<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bunyamin</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Bunyamin"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Bunyamin"/>
		<updated>2026-04-19T13:17:22Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=225049</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=225049"/>
				<updated>2017-01-13T21:08:44Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Application Security Day, Eskişehir 2015, Conference */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:tatli~owasp.org  Dr. Emin Islam Tatli], [mailto:onurkarasalihoglu~gmail.com Onur Karasalihoglu], [mailto:adilhafa~gmail.com Adil Hafa], [mailto:suleymanpetek~yahoo.com Suleyman Petek], [mailto:fatihersinadim~gmail.com Fatih Ersinadim]&lt;br /&gt;
&lt;br /&gt;
Web Page: http://www.webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
Twitter: https://twitter.com/owasptr&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Meeting, İstanbul, 27th Dec 2016 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/haberler/bulusma-27-aralik-2016.html Chapter Meeting, İstanbul 2016]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2016, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/haberler/uygulama-guvenligi-gunu-2016.html Application Security Day, İstanbul 2016]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, Eskişehir 2015, Conference ==&lt;br /&gt;
&lt;br /&gt;
Slides to download: [http://www.appsectr.org/?page_id=53 Application Security Day, Eskişehir 2015]&lt;br /&gt;
&lt;br /&gt;
== Chapter Meeting, İstanbul, 26th May 2014 ==&lt;br /&gt;
&lt;br /&gt;
== Attendance at Cyber Security Conference, İstanbul, 13 May 2014 ==&lt;br /&gt;
[http://www.siberguvenlikkonferansi.org/p/sponsorlar.html Cyber Security Conference 2014]&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2013, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/2013/ Application Security Day, İstanbul 2013]&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=222308</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=222308"/>
				<updated>2016-10-10T20:31:13Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:tatli~owasp.org  Dr. Emin Islam Tatli], [mailto:onurkarasalihoglu~gmail.com Onur Karasalihoglu], [mailto:adilhafa~gmail.com Adil Hafa], [mailto:suleymanpetek~yahoo.com Suleyman Petek], [mailto:fatihersinadim~gmail.com Fatih Ersinadim]&lt;br /&gt;
&lt;br /&gt;
Web Page: http://www.webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
Twitter: https://twitter.com/owasptr&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, Eskişehir 2015, Conference ==&lt;br /&gt;
&lt;br /&gt;
Slides to download: [http://www.appsectr.org/?page_id=53 Application Security Day, Eskişehir 2015]&lt;br /&gt;
&lt;br /&gt;
== Chapter Meeting, İstanbul, 26th May 2014 ==&lt;br /&gt;
&lt;br /&gt;
== Attendance at Cyber Security Conference, İstanbul, 13 May 2014 ==&lt;br /&gt;
[http://www.siberguvenlikkonferansi.org/p/sponsorlar.html Cyber Security Conference 2014]&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2013, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/2013/ Application Security Day, İstanbul 2013]&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=187491</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=187491"/>
				<updated>2015-01-02T22:18:19Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* About OWASP/TR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=132541</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=132541"/>
				<updated>2012-07-03T10:29:49Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* About OWASP/TR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat], [mailto:denizcev@gmail.com Deniz Cevik]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=129352</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=129352"/>
				<updated>2012-05-07T12:59:18Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* About OWASP/TR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Published &lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=122646</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=122646"/>
				<updated>2012-01-11T01:12:53Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Projects/Tools/Translations */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Committee Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Published &lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=122645</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=122645"/>
				<updated>2012-01-11T01:12:40Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Committee Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Published &lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
=== Projects/Tools/Translations ===&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=122644</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=122644"/>
				<updated>2012-01-11T01:11:57Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Committee Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Published &lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=122643</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=122643"/>
				<updated>2012-01-11T01:11:44Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Committee Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
Published &lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=122642</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=122642"/>
				<updated>2012-01-11T01:10:43Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Chapter Brochure */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Committee Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Sec Check List 2012] Published Web App Security Check List 2012 in Turkish.&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=121685</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=121685"/>
				<updated>2011-12-20T08:46:54Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* About OWASP/TR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Committee Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=121666</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=121666"/>
				<updated>2011-12-19T22:37:37Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-founder is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Committee Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=121665</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=121665"/>
				<updated>2011-12-19T22:06:35Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Local News/Brochure */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-founder is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Committee Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=121664</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=121664"/>
				<updated>2011-12-19T22:06:16Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Local News */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-founder is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Committee Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=121663</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=121663"/>
				<updated>2011-12-19T22:05:59Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* About OWASP/TR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-founder is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Committee Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] is out!&lt;br /&gt;
* [http://www.webguvenligi.org/docs/Javada_Guvenli_Yazilim_Gelistirme_OWASPTR.pdf Secure Coding Principles in Java] by [http://www.architectingsecurity.com Dr. Emin Islam Tatlı] is out!&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf WebAppSec Checklist] Web Uygulama Güvenliği Kontrol Listesi 2010 by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=121662</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=121662"/>
				<updated>2011-12-19T22:05:41Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* About OWASP/TR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-founder is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Committee Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:eitatli@gmail.com Emin Islam Tatli]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] is out!&lt;br /&gt;
* [http://www.webguvenligi.org/docs/Javada_Guvenli_Yazilim_Gelistirme_OWASPTR.pdf Secure Coding Principles in Java] by [http://www.architectingsecurity.com Dr. Emin Islam Tatlı] is out!&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf WebAppSec Checklist] Web Uygulama Güvenliği Kontrol Listesi 2010 by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
[[Category:Middle East]]&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=92114</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=92114"/>
				<updated>2010-10-29T11:29:03Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir],  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur],[mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun], [mailto:canberk.bolat~gmail.com Canberk Bolat]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine]. 6th edition of OWASP-TR's Turkish web security e-magazine is out. Hey, it's one year old now.&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf WebAppSec Checklist] Web Uygulama Güvenliği Kontrol Listesi 2010 by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid one and a half year].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=88783</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=88783"/>
				<updated>2010-09-07T08:52:37Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir],  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur],[mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine]. 6th edition of OWASP-TR's Turkish web security e-magazine is out. Hey, it's one year old now.&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf WebAppSec Checklist] Web Uygulama Güvenliği Kontrol Listesi 2010 by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid one and a half year].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=88160</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=88160"/>
				<updated>2010-08-30T00:04:10Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* About OWASP/TR */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The members are [mailto:bunyamindemir~gmail.com Bunyamin Demir],  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur],[mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Don't miss out the [http://www.owasp.org/index.php/Turkey#tab=Local_News.2FBrochure Local News]!!!&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Local News/Brochure ====&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org E-Magazine]. 5th edition of OWASP-TR's Turkish web security e-magazine is out.&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] compilation of a study on analyzing the possible behavior of a malicious Java web developer&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [somewhat obsolete for a solid one and a half year].&lt;br /&gt;
&lt;br /&gt;
==== Projects/Tools/Translations ====&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=32752</id>
		<title>OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=32752"/>
				<updated>2008-06-29T15:23:56Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page contains Projects, Authors, Status Target and Reviewers of the sponsored programme [[OWASP Summer of Code 2008]].&lt;br /&gt;
== DOCUMENTATION PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Verification Standard Project|OWASP Application Security Verification Standard]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mike Boberski &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jeff.williams(at)owasp.org Jeff Williams]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend(at)insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AppSensor Project|OWASP AppSensor - Detect and Respond to Attacks from Within the Application]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:michael.coates(at)aspectsecurity.com Michael Coates]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eric.sheridan(at)aspectsecurity.com Eric Sheridan]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:thrynn404(at)gmail.com Randy Janinda]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Backend Security Project|OWASP Backend Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Carlo Pelliccioni&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Classic ASP Security Project|OWASP Classic ASP Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rodrigo@rmarcos.com Rodrigo Marcos]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Review Project|OWASP Code review guide, V1.1]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eoin Keary&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:psatishkumar(at)gmail.com P.Satish Kumar]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Corporate Application Security Rating Guide|OWASP Corporate Application Security Rating Guide]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Parvathy Iyer&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Neal Kirschner&amp;lt;br&amp;gt;Email address?&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:Omar.Sherin(at)infosec2.com Omar Sherin]&amp;lt;br&amp;gt;TBC &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Education Project|OWASP Education Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Martin Knobloch&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:sebastien.gioria@owasp.fr Sebastien Gioria]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn(at)bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Internationalization|OWASP Internationalization Guidelines Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP .NET Project#OWASP .NET Project Leader|OWASP .NET Project Leader]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mark Roxberry &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary(at)gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dennis.hurst(at)hp.com Dennis Hurst]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Positive Security Project|OWASP Positive Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eduardo Vianna de Camargo Neves &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:welias(at)conviso.com.br Wagner Elias]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Ruby on Rails Security Guide V2|OWASP Ruby on Rails Security Guide v2]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Heiko Webers &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:steve.jones(at)unf.edu Steve Jones]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jeff.cabaniss(at)gmail.com Jeff Cabaniss]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Securing WebGoat using ModSecurity Project|OWASP Securing WebGoat using ModSecurity]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Stephen Evans &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ivan.ristic(at)breach.com Ivan Ristic] &amp;amp; Breach Group&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:christian.folini(at)netnea.com Christian Folini]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot;|'''[[:Category:OWASP Source Code Review OWASP Projects Project|OWASP Source Code Review OWASP Projects]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | James Walden&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:marco.m.morana(at)gmail.com Marco M. Morana]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Spanish|OWASP Spanish Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Testing Project|OWASP Testing Guide v3]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matteo Meucci &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;400&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;120&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''3rd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''4th&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP ASDR Project|OWASP Application Security Desk Reference (ASDR)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Leonardo Cavallari Militelli &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:williamtsmith(at)gmail.com William Smith]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#William Smith | Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Kenneth R. van Wyk| Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kcfredman(at)gmail.com Frederick Donovan]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Frederick Donovan | Bio]]&amp;lt;br&amp;gt;  (Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== TOOLS PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:GTK plus GUI for w3af Project|GTK+ GUI for w3af project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Facundo Batista&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:andres.riancho(at)gmail.com Andres Riancho]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/ariancho Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah(at)securenet(dot)de Achim Hoffmann]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Achim Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Access Control Rules Tester Project|OWASP Access Control Rules Tester]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Andrew Petukhov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:caughron(at)gmail.com Mat Caughron]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/A84/998 Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mg_chen(at)yahoo.com Min Chen]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/mgchen Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AntiSamy Project .NET| OWASP AntiSamy .NET]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arshan Dabirsiaghi&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dallasspohn(at)sbcglobal.net Dallas Spohn]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project|OWASP Application Security Tool Benchmarking Environment and Site Generator refresh]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dmitry Kozlov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:medelibero(at)gmail.com Mike de Libero]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Crawler|OWASP Code Crawler ]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Alessio Marziali &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Interceptor Project|OWASP Interceptor Project - 2008 Update]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Justin Derry&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dallasspohn(at)sbcglobal.net Dallas Spohn]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP JSP Testing Tool Project|OWASP UI Component Verification Project (a.k.a. OWASP JSP Testing Tool)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jason Li&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:markkerzner(at)gmail.com Mark Kerzner]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabricio.fujikawa(at)infoglobo.com.br Fabrício Fujikawa]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Live CD 2008 Project|OWASP Live CD 2008 Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matt Tesauro&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:admin@wirefall.com Dustin Dykes]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/607/6b1 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jkpoots(at)rogers.com Kent Poots] &amp;lt;br&amp;gt; [http://www.linkedin.com/pub/5/25B/114 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenSign Server Project|OWASP Online code signing and integrity verification service for open source community (OpenSign Server)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Phil Potisk and Richard Conway&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend@insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:a_campani@yahoo.fr Antonio Campanile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp|OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arturo 'Buanzo' Busleiman&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | (need one)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Orizon Project|OWASP Orizon Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Paolo Perego&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:seba@deleersnyder.eu Sebastien Deleersnyder]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz@owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Python Static Analysis Project|OWASP Python Static Analysis]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Georgy Klimov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn@bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:diepvien00thayh@gmail.com P.Q.Huy]&amp;lt;br&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Skavenger Project|OWASP Skavenger]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mro(at)securenet.de Matthias Rohr]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Rogan Dawes&amp;lt;br&amp;gt;Email address?&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah(at)securenet(dot)de Achim Hoffmann]&amp;lt;br&amp;gt;[https://www.owasp.org/index.php/User:Achim Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Sqlibench Project|OWASP SQL Injector Benchmarking Project (SQLiBENCH)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:urgunb@hotmail.com Bedirhan Urgun]&amp;lt;br&amp;gt;[mailto:mesut@h-labs.org Mesut Timur]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ferruh@mavituna.com Ferruh Mavituna]&amp;lt;br/&amp;gt; [[Project Information:Sqlibench:Ferruh|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kfuller@dmv.ca.gov Kevin Fuller] &amp;lt;br/&amp;gt;[[Project Information:Sqlibench:Kevin|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Teachable Static Analysis Workbench Project|OWASP Teachable Static Analysis Workbench]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ddk(at)cs.msu.su Dmitry Kozlov]&amp;lt;br&amp;gt;Igor Konnov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alex Fry]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP WeBekci Project|OWASP WeBekci Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:bunyamin@owasp.org Bunyamin Demir]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:stefano.dipaola(at)wisec.i Stefano Di Paola]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== DESIGN/CORPORATE PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Book Cover &amp;amp; Sleeve Design|OWASP Book Cover &amp;amp; Sleeve Design]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Individual and Corporate Member Packs plus Conference Attendee Packs Brief|OWASP Individual &amp;amp; Corporate Member Packs, Conference Attendee Packs Brief]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Information:Webekci&amp;diff=32746</id>
		<title>Project Information:Webekci</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Information:Webekci&amp;diff=32746"/>
				<updated>2008-06-29T15:16:04Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;7&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT IDENTIFICATION''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Project Name'''&lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|&amp;lt;font color=&amp;quot;black&amp;quot;&amp;gt;'''WeBekci''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;| '''Short Project Description''' &lt;br /&gt;
 | colspan=&amp;quot;6&amp;quot; style=&amp;quot;width:85%; background:#cccccc&amp;quot; align=&amp;quot;left&amp;quot;|WeBekci tries to provide an admin panel that ModSecurity, which is an open source web application firewall that runs as an Apache module, lacks. &amp;lt;br&amp;gt; Web application firewalls (WAF) are gaining importance among the information security technologies designed to protect web sites from attack. WAF solutions prevent attacks that network firewalls and intrusion detection systems can't and they require no modification of application source code. ModSecurity is an embeddable web application firewall and it provides protection from a range of attacks against web applications. It is an open source project available to everyone; it however does not come with an admin panel. &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Email Contacts'''&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Leader&amp;lt;br&amp;gt;[mailto:bunyamin(at)owasp.org '''Bünyamin Demir''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Project Contributors&amp;lt;br&amp;gt;[mailto:urgunb(at)hotmail.com '''Bedirhan Urgun''']&amp;lt;br&amp;gt;[mailto:christophe(at)vandeplas.com '''Christophe Vandeplas''']&amp;lt;br&amp;gt;[mailto:serrano.neves(at)gmail.com '''Eduardo Jorge'''] &lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[mailto:Owasp-webekci@lists.owasp.org '''Project Mailing List''']&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|First Reviewer&amp;lt;br&amp;gt;[mailto:afry(at)strongcrypto.biz '''Alex Fry''']&amp;lt;br&amp;gt;(TBC)&lt;br /&gt;
 | style=&amp;quot;width:14%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|Second Reviewer&amp;lt;br&amp;gt;[mailto:stefano.dipaola(at)@wisec.it '''Stefano Di Paola''']&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|OWASP Board Member&amp;lt;br&amp;gt;(if applicable)&amp;lt;br&amp;gt;[mailto:name(at)name '''Name&amp;amp;Email''']&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''PROJECT MAIN LINKS''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:100%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|&lt;br /&gt;
* WeBekci is a web based ModSecurity 2.x management tool and written in PHP with it's backend powered by MySQL. It can be found at [http://code.google.com/p/webekci/ WeBekci.]&lt;br /&gt;
* (If appropriate, links to be added)&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;6&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|&amp;lt;font color=&amp;quot;white&amp;quot;&amp;gt;'''SPONSORS &amp;amp; GUIDELINES''' &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008|Sponsor - '''OWASP Summer of Code 2008''']] &lt;br /&gt;
 | style=&amp;quot;width:50%; background:#cccccc&amp;quot; align=&amp;quot;center&amp;quot;|[[OWASP Summer of Code 2008 Applications - Need Futher Clarifications#OWASP-WeBekci_Project|'''Sponsored Project/Guidelines/Roadmap''']]&lt;br /&gt;
 |}&lt;br /&gt;
{| style=&amp;quot;width:100%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;5&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot;|ASSESSMENT AND REVIEW PROCESS&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#6C82B5&amp;quot; align=&amp;quot;center&amp;quot;|'''Review/Reviewer''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Author's Self Evaluation'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further) &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''First Reviewer'''&amp;lt;br&amp;gt;(applicable for Alpha Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''Second Reviewer'''&amp;lt;br&amp;gt;(applicable for Beta Quality &amp;amp; further)&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#b3b3b3&amp;quot; align=&amp;quot;center&amp;quot;|'''OWASP Board Member'''&amp;lt;br&amp;gt;(applicable just for Release Quality) &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''50% Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:Webekci - 50 Review - Self Evaluation - A|See&amp;amp;Edit: 50% Review/Self-Evaluation (A)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:Webekci - 50 Review - First Reviewer - C|See&amp;amp;Edit: 50% Review/1st Reviewer (C)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:Webekci 50 Review Second Review E|See&amp;amp;Edit: 50%Review/2nd Reviewer (E)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|X &lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:15%; background:#7B8ABD&amp;quot; align=&amp;quot;center&amp;quot;|'''Final Review''' &lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;What status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:Webekci - Final Review - Self Evaluation - B|See&amp;amp;Edit: Final Review/SelfEvaluation (B)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;What status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:Webekci - Final Review - First Reviewer - D|See&amp;amp;Edit: Final Review/1st Reviewer (D)]]&lt;br /&gt;
 | style=&amp;quot;width:21%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No''' (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;What status has been reached?&amp;lt;br&amp;gt;'''Season of Code''' - (To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:Webekci - Final Review - Second Reviewer - F|See&amp;amp;Edit: Final Review/2nd Reviewer (F)]]&lt;br /&gt;
 | style=&amp;quot;width:22%; background:#C2C2C2&amp;quot; align=&amp;quot;center&amp;quot;|Objectives &amp;amp; Deliveries reached?&amp;lt;br&amp;gt;'''Yes/No'''(To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;Which status has been reached?&amp;lt;br&amp;gt;'''Season of Code'''(To update)&amp;lt;br&amp;gt;---------&amp;lt;br&amp;gt;[[Project Information:Webekci - Final Review - OWASP Board Member - G|See/Edit: Final Review/Board Member&amp;lt;br&amp;gt; (G)]]&lt;br /&gt;
 |-&lt;br /&gt;
 |}&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=32380</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=32380"/>
				<updated>2008-06-25T12:07:48Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Turkey|extra=The current chapter leader is [mailto:urgunb@hotmail.com Bedirhan Urgun] and members are [mailto:bunyamindemir@gmail.com Bunyamin Demir], [mailto:ferruh@mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:ceriyusuf~gmail.com Yusuf Çeri].&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com iletişime] geçiniz.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=32371</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=32371"/>
				<updated>2008-06-25T11:09:39Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:urgunb@hotmail.com Bedirhan Urgun]&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Members ==&lt;br /&gt;
[mailto:bunyamindemir@gmail.com Bunyamin Demir], [mailto:ferruh@mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:ceriyusuf~gmail.com Yusuf Çeri], &lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com iletişime] geçiniz.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=32190</id>
		<title>OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Projects_Authors_Status_Target_and_Reviewers&amp;diff=32190"/>
				<updated>2008-06-23T17:20:37Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This page contains Projects, Authors, Status Target and Reviewers of the sponsored programme [[OWASP Summer of Code 2008]].&lt;br /&gt;
== DOCUMENTATION PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Verification Standard Project|OWASP Application Security Verification Standard]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mike Boberski &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jeff.williams(at)owasp.org Jeff Williams]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend(at)insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AppSensor Project|OWASP AppSensor - Detect and Respond to Attacks from Within the Application]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:michael.coates(at)aspectsecurity.com Michael Coates]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eric.sheridan(at)aspectsecurity.com Eric Sheridan]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:thrynn404(at)gmail.com Randy Janinda]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Backend Security Project|OWASP Backend Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Carlo Pelliccioni&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Classic ASP Security Project|OWASP Classic ASP Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:rodrigo@rmarcos.com Rodrigo Marcos]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Review Project|OWASP Code review guide, V1.1]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eoin Keary&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn(at)bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:psatishkumar(at)gmail.com P.Satish Kumar]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Corporate Application Security Rating Guide|OWASP Corporate Application Security Rating Guide]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Parvathy Iyer&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Neal Kirschner&amp;lt;br&amp;gt;Email address?&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:Omar.Sherin(at)infosec2.com Omar Sherin]&amp;lt;br&amp;gt;TBC &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Education Project|OWASP Education Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Martin Knobloch&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:sebastien.gioria@owasp.fr Sebastien Gioria]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn(at)bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Internationalization|OWASP Internationalization Guidelines Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP .NET Project#OWASP .NET Project Leader|OWASP .NET Project Leader]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Mark Roxberry &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary(at)gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dennis.hurst(at)hp.com Dennis Hurst]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Positive Security Project|OWASP Positive Security Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Eduardo Vianna de Camargo Neves &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:welias(at)conviso.com.br Wagner Elias]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Ruby on Rails Security Guide V2|OWASP Ruby on Rails Security Guide v2]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Heiko Webers &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:steve.jones(at)unf.edu Steve Jones]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jeff.cabaniss(at)gmail.com Jeff Cabaniss]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Securing WebGoat using ModSecurity Project|OWASP Securing WebGoat using ModSecurity]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Stephen Evans &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ivan.ristic(at)breach.com Ivan Ristic] &amp;amp; Breach Group&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:christian.folini(at)netnea.com Christian Folini]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot;|'''[[:Category:OWASP Source Code Review OWASP Projects Project|OWASP Source Code Review OWASP Projects]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | James Walden&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:marco.m.morana(at)gmail.com Marco M. Morana]&amp;lt;br&amp;gt;(TBC)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:OWASP Spanish|OWASP Spanish Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Juan Carlos Calderon &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabio.e.cerullo(at)aib.ie Fabio Cerullo]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kisero(at)gmail.com Esteban Ribičić]&amp;lt;br&amp;gt;[http://docs.google.com/Doc?id=df9vbj96_120fzfj4kfk Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Testing Project|OWASP Testing Guide v3]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matteo Meucci &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;400&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;120&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''3rd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''4th&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP ASDR Project|OWASP Application Security Desk Reference (ASDR)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Leonardo Cavallari Militelli &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:williamtsmith(at)gmail.com William Smith]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#William Smith | Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ken(at)krvw.com Kenneth Wyk]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Kenneth R. van Wyk| Bio]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kcfredman(at)gmail.com Frederick Donovan]&amp;lt;br&amp;gt;[[OWASP SoC 2008 ASDR Reviewers#Frederick Donovan | Bio]]&amp;lt;br&amp;gt;  (Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== TOOLS PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:GTK plus GUI for w3af Project|GTK+ GUI for w3af project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Facundo Batista&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:andres.riancho(at)gmail.com Andres Riancho]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah@securenet.de Achim Hoffmann]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Access Control Rules Tester Project|OWASP Access Control Rules Tester]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Andrew Petukhov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:caughron(at)gmail.com Mat Caughron]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/A84/998 Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mg_chen(at)yahoo.com Min Chen]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/mgchen Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP AntiSamy Project .NET| OWASP AntiSamy .NET]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arshan Dabirsiaghi&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dallasspohn(at)sbcglobal.net Dallas Spohn]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jeff Williams&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Application Security Tool Benchmarking Environment and Site Generator Refresh Project|OWASP Application Security Tool Benchmarking Environment and Site Generator refresh]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dmitry Kozlov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:medelibero(at)gmail.com Mike de Libero]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Code Crawler|OWASP Code Crawler ]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Alessio Marziali &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Interceptor Project|OWASP Interceptor Project - 2008 Update]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Justin Derry&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dallasspohn(at)sbcglobal.net Dallas Spohn]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP JSP Testing Tool Project|OWASP UI Component Verification Project (a.k.a. OWASP JSP Testing Tool)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Jason Li&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:markkerzner(at)gmail.com Mark Kerzner]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:fabricio.fujikawa(at)infoglobo.com.br Fabrício Fujikawa]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Live CD 2008 Project|OWASP Live CD 2008 Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Matt Tesauro&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:admin@wirefall.com Dustin Dykes]&amp;lt;br&amp;gt;[http://www.linkedin.com/pub/1/607/6b1 Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:jkpoots(at)rogers.com Kent Poots]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; |&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenSign Server Project|OWASP Online code signing and integrity verification service for open source community (OpenSign Server)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Phil Potisk and Richard Conway&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:pierre.parrend@insa-lyon.fr Pierre Parrend]&amp;lt;br&amp;gt;[http://www.rzo.free.fr Curriculum]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:a_campani@yahoo.fr Antonio Campanile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP OpenPGP Extensions for HTTP - Enigform and mod openpgp|OWASP OpenPGP Extensions for HTTP - Enigform and mod_openpgp]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Arturo 'Buanzo' Busleiman&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mark.roxberry(at)owasp.org Mark Roxberry]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz(at)owasp.org Dinis Cruz]&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Orizon Project|OWASP Orizon Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Paolo Perego&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:seba@deleersnyder.eu Sebastien Deleersnyder]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:dinis.cruz@owasp.org Dinis Cruz]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Python Static Analysis Project|OWASP Python Static Analysis]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Georgy Klimov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:namn@bluemoon.com.vn Nam Nguyen]&amp;lt;br&amp;gt;[[OWASP Summer of Code 2008 Projects Authors Status Target and Reviewers Nguyen Curriculum|Curriculum]]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:diepvien00thayh@gmail.com P.Q.Huy]&amp;lt;br&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Skavenger Project|OWASP Skavenger]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:mro(at)securenet.de Matthias Rohr]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Rogan Dawes&amp;lt;br&amp;gt;Email address?&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ah@securenet.de Achim Hoffmann]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Sqlibench Project|OWASP SQL Injector Benchmarking Project (SQLiBENCH)]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:urgunb@hotmail.com Bedirhan Urgun]&amp;lt;br&amp;gt;[mailto:mesut@h-labs.org Mesut Timur]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ferruh@mavituna.com Ferruh Mavituna]&amp;lt;br/&amp;gt; [[Project Information:Sqlibench:Ferruh|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kfuller@dmv.ca.gov Kevin Fuller] &amp;lt;br/&amp;gt;[[Project Information:Sqlibench:Kevin|background info]]&amp;lt;br/&amp;gt;(Confirmed) &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Teachable Static Analysis Workbench Project|OWASP Teachable Static Analysis Workbench]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:ddk(at)cs.msu.su Dmitry Kozlov]&amp;lt;br&amp;gt;Igor Konnov&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alex Fry]&amp;lt;br&amp;gt;TBC&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Not applicable&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP WeBekci Project|OWASP WeBekci Project]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:bunyamin@owasp.org Bunyamin Demir]&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Beta&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:afry(at)strongcrypto.biz Alexander Fry]&amp;lt;br&amp;gt;[http://www.linkedin.com/in/alexanderfry Profile]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== DESIGN/CORPORATE PROJECTS ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; style=&amp;quot;text-align:center&amp;quot;&lt;br /&gt;
