the books.&lt;br /&gt;
 &lt;br /&gt;
Another important way to distribute the available knowledge is though education! &lt;br /&gt;
&lt;br /&gt;
The Summit Working Session on Education will cover important aspects such as:&lt;br /&gt;
* How to improve knowledge transfer from OWASP projects towards the community,&lt;br /&gt;
* How to create training material (lessons, classes, courses) from OWASP project material?&lt;br /&gt;
* How to set up an OWASP education baseline,&lt;br /&gt;
* How to setup an OWASP Boot Camp,&lt;br /&gt;
* How to connect to organisation to promote OWASP education content: e.g. universities, other non-profit (or profit?) education organisations,&lt;br /&gt;
* How to organize the OWASP / Conference trainings to make them the best in the world?&lt;br /&gt;
* Can we integrate this into OWASP certification projects?&lt;br /&gt;
* How to setup an OWASP Boot Camp?&lt;br /&gt;
&lt;br /&gt;
This working session is the ideal opportunity to build further on the shoulders of giants and spread OWASP's solutions through the education project!&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; valign=&amp;quot;top&amp;quot;  | Session Page || style=&amp;quot;background:#C2C2C2&amp;quot; | [[OWASP_Working_Session_Education_Project]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;br /&gt;
&lt;br /&gt;
== PRESS RELEASES ==&lt;br /&gt;
&lt;br /&gt;
=== OWASP European Summit/October 13th, 2008 ===&lt;br /&gt;
&lt;br /&gt;
'''OWASP European Summit - Portugal'''&amp;lt;br&amp;gt;&lt;br /&gt;
''Portugal/Algarve  - 4th - 7th November 2008''&lt;br /&gt;
&lt;br /&gt;
Setting the Web Application Security Agenda for 2009:  OWASP Invites You to Join Our Summit in Portugal&lt;br /&gt;
http://www.owasp.org/index.php/OWASP_EU_Summit_2008 &lt;br /&gt;
&lt;br /&gt;
With the theme 'Setting the AppSec agenda for 2009', the OWASP Summit will be a worldwide gathering of OWASP leaders and key industry players to present and discuss the latest OWASP tools, documentation projects, and web application security trends. Join us in Portugal in just a few short weeks! This venue hosts a diverse selection of training courses along with technical and business tracks, making it THE place to learn about web application security and the resources OWASP has available for use today. &lt;br /&gt;
&lt;br /&gt;
OWASP is a not-for-profit organization with the purpose of supporting the Web Application Security community around the world, and has granted $250,000 USD for web application security research.  In addition to over 40 presentations from the OWASP Leaders and grant recipients, the OWASP Summit will host multiple Working Sessions designed to improve collaboration, achieve specific objectives and identify roadmaps for OWASP projects, chapters, and the OWASP community itself. &lt;br /&gt;
&lt;br /&gt;
To facilitate this event, OWASP is investing $150,000 USD which will be used to cover air travel and accommodation expenses for OWASP leaders, active contributors, and select key industry leaders.  With their confirmed presence (see list here: http://spreadsheets.google.com/pub?key=pAX6n7m2zaTVLrPtR07riBA), the OWASP Summit will provide a relaxed but professional environment to meet, discuss, influence and contribute to OWASP projects.&lt;br /&gt;
&lt;br /&gt;
The OWASP Summit will also host a large and diverse selection of training courses, covering multiple OWASP specific and Web Application Security Topics. &lt;br /&gt;
&lt;br /&gt;
The remarkable impact of OWASP is made possible only by the collaboration of many dedicated people and organizations worldwide.  In that spirit of cooperation, OWASP invites all its members and interested individuals and companies to attend this thrilling event.  Please join us and help to set the Web Application Security Agenda for 2009!&lt;br /&gt;
&lt;br /&gt;
Regarding the event sponsorship matters, there are still a few opportunities available (see here http://www.owasp.org/index.php/OWASP_EU_Summit_2008_Sponsors) – do not miss the opportunity to associate your brand with this gripping and worldwide event!&lt;br /&gt;
&lt;br /&gt;
Please see below for additional details about the OWASP Summit or visit the OWASP Summit website: http://www.owasp.org/index.php/OWASP_EU_Summit_2008.&lt;br /&gt;
&lt;br /&gt;
'''Projects'''&lt;br /&gt;
&lt;br /&gt;
OWASP projects selected for Summit presentation include new documentation and innovative tools to help developers, architects, and security specialists ensure that applications are secure:&lt;br /&gt;
&lt;br /&gt;
* Application Security Verification Standard,&lt;br /&gt;
* Code review guide, V1.1,&lt;br /&gt;
* Ruby on Rails Security Guide v2,&lt;br /&gt;
* Securing WebGoat using ModSecurity,&lt;br /&gt;
* Testing Guide v3,&lt;br /&gt;
* GTK+ GUI for w3af project,&lt;br /&gt;
* Access Control Rules Tester,&lt;br /&gt;
* AntiSamy .NET,&lt;br /&gt;
* Live CD &amp;amp; DVD Project,&lt;br /&gt;
* OpenPGP Extensions for HTTP,&lt;br /&gt;
* Orizon Project,&lt;br /&gt;
* Python Static Analysis,&lt;br /&gt;
* WebScarab-NG, &lt;br /&gt;
* And many, many others.&lt;br /&gt;
&lt;br /&gt;
'''Working Sessions'''&lt;br /&gt;
&lt;br /&gt;
Expecting the presence of the application security industry key players, the Working Sessions will cover a wide range of issues such as:&lt;br /&gt;
&lt;br /&gt;
* OWASP Top 10 2009, &lt;br /&gt;
* Browser Security,&lt;br /&gt;
* Web Application Framework Security, &lt;br /&gt;
* Enterprise Security API Project, &lt;br /&gt;
* Best Practices for OWASP Chapter Leaders, &lt;br /&gt;
* OWASP Documentation Projects, &lt;br /&gt;
* OWASP Tools Projects, &lt;br /&gt;
* OWASP Education Project, &lt;br /&gt;
* OWASP Strategic Planning for 2009, &lt;br /&gt;
* OWASP Certification,&lt;br /&gt;
* OWASP Winter of Code 2009&lt;br /&gt;
* Two-way Internationalization of OWASP Content&lt;br /&gt;
* And many more.&lt;br /&gt;
&lt;br /&gt;
'''Training'''&lt;br /&gt;
&lt;br /&gt;
These 2-day, 1-day or 1/2-day training courses cover a wide range of OWASP specific and Web Application Security Topics:&lt;br /&gt;
&lt;br /&gt;
* OWASP Top 10 - What Developers Should Know on Web Application Security&lt;br /&gt;
* Uncovering WebScarab's Secret Treasures&lt;br /&gt;
* Securing WebGoat with ModSecurity  &lt;br /&gt;
* Secure Programming with Java &lt;br /&gt;
* Advanced Web Application Security Testing &lt;br /&gt;
* Building Secure Web 2.0 Applications&lt;br /&gt;
* Building Secure Web Services&lt;br /&gt;
* Building Secure Web Applications with OWASP's Enterprise Security API (ESAPI)&lt;br /&gt;
* Classic ASP Security using OWASP tools &lt;br /&gt;
* Web Application Assessments&lt;br /&gt;
* Hacking Owasp Orizon Project v1.0&lt;br /&gt;
* Ajax Security&lt;br /&gt;
* Practical Penetration Testing: Think Like an Attacker to Stop Attacks&lt;br /&gt;
* Linux Software Exploitation&lt;br /&gt;
* Web server/services hardening using SELinux&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Main Contact:&lt;br /&gt;
&lt;br /&gt;
Kate Hartmann&amp;lt;br/&amp;gt;&lt;br /&gt;
OWASP Operations Director&amp;lt;br/&amp;gt;&lt;br /&gt;
9175 Guilford Road, Suite 300&amp;lt;br/&amp;gt;&lt;br /&gt;
Columbia, MD 21046, USA&amp;lt;br/&amp;gt;&lt;br /&gt;
Phone: +1-301-575-0189&amp;lt;br/&amp;gt;&lt;br /&gt;
Facsimile: +1-301-604-8033&amp;lt;br/&amp;gt;&lt;br /&gt;
Email: kate.hartmann@owasp.org&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Portuguese Version ====&lt;br /&gt;
&lt;br /&gt;
Please click [http://www.box.net/shared/a8bol7salv here] to see.&lt;br /&gt;
'''Bold text'''&lt;br /&gt;
&lt;br /&gt;
==== Brazilian Version ====&lt;br /&gt;
&lt;br /&gt;
Please click [http://convisosec.com/PublicDocuments/OWASP/owaspeusummitpressreleasebr.pdf here] to see.&lt;br /&gt;
&lt;br /&gt;
==== French Version ====&lt;br /&gt;
&lt;br /&gt;
Please click [[OWASP EU Summit 2008 PR French|here]] to see.&lt;br /&gt;
&lt;br /&gt;
==== Spanish Version ====&lt;br /&gt;
&lt;br /&gt;
Please click [[OWASP EU Summit 2008 ES Spanish|here]] to see.&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=33592</id>
		<title>Project Information:template Enigform and mod OpenPGP</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=33592"/>
				<updated>2008-07-07T14:19:50Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The goal of this project is to focus on mod_openpgp and Secure Session Management, presenting a working web-site using this new authentication methodology in such a way that it will attract security professionals and web-developers to this new mix of two good'ol protocols: HTTP and OpenPGP. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:buanzo(at)buanzo.com.ar '''Arturo 'Buanzo' Busleiman''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/buanzo Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:to(at)change '''Name&amp;amp;Email''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-enigform-and-mod-openpgp '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:Owasp-Enigform-and-mod-OpenPGP@lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:mark.roxberry(at)owasp.org '''Mark Roxberry''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/roxberry Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:dinis.cruz(at)owasp.org '''Dinis Cruz''']&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;Not applicable&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[http://digg.com/security/Feedback_Request_Ideas_for_an_Enigform_mod_openpgp_website '''Feedback Request - Click here for more details''']&lt;br /&gt;
* http://wiki.buanzo.org - Main mod_openpgp and Enigform documentation (Wiki)&lt;br /&gt;
* http://maotest.buanzo.org - Main Enigform / mod_openpgp test site.&lt;br /&gt;
* http://enigform.mozdev.org - Main Enigform Development site&lt;br /&gt;
* http://foros.buanzo.com.ar/viewforum.php?f=35 - Enigform / mod_openpgp Support Forum&lt;br /&gt;
* svn://svn.buanzo.org/mod_openpgp - mod_openpgp and test-site / tools subversion repository.&lt;br /&gt;
* http://www.freesoftwaremagazine.com/blogs/interview_with_arturo_busleiman - An Interview with Buanzo.&lt;br /&gt;
* http://freshmeat.net/articles/view/2599 - An early Enigform article.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Enigform: Firefox Addon for OpenPGP signing of HTTP requests Project]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OpenPGP Extensions for HTTP - Enigform and mod_openpgp|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - Self Evaluation - A|Click to read 50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - First Reviewer - C|Click to read 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=33591</id>
		<title>Project Information:template Enigform and mod OpenPGP</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=33591"/>
				<updated>2008-07-07T14:17:49Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The goal of this project is to focus on mod_openpgp and Secure Session Management, presenting a working web-site using this new authentication methodology in such a way that it will attract security professionals and web-developers to this new mix of two good'ol protocols: HTTP and OpenPGP. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:buanzo(at)buanzo.com.ar '''Arturo 'Buanzo' Busleiman''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/buanzo Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:to(at)change '''Name&amp;amp;Email''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-enigform-and-mod-openpgp '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:Owasp-Enigform-and-mod-OpenPGP@lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:mark.roxberry(at)owasp.org '''Mark Roxberry''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/roxberry Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:dinis.cruz(at)owasp.org '''Dinis Cruz''']&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;Not applicable&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[http://digg.com/security/Feedback_Request_Ideas_for_an_Enigform_mod_openpgp_website '''Feedback Request - Click here for more''']&lt;br /&gt;
* http://wiki.buanzo.org - Main mod_openpgp and Enigform documentation (Wiki)&lt;br /&gt;
* http://maotest.buanzo.org - Main Enigform / mod_openpgp test site.&lt;br /&gt;
* http://enigform.mozdev.org - Main Enigform Development site&lt;br /&gt;
* http://foros.buanzo.com.ar/viewforum.php?f=35 - Enigform / mod_openpgp Support Forum&lt;br /&gt;
* svn://svn.buanzo.org/mod_openpgp - mod_openpgp and test-site / tools subversion repository.&lt;br /&gt;
* http://www.freesoftwaremagazine.com/blogs/interview_with_arturo_busleiman - An Interview with Buanzo.&lt;br /&gt;
* http://freshmeat.net/articles/view/2599 - An early Enigform article.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Enigform: Firefox Addon for OpenPGP signing of HTTP requests Project]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OpenPGP Extensions for HTTP - Enigform and mod_openpgp|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - Self Evaluation - A|Click to read 50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - First Reviewer - C|Click to read 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=33279</id>
		<title>Project Information:template Enigform and mod OpenPGP</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=33279"/>
				<updated>2008-07-03T11:03:24Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The goal of this project is to focus on mod_openpgp and Secure Session Management, presenting a working web-site using this new authentication methodology in such a way that it will attract security professionals and web-developers to this new mix of two good'ol protocols: HTTP and OpenPGP. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:buanzo(at)buanzo.com.ar '''Arturo 'Buanzo' Busleiman''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/buanzo Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:to(at)change '''Name&amp;amp;Email''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-enigform-and-mod-openpgp '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:Owasp-Enigform-and-mod-OpenPGP@lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:mark.roxberry(at)owasp.org '''Mark Roxberry''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/roxberry Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:dinis.cruz(at)owasp.org '''Dinis Cruz''']&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;Not applicable&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* http://wiki.buanzo.org - Main mod_openpgp and Enigform documentation (Wiki)&lt;br /&gt;
* http://maotest.buanzo.org - Main Enigform / mod_openpgp test site.&lt;br /&gt;
* http://enigform.mozdev.org - Main Enigform Development site&lt;br /&gt;
* http://foros.buanzo.com.ar/viewforum.php?f=35 - Enigform / mod_openpgp Support Forum&lt;br /&gt;
* svn://svn.buanzo.org/mod_openpgp - mod_openpgp and test-site / tools subversion repository.&lt;br /&gt;
* http://www.freesoftwaremagazine.com/blogs/interview_with_arturo_busleiman - An Interview with Buanzo.&lt;br /&gt;
* http://freshmeat.net/articles/view/2599 - An early Enigform article.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Enigform: Firefox Addon for OpenPGP signing of HTTP requests Project]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OpenPGP Extensions for HTTP - Enigform and mod_openpgp|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - Self Evaluation - A|Click to read 50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - First Reviewer - C|Click to read 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=33277</id>
		<title>Project Information:template Enigform and mod OpenPGP</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=33277"/>
				<updated>2008-07-03T11:02:03Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: set &amp;quot;Objectives &amp;amp; Deliveries reached -&amp;gt; Yes&amp;quot; for Author and 1st reviewer, according to reviews.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The goal of this project is to focus on mod_openpgp and Secure Session Management, presenting a working web-site using this new authentication methodology in such a way that it will attract security professionals and web-developers to this new mix of two good'ol protocols: HTTP and OpenPGP. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:buanzo(at)buanzo.com.ar '''Arturo 'Buanzo' Busleiman''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/buanzo Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:to(at)change '''Name&amp;amp;Email''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-enigform-and-mod-openpgp '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:Owasp-Enigform-and-mod-OpenPGP@lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:mark.roxberry(at)owasp.org '''Mark Roxberry''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/roxberry Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:dinis.cruz(at)owasp.org '''Dinis Cruz''']&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;Not applicable&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* http://wiki.buanzo.org - Main mod_openpgp and Enigform documentation (Wiki)&lt;br /&gt;
* http://maotest.buanzo.org - Main Enigform / mod_openpgp test site.&lt;br /&gt;
* http://enigform.mozdev.org - Main Enigform Development site&lt;br /&gt;
* http://foros.buanzo.com.ar/viewforum.php?f=35 - Enigform / mod_openpgp Support Forum&lt;br /&gt;
* svn://svn.buanzo.org/mod_openpgp - mod_openpgp and test-site / tools subversion repository.&lt;br /&gt;
* http://www.freesoftwaremagazine.com/blogs/interview_with_arturo_busleiman - An Interview with Buanzo.&lt;br /&gt;
* http://freshmeat.net/articles/view/2599 - An early Enigform article.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Enigform: Firefox Addon for OpenPGP signing of HTTP requests Project]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OpenPGP Extensions for HTTP - Enigform and mod_openpgp|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes'''&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP_-_50_Review_-_Self_Evaluation_-_A&amp;diff=33162</id>
		<title>Project Information:template Enigform and mod OpenPGP - 50 Review - Self Evaluation - A</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP_-_50_Review_-_Self_Evaluation_-_A&amp;diff=33162"/>
				<updated>2008-07-02T15:21:53Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[Project Information:template Enigform and mod OpenPGP|Click here to return to the previous page]].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''50% REVIEW PROCESS''' &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
Project Deliveries &amp;amp; Objectives  &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&lt;br /&gt;
[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OpenPGP Extensions for HTTP - Enigform and mod_openpgp|OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp  Project's Deliveries &amp;amp; Objectives]]&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25x%; background:#4058A0&amp;quot; align=&amp;quot;center&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''QUESTIONS''' &lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#4058A0&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''ANSWERS'''  &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
1. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OpenPGP Extensions for HTTP - Enigform and mod_openpgp|'''the assumed ones''']], please exemplify writing down those of them that haven't been realised.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|I'm working on more replay-attacks countermeasures, and we are deciding on the &amp;quot;Demo Site&amp;quot; issue. I still have to do research on WebGoat, but I also thought about creating an Enigform Auth plugin for Wordpress, phpBB, etc. I'd like to point out that the maotest.buanzo.org website is a TESTING site, and not an actual Demo site. Still to  implement: * Automatic Sessions Termination on Firefox Exit/Crash, * Better error-handling (Client side), * More documentation (current one suffices to implement a mod_openpgp enabled Apache server, but lacks better client-side FAQs and HOWTOs).&lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| &lt;br /&gt;
&lt;br /&gt;
2. At what extent have the project deliveries &amp;amp; objectives been accomplished?  Having in consideration [[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OpenPGP Extensions for HTTP - Enigform and mod_openpgp|'''the assumed ones''']], please quantify in terms of percentage.&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|I agree with Mark Roxberry's 60% completeness. The other 40% will mainly be Documentation, bugfixes and minor improvements, but a big % regarding the Demo site / Auth Plugin idea.&lt;br /&gt;
 |- &lt;br /&gt;
 |- &lt;br /&gt;
 | style=&amp;quot;width:25%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
3. What kind of help is required either from the Reviewers or from the OWASP Community?&lt;br /&gt;
 | colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:75%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|Mark has been a GREAT help. He was not only a reviewer but a devoted beta tester. I'm glad to be working with him.&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=33144</id>
		<title>Project Information:template Enigform and mod OpenPGP</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=33144"/>