! width=&amp;quot;600&amp;quot; height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | Application&lt;br /&gt;
! width=&amp;quot;220&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''Author'''&lt;br /&gt;
! width=&amp;quot;60&amp;quot; align=&amp;quot;CENTER&amp;quot; | [[:Category:OWASP Project Assessment|'''Status Target''']]&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''1st&amp;lt;br&amp;gt;Reviewer'''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''2nd&amp;lt;br&amp;gt;Reviewer '''&lt;br /&gt;
! width=&amp;quot;108&amp;quot; align=&amp;quot;CENTER&amp;quot; | '''OWASP&amp;lt;br&amp;gt;Board&amp;lt;br&amp;gt;Reviewer&lt;br /&gt;
'''&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Book Cover &amp;amp; Sleeve Design|OWASP Book Cover &amp;amp; Sleeve Design]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:kris_seeburn@utm.intnet.mu Kris Seeburn]&amp;lt;br&amp;gt;(TBC)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;br /&gt;
| height=&amp;quot;18&amp;quot; bgcolor=&amp;quot;#FFFFFF&amp;quot; align=&amp;quot;CENTER&amp;quot; valign=&amp;quot;MIDDLE&amp;quot; | '''[[:Category:OWASP Individual and Corporate Member Packs plus Conference Attendee Packs Brief|OWASP Individual &amp;amp; Corporate Member Packs, Conference Attendee Packs Brief]]'''&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | LXstudios,&amp;lt;br&amp;gt;[mailto:deb@lxstudios.com Deb Brewer] &lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Quality&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:eoinkeary@gmail.com Eoin Keary]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | [mailto:yiannis@owasp.org Yiannis Pavlosoglou]&amp;lt;br&amp;gt;(Confirmed)&lt;br /&gt;
| align=&amp;quot;CENTER&amp;quot; | Dinis Cruz&lt;br /&gt;
|-&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=32035</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=32035"/>
				<updated>2008-06-19T18:16:33Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:urgunb@hotmail.com Bedirhan Urgun], [mailto:bunyamindemir@gmail.com Bunyamin Demir], [mailto:ferruh@mavituna.com Ferruh Mavituna]&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com iletişime] geçiniz.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=32034</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=32034"/>
				<updated>2008-06-19T18:16:11Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:urgunb@hotmail.com Bedirhan Urgun], [mailto:bunyamindemir@gmail.com Bunyamin Demirs], [mailto:ferruh@mavituna.com Ferruh Mavituna]&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com iletişime] geçiniz.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_WeBekci_Project&amp;diff=26968</id>
		<title>Category:OWASP WeBekci Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_WeBekci_Project&amp;diff=26968"/>
				<updated>2008-03-23T14:24:53Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== What is WeBekci? ==&lt;br /&gt;
WeBekci is a web based ModSecurity 2.x management tool. WeBekci is written in PHP,  Its backend is powered by MySQL and the frontend by XAJAX framework. It is an OWASP Project.&lt;br /&gt;
&lt;br /&gt;
== What is ModSecurity for Apache? ==&lt;br /&gt;
With over 70% of all attacks now carried out over the web application level, organisations need every help they can get in making their systems secure. Web application firewalls are deployed to establish an external security layer that increases security, detects, and prevents attacks before they reach web applications&lt;br /&gt;
[http://www.modsecurity.org (ModSecurity).]&lt;br /&gt;
&lt;br /&gt;
== Goals ==&lt;br /&gt;
It will remove management overhead of ModSecurity 2.x. You can configure modsecurity.conf, add special rules and watch system, apache and modsecurity logs (only guardianlog has been implemented in this version).&lt;br /&gt;
&lt;br /&gt;
== Features ==&lt;br /&gt;
It covers 90 percent of the ModSecurity 2.x configuration features. Manual- and GUI-based rule managements are supported. It permits to add single-argument rules and it covers 70 percent of the action parameters. It can be used in monitoring system, apache and ModSecurity guardian logs. As of this version the monitoring utility is rather basic and it gives some information about the system.&lt;br /&gt;
&lt;br /&gt;
== Future Development ==&lt;br /&gt;
* '''Configuration'''        : Most of the configuration parameters will be managed through the web interface&lt;br /&gt;
* '''Rule Generator'''       : Basic rules will be generated using the web interface&lt;br /&gt;
* '''Core Rule Integration''': Core rules will be added to the database for use&lt;br /&gt;
* '''Logging and Reporting''': Apache error log and modsec_audit log will be parsed and presented to the user thru the web interface&lt;br /&gt;
* '''DB Support'''           : MySQL&lt;br /&gt;
&lt;br /&gt;
[[Image:webekci.gif|thumb|350px|right]]&lt;br /&gt;
&lt;br /&gt;
== Requirement == &lt;br /&gt;
&lt;br /&gt;
* Platform Linux/Unix,&lt;br /&gt;
* Apache + ModSecurty 2.x &lt;br /&gt;
* Php&lt;br /&gt;
* Mysql&lt;br /&gt;
&lt;br /&gt;
== News ==&lt;br /&gt;
 '''OWASP WeBekci Project Release! - 31 March 2007 '''&lt;br /&gt;
&lt;br /&gt;
== Installation== &lt;br /&gt;
&lt;br /&gt;
Download adress: http://sourceforge.net/projects/webekci/&lt;br /&gt;
&lt;br /&gt;
  # tar –zxvf webekci-1.0.tar.gz&lt;br /&gt;
  # mv webekci /usr/local/www/&lt;br /&gt;
  # cd /usr/local/www/webekci&lt;br /&gt;
&lt;br /&gt;
Primarily, create .htaccess and .htpasswd files. These are required for WeBekci`s own.  &lt;br /&gt;
Edit .htaccess file:&lt;br /&gt;
&lt;br /&gt;
  # vi .htaccess &lt;br /&gt;
&lt;br /&gt;
In the .htaccess file, enter the correct path for the .htpasswd file in the AuthUserFile line in accordance with your own configuration:&lt;br /&gt;
&lt;br /&gt;
  AuthUserFile /usr/home/bunyamin/.htpasswd&lt;br /&gt;
  AuthType Basic&lt;br /&gt;
  AuthName &amp;quot;Owasp-WeBekci Screet Area&amp;quot;&lt;br /&gt;
  &amp;lt;LIMIT GET POST&amp;gt;&lt;br /&gt;
  require valid-user&lt;br /&gt;
  &amp;lt;/LIMIT&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Now edit .htpasswd file:&lt;br /&gt;
&lt;br /&gt;
  # vi .htpasswd&lt;br /&gt;
&lt;br /&gt;
If the user name is going to be “webekci” and password “1234”, then enter:&lt;br /&gt;
&lt;br /&gt;
  webekci:cwc9eWGIM9r5M&lt;br /&gt;
&lt;br /&gt;
You may enter your own UID and password.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Now, you need define “directory” in the httpd.conf file.&lt;br /&gt;
&lt;br /&gt;
  Alias /webekci/ &amp;quot;/usr/local/www/webekci/&amp;quot;&lt;br /&gt;
  &amp;lt;Directory &amp;quot;/usr/local/www/webekci/&amp;quot;&amp;gt;&lt;br /&gt;
     Options None&lt;br /&gt;
     AllowOverride All&lt;br /&gt;
     Order Allow,Deny&lt;br /&gt;
     Allow from all&lt;br /&gt;
  &amp;lt;/Directory&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Note: If you are using mod_rewrite, then enter  “AllowOverride All” so that .htaccess file can be read. Otherwise enter “AllowOverride None”.&lt;br /&gt;
&lt;br /&gt;
  # apachectl restart&lt;br /&gt;
&lt;br /&gt;
Make necessary modifications in config.php file. Add the following line:&lt;br /&gt;
&lt;br /&gt;
$config['modsecurity_conf']='/usr/local/etc/apache22/extra/mod_security.conf';&lt;br /&gt;
&lt;br /&gt;
It’s important to create the mod_security.conf file and include its path to the httpd.conf. Let’s add the following line into your httpd.conf. Change the path according to your distribution if necessary.&lt;br /&gt;
&lt;br /&gt;
  Include etc/apache22/extra/mod_security.conf&lt;br /&gt;
&lt;br /&gt;
To give the www user read and write permissions:&lt;br /&gt;
&lt;br /&gt;
  # chown www /usr/local/etc/apache22/extra/mod_security.conf&lt;br /&gt;
&lt;br /&gt;
Note: www user is the user where apache runs. Please check the the following entries in httpd.conf: &lt;br /&gt;
&lt;br /&gt;
User www&lt;br /&gt;
&lt;br /&gt;
Group www&lt;br /&gt;
&lt;br /&gt;
Some distributions may have different user and/or group names.&lt;br /&gt;
&lt;br /&gt;
After configuring WeBekci you need to restart apache. Do this with these sudo  configurations:&lt;br /&gt;
$config['apache_config_test'] = '/usr/local/bin/sudo /usr/local/sbin/httpd -t';&lt;br /&gt;
&lt;br /&gt;
$config['apache_restart']='/usr/local/bin/sudo /usr/local/sbin/httpd -k restart';&lt;br /&gt;
&lt;br /&gt;
Also alter your config.php according to your distro. Edit sudoers file:&lt;br /&gt;
&lt;br /&gt;
  # vi /usr/local/etc/sudoers&lt;br /&gt;
&lt;br /&gt;
Enter these lines:&lt;br /&gt;
&lt;br /&gt;
  www ALL=NOPASSWD:/usr/local/sbin/httpd -k restart&lt;br /&gt;
  www ALL=NOPASSWD:/usr/local/sbin/httpd -t&lt;br /&gt;
&lt;br /&gt;
Now www user can do “config test” and “restart” operations restart apache without having to enter password.&lt;br /&gt;
&lt;br /&gt;
Please make sure you entered MySQL related changes in your config.php file; and browse your site and run the install.php file:&lt;br /&gt;
&lt;br /&gt;
http://www.site.com/webekci/install.php&lt;br /&gt;
&lt;br /&gt;
Do not forget to delete install.php later..&lt;br /&gt;
&lt;br /&gt;
  # rm install.php&lt;br /&gt;
&lt;br /&gt;
A reminder: www user must have read-write rights to audit, debug and guardian log files. For instance, if the Guardian log file has the path as “/var/log/modsec_guardian.log” , then we need to enter this command:&lt;br /&gt;
&lt;br /&gt;
  # chown www /var/log/modsec_guardian.log&lt;br /&gt;
&lt;br /&gt;
Now the guardian log can be seen in the program. You have to do chown for other log files, too.&lt;br /&gt;
&lt;br /&gt;
I express my gratitude to those who helped me with this write-up.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Contributor ==&lt;br /&gt;
The project is lead by * [[User:Bunyamin|Bunyamin Demir]] (bunyamin~owasp.org)&lt;br /&gt;
&lt;br /&gt;
Mail list: owasp-webekci~lists.owasp.org&lt;br /&gt;
&lt;br /&gt;
== Documents ==&lt;br /&gt;
ModSecurity 2.1.0 Reference documentation [http://www.modsecurity.org/documentation/modsecurity-apache/2.1.0/modsecurity2-apache-reference.pdf (English)] [http://www.modsecurity.org/documentation/contributed/ModSecurity_2.1.0_Turkish.pdf (Turkish)]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
WeBekci documentation [[Media:Owasp-webekci-1.0_en.doc |(English)]] [[Media:Owasp-webekci-1.0_tr.doc |(Turkish)]]&lt;br /&gt;
&lt;br /&gt;
== Project Sponsor ==&lt;br /&gt;
If you would like to help WeBekci project development, feel free to contact the project leader.&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26967</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26967"/>
				<updated>2008-03-23T14:18:14Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* OWASP-WeBekci Project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli &lt;br /&gt;
* Proposal: Make [[OWASP ASDR Project|OWASP ASDR Project]] a release quality document.&lt;br /&gt;
&lt;br /&gt;
The ASDR is a reference volume that contains basic information about all the foundational topics in application security. It intends to replace and refresh [[OWASP Honeycomb Project|Honeycomb Project]] with a new structure for articles and relationship between categories, thus making it a release quality doc.&lt;br /&gt;
&lt;br /&gt;
This idea raised when finished the [[Attack|Attack Reference Guide]] for [[OWASP Spring Of Code 2007|OWASP Spring Of Code 2007]], where it was identified that OWASP reference articles need some special attention. Jeff Williams is totally supporting this project.&lt;br /&gt;
&lt;br /&gt;
We already have defined which type of article we should include on Desk Reference, as follows:&lt;br /&gt;
* [[:Category:Principle|Principles]]&lt;br /&gt;
* [[:Category:Threat_Agent|Threat Agents]]&lt;br /&gt;
* [[:Category:Attack|Attacks]]&lt;br /&gt;
* [[:Category:Vulnerability|Vulnerabilities]]&lt;br /&gt;
* [[:Category:Countermeasure|Countermeasures]]&lt;br /&gt;
* [[:Category:Technical Impact|Technical Impacts]]&lt;br /&gt;
* [[:Category:Business Impact|Business Impacts]]&lt;br /&gt;
&lt;br /&gt;
*Road Map: A complete project roadmap can be found on '''[[ASDR Table of Contents|ASDR Table of Contents]]'''. Basically, the following activities should be performed, some of them already started:&lt;br /&gt;
** Define articles templates for each reference type&lt;br /&gt;
** Define subcategories for articles classification&lt;br /&gt;
** Compile first DRAFT version of ASDR Book&lt;br /&gt;
** Articles development &amp;amp; Call for Volunteers&lt;br /&gt;
** Articles revision&lt;br /&gt;
** First version of OWASP ASDR book&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali (aka nTze)&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Security Software Life Cycle'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;br /&gt;
&lt;br /&gt;
== OWASP Classic ASP Security Project  ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
I am interested in making P018 - OWASP Classic ASP Security Project happen, Classic ASP 2.0 and 3.0 applications are still largely used as this technology is more than 10 years old and was largely used. there are thousands of sites on the wild that need guidance on the security arena. This is where OWASP can come up and provide help for “making the Web a better place” and continue spreading the word on security. I have always be a passionate of the technology (regardless of its inconveniences such as being old and DLL-hell prone) and I am really exited on the idea of sharing my knowledge of this area to the world and what best that though OWASP.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
Create a secure framework for Classic ASP application by complementing existing OWASP projects with documentation for this particular technology and the creation of security libraries. More specifically:&lt;br /&gt;
* Creation of a Common Object Repository for ASP applications based on OWASP ESAPI Project including objects and/or references to libraries for security applications all this aligned with OWASP Top10 and OWASP Guide .&lt;br /&gt;
* Create Documentation aligned to OWASP Code Review Project Checklist providing additional technology-specific checks.&lt;br /&gt;
* Addition of expression for Code Review Tool to support Classic ASP applications.&lt;br /&gt;
* Implementation of Version 1 of Stinger for ASP either by using an installable COM library or ISAPI.&lt;br /&gt;
* This same module will compliment the OWASP Validation Documentation Project.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver. &lt;br /&gt;
&lt;br /&gt;
Also I’ve had close contact with OWASP since 2005&lt;br /&gt;
[https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html] by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish.&lt;br /&gt;
&lt;br /&gt;
== Internationalization Guidelines and OWASP-Spanish Project ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
The main goal of OWASP is to spread the word about security (“Our mission is to make application security &amp;quot;visible,&amp;quot; so that people and organizations can make informed decisions about application security risks.”) and OWASP has done great work so far :). And now it’s time for a next big step.&lt;br /&gt;
&lt;br /&gt;
The number of native and secondary speakers in the world for Chinese, Spanish, French, Russian, Arabic and Indi languages are estimated in similar number to English speaking or even more (Some References at [http://en.wikipedia.org/wiki/Ethnologue_list_of_most_spoken_languages Ethnologue], [http://encarta.msn.com/media_701500404/Languages_Spoken_by_More_Than_10_Million_People.html Encarta], [http://en.wikipedia.org/wiki/List_of_languages_by_number_of_native_speakers Wikipedia]). I think is a good time for OWASP to reach those that do not speak English to have full access to all the OWASP materials, not just a couple of documents.&lt;br /&gt;
&lt;br /&gt;
OWASP, while open to translations, do not have clear guidelines on how to translate OWASP contents and (AFAIK) there is no multi-language support in OWASP.org site. This is understandable as there is no formal project for internationalization so far. &lt;br /&gt;
&lt;br /&gt;
'''Oportunity and Effort'''&amp;lt;br&amp;gt;&lt;br /&gt;
This is great opportunity to make Spanish the first language on which the OWASP site and documentation is fully translated and at the same time share the experience with other people interested in the same objective, Bring OWASP to the world.  And this is something I’ve being pushing for some time ago and that could be possible “at once” via SoC 2008.&lt;br /&gt;
&lt;br /&gt;
I understand this is significant effort so to have it done I will count with the help of 6 people (friend of mine, all of them Security auditors with excellent English level) plus a few well known contributors from OWASP-Spanish effort, so the founding will be divided among the people involved in the same proportion of the work they do for the completion of this effort. This, to encourage delivery.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
* Team up with Larry Casey to implement Multilanguage support in OWASP.org Mediawiki.&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to start a new language translation for OWASP Document and Site Pages&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to implement internationalization and localization ([http://www.w3.org/International/ i18n]) on OWASP Software &lt;br /&gt;
* Full translation to Spanish of all the release-level document projects. Those are:&lt;br /&gt;
** Top 10 2007&lt;br /&gt;
** Guide 2 (Already translated)&lt;br /&gt;
** Testing Guide (Already Translated)&lt;br /&gt;
** Legal&lt;br /&gt;
** FAQ&lt;br /&gt;
* Full Translation of major sections of OWASP Site&lt;br /&gt;
** Project Main Pages (Release, Beta and Alpha levels for both documents and tools projects)&lt;br /&gt;
** Principles&lt;br /&gt;
** References Section&lt;br /&gt;
** Conferences&lt;br /&gt;
** News (Those currently displayed in OWASP site)&lt;br /&gt;
** About OWASP&lt;br /&gt;
* Evaluation of Spanish translation approach for WebGoat and WebScarab and delivery of this document to Bruce and Rogan for possible implementation in near future.&lt;br /&gt;
* Leverage for deploy of es.owasp.org, the domain already exists but is not redirecting correctly.&lt;br /&gt;
* Create a Communication strategy to help and keep track on new pages or changes in significant pages so all the translations are in sync.&lt;br /&gt;
&lt;br /&gt;
'''Out of Scope'''&amp;lt;br&amp;gt;&lt;br /&gt;
Translation of the following sections are NOT in Scope&lt;br /&gt;
* Local Chapters Pages&lt;br /&gt;
* Presentations&lt;br /&gt;
* Conferences&lt;br /&gt;
* Videos&lt;br /&gt;
* Blogs&lt;br /&gt;
* All the projects deliverables in Alpha and Beta Stages&lt;br /&gt;
* All the documentation “on development” like Guide Version 3.0&lt;br /&gt;
* Translation of Pages, documentation or tools to other language other than Spanish according to the stated in above section.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I’ve being part of contributions to OWASP documents on the translation arena since 2005 [https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html], a few of them by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish. It is time to make the full job done :).&lt;br /&gt;
&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver.&lt;br /&gt;
&lt;br /&gt;
== The Ruby on Rails Security Guide v2 ==&lt;br /&gt;
Heiko Webers&lt;br /&gt;
&lt;br /&gt;
The last security guide for Rails [http://www.owasp.org/index.php/Category:OWASP_Web_Application_Security_Put_Into_Practice] was a great success, with a lot of more secure web applications and continued awareness in the community of security issues. The Ruby on Rails Security Project [http://www.rorsecurity.info/] is the one and only source of information about Rails security topics, and I keep the community up-to-date with blog posts and conference talks in Europe. The Guide and the Project has been mentioned in several Rails books and web-sites.&lt;br /&gt;
&lt;br /&gt;
Version 1 of the Ruby on Rails Security Guide was sponsored by the SpoC 07, set the standard for OWASP programming language specific guides in terms of the topic outline and has been published as a book [http://www.lulu.com/content/1412042]. Nevertheless I'm convinced that a more compact design and a &amp;quot;question-and-answer&amp;quot; style of writing will reach an even larger audience. Of course the new Guide will still include answers to the OWASP Top Ten security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
A lot has changed since the publishing of the first Guide. Some new security holes have been found, there are new advises and most importantly Rails version 2.0 has been released. The new Ruby on Rails Security Guide aims at providing an up-to-date coding and configuration guide for the Rails community.&lt;br /&gt;
&lt;br /&gt;
In the new Rails Security Guide I'd like to&lt;br /&gt;
* update the entire book to match Rails 2.0&lt;br /&gt;
* cover new topics, including, but not limited to:&lt;br /&gt;
** Intranet and administration interface security,&lt;br /&gt;
** phishing,&lt;br /&gt;
** real-world attack situations,&lt;br /&gt;
** short excursus on server monitoring,&lt;br /&gt;
** the new CookieStore session management,&lt;br /&gt;
** vulnerabilities in popular plug-ins,&lt;br /&gt;
** denial-of-service attacks&lt;br /&gt;
* cover all OWASP Top Ten security vulnerabilities&lt;br /&gt;
* a more compact writing style, more examples and &amp;quot;questions-and-answers&amp;quot;&lt;br /&gt;
* introduce the OWASP and Rails security to a greater audience&lt;br /&gt;
&lt;br /&gt;
== OWASP Application Security Verification Standard ==&lt;br /&gt;
&lt;br /&gt;
*Mike&lt;br /&gt;
&lt;br /&gt;
'''OWASP Application Security Verification Standard Proposal'''&lt;br /&gt;
&lt;br /&gt;
'''Educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
The applicant is a hands-on senior professional services manager with a trademark of&lt;br /&gt;
developing creative solutions to complex application security-related technical problems. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a background in trusted product evaluation:&lt;br /&gt;
&lt;br /&gt;
*CC evaluation&lt;br /&gt;
*CC evidence development, including operating system test code development&lt;br /&gt;
*CC project management&lt;br /&gt;
*TCSEC evaluation&lt;br /&gt;
*TCSEC project management&lt;br /&gt;
*TEF management&lt;br /&gt;
*CCTL management&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in security-related software development and integration:&lt;br /&gt;
&lt;br /&gt;
*PKI toolkit development&lt;br /&gt;
*PK-E application integration&lt;br /&gt;
*Secure web portal application development&lt;br /&gt;
*Secure web portal integration&lt;br /&gt;
*Secure instant messaging application development, including three patents&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in cryptomodule testing:&lt;br /&gt;
&lt;br /&gt;
*FIPS 140 evaluation&lt;br /&gt;
*FIPS 140 evidence development&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
The applicant does not have experience in contributing to open communities.&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
OWASP is looking for a commercially-workable open standard for performing application security verification efforts. The problem is that there is a huge range in the coverage and level of rigor available in the market, and consumers have no way to tell the difference between someone just running a grep tool, and someone doing painstaking code review and manual testing. So, a standard is needed.&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s)'''&lt;br /&gt;
&lt;br /&gt;
The applicant’s proposal will address the above challenges as follows:&lt;br /&gt;
&lt;br /&gt;
*The applicant will define an evaluation framework that may be used to conduct OWASP Application Security Verification Standard certifications.&lt;br /&gt;
*The applicant will define an OWASP Application Security Verification Standard which defines levels that applications may be certified against.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
The applicant will carry out these activities. Please see below for a proposed list of specific deliverables.&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following deliverables:&lt;br /&gt;
&lt;br /&gt;
*'''Scheme Overview document.''' This will define the overall framework with roles, responsibilities, and processes.&lt;br /&gt;
*'''Evaluation and Certification document.''' This will describe the evaluation and certification process.&lt;br /&gt;
*'''Conditions for the Use of Trademarks.''' This will describe OWASP’s name, logo, and certificate may be used and referenced.&lt;br /&gt;
*'''Evaluation Report Content Requirements.''' This will describe the content requirements of evaluation reports.&lt;br /&gt;
*'''OWASP Application Security Verification Standard.''' This will define the levels that applications may be certified against.&lt;br /&gt;
*'''OWASP Application Security Verification Standard Appendix A.''' This will define the required content of the OWASP Application Security Verification Standard Security Policy.&lt;br /&gt;
*'''Policy Letter #1. Acceptance of Security Policies into OWASP Evaluation''' This will define the requirements to be listed as in evaluation on the OWASP web site.&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following rough project schedule:&lt;br /&gt;
&lt;br /&gt;
*2nd April. Project kickoff.&lt;br /&gt;
*15th June. Alpha Quality drafts of Scheme Overview document and of OWASP Application Security Verification Standard document completed.&lt;br /&gt;
*31st August. Project completion. Beta Quality drafts of all documents completed.&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
The long-term vision for the project is to normalize the range in the coverage and level of rigor available in the market when it comes to performing application security verification.&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected.'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a uniquely-qualified perspective given his experience with TCSEC, TTAP, CC, FIPS 140-1, and FIPS 140-2 evaluation programs, and his real-world perspective as a developer and integrator of security-related applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== GTK+ GUI for w3af project ==&lt;br /&gt;
&lt;br /&gt;
''Facundo Batista''&lt;br /&gt;
&lt;br /&gt;
'''Your educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
I'm Electronic Engineer with a Master in Engineer Innovation in&lt;br /&gt;
Bologna University, Italy. I live in Buenos Aires, Argentina, and love&lt;br /&gt;
reading books, playing tennis, and programming Python.&lt;br /&gt;
&lt;br /&gt;
I worked in a mobile company for six years, in the Network Management&lt;br /&gt;
department, then I was Chief Developer of a Mobile Content Provider,&lt;br /&gt;
and now I'm Solution Architect in Multimedia &amp;amp; Systems Integration in&lt;br /&gt;
Ericsson. Also I was professor in several universities, high schools&lt;br /&gt;
and other institutions.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
None, more than working in w3af. However, my proposal here is not&lt;br /&gt;
related to the security part of the product, but to its graphical&lt;br /&gt;
interface and usability.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I'm very involved in the free software and open source community. I'm&lt;br /&gt;
a Python Core Developer and member of the Python Software Foundation&lt;br /&gt;
by merit. I have a long history of talks given in several&lt;br /&gt;
international (PyCon, EuroPython) and national (a lot!) conferences. I&lt;br /&gt;
also teach Python in educational institutions, enterprises and as a&lt;br /&gt;
private instructor. I founded Python Argentina, the national users&lt;br /&gt;
groups, and I'm a very active member of it.&lt;br /&gt;
&lt;br /&gt;
I also lead other open source projects (SMPPy, SiGeFi, etc.) and&lt;br /&gt;
particpate in others (Docutils, w3af itself, etc.).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
My main objective is to minimize the effort and learning curve of&lt;br /&gt;
using w3af, providing a very usable graphical interface.&lt;br /&gt;
&lt;br /&gt;
Note that as the interface is cross platform, being usable also in the&lt;br /&gt;
win32 environment, it will help to popularize the w3af project.&lt;br /&gt;
&lt;br /&gt;
This will allow users without information security knowledge to verify&lt;br /&gt;
that their web applications are correctly programmed and configured.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
I will carry the following activities, detailed later in smaller steps:&lt;br /&gt;
&lt;br /&gt;
- Design and code new windows and interfaces to increase the functionality of the project.&lt;br /&gt;
&lt;br /&gt;
- Tuning of the process workflow, allowing a more intuitive way of working.&lt;br /&gt;
&lt;br /&gt;
- Visual polishing for a more pleasant and intuitive tool.&lt;br /&gt;
&lt;br /&gt;
- Usability tests and improvements.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
''New features implemented in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Local proxy to trap and modify requests and responses sent from a browser.&lt;br /&gt;
&lt;br /&gt;
- Manually send a request and analyze the response.&lt;br /&gt;
&lt;br /&gt;
- Manually create a fuzzed requests based on tokens, so user can construct easily differents HTTP request with a regex-like semantics.&lt;br /&gt;
&lt;br /&gt;
- Wizard to perform a vulnerability assessment.&lt;br /&gt;
&lt;br /&gt;
- Graphical display of site map and vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
- Reload a plugin after its edited from within the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Embebed tool to encode/decode URL/Base64 and to hash sha1/md5.&lt;br /&gt;
&lt;br /&gt;
- HTTP response side by side content compare.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Usability improvements in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Meetings with a usability expert that the w3af team leader has already contacted and worked with.&lt;br /&gt;
&lt;br /&gt;
- Kill all pending bugs and make a stable release.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Documentation:''&lt;br /&gt;
&lt;br /&gt;
- Users guide for the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Help system for the GUI itself&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
To provide the web application security community with a stable and fully &lt;br /&gt;
featured framework to perform all the tasks included in a penetration test&lt;br /&gt;
from within the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected'''&lt;br /&gt;
&lt;br /&gt;
w3af is one of the most active web application security projects;&lt;br /&gt;
the community that supports it is growing and we need the support of &lt;br /&gt;
already established organizations like OWASP to keep working at the &lt;br /&gt;
rate that we want to.&lt;br /&gt;
&lt;br /&gt;
== P006 OWASP Corporate Application Security Rating Guide and P025 OWASP Positive Security Project ==&lt;br /&gt;
&lt;br /&gt;
by Eduardo Vianna de Camargo Neves&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
A common approach on most companies is to increase the protection of their assets after the occurrence of a considerable impact. However some companies learned that a positive approach on IT Security is most effective and can reduce the financial costs on responses to security incidents. Benchmarking the application security practices on the corporate world will allow us to understand what steps are required to keep the IT environment protected, using this knowledge to create a public Security Rating Guide that can be used to support the establishment of a security baseline within the community.&lt;br /&gt;
&lt;br /&gt;
Moreover the information from this analysis can be used to support the development of a campaign to spread a positive security posture in the market. The liaison with companies that maintain good security practices  will help to start this initiative from a higher degree and involve several actors on the security stage for the same direction to a market were security is understood as a business value.&lt;br /&gt;
&lt;br /&gt;
'''Approach'''&lt;br /&gt;
&lt;br /&gt;
Assessing public materials from the Top 50 Companies and Top 50 Software Companies, a rating guide will be produced showing tangible metrics that are achieved by those companies and allow them to be considered secure enough on a comparison to a baseline of good practices. As a result the Corporate Application Security Rating Guide will be produced and published for the community and the deliverables used to support the development of the Positive Security Project with facts from a real analysis.&lt;br /&gt;
&lt;br /&gt;
'''Benefits'''&lt;br /&gt;
&lt;br /&gt;
The whole community will be benefited from these initiatives. With the adequate support from OWASP to maintain the projects active and liaise with big players on the market, we can expect the following:&lt;br /&gt;
&lt;br /&gt;
• The community will receive a Security Rating Guide that will allow them to compare their own security practices within the market. As this will be a public document, suppliers and buyers worldwide will share the same information allowing them to adequate the expectations on the usage of security services and tools.&lt;br /&gt;
&lt;br /&gt;
• The Security Rating Guide can be used as a marketing tool by the companies, allowing them to sell security as a business value and avoiding the old-fashion and inadequate FUD approach.&lt;br /&gt;
&lt;br /&gt;
• The knowledge and relationship developed during the production of the Security Rating Guide will allow us to produce the deliverables on Positive Security Project with real information, increasing the credibility of the initiative for the market.&lt;br /&gt;
&lt;br /&gt;
• The Security Rating Guide and the Positive Security Project can be walk in parallel, merging their information to support a concise and continuous marketing campaign to encourage a positive approach on the market.&lt;br /&gt;
&lt;br /&gt;
• As an open community free from commercial pressures, OWASP can use both projects to support the evaluation of security products for the market, allowing the organization to receive profits from these services and support current and future projects.&lt;br /&gt;
&lt;br /&gt;
'''Summarized Work Breakdown Structure (WBS)'''&lt;br /&gt;
&lt;br /&gt;
All the activities will be leaded by Eduardo V. C. Neves, which will be responsible as a single point of contact with the sponsors and to manage a team of compromised volunteers from OWASP community and participants from security communities and associations (i.e. ISSA, SANS and ISC2).&lt;br /&gt;
&lt;br /&gt;
The activities will be carried on WBS summarized bellow. Dates presented should be considered as deadlines for the activities:&lt;br /&gt;
&lt;br /&gt;
• Criteria establishment and definition of the Top 50 Companies and Top 50 Software Companies (April 11)&lt;br /&gt;
&lt;br /&gt;
• Assessment of public materials to support the ranking establishment (April 18)&lt;br /&gt;
&lt;br /&gt;
• Establishment of the Corporate Application Security Rating Guide (April 25)&lt;br /&gt;
&lt;br /&gt;
• Publishing of the Corporate Application Security Rating Guide on OWASP web site and promotion over adequate channels (i.e. publications, blogs and associations) (May 09) (1)&lt;br /&gt;
&lt;br /&gt;
• Criteria establishment and approval of marketing templates for Positive Security Project (May 16) (2)&lt;br /&gt;
&lt;br /&gt;
• Development of the Positive Security Project material (i.e. blog and marketing sheets) (May 30)&lt;br /&gt;
&lt;br /&gt;
• Liaison with the OWASP Members, Top 50 Companies and Top 50 Software Companies to present the project and negotiate their participation as supporters, sponsors or contributors. (June 27)&lt;br /&gt;
&lt;br /&gt;
• Update on Corporate Application Security Rating Guide, including their score on Positive Security approach (July 4)&lt;br /&gt;
&lt;br /&gt;
• Presentation of the Positive Security Project approach and Corporate Application Security Rating Guide on the market (July 31) (3)&lt;br /&gt;
&lt;br /&gt;
• Conference calls with team members to evaluate the results of the initiatives in all countries and produce project´s documents (i.e. lessons learned, update on marketing material and evaluation of alternative approaches for the future steps). (August 15)&lt;br /&gt;
&lt;br /&gt;
• Prepare project documentation and present to the OWASP community on the web site (August 31)&lt;br /&gt;
&lt;br /&gt;
''(1) Support from OWASP Foundation is required to liaise with companies and associations worldwide&lt;br /&gt;
&lt;br /&gt;
''(2) Support from OWASP Foundation and community are required to evaluate adequate marketing templates and translate original documents for their own languages''&lt;br /&gt;
&lt;br /&gt;
''(3) Support from OWASP community is required to spread the word on all countries were OWASP members are located.''&lt;br /&gt;
'''''&lt;br /&gt;
&lt;br /&gt;
'''Project Control'''&lt;br /&gt;
&lt;br /&gt;
The project will be managed following PRINCE2 Process Model and all control documents published for the OWASP community. The following mandatory project control documents are planned:&lt;br /&gt;
&lt;br /&gt;
• Project Initiation Document: To document project´s background, definition, objectives, approach, etc.&lt;br /&gt;
&lt;br /&gt;
• Communication Plan: To assure that OWASP Community are being continuous communicated about project status and deliverables achievement.&lt;br /&gt;
&lt;br /&gt;
• Highlight Report: To provide the OWASP Community with a summary of the project status, progress and potential problems or areas where help may be required.&lt;br /&gt;
&lt;br /&gt;
• End Project Report: To present project achievements. Should be considered the final project report.&lt;br /&gt;
&lt;br /&gt;
More documents may be included during project development to support the control and assure a high quality level (i.e. issue log, project approach).&lt;br /&gt;
&lt;br /&gt;
'''Long Range Plan'''&lt;br /&gt;
&lt;br /&gt;
Both projects should walk in parallel and be used as tools to support efforts to encourage and make the positive approach a reality on the IT Security field. These initiatives shall be supported by OWASP as long term plans and grow to a continuous world-wide campaign in this direction that must achieve big players on the market and be recognized by the community as a tool that must be used to evaluate security enabled companies and products. &lt;br /&gt;
&lt;br /&gt;
'''Why me?'''&lt;br /&gt;
&lt;br /&gt;
Can be me, you or anyone that carries these projects in a professional fashion and assure that all deliverables are being achieved. The most important parts is to make it happen, talk and get the support from reputable associations and large companies (OWASP Members are a good start) and lead it as a long range responsibility.&lt;br /&gt;
&lt;br /&gt;
I am running to win this project because I believe in all of this. I see both as very valuable initiatives that can help companies to make more business; people to get more jobs and the whole community to win in a scenario where our contributions on the security market are recognized as business tools.&lt;br /&gt;
&lt;br /&gt;
'''About me'''&lt;br /&gt;
&lt;br /&gt;
Information Security professional and enthusiastic with 15 years dedicated to achieve expressive results in the areas of IT, Information Security, Compliance and Project Management. A CISSP in good stand and Officer at the ISSA Brazilian Chapter, my professional career gave me extensive knowledge in several fields of Information Security with accumulated experience at consulting firms, as CSO at a world player company on consumer goods market and now as an entrepreneur at Latin American market.&lt;br /&gt;
&lt;br /&gt;
''Application security experience and accomplishments''&lt;br /&gt;
&lt;br /&gt;
My work experience is on Security Management, Risk Assessment, Business Continuity and Disaster Recovery, Security Awareness and other managed-related fields on our industry. I don’t have hands-on experience on application security and this is the main reason why I am running to be qualified on the project described bellow, where I believe that my skills can be used to achieve an excellent result for the community.&lt;br /&gt;
&lt;br /&gt;
''Participation and leadership in open communities''&lt;br /&gt;
&lt;br /&gt;
• Member of OWASP Brazil where I made some small contributions in a recent past.&lt;br /&gt;
&lt;br /&gt;
• Member of ABNT/CB-21/SC02 committee, Brazilian ISO representative for 27001 and 17799 standards&lt;br /&gt;
&lt;br /&gt;
• Officer of ISSA Brazil Chapter where I am responsible for the South Region and as the editor of Antebellum, the ISSA Brazil Journal&lt;br /&gt;
&lt;br /&gt;
• Founder and member of GISI-PR, an open community focused on discuss and promote Information Security initiatives within Paraná State, Brazil&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application ==&lt;br /&gt;
'''Name'''&lt;br /&gt;
&lt;br /&gt;
Michael Coates&lt;br /&gt;
&lt;br /&gt;
'''Project'''&lt;br /&gt;
&lt;br /&gt;
P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses, '''&lt;br /&gt;
&lt;br /&gt;
As critical applications continue to become more accessible and inter-connected, it is paramount that the information be protected. We must also realize that our defenses may not be perfect. Given enough time, attackers can identify security flaws in the design or implementation of an application. In addition to implementing layers of defense within an application, it is critical that we identify malicious individuals before they are able to identify any gaps in our defenses. The best place to identify malicious activity against the application is within the application itself.&lt;br /&gt;
Network based intrusion detection systems are not appropriate to handle the custom and intricate workings of an enterprise application and are ill-suited to detect attacks focusing on application logic such as authentication, access control, etc.  The application itself is the best place to identify and respond to malicious activity.&lt;br /&gt;
This project will create the framework which can be used to build a robust system of attack detection, analysis, and response within an enterprise application&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s), '''&lt;br /&gt;
&lt;br /&gt;
I plan to use a methodical approach throughout the creation of this resource. I will reference my own professional experience, OWASP resources, ESAPI, and academic materials to identify a robust set of potential attacks and identification methods. Thresholds will be recommended for each of the detected attacks. Each recommended threshold value and response recommendation will be accompanied with additional information to describe the purpose of the threshold and recommendation. This additional information will allow the reader to determine if the threshold is appropriate for their implementation.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities, '''&lt;br /&gt;
&lt;br /&gt;
I will complete the following activities:&lt;br /&gt;
1. Identify and define attack patterns against applications&lt;br /&gt;
2. Document points of detection within the application for the attack patterns &amp;amp; identify key information to log&lt;br /&gt;
3. Create thresholds for generating security alerts&lt;br /&gt;
4. Define recommended response actions for the security alerts&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress, '''&lt;br /&gt;
&lt;br /&gt;
April 2, 2008 - Project Begins&lt;br /&gt;
&lt;br /&gt;
April 2, 2008-April 12, 2008 - High level planning &amp;amp; design 	&lt;br /&gt;
&lt;br /&gt;
April 12, 2008-May 1, 2008 - Identify and define attack patterns against applications	&lt;br /&gt;
&lt;br /&gt;
May 1, 2008-June 1, 2008 - Document points of detection within the application for the attack patterns &amp;amp; identify key information to log	&lt;br /&gt;
&lt;br /&gt;
June 1, 2008-June 13, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
June 15, 2008 - Status Report	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Create thresholds for generating security alerts	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Define recommended response actions for the security alerts	&lt;br /&gt;
&lt;br /&gt;
Aug 16, 2008-Aug 30, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
Aug 31, 2008 - Project Complete	&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project, '''&lt;br /&gt;
&lt;br /&gt;
1.  I’d like to include a tiered type approach of thresholds and responses. This is would be similar to the approach used by FISMA of defining different controls for High, Medium, and Low systems.&lt;br /&gt;
&lt;br /&gt;
2. Building on item #1, I want to eventually include a system which lets the user provide information about their system.  This information could include rating or prioritizing different security concerns. a customized set of monitoring points, thresholds and response actions can be recommended for the application based on the provided data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About Me'''&lt;br /&gt;
&lt;br /&gt;
'''Education &amp;amp; Professional Background'''&lt;br /&gt;
&lt;br /&gt;
Masters of Science in Computer, Information and Network Security – DePaul University &lt;br /&gt;
(Expected Graduation 2009)&lt;br /&gt;
Bachelor of Science in Computer Science – University of Illinois&lt;br /&gt;
Extensive experience in conducting black and white box security reviews of complex applications and networks for major financial organizations and international telecoms. I also have experience working as the primary investigator of attacks against a multi-national organization with IDS sensors in networks throughout the world. In addition, I have experience working with several regulatory controls and security standards (FISMA, NIST, GLBA etc). My experience as an ethical hacker and incident responder puts me in an excellent position to tackle this project. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
I am a Senior Computer Security Engineer with Aspect Security where I perform security code reviews and application security testing against a variety of platforms. Prior to working with Aspect Security, I was heavily involved in the discovery and exploitation of application vulnerabilities during black box ethical hacking assessments for numerous clients.&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I am a member of OWASP and attend Chicago OWASP chapter meetings. I also attend ChiSec, an informal meet-up of security professionals in the Chicago area. In addition, I interact with the community through my security blog. http://michaelcoates.wordpress.com. &lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected. '''&lt;br /&gt;
&lt;br /&gt;
I created a similar framework while working within a Security Operation Center. I created attack scenarios, identified relevant IDS events, defined thresholds and appropriate response action for the Security analysts.&lt;br /&gt;
&lt;br /&gt;
'''Requested Reviewer - Eric Sheridan, Application Security Consultant at Aspect Security, Inc.'''&lt;br /&gt;
&lt;br /&gt;
Eric Sheridan is an Application Security Consultant at Aspect Security, a consulting services company specializing in application security. At Aspect Security, Eric specializes in execution of security verification assessments and the establishment of security activities throughout the development lifecycle. In addition, Eric is an instructor in Aspect’s portfolio of Application Security Courses. Eric is also an active participant in OWASP whose contributions include work with projects such as WebGoat, Stinger, CSRFGuard, CSRFTester, and the SASAP project from OWASP SPoC 2007. Eric was also a featured speaker at the 2007 OWASP/WASC San Jose conference.&lt;br /&gt;
&lt;br /&gt;
Contact Information: eric dot sheridan 'at' owasp dot org&lt;br /&gt;
&lt;br /&gt;
== OWASP Interceptor Project - 2008 Update ==&lt;br /&gt;
&lt;br /&gt;
by Justin Derry&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_Interceptor_Project&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
The OWASP Interceptor project was originally written by myself and donated to the OWASP project. Since it has been online numerous people have downloaded the tools and used the code/toolkit. Currently the industry has very limited “XML” or SOAP client testing tools that are designed specifically to perform XML interception and manipulation. The Objective of the Interceptor project is to provide a strong tool for performing XML penetration tests against Web Service (or XML/SOAP) endpoints. The tool should not replace other proxy interception tools such as Charles, Web Scarab and so on, but be purely focused on handling and reading XML structures from clients.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Interceptor tool includes a “swiss-army” knife of features that will help with decoding/hash generation and interpretation of XML code. The key objective is to make a tool that can assist with the collection, inspection and attack replay of XML requests against service endpoints. This year it’s time for an update. The tool doesn’t run on Vista and needs a number of back-end features addressed as well as some help files etc. (Help to get the tool out of BETA status).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Objectives this year'''&lt;br /&gt;
&lt;br /&gt;
This year I see the following objectives in the application code base.&lt;br /&gt;
•	Get the Interface to run on all Window Platforms (.NET) Win2000, XP and Vista;&lt;br /&gt;
&lt;br /&gt;
•	Update the TCP handle libraries to be faster&lt;br /&gt;
&lt;br /&gt;
•	Update the XML Parser engine to support the latest structures&lt;br /&gt;
&lt;br /&gt;
•	Provide a “default” attack database of known XML attack methods (this is a big one)&lt;br /&gt;
&lt;br /&gt;
•	Write a number of help files on how to use the tool&lt;br /&gt;
&lt;br /&gt;
•	Update the toolkit BASE64 Decoder, XML Generators etc with further tools&lt;br /&gt;
&lt;br /&gt;
•	Write a better “reporting” engine to show the result of simulated attack responses&lt;br /&gt;
&lt;br /&gt;
•	Better HTTP support for Manipulation, Authentication and Header Injection etc&lt;br /&gt;
&lt;br /&gt;
•	Better support for interception and handling AJAX XML requests&lt;br /&gt;
&lt;br /&gt;
These are the core features I would like to introduce, with also further to probably come as a part of the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&lt;br /&gt;
&lt;br /&gt;
The current development cycle stopped due to limited time and the need to purchase the IDE tools to develop the interface in .NET. As a Summer of Code 2008 sponsored project we can get the IDE interface tools to implement “Vista” features that will see the tool run on all .NET platforms (Win2000, XP and Vista). Recent changes in my job will allow me to spend more time on developing the toolkit.&lt;br /&gt;
&lt;br /&gt;
Over a number of years I have been involved with OWASP, whilst most recently getting involved with running the OWASP Australia Security Conference for 2008, as well as the Brisbane Chapter. I am also working in the Asia Pacific RIM to further increase the awareness of OWASP and Application Security. My Conference duties for the year have finished up (till planning starts again in a couple of months) so my time can be invested in updating the toolkit.&lt;br /&gt;
&lt;br /&gt;
I believe during the previous years, i have shown OWASP that i am willing and able to produce a quality outcome and i am prepared to put the effort into OWASP to acheive the goals set out for this project. &lt;br /&gt;
&lt;br /&gt;
Some of the Sponsorship money for the project would go to purchasing a specific toolkit for the UI. (The UI is important simply because we want the application to be user friendly). Xceed Components provide a Smart UI as well as some of the decoding and compression features the tool needs. This would require us to approach them upfront for a “free” licence or use some of the Sponsorship money to buy the toolkit. But we can tackle that problem when we come to it.&lt;br /&gt;
&lt;br /&gt;
== SQL Injector Benchmarking Project (SQLiBENCH) ==&lt;br /&gt;
&lt;br /&gt;
by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
'''Prelude'''&lt;br /&gt;
&lt;br /&gt;
There're a lot of and great open source tools (takeover/dumpers/hybrid) for taking advantage of an sql injection vulnerability both used by web application security specialists and attackers. &lt;br /&gt;
Techniques used, databases supported, algorithms employed and abilities implemented by these &amp;quot;sql injectors&amp;quot; greatly varies. Standardization is one of the abstract goals of OWASP and we think it's important to standardize general vulnerability techniques exists in web applications and one of the biggest one is sql manipulation. &lt;br /&gt;
In our effort, we aim to produce a standardization of techniques used in exploiting sql injection by automatic tools. &lt;br /&gt;
&lt;br /&gt;
'''Proposal'''&lt;br /&gt;
&lt;br /&gt;
The goal of the project is to create a detailed set of benchmarking criterias for automatic sql injection tools and applying these to a set of open source sql injectors, producing analysis/benchmarking reports.&lt;br /&gt;
Additionaly, in a semi-academic manner, algorithms used by several sql injectors will be analyzed both implementation and complexity vise.&lt;br /&gt;
&lt;br /&gt;
'''Deliverables And Project Schedule Milestones'''&lt;br /&gt;
&lt;br /&gt;
Two set of documents will be produced. One of them will include the benchmarking criterias and the other will comprise of analysis of selected sql injectors against the benchmarking criterias.&lt;br /&gt;
Moreover, an interactive visual data flow diagram, giving hints to testers about which tool should be used under which circumstances, will be implemented with web-based technologies such as jquery library. &lt;br /&gt;
&lt;br /&gt;
April 03    Project Kickoff&lt;br /&gt;
&lt;br /&gt;
April 03-30 Determination of the benchmarking criterias &lt;br /&gt;
&lt;br /&gt;
May   01-15 Producing a test environment image with 5-6 rdbms (MSSQL Express, Oracle Express, DB2 Express, MySQL, PgSQL, etc.) and a vulnerable application (which will support different sql injection types, databases and include logging capabilities)&lt;br /&gt;
&lt;br /&gt;
May   15-31 Selecting and installing automatic sql injectors onto the test system and starting to use them on vulnerable application&lt;br /&gt;
&lt;br /&gt;
June  01-30 Analysing tools and applying benchmarking criterias, contacting the authors as we proceed &lt;br /&gt;
&lt;br /&gt;
July  01-31 Producing reports for benchmarking criterias and tool analysis&lt;br /&gt;
&lt;br /&gt;
'''About Us'''&lt;br /&gt;
&lt;br /&gt;
We're part of OWASP-Turkey. [http://www.h-labs.org Mesut Timur] is a junior in the Computer Engineering Dept. of [http://www.gyte.edu.tr University of GYTE] and [http://www.webguvenligi.org Bedirhan Urgun] is a web/application security specialist in [http://www.uekae.tubitak.gov.tr TUBITAK-UEKAE].&lt;br /&gt;
&lt;br /&gt;
== OWASP-WeBekci Project ==&lt;br /&gt;
&lt;br /&gt;
by Bunyamin Demir&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_WeBekci_Project&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
Web application firewalls (WAF) are gaining importance among the information security technologies designed to protect web sites from attack. WAF solutions prevent attacks that network firewalls and intrusion detection systems can't and they require no modification of application source code. ModSecurity [http://www.modsecurity.org/] is an open source web application firewall that runs as an Apache module. It is an embeddable web application firewall and it provides protection from a range of attacks against web applications. It is an open source project available to everyone; it however does not come with an admin panel. &lt;br /&gt;
&lt;br /&gt;
I decided to provide this essential tool with a control panel which I believe will ease and thus encourage its usage.&lt;br /&gt;
&lt;br /&gt;
ModSecurity allows for HTTP traffic monitoring and real-time analysis with no changes to existing infrastructure. My main goal is to analyze attacks and generate rules to change the configuration of the ModSecurity accordingly.&lt;br /&gt;
&lt;br /&gt;
ModSecurity  has a feature called “flexible rule engine” as its heart of Attack Prevention capability . It uses ModSecurity’s “Rule Language,” (a programming language designed to work with HTTP transaction data). It is easy to use and flexible; yet the system administrators need to learn its own rules to create what is called “Certified ModSecurity Rules” to be implemented. My control panel will automate the major code-generation in Rule Language. &lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&lt;br /&gt;
&lt;br /&gt;
* '''Configuration'''        : Most of the configuration parameters will be managed through the web interface&lt;br /&gt;
* '''Rule Generator'''       : Basic rules will be generated using the web interface&lt;br /&gt;
* '''Core Rule Integration''': Core rules will be added to the database for use&lt;br /&gt;
* '''Logging and Reporting''': Apache error log and modsec_audit log will be parsed and presented to the user thru the web interface&lt;br /&gt;
* '''DB Support'''           : MySQL&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
Being a SpoC2007 project, it couldn't be implemented mainly due to a job change and therefore lack of time. With the help of Bedirhan Urgun we'll be able to produce a quality web admin panel GUI for a same host modsec installation infrastructure. We are both part of OWASP Turkey [http://www.owasp.org/index.php/Turkey] and tried to produce a great deal of awareness both about web security and OWASP with both documents/chapter meetings/email list and mini-conferences.&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26966</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26966"/>
				<updated>2008-03-23T14:11:49Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* OWASP-WeBekci Project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli &lt;br /&gt;
* Proposal: Make [[OWASP ASDR Project|OWASP ASDR Project]] a release quality document.&lt;br /&gt;
&lt;br /&gt;
The ASDR is a reference volume that contains basic information about all the foundational topics in application security. It intends to replace and refresh [[OWASP Honeycomb Project|Honeycomb Project]] with a new structure for articles and relationship between categories, thus making it a release quality doc.&lt;br /&gt;
&lt;br /&gt;
This idea raised when finished the [[Attack|Attack Reference Guide]] for [[OWASP Spring Of Code 2007|OWASP Spring Of Code 2007]], where it was identified that OWASP reference articles need some special attention. Jeff Williams is totally supporting this project.&lt;br /&gt;
&lt;br /&gt;
We already have defined which type of article we should include on Desk Reference, as follows:&lt;br /&gt;
* [[:Category:Principle|Principles]]&lt;br /&gt;
* [[:Category:Threat_Agent|Threat Agents]]&lt;br /&gt;
* [[:Category:Attack|Attacks]]&lt;br /&gt;
* [[:Category:Vulnerability|Vulnerabilities]]&lt;br /&gt;
* [[:Category:Countermeasure|Countermeasures]]&lt;br /&gt;
* [[:Category:Technical Impact|Technical Impacts]]&lt;br /&gt;
* [[:Category:Business Impact|Business Impacts]]&lt;br /&gt;
&lt;br /&gt;
*Road Map: A complete project roadmap can be found on '''[[ASDR Table of Contents|ASDR Table of Contents]]'''. Basically, the following activities should be performed, some of them already started:&lt;br /&gt;
** Define articles templates for each reference type&lt;br /&gt;
** Define subcategories for articles classification&lt;br /&gt;
** Compile first DRAFT version of ASDR Book&lt;br /&gt;
** Articles development &amp;amp; Call for Volunteers&lt;br /&gt;
** Articles revision&lt;br /&gt;
** First version of OWASP ASDR book&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali (aka nTze)&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Security Software Life Cycle'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;br /&gt;
&lt;br /&gt;
== OWASP Classic ASP Security Project  ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
I am interested in making P018 - OWASP Classic ASP Security Project happen, Classic ASP 2.0 and 3.0 applications are still largely used as this technology is more than 10 years old and was largely used. there are thousands of sites on the wild that need guidance on the security arena. This is where OWASP can come up and provide help for “making the Web a better place” and continue spreading the word on security. I have always be a passionate of the technology (regardless of its inconveniences such as being old and DLL-hell prone) and I am really exited on the idea of sharing my knowledge of this area to the world and what best that though OWASP.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
Create a secure framework for Classic ASP application by complementing existing OWASP projects with documentation for this particular technology and the creation of security libraries. More specifically:&lt;br /&gt;
* Creation of a Common Object Repository for ASP applications based on OWASP ESAPI Project including objects and/or references to libraries for security applications all this aligned with OWASP Top10 and OWASP Guide .&lt;br /&gt;
* Create Documentation aligned to OWASP Code Review Project Checklist providing additional technology-specific checks.&lt;br /&gt;
* Addition of expression for Code Review Tool to support Classic ASP applications.&lt;br /&gt;
* Implementation of Version 1 of Stinger for ASP either by using an installable COM library or ISAPI.&lt;br /&gt;
* This same module will compliment the OWASP Validation Documentation Project.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver. &lt;br /&gt;
&lt;br /&gt;
Also I’ve had close contact with OWASP since 2005&lt;br /&gt;
[https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html] by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish.&lt;br /&gt;
&lt;br /&gt;
== Internationalization Guidelines and OWASP-Spanish Project ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
The main goal of OWASP is to spread the word about security (“Our mission is to make application security &amp;quot;visible,&amp;quot; so that people and organizations can make informed decisions about application security risks.”) and OWASP has done great work so far :). And now it’s time for a next big step.&lt;br /&gt;
&lt;br /&gt;
The number of native and secondary speakers in the world for Chinese, Spanish, French, Russian, Arabic and Indi languages are estimated in similar number to English speaking or even more (Some References at [http://en.wikipedia.org/wiki/Ethnologue_list_of_most_spoken_languages Ethnologue], [http://encarta.msn.com/media_701500404/Languages_Spoken_by_More_Than_10_Million_People.html Encarta], [http://en.wikipedia.org/wiki/List_of_languages_by_number_of_native_speakers Wikipedia]). I think is a good time for OWASP to reach those that do not speak English to have full access to all the OWASP materials, not just a couple of documents.&lt;br /&gt;
&lt;br /&gt;
OWASP, while open to translations, do not have clear guidelines on how to translate OWASP contents and (AFAIK) there is no multi-language support in OWASP.org site. This is understandable as there is no formal project for internationalization so far. &lt;br /&gt;
&lt;br /&gt;
'''Oportunity and Effort'''&amp;lt;br&amp;gt;&lt;br /&gt;
This is great opportunity to make Spanish the first language on which the OWASP site and documentation is fully translated and at the same time share the experience with other people interested in the same objective, Bring OWASP to the world.  And this is something I’ve being pushing for some time ago and that could be possible “at once” via SoC 2008.&lt;br /&gt;
&lt;br /&gt;
I understand this is significant effort so to have it done I will count with the help of 6 people (friend of mine, all of them Security auditors with excellent English level) plus a few well known contributors from OWASP-Spanish effort, so the founding will be divided among the people involved in the same proportion of the work they do for the completion of this effort. This, to encourage delivery.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
* Team up with Larry Casey to implement Multilanguage support in OWASP.org Mediawiki.&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to start a new language translation for OWASP Document and Site Pages&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to implement internationalization and localization ([http://www.w3.org/International/ i18n]) on OWASP Software &lt;br /&gt;
* Full translation to Spanish of all the release-level document projects. Those are:&lt;br /&gt;
** Top 10 2007&lt;br /&gt;
** Guide 2 (Already translated)&lt;br /&gt;
** Testing Guide (Already Translated)&lt;br /&gt;
** Legal&lt;br /&gt;
** FAQ&lt;br /&gt;
* Full Translation of major sections of OWASP Site&lt;br /&gt;
** Project Main Pages (Release, Beta and Alpha levels for both documents and tools projects)&lt;br /&gt;
** Principles&lt;br /&gt;
** References Section&lt;br /&gt;
** Conferences&lt;br /&gt;
** News (Those currently displayed in OWASP site)&lt;br /&gt;
** About OWASP&lt;br /&gt;
* Evaluation of Spanish translation approach for WebGoat and WebScarab and delivery of this document to Bruce and Rogan for possible implementation in near future.&lt;br /&gt;
* Leverage for deploy of es.owasp.org, the domain already exists but is not redirecting correctly.&lt;br /&gt;
* Create a Communication strategy to help and keep track on new pages or changes in significant pages so all the translations are in sync.&lt;br /&gt;
&lt;br /&gt;
'''Out of Scope'''&amp;lt;br&amp;gt;&lt;br /&gt;
Translation of the following sections are NOT in Scope&lt;br /&gt;
* Local Chapters Pages&lt;br /&gt;
* Presentations&lt;br /&gt;
* Conferences&lt;br /&gt;
* Videos&lt;br /&gt;
* Blogs&lt;br /&gt;
* All the projects deliverables in Alpha and Beta Stages&lt;br /&gt;
* All the documentation “on development” like Guide Version 3.0&lt;br /&gt;
* Translation of Pages, documentation or tools to other language other than Spanish according to the stated in above section.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I’ve being part of contributions to OWASP documents on the translation arena since 2005 [https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html], a few of them by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish. It is time to make the full job done :).&lt;br /&gt;
&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver.&lt;br /&gt;
&lt;br /&gt;
== The Ruby on Rails Security Guide v2 ==&lt;br /&gt;
Heiko Webers&lt;br /&gt;
&lt;br /&gt;
The last security guide for Rails [http://www.owasp.org/index.php/Category:OWASP_Web_Application_Security_Put_Into_Practice] was a great success, with a lot of more secure web applications and continued awareness in the community of security issues. The Ruby on Rails Security Project [http://www.rorsecurity.info/] is the one and only source of information about Rails security topics, and I keep the community up-to-date with blog posts and conference talks in Europe. The Guide and the Project has been mentioned in several Rails books and web-sites.&lt;br /&gt;
&lt;br /&gt;
Version 1 of the Ruby on Rails Security Guide was sponsored by the SpoC 07, set the standard for OWASP programming language specific guides in terms of the topic outline and has been published as a book [http://www.lulu.com/content/1412042]. Nevertheless I'm convinced that a more compact design and a &amp;quot;question-and-answer&amp;quot; style of writing will reach an even larger audience. Of course the new Guide will still include answers to the OWASP Top Ten security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
A lot has changed since the publishing of the first Guide. Some new security holes have been found, there are new advises and most importantly Rails version 2.0 has been released. The new Ruby on Rails Security Guide aims at providing an up-to-date coding and configuration guide for the Rails community.&lt;br /&gt;
&lt;br /&gt;
In the new Rails Security Guide I'd like to&lt;br /&gt;
* update the entire book to match Rails 2.0&lt;br /&gt;
* cover new topics, including, but not limited to:&lt;br /&gt;
** Intranet and administration interface security,&lt;br /&gt;
** phishing,&lt;br /&gt;
** real-world attack situations,&lt;br /&gt;
** short excursus on server monitoring,&lt;br /&gt;
** the new CookieStore session management,&lt;br /&gt;
** vulnerabilities in popular plug-ins,&lt;br /&gt;
** denial-of-service attacks&lt;br /&gt;
* cover all OWASP Top Ten security vulnerabilities&lt;br /&gt;
* a more compact writing style, more examples and &amp;quot;questions-and-answers&amp;quot;&lt;br /&gt;
* introduce the OWASP and Rails security to a greater audience&lt;br /&gt;
&lt;br /&gt;
== OWASP Application Security Verification Standard ==&lt;br /&gt;
&lt;br /&gt;
*Mike&lt;br /&gt;
&lt;br /&gt;
'''OWASP Application Security Verification Standard Proposal'''&lt;br /&gt;
&lt;br /&gt;
'''Educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
The applicant is a hands-on senior professional services manager with a trademark of&lt;br /&gt;
developing creative solutions to complex application security-related technical problems. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a background in trusted product evaluation:&lt;br /&gt;
&lt;br /&gt;
*CC evaluation&lt;br /&gt;
*CC evidence development, including operating system test code development&lt;br /&gt;
*CC project management&lt;br /&gt;
*TCSEC evaluation&lt;br /&gt;
*TCSEC project management&lt;br /&gt;
*TEF management&lt;br /&gt;
*CCTL management&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in security-related software development and integration:&lt;br /&gt;
&lt;br /&gt;
*PKI toolkit development&lt;br /&gt;
*PK-E application integration&lt;br /&gt;
*Secure web portal application development&lt;br /&gt;
*Secure web portal integration&lt;br /&gt;
*Secure instant messaging application development, including three patents&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in cryptomodule testing:&lt;br /&gt;
&lt;br /&gt;
*FIPS 140 evaluation&lt;br /&gt;
*FIPS 140 evidence development&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
The applicant does not have experience in contributing to open communities.&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
OWASP is looking for a commercially-workable open standard for performing application security verification efforts. The problem is that there is a huge range in the coverage and level of rigor available in the market, and consumers have no way to tell the difference between someone just running a grep tool, and someone doing painstaking code review and manual testing. So, a standard is needed.&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s)'''&lt;br /&gt;
&lt;br /&gt;
The applicant’s proposal will address the above challenges as follows:&lt;br /&gt;
&lt;br /&gt;
*The applicant will define an evaluation framework that may be used to conduct OWASP Application Security Verification Standard certifications.&lt;br /&gt;
*The applicant will define an OWASP Application Security Verification Standard which defines levels that applications may be certified against.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
The applicant will carry out these activities. Please see below for a proposed list of specific deliverables.&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following deliverables:&lt;br /&gt;
&lt;br /&gt;
*'''Scheme Overview document.''' This will define the overall framework with roles, responsibilities, and processes.&lt;br /&gt;
*'''Evaluation and Certification document.''' This will describe the evaluation and certification process.&lt;br /&gt;
*'''Conditions for the Use of Trademarks.''' This will describe OWASP’s name, logo, and certificate may be used and referenced.&lt;br /&gt;
*'''Evaluation Report Content Requirements.''' This will describe the content requirements of evaluation reports.&lt;br /&gt;
*'''OWASP Application Security Verification Standard.''' This will define the levels that applications may be certified against.&lt;br /&gt;
*'''OWASP Application Security Verification Standard Appendix A.''' This will define the required content of the OWASP Application Security Verification Standard Security Policy.&lt;br /&gt;
*'''Policy Letter #1. Acceptance of Security Policies into OWASP Evaluation''' This will define the requirements to be listed as in evaluation on the OWASP web site.&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following rough project schedule:&lt;br /&gt;
&lt;br /&gt;
*2nd April. Project kickoff.&lt;br /&gt;
*15th June. Alpha Quality drafts of Scheme Overview document and of OWASP Application Security Verification Standard document completed.&lt;br /&gt;
*31st August. Project completion. Beta Quality drafts of all documents completed.&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
The long-term vision for the project is to normalize the range in the coverage and level of rigor available in the market when it comes to performing application security verification.&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected.'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a uniquely-qualified perspective given his experience with TCSEC, TTAP, CC, FIPS 140-1, and FIPS 140-2 evaluation programs, and his real-world perspective as a developer and integrator of security-related applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== GTK+ GUI for w3af project ==&lt;br /&gt;
&lt;br /&gt;
''Facundo Batista''&lt;br /&gt;
&lt;br /&gt;
'''Your educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
I'm Electronic Engineer with a Master in Engineer Innovation in&lt;br /&gt;
Bologna University, Italy. I live in Buenos Aires, Argentina, and love&lt;br /&gt;
reading books, playing tennis, and programming Python.&lt;br /&gt;
&lt;br /&gt;
I worked in a mobile company for six years, in the Network Management&lt;br /&gt;
department, then I was Chief Developer of a Mobile Content Provider,&lt;br /&gt;
and now I'm Solution Architect in Multimedia &amp;amp; Systems Integration in&lt;br /&gt;
Ericsson. Also I was professor in several universities, high schools&lt;br /&gt;
and other institutions.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
None, more than working in w3af. However, my proposal here is not&lt;br /&gt;
related to the security part of the product, but to its graphical&lt;br /&gt;
interface and usability.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I'm very involved in the free software and open source community. I'm&lt;br /&gt;
a Python Core Developer and member of the Python Software Foundation&lt;br /&gt;
by merit. I have a long history of talks given in several&lt;br /&gt;
international (PyCon, EuroPython) and national (a lot!) conferences. I&lt;br /&gt;
also teach Python in educational institutions, enterprises and as a&lt;br /&gt;
private instructor. I founded Python Argentina, the national users&lt;br /&gt;
groups, and I'm a very active member of it.&lt;br /&gt;
&lt;br /&gt;
I also lead other open source projects (SMPPy, SiGeFi, etc.) and&lt;br /&gt;
particpate in others (Docutils, w3af itself, etc.).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
My main objective is to minimize the effort and learning curve of&lt;br /&gt;
using w3af, providing a very usable graphical interface.&lt;br /&gt;
&lt;br /&gt;
Note that as the interface is cross platform, being usable also in the&lt;br /&gt;