				<updated>2008-07-02T14:27:03Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: added Buanzo's linkedin profile link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The goal of this project is to focus on mod_openpgp and Secure Session Management, presenting a working web-site using this new authentication methodology in such a way that it will attract security professionals and web-developers to this new mix of two good'ol protocols: HTTP and OpenPGP. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:buanzo(at)buanzo.com.ar '''Arturo 'Buanzo' Busleiman''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/buanzo Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:to(at)change '''Name&amp;amp;Email''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-enigform-and-mod-openpgp '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:Owasp-Enigform-and-mod-OpenPGP@lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:mark.roxberry(at)owasp.org '''Mark Roxberry''']&amp;lt;br&amp;gt;[http://www.linkedin.com/in/roxberry Profile]&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:name@name '''Name''']&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:dinis.cruz(at)owasp.org '''Dinis Cruz''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* http://wiki.buanzo.org - Main mod_openpgp and Enigform documentation (Wiki)&lt;br /&gt;
* http://maotest.buanzo.org - Main Enigform / mod_openpgp test site.&lt;br /&gt;
* http://enigform.mozdev.org - Main Enigform Development site&lt;br /&gt;
* http://foros.buanzo.com.ar/viewforum.php?f=35 - Enigform / mod_openpgp Support Forum&lt;br /&gt;
* svn://svn.buanzo.org/mod_openpgp - mod_openpgp and test-site / tools subversion repository.&lt;br /&gt;
* http://www.freesoftwaremagazine.com/blogs/interview_with_arturo_busleiman - An Interview with Buanzo.&lt;br /&gt;
* http://freshmeat.net/articles/view/2599 - An early Enigform article.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Enigform: Firefox Addon for OpenPGP signing of HTTP requests Project]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OpenPGP Extensions for HTTP - Enigform and mod_openpgp|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008&amp;diff=33129</id>
		<title>OWASP EU Summit 2008</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_EU_Summit_2008&amp;diff=33129"/>
				<updated>2008-07-02T11:47:46Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: Added Arturo Alberto Busleiman (a.k.a Buanzo) to SoC08&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;(WORK IN PROGRESS /UNDER DISCUSSION)&lt;br /&gt;
== UPDATES ==&lt;br /&gt;
*[[OWASP EU Summit 2008 - updates|'''OWASP EU Summit 2008 - updates''']]&lt;br /&gt;
&lt;br /&gt;
== What: OWASP Summit, a conference about OWASP and for OWASP's community ==&lt;br /&gt;
=== When: 4 to 7 Nov 2008 (4 &amp;amp; 5: Meetings and Training, 6 &amp;amp; 7: Conference) === &lt;br /&gt;
=== Where: Portugal ===&lt;br /&gt;
Faro or Lisbon&lt;br /&gt;
=== Organization===&lt;br /&gt;
Paulo Coimbra and Dinis Cruz&lt;br /&gt;
== Agenda ==&lt;br /&gt;
Theme: Present OWASP's projects, community and activities  .....     '....Connecting the dots.... &amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''Day 1 &amp;amp; 2'''&lt;br /&gt;
*Training sessions (similar to what happens at the moment at the other OWASP conferences)&lt;br /&gt;
*OWASP Working Group sessions (1/2 day each) on:&lt;br /&gt;
** OWASP Governance, &amp;quot;What is OWASP's position on ....&amp;quot; &amp;amp; Action Plan for 2009&lt;br /&gt;
** ESAPI&lt;br /&gt;
** Browser Security&lt;br /&gt;
** OWASP Top 10 2009&lt;br /&gt;
&lt;br /&gt;
'''Day 3 &amp;amp; 4 Agenda:'''&lt;br /&gt;
* Presentations from AoC, SpoC and SoC Participants&lt;br /&gt;
* Presentations from 'Release' Quality OWASP projects (not included in the list above) or Key OWASP projects (like ESAPI)&lt;br /&gt;
* Presentations about OWASP : How it works, Financial reports, OotM (OWASP on the Move), new project management guidelines, local chapter finances, OWASP governance &lt;br /&gt;
* Presentation from Chapter leaders on the activities developed on their project&lt;br /&gt;
* Discussion on next steps for OWASP and focus of next OWASP financial investment plans&lt;br /&gt;
&lt;br /&gt;
Other ideas:&lt;br /&gt;
&lt;br /&gt;
* vote on 6th OWASP board member (Candidates to Apply)&lt;br /&gt;
&lt;br /&gt;
== other details==&lt;br /&gt;
&lt;br /&gt;
'''Projected Attendees:450 '''&lt;br /&gt;
* 200 with some (or all) expenses covered by OWASP&lt;br /&gt;
** 33 SoC participants&lt;br /&gt;
** 70 SoC reviewers&lt;br /&gt;
** 10 SoC Collaborators&lt;br /&gt;
** 15 AoC &amp;amp; SpoC participants&lt;br /&gt;
** 15 Chapter Leaders&lt;br /&gt;
** 8 OWASP Board &amp;amp; Employees&lt;br /&gt;
** 49 OWASP non-individual members (2x per 9k Corporate? 1x for the others?)&lt;br /&gt;
&lt;br /&gt;
=== Financial details ===&lt;br /&gt;
'''Expenses'''&lt;br /&gt;
* Accommodation &amp;amp; meals: 80,000 USD  = 400 USD per person (200x) for 3 nights accommodation  and 5 meals (3 dinners and 2 lunches)&lt;br /&gt;
* Flights &amp;amp;  Trains : 70,000 USD&lt;br /&gt;
&lt;br /&gt;
'''Revenue sources'''&lt;br /&gt;
* Tickets (for the 250 non 'OWASP invited' attendees)&lt;br /&gt;
* Training Sessions&lt;br /&gt;
* Conference sponsors&lt;br /&gt;
&lt;br /&gt;
== Participants ==&lt;br /&gt;
=== OWASP Board members &amp;amp; employees ===&lt;br /&gt;
* Jeff Williams &lt;br /&gt;
* Dave Wichers &lt;br /&gt;
* Dinis Cruz &lt;br /&gt;
* Tom Brennan &lt;br /&gt;
* Sebastien Deleersnyder &lt;br /&gt;
* Paulo Coimbra&lt;br /&gt;
* Kate Hartmann (to be confirmed)&lt;br /&gt;
* Alison McNamee (to be confirmed)&lt;br /&gt;
* Larry Casey (to be confirmed)&lt;br /&gt;
&lt;br /&gt;
=== Summer of Code 08 Participants &amp;amp; Reviewers ===&lt;br /&gt;
* (please add your name in the following format)&lt;br /&gt;
* OWASP Classic ASP Security Project Reviewer Esteban Ribicic Argentina -living in Croatia/Wien-&lt;br /&gt;
* OWASP Internationalization Guidelines Reviewer Project Esteban Ribicic&lt;br /&gt;
* OWASP Spanish Project Reviewer Esteban Ribicic&lt;br /&gt;
* OWASP Ruby on Rails Security Project Leader Heiko Webers from Germany&lt;br /&gt;
* OWASP Code Review Guide Lead - Eoin Keary - Ireland&lt;br /&gt;
* OWASP Enigform and mod_Openpgp - Arturo Alberto Busleiman (a.k.a Buanzo) - Argentina&lt;br /&gt;
&lt;br /&gt;
=== Winter of Code 07 Participants (Completed Projects) ===&lt;br /&gt;
* (please add your name)&lt;br /&gt;
* {Project} {Name} {Origin Country}&lt;br /&gt;
&lt;br /&gt;
=== Autumn of Code 06 Participants ===&lt;br /&gt;
* (please add your name)&lt;br /&gt;
* {Project} {Name} {Origin Country}&lt;br /&gt;
&lt;br /&gt;
* OWASP Pantera, Simon Roses Femerling, Spain&lt;br /&gt;
&lt;br /&gt;
=== Active Chapter Leaders ===&lt;br /&gt;
* (please add your name in the following format)&lt;br /&gt;
* {Chapter} {Role} {Name} {Origin Country}&lt;br /&gt;
&lt;br /&gt;
=== Active Project Leaders (not currently participating on SoC 08)===&lt;br /&gt;
* (please add your name in the following format)&lt;br /&gt;
* {Project} {Role} {Name} {Origin Country}&lt;br /&gt;
&lt;br /&gt;
=== Significant Past OWASP contributor (that is not already covered by one of the above categories) ===&lt;br /&gt;
* (please add your name in the following format)&lt;br /&gt;
* {Project/Chapter} {Role} {Name} {Origin Country}&lt;br /&gt;
&lt;br /&gt;
=== Logistic and Support team ===&lt;br /&gt;
* Summit Graphic Design + Summit organization + on-site logistics support, Sarah Cruz, UK (London)&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=32453</id>
		<title>OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=32453"/>
				<updated>2008-06-26T15:39:50Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: /* TOOLS PROJECTS */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page contains Projects, Authors, Status Target and Reviewers of the sponsored programme [[OWASP Summer of Code 2008]].&lt;br /&gt;
== DOCUMENTATION PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Verification Standard Project|OWASP Application Security Verification Standard]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mike Boberski &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jeff.williams(at)owasp.org Jeff Williams]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend(at)insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AppSensor Project|OWASP AppSensor - Detect and Respond to Attacks from Within the Application]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:michael.coates(at)aspectsecurity.com Michael Coates]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eric.sheridan(at)aspectsecurity.com Eric Sheridan]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:thrynn404(at)gmail.com Randy Janinda]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Backend Security Project|OWASP Backend Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Carlo Pelliccioni&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Classic ASP Security Project|OWASP Classic ASP Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rodrigo@rmarcos.com Rodrigo Marcos]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Review Project|OWASP Code review guide, V1.1]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eoin Keary&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:psatishkumar(at)gmail.com P.Satish Kumar]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Corporate Application Security Rating Guide|OWASP Corporate Application Security Rating Guide]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Parvathy Iyer&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Neal Kirschner&amp;lt;br&amp;gt;Email address?&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:Omar.Sherin(at)infosec2.com Omar Sherin]&amp;lt;br&amp;gt;TBC &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Education Project|OWASP Education Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Martin Knobloch&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:sebastien.gioria@owasp.fr Sebastien Gioria]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn(at)bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Internationalization|OWASP Internationalization Guidelines Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP .NET Project#OWASP .NET Project Leader|OWASP .NET Project Leader]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mark Roxberry &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary(at)gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dennis.hurst(at)hp.com Dennis Hurst]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Positive Security Project|OWASP Positive Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eduardo Vianna de Camargo Neves &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:welias(at)conviso.com.br Wagner Elias]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Ruby on Rails Security Guide V2|OWASP Ruby on Rails Security Guide v2]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Heiko Webers &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:steve.jones(at)unf.edu Steve Jones]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jeff.cabaniss(at)gmail.com Jeff Cabaniss]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Securing WebGoat using ModSecurity Project|OWASP Securing WebGoat using ModSecurity]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Stephen Evans &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ivan.ristic(at)breach.com Ivan Ristic] &amp;amp; Breach Group&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:christian.folini(at)netnea.com Christian Folini]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot;|'''[[:Category:OWASP Source Code Review OWASP Projects Project|OWASP Source Code Review OWASP Projects]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | James Walden&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:marco.m.morana(at)gmail.com Marco M. Morana]&amp;lt;br&amp;gt;(TBC)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Spanish|OWASP Spanish Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Testing Project|OWASP Testing Guide v3]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matteo Meucci &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;400&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;120&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''3rd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''4th&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP ASDR Project|OWASP Application Security Desk Reference (ASDR)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Leonardo Cavallari Militelli &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:williamtsmith(at)gmail.com William Smith]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#William Smith | Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Kenneth R. van Wyk| Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kcfredman(at)gmail.com Frederick Donovan]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Frederick Donovan | Bio]]&amp;lt;br&amp;gt;  (Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== TOOLS PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:GTK plus GUI for w3af Project|GTK+ GUI for w3af project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Facundo Batista&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:andres.riancho(at)gmail.com Andres Riancho]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah@securenet.de Achim Hoffmann]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Access Control Rules Tester Project|OWASP Access Control Rules Tester]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Andrew Petukhov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:caughron(at)gmail.com Mat Caughron]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/A84/998 Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mg_chen(at)yahoo.com Min Chen]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/mgchen Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AntiSamy Project .NET| OWASP AntiSamy .NET]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arshan Dabirsiaghi&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dallasspohn(at)sbcglobal.net Dallas Spohn]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project|OWASP Application Security Tool Benchmarking Environment and Site Generator refresh]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dmitry Kozlov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:medelibero(at)gmail.com Mike de Libero]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Crawler|OWASP Code Crawler ]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Alessio Marziali &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Interceptor Project|OWASP Interceptor Project - 2008 Update]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Justin Derry&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dallasspohn(at)sbcglobal.net Dallas Spohn]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP JSP Testing Tool Project|OWASP UI Component Verification Project (a.k.a. OWASP JSP Testing Tool)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jason Li&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:markkerzner(at)gmail.com Mark Kerzner]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabricio.fujikawa(at)infoglobo.com.br Fabrício Fujikawa]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Live CD 2008 Project|OWASP Live CD 2008 Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matt Tesauro&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:admin@wirefall.com Dustin Dykes]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/607/6b1 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jkpoots(at)rogers.com Kent Poots] &amp;lt;br&amp;gt; [http://www.linkedin.com/pub/5/25B/114 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenSign Server Project|OWASP Online code signing and integrity verification service for open source community (OpenSign Server)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Phil Potisk and Richard Conway&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend@insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:a_campani@yahoo.fr Antonio Campanile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp|OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arturo 'Buanzo' Busleiman&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | (need one)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Orizon Project|OWASP Orizon Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Paolo Perego&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:seba@deleersnyder.eu Sebastien Deleersnyder]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz@owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Python Static Analysis Project|OWASP Python Static Analysis]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Georgy Klimov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn@bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:diepvien00thayh@gmail.com P.Q.Huy]&amp;lt;br&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Skavenger Project|OWASP Skavenger]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mro(at)securenet.de Matthias Rohr]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Rogan Dawes&amp;lt;br&amp;gt;Email address?&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah@securenet.de Achim Hoffmann]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Sqlibench Project|OWASP SQL Injector Benchmarking Project (SQLiBENCH)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:urgunb@hotmail.com Bedirhan Urgun]&amp;lt;br&amp;gt;[mailto:mesut@h-labs.org Mesut Timur]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ferruh@mavituna.com Ferruh Mavituna]&amp;lt;br/&amp;gt; [[Project Information:Sqlibench:Ferruh|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kfuller@dmv.ca.gov Kevin Fuller] &amp;lt;br/&amp;gt;[[Project Information:Sqlibench:Kevin|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Teachable Static Analysis Workbench Project|OWASP Teachable Static Analysis Workbench]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ddk(at)cs.msu.su Dmitry Kozlov]&amp;lt;br&amp;gt;Igor Konnov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alex Fry]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP WeBekci Project|OWASP WeBekci Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:bunyamin@owasp.org Bunyamin Demir]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== DESIGN/CORPORATE PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Book Cover &amp;amp; Sleeve Design|OWASP Book Cover &amp;amp; Sleeve Design]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Individual and Corporate Member Packs plus Conference Attendee Packs Brief|OWASP Individual &amp;amp; Corporate Member Packs, Conference Attendee Packs Brief]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=32168</id>
		<title>Project Information:template Enigform and mod OpenPGP</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=32168"/>
				<updated>2008-06-23T14:30:16Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: added wiki&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The goal of this project is to focus on mod_openpgp and Secure Session Management, presenting a working web-site using this new authentication methodology in such a way that it will attract security professionals and web-developers to this new mix of two good'ol protocols: HTTP and OpenPGP. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:buanzo(at)buanzo.com.ar '''Arturo 'Buanzo' Busleiman''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:to(at)change '''Name&amp;amp;Email''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[https://lists.owasp.org/mailman/listinfo/owasp-enigform-and-mod-openpgp '''Mailing List/Subscribe''']&amp;lt;br&amp;gt;[mailto:Owasp-Enigform-and-mod-OpenPGP@lists.owasp.org '''Mailing List/Use''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:mark.roxberry(at)owasp.org '''Mark Roxberry''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:name@name '''Name''']&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:dinis.cruz(at)owasp.org '''Dinis Cruz''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* http://wiki.buanzo.org - Main mod_openpgp and Enigform documentation (Wiki)&lt;br /&gt;
* http://maotest.buanzo.org - Main Enigform / mod_openpgp test site.&lt;br /&gt;
* http://enigform.mozdev.org - Main Enigform Development site&lt;br /&gt;
* http://foros.buanzo.com.ar/viewforum.php?f=35 - Enigform / mod_openpgp Support Forum&lt;br /&gt;
* svn://svn.buanzo.org/mod_openpgp - mod_openpgp and test-site / tools subversion repository.&lt;br /&gt;
* http://www.freesoftwaremagazine.com/blogs/interview_with_arturo_busleiman - An Interview with Buanzo.&lt;br /&gt;
* http://freshmeat.net/articles/view/2599 - An early Enigform article.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Enigform: Firefox Addon for OpenPGP signing of HTTP requests Project]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OpenPGP Extensions for HTTP - Enigform and mod_openpgp|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=32076</id>
		<title>Project Information:template Enigform and mod OpenPGP</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:template_Enigform_and_mod_OpenPGP&amp;diff=32076"/>
				<updated>2008-06-20T13:04:40Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: added related links&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp Project''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|The goal of this project is to focus on mod_openpgp and Secure Session Management, presenting a working web-site using this new authentication methodology in such a way that it will attract security professionals and web-developers to this new mix of two good'ol protocols: HTTP and OpenPGP. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:buanzo(at)buanzo.com.ar '''Arturo 'Buanzo' Busleiman''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:to(at)change '''Name&amp;amp;Email''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[mailto:Owasp-Enigform-and-mod-OpenPGP@lists.owasp.org '''Project Mailing List''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:mark.roxberry(at)owasp.org '''Mark Roxberry''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:name@name '''Name''']&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;[mailto:dinis.cruz(at)owasp.org '''Dinis Cruz''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* http://maotest.buanzo.org - Main Enigform / mod_openpgp test site.&lt;br /&gt;
* http://enigform.mozdev.org - Main Enigform Development site&lt;br /&gt;
* http://foros.buanzo.com.ar/viewforum.php?f=35 - Enigform / mod_openpgp Support Forum&lt;br /&gt;
* svn://svn.buanzo.org/mod_openpgp - mod_openpgp and test-site / tools subversion repository.&lt;br /&gt;
* http://www.freesoftwaremagazine.com/blogs/interview_with_arturo_busleiman - An Interview with Buanzo.&lt;br /&gt;
* http://freshmeat.net/articles/view/2599 - An early Enigform article.&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''RELATED PROJECTS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Enigform: Firefox Addon for OpenPGP signing of HTTP requests Project]]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OpenPGP Extensions for HTTP - Enigform and mod_openpgp|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - Self Evaluation - A|See&amp;amp;Edit:50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:template Enigform and mod OpenPGP - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26990</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26990"/>
				<updated>2008-03-24T18:28:18Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: /* OpenPGP Extensions for HTTP - Enigform and mod_openpgp */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli &lt;br /&gt;
* Proposal: Make [[OWASP ASDR Project|OWASP ASDR Project]] a release quality document.&lt;br /&gt;
&lt;br /&gt;
The ASDR is a reference volume that contains basic information about all the foundational topics in application security. It intends to replace and refresh [[OWASP Honeycomb Project|Honeycomb Project]] with a new structure for articles and relationship between categories, thus making it a release quality doc.&lt;br /&gt;
&lt;br /&gt;
This idea raised when finished the [[Attack|Attack Reference Guide]] for [[OWASP Spring Of Code 2007|OWASP Spring Of Code 2007]], where it was identified that OWASP reference articles need some special attention. Jeff Williams is totally supporting this project.&lt;br /&gt;
&lt;br /&gt;
We already have defined which type of article we should include on Desk Reference, as follows:&lt;br /&gt;
* [[:Category:Principle|Principles]]&lt;br /&gt;
* [[:Category:Threat_Agent|Threat Agents]]&lt;br /&gt;
* [[:Category:Attack|Attacks]]&lt;br /&gt;
* [[:Category:Vulnerability|Vulnerabilities]]&lt;br /&gt;
* [[:Category:Countermeasure|Countermeasures]]&lt;br /&gt;
* [[:Category:Technical Impact|Technical Impacts]]&lt;br /&gt;
* [[:Category:Business Impact|Business Impacts]]&lt;br /&gt;
&lt;br /&gt;
*Road Map: A complete project roadmap can be found on '''[[ASDR Table of Contents|ASDR Table of Contents]]'''. Basically, the following activities should be performed, some of them already started:&lt;br /&gt;
** Define articles templates for each reference type&lt;br /&gt;
** Define subcategories for articles classification&lt;br /&gt;
** Compile first DRAFT version of ASDR Book&lt;br /&gt;
** Articles development &amp;amp; Call for Volunteers&lt;br /&gt;
** Articles revision&lt;br /&gt;
** First version of OWASP ASDR book&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali (aka nTze)&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Security Software Life Cycle'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;br /&gt;
&lt;br /&gt;
== OWASP Classic ASP Security Project  ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
I am interested in making P018 - OWASP Classic ASP Security Project happen, Classic ASP 2.0 and 3.0 applications are still largely used as this technology is more than 10 years old and was largely used. there are thousands of sites on the wild that need guidance on the security arena. This is where OWASP can come up and provide help for “making the Web a better place” and continue spreading the word on security. I have always be a passionate of the technology (regardless of its inconveniences such as being old and DLL-hell prone) and I am really exited on the idea of sharing my knowledge of this area to the world and what best that though OWASP.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
Create a secure framework for Classic ASP application by complementing existing OWASP projects with documentation for this particular technology and the creation of security libraries. More specifically:&lt;br /&gt;
* Creation of a Common Object Repository for ASP applications based on OWASP ESAPI Project including objects and/or references to libraries for security applications all this aligned with OWASP Top10 and OWASP Guide .&lt;br /&gt;
* Create Documentation aligned to OWASP Code Review Project Checklist providing additional technology-specific checks.&lt;br /&gt;
* Addition of expression for Code Review Tool to support Classic ASP applications.&lt;br /&gt;
* Implementation of Version 1 of Stinger for ASP either by using an installable COM library or ISAPI.&lt;br /&gt;
* This same module will compliment the OWASP Validation Documentation Project.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver. &lt;br /&gt;
&lt;br /&gt;
Also I’ve had close contact with OWASP since 2005&lt;br /&gt;
[https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html] by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish.&lt;br /&gt;
&lt;br /&gt;
== Internationalization Guidelines and OWASP-Spanish Project ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
The main goal of OWASP is to spread the word about security (“Our mission is to make application security &amp;quot;visible,&amp;quot; so that people and organizations can make informed decisions about application security risks.”) and OWASP has done great work so far :). And now it’s time for a next big step.&lt;br /&gt;
&lt;br /&gt;
The number of native and secondary speakers in the world for Chinese, Spanish, French, Russian, Arabic and Indi languages are estimated in similar number to English speaking or even more (Some References at [http://en.wikipedia.org/wiki/Ethnologue_list_of_most_spoken_languages Ethnologue], [http://encarta.msn.com/media_701500404/Languages_Spoken_by_More_Than_10_Million_People.html Encarta], [http://en.wikipedia.org/wiki/List_of_languages_by_number_of_native_speakers Wikipedia]). I think is a good time for OWASP to reach those that do not speak English to have full access to all the OWASP materials, not just a couple of documents.&lt;br /&gt;
&lt;br /&gt;
OWASP, while open to translations, do not have clear guidelines on how to translate OWASP contents and (AFAIK) there is no multi-language support in OWASP.org site. This is understandable as there is no formal project for internationalization so far. &lt;br /&gt;
&lt;br /&gt;
'''Oportunity and Effort'''&amp;lt;br&amp;gt;&lt;br /&gt;
This is great opportunity to make Spanish the first language on which the OWASP site and documentation is fully translated and at the same time share the experience with other people interested in the same objective, Bring OWASP to the world.  And this is something I’ve being pushing for some time ago and that could be possible “at once” via SoC 2008.&lt;br /&gt;
&lt;br /&gt;
I understand this is significant effort so to have it done I will count with the help of 6 people (friend of mine, all of them Security auditors with excellent English level) plus a few well known contributors from OWASP-Spanish effort, so the founding will be divided among the people involved in the same proportion of the work they do for the completion of this effort. This, to encourage delivery.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
* Team up with Larry Casey to implement Multilanguage support in OWASP.org Mediawiki.&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to start a new language translation for OWASP Document and Site Pages&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to implement internationalization and localization ([http://www.w3.org/International/ i18n]) on OWASP Software &lt;br /&gt;
* Full translation to Spanish of all the release-level document projects. Those are:&lt;br /&gt;
** Top 10 2007&lt;br /&gt;
** Guide 2 (Already translated)&lt;br /&gt;
** Testing Guide (Already Translated)&lt;br /&gt;
** Legal&lt;br /&gt;
** FAQ&lt;br /&gt;
* Full Translation of major sections of OWASP Site&lt;br /&gt;
** Project Main Pages (Release, Beta and Alpha levels for both documents and tools projects)&lt;br /&gt;
** Principles&lt;br /&gt;
** References Section&lt;br /&gt;
** Conferences&lt;br /&gt;
** News (Those currently displayed in OWASP site)&lt;br /&gt;
** About OWASP&lt;br /&gt;
* Evaluation of Spanish translation approach for WebGoat and WebScarab and delivery of this document to Bruce and Rogan for possible implementation in near future.&lt;br /&gt;
* Leverage for deploy of es.owasp.org, the domain already exists but is not redirecting correctly.&lt;br /&gt;
* Create a Communication strategy to help and keep track on new pages or changes in significant pages so all the translations are in sync.&lt;br /&gt;
&lt;br /&gt;
'''Out of Scope'''&amp;lt;br&amp;gt;&lt;br /&gt;
Translation of the following sections are NOT in Scope&lt;br /&gt;
* Local Chapters Pages&lt;br /&gt;
* Presentations&lt;br /&gt;
* Conferences&lt;br /&gt;
* Videos&lt;br /&gt;
* Blogs&lt;br /&gt;
* All the projects deliverables in Alpha and Beta Stages&lt;br /&gt;
* All the documentation “on development” like Guide Version 3.0&lt;br /&gt;
* Translation of Pages, documentation or tools to other language other than Spanish according to the stated in above section.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I’ve being part of contributions to OWASP documents on the translation arena since 2005 [https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html], a few of them by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish. It is time to make the full job done :).&lt;br /&gt;
&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver.&lt;br /&gt;
&lt;br /&gt;
== The Ruby on Rails Security Guide v2 ==&lt;br /&gt;
Heiko Webers&lt;br /&gt;
&lt;br /&gt;
The last security guide for Rails [http://www.owasp.org/index.php/Category:OWASP_Web_Application_Security_Put_Into_Practice] was a great success, with a lot of more secure web applications and continued awareness in the community of security issues. The Ruby on Rails Security Project [http://www.rorsecurity.info/] is the one and only source of information about Rails security topics, and I keep the community up-to-date with blog posts and conference talks in Europe. The Guide and the Project has been mentioned in several Rails books and web-sites.&lt;br /&gt;
&lt;br /&gt;
Version 1 of the Ruby on Rails Security Guide was sponsored by the SpoC 07, set the standard for OWASP programming language specific guides in terms of the topic outline and has been published as a book [http://www.lulu.com/content/1412042]. Nevertheless I'm convinced that a more compact design and a &amp;quot;question-and-answer&amp;quot; style of writing will reach an even larger audience. Of course the new Guide will still include answers to the OWASP Top Ten security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
A lot has changed since the publishing of the first Guide. Some new security holes have been found, there are new advises and most importantly Rails version 2.0 has been released. The new Ruby on Rails Security Guide aims at providing an up-to-date coding and configuration guide for the Rails community.&lt;br /&gt;
&lt;br /&gt;
In the new Rails Security Guide I'd like to&lt;br /&gt;
* update the entire book to match Rails 2.0&lt;br /&gt;
* cover new topics, including, but not limited to:&lt;br /&gt;
** Intranet and administration interface security,&lt;br /&gt;
** phishing,&lt;br /&gt;
** real-world attack situations,&lt;br /&gt;
** short excursus on server monitoring,&lt;br /&gt;
** the new CookieStore session management,&lt;br /&gt;
** vulnerabilities in popular plug-ins,&lt;br /&gt;
** denial-of-service attacks&lt;br /&gt;
* cover all OWASP Top Ten security vulnerabilities&lt;br /&gt;
* a more compact writing style, more examples and &amp;quot;questions-and-answers&amp;quot;&lt;br /&gt;
* introduce the OWASP and Rails security to a greater audience&lt;br /&gt;
&lt;br /&gt;
== OWASP Application Security Verification Standard ==&lt;br /&gt;
&lt;br /&gt;
*Mike&lt;br /&gt;
&lt;br /&gt;
'''OWASP Application Security Verification Standard Proposal'''&lt;br /&gt;
&lt;br /&gt;
'''Educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
The applicant is a hands-on senior professional services manager with a trademark of&lt;br /&gt;
developing creative solutions to complex application security-related technical problems. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a background in trusted product evaluation:&lt;br /&gt;
&lt;br /&gt;
*CC evaluation&lt;br /&gt;
*CC evidence development, including operating system test code development&lt;br /&gt;
*CC project management&lt;br /&gt;
*TCSEC evaluation&lt;br /&gt;
*TCSEC project management&lt;br /&gt;
*TEF management&lt;br /&gt;
*CCTL management&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in security-related software development and integration:&lt;br /&gt;
&lt;br /&gt;
*PKI toolkit development&lt;br /&gt;
*PK-E application integration&lt;br /&gt;
*Secure web portal application development&lt;br /&gt;
*Secure web portal integration&lt;br /&gt;
*Secure instant messaging application development, including three patents&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in cryptomodule testing:&lt;br /&gt;
&lt;br /&gt;
*FIPS 140 evaluation&lt;br /&gt;
*FIPS 140 evidence development&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
The applicant does not have experience in contributing to open communities.&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
OWASP is looking for a commercially-workable open standard for performing application security verification efforts. The problem is that there is a huge range in the coverage and level of rigor available in the market, and consumers have no way to tell the difference between someone just running a grep tool, and someone doing painstaking code review and manual testing. So, a standard is needed.&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s)'''&lt;br /&gt;
&lt;br /&gt;
The applicant’s proposal will address the above challenges as follows:&lt;br /&gt;
&lt;br /&gt;
*The applicant will define an evaluation framework that may be used to conduct OWASP Application Security Verification Standard certifications.&lt;br /&gt;
*The applicant will define an OWASP Application Security Verification Standard which defines levels that applications may be certified against.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
The applicant will carry out these activities. Please see below for a proposed list of specific deliverables.&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following deliverables:&lt;br /&gt;
&lt;br /&gt;
*'''Scheme Overview document.''' This will define the overall framework with roles, responsibilities, and processes.&lt;br /&gt;
*'''Evaluation and Certification document.''' This will describe the evaluation and certification process.&lt;br /&gt;
*'''Conditions for the Use of Trademarks.''' This will describe OWASP’s name, logo, and certificate may be used and referenced.&lt;br /&gt;
*'''Evaluation Report Content Requirements.''' This will describe the content requirements of evaluation reports.&lt;br /&gt;
*'''OWASP Application Security Verification Standard.''' This will define the levels that applications may be certified against.&lt;br /&gt;
*'''OWASP Application Security Verification Standard Appendix A.''' This will define the required content of the OWASP Application Security Verification Standard Security Policy.&lt;br /&gt;
*'''Policy Letter #1. Acceptance of Security Policies into OWASP Evaluation''' This will define the requirements to be listed as in evaluation on the OWASP web site.&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following rough project schedule:&lt;br /&gt;
&lt;br /&gt;
*2nd April. Project kickoff.&lt;br /&gt;
*15th June. Alpha Quality drafts of Scheme Overview document and of OWASP Application Security Verification Standard document completed.&lt;br /&gt;
*31st August. Project completion. Beta Quality drafts of all documents completed.&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
The long-term vision for the project is to normalize the range in the coverage and level of rigor available in the market when it comes to performing application security verification.&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected.'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a uniquely-qualified perspective given his experience with TCSEC, TTAP, CC, FIPS 140-1, and FIPS 140-2 evaluation programs, and his real-world perspective as a developer and integrator of security-related applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== GTK+ GUI for w3af project ==&lt;br /&gt;
&lt;br /&gt;
''Facundo Batista''&lt;br /&gt;
&lt;br /&gt;
'''Your educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
I'm Electronic Engineer with a Master in Engineer Innovation in&lt;br /&gt;
Bologna University, Italy. I live in Buenos Aires, Argentina, and love&lt;br /&gt;
reading books, playing tennis, and programming Python.&lt;br /&gt;
&lt;br /&gt;
I worked in a mobile company for six years, in the Network Management&lt;br /&gt;
department, then I was Chief Developer of a Mobile Content Provider,&lt;br /&gt;
and now I'm Solution Architect in Multimedia &amp;amp; Systems Integration in&lt;br /&gt;
Ericsson. Also I was professor in several universities, high schools&lt;br /&gt;
and other institutions.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
None, more than working in w3af. However, my proposal here is not&lt;br /&gt;
related to the security part of the product, but to its graphical&lt;br /&gt;
interface and usability.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I'm very involved in the free software and open source community. I'm&lt;br /&gt;
a Python Core Developer and member of the Python Software Foundation&lt;br /&gt;
by merit. I have a long history of talks given in several&lt;br /&gt;
international (PyCon, EuroPython) and national (a lot!) conferences. I&lt;br /&gt;
also teach Python in educational institutions, enterprises and as a&lt;br /&gt;
private instructor. I founded Python Argentina, the national users&lt;br /&gt;
groups, and I'm a very active member of it.&lt;br /&gt;
&lt;br /&gt;
I also lead other open source projects (SMPPy, SiGeFi, etc.) and&lt;br /&gt;
particpate in others (Docutils, w3af itself, etc.).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
My main objective is to minimize the effort and learning curve of&lt;br /&gt;
using w3af, providing a very usable graphical interface.&lt;br /&gt;
&lt;br /&gt;
Note that as the interface is cross platform, being usable also in the&lt;br /&gt;
win32 environment, it will help to popularize the w3af project.&lt;br /&gt;
&lt;br /&gt;
This will allow users without information security knowledge to verify&lt;br /&gt;
that their web applications are correctly programmed and configured.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
I will carry the following activities, detailed later in smaller steps:&lt;br /&gt;
&lt;br /&gt;
- Design and code new windows and interfaces to increase the functionality of the project.&lt;br /&gt;
&lt;br /&gt;
- Tuning of the process workflow, allowing a more intuitive way of working.&lt;br /&gt;
&lt;br /&gt;
- Visual polishing for a more pleasant and intuitive tool.&lt;br /&gt;
&lt;br /&gt;
- Usability tests and improvements.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
''New features implemented in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Local proxy to trap and modify requests and responses sent from a browser.&lt;br /&gt;
&lt;br /&gt;
- Manually send a request and analyze the response.&lt;br /&gt;
&lt;br /&gt;
- Manually create a fuzzed requests based on tokens, so user can construct easily differents HTTP request with a regex-like semantics.&lt;br /&gt;
&lt;br /&gt;
- Wizard to perform a vulnerability assessment.&lt;br /&gt;
&lt;br /&gt;
- Graphical display of site map and vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