win32 environment, it will help to popularize the w3af project.&lt;br /&gt;
&lt;br /&gt;
This will allow users without information security knowledge to verify&lt;br /&gt;
that their web applications are correctly programmed and configured.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
I will carry the following activities, detailed later in smaller steps:&lt;br /&gt;
&lt;br /&gt;
- Design and code new windows and interfaces to increase the functionality of the project.&lt;br /&gt;
&lt;br /&gt;
- Tuning of the process workflow, allowing a more intuitive way of working.&lt;br /&gt;
&lt;br /&gt;
- Visual polishing for a more pleasant and intuitive tool.&lt;br /&gt;
&lt;br /&gt;
- Usability tests and improvements.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
''New features implemented in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Local proxy to trap and modify requests and responses sent from a browser.&lt;br /&gt;
&lt;br /&gt;
- Manually send a request and analyze the response.&lt;br /&gt;
&lt;br /&gt;
- Manually create a fuzzed requests based on tokens, so user can construct easily differents HTTP request with a regex-like semantics.&lt;br /&gt;
&lt;br /&gt;
- Wizard to perform a vulnerability assessment.&lt;br /&gt;
&lt;br /&gt;
- Graphical display of site map and vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
- Reload a plugin after its edited from within the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Embebed tool to encode/decode URL/Base64 and to hash sha1/md5.&lt;br /&gt;
&lt;br /&gt;
- HTTP response side by side content compare.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Usability improvements in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Meetings with a usability expert that the w3af team leader has already contacted and worked with.&lt;br /&gt;
&lt;br /&gt;
- Kill all pending bugs and make a stable release.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Documentation:''&lt;br /&gt;
&lt;br /&gt;
- Users guide for the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Help system for the GUI itself&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
To provide the web application security community with a stable and fully &lt;br /&gt;
featured framework to perform all the tasks included in a penetration test&lt;br /&gt;
from within the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected'''&lt;br /&gt;
&lt;br /&gt;
w3af is one of the most active web application security projects;&lt;br /&gt;
the community that supports it is growing and we need the support of &lt;br /&gt;
already established organizations like OWASP to keep working at the &lt;br /&gt;
rate that we want to.&lt;br /&gt;
&lt;br /&gt;
== P006 OWASP Corporate Application Security Rating Guide and P025 OWASP Positive Security Project ==&lt;br /&gt;
&lt;br /&gt;
by Eduardo Vianna de Camargo Neves&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
A common approach on most companies is to increase the protection of their assets after the occurrence of a considerable impact. However some companies learned that a positive approach on IT Security is most effective and can reduce the financial costs on responses to security incidents. Benchmarking the application security practices on the corporate world will allow us to understand what steps are required to keep the IT environment protected, using this knowledge to create a public Security Rating Guide that can be used to support the establishment of a security baseline within the community.&lt;br /&gt;
&lt;br /&gt;
Moreover the information from this analysis can be used to support the development of a campaign to spread a positive security posture in the market. The liaison with companies that maintain good security practices  will help to start this initiative from a higher degree and involve several actors on the security stage for the same direction to a market were security is understood as a business value.&lt;br /&gt;
&lt;br /&gt;
'''Approach'''&lt;br /&gt;
&lt;br /&gt;
Assessing public materials from the Top 50 Companies and Top 50 Software Companies, a rating guide will be produced showing tangible metrics that are achieved by those companies and allow them to be considered secure enough on a comparison to a baseline of good practices. As a result the Corporate Application Security Rating Guide will be produced and published for the community and the deliverables used to support the development of the Positive Security Project with facts from a real analysis.&lt;br /&gt;
&lt;br /&gt;
'''Benefits'''&lt;br /&gt;
&lt;br /&gt;
The whole community will be benefited from these initiatives. With the adequate support from OWASP to maintain the projects active and liaise with big players on the market, we can expect the following:&lt;br /&gt;
&lt;br /&gt;
• The community will receive a Security Rating Guide that will allow them to compare their own security practices within the market. As this will be a public document, suppliers and buyers worldwide will share the same information allowing them to adequate the expectations on the usage of security services and tools.&lt;br /&gt;
&lt;br /&gt;
• The Security Rating Guide can be used as a marketing tool by the companies, allowing them to sell security as a business value and avoiding the old-fashion and inadequate FUD approach.&lt;br /&gt;
&lt;br /&gt;
• The knowledge and relationship developed during the production of the Security Rating Guide will allow us to produce the deliverables on Positive Security Project with real information, increasing the credibility of the initiative for the market.&lt;br /&gt;
&lt;br /&gt;
• The Security Rating Guide and the Positive Security Project can be walk in parallel, merging their information to support a concise and continuous marketing campaign to encourage a positive approach on the market.&lt;br /&gt;
&lt;br /&gt;
• As an open community free from commercial pressures, OWASP can use both projects to support the evaluation of security products for the market, allowing the organization to receive profits from these services and support current and future projects.&lt;br /&gt;
&lt;br /&gt;
'''Summarized Work Breakdown Structure (WBS)'''&lt;br /&gt;
&lt;br /&gt;
All the activities will be leaded by Eduardo V. C. Neves, which will be responsible as a single point of contact with the sponsors and to manage a team of compromised volunteers from OWASP community and participants from security communities and associations (i.e. ISSA, SANS and ISC2).&lt;br /&gt;
&lt;br /&gt;
The activities will be carried on WBS summarized bellow. Dates presented should be considered as deadlines for the activities:&lt;br /&gt;
&lt;br /&gt;
• Criteria establishment and definition of the Top 50 Companies and Top 50 Software Companies (April 11)&lt;br /&gt;
&lt;br /&gt;
• Assessment of public materials to support the ranking establishment (April 18)&lt;br /&gt;
&lt;br /&gt;
• Establishment of the Corporate Application Security Rating Guide (April 25)&lt;br /&gt;
&lt;br /&gt;
• Publishing of the Corporate Application Security Rating Guide on OWASP web site and promotion over adequate channels (i.e. publications, blogs and associations) (May 09) (1)&lt;br /&gt;
&lt;br /&gt;
• Criteria establishment and approval of marketing templates for Positive Security Project (May 16) (2)&lt;br /&gt;
&lt;br /&gt;
• Development of the Positive Security Project material (i.e. blog and marketing sheets) (May 30)&lt;br /&gt;
&lt;br /&gt;
• Liaison with the OWASP Members, Top 50 Companies and Top 50 Software Companies to present the project and negotiate their participation as supporters, sponsors or contributors. (June 27)&lt;br /&gt;
&lt;br /&gt;
• Update on Corporate Application Security Rating Guide, including their score on Positive Security approach (July 4)&lt;br /&gt;
&lt;br /&gt;
• Presentation of the Positive Security Project approach and Corporate Application Security Rating Guide on the market (July 31) (3)&lt;br /&gt;
&lt;br /&gt;
• Conference calls with team members to evaluate the results of the initiatives in all countries and produce project´s documents (i.e. lessons learned, update on marketing material and evaluation of alternative approaches for the future steps). (August 15)&lt;br /&gt;
&lt;br /&gt;
• Prepare project documentation and present to the OWASP community on the web site (August 31)&lt;br /&gt;
&lt;br /&gt;
''(1) Support from OWASP Foundation is required to liaise with companies and associations worldwide&lt;br /&gt;
&lt;br /&gt;
''(2) Support from OWASP Foundation and community are required to evaluate adequate marketing templates and translate original documents for their own languages''&lt;br /&gt;
&lt;br /&gt;
''(3) Support from OWASP community is required to spread the word on all countries were OWASP members are located.''&lt;br /&gt;
'''''&lt;br /&gt;
&lt;br /&gt;
'''Project Control'''&lt;br /&gt;
&lt;br /&gt;
The project will be managed following PRINCE2 Process Model and all control documents published for the OWASP community. The following mandatory project control documents are planned:&lt;br /&gt;
&lt;br /&gt;
• Project Initiation Document: To document project´s background, definition, objectives, approach, etc.&lt;br /&gt;
&lt;br /&gt;
• Communication Plan: To assure that OWASP Community are being continuous communicated about project status and deliverables achievement.&lt;br /&gt;
&lt;br /&gt;
• Highlight Report: To provide the OWASP Community with a summary of the project status, progress and potential problems or areas where help may be required.&lt;br /&gt;
&lt;br /&gt;
• End Project Report: To present project achievements. Should be considered the final project report.&lt;br /&gt;
&lt;br /&gt;
More documents may be included during project development to support the control and assure a high quality level (i.e. issue log, project approach).&lt;br /&gt;
&lt;br /&gt;
'''Long Range Plan'''&lt;br /&gt;
&lt;br /&gt;
Both projects should walk in parallel and be used as tools to support efforts to encourage and make the positive approach a reality on the IT Security field. These initiatives shall be supported by OWASP as long term plans and grow to a continuous world-wide campaign in this direction that must achieve big players on the market and be recognized by the community as a tool that must be used to evaluate security enabled companies and products. &lt;br /&gt;
&lt;br /&gt;
'''Why me?'''&lt;br /&gt;
&lt;br /&gt;
Can be me, you or anyone that carries these projects in a professional fashion and assure that all deliverables are being achieved. The most important parts is to make it happen, talk and get the support from reputable associations and large companies (OWASP Members are a good start) and lead it as a long range responsibility.&lt;br /&gt;
&lt;br /&gt;
I am running to win this project because I believe in all of this. I see both as very valuable initiatives that can help companies to make more business; people to get more jobs and the whole community to win in a scenario where our contributions on the security market are recognized as business tools.&lt;br /&gt;
&lt;br /&gt;
'''About me'''&lt;br /&gt;
&lt;br /&gt;
Information Security professional and enthusiastic with 15 years dedicated to achieve expressive results in the areas of IT, Information Security, Compliance and Project Management. A CISSP in good stand and Officer at the ISSA Brazilian Chapter, my professional career gave me extensive knowledge in several fields of Information Security with accumulated experience at consulting firms, as CSO at a world player company on consumer goods market and now as an entrepreneur at Latin American market.&lt;br /&gt;
&lt;br /&gt;
''Application security experience and accomplishments''&lt;br /&gt;
&lt;br /&gt;
My work experience is on Security Management, Risk Assessment, Business Continuity and Disaster Recovery, Security Awareness and other managed-related fields on our industry. I don’t have hands-on experience on application security and this is the main reason why I am running to be qualified on the project described bellow, where I believe that my skills can be used to achieve an excellent result for the community.&lt;br /&gt;
&lt;br /&gt;
''Participation and leadership in open communities''&lt;br /&gt;
&lt;br /&gt;
• Member of OWASP Brazil where I made some small contributions in a recent past.&lt;br /&gt;
&lt;br /&gt;
• Member of ABNT/CB-21/SC02 committee, Brazilian ISO representative for 27001 and 17799 standards&lt;br /&gt;
&lt;br /&gt;
• Officer of ISSA Brazil Chapter where I am responsible for the South Region and as the editor of Antebellum, the ISSA Brazil Journal&lt;br /&gt;
&lt;br /&gt;
• Founder and member of GISI-PR, an open community focused on discuss and promote Information Security initiatives within Paraná State, Brazil&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application ==&lt;br /&gt;
'''Name'''&lt;br /&gt;
&lt;br /&gt;
Michael Coates&lt;br /&gt;
&lt;br /&gt;
'''Project'''&lt;br /&gt;
&lt;br /&gt;
P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses, '''&lt;br /&gt;
&lt;br /&gt;
As critical applications continue to become more accessible and inter-connected, it is paramount that the information be protected. We must also realize that our defenses may not be perfect. Given enough time, attackers can identify security flaws in the design or implementation of an application. In addition to implementing layers of defense within an application, it is critical that we identify malicious individuals before they are able to identify any gaps in our defenses. The best place to identify malicious activity against the application is within the application itself.&lt;br /&gt;
Network based intrusion detection systems are not appropriate to handle the custom and intricate workings of an enterprise application and are ill-suited to detect attacks focusing on application logic such as authentication, access control, etc.  The application itself is the best place to identify and respond to malicious activity.&lt;br /&gt;
This project will create the framework which can be used to build a robust system of attack detection, analysis, and response within an enterprise application&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s), '''&lt;br /&gt;
&lt;br /&gt;
I plan to use a methodical approach throughout the creation of this resource. I will reference my own professional experience, OWASP resources, ESAPI, and academic materials to identify a robust set of potential attacks and identification methods. Thresholds will be recommended for each of the detected attacks. Each recommended threshold value and response recommendation will be accompanied with additional information to describe the purpose of the threshold and recommendation. This additional information will allow the reader to determine if the threshold is appropriate for their implementation.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities, '''&lt;br /&gt;
&lt;br /&gt;
I will complete the following activities:&lt;br /&gt;
1. Identify and define attack patterns against applications&lt;br /&gt;
2. Document points of detection within the application for the attack patterns &amp;amp; identify key information to log&lt;br /&gt;
3. Create thresholds for generating security alerts&lt;br /&gt;
4. Define recommended response actions for the security alerts&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress, '''&lt;br /&gt;
&lt;br /&gt;
April 2, 2008 - Project Begins&lt;br /&gt;
&lt;br /&gt;
April 2, 2008-April 12, 2008 - High level planning &amp;amp; design 	&lt;br /&gt;
&lt;br /&gt;
April 12, 2008-May 1, 2008 - Identify and define attack patterns against applications	&lt;br /&gt;
&lt;br /&gt;
May 1, 2008-June 1, 2008 - Document points of detection within the application for the attack patterns &amp;amp; identify key information to log	&lt;br /&gt;
&lt;br /&gt;
June 1, 2008-June 13, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
June 15, 2008 - Status Report	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Create thresholds for generating security alerts	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Define recommended response actions for the security alerts	&lt;br /&gt;
&lt;br /&gt;
Aug 16, 2008-Aug 30, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
Aug 31, 2008 - Project Complete	&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project, '''&lt;br /&gt;
&lt;br /&gt;
1.  I’d like to include a tiered type approach of thresholds and responses. This is would be similar to the approach used by FISMA of defining different controls for High, Medium, and Low systems.&lt;br /&gt;
&lt;br /&gt;
2. Building on item #1, I want to eventually include a system which lets the user provide information about their system.  This information could include rating or prioritizing different security concerns. a customized set of monitoring points, thresholds and response actions can be recommended for the application based on the provided data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About Me'''&lt;br /&gt;
&lt;br /&gt;
'''Education &amp;amp; Professional Background'''&lt;br /&gt;
&lt;br /&gt;
Masters of Science in Computer, Information and Network Security – DePaul University &lt;br /&gt;
(Expected Graduation 2009)&lt;br /&gt;
Bachelor of Science in Computer Science – University of Illinois&lt;br /&gt;
Extensive experience in conducting black and white box security reviews of complex applications and networks for major financial organizations and international telecoms. I also have experience working as the primary investigator of attacks against a multi-national organization with IDS sensors in networks throughout the world. In addition, I have experience working with several regulatory controls and security standards (FISMA, NIST, GLBA etc). My experience as an ethical hacker and incident responder puts me in an excellent position to tackle this project. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
I am a Senior Computer Security Engineer with Aspect Security where I perform security code reviews and application security testing against a variety of platforms. Prior to working with Aspect Security, I was heavily involved in the discovery and exploitation of application vulnerabilities during black box ethical hacking assessments for numerous clients.&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I am a member of OWASP and attend Chicago OWASP chapter meetings. I also attend ChiSec, an informal meet-up of security professionals in the Chicago area. In addition, I interact with the community through my security blog. http://michaelcoates.wordpress.com. &lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected. '''&lt;br /&gt;
&lt;br /&gt;
I created a similar framework while working within a Security Operation Center. I created attack scenarios, identified relevant IDS events, defined thresholds and appropriate response action for the Security analysts.&lt;br /&gt;
&lt;br /&gt;
'''Requested Reviewer - Eric Sheridan, Application Security Consultant at Aspect Security, Inc.'''&lt;br /&gt;
&lt;br /&gt;
Eric Sheridan is an Application Security Consultant at Aspect Security, a consulting services company specializing in application security. At Aspect Security, Eric specializes in execution of security verification assessments and the establishment of security activities throughout the development lifecycle. In addition, Eric is an instructor in Aspect’s portfolio of Application Security Courses. Eric is also an active participant in OWASP whose contributions include work with projects such as WebGoat, Stinger, CSRFGuard, CSRFTester, and the SASAP project from OWASP SPoC 2007. Eric was also a featured speaker at the 2007 OWASP/WASC San Jose conference.&lt;br /&gt;
&lt;br /&gt;
Contact Information: eric dot sheridan 'at' owasp dot org&lt;br /&gt;
&lt;br /&gt;
== OWASP Interceptor Project - 2008 Update ==&lt;br /&gt;
&lt;br /&gt;
by Justin Derry&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_Interceptor_Project&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
The OWASP Interceptor project was originally written by myself and donated to the OWASP project. Since it has been online numerous people have downloaded the tools and used the code/toolkit. Currently the industry has very limited “XML” or SOAP client testing tools that are designed specifically to perform XML interception and manipulation. The Objective of the Interceptor project is to provide a strong tool for performing XML penetration tests against Web Service (or XML/SOAP) endpoints. The tool should not replace other proxy interception tools such as Charles, Web Scarab and so on, but be purely focused on handling and reading XML structures from clients.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Interceptor tool includes a “swiss-army” knife of features that will help with decoding/hash generation and interpretation of XML code. The key objective is to make a tool that can assist with the collection, inspection and attack replay of XML requests against service endpoints. This year it’s time for an update. The tool doesn’t run on Vista and needs a number of back-end features addressed as well as some help files etc. (Help to get the tool out of BETA status).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Objectives this year'''&lt;br /&gt;
&lt;br /&gt;
This year I see the following objectives in the application code base.&lt;br /&gt;
•	Get the Interface to run on all Window Platforms (.NET) Win2000, XP and Vista;&lt;br /&gt;
&lt;br /&gt;
•	Update the TCP handle libraries to be faster&lt;br /&gt;
&lt;br /&gt;
•	Update the XML Parser engine to support the latest structures&lt;br /&gt;
&lt;br /&gt;
•	Provide a “default” attack database of known XML attack methods (this is a big one)&lt;br /&gt;
&lt;br /&gt;
•	Write a number of help files on how to use the tool&lt;br /&gt;
&lt;br /&gt;
•	Update the toolkit BASE64 Decoder, XML Generators etc with further tools&lt;br /&gt;
&lt;br /&gt;
•	Write a better “reporting” engine to show the result of simulated attack responses&lt;br /&gt;
&lt;br /&gt;
•	Better HTTP support for Manipulation, Authentication and Header Injection etc&lt;br /&gt;
&lt;br /&gt;
•	Better support for interception and handling AJAX XML requests&lt;br /&gt;
&lt;br /&gt;
These are the core features I would like to introduce, with also further to probably come as a part of the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&lt;br /&gt;
&lt;br /&gt;
The current development cycle stopped due to limited time and the need to purchase the IDE tools to develop the interface in .NET. As a Summer of Code 2008 sponsored project we can get the IDE interface tools to implement “Vista” features that will see the tool run on all .NET platforms (Win2000, XP and Vista). Recent changes in my job will allow me to spend more time on developing the toolkit.&lt;br /&gt;
&lt;br /&gt;
Over a number of years I have been involved with OWASP, whilst most recently getting involved with running the OWASP Australia Security Conference for 2008, as well as the Brisbane Chapter. I am also working in the Asia Pacific RIM to further increase the awareness of OWASP and Application Security. My Conference duties for the year have finished up (till planning starts again in a couple of months) so my time can be invested in updating the toolkit.&lt;br /&gt;
&lt;br /&gt;
I believe during the previous years, i have shown OWASP that i am willing and able to produce a quality outcome and i am prepared to put the effort into OWASP to acheive the goals set out for this project. &lt;br /&gt;
&lt;br /&gt;
Some of the Sponsorship money for the project would go to purchasing a specific toolkit for the UI. (The UI is important simply because we want the application to be user friendly). Xceed Components provide a Smart UI as well as some of the decoding and compression features the tool needs. This would require us to approach them upfront for a “free” licence or use some of the Sponsorship money to buy the toolkit. But we can tackle that problem when we come to it.&lt;br /&gt;
&lt;br /&gt;
== SQL Injector Benchmarking Project (SQLiBENCH) ==&lt;br /&gt;
&lt;br /&gt;
by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
'''Prelude'''&lt;br /&gt;
&lt;br /&gt;
There're a lot of and great open source tools (takeover/dumpers/hybrid) for taking advantage of an sql injection vulnerability both used by web application security specialists and attackers. &lt;br /&gt;
Techniques used, databases supported, algorithms employed and abilities implemented by these &amp;quot;sql injectors&amp;quot; greatly varies. Standardization is one of the abstract goals of OWASP and we think it's important to standardize general vulnerability techniques exists in web applications and one of the biggest one is sql manipulation. &lt;br /&gt;
In our effort, we aim to produce a standardization of techniques used in exploiting sql injection by automatic tools. &lt;br /&gt;
&lt;br /&gt;
'''Proposal'''&lt;br /&gt;
&lt;br /&gt;
The goal of the project is to create a detailed set of benchmarking criterias for automatic sql injection tools and applying these to a set of open source sql injectors, producing analysis/benchmarking reports.&lt;br /&gt;
Additionaly, in a semi-academic manner, algorithms used by several sql injectors will be analyzed both implementation and complexity vise.&lt;br /&gt;
&lt;br /&gt;
'''Deliverables And Project Schedule Milestones'''&lt;br /&gt;
&lt;br /&gt;
Two set of documents will be produced. One of them will include the benchmarking criterias and the other will comprise of analysis of selected sql injectors against the benchmarking criterias.&lt;br /&gt;
Moreover, an interactive visual data flow diagram, giving hints to testers about which tool should be used under which circumstances, will be implemented with web-based technologies such as jquery library. &lt;br /&gt;
&lt;br /&gt;
April 03    Project Kickoff&lt;br /&gt;
&lt;br /&gt;
April 03-30 Determination of the benchmarking criterias &lt;br /&gt;
&lt;br /&gt;
May   01-15 Producing a test environment image with 5-6 rdbms (MSSQL Express, Oracle Express, DB2 Express, MySQL, PgSQL, etc.) and a vulnerable application (which will support different sql injection types, databases and include logging capabilities)&lt;br /&gt;
&lt;br /&gt;
May   15-31 Selecting and installing automatic sql injectors onto the test system and starting to use them on vulnerable application&lt;br /&gt;
&lt;br /&gt;
June  01-30 Analysing tools and applying benchmarking criterias, contacting the authors as we proceed &lt;br /&gt;
&lt;br /&gt;
July  01-31 Producing reports for benchmarking criterias and tool analysis&lt;br /&gt;
&lt;br /&gt;
'''About Us'''&lt;br /&gt;
&lt;br /&gt;
We're part of OWASP-Turkey. [http://www.h-labs.org Mesut Timur] is a junior in the Computer Engineering Dept. of [http://www.gyte.edu.tr University of GYTE] and [http://www.webguvenligi.org Bedirhan Urgun] is a web/application security specialist in [http://www.uekae.tubitak.gov.tr TUBITAK-UEKAE].&lt;br /&gt;
&lt;br /&gt;
== OWASP-WeBekci Project ==&lt;br /&gt;
&lt;br /&gt;
by Bunyamin Demir&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_Webekci_Project&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
Web application firewalls (WAF) are gaining importance among the information security technologies designed to protect web sites from attack. WAF solutions prevent attacks that network firewalls and intrusion detection systems can't and they require no modification of application source code. ModSecurity [http://www.modsecurity.org/] is an open source web application firewall that runs as an Apache module. It is an embeddable web application firewall and it provides protection from a range of attacks against web applications. It is an open source project available to everyone; it however does not come with an admin panel. &lt;br /&gt;
&lt;br /&gt;
I decided to provide this essential tool with a control panel which I believe will ease and thus encourage its usage.&lt;br /&gt;
&lt;br /&gt;
ModSecurity allows for HTTP traffic monitoring and real-time analysis with no changes to existing infrastructure. My main goal is to analyze attacks and generate rules to change the configuration of the ModSecurity accordingly.&lt;br /&gt;
&lt;br /&gt;
ModSecurity  has a feature called “flexible rule engine” as its heart of Attack Prevention capability . It uses ModSecurity’s “Rule Language,” (a programming language designed to work with HTTP transaction data). It is easy to use and flexible; yet the system administrators need to learn its own rules to create what is called “Certified ModSecurity Rules” to be implemented. My control panel will automate the major code-generation in Rule Language. &lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&lt;br /&gt;
&lt;br /&gt;
* '''Configuration'''        : Most of the configuration parameters will be managed through the web interface&lt;br /&gt;
* '''Rule Generator'''       : Basic rules will be generated using the web interface&lt;br /&gt;
* '''Core Rule Integration''': Core rules will be added to the database for use&lt;br /&gt;
* '''Logging and Reporting''': Apache error log and modsec_audit log will be parsed and presented to the user thru the web interface&lt;br /&gt;
* '''DB Support'''           : MySQL&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
Being a SpoC2007 project, it couldn't be implemented mainly due to a job change and therefore lack of time. With the help of Bedirhan Urgun we'll be able to produce a quality web admin panel GUI for a same host modsec installation infrastructure. We are both part of OWASP Turkey [http://www.owasp.org/index.php/Turkey] and tried to produce a great deal of awareness both about web security and OWASP with both documents/chapter meetings/email list and mini-conferences.&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26965</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26965"/>
				<updated>2008-03-23T14:10:30Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Bunyamin Demir – OWASP WeBekci Project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli &lt;br /&gt;
* Proposal: Make [[OWASP ASDR Project|OWASP ASDR Project]] a release quality document.&lt;br /&gt;
&lt;br /&gt;
The ASDR is a reference volume that contains basic information about all the foundational topics in application security. It intends to replace and refresh [[OWASP Honeycomb Project|Honeycomb Project]] with a new structure for articles and relationship between categories, thus making it a release quality doc.&lt;br /&gt;
&lt;br /&gt;
This idea raised when finished the [[Attack|Attack Reference Guide]] for [[OWASP Spring Of Code 2007|OWASP Spring Of Code 2007]], where it was identified that OWASP reference articles need some special attention. Jeff Williams is totally supporting this project.&lt;br /&gt;
&lt;br /&gt;
We already have defined which type of article we should include on Desk Reference, as follows:&lt;br /&gt;
* [[:Category:Principle|Principles]]&lt;br /&gt;
* [[:Category:Threat_Agent|Threat Agents]]&lt;br /&gt;
* [[:Category:Attack|Attacks]]&lt;br /&gt;
* [[:Category:Vulnerability|Vulnerabilities]]&lt;br /&gt;
* [[:Category:Countermeasure|Countermeasures]]&lt;br /&gt;
* [[:Category:Technical Impact|Technical Impacts]]&lt;br /&gt;
* [[:Category:Business Impact|Business Impacts]]&lt;br /&gt;
&lt;br /&gt;
*Road Map: A complete project roadmap can be found on '''[[ASDR Table of Contents|ASDR Table of Contents]]'''. Basically, the following activities should be performed, some of them already started:&lt;br /&gt;
** Define articles templates for each reference type&lt;br /&gt;
** Define subcategories for articles classification&lt;br /&gt;
** Compile first DRAFT version of ASDR Book&lt;br /&gt;
** Articles development &amp;amp; Call for Volunteers&lt;br /&gt;
** Articles revision&lt;br /&gt;
** First version of OWASP ASDR book&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali (aka nTze)&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Security Software Life Cycle'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;br /&gt;
&lt;br /&gt;
== OWASP Classic ASP Security Project  ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
I am interested in making P018 - OWASP Classic ASP Security Project happen, Classic ASP 2.0 and 3.0 applications are still largely used as this technology is more than 10 years old and was largely used. there are thousands of sites on the wild that need guidance on the security arena. This is where OWASP can come up and provide help for “making the Web a better place” and continue spreading the word on security. I have always be a passionate of the technology (regardless of its inconveniences such as being old and DLL-hell prone) and I am really exited on the idea of sharing my knowledge of this area to the world and what best that though OWASP.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
Create a secure framework for Classic ASP application by complementing existing OWASP projects with documentation for this particular technology and the creation of security libraries. More specifically:&lt;br /&gt;
* Creation of a Common Object Repository for ASP applications based on OWASP ESAPI Project including objects and/or references to libraries for security applications all this aligned with OWASP Top10 and OWASP Guide .&lt;br /&gt;
* Create Documentation aligned to OWASP Code Review Project Checklist providing additional technology-specific checks.&lt;br /&gt;
* Addition of expression for Code Review Tool to support Classic ASP applications.&lt;br /&gt;
* Implementation of Version 1 of Stinger for ASP either by using an installable COM library or ISAPI.&lt;br /&gt;
* This same module will compliment the OWASP Validation Documentation Project.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver. &lt;br /&gt;
&lt;br /&gt;
Also I’ve had close contact with OWASP since 2005&lt;br /&gt;
[https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html] by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish.&lt;br /&gt;
&lt;br /&gt;
== Internationalization Guidelines and OWASP-Spanish Project ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
The main goal of OWASP is to spread the word about security (“Our mission is to make application security &amp;quot;visible,&amp;quot; so that people and organizations can make informed decisions about application security risks.”) and OWASP has done great work so far :). And now it’s time for a next big step.&lt;br /&gt;
&lt;br /&gt;
The number of native and secondary speakers in the world for Chinese, Spanish, French, Russian, Arabic and Indi languages are estimated in similar number to English speaking or even more (Some References at [http://en.wikipedia.org/wiki/Ethnologue_list_of_most_spoken_languages Ethnologue], [http://encarta.msn.com/media_701500404/Languages_Spoken_by_More_Than_10_Million_People.html Encarta], [http://en.wikipedia.org/wiki/List_of_languages_by_number_of_native_speakers Wikipedia]). I think is a good time for OWASP to reach those that do not speak English to have full access to all the OWASP materials, not just a couple of documents.&lt;br /&gt;
&lt;br /&gt;
OWASP, while open to translations, do not have clear guidelines on how to translate OWASP contents and (AFAIK) there is no multi-language support in OWASP.org site. This is understandable as there is no formal project for internationalization so far. &lt;br /&gt;
&lt;br /&gt;
'''Oportunity and Effort'''&amp;lt;br&amp;gt;&lt;br /&gt;
This is great opportunity to make Spanish the first language on which the OWASP site and documentation is fully translated and at the same time share the experience with other people interested in the same objective, Bring OWASP to the world.  And this is something I’ve being pushing for some time ago and that could be possible “at once” via SoC 2008.&lt;br /&gt;
&lt;br /&gt;
I understand this is significant effort so to have it done I will count with the help of 6 people (friend of mine, all of them Security auditors with excellent English level) plus a few well known contributors from OWASP-Spanish effort, so the founding will be divided among the people involved in the same proportion of the work they do for the completion of this effort. This, to encourage delivery.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
* Team up with Larry Casey to implement Multilanguage support in OWASP.org Mediawiki.&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to start a new language translation for OWASP Document and Site Pages&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to implement internationalization and localization ([http://www.w3.org/International/ i18n]) on OWASP Software &lt;br /&gt;
* Full translation to Spanish of all the release-level document projects. Those are:&lt;br /&gt;
** Top 10 2007&lt;br /&gt;
** Guide 2 (Already translated)&lt;br /&gt;
** Testing Guide (Already Translated)&lt;br /&gt;
** Legal&lt;br /&gt;
** FAQ&lt;br /&gt;
* Full Translation of major sections of OWASP Site&lt;br /&gt;
** Project Main Pages (Release, Beta and Alpha levels for both documents and tools projects)&lt;br /&gt;
** Principles&lt;br /&gt;
** References Section&lt;br /&gt;
** Conferences&lt;br /&gt;
** News (Those currently displayed in OWASP site)&lt;br /&gt;
** About OWASP&lt;br /&gt;
* Evaluation of Spanish translation approach for WebGoat and WebScarab and delivery of this document to Bruce and Rogan for possible implementation in near future.&lt;br /&gt;
* Leverage for deploy of es.owasp.org, the domain already exists but is not redirecting correctly.&lt;br /&gt;
* Create a Communication strategy to help and keep track on new pages or changes in significant pages so all the translations are in sync.&lt;br /&gt;
&lt;br /&gt;
'''Out of Scope'''&amp;lt;br&amp;gt;&lt;br /&gt;
Translation of the following sections are NOT in Scope&lt;br /&gt;
* Local Chapters Pages&lt;br /&gt;
* Presentations&lt;br /&gt;
* Conferences&lt;br /&gt;
* Videos&lt;br /&gt;
* Blogs&lt;br /&gt;
* All the projects deliverables in Alpha and Beta Stages&lt;br /&gt;
* All the documentation “on development” like Guide Version 3.0&lt;br /&gt;
* Translation of Pages, documentation or tools to other language other than Spanish according to the stated in above section.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I’ve being part of contributions to OWASP documents on the translation arena since 2005 [https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html], a few of them by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish. It is time to make the full job done :).&lt;br /&gt;
&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver.&lt;br /&gt;
&lt;br /&gt;
== The Ruby on Rails Security Guide v2 ==&lt;br /&gt;
Heiko Webers&lt;br /&gt;
&lt;br /&gt;
The last security guide for Rails [http://www.owasp.org/index.php/Category:OWASP_Web_Application_Security_Put_Into_Practice] was a great success, with a lot of more secure web applications and continued awareness in the community of security issues. The Ruby on Rails Security Project [http://www.rorsecurity.info/] is the one and only source of information about Rails security topics, and I keep the community up-to-date with blog posts and conference talks in Europe. The Guide and the Project has been mentioned in several Rails books and web-sites.&lt;br /&gt;
&lt;br /&gt;