- Reload a plugin after its edited from within the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Embebed tool to encode/decode URL/Base64 and to hash sha1/md5.&lt;br /&gt;
&lt;br /&gt;
- HTTP response side by side content compare.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Usability improvements in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Meetings with a usability expert that the w3af team leader has already contacted and worked with.&lt;br /&gt;
&lt;br /&gt;
- Kill all pending bugs and make a stable release.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Documentation:''&lt;br /&gt;
&lt;br /&gt;
- Users guide for the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Help system for the GUI itself&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
To provide the web application security community with a stable and fully &lt;br /&gt;
featured framework to perform all the tasks included in a penetration test&lt;br /&gt;
from within the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected'''&lt;br /&gt;
&lt;br /&gt;
w3af is one of the most active web application security projects;&lt;br /&gt;
the community that supports it is growing and we need the support of &lt;br /&gt;
already established organizations like OWASP to keep working at the &lt;br /&gt;
rate that we want to.&lt;br /&gt;
&lt;br /&gt;
== P006 OWASP Corporate Application Security Rating Guide and P025 OWASP Positive Security Project ==&lt;br /&gt;
&lt;br /&gt;
by Eduardo Vianna de Camargo Neves&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
A common approach on most companies is to increase the protection of their assets after the occurrence of a considerable impact. However some companies learned that a positive approach on IT Security is most effective and can reduce the financial costs on responses to security incidents. Benchmarking the application security practices on the corporate world will allow us to understand what steps are required to keep the IT environment protected, using this knowledge to create a public Security Rating Guide that can be used to support the establishment of a security baseline within the community.&lt;br /&gt;
&lt;br /&gt;
Moreover the information from this analysis can be used to support the development of a campaign to spread a positive security posture in the market. The liaison with companies that maintain good security practices  will help to start this initiative from a higher degree and involve several actors on the security stage for the same direction to a market were security is understood as a business value.&lt;br /&gt;
&lt;br /&gt;
'''Approach'''&lt;br /&gt;
&lt;br /&gt;
Assessing public materials from the Top 50 Companies and Top 50 Software Companies, a rating guide will be produced showing tangible metrics that are achieved by those companies and allow them to be considered secure enough on a comparison to a baseline of good practices. As a result the Corporate Application Security Rating Guide will be produced and published for the community and the deliverables used to support the development of the Positive Security Project with facts from a real analysis.&lt;br /&gt;
&lt;br /&gt;
'''Benefits'''&lt;br /&gt;
&lt;br /&gt;
The whole community will be benefited from these initiatives. With the adequate support from OWASP to maintain the projects active and liaise with big players on the market, we can expect the following:&lt;br /&gt;
&lt;br /&gt;
• The community will receive a Security Rating Guide that will allow them to compare their own security practices within the market. As this will be a public document, suppliers and buyers worldwide will share the same information allowing them to adequate the expectations on the usage of security services and tools.&lt;br /&gt;
&lt;br /&gt;
• The Security Rating Guide can be used as a marketing tool by the companies, allowing them to sell security as a business value and avoiding the old-fashion and inadequate FUD approach.&lt;br /&gt;
&lt;br /&gt;
• The knowledge and relationship developed during the production of the Security Rating Guide will allow us to produce the deliverables on Positive Security Project with real information, increasing the credibility of the initiative for the market.&lt;br /&gt;
&lt;br /&gt;
• The Security Rating Guide and the Positive Security Project can be walk in parallel, merging their information to support a concise and continuous marketing campaign to encourage a positive approach on the market.&lt;br /&gt;
&lt;br /&gt;
• As an open community free from commercial pressures, OWASP can use both projects to support the evaluation of security products for the market, allowing the organization to receive profits from these services and support current and future projects.&lt;br /&gt;
&lt;br /&gt;
'''Summarized Work Breakdown Structure (WBS)'''&lt;br /&gt;
&lt;br /&gt;
All the activities will be leaded by Eduardo V. C. Neves, which will be responsible as a single point of contact with the sponsors and to manage a team of compromised volunteers from OWASP community and participants from security communities and associations (i.e. ISSA, SANS and ISC2).&lt;br /&gt;
&lt;br /&gt;
The activities will be carried on WBS summarized bellow. Dates presented should be considered as deadlines for the activities:&lt;br /&gt;
&lt;br /&gt;
• Criteria establishment and definition of the Top 50 Companies and Top 50 Software Companies (April 11)&lt;br /&gt;
&lt;br /&gt;
• Assessment of public materials to support the ranking establishment (April 18)&lt;br /&gt;
&lt;br /&gt;
• Establishment of the Corporate Application Security Rating Guide (April 25)&lt;br /&gt;
&lt;br /&gt;
• Publishing of the Corporate Application Security Rating Guide on OWASP web site and promotion over adequate channels (i.e. publications, blogs and associations) (May 09) (1)&lt;br /&gt;
&lt;br /&gt;
• Criteria establishment and approval of marketing templates for Positive Security Project (May 16) (2)&lt;br /&gt;
&lt;br /&gt;
• Development of the Positive Security Project material (i.e. blog and marketing sheets) (May 30)&lt;br /&gt;
&lt;br /&gt;
• Liaison with the OWASP Members, Top 50 Companies and Top 50 Software Companies to present the project and negotiate their participation as supporters, sponsors or contributors. (June 27)&lt;br /&gt;
&lt;br /&gt;
• Update on Corporate Application Security Rating Guide, including their score on Positive Security approach (July 4)&lt;br /&gt;
&lt;br /&gt;
• Presentation of the Positive Security Project approach and Corporate Application Security Rating Guide on the market (July 31) (3)&lt;br /&gt;
&lt;br /&gt;
• Conference calls with team members to evaluate the results of the initiatives in all countries and produce project´s documents (i.e. lessons learned, update on marketing material and evaluation of alternative approaches for the future steps). (August 15)&lt;br /&gt;
&lt;br /&gt;
• Prepare project documentation and present to the OWASP community on the web site (August 31)&lt;br /&gt;
&lt;br /&gt;
''(1) Support from OWASP Foundation is required to liaise with companies and associations worldwide&lt;br /&gt;
&lt;br /&gt;
''(2) Support from OWASP Foundation and community are required to evaluate adequate marketing templates and translate original documents for their own languages''&lt;br /&gt;
&lt;br /&gt;
''(3) Support from OWASP community is required to spread the word on all countries were OWASP members are located.''&lt;br /&gt;
'''''&lt;br /&gt;
&lt;br /&gt;
'''Project Control'''&lt;br /&gt;
&lt;br /&gt;
The project will be managed following PRINCE2 Process Model and all control documents published for the OWASP community. The following mandatory project control documents are planned:&lt;br /&gt;
&lt;br /&gt;
• Project Initiation Document: To document project´s background, definition, objectives, approach, etc.&lt;br /&gt;
&lt;br /&gt;
• Communication Plan: To assure that OWASP Community are being continuous communicated about project status and deliverables achievement.&lt;br /&gt;
&lt;br /&gt;
• Highlight Report: To provide the OWASP Community with a summary of the project status, progress and potential problems or areas where help may be required.&lt;br /&gt;
&lt;br /&gt;
• End Project Report: To present project achievements. Should be considered the final project report.&lt;br /&gt;
&lt;br /&gt;
More documents may be included during project development to support the control and assure a high quality level (i.e. issue log, project approach).&lt;br /&gt;
&lt;br /&gt;
'''Long Range Plan'''&lt;br /&gt;
&lt;br /&gt;
Both projects should walk in parallel and be used as tools to support efforts to encourage and make the positive approach a reality on the IT Security field. These initiatives shall be supported by OWASP as long term plans and grow to a continuous world-wide campaign in this direction that must achieve big players on the market and be recognized by the community as a tool that must be used to evaluate security enabled companies and products. &lt;br /&gt;
&lt;br /&gt;
'''Why me?'''&lt;br /&gt;
&lt;br /&gt;
Can be me, you or anyone that carries these projects in a professional fashion and assure that all deliverables are being achieved. The most important parts is to make it happen, talk and get the support from reputable associations and large companies (OWASP Members are a good start) and lead it as a long range responsibility.&lt;br /&gt;
&lt;br /&gt;
I am running to win this project because I believe in all of this. I see both as very valuable initiatives that can help companies to make more business; people to get more jobs and the whole community to win in a scenario where our contributions on the security market are recognized as business tools.&lt;br /&gt;
&lt;br /&gt;
'''About me'''&lt;br /&gt;
&lt;br /&gt;
Information Security professional and enthusiastic with 15 years dedicated to achieve expressive results in the areas of IT, Information Security, Compliance and Project Management. A CISSP in good stand and Officer at the ISSA Brazilian Chapter, my professional career gave me extensive knowledge in several fields of Information Security with accumulated experience at consulting firms, as CSO at a world player company on consumer goods market and now as an entrepreneur at Latin American market.&lt;br /&gt;
&lt;br /&gt;
''Application security experience and accomplishments''&lt;br /&gt;
&lt;br /&gt;
My work experience is on Security Management, Risk Assessment, Business Continuity and Disaster Recovery, Security Awareness and other managed-related fields on our industry. I don’t have hands-on experience on application security and this is the main reason why I am running to be qualified on the project described bellow, where I believe that my skills can be used to achieve an excellent result for the community.&lt;br /&gt;
&lt;br /&gt;
''Participation and leadership in open communities''&lt;br /&gt;
&lt;br /&gt;
• Member of OWASP Brazil where I made some small contributions in a recent past.&lt;br /&gt;
&lt;br /&gt;
• Member of ABNT/CB-21/SC02 committee, Brazilian ISO representative for 27001 and 17799 standards&lt;br /&gt;
&lt;br /&gt;
• Officer of ISSA Brazil Chapter where I am responsible for the South Region and as the editor of Antebellum, the ISSA Brazil Journal&lt;br /&gt;
&lt;br /&gt;
• Founder and member of GISI-PR, an open community focused on discuss and promote Information Security initiatives within Paraná State, Brazil&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application ==&lt;br /&gt;
'''Name'''&lt;br /&gt;
&lt;br /&gt;
Michael Coates&lt;br /&gt;
&lt;br /&gt;
'''Project'''&lt;br /&gt;
&lt;br /&gt;
P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses, '''&lt;br /&gt;
&lt;br /&gt;
As critical applications continue to become more accessible and inter-connected, it is paramount that the information be protected. We must also realize that our defenses may not be perfect. Given enough time, attackers can identify security flaws in the design or implementation of an application. In addition to implementing layers of defense within an application, it is critical that we identify malicious individuals before they are able to identify any gaps in our defenses. The best place to identify malicious activity against the application is within the application itself.&lt;br /&gt;
Network based intrusion detection systems are not appropriate to handle the custom and intricate workings of an enterprise application and are ill-suited to detect attacks focusing on application logic such as authentication, access control, etc.  The application itself is the best place to identify and respond to malicious activity.&lt;br /&gt;
This project will create the framework which can be used to build a robust system of attack detection, analysis, and response within an enterprise application&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s), '''&lt;br /&gt;
&lt;br /&gt;
I plan to use a methodical approach throughout the creation of this resource. I will reference my own professional experience, OWASP resources, ESAPI, and academic materials to identify a robust set of potential attacks and identification methods. Thresholds will be recommended for each of the detected attacks. Each recommended threshold value and response recommendation will be accompanied with additional information to describe the purpose of the threshold and recommendation. This additional information will allow the reader to determine if the threshold is appropriate for their implementation.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities, '''&lt;br /&gt;
&lt;br /&gt;
I will complete the following activities:&lt;br /&gt;
1. Identify and define attack patterns against applications&lt;br /&gt;
2. Document points of detection within the application for the attack patterns &amp;amp; identify key information to log&lt;br /&gt;
3. Create thresholds for generating security alerts&lt;br /&gt;
4. Define recommended response actions for the security alerts&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress, '''&lt;br /&gt;
&lt;br /&gt;
April 2, 2008 - Project Begins&lt;br /&gt;
&lt;br /&gt;
April 2, 2008-April 12, 2008 - High level planning &amp;amp; design 	&lt;br /&gt;
&lt;br /&gt;
April 12, 2008-May 1, 2008 - Identify and define attack patterns against applications	&lt;br /&gt;
&lt;br /&gt;
May 1, 2008-June 1, 2008 - Document points of detection within the application for the attack patterns &amp;amp; identify key information to log	&lt;br /&gt;
&lt;br /&gt;
June 1, 2008-June 13, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
June 15, 2008 - Status Report	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Create thresholds for generating security alerts	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Define recommended response actions for the security alerts	&lt;br /&gt;
&lt;br /&gt;
Aug 16, 2008-Aug 30, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
Aug 31, 2008 - Project Complete	&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project, '''&lt;br /&gt;
&lt;br /&gt;
1.  I’d like to include a tiered type approach of thresholds and responses. This is would be similar to the approach used by FISMA of defining different controls for High, Medium, and Low systems.&lt;br /&gt;
&lt;br /&gt;
2. Building on item #1, I want to eventually include a system which lets the user provide information about their system.  This information could include rating or prioritizing different security concerns. a customized set of monitoring points, thresholds and response actions can be recommended for the application based on the provided data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About Me'''&lt;br /&gt;
&lt;br /&gt;
'''Education &amp;amp; Professional Background'''&lt;br /&gt;
&lt;br /&gt;
Masters of Science in Computer, Information and Network Security – DePaul University &lt;br /&gt;
(Expected Graduation 2009)&lt;br /&gt;
Bachelor of Science in Computer Science – University of Illinois&lt;br /&gt;
Extensive experience in conducting black and white box security reviews of complex applications and networks for major financial organizations and international telecoms. I also have experience working as the primary investigator of attacks against a multi-national organization with IDS sensors in networks throughout the world. In addition, I have experience working with several regulatory controls and security standards (FISMA, NIST, GLBA etc). My experience as an ethical hacker and incident responder puts me in an excellent position to tackle this project. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
I am a Senior Computer Security Engineer with Aspect Security where I perform security code reviews and application security testing against a variety of platforms. Prior to working with Aspect Security, I was heavily involved in the discovery and exploitation of application vulnerabilities during black box ethical hacking assessments for numerous clients.&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I am a member of OWASP and attend Chicago OWASP chapter meetings. I also attend ChiSec, an informal meet-up of security professionals in the Chicago area. In addition, I interact with the community through my security blog. http://michaelcoates.wordpress.com. &lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected. '''&lt;br /&gt;
&lt;br /&gt;
I created a similar framework while working within a Security Operation Center. I created attack scenarios, identified relevant IDS events, defined thresholds and appropriate response action for the Security analysts.&lt;br /&gt;
&lt;br /&gt;
'''Requested Reviewer - Eric Sheridan, Application Security Consultant at Aspect Security, Inc.'''&lt;br /&gt;
&lt;br /&gt;
Eric Sheridan is an Application Security Consultant at Aspect Security, a consulting services company specializing in application security. At Aspect Security, Eric specializes in execution of security verification assessments and the establishment of security activities throughout the development lifecycle. In addition, Eric is an instructor in Aspect’s portfolio of Application Security Courses. Eric is also an active participant in OWASP whose contributions include work with projects such as WebGoat, Stinger, CSRFGuard, CSRFTester, and the SASAP project from OWASP SPoC 2007. Eric was also a featured speaker at the 2007 OWASP/WASC San Jose conference.&lt;br /&gt;
&lt;br /&gt;
Contact Information: eric dot sheridan 'at' owasp dot org&lt;br /&gt;
&lt;br /&gt;
== OWASP Interceptor Project - 2008 Update ==&lt;br /&gt;
&lt;br /&gt;
by Justin Derry&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_Interceptor_Project&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
The OWASP Interceptor project was originally written by myself and donated to the OWASP project. Since it has been online numerous people have downloaded the tools and used the code/toolkit. Currently the industry has very limited “XML” or SOAP client testing tools that are designed specifically to perform XML interception and manipulation. The Objective of the Interceptor project is to provide a strong tool for performing XML penetration tests against Web Service (or XML/SOAP) endpoints. The tool should not replace other proxy interception tools such as Charles, Web Scarab and so on, but be purely focused on handling and reading XML structures from clients.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Interceptor tool includes a “swiss-army” knife of features that will help with decoding/hash generation and interpretation of XML code. The key objective is to make a tool that can assist with the collection, inspection and attack replay of XML requests against service endpoints. This year it’s time for an update. The tool doesn’t run on Vista and needs a number of back-end features addressed as well as some help files etc. (Help to get the tool out of BETA status).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Objectives this year'''&lt;br /&gt;
&lt;br /&gt;
This year I see the following objectives in the application code base.&lt;br /&gt;
•	Get the Interface to run on all Window Platforms (.NET) Win2000, XP and Vista;&lt;br /&gt;
&lt;br /&gt;
•	Update the TCP handle libraries to be faster&lt;br /&gt;
&lt;br /&gt;
•	Update the XML Parser engine to support the latest structures&lt;br /&gt;
&lt;br /&gt;
•	Provide a “default” attack database of known XML attack methods (this is a big one)&lt;br /&gt;
&lt;br /&gt;
•	Write a number of help files on how to use the tool&lt;br /&gt;
&lt;br /&gt;
•	Update the toolkit BASE64 Decoder, XML Generators etc with further tools&lt;br /&gt;
&lt;br /&gt;
•	Write a better “reporting” engine to show the result of simulated attack responses&lt;br /&gt;
&lt;br /&gt;
•	Better HTTP support for Manipulation, Authentication and Header Injection etc&lt;br /&gt;
&lt;br /&gt;
•	Better support for interception and handling AJAX XML requests&lt;br /&gt;
&lt;br /&gt;
These are the core features I would like to introduce, with also further to probably come as a part of the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&lt;br /&gt;
&lt;br /&gt;
The current development cycle stopped due to limited time and the need to purchase the IDE tools to develop the interface in .NET. As a Summer of Code 2008 sponsored project we can get the IDE interface tools to implement “Vista” features that will see the tool run on all .NET platforms (Win2000, XP and Vista). Recent changes in my job will allow me to spend more time on developing the toolkit.&lt;br /&gt;
&lt;br /&gt;
Over a number of years I have been involved with OWASP, whilst most recently getting involved with running the OWASP Australia Security Conference for 2008, as well as the Brisbane Chapter. I am also working in the Asia Pacific RIM to further increase the awareness of OWASP and Application Security. My Conference duties for the year have finished up (till planning starts again in a couple of months) so my time can be invested in updating the toolkit.&lt;br /&gt;
&lt;br /&gt;
I believe during the previous years, i have shown OWASP that i am willing and able to produce a quality outcome and i am prepared to put the effort into OWASP to acheive the goals set out for this project. &lt;br /&gt;
&lt;br /&gt;
Some of the Sponsorship money for the project would go to purchasing a specific toolkit for the UI. (The UI is important simply because we want the application to be user friendly). Xceed Components provide a Smart UI as well as some of the decoding and compression features the tool needs. This would require us to approach them upfront for a “free” licence or use some of the Sponsorship money to buy the toolkit. But we can tackle that problem when we come to it.&lt;br /&gt;
&lt;br /&gt;
== SQL Injector Benchmarking Project (SQLiBENCH) ==&lt;br /&gt;
&lt;br /&gt;
by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
'''Prelude'''&lt;br /&gt;
&lt;br /&gt;
There're a lot of and great open source tools (takeover/dumpers/hybrid) for taking advantage of an sql injection vulnerability both used by web application security specialists and attackers. &lt;br /&gt;
Techniques used, databases supported, algorithms employed and abilities implemented by these &amp;quot;sql injectors&amp;quot; greatly varies. Standardization is one of the abstract goals of OWASP and we think it's important to standardize general vulnerability techniques exists in web applications and one of the biggest one is sql manipulation. &lt;br /&gt;
In our effort, we aim to produce a standardization of techniques used in exploiting sql injection by automatic tools. &lt;br /&gt;
&lt;br /&gt;
'''Proposal'''&lt;br /&gt;
&lt;br /&gt;
The goal of the project is to create a detailed set of benchmarking criterias for automatic sql injection tools and applying these to a set of open source sql injectors, producing analysis/benchmarking reports.&lt;br /&gt;
Additionaly, in a semi-academic manner, algorithms used by several sql injectors will be analyzed both implementation and complexity vise.&lt;br /&gt;
&lt;br /&gt;
'''Deliverables And Project Schedule Milestones'''&lt;br /&gt;
&lt;br /&gt;
Two set of documents will be produced. One of them will include the benchmarking criterias and the other will comprise of analysis of selected sql injectors against the benchmarking criterias.&lt;br /&gt;
Moreover, an interactive visual data flow diagram, giving hints to testers about which tool should be used under which circumstances, will be implemented with web-based technologies such as jquery library. &lt;br /&gt;
&lt;br /&gt;
April 03    Project Kickoff&lt;br /&gt;
&lt;br /&gt;
April 03-30 Determination of the benchmarking criterias &lt;br /&gt;
&lt;br /&gt;
May   01-15 Producing a test environment image with 5-6 rdbms (MSSQL Express, Oracle Express, DB2 Express, MySQL, PgSQL, etc.) and a vulnerable application (which will support different sql injection types, databases and include logging capabilities)&lt;br /&gt;
&lt;br /&gt;
May   15-31 Selecting and installing automatic sql injectors onto the test system and starting to use them on vulnerable application&lt;br /&gt;
&lt;br /&gt;
June  01-30 Analysing tools and applying benchmarking criterias, contacting the authors as we proceed &lt;br /&gt;
&lt;br /&gt;
July  01-31 Producing reports for benchmarking criterias and tool analysis&lt;br /&gt;
&lt;br /&gt;
'''About Us'''&lt;br /&gt;
&lt;br /&gt;
We're part of OWASP-Turkey. [http://www.h-labs.org Mesut Timur] is a junior in the Computer Engineering Dept. of [http://www.gyte.edu.tr University of GYTE] and [http://www.webguvenligi.org Bedirhan Urgun] is a web/application security specialist in [http://www.uekae.tubitak.gov.tr TUBITAK-UEKAE].&lt;br /&gt;
&lt;br /&gt;
== OWASP-WeBekci Project ==&lt;br /&gt;
&lt;br /&gt;
by Bunyamin Demir&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_WeBekci_Project&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
Web application firewalls (WAF) are gaining importance among the information security technologies designed to protect web sites from attack. WAF solutions prevent attacks that network firewalls and intrusion detection systems can't and they require no modification of application source code. ModSecurity [http://www.modsecurity.org/] is an open source web application firewall that runs as an Apache module. It is an embeddable web application firewall and it provides protection from a range of attacks against web applications. It is an open source project available to everyone; it however does not come with an admin panel. &lt;br /&gt;
&lt;br /&gt;
I decided to provide this essential tool with a control panel which I believe will ease and thus encourage its usage.&lt;br /&gt;
&lt;br /&gt;
ModSecurity allows for HTTP traffic monitoring and real-time analysis with no changes to existing infrastructure. My main goal is to analyze attacks and generate rules to change the configuration of the ModSecurity accordingly.&lt;br /&gt;
&lt;br /&gt;
ModSecurity  has a feature called “flexible rule engine” as its heart of Attack Prevention capability . It uses ModSecurity’s “Rule Language,” (a programming language designed to work with HTTP transaction data). It is easy to use and flexible; yet the system administrators need to learn its own rules to create what is called “Certified ModSecurity Rules” to be implemented. My control panel will automate the major code-generation in Rule Language. &lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&lt;br /&gt;
&lt;br /&gt;
* '''Configuration'''        : Most of the configuration parameters will be managed through the web interface&lt;br /&gt;
* '''Rule Generator'''       : Basic rules will be generated using the web interface&lt;br /&gt;
* '''Core Rule Integration''': Core rules will be added to the database for use&lt;br /&gt;
* '''Logging and Reporting''': Apache error log and modsec_audit log will be parsed and presented to the user thru the web interface&lt;br /&gt;
* '''DB Support'''           : MySQL&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
Being a SpoC2007 project, it couldn't be implemented mainly due to a job change and therefore lack of time. With the help of Bedirhan Urgun we'll be able to produce a quality web admin panel GUI for a same host modsec installation infrastructure. We are both part of OWASP Turkey [http://www.owasp.org/index.php/Turkey] and tried to produce a great deal of awareness both about web security and OWASP with both documents/chapter meetings/email list and mini-conferences.&lt;br /&gt;
&lt;br /&gt;
== Teachable Static Analysis Workbench ==&lt;br /&gt;
&lt;br /&gt;
By Dmitry Kozlov, Igor Konnov&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''&lt;br /&gt;
&lt;br /&gt;
This application covers two OWASP Project proposals: P002 Teachable Static Analysis Workbench and P023 Code Review Tree. These project proposals look complementary and the key idea was to create ONE tool for code review instead of number non-integrated tools.&lt;br /&gt;
Note: this project is very close to P024 Attack Surface Metric too – based on web application entry points and used backends it is easy to compute such a metric.&lt;br /&gt;
&lt;br /&gt;
'''Project objectives and deliverables:'''&lt;br /&gt;
&lt;br /&gt;
Project is intended two deliverables: research technical report (publication ready article) and a workbench prototype.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The research will be intended to answer the following questions: &lt;br /&gt;
* Can we integrate existing open source static analysis tools (OWASP and third-party) to work altogether? We plan analysis to cover the following tools: LAPSE, Orizon, ESAPI, FindBugs.&lt;br /&gt;
* How static analysis workbench can be taught by security analyst?&lt;br /&gt;
* How static analysis workbench can support web-applications built using MVC frameworks?&lt;br /&gt;
&lt;br /&gt;
Workbench prototype will be Java-based Eclipse plug-in which aim is to help security analyst/code reviewer validation of web application. At prototype step we suggest to analyze J2EE Web tier applications build on Java Servlets, JSP (without business logic in it) and one MVC framework (Apache Struts).  We plan workbench prototype to have the following functionality:&lt;br /&gt;
* Input validation vulnerabilities analysis: identification of web application entry points (aka attack surface in P024), call graph for each entry point (see “Packages -&amp;gt; Classes -&amp;gt; Methods -&amp;gt; callsites” in P023), identification of data validation routines, teachable taint analysis. &lt;br /&gt;
* Authentification and access control analysis: identification of code related to access control and it’s analysis.&lt;br /&gt;
* Pattern-based code analysis.&lt;br /&gt;
* Teachability: analyst indicates security-related code (sources of tainted data, sensitive sinks, input validation and sanitizing functions, access control code, etc.) and workbench automatically recomputes possible vulnerabilities list. The second idea is to spread knowledge gathered from analyst to other web applications.&lt;br /&gt;
&lt;br /&gt;
Project budget: $10K (note: this project combines two OWAPS Project Proposals)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Future development:'''&lt;br /&gt;
&lt;br /&gt;
Further, workbench can be extended to support various Java web application frameworks and to support Python web applications (it seems to us that teachable tool is much more valuable for Python and other languages where the notion of web application is not so formal as in J2EE).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Background: '''&lt;br /&gt;
&lt;br /&gt;
Dmitry Kozlov is a postdoc researcher at Moscow State &lt;br /&gt;
University. Since 2003 he leads a group performing research in the area of web &lt;br /&gt;
application security. In 2007 this group took part in OWASP Spring of &lt;br /&gt;
Code on project &amp;quot;Python Dynamic Analysis&amp;quot;. This project was implemented &lt;br /&gt;
mostly by Dmitry’s PhD student Andrew Petukhov. Also in 2007 this group created static analysis tool for Python language, based on Pixy PHP analyser (publication is upcoming).&lt;br /&gt;
&lt;br /&gt;
Igor Konnov is PhD student at Moscow State University he has strong background in program analysis and verification.&lt;br /&gt;
&lt;br /&gt;
== OpenPGP Extensions for HTTP - Enigform and mod_openpgp ==&lt;br /&gt;
By Arturo 'Buanzo' Busleiman&lt;br /&gt;
&lt;br /&gt;
=== Introduction to the project ===&lt;br /&gt;
My name is Arturo Busleiman, a.k.a Buanzo. Last year I worked with OWASP to take Enigform (The OpenPGP Firefox Extension) and mod_openpgp (The Apache counterpart) to an usable level. This year, I want to focus on mod_openpgp and Secure Session Management, presenting a working web-site using this new authentication methodology in such a way that it will attract security professionals and web-developers to this new mix of two good'ol protocols: HTTP and OpenPGP.&lt;br /&gt;
&lt;br /&gt;
For that to happen, OWASP support is essential. I'm very happy to submit my application for Summer of Code 2008.&lt;br /&gt;
&lt;br /&gt;
=== About Buanzo ===&lt;br /&gt;
&lt;br /&gt;
I am a 26 year old Independent security consultant from Buenos Aires, Argentina, that has contributed to the world of information systems security since 1994. Linux and Security are my life.&lt;br /&gt;
&lt;br /&gt;
A quick search for buanzo on google [http://www.google.com/search?hl=en&amp;amp;q=buanzo&amp;amp;btnG=Google+Search] will provide all necessary details about my professional and community background. For comprobable experience, you could also check my Rent a Coder profile.[http://www.rentacoder.com/RentACoder/SoftwareCoders/showBioInfo.asp?lngAuthorId=735204] or my &amp;quot;Customer Comments&amp;quot; page at [http://www.buanzo.com.ar/pro/].&lt;br /&gt;
&lt;br /&gt;
I've contributed scripts, fixes and translations to the Nmap project. I've also acted as Expert Contributor for SANS TOP-20 2004, 2005, 2006 and 2007. I've developed &lt;br /&gt;
tools and written documentation that can be found in Freshmeat, mozdev.org and addons.mozilla.org. Also I've written&lt;br /&gt;
the Unix chapter of the OISSG's Information Systems Security Assessment Framework, v1.0 [http://www.oissg.org/content/view/71/71/].&lt;br /&gt;
&lt;br /&gt;
In my free time, I &amp;quot;run&amp;quot; the 2600 Argentina meetings, write articles, give talks and play the guitar.&lt;br /&gt;
&lt;br /&gt;
I'm an active member of the FLOSS community since 1996, having written articles in magazines http://www.net-security.org/dl/articles/Detecting_and_Understanding_rootkits.txt, made TV, radio and newspaper appearances [http://codigoabierto.bitacoras.com/archivos/2005/04/01/buanzo-hacks] and led different security research groups of Spain, Mexico and Argentina. Currently I contribute time thorugh my sites, forums and blogs, answering questions in mailing lists and helping coordinate some local LUGs. I do also manager the Linux Counter for Argentina [http://counter.li.org/reports/place.php?place=AR].&lt;br /&gt;
&lt;br /&gt;
=== About Enigform ===&lt;br /&gt;
&lt;br /&gt;
The project has draw attention from the IETF OpenPGP Working Group, and even Vinton Cerf (The Father of the Internet) said that Enigform and mod_openpgp &amp;quot;[this] strikes me as a really interesting idea and I hope you (Buanzo) will pursue it with the W3C.&amp;quot; (February 18, 2008). [http://en.wikipedia.org/wiki/Enigform]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26989</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26989"/>
				<updated>2008-03-24T18:24:57Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: Added Enigform project, user Buanzo / Arturo Busleiman.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli &lt;br /&gt;
* Proposal: Make [[OWASP ASDR Project|OWASP ASDR Project]] a release quality document.&lt;br /&gt;
&lt;br /&gt;
The ASDR is a reference volume that contains basic information about all the foundational topics in application security. It intends to replace and refresh [[OWASP Honeycomb Project|Honeycomb Project]] with a new structure for articles and relationship between categories, thus making it a release quality doc.&lt;br /&gt;
&lt;br /&gt;
This idea raised when finished the [[Attack|Attack Reference Guide]] for [[OWASP Spring Of Code 2007|OWASP Spring Of Code 2007]], where it was identified that OWASP reference articles need some special attention. Jeff Williams is totally supporting this project.&lt;br /&gt;
&lt;br /&gt;
We already have defined which type of article we should include on Desk Reference, as follows:&lt;br /&gt;
* [[:Category:Principle|Principles]]&lt;br /&gt;
* [[:Category:Threat_Agent|Threat Agents]]&lt;br /&gt;
* [[:Category:Attack|Attacks]]&lt;br /&gt;
* [[:Category:Vulnerability|Vulnerabilities]]&lt;br /&gt;
* [[:Category:Countermeasure|Countermeasures]]&lt;br /&gt;
* [[:Category:Technical Impact|Technical Impacts]]&lt;br /&gt;
* [[:Category:Business Impact|Business Impacts]]&lt;br /&gt;
&lt;br /&gt;
*Road Map: A complete project roadmap can be found on '''[[ASDR Table of Contents|ASDR Table of Contents]]'''. Basically, the following activities should be performed, some of them already started:&lt;br /&gt;
** Define articles templates for each reference type&lt;br /&gt;
** Define subcategories for articles classification&lt;br /&gt;
** Compile first DRAFT version of ASDR Book&lt;br /&gt;
** Articles development &amp;amp; Call for Volunteers&lt;br /&gt;
** Articles revision&lt;br /&gt;
** First version of OWASP ASDR book&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali (aka nTze)&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Security Software Life Cycle'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;br /&gt;
&lt;br /&gt;
== OWASP Classic ASP Security Project  ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
I am interested in making P018 - OWASP Classic ASP Security Project happen, Classic ASP 2.0 and 3.0 applications are still largely used as this technology is more than 10 years old and was largely used. there are thousands of sites on the wild that need guidance on the security arena. This is where OWASP can come up and provide help for “making the Web a better place” and continue spreading the word on security. I have always be a passionate of the technology (regardless of its inconveniences such as being old and DLL-hell prone) and I am really exited on the idea of sharing my knowledge of this area to the world and what best that though OWASP.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
Create a secure framework for Classic ASP application by complementing existing OWASP projects with documentation for this particular technology and the creation of security libraries. More specifically:&lt;br /&gt;
* Creation of a Common Object Repository for ASP applications based on OWASP ESAPI Project including objects and/or references to libraries for security applications all this aligned with OWASP Top10 and OWASP Guide .&lt;br /&gt;
* Create Documentation aligned to OWASP Code Review Project Checklist providing additional technology-specific checks.&lt;br /&gt;
* Addition of expression for Code Review Tool to support Classic ASP applications.&lt;br /&gt;
* Implementation of Version 1 of Stinger for ASP either by using an installable COM library or ISAPI.&lt;br /&gt;
* This same module will compliment the OWASP Validation Documentation Project.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver. &lt;br /&gt;
&lt;br /&gt;
Also I’ve had close contact with OWASP since 2005&lt;br /&gt;
[https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html] by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish.&lt;br /&gt;
&lt;br /&gt;
== Internationalization Guidelines and OWASP-Spanish Project ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
The main goal of OWASP is to spread the word about security (“Our mission is to make application security &amp;quot;visible,&amp;quot; so that people and organizations can make informed decisions about application security risks.”) and OWASP has done great work so far :). And now it’s time for a next big step.&lt;br /&gt;
&lt;br /&gt;
The number of native and secondary speakers in the world for Chinese, Spanish, French, Russian, Arabic and Indi languages are estimated in similar number to English speaking or even more (Some References at [http://en.wikipedia.org/wiki/Ethnologue_list_of_most_spoken_languages Ethnologue], [http://encarta.msn.com/media_701500404/Languages_Spoken_by_More_Than_10_Million_People.html Encarta], [http://en.wikipedia.org/wiki/List_of_languages_by_number_of_native_speakers Wikipedia]). I think is a good time for OWASP to reach those that do not speak English to have full access to all the OWASP materials, not just a couple of documents.&lt;br /&gt;
&lt;br /&gt;
OWASP, while open to translations, do not have clear guidelines on how to translate OWASP contents and (AFAIK) there is no multi-language support in OWASP.org site. This is understandable as there is no formal project for internationalization so far. &lt;br /&gt;
&lt;br /&gt;
'''Oportunity and Effort'''&amp;lt;br&amp;gt;&lt;br /&gt;
This is great opportunity to make Spanish the first language on which the OWASP site and documentation is fully translated and at the same time share the experience with other people interested in the same objective, Bring OWASP to the world.  And this is something I’ve being pushing for some time ago and that could be possible “at once” via SoC 2008.&lt;br /&gt;
&lt;br /&gt;
I understand this is significant effort so to have it done I will count with the help of 6 people (friend of mine, all of them Security auditors with excellent English level) plus a few well known contributors from OWASP-Spanish effort, so the founding will be divided among the people involved in the same proportion of the work they do for the completion of this effort. This, to encourage delivery.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
* Team up with Larry Casey to implement Multilanguage support in OWASP.org Mediawiki.&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to start a new language translation for OWASP Document and Site Pages&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to implement internationalization and localization ([http://www.w3.org/International/ i18n]) on OWASP Software &lt;br /&gt;
* Full translation to Spanish of all the release-level document projects. Those are:&lt;br /&gt;
** Top 10 2007&lt;br /&gt;
** Guide 2 (Already translated)&lt;br /&gt;
** Testing Guide (Already Translated)&lt;br /&gt;
** Legal&lt;br /&gt;
** FAQ&lt;br /&gt;
* Full Translation of major sections of OWASP Site&lt;br /&gt;