Version 1 of the Ruby on Rails Security Guide was sponsored by the SpoC 07, set the standard for OWASP programming language specific guides in terms of the topic outline and has been published as a book [http://www.lulu.com/content/1412042]. Nevertheless I'm convinced that a more compact design and a &amp;quot;question-and-answer&amp;quot; style of writing will reach an even larger audience. Of course the new Guide will still include answers to the OWASP Top Ten security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
A lot has changed since the publishing of the first Guide. Some new security holes have been found, there are new advises and most importantly Rails version 2.0 has been released. The new Ruby on Rails Security Guide aims at providing an up-to-date coding and configuration guide for the Rails community.&lt;br /&gt;
&lt;br /&gt;
In the new Rails Security Guide I'd like to&lt;br /&gt;
* update the entire book to match Rails 2.0&lt;br /&gt;
* cover new topics, including, but not limited to:&lt;br /&gt;
** Intranet and administration interface security,&lt;br /&gt;
** phishing,&lt;br /&gt;
** real-world attack situations,&lt;br /&gt;
** short excursus on server monitoring,&lt;br /&gt;
** the new CookieStore session management,&lt;br /&gt;
** vulnerabilities in popular plug-ins,&lt;br /&gt;
** denial-of-service attacks&lt;br /&gt;
* cover all OWASP Top Ten security vulnerabilities&lt;br /&gt;
* a more compact writing style, more examples and &amp;quot;questions-and-answers&amp;quot;&lt;br /&gt;
* introduce the OWASP and Rails security to a greater audience&lt;br /&gt;
&lt;br /&gt;
== OWASP Application Security Verification Standard ==&lt;br /&gt;
&lt;br /&gt;
*Mike&lt;br /&gt;
&lt;br /&gt;
'''OWASP Application Security Verification Standard Proposal'''&lt;br /&gt;
&lt;br /&gt;
'''Educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
The applicant is a hands-on senior professional services manager with a trademark of&lt;br /&gt;
developing creative solutions to complex application security-related technical problems. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a background in trusted product evaluation:&lt;br /&gt;
&lt;br /&gt;
*CC evaluation&lt;br /&gt;
*CC evidence development, including operating system test code development&lt;br /&gt;
*CC project management&lt;br /&gt;
*TCSEC evaluation&lt;br /&gt;
*TCSEC project management&lt;br /&gt;
*TEF management&lt;br /&gt;
*CCTL management&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in security-related software development and integration:&lt;br /&gt;
&lt;br /&gt;
*PKI toolkit development&lt;br /&gt;
*PK-E application integration&lt;br /&gt;
*Secure web portal application development&lt;br /&gt;
*Secure web portal integration&lt;br /&gt;
*Secure instant messaging application development, including three patents&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in cryptomodule testing:&lt;br /&gt;
&lt;br /&gt;
*FIPS 140 evaluation&lt;br /&gt;
*FIPS 140 evidence development&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
The applicant does not have experience in contributing to open communities.&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
OWASP is looking for a commercially-workable open standard for performing application security verification efforts. The problem is that there is a huge range in the coverage and level of rigor available in the market, and consumers have no way to tell the difference between someone just running a grep tool, and someone doing painstaking code review and manual testing. So, a standard is needed.&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s)'''&lt;br /&gt;
&lt;br /&gt;
The applicant’s proposal will address the above challenges as follows:&lt;br /&gt;
&lt;br /&gt;
*The applicant will define an evaluation framework that may be used to conduct OWASP Application Security Verification Standard certifications.&lt;br /&gt;
*The applicant will define an OWASP Application Security Verification Standard which defines levels that applications may be certified against.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
The applicant will carry out these activities. Please see below for a proposed list of specific deliverables.&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following deliverables:&lt;br /&gt;
&lt;br /&gt;
*'''Scheme Overview document.''' This will define the overall framework with roles, responsibilities, and processes.&lt;br /&gt;
*'''Evaluation and Certification document.''' This will describe the evaluation and certification process.&lt;br /&gt;
*'''Conditions for the Use of Trademarks.''' This will describe OWASP’s name, logo, and certificate may be used and referenced.&lt;br /&gt;
*'''Evaluation Report Content Requirements.''' This will describe the content requirements of evaluation reports.&lt;br /&gt;
*'''OWASP Application Security Verification Standard.''' This will define the levels that applications may be certified against.&lt;br /&gt;
*'''OWASP Application Security Verification Standard Appendix A.''' This will define the required content of the OWASP Application Security Verification Standard Security Policy.&lt;br /&gt;
*'''Policy Letter #1. Acceptance of Security Policies into OWASP Evaluation''' This will define the requirements to be listed as in evaluation on the OWASP web site.&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following rough project schedule:&lt;br /&gt;
&lt;br /&gt;
*2nd April. Project kickoff.&lt;br /&gt;
*15th June. Alpha Quality drafts of Scheme Overview document and of OWASP Application Security Verification Standard document completed.&lt;br /&gt;
*31st August. Project completion. Beta Quality drafts of all documents completed.&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
The long-term vision for the project is to normalize the range in the coverage and level of rigor available in the market when it comes to performing application security verification.&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected.'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a uniquely-qualified perspective given his experience with TCSEC, TTAP, CC, FIPS 140-1, and FIPS 140-2 evaluation programs, and his real-world perspective as a developer and integrator of security-related applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== GTK+ GUI for w3af project ==&lt;br /&gt;
&lt;br /&gt;
''Facundo Batista''&lt;br /&gt;
&lt;br /&gt;
'''Your educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
I'm Electronic Engineer with a Master in Engineer Innovation in&lt;br /&gt;
Bologna University, Italy. I live in Buenos Aires, Argentina, and love&lt;br /&gt;
reading books, playing tennis, and programming Python.&lt;br /&gt;
&lt;br /&gt;
I worked in a mobile company for six years, in the Network Management&lt;br /&gt;
department, then I was Chief Developer of a Mobile Content Provider,&lt;br /&gt;
and now I'm Solution Architect in Multimedia &amp;amp; Systems Integration in&lt;br /&gt;
Ericsson. Also I was professor in several universities, high schools&lt;br /&gt;
and other institutions.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
None, more than working in w3af. However, my proposal here is not&lt;br /&gt;
related to the security part of the product, but to its graphical&lt;br /&gt;
interface and usability.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I'm very involved in the free software and open source community. I'm&lt;br /&gt;
a Python Core Developer and member of the Python Software Foundation&lt;br /&gt;
by merit. I have a long history of talks given in several&lt;br /&gt;
international (PyCon, EuroPython) and national (a lot!) conferences. I&lt;br /&gt;
also teach Python in educational institutions, enterprises and as a&lt;br /&gt;
private instructor. I founded Python Argentina, the national users&lt;br /&gt;
groups, and I'm a very active member of it.&lt;br /&gt;
&lt;br /&gt;
I also lead other open source projects (SMPPy, SiGeFi, etc.) and&lt;br /&gt;
particpate in others (Docutils, w3af itself, etc.).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
My main objective is to minimize the effort and learning curve of&lt;br /&gt;
using w3af, providing a very usable graphical interface.&lt;br /&gt;
&lt;br /&gt;
Note that as the interface is cross platform, being usable also in the&lt;br /&gt;
win32 environment, it will help to popularize the w3af project.&lt;br /&gt;
&lt;br /&gt;
This will allow users without information security knowledge to verify&lt;br /&gt;
that their web applications are correctly programmed and configured.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
I will carry the following activities, detailed later in smaller steps:&lt;br /&gt;
&lt;br /&gt;
- Design and code new windows and interfaces to increase the functionality of the project.&lt;br /&gt;
&lt;br /&gt;
- Tuning of the process workflow, allowing a more intuitive way of working.&lt;br /&gt;
&lt;br /&gt;
- Visual polishing for a more pleasant and intuitive tool.&lt;br /&gt;
&lt;br /&gt;
- Usability tests and improvements.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
''New features implemented in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Local proxy to trap and modify requests and responses sent from a browser.&lt;br /&gt;
&lt;br /&gt;
- Manually send a request and analyze the response.&lt;br /&gt;
&lt;br /&gt;
- Manually create a fuzzed requests based on tokens, so user can construct easily differents HTTP request with a regex-like semantics.&lt;br /&gt;
&lt;br /&gt;
- Wizard to perform a vulnerability assessment.&lt;br /&gt;
&lt;br /&gt;
- Graphical display of site map and vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
- Reload a plugin after its edited from within the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Embebed tool to encode/decode URL/Base64 and to hash sha1/md5.&lt;br /&gt;
&lt;br /&gt;
- HTTP response side by side content compare.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Usability improvements in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Meetings with a usability expert that the w3af team leader has already contacted and worked with.&lt;br /&gt;
&lt;br /&gt;
- Kill all pending bugs and make a stable release.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Documentation:''&lt;br /&gt;
&lt;br /&gt;
- Users guide for the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Help system for the GUI itself&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
To provide the web application security community with a stable and fully &lt;br /&gt;
featured framework to perform all the tasks included in a penetration test&lt;br /&gt;
from within the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected'''&lt;br /&gt;
&lt;br /&gt;
w3af is one of the most active web application security projects;&lt;br /&gt;
the community that supports it is growing and we need the support of &lt;br /&gt;
already established organizations like OWASP to keep working at the &lt;br /&gt;
rate that we want to.&lt;br /&gt;
&lt;br /&gt;
== P006 OWASP Corporate Application Security Rating Guide and P025 OWASP Positive Security Project ==&lt;br /&gt;
&lt;br /&gt;
by Eduardo Vianna de Camargo Neves&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
A common approach on most companies is to increase the protection of their assets after the occurrence of a considerable impact. However some companies learned that a positive approach on IT Security is most effective and can reduce the financial costs on responses to security incidents. Benchmarking the application security practices on the corporate world will allow us to understand what steps are required to keep the IT environment protected, using this knowledge to create a public Security Rating Guide that can be used to support the establishment of a security baseline within the community.&lt;br /&gt;
&lt;br /&gt;
Moreover the information from this analysis can be used to support the development of a campaign to spread a positive security posture in the market. The liaison with companies that maintain good security practices  will help to start this initiative from a higher degree and involve several actors on the security stage for the same direction to a market were security is understood as a business value.&lt;br /&gt;
&lt;br /&gt;
'''Approach'''&lt;br /&gt;
&lt;br /&gt;
Assessing public materials from the Top 50 Companies and Top 50 Software Companies, a rating guide will be produced showing tangible metrics that are achieved by those companies and allow them to be considered secure enough on a comparison to a baseline of good practices. As a result the Corporate Application Security Rating Guide will be produced and published for the community and the deliverables used to support the development of the Positive Security Project with facts from a real analysis.&lt;br /&gt;
&lt;br /&gt;
'''Benefits'''&lt;br /&gt;
&lt;br /&gt;
The whole community will be benefited from these initiatives. With the adequate support from OWASP to maintain the projects active and liaise with big players on the market, we can expect the following:&lt;br /&gt;
&lt;br /&gt;
• The community will receive a Security Rating Guide that will allow them to compare their own security practices within the market. As this will be a public document, suppliers and buyers worldwide will share the same information allowing them to adequate the expectations on the usage of security services and tools.&lt;br /&gt;
&lt;br /&gt;
• The Security Rating Guide can be used as a marketing tool by the companies, allowing them to sell security as a business value and avoiding the old-fashion and inadequate FUD approach.&lt;br /&gt;
&lt;br /&gt;
• The knowledge and relationship developed during the production of the Security Rating Guide will allow us to produce the deliverables on Positive Security Project with real information, increasing the credibility of the initiative for the market.&lt;br /&gt;
&lt;br /&gt;
• The Security Rating Guide and the Positive Security Project can be walk in parallel, merging their information to support a concise and continuous marketing campaign to encourage a positive approach on the market.&lt;br /&gt;
&lt;br /&gt;
• As an open community free from commercial pressures, OWASP can use both projects to support the evaluation of security products for the market, allowing the organization to receive profits from these services and support current and future projects.&lt;br /&gt;
&lt;br /&gt;
'''Summarized Work Breakdown Structure (WBS)'''&lt;br /&gt;
&lt;br /&gt;
All the activities will be leaded by Eduardo V. C. Neves, which will be responsible as a single point of contact with the sponsors and to manage a team of compromised volunteers from OWASP community and participants from security communities and associations (i.e. ISSA, SANS and ISC2).&lt;br /&gt;
&lt;br /&gt;
The activities will be carried on WBS summarized bellow. Dates presented should be considered as deadlines for the activities:&lt;br /&gt;
&lt;br /&gt;
• Criteria establishment and definition of the Top 50 Companies and Top 50 Software Companies (April 11)&lt;br /&gt;
&lt;br /&gt;
• Assessment of public materials to support the ranking establishment (April 18)&lt;br /&gt;
&lt;br /&gt;
• Establishment of the Corporate Application Security Rating Guide (April 25)&lt;br /&gt;
&lt;br /&gt;
• Publishing of the Corporate Application Security Rating Guide on OWASP web site and promotion over adequate channels (i.e. publications, blogs and associations) (May 09) (1)&lt;br /&gt;
&lt;br /&gt;
• Criteria establishment and approval of marketing templates for Positive Security Project (May 16) (2)&lt;br /&gt;
&lt;br /&gt;
• Development of the Positive Security Project material (i.e. blog and marketing sheets) (May 30)&lt;br /&gt;
&lt;br /&gt;
• Liaison with the OWASP Members, Top 50 Companies and Top 50 Software Companies to present the project and negotiate their participation as supporters, sponsors or contributors. (June 27)&lt;br /&gt;
&lt;br /&gt;
• Update on Corporate Application Security Rating Guide, including their score on Positive Security approach (July 4)&lt;br /&gt;
&lt;br /&gt;
• Presentation of the Positive Security Project approach and Corporate Application Security Rating Guide on the market (July 31) (3)&lt;br /&gt;
&lt;br /&gt;
• Conference calls with team members to evaluate the results of the initiatives in all countries and produce project´s documents (i.e. lessons learned, update on marketing material and evaluation of alternative approaches for the future steps). (August 15)&lt;br /&gt;
&lt;br /&gt;
• Prepare project documentation and present to the OWASP community on the web site (August 31)&lt;br /&gt;
&lt;br /&gt;
''(1) Support from OWASP Foundation is required to liaise with companies and associations worldwide&lt;br /&gt;
&lt;br /&gt;
''(2) Support from OWASP Foundation and community are required to evaluate adequate marketing templates and translate original documents for their own languages''&lt;br /&gt;
&lt;br /&gt;
''(3) Support from OWASP community is required to spread the word on all countries were OWASP members are located.''&lt;br /&gt;
'''''&lt;br /&gt;
&lt;br /&gt;
'''Project Control'''&lt;br /&gt;
&lt;br /&gt;
The project will be managed following PRINCE2 Process Model and all control documents published for the OWASP community. The following mandatory project control documents are planned:&lt;br /&gt;
&lt;br /&gt;
• Project Initiation Document: To document project´s background, definition, objectives, approach, etc.&lt;br /&gt;
&lt;br /&gt;
• Communication Plan: To assure that OWASP Community are being continuous communicated about project status and deliverables achievement.&lt;br /&gt;
&lt;br /&gt;
• Highlight Report: To provide the OWASP Community with a summary of the project status, progress and potential problems or areas where help may be required.&lt;br /&gt;
&lt;br /&gt;
• End Project Report: To present project achievements. Should be considered the final project report.&lt;br /&gt;
&lt;br /&gt;
More documents may be included during project development to support the control and assure a high quality level (i.e. issue log, project approach).&lt;br /&gt;
&lt;br /&gt;
'''Long Range Plan'''&lt;br /&gt;
&lt;br /&gt;
Both projects should walk in parallel and be used as tools to support efforts to encourage and make the positive approach a reality on the IT Security field. These initiatives shall be supported by OWASP as long term plans and grow to a continuous world-wide campaign in this direction that must achieve big players on the market and be recognized by the community as a tool that must be used to evaluate security enabled companies and products. &lt;br /&gt;
&lt;br /&gt;
'''Why me?'''&lt;br /&gt;
&lt;br /&gt;
Can be me, you or anyone that carries these projects in a professional fashion and assure that all deliverables are being achieved. The most important parts is to make it happen, talk and get the support from reputable associations and large companies (OWASP Members are a good start) and lead it as a long range responsibility.&lt;br /&gt;
&lt;br /&gt;
I am running to win this project because I believe in all of this. I see both as very valuable initiatives that can help companies to make more business; people to get more jobs and the whole community to win in a scenario where our contributions on the security market are recognized as business tools.&lt;br /&gt;
&lt;br /&gt;
'''About me'''&lt;br /&gt;
&lt;br /&gt;
Information Security professional and enthusiastic with 15 years dedicated to achieve expressive results in the areas of IT, Information Security, Compliance and Project Management. A CISSP in good stand and Officer at the ISSA Brazilian Chapter, my professional career gave me extensive knowledge in several fields of Information Security with accumulated experience at consulting firms, as CSO at a world player company on consumer goods market and now as an entrepreneur at Latin American market.&lt;br /&gt;
&lt;br /&gt;
''Application security experience and accomplishments''&lt;br /&gt;
&lt;br /&gt;
My work experience is on Security Management, Risk Assessment, Business Continuity and Disaster Recovery, Security Awareness and other managed-related fields on our industry. I don’t have hands-on experience on application security and this is the main reason why I am running to be qualified on the project described bellow, where I believe that my skills can be used to achieve an excellent result for the community.&lt;br /&gt;
&lt;br /&gt;
''Participation and leadership in open communities''&lt;br /&gt;
&lt;br /&gt;
• Member of OWASP Brazil where I made some small contributions in a recent past.&lt;br /&gt;
&lt;br /&gt;
• Member of ABNT/CB-21/SC02 committee, Brazilian ISO representative for 27001 and 17799 standards&lt;br /&gt;
&lt;br /&gt;
• Officer of ISSA Brazil Chapter where I am responsible for the South Region and as the editor of Antebellum, the ISSA Brazil Journal&lt;br /&gt;
&lt;br /&gt;
• Founder and member of GISI-PR, an open community focused on discuss and promote Information Security initiatives within Paraná State, Brazil&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application ==&lt;br /&gt;
'''Name'''&lt;br /&gt;
&lt;br /&gt;
Michael Coates&lt;br /&gt;
&lt;br /&gt;
'''Project'''&lt;br /&gt;
&lt;br /&gt;
P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses, '''&lt;br /&gt;
&lt;br /&gt;
As critical applications continue to become more accessible and inter-connected, it is paramount that the information be protected. We must also realize that our defenses may not be perfect. Given enough time, attackers can identify security flaws in the design or implementation of an application. In addition to implementing layers of defense within an application, it is critical that we identify malicious individuals before they are able to identify any gaps in our defenses. The best place to identify malicious activity against the application is within the application itself.&lt;br /&gt;
Network based intrusion detection systems are not appropriate to handle the custom and intricate workings of an enterprise application and are ill-suited to detect attacks focusing on application logic such as authentication, access control, etc.  The application itself is the best place to identify and respond to malicious activity.&lt;br /&gt;
This project will create the framework which can be used to build a robust system of attack detection, analysis, and response within an enterprise application&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s), '''&lt;br /&gt;
&lt;br /&gt;
I plan to use a methodical approach throughout the creation of this resource. I will reference my own professional experience, OWASP resources, ESAPI, and academic materials to identify a robust set of potential attacks and identification methods. Thresholds will be recommended for each of the detected attacks. Each recommended threshold value and response recommendation will be accompanied with additional information to describe the purpose of the threshold and recommendation. This additional information will allow the reader to determine if the threshold is appropriate for their implementation.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities, '''&lt;br /&gt;
&lt;br /&gt;
I will complete the following activities:&lt;br /&gt;
1. Identify and define attack patterns against applications&lt;br /&gt;
2. Document points of detection within the application for the attack patterns &amp;amp; identify key information to log&lt;br /&gt;
3. Create thresholds for generating security alerts&lt;br /&gt;
4. Define recommended response actions for the security alerts&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress, '''&lt;br /&gt;
&lt;br /&gt;
April 2, 2008 - Project Begins&lt;br /&gt;
&lt;br /&gt;
April 2, 2008-April 12, 2008 - High level planning &amp;amp; design 	&lt;br /&gt;
&lt;br /&gt;
April 12, 2008-May 1, 2008 - Identify and define attack patterns against applications	&lt;br /&gt;
&lt;br /&gt;
May 1, 2008-June 1, 2008 - Document points of detection within the application for the attack patterns &amp;amp; identify key information to log	&lt;br /&gt;
&lt;br /&gt;
June 1, 2008-June 13, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
June 15, 2008 - Status Report	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Create thresholds for generating security alerts	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Define recommended response actions for the security alerts	&lt;br /&gt;
&lt;br /&gt;
Aug 16, 2008-Aug 30, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
Aug 31, 2008 - Project Complete	&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project, '''&lt;br /&gt;
&lt;br /&gt;
1.  I’d like to include a tiered type approach of thresholds and responses. This is would be similar to the approach used by FISMA of defining different controls for High, Medium, and Low systems.&lt;br /&gt;
&lt;br /&gt;
2. Building on item #1, I want to eventually include a system which lets the user provide information about their system.  This information could include rating or prioritizing different security concerns. a customized set of monitoring points, thresholds and response actions can be recommended for the application based on the provided data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About Me'''&lt;br /&gt;
&lt;br /&gt;
'''Education &amp;amp; Professional Background'''&lt;br /&gt;
&lt;br /&gt;
Masters of Science in Computer, Information and Network Security – DePaul University &lt;br /&gt;
(Expected Graduation 2009)&lt;br /&gt;
Bachelor of Science in Computer Science – University of Illinois&lt;br /&gt;
Extensive experience in conducting black and white box security reviews of complex applications and networks for major financial organizations and international telecoms. I also have experience working as the primary investigator of attacks against a multi-national organization with IDS sensors in networks throughout the world. In addition, I have experience working with several regulatory controls and security standards (FISMA, NIST, GLBA etc). My experience as an ethical hacker and incident responder puts me in an excellent position to tackle this project. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
I am a Senior Computer Security Engineer with Aspect Security where I perform security code reviews and application security testing against a variety of platforms. Prior to working with Aspect Security, I was heavily involved in the discovery and exploitation of application vulnerabilities during black box ethical hacking assessments for numerous clients.&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I am a member of OWASP and attend Chicago OWASP chapter meetings. I also attend ChiSec, an informal meet-up of security professionals in the Chicago area. In addition, I interact with the community through my security blog. http://michaelcoates.wordpress.com. &lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected. '''&lt;br /&gt;
&lt;br /&gt;
I created a similar framework while working within a Security Operation Center. I created attack scenarios, identified relevant IDS events, defined thresholds and appropriate response action for the Security analysts.&lt;br /&gt;
&lt;br /&gt;
'''Requested Reviewer - Eric Sheridan, Application Security Consultant at Aspect Security, Inc.'''&lt;br /&gt;
&lt;br /&gt;
Eric Sheridan is an Application Security Consultant at Aspect Security, a consulting services company specializing in application security. At Aspect Security, Eric specializes in execution of security verification assessments and the establishment of security activities throughout the development lifecycle. In addition, Eric is an instructor in Aspect’s portfolio of Application Security Courses. Eric is also an active participant in OWASP whose contributions include work with projects such as WebGoat, Stinger, CSRFGuard, CSRFTester, and the SASAP project from OWASP SPoC 2007. Eric was also a featured speaker at the 2007 OWASP/WASC San Jose conference.&lt;br /&gt;
&lt;br /&gt;
Contact Information: eric dot sheridan 'at' owasp dot org&lt;br /&gt;
&lt;br /&gt;
== OWASP Interceptor Project - 2008 Update ==&lt;br /&gt;
&lt;br /&gt;
by Justin Derry&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_Interceptor_Project&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
The OWASP Interceptor project was originally written by myself and donated to the OWASP project. Since it has been online numerous people have downloaded the tools and used the code/toolkit. Currently the industry has very limited “XML” or SOAP client testing tools that are designed specifically to perform XML interception and manipulation. The Objective of the Interceptor project is to provide a strong tool for performing XML penetration tests against Web Service (or XML/SOAP) endpoints. The tool should not replace other proxy interception tools such as Charles, Web Scarab and so on, but be purely focused on handling and reading XML structures from clients.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Interceptor tool includes a “swiss-army” knife of features that will help with decoding/hash generation and interpretation of XML code. The key objective is to make a tool that can assist with the collection, inspection and attack replay of XML requests against service endpoints. This year it’s time for an update. The tool doesn’t run on Vista and needs a number of back-end features addressed as well as some help files etc. (Help to get the tool out of BETA status).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Objectives this year'''&lt;br /&gt;
&lt;br /&gt;
This year I see the following objectives in the application code base.&lt;br /&gt;
•	Get the Interface to run on all Window Platforms (.NET) Win2000, XP and Vista;&lt;br /&gt;
&lt;br /&gt;
•	Update the TCP handle libraries to be faster&lt;br /&gt;
&lt;br /&gt;
•	Update the XML Parser engine to support the latest structures&lt;br /&gt;
&lt;br /&gt;
•	Provide a “default” attack database of known XML attack methods (this is a big one)&lt;br /&gt;
&lt;br /&gt;
•	Write a number of help files on how to use the tool&lt;br /&gt;
&lt;br /&gt;
•	Update the toolkit BASE64 Decoder, XML Generators etc with further tools&lt;br /&gt;
&lt;br /&gt;
•	Write a better “reporting” engine to show the result of simulated attack responses&lt;br /&gt;
&lt;br /&gt;
•	Better HTTP support for Manipulation, Authentication and Header Injection etc&lt;br /&gt;
&lt;br /&gt;
•	Better support for interception and handling AJAX XML requests&lt;br /&gt;
&lt;br /&gt;
These are the core features I would like to introduce, with also further to probably come as a part of the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&lt;br /&gt;
&lt;br /&gt;
The current development cycle stopped due to limited time and the need to purchase the IDE tools to develop the interface in .NET. As a Summer of Code 2008 sponsored project we can get the IDE interface tools to implement “Vista” features that will see the tool run on all .NET platforms (Win2000, XP and Vista). Recent changes in my job will allow me to spend more time on developing the toolkit.&lt;br /&gt;
&lt;br /&gt;
Over a number of years I have been involved with OWASP, whilst most recently getting involved with running the OWASP Australia Security Conference for 2008, as well as the Brisbane Chapter. I am also working in the Asia Pacific RIM to further increase the awareness of OWASP and Application Security. My Conference duties for the year have finished up (till planning starts again in a couple of months) so my time can be invested in updating the toolkit.&lt;br /&gt;
&lt;br /&gt;
I believe during the previous years, i have shown OWASP that i am willing and able to produce a quality outcome and i am prepared to put the effort into OWASP to acheive the goals set out for this project. &lt;br /&gt;
&lt;br /&gt;
Some of the Sponsorship money for the project would go to purchasing a specific toolkit for the UI. (The UI is important simply because we want the application to be user friendly). Xceed Components provide a Smart UI as well as some of the decoding and compression features the tool needs. This would require us to approach them upfront for a “free” licence or use some of the Sponsorship money to buy the toolkit. But we can tackle that problem when we come to it.&lt;br /&gt;
&lt;br /&gt;
== SQL Injector Benchmarking Project (SQLiBENCH) ==&lt;br /&gt;
&lt;br /&gt;
by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
'''Prelude'''&lt;br /&gt;
&lt;br /&gt;
There're a lot of and great open source tools (takeover/dumpers/hybrid) for taking advantage of an sql injection vulnerability both used by web application security specialists and attackers. &lt;br /&gt;
Techniques used, databases supported, algorithms employed and abilities implemented by these &amp;quot;sql injectors&amp;quot; greatly varies. Standardization is one of the abstract goals of OWASP and we think it's important to standardize general vulnerability techniques exists in web applications and one of the biggest one is sql manipulation. &lt;br /&gt;
In our effort, we aim to produce a standardization of techniques used in exploiting sql injection by automatic tools. &lt;br /&gt;
&lt;br /&gt;
'''Proposal'''&lt;br /&gt;
&lt;br /&gt;
The goal of the project is to create a detailed set of benchmarking criterias for automatic sql injection tools and applying these to a set of open source sql injectors, producing analysis/benchmarking reports.&lt;br /&gt;
Additionaly, in a semi-academic manner, algorithms used by several sql injectors will be analyzed both implementation and complexity vise.&lt;br /&gt;
&lt;br /&gt;
'''Deliverables And Project Schedule Milestones'''&lt;br /&gt;
&lt;br /&gt;
Two set of documents will be produced. One of them will include the benchmarking criterias and the other will comprise of analysis of selected sql injectors against the benchmarking criterias.&lt;br /&gt;
Moreover, an interactive visual data flow diagram, giving hints to testers about which tool should be used under which circumstances, will be implemented with web-based technologies such as jquery library. &lt;br /&gt;
&lt;br /&gt;
April 03    Project Kickoff&lt;br /&gt;
&lt;br /&gt;
April 03-30 Determination of the benchmarking criterias &lt;br /&gt;
&lt;br /&gt;
May   01-15 Producing a test environment image with 5-6 rdbms (MSSQL Express, Oracle Express, DB2 Express, MySQL, PgSQL, etc.) and a vulnerable application (which will support different sql injection types, databases and include logging capabilities)&lt;br /&gt;
&lt;br /&gt;
May   15-31 Selecting and installing automatic sql injectors onto the test system and starting to use them on vulnerable application&lt;br /&gt;
&lt;br /&gt;
June  01-30 Analysing tools and applying benchmarking criterias, contacting the authors as we proceed &lt;br /&gt;
&lt;br /&gt;
July  01-31 Producing reports for benchmarking criterias and tool analysis&lt;br /&gt;
&lt;br /&gt;
'''About Us'''&lt;br /&gt;
&lt;br /&gt;
We're part of OWASP-Turkey. [http://www.h-labs.org Mesut Timur] is a junior in the Computer Engineering Dept. of [http://www.gyte.edu.tr University of GYTE] and [http://www.webguvenligi.org Bedirhan Urgun] is a web/application security specialist in [http://www.uekae.tubitak.gov.tr TUBITAK-UEKAE].&lt;br /&gt;
&lt;br /&gt;
== OWASP-WeBekci Project ==&lt;br /&gt;
&lt;br /&gt;
==== Executive Summary: ====&lt;br /&gt;
&lt;br /&gt;
Web application firewalls (WAF) are gaining importance among the information security technologies designed to protect web sites from attack. WAF solutions prevent attacks that network firewalls and intrusion detection systems can't and they require no modification of application source code. ModSecurity [http://www.modsecurity.org/] is an open source web application firewall that runs as an Apache module. It is an embeddable web application firewall and it provides protection from a range of attacks against web applications. It is an open source project available to everyone; it however does not come with an admin panel. &lt;br /&gt;
&lt;br /&gt;
I decided to provide this essential tool with a control panel which I believe will ease and thus encourage its usage.&lt;br /&gt;
&lt;br /&gt;
ModSecurity allows for HTTP traffic monitoring and real-time analysis with no changes to existing infrastructure. My main goal is to analyze attacks and generate rules to change the configuration of the ModSecurity accordingly.&lt;br /&gt;
&lt;br /&gt;
ModSecurity  has a feature called “flexible rule engine” as its heart of Attack Prevention capability . It uses ModSecurity’s “Rule Language,” (a programming language designed to work with HTTP transaction data). It is easy to use and flexible; yet the system administrators need to learn its own rules to create what is called “Certified ModSecurity Rules” to be implemented. My control panel will automate the major code-generation in Rule Language. &lt;br /&gt;
&lt;br /&gt;
==== Objectives and Deliverables: ====&lt;br /&gt;
&lt;br /&gt;
* '''Configuration'''        : Most of the configuration parameters will be managed through the web interface&lt;br /&gt;
* '''Rule Generator'''       : Basic rules will be generated using the web interface&lt;br /&gt;
* '''Core Rule Integration''': Core rules will be added to the database for use&lt;br /&gt;
* '''Logging and Reporting''': Apache error log and modsec_audit log will be parsed and presented to the user thru the web interface&lt;br /&gt;
* '''DB Support'''           : MySQL&lt;br /&gt;
&lt;br /&gt;
==== Why I should be sponsored for the project: ====&lt;br /&gt;
Being a SpoC2007 project, it couldn't be implemented mainly due to a job change and therefore lack of time. With the help of Bedirhan Urgun we'll be able to produce a quality web admin panel GUI for a same host modsec installation infrastructure. We are both part of OWASP Turkey [http://www.owasp.org/index.php/Turkey] and tried to produce a great deal of awareness both about web security and OWASP with both documents/chapter meetings/email list and mini-conferences.&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26964</id>
		<title>OWASP Summer of Code 2008 Applications</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Summer_of_Code_2008_Applications&amp;diff=26964"/>
				<updated>2008-03-23T14:08:24Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''This page contains project Applications to the [[OWASP_Summer_of_Code_2008|OWASP Summer Of Code 2008]]'''&lt;br /&gt;
&lt;br /&gt;
= A few notes =&lt;br /&gt;
*'''If you want to apply for a SoC 2008 sponsorship you HAVE TO USE THIS PAGE for your application.'''&lt;br /&gt;
** See [[OWASP Summer of Code 2008#How To Participate (To Developers)|How To Participate]] for what to do once you completed your Application.&lt;br /&gt;
** Please remember that projects will be selected and funded based on how well they meet the [[OWASP Summer of Code 2008#Jury and Selection Criteria| Selection Criteria]].&lt;br /&gt;
** Please see [[OWASP Autumn of Code 2006 - Applications|AoC 06]] and [[OWASP Spring Of Code 2007 Applications|SpoC 07]] for examples of Applications.&lt;br /&gt;
* '''You can propose your project in any form you wish, but the best proposals will be well thought out, clear and concise, and reflective of your passion for the topic.  We strongly suggest that you include [[OWASP Summer of Code 2008 Applications - Proposal Type|this information in your proposal]].&lt;br /&gt;
'''&lt;br /&gt;
= Applications - {Fill in below}  =&lt;br /&gt;
&lt;br /&gt;
== The Application Security Desk Reference - ASDR ==&lt;br /&gt;
* Leonardo Cavallari Militelli &lt;br /&gt;
* Proposal: Make [[OWASP ASDR Project|OWASP ASDR Project]] a release quality document.&lt;br /&gt;
&lt;br /&gt;
The ASDR is a reference volume that contains basic information about all the foundational topics in application security. It intends to replace and refresh [[OWASP Honeycomb Project|Honeycomb Project]] with a new structure for articles and relationship between categories, thus making it a release quality doc.&lt;br /&gt;
&lt;br /&gt;
This idea raised when finished the [[Attack|Attack Reference Guide]] for [[OWASP Spring Of Code 2007|OWASP Spring Of Code 2007]], where it was identified that OWASP reference articles need some special attention. Jeff Williams is totally supporting this project.&lt;br /&gt;
&lt;br /&gt;
We already have defined which type of article we should include on Desk Reference, as follows:&lt;br /&gt;
* [[:Category:Principle|Principles]]&lt;br /&gt;
* [[:Category:Threat_Agent|Threat Agents]]&lt;br /&gt;
* [[:Category:Attack|Attacks]]&lt;br /&gt;
* [[:Category:Vulnerability|Vulnerabilities]]&lt;br /&gt;
* [[:Category:Countermeasure|Countermeasures]]&lt;br /&gt;
* [[:Category:Technical Impact|Technical Impacts]]&lt;br /&gt;
* [[:Category:Business Impact|Business Impacts]]&lt;br /&gt;
&lt;br /&gt;
*Road Map: A complete project roadmap can be found on '''[[ASDR Table of Contents|ASDR Table of Contents]]'''. Basically, the following activities should be performed, some of them already started:&lt;br /&gt;
** Define articles templates for each reference type&lt;br /&gt;
** Define subcategories for articles classification&lt;br /&gt;
** Compile first DRAFT version of ASDR Book&lt;br /&gt;
** Articles development &amp;amp; Call for Volunteers&lt;br /&gt;
** Articles revision&lt;br /&gt;
** First version of OWASP ASDR book&lt;br /&gt;
&lt;br /&gt;
== OWASP Code review guide, V1.1 ==&lt;br /&gt;
* Eoin Keary,&lt;br /&gt;
'''Code Review Guide Proposal''':&lt;br /&gt;
&lt;br /&gt;
'''Introduction:'''The code review guide is currently at version RC 2.0 and the second best selling OWASP book.&lt;br /&gt;
I have received many positive comments regarding this initial version and believe it’s a key enabler for the OWASP fight against software insecurity.&lt;br /&gt;
&lt;br /&gt;
It has even inspired individuals to build tools based on its information and I have convinced such people (Alessio Marziali) to open source their tool and make it an OWASP project.&lt;br /&gt;
&lt;br /&gt;
The combination of a book on secure code review and a tool to support such an activity is very powerful as it gives the developer community a place to start regarding secure application development.&lt;br /&gt;
&lt;br /&gt;
'''Proposal:'''&lt;br /&gt;
I am proposing that I improve the code review guide from a number of aspects. This should place the guide as a de facto secure code review guide in the application security industry.&lt;br /&gt;
&lt;br /&gt;
'''Additional and expanded Chapters:'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Transactional analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
	Expand chapter.&amp;lt;br&amp;gt;&lt;br /&gt;
	Examples via diagrams.&amp;lt;br&amp;gt;&lt;br /&gt;
	&lt;br /&gt;
'''Threat Modeling and Analysis'''&amp;lt;br&amp;gt;&lt;br /&gt;
The approach to examining an application to be reviewed.&amp;lt;br&amp;gt;&lt;br /&gt;
Focusing on areas of interest.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Example reports and how to write one'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to determine the risk level of a finding.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Automated code review''' &amp;lt;br&amp;gt;&lt;br /&gt;
Code crawler documentation and usage.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Rich Internet Applications'''&amp;lt;br&amp;gt; &lt;br /&gt;
Expanded chapters on Flash, Ajax.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP ESAPI (Enterprise Security API)'''&amp;lt;br&amp;gt;&lt;br /&gt;
What it is, Why use it. What to review.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Code review Metrics:'''&amp;lt;br&amp;gt;&lt;br /&gt;
How to compile, use and analyse metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Rolling out metrics in the Enterprise.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Integrating Code review with an existing SDLC'''&lt;br /&gt;
Integration of Secure Code review with an existing SDLC.&amp;lt;br&amp;gt;&lt;br /&gt;
Secure Code review roadmap definition.&amp;lt;br&amp;gt;&lt;br /&gt;
Documentation requirements.&amp;lt;br&amp;gt;&lt;br /&gt;
Scope definition.&amp;lt;br&amp;gt;&lt;br /&gt;
SDLC steering comittee establishment.&amp;lt;br&amp;gt;&lt;br /&gt;
Performace criteria, benchmarks and metrics.&amp;lt;br&amp;gt;&lt;br /&gt;
Integration of SDLC results into key IT governance areas.&amp;lt;br&amp;gt;&lt;br /&gt;
Critical success factors.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== The OWASP Testing Guide v3 ==&lt;br /&gt;
* Matteo Meucci&lt;br /&gt;
* The OWASP Testing Guide v2 was a great success, with thousand downloads and many many Companies that have adopted it as standard for a Web Application Penetration Testing.&lt;br /&gt;
Now it's time to begin a new project that is based on v2 but improve it and complete it.&lt;br /&gt;
&lt;br /&gt;
In the OWASP Testing Guide v2 we have split the set of tests in 8 sub-categories:&lt;br /&gt;
&lt;br /&gt;
    * Information Gathering&lt;br /&gt;
    * Business logic testing&lt;br /&gt;
    * Authentication Testing&lt;br /&gt;
    * Session Management Testing&lt;br /&gt;
    * Data Validation Testing&lt;br /&gt;
    * Denial of Service Testing&lt;br /&gt;
    * Web Services Testing&lt;br /&gt;
    * AJAX Testing &lt;br /&gt;
&lt;br /&gt;
The following are my thoughts about the new OWASP Testing Guide v3:&lt;br /&gt;
&lt;br /&gt;
1) Authorization testing missing. As Jeff and Dave said many time before it's important to create a new category.&lt;br /&gt;
2) Information gathering is not a set of vulnerabilities --&amp;gt; not in report --&amp;gt; new category: Passive mode analysis&lt;br /&gt;
3) Infrastructural test --&amp;gt; new category&lt;br /&gt;
4) Web Services section needs improvement&lt;br /&gt;
5) AJAX Testing section needs improvement&lt;br /&gt;
6) New category: Client side Testing. AJAX and Flash Testing&lt;br /&gt;
&lt;br /&gt;
* This [http://www.owasp.org/index.php/Image:Planning_OTGv3.doc document] analyze the OWASP Testing Guide v2 vulnerabilities and a plan for create the new v3. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code Crawler ==&lt;br /&gt;
* Alessio Marziali (aka nTze)&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
'''Description'''&amp;lt;br&amp;gt;&lt;br /&gt;
This tool is aimed at assisting code review practitioners. It is a static code review tool which searches for key topics within .NET and J2EE/JAVA code.&lt;br /&gt;
The aim of the tool is to accompany the OWASP Code review Guide and to implement a total code review solution for &amp;quot;everyone&amp;quot;; Where &amp;quot;everyone&amp;quot; means &amp;quot;more&amp;quot; companies performing secure software activities.&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
Key areas of improvement:&amp;lt;br&amp;gt;&lt;br /&gt;
'''Reporting'''&amp;lt;br&amp;gt;&lt;br /&gt;
- PDF&lt;br /&gt;
- Microsoft Office Compatible Word Document&lt;br /&gt;
- HTML&lt;br /&gt;
&lt;br /&gt;
'''Scanning'''&amp;lt;br&amp;gt;&lt;br /&gt;
- Multiple File scanned at the same time&amp;lt;br&amp;gt;&lt;br /&gt;
-- Open Microsoft Visual Studio's Solutions&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Bigger Database''' &amp;lt;br&amp;gt;&lt;br /&gt;
Which will provide more information about the threats such vulnerability type (XSS,SQL Injection, Remote File Inclusion etc).&amp;lt;br&amp;gt;&lt;br /&gt;
'''Security Software Life Cycle'''&amp;lt;br&amp;gt;&lt;br /&gt;
A feature that will let you save the threats for each project/document, so the reviewer can check how the development is going from a “security prospective” during the entire software lifecycle.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Improvement of the code scan system.&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== The Owasp Orizon Project ==&lt;br /&gt;
* Paolo Perego (aka thesp0nge),&lt;br /&gt;
* The Owasp Orizon Project, &lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
The [http://www.owasp.org/index.php/Category:OWASP_Orizon_Project Owasp Orizon Project] born in 2006 in order to provide a framework to all Owasp projects developing code review services.&lt;br /&gt;
&lt;br /&gt;
The project is in a quite stable stage and it is usable for Java static code review and some dynamic tests against XSS.&lt;br /&gt;
Owasp Orizon includes also APIs for code crawling, usable for code crawling tools.&lt;br /&gt;
&lt;br /&gt;
[http://milk.sf.net Milk] project is a java code review tool I'm writing using Orizon as background engine. Its goal is to show engine capabilities.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
* plugin architecture for static code review library: this planned feature will be announced (hopefully, if my CFP will be accepted) to next Owasp European App conf.&lt;br /&gt;
* starting C# support&lt;br /&gt;
* upgrade from Alpha quality project to Beta quality project in accord to [http://www.owasp.org/index.php/Category:OWASP_Project_Assessment Owasp Project Assessment criteria]&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
Owasp Orizon is the first Owasp project I'm involved in. I'm also contributor of Owasp Italian chapter managed by Matteo Meucci and I'm talking at various speeches about application security and safe coding best practices.&lt;br /&gt;
&lt;br /&gt;
I'm a security consultant working in ethical hacking and we're approaching code review and safe topics right now. I'm a developer too so I understand also the &amp;quot;dark side&amp;quot; of the problem developing code with security in mind.&lt;br /&gt;
&lt;br /&gt;
I work using the &amp;quot;release early release often&amp;quot; paradigm so to be concrete and let other people having something usable to work with. &lt;br /&gt;
&lt;br /&gt;
In the last year Owasp Orizon evolved a lot with a good static code review engine and a lot of code was written to give Owasp guys the best framework as possible to be used for writing code review tools. I hope to pursuit my goals again with SoC 2008.&lt;br /&gt;
&lt;br /&gt;
== Skavenger ==&lt;br /&gt;
* Matthias Rohr&lt;br /&gt;
&lt;br /&gt;
'''Introduction'''&lt;br /&gt;
&lt;br /&gt;
Skavenger is a web application security assessment toolkit which arised from many years of professional experience in the web application assessment field and is the result of nearly one your of work.&lt;br /&gt;
&lt;br /&gt;
It passively analyzes traffic logged by various MITM proxies (such as WebScarab and Burp) as well as other sources (like Firefox's LiveHTTPHeader plugin) and helps to identify various kinds of possible vulnerabilities (such as XSS, CRLF injection, an insecure session management and several kinds of information disclosure). Skavenger's modular design allows the integration of custom scanning modules without any knowledge about the tool at all.&lt;br /&gt;
&lt;br /&gt;
Skavenger is completely written in Perl and can be downloaded from:&lt;br /&gt;
https://sourceforge.net/projects/skavenger/&lt;br /&gt;
&lt;br /&gt;
'''Objectives and deliverables'''&lt;br /&gt;
&lt;br /&gt;
Here are some ideas:&lt;br /&gt;
* A GUI to monitor and analyze scanning results&lt;br /&gt;
* More sophisticated scanner modules (e.g. for better backend identification and more platform specific tests)&lt;br /&gt;
* Database integration&lt;br /&gt;
* API's to integrate modules in other languages (such as Python or Java).&lt;br /&gt;
* Better source integration with custom Firefox, Burp or (of course) WebScarab plugins&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP .NET Project Leader ==&lt;br /&gt;
* Mark Roxberry&lt;br /&gt;
&lt;br /&gt;
'''Project Proposal'''&lt;br /&gt;
&lt;br /&gt;
Assume the lead of the OWASP .NET Project.  Ensure that information, materials and software are relevant to building secure .NET web applications and services.  Provide deep content for all roles related to .NET web applications and services including:&lt;br /&gt;
&lt;br /&gt;
* Architectural guidance&lt;br /&gt;
* Developer tools, information and checklists&lt;br /&gt;
* IT professional content (for those that deploy and maintain .NET websites)&lt;br /&gt;
* Penetration testing resources&lt;br /&gt;
* Incident response resources&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively recruit .NET contributors, including personnel from Microsoft, but others throughout the .NET ecosystem.  Including experts from communities from large companies to ISVs, from enterprise architects to ALT.NET developers will be important for the overall reach of the OWASP .NET project.  Other communities to consider include developers who use Mono (.NET for Linux), including Moonlight (Silverlight for Linux).&lt;br /&gt;
&lt;br /&gt;
The OWASP .NET Project Leader will actively contribute to the OWASP projects that require .NET resources, by recruiting resources or contributing to the project.&lt;br /&gt;
&lt;br /&gt;
I propose to have the project active in 1-3 months, with continuous recruitment efforts for contributors for the life of the project.  Metrics for success can include number of contributors, number of articles, search engine ranks for pages and site visit counts.  For the application however, I will submit that within 3 months I can provide a baseline to set site goals for each metric.&lt;br /&gt;
&lt;br /&gt;
'''Why I should be sponsored for the project'''&lt;br /&gt;
&lt;br /&gt;
I have previously contributed to the OWASP Test Guide v2 project, providing content and reviewed content.  I care about the OWASP mission.  In fact, I have used the OWASP Top 10 to teach developers about vulnerabilities in web applications.&lt;br /&gt;
&lt;br /&gt;
I have 15 years of technical leadership experience using Microsoft technologies.  I have lead small and large teams as a technical lead, lead developer and architect on small and large projects.  I am a Certified Information Systems Security Professional (CISSP) and a Certified Ethical Hacker.  I am on top of current trends and required to be informed regarding .NET web development and security, including, for example ASP.NET MVC, Silverlight, Unity, Entity Framework.  I am personally interested in providing security resources to .NET developers globally, specific and applicable to their projects.&lt;br /&gt;
&lt;br /&gt;
== OWASP Backend Security Project ==&lt;br /&gt;
* Full name: Carlo Pelliccioni&lt;br /&gt;
* Project: OWASP Backend Security Project&lt;br /&gt;
* Project description: &lt;br /&gt;
:OWASP Backend Security Project is a new project created to improve and to collect the existant information about the backend security.&lt;br /&gt;
:The project is composed by three sections (security development, security hardening and security testing). &lt;br /&gt;
:The aim is to define the guidelines for the companies and IT professionals working in the security field into processes development and back-end components management/testing in the enterprise architecture.&lt;br /&gt;
&lt;br /&gt;
* Objectives:&lt;br /&gt;
&lt;br /&gt;
 '''Overview'''&lt;br /&gt;
 Create a section with an introduction about the project (high-level description) explaining the main&lt;br /&gt;
 goals.&lt;br /&gt;
&lt;br /&gt;
 '''Development'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki concerning PHP,&lt;br /&gt;
 JAVA and ASP.NET and extend the projects' sections with new contents.&lt;br /&gt;
&lt;br /&gt;
 '''Hardening'''&lt;br /&gt;
 Create new guidelines about the dbms hardening&lt;br /&gt;
&lt;br /&gt;
 '''Testing'''&lt;br /&gt;
 Include the writings already existant in OWASP wiki about security testing.&lt;br /&gt;
 Create new articles about security testing.&lt;br /&gt;
&lt;br /&gt;
== OWASP Classic ASP Security Project  ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
I am interested in making P018 - OWASP Classic ASP Security Project happen, Classic ASP 2.0 and 3.0 applications are still largely used as this technology is more than 10 years old and was largely used. there are thousands of sites on the wild that need guidance on the security arena. This is where OWASP can come up and provide help for “making the Web a better place” and continue spreading the word on security. I have always be a passionate of the technology (regardless of its inconveniences such as being old and DLL-hell prone) and I am really exited on the idea of sharing my knowledge of this area to the world and what best that though OWASP.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
Create a secure framework for Classic ASP application by complementing existing OWASP projects with documentation for this particular technology and the creation of security libraries. More specifically:&lt;br /&gt;
* Creation of a Common Object Repository for ASP applications based on OWASP ESAPI Project including objects and/or references to libraries for security applications all this aligned with OWASP Top10 and OWASP Guide .&lt;br /&gt;
* Create Documentation aligned to OWASP Code Review Project Checklist providing additional technology-specific checks.&lt;br /&gt;
* Addition of expression for Code Review Tool to support Classic ASP applications.&lt;br /&gt;
* Implementation of Version 1 of Stinger for ASP either by using an installable COM library or ISAPI.&lt;br /&gt;
* This same module will compliment the OWASP Validation Documentation Project.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver. &lt;br /&gt;
&lt;br /&gt;
Also I’ve had close contact with OWASP since 2005&lt;br /&gt;
[https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html] by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish.&lt;br /&gt;
&lt;br /&gt;
== Internationalization Guidelines and OWASP-Spanish Project ==&lt;br /&gt;
* Juan Carlos Calderon&lt;br /&gt;
'''Executive Summary'''&amp;lt;br&amp;gt;&lt;br /&gt;
The main goal of OWASP is to spread the word about security (“Our mission is to make application security &amp;quot;visible,&amp;quot; so that people and organizations can make informed decisions about application security risks.”) and OWASP has done great work so far :). And now it’s time for a next big step.&lt;br /&gt;
&lt;br /&gt;
The number of native and secondary speakers in the world for Chinese, Spanish, French, Russian, Arabic and Indi languages are estimated in similar number to English speaking or even more (Some References at [http://en.wikipedia.org/wiki/Ethnologue_list_of_most_spoken_languages Ethnologue], [http://encarta.msn.com/media_701500404/Languages_Spoken_by_More_Than_10_Million_People.html Encarta], [http://en.wikipedia.org/wiki/List_of_languages_by_number_of_native_speakers Wikipedia]). I think is a good time for OWASP to reach those that do not speak English to have full access to all the OWASP materials, not just a couple of documents.&lt;br /&gt;
&lt;br /&gt;
OWASP, while open to translations, do not have clear guidelines on how to translate OWASP contents and (AFAIK) there is no multi-language support in OWASP.org site. This is understandable as there is no formal project for internationalization so far. &lt;br /&gt;
&lt;br /&gt;
'''Oportunity and Effort'''&amp;lt;br&amp;gt;&lt;br /&gt;
This is great opportunity to make Spanish the first language on which the OWASP site and documentation is fully translated and at the same time share the experience with other people interested in the same objective, Bring OWASP to the world.  And this is something I’ve being pushing for some time ago and that could be possible “at once” via SoC 2008.&lt;br /&gt;
&lt;br /&gt;
I understand this is significant effort so to have it done I will count with the help of 6 people (friend of mine, all of them Security auditors with excellent English level) plus a few well known contributors from OWASP-Spanish effort, so the founding will be divided among the people involved in the same proportion of the work they do for the completion of this effort. This, to encourage delivery.&lt;br /&gt;
&lt;br /&gt;
'''Objectives and Deliverables'''&amp;lt;br&amp;gt;&lt;br /&gt;
* Team up with Larry Casey to implement Multilanguage support in OWASP.org Mediawiki.&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to start a new language translation for OWASP Document and Site Pages&lt;br /&gt;
* General Guidelines on minimum/recommended requirements to implement internationalization and localization ([http://www.w3.org/International/ i18n]) on OWASP Software &lt;br /&gt;
* Full translation to Spanish of all the release-level document projects. Those are:&lt;br /&gt;
** Top 10 2007&lt;br /&gt;
** Guide 2 (Already translated)&lt;br /&gt;
** Testing Guide (Already Translated)&lt;br /&gt;
** Legal&lt;br /&gt;
** FAQ&lt;br /&gt;
* Full Translation of major sections of OWASP Site&lt;br /&gt;
** Project Main Pages (Release, Beta and Alpha levels for both documents and tools projects)&lt;br /&gt;
** Principles&lt;br /&gt;
** References Section&lt;br /&gt;
** Conferences&lt;br /&gt;
** News (Those currently displayed in OWASP site)&lt;br /&gt;
** About OWASP&lt;br /&gt;
* Evaluation of Spanish translation approach for WebGoat and WebScarab and delivery of this document to Bruce and Rogan for possible implementation in near future.&lt;br /&gt;
* Leverage for deploy of es.owasp.org, the domain already exists but is not redirecting correctly.&lt;br /&gt;
* Create a Communication strategy to help and keep track on new pages or changes in significant pages so all the translations are in sync.&lt;br /&gt;
&lt;br /&gt;
'''Out of Scope'''&amp;lt;br&amp;gt;&lt;br /&gt;
Translation of the following sections are NOT in Scope&lt;br /&gt;
* Local Chapters Pages&lt;br /&gt;
* Presentations&lt;br /&gt;
* Conferences&lt;br /&gt;
* Videos&lt;br /&gt;
* Blogs&lt;br /&gt;
* All the projects deliverables in Alpha and Beta Stages&lt;br /&gt;
* All the documentation “on development” like Guide Version 3.0&lt;br /&gt;
* Translation of Pages, documentation or tools to other language other than Spanish according to the stated in above section.&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&amp;lt;br&amp;gt;&lt;br /&gt;
I’ve being part of contributions to OWASP documents on the translation arena since 2005 [https://lists.owasp.org/pipermail/owasp-spanish/2005-March/000069.html], a few of them by making possible the translation of OWASP Top 10 2004 [http://www.owasp.org/index.php/Top_10_2004] and OWASP Testing Guide V1.17 [http://www.owasp.org/docroot/owasp/misc/testing_spanish.pdf] to Spanish. It is time to make the full job done :).&lt;br /&gt;
&lt;br /&gt;
I have 10 years of experience on Web technologies. During 8 years I have performed and leaded hundreds of Security Source Code Reviews and Black box testing on Web Applications. On my current job I lead 30 people in diverse locations all of them working on the Application Security arena, so I am accustomed to execute and deliver.&lt;br /&gt;
&lt;br /&gt;
== The Ruby on Rails Security Guide v2 ==&lt;br /&gt;
Heiko Webers&lt;br /&gt;
&lt;br /&gt;
The last security guide for Rails [http://www.owasp.org/index.php/Category:OWASP_Web_Application_Security_Put_Into_Practice] was a great success, with a lot of more secure web applications and continued awareness in the community of security issues. The Ruby on Rails Security Project [http://www.rorsecurity.info/] is the one and only source of information about Rails security topics, and I keep the community up-to-date with blog posts and conference talks in Europe. The Guide and the Project has been mentioned in several Rails books and web-sites.&lt;br /&gt;
&lt;br /&gt;
Version 1 of the Ruby on Rails Security Guide was sponsored by the SpoC 07, set the standard for OWASP programming language specific guides in terms of the topic outline and has been published as a book [http://www.lulu.com/content/1412042]. Nevertheless I'm convinced that a more compact design and a &amp;quot;question-and-answer&amp;quot; style of writing will reach an even larger audience. Of course the new Guide will still include answers to the OWASP Top Ten security vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
A lot has changed since the publishing of the first Guide. Some new security holes have been found, there are new advises and most importantly Rails version 2.0 has been released. The new Ruby on Rails Security Guide aims at providing an up-to-date coding and configuration guide for the Rails community.&lt;br /&gt;
&lt;br /&gt;
In the new Rails Security Guide I'd like to&lt;br /&gt;
* update the entire book to match Rails 2.0&lt;br /&gt;
* cover new topics, including, but not limited to:&lt;br /&gt;
** Intranet and administration interface security,&lt;br /&gt;
** phishing,&lt;br /&gt;
** real-world attack situations,&lt;br /&gt;
** short excursus on server monitoring,&lt;br /&gt;
** the new CookieStore session management,&lt;br /&gt;
** vulnerabilities in popular plug-ins,&lt;br /&gt;
** denial-of-service attacks&lt;br /&gt;
* cover all OWASP Top Ten security vulnerabilities&lt;br /&gt;
* a more compact writing style, more examples and &amp;quot;questions-and-answers&amp;quot;&lt;br /&gt;
* introduce the OWASP and Rails security to a greater audience&lt;br /&gt;
&lt;br /&gt;
== OWASP Application Security Verification Standard ==&lt;br /&gt;
&lt;br /&gt;
*Mike&lt;br /&gt;
&lt;br /&gt;
'''OWASP Application Security Verification Standard Proposal'''&lt;br /&gt;
&lt;br /&gt;
'''Educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
The applicant is a hands-on senior professional services manager with a trademark of&lt;br /&gt;
developing creative solutions to complex application security-related technical problems. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a background in trusted product evaluation:&lt;br /&gt;
&lt;br /&gt;
*CC evaluation&lt;br /&gt;
*CC evidence development, including operating system test code development&lt;br /&gt;
*CC project management&lt;br /&gt;
*TCSEC evaluation&lt;br /&gt;
*TCSEC project management&lt;br /&gt;
*TEF management&lt;br /&gt;
*CCTL management&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in security-related software development and integration:&lt;br /&gt;
&lt;br /&gt;
*PKI toolkit development&lt;br /&gt;
*PK-E application integration&lt;br /&gt;
*Secure web portal application development&lt;br /&gt;
*Secure web portal integration&lt;br /&gt;
*Secure instant messaging application development, including three patents&lt;br /&gt;
&lt;br /&gt;
The applicant also has a background in cryptomodule testing:&lt;br /&gt;
&lt;br /&gt;
*FIPS 140 evaluation&lt;br /&gt;
*FIPS 140 evidence development&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
The applicant does not have experience in contributing to open communities.&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
OWASP is looking for a commercially-workable open standard for performing application security verification efforts. The problem is that there is a huge range in the coverage and level of rigor available in the market, and consumers have no way to tell the difference between someone just running a grep tool, and someone doing painstaking code review and manual testing. So, a standard is needed.&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s)'''&lt;br /&gt;
&lt;br /&gt;
The applicant’s proposal will address the above challenges as follows:&lt;br /&gt;
&lt;br /&gt;
*The applicant will define an evaluation framework that may be used to conduct OWASP Application Security Verification Standard certifications.&lt;br /&gt;
*The applicant will define an OWASP Application Security Verification Standard which defines levels that applications may be certified against.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
The applicant will carry out these activities. Please see below for a proposed list of specific deliverables.&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following deliverables:&lt;br /&gt;
&lt;br /&gt;
*'''Scheme Overview document.''' This will define the overall framework with roles, responsibilities, and processes.&lt;br /&gt;
*'''Evaluation and Certification document.''' This will describe the evaluation and certification process.&lt;br /&gt;
*'''Conditions for the Use of Trademarks.''' This will describe OWASP’s name, logo, and certificate may be used and referenced.&lt;br /&gt;
*'''Evaluation Report Content Requirements.''' This will describe the content requirements of evaluation reports.&lt;br /&gt;
*'''OWASP Application Security Verification Standard.''' This will define the levels that applications may be certified against.&lt;br /&gt;
*'''OWASP Application Security Verification Standard Appendix A.''' This will define the required content of the OWASP Application Security Verification Standard Security Policy.&lt;br /&gt;
*'''Policy Letter #1. Acceptance of Security Policies into OWASP Evaluation''' This will define the requirements to be listed as in evaluation on the OWASP web site.&lt;br /&gt;
&lt;br /&gt;
The applicant proposes the following rough project schedule:&lt;br /&gt;
&lt;br /&gt;
*2nd April. Project kickoff.&lt;br /&gt;
*15th June. Alpha Quality drafts of Scheme Overview document and of OWASP Application Security Verification Standard document completed.&lt;br /&gt;
*31st August. Project completion. Beta Quality drafts of all documents completed.&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
The long-term vision for the project is to normalize the range in the coverage and level of rigor available in the market when it comes to performing application security verification.&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected.'''&lt;br /&gt;
&lt;br /&gt;
The applicant has a uniquely-qualified perspective given his experience with TCSEC, TTAP, CC, FIPS 140-1, and FIPS 140-2 evaluation programs, and his real-world perspective as a developer and integrator of security-related applications.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== GTK+ GUI for w3af project ==&lt;br /&gt;
&lt;br /&gt;
''Facundo Batista''&lt;br /&gt;
&lt;br /&gt;
'''Your educational and professional background'''&lt;br /&gt;
&lt;br /&gt;
I'm Electronic Engineer with a Master in Engineer Innovation in&lt;br /&gt;
Bologna University, Italy. I live in Buenos Aires, Argentina, and love&lt;br /&gt;
reading books, playing tennis, and programming Python.&lt;br /&gt;
&lt;br /&gt;
I worked in a mobile company for six years, in the Network Management&lt;br /&gt;
department, then I was Chief Developer of a Mobile Content Provider,&lt;br /&gt;
and now I'm Solution Architect in Multimedia &amp;amp; Systems Integration in&lt;br /&gt;
Ericsson. Also I was professor in several universities, high schools&lt;br /&gt;
and other institutions.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
None, more than working in w3af. However, my proposal here is not&lt;br /&gt;
related to the security part of the product, but to its graphical&lt;br /&gt;
interface and usability.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I'm very involved in the free software and open source community. I'm&lt;br /&gt;
a Python Core Developer and member of the Python Software Foundation&lt;br /&gt;
by merit. I have a long history of talks given in several&lt;br /&gt;
international (PyCon, EuroPython) and national (a lot!) conferences. I&lt;br /&gt;
also teach Python in educational institutions, enterprises and as a&lt;br /&gt;
private instructor. I founded Python Argentina, the national users&lt;br /&gt;
groups, and I'm a very active member of it.&lt;br /&gt;
&lt;br /&gt;
I also lead other open source projects (SMPPy, SiGeFi, etc.) and&lt;br /&gt;
particpate in others (Docutils, w3af itself, etc.).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses'''&lt;br /&gt;
&lt;br /&gt;
My main objective is to minimize the effort and learning curve of&lt;br /&gt;
using w3af, providing a very usable graphical interface.&lt;br /&gt;
&lt;br /&gt;
Note that as the interface is cross platform, being usable also in the&lt;br /&gt;
win32 environment, it will help to popularize the w3af project.&lt;br /&gt;
&lt;br /&gt;
This will allow users without information security knowledge to verify&lt;br /&gt;
that their web applications are correctly programmed and configured.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities'''&lt;br /&gt;
&lt;br /&gt;
I will carry the following activities, detailed later in smaller steps:&lt;br /&gt;
&lt;br /&gt;
- Design and code new windows and interfaces to increase the functionality of the project.&lt;br /&gt;
&lt;br /&gt;
- Tuning of the process workflow, allowing a more intuitive way of working.&lt;br /&gt;
&lt;br /&gt;
- Visual polishing for a more pleasant and intuitive tool.&lt;br /&gt;
&lt;br /&gt;
- Usability tests and improvements.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress'''&lt;br /&gt;
&lt;br /&gt;
''New features implemented in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Local proxy to trap and modify requests and responses sent from a browser.&lt;br /&gt;
&lt;br /&gt;
- Manually send a request and analyze the response.&lt;br /&gt;
&lt;br /&gt;
- Manually create a fuzzed requests based on tokens, so user can construct easily differents HTTP request with a regex-like semantics.&lt;br /&gt;
&lt;br /&gt;
- Wizard to perform a vulnerability assessment.&lt;br /&gt;
&lt;br /&gt;
- Graphical display of site map and vulnerabilities.&lt;br /&gt;
&lt;br /&gt;
- Reload a plugin after its edited from within the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Embebed tool to encode/decode URL/Base64 and to hash sha1/md5.&lt;br /&gt;
&lt;br /&gt;
- HTTP response side by side content compare.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Usability improvements in the pyGTK user interface:''&lt;br /&gt;
&lt;br /&gt;
- Meetings with a usability expert that the w3af team leader has already contacted and worked with.&lt;br /&gt;
&lt;br /&gt;
- Kill all pending bugs and make a stable release.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
''Documentation:''&lt;br /&gt;
&lt;br /&gt;
- Users guide for the pyGTK user interface.&lt;br /&gt;
&lt;br /&gt;
- Help system for the GUI itself&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project'''&lt;br /&gt;
&lt;br /&gt;
To provide the web application security community with a stable and fully &lt;br /&gt;
featured framework to perform all the tasks included in a penetration test&lt;br /&gt;
from within the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected'''&lt;br /&gt;
&lt;br /&gt;
w3af is one of the most active web application security projects;&lt;br /&gt;
the community that supports it is growing and we need the support of &lt;br /&gt;
already established organizations like OWASP to keep working at the &lt;br /&gt;
rate that we want to.&lt;br /&gt;
&lt;br /&gt;
== P006 OWASP Corporate Application Security Rating Guide and P025 OWASP Positive Security Project ==&lt;br /&gt;
&lt;br /&gt;
by Eduardo Vianna de Camargo Neves&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
A common approach on most companies is to increase the protection of their assets after the occurrence of a considerable impact. However some companies learned that a positive approach on IT Security is most effective and can reduce the financial costs on responses to security incidents. Benchmarking the application security practices on the corporate world will allow us to understand what steps are required to keep the IT environment protected, using this knowledge to create a public Security Rating Guide that can be used to support the establishment of a security baseline within the community.&lt;br /&gt;
&lt;br /&gt;
Moreover the information from this analysis can be used to support the development of a campaign to spread a positive security posture in the market. The liaison with companies that maintain good security practices  will help to start this initiative from a higher degree and involve several actors on the security stage for the same direction to a market were security is understood as a business value.&lt;br /&gt;
&lt;br /&gt;
'''Approach'''&lt;br /&gt;
&lt;br /&gt;
Assessing public materials from the Top 50 Companies and Top 50 Software Companies, a rating guide will be produced showing tangible metrics that are achieved by those companies and allow them to be considered secure enough on a comparison to a baseline of good practices. As a result the Corporate Application Security Rating Guide will be produced and published for the community and the deliverables used to support the development of the Positive Security Project with facts from a real analysis.&lt;br /&gt;
&lt;br /&gt;
'''Benefits'''&lt;br /&gt;
&lt;br /&gt;
The whole community will be benefited from these initiatives. With the adequate support from OWASP to maintain the projects active and liaise with big players on the market, we can expect the following:&lt;br /&gt;
&lt;br /&gt;
• The community will receive a Security Rating Guide that will allow them to compare their own security practices within the market. As this will be a public document, suppliers and buyers worldwide will share the same information allowing them to adequate the expectations on the usage of security services and tools.&lt;br /&gt;
&lt;br /&gt;
• The Security Rating Guide can be used as a marketing tool by the companies, allowing them to sell security as a business value and avoiding the old-fashion and inadequate FUD approach.&lt;br /&gt;
&lt;br /&gt;
• The knowledge and relationship developed during the production of the Security Rating Guide will allow us to produce the deliverables on Positive Security Project with real information, increasing the credibility of the initiative for the market.&lt;br /&gt;
&lt;br /&gt;
• The Security Rating Guide and the Positive Security Project can be walk in parallel, merging their information to support a concise and continuous marketing campaign to encourage a positive approach on the market.&lt;br /&gt;
&lt;br /&gt;
• As an open community free from commercial pressures, OWASP can use both projects to support the evaluation of security products for the market, allowing the organization to receive profits from these services and support current and future projects.&lt;br /&gt;
&lt;br /&gt;
'''Summarized Work Breakdown Structure (WBS)'''&lt;br /&gt;
&lt;br /&gt;
All the activities will be leaded by Eduardo V. C. Neves, which will be responsible as a single point of contact with the sponsors and to manage a team of compromised volunteers from OWASP community and participants from security communities and associations (i.e. ISSA, SANS and ISC2).&lt;br /&gt;
&lt;br /&gt;
The activities will be carried on WBS summarized bellow. Dates presented should be considered as deadlines for the activities:&lt;br /&gt;
&lt;br /&gt;
• Criteria establishment and definition of the Top 50 Companies and Top 50 Software Companies (April 11)&lt;br /&gt;
&lt;br /&gt;
• Assessment of public materials to support the ranking establishment (April 18)&lt;br /&gt;
&lt;br /&gt;
• Establishment of the Corporate Application Security Rating Guide (April 25)&lt;br /&gt;
&lt;br /&gt;
• Publishing of the Corporate Application Security Rating Guide on OWASP web site and promotion over adequate channels (i.e. publications, blogs and associations) (May 09) (1)&lt;br /&gt;
&lt;br /&gt;
• Criteria establishment and approval of marketing templates for Positive Security Project (May 16) (2)&lt;br /&gt;