** Project Main Pages (Release, Beta and Alpha levels for both documents and tools projects)&lt;br /&gt;
** Principles&lt;br /&gt;
** References Section&lt;br /&gt;
** Conferences&lt;br /&gt;
** News (Those currently displayed in OWASP site)&lt;br /&gt;
** About OWASP&lt;br /&gt;
* Evaluation of Spanish translation approach for WebGoat and WebScarab and delivery of this document to Bruce and Rogan for possible implementation in near future.&lt;br /&gt;
* Leverage for deploy of es.owasp.org, the domain already exists but is not redirecting correctly.&lt;br /&gt;
* Create a Communication strategy to help and keep track on new pages or changes in significant pages so all the translations are in sync.&lt;br /&gt;
&lt;br /&gt;
'''Out of Scope'''&amp;lt;br&amp;gt;&lt;br /&gt;
Translation of the following sections are NOT in Scope&lt;br /&gt;
* Local Chapters Pages&lt;br /&gt;
* Presentations&lt;br /&gt;
* Conferences&lt;br /&gt;
* Videos&lt;br /&gt;
* Blogs&lt;br /&gt;
* All the projects deliverables in Alpha and Beta Stages&lt;br /&gt;
* All the documentation “on development” like Guide Version 3.0&lt;br /&gt;
* Translation of Pages, documentation or tools to other language other than Spanish according to the stated in above section.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I’ve being part of contributions to OWASP documents on the translation arena since 2005 [https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html], a few of them by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish. It is time to make the full job done :).&lt;br /&gt;
&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver.&lt;br /&gt;
&lt;br /&gt;
== The Ruby on Rails Security Guide v2 ==&lt;br /&gt;
Heiko Webers&lt;br /&gt;
&lt;br /&gt;
The last security guide for Rails [http://www.owasp.org/index.php/Category:OWASP_Web_Application_Security_Put_Into_Practice] was a great success, with a lot of more secure web applications and continued awareness in the community of security issues. The Ruby on Rails Security Project [http://www.rorsecurity.info/] is the one and only source of information about Rails security topics, and I keep the community up-to-date with blog posts and conference talks in Europe. The Guide and the Project has been mentioned in several Rails books and web-sites.&lt;br /&gt;
&lt;br /&gt;
Version 1 of the Ruby on Rails Security Guide was sponsored by the SpoC 07, set the standard for OWASP programming language specific guides in terms of the topic outline and has been published as a book [http://www.lulu.com/content/1412042]. Nevertheless I'm convinced that a more compact design and a &amp;quot;question-and-answer&amp;quot; style of writing will reach an even larger audience. Of course the new Guide will still include answers to the OWASP Top Ten security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
A lot has changed since the publishing of the first Guide. Some new security holes have been found, there are new advises and most importantly Rails version 2.0 has been released. The new Ruby on Rails Security Guide aims at providing an up-to-date coding and configuration guide for the Rails community.&lt;br /&gt;
&lt;br /&gt;
In the new Rails Security Guide I'd like to&lt;br /&gt;
* update the entire book to match Rails 2.0&lt;br /&gt;
* cover new topics, including, but not limited to:&lt;br /&gt;
** Intranet and administration interface security,&lt;br /&gt;
** phishing,&lt;br /&gt;
** real-world attack situations,&lt;br /&gt;
** short excursus on server monitoring,&lt;br /&gt;
** the new CookieStore session management,&lt;br /&gt;
** vulnerabilities in popular plug-ins,&lt;br /&gt;
** denial-of-service attacks&lt;br /&gt;
* cover all OWASP Top Ten security vulnerabilities&lt;br /&gt;
* a more compact writing style, more examples and &amp;quot;questions-and-answers&amp;quot;&lt;br /&gt;
* introduce the OWASP and Rails security to a greater audience&lt;br /&gt;
&lt;br /&gt;
== OWASP Application Security Verification Standard ==&lt;br /&gt;
&lt;br /&gt;
*Mike&lt;br /&gt;
&lt;br /&gt;
'''OWASP Application Security Verification Standard Proposal'''&lt;br /&gt;
&lt;br /&gt;
'''Educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
The applicant is a hands-on senior professional services manager with a trademark of&lt;br /&gt;
developing creative solutions to complex application security-related technical problems. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a background in trusted product evaluation:&lt;br /&gt;
&lt;br /&gt;
*CC evaluation&lt;br /&gt;
*CC evidence development, including operating system test code development&lt;br /&gt;
*CC project management&lt;br /&gt;
*TCSEC evaluation&lt;br /&gt;
*TCSEC project management&lt;br /&gt;
*TEF management&lt;br /&gt;
*CCTL management&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in security-related software development and integration:&lt;br /&gt;
&lt;br /&gt;
*PKI toolkit development&lt;br /&gt;
*PK-E application integration&lt;br /&gt;
*Secure web portal application development&lt;br /&gt;
*Secure web portal integration&lt;br /&gt;
*Secure instant messaging application development, including three patents&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in cryptomodule testing:&lt;br /&gt;
&lt;br /&gt;
*FIPS 140 evaluation&lt;br /&gt;
*FIPS 140 evidence development&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
The applicant does not have experience in contributing to open communities.&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
OWASP is looking for a commercially-workable open standard for performing application security verification efforts. The problem is that there is a huge range in the coverage and level of rigor available in the market, and consumers have no way to tell the difference between someone just running a grep tool, and someone doing painstaking code review and manual testing. So, a standard is needed.&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s)'''&lt;br /&gt;
&lt;br /&gt;
The applicant’s proposal will address the above challenges as follows:&lt;br /&gt;
&lt;br /&gt;
*The applicant will define an evaluation framework that may be used to conduct OWASP Application Security Verification Standard certifications.&lt;br /&gt;
*The applicant will define an OWASP Application Security Verification Standard which defines levels that applications may be certified against.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
The applicant will carry out these activities. Please see below for a proposed list of specific deliverables.&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following deliverables:&lt;br /&gt;
&lt;br /&gt;
*'''Scheme Overview document.''' This will define the overall framework with roles, responsibilities, and processes.&lt;br /&gt;
*'''Evaluation and Certification document.''' This will describe the evaluation and certification process.&lt;br /&gt;
*'''Conditions for the Use of Trademarks.''' This will describe OWASP’s name, logo, and certificate may be used and referenced.&lt;br /&gt;
*'''Evaluation Report Content Requirements.''' This will describe the content requirements of evaluation reports.&lt;br /&gt;
*'''OWASP Application Security Verification Standard.''' This will define the levels that applications may be certified against.&lt;br /&gt;
*'''OWASP Application Security Verification Standard Appendix A.''' This will define the required content of the OWASP Application Security Verification Standard Security Policy.&lt;br /&gt;
*'''Policy Letter #1. Acceptance of Security Policies into OWASP Evaluation''' This will define the requirements to be listed as in evaluation on the OWASP web site.&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following rough project schedule:&lt;br /&gt;
&lt;br /&gt;
*2nd April. Project kickoff.&lt;br /&gt;
*15th June. Alpha Quality drafts of Scheme Overview document and of OWASP Application Security Verification Standard document completed.&lt;br /&gt;
*31st August. Project completion. Beta Quality drafts of all documents completed.&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
The long-term vision for the project is to normalize the range in the coverage and level of rigor available in the market when it comes to performing application security verification.&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected.'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a uniquely-qualified perspective given his experience with TCSEC, TTAP, CC, FIPS 140-1, and FIPS 140-2 evaluation programs, and his real-world perspective as a developer and integrator of security-related applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== GTK+ GUI for w3af project ==&lt;br /&gt;
&lt;br /&gt;
''Facundo Batista''&lt;br /&gt;
&lt;br /&gt;
'''Your educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
I'm Electronic Engineer with a Master in Engineer Innovation in&lt;br /&gt;
Bologna University, Italy. I live in Buenos Aires, Argentina, and love&lt;br /&gt;
reading books, playing tennis, and programming Python.&lt;br /&gt;
&lt;br /&gt;
I worked in a mobile company for six years, in the Network Management&lt;br /&gt;
department, then I was Chief Developer of a Mobile Content Provider,&lt;br /&gt;
and now I'm Solution Architect in Multimedia &amp;amp; Systems Integration in&lt;br /&gt;
Ericsson. Also I was professor in several universities, high schools&lt;br /&gt;
and other institutions.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
None, more than working in w3af. However, my proposal here is not&lt;br /&gt;
related to the security part of the product, but to its graphical&lt;br /&gt;
interface and usability.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I'm very involved in the free software and open source community. I'm&lt;br /&gt;
a Python Core Developer and member of the Python Software Foundation&lt;br /&gt;
by merit. I have a long history of talks given in several&lt;br /&gt;
international (PyCon, EuroPython) and national (a lot!) conferences. I&lt;br /&gt;
also teach Python in educational institutions, enterprises and as a&lt;br /&gt;
private instructor. I founded Python Argentina, the national users&lt;br /&gt;
groups, and I'm a very active member of it.&lt;br /&gt;
&lt;br /&gt;
I also lead other open source projects (SMPPy, SiGeFi, etc.) and&lt;br /&gt;
particpate in others (Docutils, w3af itself, etc.).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
My main objective is to minimize the effort and learning curve of&lt;br /&gt;
using w3af, providing a very usable graphical interface.&lt;br /&gt;
&lt;br /&gt;
Note that as the interface is cross platform, being usable also in the&lt;br /&gt;
win32 environment, it will help to popularize the w3af project.&lt;br /&gt;
&lt;br /&gt;
This will allow users without information security knowledge to verify&lt;br /&gt;
that their web applications are correctly programmed and configured.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
I will carry the following activities, detailed later in smaller steps:&lt;br /&gt;
&lt;br /&gt;
- Design and code new windows and interfaces to increase the functionality of the project.&lt;br /&gt;
&lt;br /&gt;
- Tuning of the process workflow, allowing a more intuitive way of working.&lt;br /&gt;
&lt;br /&gt;
- Visual polishing for a more pleasant and intuitive tool.&lt;br /&gt;
&lt;br /&gt;
- Usability tests and improvements.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
''New features implemented in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Local proxy to trap and modify requests and responses sent from a browser.&lt;br /&gt;
&lt;br /&gt;
- Manually send a request and analyze the response.&lt;br /&gt;
&lt;br /&gt;
- Manually create a fuzzed requests based on tokens, so user can construct easily differents HTTP request with a regex-like semantics.&lt;br /&gt;
&lt;br /&gt;
- Wizard to perform a vulnerability assessment.&lt;br /&gt;
&lt;br /&gt;
- Graphical display of site map and vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
- Reload a plugin after its edited from within the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Embebed tool to encode/decode URL/Base64 and to hash sha1/md5.&lt;br /&gt;
&lt;br /&gt;
- HTTP response side by side content compare.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Usability improvements in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Meetings with a usability expert that the w3af team leader has already contacted and worked with.&lt;br /&gt;
&lt;br /&gt;
- Kill all pending bugs and make a stable release.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Documentation:''&lt;br /&gt;
&lt;br /&gt;
- Users guide for the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Help system for the GUI itself&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
To provide the web application security community with a stable and fully &lt;br /&gt;
featured framework to perform all the tasks included in a penetration test&lt;br /&gt;
from within the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected'''&lt;br /&gt;
&lt;br /&gt;
w3af is one of the most active web application security projects;&lt;br /&gt;
the community that supports it is growing and we need the support of &lt;br /&gt;
already established organizations like OWASP to keep working at the &lt;br /&gt;
rate that we want to.&lt;br /&gt;
&lt;br /&gt;
== P006 OWASP Corporate Application Security Rating Guide and P025 OWASP Positive Security Project ==&lt;br /&gt;
&lt;br /&gt;
by Eduardo Vianna de Camargo Neves&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
A common approach on most companies is to increase the protection of their assets after the occurrence of a considerable impact. However some companies learned that a positive approach on IT Security is most effective and can reduce the financial costs on responses to security incidents. Benchmarking the application security practices on the corporate world will allow us to understand what steps are required to keep the IT environment protected, using this knowledge to create a public Security Rating Guide that can be used to support the establishment of a security baseline within the community.&lt;br /&gt;
&lt;br /&gt;
Moreover the information from this analysis can be used to support the development of a campaign to spread a positive security posture in the market. The liaison with companies that maintain good security practices  will help to start this initiative from a higher degree and involve several actors on the security stage for the same direction to a market were security is understood as a business value.&lt;br /&gt;
&lt;br /&gt;
'''Approach'''&lt;br /&gt;
&lt;br /&gt;
Assessing public materials from the Top 50 Companies and Top 50 Software Companies, a rating guide will be produced showing tangible metrics that are achieved by those companies and allow them to be considered secure enough on a comparison to a baseline of good practices. As a result the Corporate Application Security Rating Guide will be produced and published for the community and the deliverables used to support the development of the Positive Security Project with facts from a real analysis.&lt;br /&gt;
&lt;br /&gt;
'''Benefits'''&lt;br /&gt;
&lt;br /&gt;
The whole community will be benefited from these initiatives. With the adequate support from OWASP to maintain the projects active and liaise with big players on the market, we can expect the following:&lt;br /&gt;
&lt;br /&gt;
• The community will receive a Security Rating Guide that will allow them to compare their own security practices within the market. As this will be a public document, suppliers and buyers worldwide will share the same information allowing them to adequate the expectations on the usage of security services and tools.&lt;br /&gt;
&lt;br /&gt;
• The Security Rating Guide can be used as a marketing tool by the companies, allowing them to sell security as a business value and avoiding the old-fashion and inadequate FUD approach.&lt;br /&gt;
&lt;br /&gt;
• The knowledge and relationship developed during the production of the Security Rating Guide will allow us to produce the deliverables on Positive Security Project with real information, increasing the credibility of the initiative for the market.&lt;br /&gt;
&lt;br /&gt;
• The Security Rating Guide and the Positive Security Project can be walk in parallel, merging their information to support a concise and continuous marketing campaign to encourage a positive approach on the market.&lt;br /&gt;
&lt;br /&gt;
• As an open community free from commercial pressures, OWASP can use both projects to support the evaluation of security products for the market, allowing the organization to receive profits from these services and support current and future projects.&lt;br /&gt;
&lt;br /&gt;
'''Summarized Work Breakdown Structure (WBS)'''&lt;br /&gt;
&lt;br /&gt;
All the activities will be leaded by Eduardo V. C. Neves, which will be responsible as a single point of contact with the sponsors and to manage a team of compromised volunteers from OWASP community and participants from security communities and associations (i.e. ISSA, SANS and ISC2).&lt;br /&gt;
&lt;br /&gt;
The activities will be carried on WBS summarized bellow. Dates presented should be considered as deadlines for the activities:&lt;br /&gt;
&lt;br /&gt;
• Criteria establishment and definition of the Top 50 Companies and Top 50 Software Companies (April 11)&lt;br /&gt;
&lt;br /&gt;
• Assessment of public materials to support the ranking establishment (April 18)&lt;br /&gt;
&lt;br /&gt;
• Establishment of the Corporate Application Security Rating Guide (April 25)&lt;br /&gt;
&lt;br /&gt;
• Publishing of the Corporate Application Security Rating Guide on OWASP web site and promotion over adequate channels (i.e. publications, blogs and associations) (May 09) (1)&lt;br /&gt;
&lt;br /&gt;
• Criteria establishment and approval of marketing templates for Positive Security Project (May 16) (2)&lt;br /&gt;
&lt;br /&gt;
• Development of the Positive Security Project material (i.e. blog and marketing sheets) (May 30)&lt;br /&gt;
&lt;br /&gt;
• Liaison with the OWASP Members, Top 50 Companies and Top 50 Software Companies to present the project and negotiate their participation as supporters, sponsors or contributors. (June 27)&lt;br /&gt;
&lt;br /&gt;
• Update on Corporate Application Security Rating Guide, including their score on Positive Security approach (July 4)&lt;br /&gt;
&lt;br /&gt;
• Presentation of the Positive Security Project approach and Corporate Application Security Rating Guide on the market (July 31) (3)&lt;br /&gt;
&lt;br /&gt;
• Conference calls with team members to evaluate the results of the initiatives in all countries and produce project´s documents (i.e. lessons learned, update on marketing material and evaluation of alternative approaches for the future steps). (August 15)&lt;br /&gt;
&lt;br /&gt;
• Prepare project documentation and present to the OWASP community on the web site (August 31)&lt;br /&gt;
&lt;br /&gt;
''(1) Support from OWASP Foundation is required to liaise with companies and associations worldwide&lt;br /&gt;
&lt;br /&gt;
''(2) Support from OWASP Foundation and community are required to evaluate adequate marketing templates and translate original documents for their own languages''&lt;br /&gt;
&lt;br /&gt;
''(3) Support from OWASP community is required to spread the word on all countries were OWASP members are located.''&lt;br /&gt;
'''''&lt;br /&gt;
&lt;br /&gt;
'''Project Control'''&lt;br /&gt;
&lt;br /&gt;
The project will be managed following PRINCE2 Process Model and all control documents published for the OWASP community. The following mandatory project control documents are planned:&lt;br /&gt;
&lt;br /&gt;
• Project Initiation Document: To document project´s background, definition, objectives, approach, etc.&lt;br /&gt;
&lt;br /&gt;
• Communication Plan: To assure that OWASP Community are being continuous communicated about project status and deliverables achievement.&lt;br /&gt;
&lt;br /&gt;
• Highlight Report: To provide the OWASP Community with a summary of the project status, progress and potential problems or areas where help may be required.&lt;br /&gt;
&lt;br /&gt;
• End Project Report: To present project achievements. Should be considered the final project report.&lt;br /&gt;
&lt;br /&gt;
More documents may be included during project development to support the control and assure a high quality level (i.e. issue log, project approach).&lt;br /&gt;
&lt;br /&gt;
'''Long Range Plan'''&lt;br /&gt;
&lt;br /&gt;
Both projects should walk in parallel and be used as tools to support efforts to encourage and make the positive approach a reality on the IT Security field. These initiatives shall be supported by OWASP as long term plans and grow to a continuous world-wide campaign in this direction that must achieve big players on the market and be recognized by the community as a tool that must be used to evaluate security enabled companies and products. &lt;br /&gt;
&lt;br /&gt;
'''Why me?'''&lt;br /&gt;
&lt;br /&gt;
Can be me, you or anyone that carries these projects in a professional fashion and assure that all deliverables are being achieved. The most important parts is to make it happen, talk and get the support from reputable associations and large companies (OWASP Members are a good start) and lead it as a long range responsibility.&lt;br /&gt;