&lt;br /&gt;
• Development of the Positive Security Project material (i.e. blog and marketing sheets) (May 30)&lt;br /&gt;
&lt;br /&gt;
• Liaison with the OWASP Members, Top 50 Companies and Top 50 Software Companies to present the project and negotiate their participation as supporters, sponsors or contributors. (June 27)&lt;br /&gt;
&lt;br /&gt;
• Update on Corporate Application Security Rating Guide, including their score on Positive Security approach (July 4)&lt;br /&gt;
&lt;br /&gt;
• Presentation of the Positive Security Project approach and Corporate Application Security Rating Guide on the market (July 31) (3)&lt;br /&gt;
&lt;br /&gt;
• Conference calls with team members to evaluate the results of the initiatives in all countries and produce project´s documents (i.e. lessons learned, update on marketing material and evaluation of alternative approaches for the future steps). (August 15)&lt;br /&gt;
&lt;br /&gt;
• Prepare project documentation and present to the OWASP community on the web site (August 31)&lt;br /&gt;
&lt;br /&gt;
''(1) Support from OWASP Foundation is required to liaise with companies and associations worldwide&lt;br /&gt;
&lt;br /&gt;
''(2) Support from OWASP Foundation and community are required to evaluate adequate marketing templates and translate original documents for their own languages''&lt;br /&gt;
&lt;br /&gt;
''(3) Support from OWASP community is required to spread the word on all countries were OWASP members are located.''&lt;br /&gt;
'''''&lt;br /&gt;
&lt;br /&gt;
'''Project Control'''&lt;br /&gt;
&lt;br /&gt;
The project will be managed following PRINCE2 Process Model and all control documents published for the OWASP community. The following mandatory project control documents are planned:&lt;br /&gt;
&lt;br /&gt;
• Project Initiation Document: To document project´s background, definition, objectives, approach, etc.&lt;br /&gt;
&lt;br /&gt;
• Communication Plan: To assure that OWASP Community are being continuous communicated about project status and deliverables achievement.&lt;br /&gt;
&lt;br /&gt;
• Highlight Report: To provide the OWASP Community with a summary of the project status, progress and potential problems or areas where help may be required.&lt;br /&gt;
&lt;br /&gt;
• End Project Report: To present project achievements. Should be considered the final project report.&lt;br /&gt;
&lt;br /&gt;
More documents may be included during project development to support the control and assure a high quality level (i.e. issue log, project approach).&lt;br /&gt;
&lt;br /&gt;
'''Long Range Plan'''&lt;br /&gt;
&lt;br /&gt;
Both projects should walk in parallel and be used as tools to support efforts to encourage and make the positive approach a reality on the IT Security field. These initiatives shall be supported by OWASP as long term plans and grow to a continuous world-wide campaign in this direction that must achieve big players on the market and be recognized by the community as a tool that must be used to evaluate security enabled companies and products. &lt;br /&gt;
&lt;br /&gt;
'''Why me?'''&lt;br /&gt;
&lt;br /&gt;
Can be me, you or anyone that carries these projects in a professional fashion and assure that all deliverables are being achieved. The most important parts is to make it happen, talk and get the support from reputable associations and large companies (OWASP Members are a good start) and lead it as a long range responsibility.&lt;br /&gt;
&lt;br /&gt;
I am running to win this project because I believe in all of this. I see both as very valuable initiatives that can help companies to make more business; people to get more jobs and the whole community to win in a scenario where our contributions on the security market are recognized as business tools.&lt;br /&gt;
&lt;br /&gt;
'''About me'''&lt;br /&gt;
&lt;br /&gt;
Information Security professional and enthusiastic with 15 years dedicated to achieve expressive results in the areas of IT, Information Security, Compliance and Project Management. A CISSP in good stand and Officer at the ISSA Brazilian Chapter, my professional career gave me extensive knowledge in several fields of Information Security with accumulated experience at consulting firms, as CSO at a world player company on consumer goods market and now as an entrepreneur at Latin American market.&lt;br /&gt;
&lt;br /&gt;
''Application security experience and accomplishments''&lt;br /&gt;
&lt;br /&gt;
My work experience is on Security Management, Risk Assessment, Business Continuity and Disaster Recovery, Security Awareness and other managed-related fields on our industry. I don’t have hands-on experience on application security and this is the main reason why I am running to be qualified on the project described bellow, where I believe that my skills can be used to achieve an excellent result for the community.&lt;br /&gt;
&lt;br /&gt;
''Participation and leadership in open communities''&lt;br /&gt;
&lt;br /&gt;
• Member of OWASP Brazil where I made some small contributions in a recent past.&lt;br /&gt;
&lt;br /&gt;
• Member of ABNT/CB-21/SC02 committee, Brazilian ISO representative for 27001 and 17799 standards&lt;br /&gt;
&lt;br /&gt;
• Officer of ISSA Brazil Chapter where I am responsible for the South Region and as the editor of Antebellum, the ISSA Brazil Journal&lt;br /&gt;
&lt;br /&gt;
• Founder and member of GISI-PR, an open community focused on discuss and promote Information Security initiatives within Paraná State, Brazil&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application ==&lt;br /&gt;
'''Name'''&lt;br /&gt;
&lt;br /&gt;
Michael Coates&lt;br /&gt;
&lt;br /&gt;
'''Project'''&lt;br /&gt;
&lt;br /&gt;
P017 - OWASP AppSensor - Detect and Respond to Attacks from Within the Application&lt;br /&gt;
&lt;br /&gt;
'''The opportunity, challenges, issues or need your proposal addresses, '''&lt;br /&gt;
&lt;br /&gt;
As critical applications continue to become more accessible and inter-connected, it is paramount that the information be protected. We must also realize that our defenses may not be perfect. Given enough time, attackers can identify security flaws in the design or implementation of an application. In addition to implementing layers of defense within an application, it is critical that we identify malicious individuals before they are able to identify any gaps in our defenses. The best place to identify malicious activity against the application is within the application itself.&lt;br /&gt;
Network based intrusion detection systems are not appropriate to handle the custom and intricate workings of an enterprise application and are ill-suited to detect attacks focusing on application logic such as authentication, access control, etc.  The application itself is the best place to identify and respond to malicious activity.&lt;br /&gt;
This project will create the framework which can be used to build a robust system of attack detection, analysis, and response within an enterprise application&lt;br /&gt;
&lt;br /&gt;
'''Objectives or ways in which you will meet the goal(s), '''&lt;br /&gt;
&lt;br /&gt;
I plan to use a methodical approach throughout the creation of this resource. I will reference my own professional experience, OWASP resources, ESAPI, and academic materials to identify a robust set of potential attacks and identification methods. Thresholds will be recommended for each of the detected attacks. Each recommended threshold value and response recommendation will be accompanied with additional information to describe the purpose of the threshold and recommendation. This additional information will allow the reader to determine if the threshold is appropriate for their implementation.&lt;br /&gt;
&lt;br /&gt;
'''Specific activities and who will carry out these activities, '''&lt;br /&gt;
&lt;br /&gt;
I will complete the following activities:&lt;br /&gt;
1. Identify and define attack patterns against applications&lt;br /&gt;
2. Document points of detection within the application for the attack patterns &amp;amp; identify key information to log&lt;br /&gt;
3. Create thresholds for generating security alerts&lt;br /&gt;
4. Define recommended response actions for the security alerts&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Specific deliverables and a rough project schedule so we can track progress, '''&lt;br /&gt;
&lt;br /&gt;
April 2, 2008 - Project Begins&lt;br /&gt;
&lt;br /&gt;
April 2, 2008-April 12, 2008 - High level planning &amp;amp; design 	&lt;br /&gt;
&lt;br /&gt;
April 12, 2008-May 1, 2008 - Identify and define attack patterns against applications	&lt;br /&gt;
&lt;br /&gt;
May 1, 2008-June 1, 2008 - Document points of detection within the application for the attack patterns &amp;amp; identify key information to log	&lt;br /&gt;
&lt;br /&gt;
June 1, 2008-June 13, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
June 15, 2008 - Status Report	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Create thresholds for generating security alerts	&lt;br /&gt;
&lt;br /&gt;
June 16, 2008-Aug 15, 2008 - Define recommended response actions for the security alerts	&lt;br /&gt;
&lt;br /&gt;
Aug 16, 2008-Aug 30, 2008 - Pier Review &amp;amp; Revisions	&lt;br /&gt;
&lt;br /&gt;
Aug 31, 2008 - Project Complete	&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Long-term vision for the project, '''&lt;br /&gt;
&lt;br /&gt;
1.  I’d like to include a tiered type approach of thresholds and responses. This is would be similar to the approach used by FISMA of defining different controls for High, Medium, and Low systems.&lt;br /&gt;
&lt;br /&gt;
2. Building on item #1, I want to eventually include a system which lets the user provide information about their system.  This information could include rating or prioritizing different security concerns. a customized set of monitoring points, thresholds and response actions can be recommended for the application based on the provided data.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''About Me'''&lt;br /&gt;
&lt;br /&gt;
'''Education &amp;amp; Professional Background'''&lt;br /&gt;
&lt;br /&gt;
Masters of Science in Computer, Information and Network Security – DePaul University &lt;br /&gt;
(Expected Graduation 2009)&lt;br /&gt;
Bachelor of Science in Computer Science – University of Illinois&lt;br /&gt;
Extensive experience in conducting black and white box security reviews of complex applications and networks for major financial organizations and international telecoms. I also have experience working as the primary investigator of attacks against a multi-national organization with IDS sensors in networks throughout the world. In addition, I have experience working with several regulatory controls and security standards (FISMA, NIST, GLBA etc). My experience as an ethical hacker and incident responder puts me in an excellent position to tackle this project. &lt;br /&gt;
&lt;br /&gt;
'''Application security experience and accomplishments'''&lt;br /&gt;
&lt;br /&gt;
I am a Senior Computer Security Engineer with Aspect Security where I perform security code reviews and application security testing against a variety of platforms. Prior to working with Aspect Security, I was heavily involved in the discovery and exploitation of application vulnerabilities during black box ethical hacking assessments for numerous clients.&lt;br /&gt;
&lt;br /&gt;
'''Participation and leadership in open communities'''&lt;br /&gt;
&lt;br /&gt;
I am a member of OWASP and attend Chicago OWASP chapter meetings. I also attend ChiSec, an informal meet-up of security professionals in the Chicago area. In addition, I interact with the community through my security blog. http://michaelcoates.wordpress.com. &lt;br /&gt;
&lt;br /&gt;
'''Any other reasons why you and your project should be selected. '''&lt;br /&gt;
&lt;br /&gt;
I created a similar framework while working within a Security Operation Center. I created attack scenarios, identified relevant IDS events, defined thresholds and appropriate response action for the Security analysts.&lt;br /&gt;
&lt;br /&gt;
'''Requested Reviewer - Eric Sheridan, Application Security Consultant at Aspect Security, Inc.'''&lt;br /&gt;
&lt;br /&gt;
Eric Sheridan is an Application Security Consultant at Aspect Security, a consulting services company specializing in application security. At Aspect Security, Eric specializes in execution of security verification assessments and the establishment of security activities throughout the development lifecycle. In addition, Eric is an instructor in Aspect’s portfolio of Application Security Courses. Eric is also an active participant in OWASP whose contributions include work with projects such as WebGoat, Stinger, CSRFGuard, CSRFTester, and the SASAP project from OWASP SPoC 2007. Eric was also a featured speaker at the 2007 OWASP/WASC San Jose conference.&lt;br /&gt;
&lt;br /&gt;
Contact Information: eric dot sheridan 'at' owasp dot org&lt;br /&gt;
&lt;br /&gt;
== OWASP Interceptor Project - 2008 Update ==&lt;br /&gt;
&lt;br /&gt;
by Justin Derry&lt;br /&gt;
&lt;br /&gt;
http://www.owasp.org/index.php/Category:OWASP_Interceptor_Project&lt;br /&gt;
&lt;br /&gt;
'''Executive Summary'''&lt;br /&gt;
&lt;br /&gt;
The OWASP Interceptor project was originally written by myself and donated to the OWASP project. Since it has been online numerous people have downloaded the tools and used the code/toolkit. Currently the industry has very limited “XML” or SOAP client testing tools that are designed specifically to perform XML interception and manipulation. The Objective of the Interceptor project is to provide a strong tool for performing XML penetration tests against Web Service (or XML/SOAP) endpoints. The tool should not replace other proxy interception tools such as Charles, Web Scarab and so on, but be purely focused on handling and reading XML structures from clients.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Interceptor tool includes a “swiss-army” knife of features that will help with decoding/hash generation and interpretation of XML code. The key objective is to make a tool that can assist with the collection, inspection and attack replay of XML requests against service endpoints. This year it’s time for an update. The tool doesn’t run on Vista and needs a number of back-end features addressed as well as some help files etc. (Help to get the tool out of BETA status).&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Objectives this year'''&lt;br /&gt;
&lt;br /&gt;
This year I see the following objectives in the application code base.&lt;br /&gt;
•	Get the Interface to run on all Window Platforms (.NET) Win2000, XP and Vista;&lt;br /&gt;
&lt;br /&gt;
•	Update the TCP handle libraries to be faster&lt;br /&gt;
&lt;br /&gt;
•	Update the XML Parser engine to support the latest structures&lt;br /&gt;
&lt;br /&gt;
•	Provide a “default” attack database of known XML attack methods (this is a big one)&lt;br /&gt;
&lt;br /&gt;
•	Write a number of help files on how to use the tool&lt;br /&gt;
&lt;br /&gt;
•	Update the toolkit BASE64 Decoder, XML Generators etc with further tools&lt;br /&gt;
&lt;br /&gt;
•	Write a better “reporting” engine to show the result of simulated attack responses&lt;br /&gt;
&lt;br /&gt;
•	Better HTTP support for Manipulation, Authentication and Header Injection etc&lt;br /&gt;
&lt;br /&gt;
•	Better support for interception and handling AJAX XML requests&lt;br /&gt;
&lt;br /&gt;
These are the core features I would like to introduce, with also further to probably come as a part of the project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''Why should I be sponsored for the project?'''&lt;br /&gt;
&lt;br /&gt;
The current development cycle stopped due to limited time and the need to purchase the IDE tools to develop the interface in .NET. As a Summer of Code 2008 sponsored project we can get the IDE interface tools to implement “Vista” features that will see the tool run on all .NET platforms (Win2000, XP and Vista). Recent changes in my job will allow me to spend more time on developing the toolkit.&lt;br /&gt;
&lt;br /&gt;
Over a number of years I have been involved with OWASP, whilst most recently getting involved with running the OWASP Australia Security Conference for 2008, as well as the Brisbane Chapter. I am also working in the Asia Pacific RIM to further increase the awareness of OWASP and Application Security. My Conference duties for the year have finished up (till planning starts again in a couple of months) so my time can be invested in updating the toolkit.&lt;br /&gt;
&lt;br /&gt;
I believe during the previous years, i have shown OWASP that i am willing and able to produce a quality outcome and i am prepared to put the effort into OWASP to acheive the goals set out for this project. &lt;br /&gt;
&lt;br /&gt;
Some of the Sponsorship money for the project would go to purchasing a specific toolkit for the UI. (The UI is important simply because we want the application to be user friendly). Xceed Components provide a Smart UI as well as some of the decoding and compression features the tool needs. This would require us to approach them upfront for a “free” licence or use some of the Sponsorship money to buy the toolkit. But we can tackle that problem when we come to it.&lt;br /&gt;
&lt;br /&gt;
== SQL Injector Benchmarking Project (SQLiBENCH) ==&lt;br /&gt;
&lt;br /&gt;
by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
'''Prelude'''&lt;br /&gt;
&lt;br /&gt;
There're a lot of and great open source tools (takeover/dumpers/hybrid) for taking advantage of an sql injection vulnerability both used by web application security specialists and attackers. &lt;br /&gt;
Techniques used, databases supported, algorithms employed and abilities implemented by these &amp;quot;sql injectors&amp;quot; greatly varies. Standardization is one of the abstract goals of OWASP and we think it's important to standardize general vulnerability techniques exists in web applications and one of the biggest one is sql manipulation. &lt;br /&gt;
In our effort, we aim to produce a standardization of techniques used in exploiting sql injection by automatic tools. &lt;br /&gt;
&lt;br /&gt;
'''Proposal'''&lt;br /&gt;
&lt;br /&gt;
The goal of the project is to create a detailed set of benchmarking criterias for automatic sql injection tools and applying these to a set of open source sql injectors, producing analysis/benchmarking reports.&lt;br /&gt;
Additionaly, in a semi-academic manner, algorithms used by several sql injectors will be analyzed both implementation and complexity vise.&lt;br /&gt;
&lt;br /&gt;
'''Deliverables And Project Schedule Milestones'''&lt;br /&gt;
&lt;br /&gt;
Two set of documents will be produced. One of them will include the benchmarking criterias and the other will comprise of analysis of selected sql injectors against the benchmarking criterias.&lt;br /&gt;
Moreover, an interactive visual data flow diagram, giving hints to testers about which tool should be used under which circumstances, will be implemented with web-based technologies such as jquery library. &lt;br /&gt;
&lt;br /&gt;
April 03    Project Kickoff&lt;br /&gt;
&lt;br /&gt;
April 03-30 Determination of the benchmarking criterias &lt;br /&gt;
&lt;br /&gt;
May   01-15 Producing a test environment image with 5-6 rdbms (MSSQL Express, Oracle Express, DB2 Express, MySQL, PgSQL, etc.) and a vulnerable application (which will support different sql injection types, databases and include logging capabilities)&lt;br /&gt;
&lt;br /&gt;
May   15-31 Selecting and installing automatic sql injectors onto the test system and starting to use them on vulnerable application&lt;br /&gt;
&lt;br /&gt;
June  01-30 Analysing tools and applying benchmarking criterias, contacting the authors as we proceed &lt;br /&gt;
&lt;br /&gt;
July  01-31 Producing reports for benchmarking criterias and tool analysis&lt;br /&gt;
&lt;br /&gt;
'''About Us'''&lt;br /&gt;
&lt;br /&gt;
We're part of OWASP-Turkey. [http://www.h-labs.org Mesut Timur] is a junior in the Computer Engineering Dept. of [http://www.gyte.edu.tr University of GYTE] and [http://www.webguvenligi.org Bedirhan Urgun] is a web/application security specialist in [http://www.uekae.tubitak.gov.tr TUBITAK-UEKAE].&lt;br /&gt;
&lt;br /&gt;
== Bunyamin Demir – OWASP WeBekci Project ==&lt;br /&gt;
&lt;br /&gt;
==== Executive Summary: ====&lt;br /&gt;
&lt;br /&gt;
Web application firewalls (WAF) are gaining importance among the information security technologies designed to protect web sites from attack. WAF solutions prevent attacks that network firewalls and intrusion detection systems can't and they require no modification of application source code. ModSecurity [http://www.modsecurity.org/] is an open source web application firewall that runs as an Apache module. It is an embeddable web application firewall and it provides protection from a range of attacks against web applications. It is an open source project available to everyone; it however does not come with an admin panel. &lt;br /&gt;
&lt;br /&gt;
I decided to provide this essential tool with a control panel which I believe will ease and thus encourage its usage.&lt;br /&gt;
&lt;br /&gt;
ModSecurity allows for HTTP traffic monitoring and real-time analysis with no changes to existing infrastructure. My main goal is to analyze attacks and generate rules to change the configuration of the ModSecurity accordingly.&lt;br /&gt;
&lt;br /&gt;
ModSecurity  has a feature called “flexible rule engine” as its heart of Attack Prevention capability . It uses ModSecurity’s “Rule Language,” (a programming language designed to work with HTTP transaction data). It is easy to use and flexible; yet the system administrators need to learn its own rules to create what is called “Certified ModSecurity Rules” to be implemented. My control panel will automate the major code-generation in Rule Language. &lt;br /&gt;
&lt;br /&gt;
==== Objectives and Deliverables: ====&lt;br /&gt;
&lt;br /&gt;
* '''Configuration'''        : Most of the configuration parameters will be managed through the web interface&lt;br /&gt;
* '''Rule Generator'''       : Basic rules will be generated using the web interface&lt;br /&gt;
* '''Core Rule Integration''': Core rules will be added to the database for use&lt;br /&gt;
* '''Logging and Reporting''': Apache error log and modsec_audit log will be parsed and presented to the user thru the web interface&lt;br /&gt;
* '''DB Support'''           : MySQL&lt;br /&gt;
&lt;br /&gt;
==== Why I should be sponsored for the project: ====&lt;br /&gt;
Being a SpoC2007 project, it couldn't be implemented mainly due to a job change and therefore lack of time. With the help of Bedirhan Urgun we'll be able to produce a quality web admin panel GUI for a same host modsec installation infrastructure. We are both part of OWASP Turkey [http://www.owasp.org/index.php/Turkey] and tried to produce a great deal of awareness both about web security and OWASP with both documents/chapter meetings/email list and mini-conferences.&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=22561</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=22561"/>
				<updated>2007-10-22T20:03:57Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:urgunb@hotmail.com Bedirhan Urgun], [mailto:bunyamindemir@gmail.com Bunyamin Demir], [mailto:ferruh@mavituna.com Ferruh Mavituna]&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Ceviri projesine yardim etmek isteyen arkadaslar lutfen [mailto:bunyamindemir@gmail.com iletisime] geciniz.&lt;br /&gt;
&lt;br /&gt;
== Sponsors == &lt;br /&gt;
&lt;br /&gt;
[http://www.pro-g.com.tr http://www.owasp.org/images/a/a9/Turkey_Chapter_Sponsor1_Pro-G.gif]&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=21409</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=21409"/>
				<updated>2007-09-03T21:03:34Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir@gmail.com Bunyamin Demir], [mailto:ferruh@mavituna.com Ferruh Mavituna]&lt;br /&gt;
 |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Ceviri projesine yardim etmek isteyen arkadaslar lutfen [mailto:bunyamindemir@gmail.com iletisime] geciniz.&lt;br /&gt;
&lt;br /&gt;
== Sponsors == &lt;br /&gt;
&lt;br /&gt;
[http://www.pro-g.com.tr http://www.owasp.org/images/a/a9/Turkey_Chapter_Sponsor1_Pro-G.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin Demir&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan Gurler&lt;br /&gt;
Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Day&amp;diff=21408</id>
		<title>OWASP Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Day&amp;diff=21408"/>
				<updated>2007-09-03T21:01:50Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Global Agenda (19 Chapters participating) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP Day : Worldwide OWASP chapter meetings on the topic &amp;quot;Privacy in the 21st Century&amp;quot; (5th till 12th September 2007) ==&lt;br /&gt;
&lt;br /&gt;
'''OWASP Day''' is the title given to the 17 chapter meetings (hosted by 19 OWASP Chapters) staged during the [http://www.globalsecurityweek.com/ Global Security Week].&lt;br /&gt;
&lt;br /&gt;
== Global Agenda (19 Chapters participating) ==&lt;br /&gt;
&lt;br /&gt;
* '''Wed 5th'''&lt;br /&gt;
** [[Israel]] (16:45 / 19:30)&lt;br /&gt;
*** &amp;quot;Straight from Blackhat: Dangling Pointers&amp;quot; , Jonathan Afek , Watchfire&lt;br /&gt;
*** &amp;quot;Evasive Crimeware attacks, Business drivers, and Proposed Defense&amp;quot; , Iftach Amit , Finjan&lt;br /&gt;
*** &amp;quot;Content Injection as a solution for client side browser vulnerabilities&amp;quot; , Ofer Shezaf , Breach Security (Israel chapter Leader)&lt;br /&gt;
** [[London]] (18:30 / 21:30)&lt;br /&gt;
*** &amp;quot;For my next trick... hacking Web2.0&amp;quot;, Petko D. Petkov (pdp), GNUCITIZEN&lt;br /&gt;
*** Panel: &amp;quot;Privacy in the 21st Century?&amp;quot;, moderator: Ivan Ristic&lt;br /&gt;
*** Panel: &amp;quot;Future of the OWASP London Chapter&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* '''Thu 6th'''&lt;br /&gt;
** [[NYNJMetro]] (17:30 / 21:00)&lt;br /&gt;
*** &amp;quot;Financial Real-Time Threats: Impacting Trading Floor Operations&amp;quot;&lt;br /&gt;
*** &amp;quot;JBroFuzz: Effective Fuzzing for Network and Web Applications&amp;quot; , Dr. Yiannis Pavlosoglou , Information Risk Management&lt;br /&gt;
*** &amp;quot;Stock fluctuation from an unrecognized influence&amp;quot; , Justine Bone-Aitel , Immunity Security&lt;br /&gt;
*** &amp;quot;Hackers...BotNets oh My! Obtain a briefing on the current BotNet investigations etc.&amp;quot;, NYC FBI Cyber Crime Unit &lt;br /&gt;
*** &amp;quot;Why today's vulnerability assessments are failing and a case for industry standardization&amp;quot;&lt;br /&gt;
*** &amp;quot;Blackhat/Defcon&amp;quot;, Tom Brennan (President OWASP NY/NJ Metro)&lt;br /&gt;
*** Panel: &amp;quot;Global Security Week What is the current state of Privacy on Web Application Security? What should we be focusing on?&amp;quot;&lt;br /&gt;
** [[Belgium]] (12:30 / 19:30)&lt;br /&gt;
*** pre-event: &amp;quot;Getting started with WebGoat &amp;amp; WebScarab&amp;quot; ,Erwin Geirnaert , ZION Security&lt;br /&gt;
*** &amp;quot;OWASP Evaluation and Certification Criteria Draft&amp;quot; , Mark Curphey (OWASP founder)&lt;br /&gt;
*** &amp;quot;Automated Web FOO or FUD?&amp;quot; , David Kierznowski, GNUCITIZEN&lt;br /&gt;
*** &amp;quot;OWASP Pantera Unleashed&amp;quot; , Simon Roses Femerling , Microsoft&lt;br /&gt;
*** &amp;quot;CLASP, SDL and Touchpoints Compared&amp;quot; , Bart De Win, DistriNet research group&lt;br /&gt;
*** &amp;quot;Threats of e-insecurity in Belgium and the Belgian response&amp;quot; ,  Luc Beirens, FCCU &lt;br /&gt;
*** &amp;quot;For my next trick... hacking Web2.0 (pdp)&amp;quot; , Petko D. Petkov (pdp), GNUCITIZEN &lt;br /&gt;
*** &amp;quot;Panel Discussion: “Privacy in the 21st Century?&amp;quot;, moderator: André Marien , Verizon Business - Cybertrust&lt;br /&gt;
** [[Washington DC]] + Northern VA (13:00 / 18:15)&lt;br /&gt;
*** &amp;quot;Honeyclients and Malicious Web Servers&amp;quot; , Kathy Wang , Mitre&lt;br /&gt;
*** &amp;quot;A malcode perspective on web application privacy&amp;quot; Blake Hartstein , iDefense &lt;br /&gt;
*** &amp;quot;Practical Web Privacy with Firefox&amp;quot; , Chuck Willis , Mandiant&lt;br /&gt;
*** &amp;quot;A sneak peak at Jeff's new &amp;quot;Enterprise Security API&amp;quot; , Jeff Williams , Aspect Security (OWASP board member &amp;amp; Chairman) &lt;br /&gt;
*** &amp;quot;Digital Rights Management&amp;quot; , James Stibbards , Cloakware&lt;br /&gt;
** [[San Antonio]] (11:30 / 13:00)&lt;br /&gt;
*** &amp;quot;Developing an Application Security Strategy for Large Enterprise Systems&amp;quot; , Bruce Jenkins, Fortify Software&lt;br /&gt;
** [[Seattle]] (18:00 / 21:00)&lt;br /&gt;
*** &amp;quot;Online Banking&amp;quot; , Rob Rachwald , Fortify&lt;br /&gt;
*** &amp;quot;Web Hacking 101&amp;quot;, Damon Cortesi , IOActive&lt;br /&gt;
** [[San Jose]] + San Francisco (17:00 / 20:30)&lt;br /&gt;
***  Workshop: &amp;quot;Malicious Code Injection Workshop&amp;quot; , Siva Ram , AppSec Consulting ; Arian Evans ,WhiteHat Security&lt;br /&gt;
***  Panel: &amp;quot;Privacy, Security and Breaches, Oh My!&amp;quot;, moderator: Alex Stamos, iSEC Partners ; Panelists: Doran Rotman, KPMG ; David Pollino, Washington Mutual Bank ; Robert Fly, Salesforce.com ; Larry Pingree, Safeway ; Kurt Opsahl, EFF  &lt;br /&gt;
** [[Mumbai]] (14:30 / 18:00)&lt;br /&gt;
*** &amp;quot;Black Vector of Web Exploitation&amp;quot; , Aditya Sood , Sec Niche&lt;br /&gt;
*** &amp;quot;End User Privacy Breaches&amp;quot; , Rishi Narang , Third Brigade&lt;br /&gt;
*** &amp;quot;Privacy on the Web - The road ahead in the 21st century&amp;quot; , Yogesh Badwe , GTL  &lt;br /&gt;
** [[Ottawa]] (18:00 / 20:00)&lt;br /&gt;
*** Security Development Lifecycle for IT , Christian Beauclai , Microsoft &lt;br /&gt;
** [[Phoenix]]&lt;br /&gt;
*** TBA&lt;br /&gt;
** [[Poland]] (18:00 / 21:00)&lt;br /&gt;
*** &amp;quot;OWASP&amp;quot; , Robert 'shadow' Pajak&lt;br /&gt;
*** &amp;quot;OWASP SPoC&amp;quot; , Przemyslaw 'rezos' Skowron&lt;br /&gt;
*** &amp;quot;Pentration test - OWASP in practice&amp;quot; , Jarek Sajko&lt;br /&gt;
** [[Boston]]  &lt;br /&gt;
*** TBA &lt;br /&gt;
&lt;br /&gt;
* '''Sat 8th'''&lt;br /&gt;
** [[Turkey]]&lt;br /&gt;
*** &amp;quot;Prelude. OWASP DAY and OWASP Turkey projects&amp;quot;, Bedirhan Urgun, Bunyamin Demir&lt;br /&gt;
*** &amp;quot;Privacy in Governmental Insitutions - A Current State Analysis&amp;quot;, Hayrettin Bahsi, Chief Researcher UEKAE TUBITAK  &lt;br /&gt;
*** &amp;quot;Secure Web Application Development - Korhan Gurler ,Researcher PRO-G &lt;br /&gt;
*** &amp;quot;A Panel on Privacy in Turkey - OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
* '''Mon 10th'''&lt;br /&gt;
** [[Italy]] (9:00 / 13:30)&lt;br /&gt;
*** &amp;quot;Privacy in the digital era&amp;quot; , Mauro Bregolin , KIMA Projects &amp;amp; Services&lt;br /&gt;
*** &amp;quot;OWASP Top 10 2007 - Are our information 'really' safe?&amp;quot; ,  Carlo Pelliccioni , MediaService&lt;br /&gt;
*** &amp;quot;Anti-Anti-XSS: bypass browser protections&amp;quot; , Alberto Revelli ,  Portcullis &lt;br /&gt;
*** &amp;quot;Growing Application Security Awareness&amp;quot; , Laurent Petroque , F5&lt;br /&gt;
*** &amp;quot;Buzzwords Security&amp;quot; , Luca Carettoni , SecureNetwork&lt;br /&gt;
*** &amp;quot;Hacker Attacks on the Horizon: Understanding the Top Web 2.0 Attack Vectors&amp;quot; , Danny Allan , Watchfire&lt;br /&gt;
** [[Rochester]] &lt;br /&gt;
*** &amp;quot;The new OWASP Top Ten.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* '''Mon 12th'''&lt;br /&gt;
** [[Houston]] (17:30 / 19:30)&lt;br /&gt;
*** &amp;quot;Enhancing Application Security with Bytecode Instrumentation&amp;quot; , Patrick White , Fortify Software &lt;br /&gt;
** [[Cleveland]]&lt;br /&gt;
*** &amp;quot;The new OWASP Top Ten.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''Note:''' If you are interested in doing a presentation, the following chapters have speaker slots available: Rochester, Boston, Phoenix, Poland and Turkey&lt;br /&gt;
&lt;br /&gt;
== Organizers == &lt;br /&gt;
&lt;br /&gt;
In addition to the local chapter leaders,  Dinis Cruz and Mike de Libero are the main points of contact (but of course much more help is needed :)  )&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Global Security Week (GWS) ==&lt;br /&gt;
&lt;br /&gt;
For more details on the (GWS) see:&lt;br /&gt;
*  http://www.globalsecurityweek.com/&lt;br /&gt;
* http://www.globalsecurityweek.com/html/national_activities.html&lt;br /&gt;
* http://www.globalsecurityweek.com/html/gsw_06.html  (Resources)&lt;br /&gt;
&lt;br /&gt;
And here is a description from one the organizers:&lt;br /&gt;
&lt;br /&gt;
''The aim of Global Security Week is to raise security awareness amongst the public and organizations about issues relating to security, primarily information security.  This year's theme is on the subject of privacy and we hope that a number of events will be held worldwide to promote people's awareness as to how to protect their privacy when online and also educate companies on their responsibilities, both legal and morally, when it comes to protecting the privacy of their customers.&lt;br /&gt;
''&lt;br /&gt;
''Global Security Week is a totally voluntary initiative and we have no commercial funding or agenda.  The initiative is funded entirely from the committee's own funds and time.  We have people involved in Global Security Week throughout the world and during the week we have events planned in different regions.  For example here in Ireland I plan to run a free seminar on the above topic open to anyone who wished to attend''&lt;br /&gt;
&lt;br /&gt;
''We ask that those who wish to become involved, help promote Global Security Week in their region either by running specific events dedicated to Global Security Week, taking part in events already planned or simply making people aware that the week is on and the topic is &amp;quot;Privacy in the 21st Century&amp;quot;. Even simply making people aware of Global Security Week and directing them to the website is a great help. Not having commercial funding we depend on word of mouth and like minded individuals to make people aware of the week.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== ... for future reference ... ==&lt;br /&gt;
==== (original) Proposed Event layout ==== &lt;br /&gt;
 &lt;br /&gt;
Each chapter is free to organize its mini conference and to define how long it should last.&lt;br /&gt;
&lt;br /&gt;
But within the spirit of the event the following ideas are proposed:&lt;br /&gt;
&lt;br /&gt;
* The topic of the event should be on  &amp;quot;Privacy in the 21st Century&amp;quot;, so all talks should be related to it (we should be addressing the Web Application side of Privacy (for example what happens to Privacy with SQL Injection, XSS and issues like pdp's [http://www.gnucitizen.org/blog/snoop-onto-them-as-they-snoop-onto-us Snoop onto Them as they Snoop onto us])&lt;br /&gt;
* The event should have 4 to 5 speaking slots (can be 30m if required)&lt;br /&gt;
* If possible, invite a presenter from the local government to talk about their views on the subject&lt;br /&gt;
* Presentation from a local OWASP Project leader about his/hers project (i.e. for the cases where a leader of an [https://www.owasp.org/index.php/Category:OWASP_Project OWASP Project] lives locally (or will be in that city during the event)&lt;br /&gt;
* All events are recommended to have the same panel discussion on the subject &amp;quot;'''What is the current state of Privacy on Web Application Security? and what should we be focusing on?'''&amp;quot;). After the panel discussion, each local chapters is invited to create a summary of its conclusions for publishing on the OWASP website&lt;br /&gt;
* &amp;quot;Talk 'Lets get rid of 3 major sources of vulnerabilities:&lt;br /&gt;
*# CROSS-SITE SCRIPTING: 70-90% of web applications have Cross-Site Scripting (XSS) holes. You must *both* carefully validate input and use HTML entity encoding on all data output.&lt;br /&gt;
*# SQL INJECTION: If your queries are a bunch of strings and user input concatenated together, your database could be attacked with SQL Injection. Stamp out this attack by using &amp;quot;parameterized&amp;quot; queries, such as Java's PreparedStatement instead.&lt;br /&gt;
*# SESSION EXPOSURE: Your SESSIONIDs are *just* as valuable as usernames and passwords, so make sure you never expose them. Don't ever allow authenticated SESSIONIDs to be sent without SSL or exposed in the URL.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== Other Ideas ====&lt;br /&gt;
* Create a Security Manifest that will be 'signed' by all attendees &lt;br /&gt;
* Distributed capture the flag (where each local chapter plays has a team (against the other chapters))&lt;br /&gt;
* Short intro/welcome movie at the beginning of each mini-conference by OWASP board&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Day&amp;diff=21405</id>
		<title>OWASP Day</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Day&amp;diff=21405"/>
				<updated>2007-09-03T10:18:09Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Global Agenda (19 Chapters participating) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== OWASP Day : Worldwide OWASP chapter meetings on the topic &amp;quot;Privacy in the 21st Century&amp;quot; (5th till 12th September 2007) ==&lt;br /&gt;
&lt;br /&gt;
'''OWASP Day''' is the title given to the 17 chapter meetings (hosted by 19 OWASP Chapters) staged during the [http://www.globalsecurityweek.com/ Global Security Week].&lt;br /&gt;
&lt;br /&gt;
== Global Agenda (19 Chapters participating) ==&lt;br /&gt;
&lt;br /&gt;
* '''Wed 5th'''&lt;br /&gt;