&lt;br /&gt;
I am running to win this project because I believe in all of this. I see both as very valuable initiatives that can help companies to make more business; people to get more jobs and the whole community to win in a scenario where our contributions on the security market are recognized as business tools.&lt;br /&gt;
&lt;br /&gt;
'''About me'''&lt;br /&gt;
&lt;br /&gt;
Information Security professional and enthusiastic with 15 years dedicated to achieve expressive results in the areas of IT, Information Security, Compliance and Project Management. A CISSP in good stand and Officer at the ISSA Brazilian Chapter, my professional career gave me extensive knowledge in several fields of Information Security with accumulated experience at consulting firms, as CSO at a world player company on consumer goods market and now as an entrepreneur at Latin American market.&lt;br /&gt;
&lt;br /&gt;
''Application security experience and accomplishments''&lt;br /&gt;
&lt;br /&gt;
My work experience is on Security Management, Risk Assessment, Business Continuity and Disaster Recovery, Security Awareness and other managed-related fields on our industry. I don’t have hands-on experience on application security and this is the main reason why I am running to be qualified on the project described bellow, where I believe that my skills can be used to achieve an excellent result for the community.&lt;br /&gt;
&lt;br /&gt;
''Participation and leadership in open communities''&lt;br /&gt;
&lt;br /&gt;
• Member of OWASP Brazil where I made some small contributions in a recent past.&lt;br /&gt;
&lt;br /&gt;
• Member of ABNT/CB-21/SC02 committee, Brazilian ISO representative for 27001 and 17799 standards&lt;br /&gt;
&lt;br /&gt;
• Officer of ISSA Brazil Chapter where I am responsible for the South Region and as the editor of Antebellum, the ISSA Brazil Journal&lt;br /&gt;
&lt;br /&gt;
• Founder and member of GISI-PR, an open community focused on discuss and promote Information Security initiatives within Paraná State, Brazil&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application ==&lt;br /&gt;
'''Name'''&lt;br /&gt;
&lt;br /&gt;
Michael Coates&lt;br /&gt;
&lt;br /&gt;
'''Project'''&lt;br /&gt;
&lt;br /&gt;
P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses, '''&lt;br /&gt;
&lt;br /&gt;
As critical applications continue to become more accessible and inter-connected, it is paramount that the information be protected. We must also realize that our defenses may not be perfect. Given enough time, attackers can identify security flaws in the design or implementation of an application. In addition to implementing layers of defense within an application, it is critical that we identify malicious individuals before they are able to identify any gaps in our defenses. The best place to identify malicious activity against the application is within the application itself.&lt;br /&gt;
Network based intrusion detection systems are not appropriate to handle the custom and intricate workings of an enterprise application and are ill-suited to detect attacks focusing on application logic such as authentication, access control, etc.  The application itself is the best place to identify and respond to malicious activity.&lt;br /&gt;
This project will create the framework which can be used to build a robust system of attack detection, analysis, and response within an enterprise application&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s), '''&lt;br /&gt;
&lt;br /&gt;
I plan to use a methodical approach throughout the creation of this resource. I will reference my own professional experience, OWASP resources, ESAPI, and academic materials to identify a robust set of potential attacks and identification methods. Thresholds will be recommended for each of the detected attacks. Each recommended threshold value and response recommendation will be accompanied with additional information to describe the purpose of the threshold and recommendation. This additional information will allow the reader to determine if the threshold is appropriate for their implementation.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities, '''&lt;br /&gt;
&lt;br /&gt;
I will complete the following activities:&lt;br /&gt;
1. Identify and define attack patterns against applications&lt;br /&gt;
2. Document points of detection within the application for the attack patterns &amp;amp; identify key information to log&lt;br /&gt;
3. Create thresholds for generating security alerts&lt;br /&gt;
4. Define recommended response actions for the security alerts&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress, '''&lt;br /&gt;
&lt;br /&gt;
April 2, 2008 - Project Begins&lt;br /&gt;
&lt;br /&gt;
April 2, 2008-April 12, 2008 - High level planning &amp;amp; design 	&lt;br /&gt;
&lt;br /&gt;
April 12, 2008-May 1, 2008 - Identify and define attack patterns against applications	&lt;br /&gt;
&lt;br /&gt;
May 1, 2008-June 1, 2008 - Document points of detection within the application for the attack patterns &amp;amp; identify key information to log	&lt;br /&gt;
&lt;br /&gt;
June 1, 2008-June 13, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
June 15, 2008 - Status Report	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Create thresholds for generating security alerts	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Define recommended response actions for the security alerts	&lt;br /&gt;
&lt;br /&gt;
Aug 16, 2008-Aug 30, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
Aug 31, 2008 - Project Complete	&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project, '''&lt;br /&gt;
&lt;br /&gt;
1.  I’d like to include a tiered type approach of thresholds and responses. This is would be similar to the approach used by FISMA of defining different controls for High, Medium, and Low systems.&lt;br /&gt;
&lt;br /&gt;
2. Building on item #1, I want to eventually include a system which lets the user provide information about their system.  This information could include rating or prioritizing different security concerns. a customized set of monitoring points, thresholds and response actions can be recommended for the application based on the provided data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About Me'''&lt;br /&gt;
&lt;br /&gt;
'''Education &amp;amp; Professional Background'''&lt;br /&gt;
&lt;br /&gt;
Masters of Science in Computer, Information and Network Security – DePaul University &lt;br /&gt;
(Expected Graduation 2009)&lt;br /&gt;
Bachelor of Science in Computer Science – University of Illinois&lt;br /&gt;
Extensive experience in conducting black and white box security reviews of complex applications and networks for major financial organizations and international telecoms. I also have experience working as the primary investigator of attacks against a multi-national organization with IDS sensors in networks throughout the world. In addition, I have experience working with several regulatory controls and security standards (FISMA, NIST, GLBA etc). My experience as an ethical hacker and incident responder puts me in an excellent position to tackle this project. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
I am a Senior Computer Security Engineer with Aspect Security where I perform security code reviews and application security testing against a variety of platforms. Prior to working with Aspect Security, I was heavily involved in the discovery and exploitation of application vulnerabilities during black box ethical hacking assessments for numerous clients.&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I am a member of OWASP and attend Chicago OWASP chapter meetings. I also attend ChiSec, an informal meet-up of security professionals in the Chicago area. In addition, I interact with the community through my security blog. http://michaelcoates.wordpress.com. &lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected. '''&lt;br /&gt;
&lt;br /&gt;
I created a similar framework while working within a Security Operation Center. I created attack scenarios, identified relevant IDS events, defined thresholds and appropriate response action for the Security analysts.&lt;br /&gt;
&lt;br /&gt;
'''Requested Reviewer - Eric Sheridan, Application Security Consultant at Aspect Security, Inc.'''&lt;br /&gt;
&lt;br /&gt;
Eric Sheridan is an Application Security Consultant at Aspect Security, a consulting services company specializing in application security. At Aspect Security, Eric specializes in execution of security verification assessments and the establishment of security activities throughout the development lifecycle. In addition, Eric is an instructor in Aspect’s portfolio of Application Security Courses. Eric is also an active participant in OWASP whose contributions include work with projects such as WebGoat, Stinger, CSRFGuard, CSRFTester, and the SASAP project from OWASP SPoC 2007. Eric was also a featured speaker at the 2007 OWASP/WASC San Jose conference.&lt;br /&gt;
&lt;br /&gt;
Contact Information: eric dot sheridan 'at' owasp dot org&lt;br /&gt;
&lt;br /&gt;
== OWASP Interceptor Project - 2008 Update ==&lt;br /&gt;
&lt;br /&gt;
by Justin Derry&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_Interceptor_Project&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
The OWASP Interceptor project was originally written by myself and donated to the OWASP project. Since it has been online numerous people have downloaded the tools and used the code/toolkit. Currently the industry has very limited “XML” or SOAP client testing tools that are designed specifically to perform XML interception and manipulation. The Objective of the Interceptor project is to provide a strong tool for performing XML penetration tests against Web Service (or XML/SOAP) endpoints. The tool should not replace other proxy interception tools such as Charles, Web Scarab and so on, but be purely focused on handling and reading XML structures from clients.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Interceptor tool includes a “swiss-army” knife of features that will help with decoding/hash generation and interpretation of XML code. The key objective is to make a tool that can assist with the collection, inspection and attack replay of XML requests against service endpoints. This year it’s time for an update. The tool doesn’t run on Vista and needs a number of back-end features addressed as well as some help files etc. (Help to get the tool out of BETA status).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Objectives this year'''&lt;br /&gt;
&lt;br /&gt;
This year I see the following objectives in the application code base.&lt;br /&gt;
•	Get the Interface to run on all Window Platforms (.NET) Win2000, XP and Vista;&lt;br /&gt;
&lt;br /&gt;
•	Update the TCP handle libraries to be faster&lt;br /&gt;
&lt;br /&gt;
•	Update the XML Parser engine to support the latest structures&lt;br /&gt;
&lt;br /&gt;
•	Provide a “default” attack database of known XML attack methods (this is a big one)&lt;br /&gt;
&lt;br /&gt;
•	Write a number of help files on how to use the tool&lt;br /&gt;
&lt;br /&gt;
•	Update the toolkit BASE64 Decoder, XML Generators etc with further tools&lt;br /&gt;
&lt;br /&gt;
•	Write a better “reporting” engine to show the result of simulated attack responses&lt;br /&gt;
&lt;br /&gt;
•	Better HTTP support for Manipulation, Authentication and Header Injection etc&lt;br /&gt;
&lt;br /&gt;
•	Better support for interception and handling AJAX XML requests&lt;br /&gt;
&lt;br /&gt;
These are the core features I would like to introduce, with also further to probably come as a part of the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&lt;br /&gt;
&lt;br /&gt;
The current development cycle stopped due to limited time and the need to purchase the IDE tools to develop the interface in .NET. As a Summer of Code 2008 sponsored project we can get the IDE interface tools to implement “Vista” features that will see the tool run on all .NET platforms (Win2000, XP and Vista). Recent changes in my job will allow me to spend more time on developing the toolkit.&lt;br /&gt;
&lt;br /&gt;
Over a number of years I have been involved with OWASP, whilst most recently getting involved with running the OWASP Australia Security Conference for 2008, as well as the Brisbane Chapter. I am also working in the Asia Pacific RIM to further increase the awareness of OWASP and Application Security. My Conference duties for the year have finished up (till planning starts again in a couple of months) so my time can be invested in updating the toolkit.&lt;br /&gt;
&lt;br /&gt;
I believe during the previous years, i have shown OWASP that i am willing and able to produce a quality outcome and i am prepared to put the effort into OWASP to acheive the goals set out for this project. &lt;br /&gt;
&lt;br /&gt;
Some of the Sponsorship money for the project would go to purchasing a specific toolkit for the UI. (The UI is important simply because we want the application to be user friendly). Xceed Components provide a Smart UI as well as some of the decoding and compression features the tool needs. This would require us to approach them upfront for a “free” licence or use some of the Sponsorship money to buy the toolkit. But we can tackle that problem when we come to it.&lt;br /&gt;
&lt;br /&gt;
== SQL Injector Benchmarking Project (SQLiBENCH) ==&lt;br /&gt;
&lt;br /&gt;
by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
'''Prelude'''&lt;br /&gt;
&lt;br /&gt;
There're a lot of and great open source tools (takeover/dumpers/hybrid) for taking advantage of an sql injection vulnerability both used by web application security specialists and attackers. &lt;br /&gt;
Techniques used, databases supported, algorithms employed and abilities implemented by these &amp;quot;sql injectors&amp;quot; greatly varies. Standardization is one of the abstract goals of OWASP and we think it's important to standardize general vulnerability techniques exists in web applications and one of the biggest one is sql manipulation. &lt;br /&gt;
In our effort, we aim to produce a standardization of techniques used in exploiting sql injection by automatic tools. &lt;br /&gt;
&lt;br /&gt;
'''Proposal'''&lt;br /&gt;
&lt;br /&gt;
The goal of the project is to create a detailed set of benchmarking criterias for automatic sql injection tools and applying these to a set of open source sql injectors, producing analysis/benchmarking reports.&lt;br /&gt;
Additionaly, in a semi-academic manner, algorithms used by several sql injectors will be analyzed both implementation and complexity vise.&lt;br /&gt;
&lt;br /&gt;
'''Deliverables And Project Schedule Milestones'''&lt;br /&gt;
&lt;br /&gt;
Two set of documents will be produced. One of them will include the benchmarking criterias and the other will comprise of analysis of selected sql injectors against the benchmarking criterias.&lt;br /&gt;
Moreover, an interactive visual data flow diagram, giving hints to testers about which tool should be used under which circumstances, will be implemented with web-based technologies such as jquery library. &lt;br /&gt;
&lt;br /&gt;
April 03    Project Kickoff&lt;br /&gt;
&lt;br /&gt;
April 03-30 Determination of the benchmarking criterias &lt;br /&gt;
&lt;br /&gt;
May   01-15 Producing a test environment image with 5-6 rdbms (MSSQL Express, Oracle Express, DB2 Express, MySQL, PgSQL, etc.) and a vulnerable application (which will support different sql injection types, databases and include logging capabilities)&lt;br /&gt;
&lt;br /&gt;
May   15-31 Selecting and installing automatic sql injectors onto the test system and starting to use them on vulnerable application&lt;br /&gt;
&lt;br /&gt;
June  01-30 Analysing tools and applying benchmarking criterias, contacting the authors as we proceed &lt;br /&gt;
&lt;br /&gt;
July  01-31 Producing reports for benchmarking criterias and tool analysis&lt;br /&gt;
&lt;br /&gt;
'''About Us'''&lt;br /&gt;
&lt;br /&gt;
We're part of OWASP-Turkey. [http://www.h-labs.org Mesut Timur] is a junior in the Computer Engineering Dept. of [http://www.gyte.edu.tr University of GYTE] and [http://www.webguvenligi.org Bedirhan Urgun] is a web/application security specialist in [http://www.uekae.tubitak.gov.tr TUBITAK-UEKAE].&lt;br /&gt;
&lt;br /&gt;
== OWASP-WeBekci Project ==&lt;br /&gt;
&lt;br /&gt;
by Bunyamin Demir&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_WeBekci_Project&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
Web application firewalls (WAF) are gaining importance among the information security technologies designed to protect web sites from attack. WAF solutions prevent attacks that network firewalls and intrusion detection systems can't and they require no modification of application source code. ModSecurity [http://www.modsecurity.org/] is an open source web application firewall that runs as an Apache module. It is an embeddable web application firewall and it provides protection from a range of attacks against web applications. It is an open source project available to everyone; it however does not come with an admin panel. &lt;br /&gt;
&lt;br /&gt;
I decided to provide this essential tool with a control panel which I believe will ease and thus encourage its usage.&lt;br /&gt;
&lt;br /&gt;
ModSecurity allows for HTTP traffic monitoring and real-time analysis with no changes to existing infrastructure. My main goal is to analyze attacks and generate rules to change the configuration of the ModSecurity accordingly.&lt;br /&gt;
&lt;br /&gt;
ModSecurity  has a feature called “flexible rule engine” as its heart of Attack Prevention capability . It uses ModSecurity’s “Rule Language,” (a programming language designed to work with HTTP transaction data). It is easy to use and flexible; yet the system administrators need to learn its own rules to create what is called “Certified ModSecurity Rules” to be implemented. My control panel will automate the major code-generation in Rule Language. &lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&lt;br /&gt;
&lt;br /&gt;
* '''Configuration'''        : Most of the configuration parameters will be managed through the web interface&lt;br /&gt;
* '''Rule Generator'''       : Basic rules will be generated using the web interface&lt;br /&gt;
* '''Core Rule Integration''': Core rules will be added to the database for use&lt;br /&gt;
* '''Logging and Reporting''': Apache error log and modsec_audit log will be parsed and presented to the user thru the web interface&lt;br /&gt;
* '''DB Support'''           : MySQL&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
Being a SpoC2007 project, it couldn't be implemented mainly due to a job change and therefore lack of time. With the help of Bedirhan Urgun we'll be able to produce a quality web admin panel GUI for a same host modsec installation infrastructure. We are both part of OWASP Turkey [http://www.owasp.org/index.php/Turkey] and tried to produce a great deal of awareness both about web security and OWASP with both documents/chapter meetings/email list and mini-conferences.&lt;br /&gt;
&lt;br /&gt;
== Teachable Static Analysis Workbench ==&lt;br /&gt;
&lt;br /&gt;
By Dmitry Kozlov, Igor Konnov&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''&lt;br /&gt;
&lt;br /&gt;
This application covers two OWASP Project proposals: P002 Teachable Static Analysis Workbench and P023 Code Review Tree. These project proposals look complementary and the key idea was to create ONE tool for code review instead of number non-integrated tools.&lt;br /&gt;
Note: this project is very close to P024 Attack Surface Metric too – based on web application entry points and used backends it is easy to compute such a metric.&lt;br /&gt;
&lt;br /&gt;
'''Project objectives and deliverables:'''&lt;br /&gt;
&lt;br /&gt;
Project is intended two deliverables: research technical report (publication ready article) and a workbench prototype.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The research will be intended to answer the following questions: &lt;br /&gt;
* Can we integrate existing open source static analysis tools (OWASP and third-party) to work altogether? We plan analysis to cover the following tools: LAPSE, Orizon, ESAPI, FindBugs.&lt;br /&gt;
* How static analysis workbench can be taught by security analyst?&lt;br /&gt;
* How static analysis workbench can support web-applications built using MVC frameworks?&lt;br /&gt;
&lt;br /&gt;
Workbench prototype will be Java-based Eclipse plug-in which aim is to help security analyst/code reviewer validation of web application. At prototype step we suggest to analyze J2EE Web tier applications build on Java Servlets, JSP (without business logic in it) and one MVC framework (Apache Struts).  We plan workbench prototype to have the following functionality:&lt;br /&gt;
* Input validation vulnerabilities analysis: identification of web application entry points (aka attack surface in P024), call graph for each entry point (see “Packages -&amp;gt; Classes -&amp;gt; Methods -&amp;gt; callsites” in P023), identification of data validation routines, teachable taint analysis. &lt;br /&gt;
* Authentification and access control analysis: identification of code related to access control and it’s analysis.&lt;br /&gt;
* Pattern-based code analysis.&lt;br /&gt;
* Teachability: analyst indicates security-related code (sources of tainted data, sensitive sinks, input validation and sanitizing functions, access control code, etc.) and workbench automatically recomputes possible vulnerabilities list. The second idea is to spread knowledge gathered from analyst to other web applications.&lt;br /&gt;
&lt;br /&gt;
Project budget: $10K (note: this project combines two OWAPS Project Proposals)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Future development:'''&lt;br /&gt;
&lt;br /&gt;
Further, workbench can be extended to support various Java web application frameworks and to support Python web applications (it seems to us that teachable tool is much more valuable for Python and other languages where the notion of web application is not so formal as in J2EE).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Background: '''&lt;br /&gt;
&lt;br /&gt;
Dmitry Kozlov is a postdoc researcher at Moscow State &lt;br /&gt;
University. Since 2003 he leads a group performing research in the area of web &lt;br /&gt;
application security. In 2007 this group took part in OWASP Spring of &lt;br /&gt;
Code on project &amp;quot;Python Dynamic Analysis&amp;quot;. This project was implemented &lt;br /&gt;
mostly by Dmitry’s PhD student Andrew Petukhov. Also in 2007 this group created static analysis tool for Python language, based on Pixy PHP analyser (publication is upcoming).&lt;br /&gt;
&lt;br /&gt;
Igor Konnov is PhD student at Moscow State University he has strong background in program analysis and verification.&lt;br /&gt;
&lt;br /&gt;
== OpenPGP Extensions for HTTP - Enigform and mod_openpgp ==&lt;br /&gt;
By Arturo 'Buanzo' Busleiman&lt;br /&gt;
&lt;br /&gt;
=== Introduction to the project ===&lt;br /&gt;
My name is Arturo Busleiman, a.k.a Buanzo. Last year I worked with OWASP to take Enigform (The OpenPGP Firefox Extension) and mod_openpgp (The Apache counterpart) to an usable level. This year, I want to focus on mod_openpgp and Secure Session Management, presenting a working web-site using this new authentication methodology in such a way that it will attract security professionals and web-developers to this new mix of two good'ol protocols: HTTP and OpenPGP.&lt;br /&gt;
&lt;br /&gt;
For that to happen, OWASP support is essential. I'm very happy to submit my application for Summer of Code 2008.&lt;br /&gt;
&lt;br /&gt;
=== About Buanzo ===&lt;br /&gt;
&lt;br /&gt;
I am a 26 year old Independent security consultant from Buenos Aires, Argentina, that has contributed to the world of information systems security since 1994. Linux and Security are my life.&lt;br /&gt;
&lt;br /&gt;
A quick search for buanzo on google [http://www.google.com/search?hl=en&amp;amp;q=buanzo&amp;amp;btnG=Google+Search] will provide all necessary details about my professional and community background. For comprobable experience, you could also check my Rent a Coder profile.[http://www.rentacoder.com/RentACoder/SoftwareCoders/showBioInfo.asp?lngAuthorId=735204] or my &amp;quot;Customer Comments&amp;quot; page at [http://www.buanzo.com.ar/pro/].&lt;br /&gt;
&lt;br /&gt;
I've contributed scripts, fixes and translations to the Nmap project. I've also acted as Expert Contributor for SANS TOP-20 2004, 2005, 2006 and 2007. I've developed &lt;br /&gt;
tools and written documentation that can be found in Freshmeat, mozdev.org and addons.mozilla.org. Also I've written&lt;br /&gt;
the Unix chapter of the OISSG's Information Systems Security Assessment Framework, v1.0 [http://www.oissg.org/content/view/71/71/].&lt;br /&gt;
&lt;br /&gt;
In my free time, I &amp;quot;run&amp;quot; the 2600 Argentina meetings, write articles, give talks and play the guitar.&lt;br /&gt;
&lt;br /&gt;
I'm an active member of the FLOSS community since 1996, having written articles in magazines http://www.net-security.org/dl/articles/Detecting_and_Understanding_rootkits.txt, made TV, radio and newspaper appearances [http://codigoabierto.bitacoras.com/archivos/2005/04/01/buanzo-hacks] and led different security research groups of Spain, Mexico and Argentina. Currently I contribute time thorugh my sites, forums and blogs, answering questions in mailing lists and helping coordinate some local LUGs. I do also manager the Linux Counter for Argentina [http://counter.li.org/reports/place.php?place=AR].&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=24516</id>
		<title>SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests - Progress Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=24516"/>
				<updated>2008-01-16T19:45:51Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Current Status ===&lt;br /&gt;
&lt;br /&gt;
* 16th January, 2008&lt;br /&gt;
&lt;br /&gt;
As of 16th January, The OpenPGP Secure Session Manager is fully functional. A new release of mod_openpgp and Enigform will happen before the end of January. OWASP made this possible. Thanks to Dinis Cruz and Paulo Coimbra for their support and interest in this project. And thanks to all the Internet community that has sent me feedback and kudos! :) -- Buanzo&lt;br /&gt;
&lt;br /&gt;
== Older Status Reports ==&lt;br /&gt;
&lt;br /&gt;
* 7th November, 2007&lt;br /&gt;
&lt;br /&gt;
As of 7th November, 2007, mod_openpgp, the Server-side Enigform component for Apache, supports OpenPGP-Encrypted HTTP Request Decryption. This means an HTTP client can send an encrypted HTTP request, using the Server's public key, and it will be decrypted and correctly served by the server.&lt;br /&gt;
&lt;br /&gt;
This is a HUGE feature bump, of roughly 1200 lines of C code.&lt;br /&gt;
&lt;br /&gt;
It's much more of what I expected to implement for the OWASP SPOC duration, so I'll be applying for the 2nd half of my funding now.&lt;br /&gt;
&lt;br /&gt;
Also, I've implemented most of the Secure Session Initiation Protocol, but problems with some Apache DB APIs are slowing this much more than I expected. I hope to work out all the issues, or I'll have to release a simplified version. I just hope the Decryption support is enough to apply for the 2nd half of funding.&lt;br /&gt;
&lt;br /&gt;
* 9th July, 2007&lt;br /&gt;
&lt;br /&gt;
As of 9th July, 2007, Enigform has been enhanced with remote site OpenPGP discovery, Public Key Import. Kyle Huff has joined the development team, and the Session Protocol has been proposed. Regarding Encryption, mod_openpgp supports encrypted http requests, but Enigform support for this is in research stage.Microsoft support will be last stage, once Enigform 1.0 and mod_openpgp 1.0 are released.&lt;br /&gt;
&lt;br /&gt;
== Project Links ==&lt;br /&gt;
* [http://enigform.mozdev.org Enigform Development Site]&lt;br /&gt;
* [https://addons.mozilla.org/en-US/firefox/addon/4531 Addons.Mozilla.Org - Stable Releases Installation Page]&lt;br /&gt;
* [http://freshmeat.net/projects/enigform Enigform Freshmeat Page]&lt;br /&gt;
* [http://foros.buanzo.com.ar/viewforum.php?f=35 Official Enigform Forum]&lt;br /&gt;
&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Back to Project page]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=23227</id>
		<title>SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests - Progress Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=23227"/>
				<updated>2007-11-07T14:20:08Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: /* Current Status */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Current Status ===&lt;br /&gt;
&lt;br /&gt;
As of 7th November, 2007, mod_openpgp, the Server-side Enigform component for Apache, supports OpenPGP-Encrypted HTTP Request Decryption. This means an HTTP client can send an encrypted HTTP request, using the Server's public key, and it will be decrypted and correctly served by the server.&lt;br /&gt;
&lt;br /&gt;
This is a HUGE feature bump, of roughly 1200 lines of C code.&lt;br /&gt;
&lt;br /&gt;
It's much more of what I expected to implement for the OWASP SPOC duration, so I'll be applying for the 2nd half of my funding now.&lt;br /&gt;
&lt;br /&gt;
Also, I've implemented most of the Secure Session Initiation Protocol, but problems with some Apache DB APIs are slowing this much more than I expected. I hope to work out all the issues, or I'll have to release a simplified version. I just hope the Decryption support is enough to apply for the 2nd half of funding.&lt;br /&gt;
&lt;br /&gt;
== Older Status Reports ==&lt;br /&gt;
As of 9th July, 2007, Enigform has been enhanced with remote site OpenPGP discovery, Public Key Import. Kyle Huff has joined the development team, and the Session Protocol has been proposed. Regarding Encryption, mod_openpgp supports encrypted http requests, but Enigform support for this is in research stage.Microsoft support will be last stage, once Enigform 1.0 and mod_openpgp 1.0 are released.&lt;br /&gt;
&lt;br /&gt;
== Project Links ==&lt;br /&gt;
* [http://enigform.mozdev.org Enigform Development Site]&lt;br /&gt;
* [https://addons.mozilla.org/en-US/firefox/addon/4531 Addons.Mozilla.Org - Stable Releases Installation Page]&lt;br /&gt;
* [http://freshmeat.net/projects/enigform Enigform Freshmeat Page]&lt;br /&gt;
* [http://foros.buanzo.com.ar/viewforum.php?f=35 Official Enigform Forum]&lt;br /&gt;
&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Back to Project page]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=23224</id>
		<title>SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests - Progress Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=23224"/>
				<updated>2007-11-07T14:06:10Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: /* Current Status */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Current Status ===&lt;br /&gt;
&lt;br /&gt;
As of 7th November, 2007, mod_openpgp, the Server-side Enigform component for Apache, supports OpenPGP-Encrypted HTTP Request Decryption. This means an HTTP client can send an encrypted HTTP request, using the Server's public key, and it will be decrypted and correctly served by the server.&lt;br /&gt;
&lt;br /&gt;
This is a HUGE feature bump, of roughly 1200 lines of C code.&lt;br /&gt;
&lt;br /&gt;
It's much more of what I expected to implement for the OWASP SPOC duration, so I'll be applying for the 2nd half of my funding now.&lt;br /&gt;
&lt;br /&gt;
== Older Status Reports ==&lt;br /&gt;
As of 9th July, 2007, Enigform has been enhanced with remote site OpenPGP discovery, Public Key Import. Kyle Huff has joined the development team, and the Session Protocol has been proposed. Regarding Encryption, mod_openpgp supports encrypted http requests, but Enigform support for this is in research stage.Microsoft support will be last stage, once Enigform 1.0 and mod_openpgp 1.0 are released.&lt;br /&gt;
&lt;br /&gt;
== Project Links ==&lt;br /&gt;
* [http://enigform.mozdev.org Enigform Development Site]&lt;br /&gt;
* [https://addons.mozilla.org/en-US/firefox/addon/4531 Addons.Mozilla.Org - Stable Releases Installation Page]&lt;br /&gt;
* [http://freshmeat.net/projects/enigform Enigform Freshmeat Page]&lt;br /&gt;
* [http://foros.buanzo.com.ar/viewforum.php?f=35 Official Enigform Forum]&lt;br /&gt;
&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Back to Project page]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=20157</id>
		<title>SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests - Progress Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=20157"/>
				<updated>2007-07-24T17:49:36Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Current Status ===&lt;br /&gt;
&lt;br /&gt;
As of 9th July, 2007, Enigform has been enhanced with remote site OpenPGP discovery, Public Key Import. Kyle Huff has joined the development team, and the Session Protocol has been proposed. Regarding Encryption, mod_openpgp supports encrypted http requests, but Enigform support for this is in research stage.Microsoft support will be last stage, once Enigform 1.0 and mod_openpgp 1.0 are released.&lt;br /&gt;
&lt;br /&gt;
== Project Links ==&lt;br /&gt;
* [http://enigform.mozdev.org Enigform Development Site]&lt;br /&gt;
* [https://addons.mozilla.org/en-US/firefox/addon/4531 Addons.Mozilla.Org - Stable Releases Installation Page]&lt;br /&gt;
* [http://freshmeat.net/projects/enigform Enigform Freshmeat Page]&lt;br /&gt;
* [http://foros.buanzo.com.ar/viewforum.php?f=35 Official Enigform Forum]&lt;br /&gt;
&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Back to Project page]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=20156</id>
		<title>SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests - Progress Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=20156"/>
				<updated>2007-07-24T17:48:54Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: /* Project Links */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Current Status ===&lt;br /&gt;
&lt;br /&gt;
As of 9th July, 2007, Enigform has been enhanced with remote site OpenPGP discovery, Public Key Import. Kyle Huff has joined the development team, and the Session Protocol has been proposed. Regarding Encryption, mod_openpgp supports encrypted http requests, but Enigform support for this is in research stage.Microsoft support will be last stage, once Enigform 1.0 and mod_openpgp 1.0 are released.&lt;br /&gt;
&lt;br /&gt;
== Project Links ==&lt;br /&gt;
[http://enigform.mozdev.org Enigform Development Site]&lt;br /&gt;
[https://addons.mozilla.org/en-US/firefox/addon/4531 Addons.Mozilla.Org - Stable Releases Installation Page]&lt;br /&gt;
[http://freshmeat.net/projects/enigform Enigform Freshmeat Page]&lt;br /&gt;
[http://foros.buanzo.com.ar/viewforum.php?f=35 Official Enigform Forum]&lt;br /&gt;
&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Back to Project page]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=20155</id>
		<title>SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests - Progress Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=20155"/>
				<updated>2007-07-24T17:48:00Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Current Status ===&lt;br /&gt;
&lt;br /&gt;
As of 9th July, 2007, Enigform has been enhanced with remote site OpenPGP discovery, Public Key Import. Kyle Huff has joined the development team, and the Session Protocol has been proposed. Regarding Encryption, mod_openpgp supports encrypted http requests, but Enigform support for this is in research stage.Microsoft support will be last stage, once Enigform 1.0 and mod_openpgp 1.0 are released.&lt;br /&gt;
&lt;br /&gt;
= Project Links =&lt;br /&gt;
[http://enigform.mozdev.org Enigform Development Site]&lt;br /&gt;
[https://addons.mozilla.org/en-US/firefox/addon/4531 Addons.Mozilla.Org - Stable Releases Installation Page]&lt;br /&gt;
[http://freshmeat.net/projects/enigform Enigform Freshmeat Page]&lt;br /&gt;
[http://foros.buanzo.com.ar/viewforum.php?f=35 Official Enigform Forum]&lt;br /&gt;
&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Back to Project page]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests&amp;diff=19689</id>
		<title>SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests&amp;diff=19689"/>
				<updated>2007-07-10T12:55:41Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''[http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Selection Back to SpoC 007 Selection page]'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AoC Candidate''': Arturo Busleiman (a.k.a Buanzo)&lt;br /&gt;
&lt;br /&gt;
'''Project coordinator''': Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
'''Project Progress''': 70% Complete, [[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests - Progress Page|Progress Page]]&lt;br /&gt;
&lt;br /&gt;
== Buanzo -Firefox Addon (Enigform) and Apache Module (mod_openpgp) to extend HTTP with OpenPGP capabilities ==&lt;br /&gt;
&lt;br /&gt;
=== Arturo &amp;quot;Buanzo&amp;quot; Busleiman ===&lt;br /&gt;
I am a 25 year old Independent security consultant from Buenos Aires, Argentina, that has contributed to the world of information systems security since 1994, when BBSes and Linux still lived together.&lt;br /&gt;
&lt;br /&gt;
A quick search for buanzo on google [http://www.google.com/search?hl=en&amp;amp;q=buanzo&amp;amp;btnG=Google+Search] will provide all necessary details about my professional and community background. For comprobable experience, you could also check my Rent a Coder profile.[http://www.rentacoder.com/RentACoder/SoftwareCoders/showBioInfo.asp?lngAuthorId=735204].&lt;br /&gt;
&lt;br /&gt;
In my free time I like playing with my Punk-Pop band [http://www.jamendo.com/es/artist/futurabanda/], Futurabanda. [http://www.futurabanda.com.ar], and maintaining my Restaurants, Wines and Recipes site. [http://www.vivamoslavida.com.ar]. I have to admit that my first priorities are my beloved son [http://www.fotolog.com/buanzo] and my wonderful wife [http://www.fotolog.com/buanzo].&lt;br /&gt;
&lt;br /&gt;
=== Accomplishments ===&lt;br /&gt;
&lt;br /&gt;
I've contributed scripts, fixes and translations to the Nmap project. I've also acted as Expert Contributor for SANS TOP-20 2004, 2005 and 2006. I've developed &lt;br /&gt;
tools that can be found in Freshmeat, like mprl (a getty enhancement to allow remote logins from the login: prompt of the console). I've also written&lt;br /&gt;
the Unix chapter of the OISSG's Information Systems Security Assessment Framework, v0.1 [http://www.oissg.org/content/view/71/71/]. I'm currently writing&lt;br /&gt;
an Internet Draft to be proposed for RFC named &amp;quot;OpenPGP Extensions to HTTP&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
=== Community ===&lt;br /&gt;
&lt;br /&gt;
I &amp;quot;run&amp;quot; the 2600 meetings site for Argentina [http://www.2600.com/meetings/pages.html], I've been proposed, but I refused, for President of the Argentinian Free Software group called SOLAR [www.solar.org.ar]. I'm an active member of the FLOSS community since 1996, having written articles in magazines http://www.net-security.org/dl/articles/Detecting_and_Understanding_rootkits.txt, made TV, radio and newspaper appearances [http://codigoabierto.bitacoras.com/archivos/2005/04/01/buanzo-hacks] and led different security research groups of Spain, Mexico and Argentina. Currently I contribute time thorugh my sites, forums and blogs, answering questions in mailing lists and helping coordinate some local LUGs. I do also manager the Linux Counter for Argentina [http://counter.li.org/reports/place.php?place=AR].&lt;br /&gt;
&lt;br /&gt;
=== My Project ===&lt;br /&gt;
&lt;br /&gt;
Enigform [http://enigform.mozdev.org] is a Firefox extension that enhances HTTP with OpenPGP functionality. It digitally signs and/or encrypts outgoing HTTP requests so that a web server can authenticate the identity and data of the incoming request. It is a Web Security tool because it can, if correctly implemented as any OpenPGP based technology, render man in the middle attacks useless. I think OpenPGP already speaks for itself regarding eMail. Imagine the same benefits for http and web applications. I think Enigform can fit into the OWASP Validation Project [http://www.owasp.org/index.php/Category:OWASP_Validation_Project].&lt;br /&gt;
&lt;br /&gt;
Enigform is the reference implementation of the Internet Draft I'm working on, in discussion with members of the IETF's OpenPGP Working Group.&lt;br /&gt;
&lt;br /&gt;
Some simple PHP code is enough to make a web application Enigform-aware [http://enigformtest.buanzo.com.ar]. The Smutty PHP MVC Framework already supports Enigform [http://smutty.pu-gh.com/demo/enigform], but the best approach is to use the Apache module I'm writing, called mod_auth_openpgp (which will be renamed to mod_openpgp as it evolves).&lt;br /&gt;
&lt;br /&gt;
=== Long Term ===&lt;br /&gt;
&lt;br /&gt;
Have the Draft be proposed as a Standards Track RFC document, have Enigform support directly in MS IIS, and port Enigform to other browsers&lt;br /&gt;
and/or programming languages, and also provide OpenPGP De/Encryption support.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Why should I be selected ===&lt;br /&gt;
&lt;br /&gt;
I have the experience, security awareness and means to make this project THE web security project of the decade. I am a respected member of the&lt;br /&gt;
international security community, and I firmly believe Enigform is my greatest idea so far.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''[http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Selection Back to SpoC 007 Selection page]'''&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=19688</id>
		<title>SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests - Progress Page</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_Enigform:_Firefox_Addon_for_OpenPGP_signing_of_HTTP_requests_-_Progress_Page&amp;diff=19688"/>
				<updated>2007-07-10T12:55:37Z</updated>
		
		<summary type="html">&lt;p&gt;Buanzo: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Current Status ===&lt;br /&gt;
&lt;br /&gt;
As of 9th July, 2007, Enigform has been enhanced with remote site OpenPGP discovery, Public Key Import. Kyle Huff has joined the development team, and the Session Protocol has been proposed. Regarding Encryption, mod_openpgp supports encrypted http requests, but Enigform support for this is in research stage.Microsoft support will be last stage, once Enigform 1.0 and mod_openpgp 1.0 are released.&lt;br /&gt;
&lt;br /&gt;
[[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Back to Project page]]&lt;/div&gt;</summary>
		<author><name>Buanzo</name></author>	</entry>

	</feed>