** [[Israel]] (16:45 / 19:30)&lt;br /&gt;
*** &amp;quot;Straight from Blackhat: Dangling Pointers&amp;quot; , Jonathan Afek , Watchfire&lt;br /&gt;
*** &amp;quot;Evasive Crimeware attacks, Business drivers, and Proposed Defense&amp;quot; , Iftach Amit , Finjan&lt;br /&gt;
*** &amp;quot;Content Injection as a solution for client side browser vulnerabilities&amp;quot; , Ofer Shezaf , Breach Security (Israel chapter Leader)&lt;br /&gt;
** [[London]] (18:30 / 21:30)&lt;br /&gt;
*** &amp;quot;For my next trick... hacking Web2.0&amp;quot;, Petko D. Petkov (pdp), GNUCITIZEN&lt;br /&gt;
*** Panel: &amp;quot;Privacy in the 21st Century?&amp;quot;, moderator: Ivan Ristic&lt;br /&gt;
*** Panel: &amp;quot;Future of the OWASP London Chapter&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* '''Thu 6th'''&lt;br /&gt;
** [[NYNJMetro]] (17:30 / 21:00)&lt;br /&gt;
*** &amp;quot;Financial Real-Time Threats: Impacting Trading Floor Operations&amp;quot;&lt;br /&gt;
*** &amp;quot;JBroFuzz: Effective Fuzzing for Network and Web Applications&amp;quot; , Dr. Yiannis Pavlosoglou , Information Risk Management&lt;br /&gt;
*** &amp;quot;Stock fluctuation from an unrecognized influence&amp;quot; , Justine Bone-Aitel , Immunity Security&lt;br /&gt;
*** &amp;quot;Hackers...BotNets oh My! Obtain a briefing on the current BotNet investigations etc.&amp;quot;, NYC FBI Cyber Crime Unit &lt;br /&gt;
*** &amp;quot;Why today's vulnerability assessments are failing and a case for industry standardization&amp;quot;&lt;br /&gt;
*** &amp;quot;Blackhat/Defcon&amp;quot;, Tom Brennan (President OWASP NY/NJ Metro)&lt;br /&gt;
*** Panel: &amp;quot;Global Security Week What is the current state of Privacy on Web Application Security? What should we be focusing on?&amp;quot;&lt;br /&gt;
** [[Belgium]] (12:30 / 19:30)&lt;br /&gt;
*** pre-event: &amp;quot;Getting started with WebGoat &amp;amp; WebScarab&amp;quot; ,Erwin Geirnaert , ZION Security&lt;br /&gt;
*** &amp;quot;OWASP Evaluation and Certification Criteria Draft&amp;quot; , Mark Curphey (OWASP founder)&lt;br /&gt;
*** &amp;quot;Automated Web FOO or FUD?&amp;quot; , David Kierznowski, GNUCITIZEN&lt;br /&gt;
*** &amp;quot;OWASP Pantera Unleashed&amp;quot; , Simon Roses Femerling , Microsoft&lt;br /&gt;
*** &amp;quot;CLASP, SDL and Touchpoints Compared&amp;quot; , Bart De Win, DistriNet research group&lt;br /&gt;
*** &amp;quot;Threats of e-insecurity in Belgium and the Belgian response&amp;quot; ,  Luc Beirens, FCCU &lt;br /&gt;
*** &amp;quot;For my next trick... hacking Web2.0 (pdp)&amp;quot; , Petko D. Petkov (pdp), GNUCITIZEN &lt;br /&gt;
*** &amp;quot;Panel Discussion: “Privacy in the 21st Century?&amp;quot;, moderator: André Marien , Verizon Business - Cybertrust&lt;br /&gt;
** [[Washington DC]] + Northern VA (13:00 / 18:15)&lt;br /&gt;
*** &amp;quot;Honeyclients and Malicious Web Servers&amp;quot; , Kathy Wang , Mitre&lt;br /&gt;
*** &amp;quot;A malcode perspective on web application privacy&amp;quot; Blake Hartstein , iDefense &lt;br /&gt;
*** &amp;quot;Practical Web Privacy with Firefox&amp;quot; , Chuck Willis , Mandiant&lt;br /&gt;
*** &amp;quot;A sneak peak at Jeff's new &amp;quot;Enterprise Security API&amp;quot; , Jeff Williams , Aspect Security (OWASP board member &amp;amp; Chairman) &lt;br /&gt;
*** &amp;quot;Digital Rights Management&amp;quot; , James Stibbards , Cloakware&lt;br /&gt;
** [[San Antonio]] (11:30 / 13:00)&lt;br /&gt;
*** &amp;quot;Developing an Application Security Strategy for Large Enterprise Systems&amp;quot; , Bruce Jenkins, Fortify Software&lt;br /&gt;
** [[Seattle]] (18:00 / 21:00)&lt;br /&gt;
*** &amp;quot;Online Banking&amp;quot; , Rob Rachwald , Fortify&lt;br /&gt;
*** &amp;quot;Web Hacking 101&amp;quot;, Damon Cortesi , IOActive&lt;br /&gt;
** [[San Jose]] + San Francisco (17:00 / 20:30)&lt;br /&gt;
***  Workshop: &amp;quot;Malicious Code Injection Workshop&amp;quot; , Siva Ram , AppSec Consulting ; Arian Evans ,WhiteHat Security&lt;br /&gt;
***  Panel: &amp;quot;Privacy, Security and Breaches, Oh My!&amp;quot;, moderator: Alex Stamos, iSEC Partners ; Panelists: Doran Rotman, KPMG ; David Pollino, Washington Mutual Bank ; Robert Fly, Salesforce.com ; Larry Pingree, Safeway ; Kurt Opsahl, EFF  &lt;br /&gt;
** [[Mumbai]] (14:30 / 18:00)&lt;br /&gt;
*** &amp;quot;Black Vector of Web Exploitation&amp;quot; , Aditya Sood , Sec Niche&lt;br /&gt;
*** &amp;quot;End User Privacy Breaches&amp;quot; , Rishi Narang , Third Brigade&lt;br /&gt;
*** &amp;quot;Privacy on the Web - The road ahead in the 21st century&amp;quot; , Yogesh Badwe , GTL  &lt;br /&gt;
** [[Ottawa]] (18:00 / 20:00)&lt;br /&gt;
*** Security Development Lifecycle for IT , Christian Beauclai , Microsoft &lt;br /&gt;
** [[Phoenix]]&lt;br /&gt;
*** TBA&lt;br /&gt;
** [[Poland]]&lt;br /&gt;
*** TBA  &lt;br /&gt;
** [[Boston]]  &lt;br /&gt;
*** TBA &lt;br /&gt;
&lt;br /&gt;
* '''Sat 8th'''&lt;br /&gt;
** [[Turkey]]&lt;br /&gt;
*** &amp;quot;Prelude. OWASP DAY and OWASP Turkey projects&amp;quot;, Bedirhan Urgun&lt;br /&gt;
*** &amp;quot;Privacy in Governmental Insitutions - A Current State Analysis&amp;quot;, Hayrettin Bahsi, Chief Researcher UEKAE TUBITAK  &lt;br /&gt;
*** &amp;quot;A Panel on Privacy in Turkey&lt;br /&gt;
&lt;br /&gt;
* '''Mon 10th'''&lt;br /&gt;
** [[Italy]] (9:00 / 13:30)&lt;br /&gt;
*** &amp;quot;Privacy in the digital era&amp;quot; , Mauro Bregolin , KIMA Projects &amp;amp; Services&lt;br /&gt;
*** &amp;quot;OWASP Top 10 2007 - Are our information 'really' safe?&amp;quot; ,  Carlo Pelliccioni , MediaService&lt;br /&gt;
*** &amp;quot;Anti-Anti-XSS: bypass browser protections&amp;quot; , Alberto Revelli ,  Portcullis &lt;br /&gt;
*** &amp;quot;Growing Application Security Awareness&amp;quot; , Laurent Petroque , F5&lt;br /&gt;
*** &amp;quot;Buzzwords Security&amp;quot; , Luca Carettoni , SecureNetwork&lt;br /&gt;
*** &amp;quot;Hacker Attacks on the Horizon: Understanding the Top Web 2.0 Attack Vectors&amp;quot; , Danny Allan , Watchfire&lt;br /&gt;
** [[Rochester]] &lt;br /&gt;
*** &amp;quot;The new OWASP Top Ten.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* '''Mon 12th'''&lt;br /&gt;
** [[Houston]] (17:30 / 19:30)&lt;br /&gt;
*** &amp;quot;Enhancing Application Security with Bytecode Instrumentation&amp;quot; , Patrick White , Fortify Software &lt;br /&gt;
** [[Cleveland]]&lt;br /&gt;
*** &amp;quot;The new OWASP Top Ten.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''Note:''' If you are interested in doing a presentation, the following chapters have speaker slots available: Rochester, Boston, Phoenix, Poland and Turkey&lt;br /&gt;
&lt;br /&gt;
== Organizers == &lt;br /&gt;
&lt;br /&gt;
In addition to the local chapter leaders,  Dinis Cruz and Mike de Libero are the main points of contact (but of course much more help is needed :)  )&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Global Security Week (GWS) ==&lt;br /&gt;
&lt;br /&gt;
For more details on the (GWS) see:&lt;br /&gt;
*  http://www.globalsecurityweek.com/&lt;br /&gt;
* http://www.globalsecurityweek.com/html/national_activities.html&lt;br /&gt;
* http://www.globalsecurityweek.com/html/gsw_06.html  (Resources)&lt;br /&gt;
&lt;br /&gt;
And here is a description from one the organizers:&lt;br /&gt;
&lt;br /&gt;
''The aim of Global Security Week is to raise security awareness amongst the public and organizations about issues relating to security, primarily information security.  This year's theme is on the subject of privacy and we hope that a number of events will be held worldwide to promote people's awareness as to how to protect their privacy when online and also educate companies on their responsibilities, both legal and morally, when it comes to protecting the privacy of their customers.&lt;br /&gt;
''&lt;br /&gt;
''Global Security Week is a totally voluntary initiative and we have no commercial funding or agenda.  The initiative is funded entirely from the committee's own funds and time.  We have people involved in Global Security Week throughout the world and during the week we have events planned in different regions.  For example here in Ireland I plan to run a free seminar on the above topic open to anyone who wished to attend''&lt;br /&gt;
&lt;br /&gt;
''We ask that those who wish to become involved, help promote Global Security Week in their region either by running specific events dedicated to Global Security Week, taking part in events already planned or simply making people aware that the week is on and the topic is &amp;quot;Privacy in the 21st Century&amp;quot;. Even simply making people aware of Global Security Week and directing them to the website is a great help. Not having commercial funding we depend on word of mouth and like minded individuals to make people aware of the week.''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== ... for future reference ... ==&lt;br /&gt;
==== (original) Proposed Event layout ==== &lt;br /&gt;
 &lt;br /&gt;
Each chapter is free to organize its mini conference and to define how long it should last.&lt;br /&gt;
&lt;br /&gt;
But within the spirit of the event the following ideas are proposed:&lt;br /&gt;
&lt;br /&gt;
* The topic of the event should be on  &amp;quot;Privacy in the 21st Century&amp;quot;, so all talks should be related to it (we should be addressing the Web Application side of Privacy (for example what happens to Privacy with SQL Injection, XSS and issues like pdp's [http://www.gnucitizen.org/blog/snoop-onto-them-as-they-snoop-onto-us Snoop onto Them as they Snoop onto us])&lt;br /&gt;
* The event should have 4 to 5 speaking slots (can be 30m if required)&lt;br /&gt;
* If possible, invite a presenter from the local government to talk about their views on the subject&lt;br /&gt;
* Presentation from a local OWASP Project leader about his/hers project (i.e. for the cases where a leader of an [https://www.owasp.org/index.php/Category:OWASP_Project OWASP Project] lives locally (or will be in that city during the event)&lt;br /&gt;
* All events are recommended to have the same panel discussion on the subject &amp;quot;'''What is the current state of Privacy on Web Application Security? and what should we be focusing on?'''&amp;quot;). After the panel discussion, each local chapters is invited to create a summary of its conclusions for publishing on the OWASP website&lt;br /&gt;
* &amp;quot;Talk 'Lets get rid of 3 major sources of vulnerabilities:&lt;br /&gt;
*# CROSS-SITE SCRIPTING: 70-90% of web applications have Cross-Site Scripting (XSS) holes. You must *both* carefully validate input and use HTML entity encoding on all data output.&lt;br /&gt;
*# SQL INJECTION: If your queries are a bunch of strings and user input concatenated together, your database could be attacked with SQL Injection. Stamp out this attack by using &amp;quot;parameterized&amp;quot; queries, such as Java's PreparedStatement instead.&lt;br /&gt;
*# SESSION EXPOSURE: Your SESSIONIDs are *just* as valuable as usernames and passwords, so make sure you never expose them. Don't ever allow authenticated SESSIONIDs to be sent without SSL or exposed in the URL.&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==== Other Ideas ====&lt;br /&gt;
* Create a Security Manifest that will be 'signed' by all attendees &lt;br /&gt;
* Distributed capture the flag (where each local chapter plays has a team (against the other chapters))&lt;br /&gt;
* Short intro/welcome movie at the beginning of each mini-conference by OWASP board&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=20480</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=20480"/>
				<updated>2007-07-30T13:59:48Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir@gmail.com Bunyamin Demir], [mailto:ferruh@mavituna.com Ferruh Mavituna], [mailto:urgunb@hotmail.com Bedirhan Urgun] |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Ceviri projesine yardim etmek isteyen arkadaslar lutfen [mailto:bunyamindemir@gmail.com iletisime] geciniz.&lt;br /&gt;
&lt;br /&gt;
== Sponsors == &lt;br /&gt;
&lt;br /&gt;
[http://www.pro-g.com.tr http://www.owasp.org/images/a/a9/Turkey_Chapter_Sponsor1_Pro-G.gif]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Turkey_Chapter_Sponsor1_Pro-G.gif&amp;diff=20477</id>
		<title>File:Turkey Chapter Sponsor1 Pro-G.gif</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Turkey_Chapter_Sponsor1_Pro-G.gif&amp;diff=20477"/>
				<updated>2007-07-30T13:53:51Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: OWASP Turkey Chapter Sponsor&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;OWASP Turkey Chapter Sponsor&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Spring_Of_Code_2007_-_Projects&amp;diff=20453</id>
		<title>OWASP Spring Of Code 2007 - Projects</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Spring_Of_Code_2007_-_Projects&amp;diff=20453"/>
				<updated>2007-07-29T19:19:35Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== All SpoC Projects ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot; WIDTH=100%&lt;br /&gt;
|-&lt;br /&gt;
! SpoC Project Name&lt;br /&gt;
! Author&lt;br /&gt;
! Confirmed&lt;br /&gt;
! Status&lt;br /&gt;
! Coordinated by &lt;br /&gt;
|-&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - The OWASP Web Security Certification Framework|The OWASP Web Security Certification Framework]]&lt;br /&gt;
| Mark Curphey&lt;br /&gt;
| Yes&lt;br /&gt;
| 45% &lt;br /&gt;
| OWASP Board&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - SqlMap|SqlMap]]&lt;br /&gt;
| Bernardo Damele&lt;br /&gt;
| Yes&lt;br /&gt;
| 60% (to review)&lt;br /&gt;
| Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP Site Generator|OWASP Site Generator]]&lt;br /&gt;
| Boris&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Attacks Reference Guide|Attacks Reference Guide]]&lt;br /&gt;
| NSRAV Security Research Group&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - The Scholastic Application Security Assessment Project|The Scholastic Application Security Assessment Project]]&lt;br /&gt;
| Eric Sheridan and &lt;br /&gt;
Dr. Goran Trajkovski&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Inspekt|Inspekt: Input filtering and validation library for PHP]]&lt;br /&gt;
| Ed Finkler&lt;br /&gt;
| Yes&lt;br /&gt;
| 50% (to review)&lt;br /&gt;
| Andrew v d Stock &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Code review Project|Code review Project]]&lt;br /&gt;
| Eoin Keary&lt;br /&gt;
| Yes&lt;br /&gt;
| 25% &lt;br /&gt;
| Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP Certification Project|OWASP Certification Project]]&lt;br /&gt;
| Matteo Meucci&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP Education Project|OWASP Education Project]]&lt;br /&gt;
| Sebastien Deleersnyder&lt;br /&gt;
| Yes&lt;br /&gt;
| 37,5% &lt;br /&gt;
| Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP The Anti-Samy Project|OWASP The Anti-Samy Project]]&lt;br /&gt;
| Arshan Dabirsiaghi&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Security throughout the SDLC|Security throughout the SDLC]]&lt;br /&gt;
| Keith Casey&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP WebGoat Solutions Guide|OWASP WebGoat Solutions Guide]]&lt;br /&gt;
| Erwin Geirnaert&lt;br /&gt;
| Yes&lt;br /&gt;
| 90% &lt;br /&gt;
| Jeff Williams&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP WeBekci Project|OWASP WeBekci Project]]&lt;br /&gt;
| Bunyamin Demir&lt;br /&gt;
| Yes&lt;br /&gt;
| 40% &lt;br /&gt;
| Ivan Ristic &lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Python Tainted Mode|Python Tainted Mode]]&lt;br /&gt;
| Denis&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - WebScarab NG Security Test Automation|WebScarab NG Security Test Automation]]&lt;br /&gt;
| Darren Edmonds&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| Jeff Williams&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Refresh Attacks list|Refresh Attacks list]]&lt;br /&gt;
| Przemyslaw 'rezos' Skowron&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Best Practices &amp;amp; Countermeasures|Best Practices &amp;amp; Countermeasures]]&lt;br /&gt;
| Jim&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP Brand|OWASP brand]]&lt;br /&gt;
| Paulo Coimbra&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Web Application Security put into practice|Web Application Security put into practice]]&lt;br /&gt;
| Heiko Webers&lt;br /&gt;
| Yes&lt;br /&gt;
| 60% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP JBroFuzz Project|OWASP JBroFuzz Project]]&lt;br /&gt;
| Subere&lt;br /&gt;
| Yes&lt;br /&gt;
| 40% &lt;br /&gt;
| TBA&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Owasp Orizon Project|Owasp Orizon Project]]&lt;br /&gt;
| Paolo Perego&lt;br /&gt;
| Yes&lt;br /&gt;
| 45% &lt;br /&gt;
| Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Enigform: Firefox Addon for OpenPGP signing of HTTP requests|Enigform: Firefox Addon for OpenPGP signing of HTTP requests]]&lt;br /&gt;
| Arturo (Buanzo) Busleiman&lt;br /&gt;
| Yes&lt;br /&gt;
| half term review: done &lt;br /&gt;
| Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP LiveCD Education Project|OWASP LiveCD Education Project]]&lt;br /&gt;
| Josh Sweeney&lt;br /&gt;
| Yes&lt;br /&gt;
| 50% (to review) &lt;br /&gt;
| Eoin Keary&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP Java Project|OWASP Java Project]]&lt;br /&gt;
| Erwin Geirnaert&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| Jeff Williams&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - OWASP LiveCD Project|OWASP LiveCD Project]]&lt;br /&gt;
| Joshua Perrymon&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| Eoin Keary&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Interim @ Aspect Offices|Interim @ Aspect Offices]]&lt;br /&gt;
| Andy Gocke&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| Jeff Williams&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - 10x 1000USD to FOSS projects we all use |10x 1000USD to FOSS projects we all use ]]&lt;br /&gt;
| (tbd)&lt;br /&gt;
| No&lt;br /&gt;
| 0% &lt;br /&gt;
| Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
! [[SpoC 007 - Help with SpoC project management|Help with SpoC project management]]&lt;br /&gt;
| Paulo Coimbra&lt;br /&gt;
| Yes&lt;br /&gt;
| 0% &lt;br /&gt;
| Dinis Cruz&lt;br /&gt;
&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=SpoC_007_-_OWASP_WeBekci_Project&amp;diff=20452</id>
		<title>SpoC 007 - OWASP WeBekci Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=SpoC_007_-_OWASP_WeBekci_Project&amp;diff=20452"/>
				<updated>2007-07-29T19:18:44Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''[http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Selection Back to SpoC 007 Selection page]'''&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''AoC Candidate''':   Bunyamin Demir&lt;br /&gt;
&lt;br /&gt;
'''Project coordinator''': Ivan Ristic&lt;br /&gt;
&lt;br /&gt;
'''Project Progress''': 40% Complete, [[SpoC 007 - OWASP WeBekci Project - Progress Page|Progress Page]]&lt;br /&gt;
&lt;br /&gt;
== Bunyamin Demir – OWASP WeBekci Project ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== Executive Summary ===&lt;br /&gt;
&lt;br /&gt;
Web application firewalls (WAF) are gaining importance among the information security technologies designed to protect web sites from attack. WAF solutions prevent attacks that network firewalls and intrusion detection systems can't and they require no modification of application source code. ModSecurity [17] is an open source web application firewall that runs as an Apache module. It is an embeddable web application firewall and it provides protection from a range of attacks against web applications. It is an open source project available to everyone; it however does not come with an admin panel.&lt;br /&gt;
&lt;br /&gt;
I decided to provide this essential tool with a control panel which I believe will ease and thus encourage its usage.&lt;br /&gt;
&lt;br /&gt;
ModSecurity allows for HTTP traffic monitoring and real-time analysis with no changes to existing infrastructure. My main goal is to analyze attacks and generate rules to change the configuration of the ModSecurity accordingly.&lt;br /&gt;
&lt;br /&gt;
ModSecurity has a feature called “flexible rule engine” as its heart of Attack Prevention capability . It uses ModSecurity’s “Rule Language,” (a programming language designed to work with HTTP transaction data). It is easy to use and flexible; yet the system administrators need to learn its own rules to create what is called “Certified ModSecurity Rules” to be implemented. My control panel will automate the major code-generation in Rule Language.  &lt;br /&gt;
&lt;br /&gt;
=== Objectives and Deliverables ===&lt;br /&gt;
&lt;br /&gt;
* '''Configuration''' : Will add all configuration parameter (80%)&lt;br /&gt;
* '''RuleLoggin Generator''': Will write all the Rules in Rule Language(50%)&lt;br /&gt;
* '''Logging'''  : Errorlog, GuardianLog, Auditlog and Debuglog will be added.(30%)&lt;br /&gt;
* '''Multiple-DB'''  : Will add PostgreSql and Sqlite support.(0%)&lt;br /&gt;
&lt;br /&gt;
=== Why I should be sponsored for the project ===&lt;br /&gt;
&lt;br /&gt;
I am involved with OWASP Turkey and interested very much in WAF. Even though this is my first project for OWASP, I am very much interested in every aspect of ModSecurity. With SpoC007’s support I will finalize my work on OWASP WeBekci. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
'''[http://www.owasp.org/index.php/OWASP_Spring_Of_Code_2007_Selection Back to SpoC 007 Selection page]'''&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=19948</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=19948"/>
				<updated>2007-07-17T09:24:50Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Last Event - 1st Web Security Days - July 14 (Turkey 2007) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir@gmail.com Bunyamin Demir], [mailto:ferruh@mavituna.com Ferruh Mavituna], [mailto:urgunb@hotmail.com Bedirhan Urgun] |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Ceviri projesine yardim etmek isteyen arkadaslar lutfen [mailto:bunyamindemir@gmail.com iletisime] geciniz.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=19947</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=19947"/>
				<updated>2007-07-17T09:24:32Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Last Event - 1st Web Security Days - July 14 (Turkey 2007) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir@gmail.com Bunyamin Demir], [mailto:ferruh@mavituna.com Ferruh Mavituna], [mailto:urgunb@hotmail.com Bedirhan Urgun] |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Ceviri projesine yardim etmek isteyen arkadaslar lutfen [mailto:bunyamindemir@gmail.com iletisime] geciniz.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=19946</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=19946"/>
				<updated>2007-07-17T09:23:53Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Next Event - 1st Web Security Days - July 14 (Turkey 2007) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir@gmail.com Bunyamin Demir], [mailto:ferruh@mavituna.com Ferruh Mavituna], [mailto:urgunb@hotmail.com Bedirhan Urgun] |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Ceviri projesine yardim etmek isteyen arkadaslar lutfen [mailto:bunyamindemir@gmail.com iletisime] geciniz.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the Web Security Days has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=1st_Web_Security_Days_OWASP_Turkey&amp;diff=19945</id>
		<title>1st Web Security Days OWASP Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=1st_Web_Security_Days_OWASP_Turkey&amp;diff=19945"/>
				<updated>2007-07-17T09:21:54Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Sponsored */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
First of the Web Security Days has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations. &lt;br /&gt;
&lt;br /&gt;
Dinis Cruz (Chief OWASP Evangelist) actively participating with his two presentations, attendees had the chance of capturing a first hand understanding of OWASP’s general structure, projects, the current state, in short, the spirit. Moreover, Dinis also presented a general view of an application audit by combining the best of two worlds; black box testing and source code review. Both of the presentations are humbly translated into Turkish onsite.&lt;br /&gt;
&lt;br /&gt;
Ferruh Mavituna has launched his fresh new testing/attacking tool on what he dubbed as “XSS Tunnelling” vowing the audience. Bunyamin Demir has provided a general overview of modsecurity WAF module of Apache with practical attack and prevention steps. Bedirhan Urgun has demoed an attack vector (cache poisoning) by using HRS, backed up with a master/zombie scenerio implemented on Attack API. Finally, Omur Camci has demonstrated fundamental Java security functionalities such as creating partial trust policies and signing jar files.&lt;br /&gt;
&lt;br /&gt;
We’d like to thank our sponsors; [http://www.gelisimplatformu.org/ Gelisim Platformu] and [http://www.pro-g.com.tr/ Pro-G Security]. &lt;br /&gt;
&lt;br /&gt;
Encouraged with this one, we hope next meeting (could it be 6th September with Owasp Live…) will be more fluent, beneficial and definitely crowded.&lt;br /&gt;
&lt;br /&gt;
Thanks again to all participated.&lt;br /&gt;
&lt;br /&gt;
Last but not the least, presentation materials will be available soon and links to those materials (ppt, videos and papers) will be published here.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey chapter&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Saturday 14 July 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:00-18:00&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.gelisimplatformu.org Gelisim Platformu] - Gayrettepe 80310 Istanbul - Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Agenda&lt;br /&gt;
 |-&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:00-11:05 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Registration and Opening - ''OWASP-Turkey''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:05-12:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP World (tools, documents, projects,etc..) - ''Dinis Cruz (Chief Evangelist)''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:10-12:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | HTTP Response Splitting, Demo (Web Cache Poisoning and a little more) - ''Bedirhan Urgun''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:30-13:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Lunch&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:45-14:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | XSS Tunnelling - ''Ferruh Mavituna''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:35-15:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Web Application Security With ModSecurity - ''Bunyamin Demir''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:10-16:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Security Practices In Java - ''GP Bilisim Kulubu''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:50-16:10 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:10-16:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Live Demo Of An Web Application Security Review (And Source Code Analysis) - ''Dinis Cruz''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 17:00-17:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Q&amp;amp;A and What can we do for OWASP?&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 17:45-18:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Closing - ''OWASP-Turkey''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Sponsored ==&lt;br /&gt;
&lt;br /&gt;
The event was sponsored by [http://www.gelisimplatformu.org/ Gelisim Platformu] and [http://www.pro-g.com.tr/ Pro-G Security]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;[[Image:Gelisim_platformu_logo.gif]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[Image:Pro-g_web_security_days_logo.gif|Pro-g_web_security_days_logo.gif]]&amp;lt;/center&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=1st_Web_Security_Days_OWASP_Turkey&amp;diff=19944</id>
		<title>1st Web Security Days OWASP Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=1st_Web_Security_Days_OWASP_Turkey&amp;diff=19944"/>
				<updated>2007-07-17T09:21:01Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* 1st Web Security Days - July 14 (Turkey 2007) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
First of the Web Security Days has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations. &lt;br /&gt;
&lt;br /&gt;
Dinis Cruz (Chief OWASP Evangelist) actively participating with his two presentations, attendees had the chance of capturing a first hand understanding of OWASP’s general structure, projects, the current state, in short, the spirit. Moreover, Dinis also presented a general view of an application audit by combining the best of two worlds; black box testing and source code review. Both of the presentations are humbly translated into Turkish onsite.&lt;br /&gt;
&lt;br /&gt;
Ferruh Mavituna has launched his fresh new testing/attacking tool on what he dubbed as “XSS Tunnelling” vowing the audience. Bunyamin Demir has provided a general overview of modsecurity WAF module of Apache with practical attack and prevention steps. Bedirhan Urgun has demoed an attack vector (cache poisoning) by using HRS, backed up with a master/zombie scenerio implemented on Attack API. Finally, Omur Camci has demonstrated fundamental Java security functionalities such as creating partial trust policies and signing jar files.&lt;br /&gt;
&lt;br /&gt;
We’d like to thank our sponsors; [http://www.gelisimplatformu.org/ Gelisim Platformu] and [http://www.pro-g.com.tr/ Pro-G Security]. &lt;br /&gt;
&lt;br /&gt;
Encouraged with this one, we hope next meeting (could it be 6th September with Owasp Live…) will be more fluent, beneficial and definitely crowded.&lt;br /&gt;
&lt;br /&gt;
Thanks again to all participated.&lt;br /&gt;
&lt;br /&gt;
Last but not the least, presentation materials will be available soon and links to those materials (ppt, videos and papers) will be published here.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey chapter&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Saturday 14 July 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:00-18:00&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.gelisimplatformu.org Gelisim Platformu] - Gayrettepe 80310 Istanbul - Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Agenda&lt;br /&gt;
 |-&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:00-11:05 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Registration and Opening - ''OWASP-Turkey''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:05-12:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP World (tools, documents, projects,etc..) - ''Dinis Cruz (Chief Evangelist)''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:10-12:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | HTTP Response Splitting, Demo (Web Cache Poisoning and a little more) - ''Bedirhan Urgun''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:30-13:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Lunch&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:45-14:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | XSS Tunnelling - ''Ferruh Mavituna''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:35-15:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Web Application Security With ModSecurity - ''Bunyamin Demir''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:10-16:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Security Practices In Java - ''GP Bilisim Kulubu''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:50-16:10 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:10-16:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Live Demo Of An Web Application Security Review (And Source Code Analysis) - ''Dinis Cruz''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 17:00-17:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Q&amp;amp;A and What can we do for OWASP?&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 17:45-18:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Closing - ''OWASP-Turkey''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Sponsored ==&lt;br /&gt;
&lt;br /&gt;
The event was sponsored by Gelisim Platformu and Pro-G&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;[[Image:Gelisim_platformu_logo.gif]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[Image:Pro-g_web_security_days_logo.gif|Pro-g_web_security_days_logo.gif]]&amp;lt;/center&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=1st_Web_Security_Days_OWASP_Turkey&amp;diff=19942</id>
		<title>1st Web Security Days OWASP Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=1st_Web_Security_Days_OWASP_Turkey&amp;diff=19942"/>
				<updated>2007-07-16T19:40:48Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: New page: == 1st Web Security Days - July 14 (Turkey 2007) ==   First of the Web Security Days has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered atte...&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
First of the Web Security Days has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations. &lt;br /&gt;
&lt;br /&gt;
Dinis Cruz (Chief OWASP Evangelist) actively participating with his two presentations, attendees had the chance of capturing a first hand understanding of OWASP’s general structure, projects, the current state, in short, the spirit. Moreover, Dinis also presented a general view of an application audit by combining the best of two worlds; black box testing and source code review. Both of the presentations are humbly translated into Turkish onsite.&lt;br /&gt;
&lt;br /&gt;
Ferruh Mavituna has launched his fresh new testing/attacking tool on what he dubbed as “XSS Tunnelling” vowing the audience. Bunyamin Demir has provided a general overview of modsecurity WAF module of Apache with practical attack and prevention steps. Bedirhan Urgun has demoed an attack vector (cache poisoning) by using HRS, backed up with a master/zombie scenerio implemented on Attack API. Finally, Omur Camci has demonstrated fundamental Java security functionalities such as creating partial trust policies and signing jar files.&lt;br /&gt;
&lt;br /&gt;
We’d like to thank our sponsors; Gelisim Platformu and Pro-G Security. &lt;br /&gt;
&lt;br /&gt;
Encouraged with this one, we hope next meeting (could it be 6th September with Owasp Live…) will be more fluent, beneficial and definitely crowded.&lt;br /&gt;
&lt;br /&gt;
Thanks again to all participated.&lt;br /&gt;
&lt;br /&gt;
Last but not the least, presentation materials will be available soon and links to those materials (ppt, videos and papers) will be published here.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey chapter&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Agenda ==&lt;br /&gt;
&lt;br /&gt;
'''Saturday 14 July 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:00-18:00&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.gelisimplatformu.org Gelisim Platformu] - Gayrettepe 80310 Istanbul - Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Agenda&lt;br /&gt;
 |-&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:00-11:05 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Registration and Opening - ''OWASP-Turkey''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:05-12:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP World (tools, documents, projects,etc..) - ''Dinis Cruz (Chief Evangelist)''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:10-12:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | HTTP Response Splitting, Demo (Web Cache Poisoning and a little more) - ''Bedirhan Urgun''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:30-13:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Lunch&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:45-14:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | XSS Tunnelling - ''Ferruh Mavituna''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:35-15:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Web Application Security With ModSecurity - ''Bunyamin Demir''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:10-16:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Security Practices In Java - ''GP Bilisim Kulubu''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:50-16:10 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:10-16:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Live Demo Of An Web Application Security Review (And Source Code Analysis) - ''Dinis Cruz''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 17:00-17:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Q&amp;amp;A and What can we do for OWASP?&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 17:45-18:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Closing - ''OWASP-Turkey''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Sponsored ==&lt;br /&gt;
&lt;br /&gt;
The event was sponsored by Gelisim Platformu and Pro-G&lt;br /&gt;
&lt;br /&gt;
&amp;lt;center&amp;gt;[[Image:Gelisim_platformu_logo.gif]]&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;&amp;amp;nbsp;[[Image:Pro-g_web_security_days_logo.gif|Pro-g_web_security_days_logo.gif]]&amp;lt;/center&amp;gt;&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Pro-g_web_security_days_logo.gif&amp;diff=19941</id>
		<title>File:Pro-g web security days logo.gif</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Pro-g_web_security_days_logo.gif&amp;diff=19941"/>
				<updated>2007-07-16T19:35:54Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: Pro-G&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Pro-G&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:Gelisim_platformu_logo.gif&amp;diff=19940</id>
		<title>File:Gelisim platformu logo.gif</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:Gelisim_platformu_logo.gif&amp;diff=19940"/>
				<updated>2007-07-16T19:32:26Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: Gelisim Platformu&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Gelisim Platformu&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=19778</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=19778"/>
				<updated>2007-07-12T12:10:03Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Next Event - 1st Web Security Days - July 14 (Turkey 2007) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir@gmail.com Bunyamin Demir], [mailto:ferruh@mavituna.com Ferruh Mavituna], [mailto:urgunb@hotmail.com Bedirhan Urgun] |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Ceviri projesine yardim etmek isteyen arkadaslar lutfen [mailto:bunyamindemir@gmail.com iletisime] geciniz.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Next Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Everyone is welcome to join us at our chapter event. We will meet at the conference room at [http://www.gelisimplatformu.org/ Gelisim Platformu].&lt;br /&gt;
&lt;br /&gt;
'''Saturday 14 July 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:00-18:00&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.gelisimplatformu.org Gelisim Platformu] - Gayrettepe 80310 Istanbul - Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For registration [http://www.webguvenligi.org/owaspKayit/kayit.php please].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Agenda&lt;br /&gt;
 |-&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:00-11:05 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Registration and Opening - ''OWASP-Turkey''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:05-12:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP World (tools, documents, projects,etc..) - ''Dinis Cruz (Chief Evangelist)''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:10-12:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | HTTP Response Splitting, Demo (Web Cache Poisoning and a little more) - ''Bedirhan Urgun''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:30-13:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Lunch&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:45-14:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | XSS Tunnelling - ''Ferruh Mavituna''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:35-15:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Web Application Security With ModSecurity - ''Bunyamin Demir''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:10-16:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Security Practices In Java - ''GP Bilisim Kulubu''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:50-16:10 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:10-16:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Live Demo Of An Web Application Security Review (And Source Code Analysis) - ''Dinis Cruz''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 17:00-17:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Q&amp;amp;A and What can we do for OWASP?&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 17:45-18:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Closing - ''OWASP-Turkey''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=19777</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=19777"/>
				<updated>2007-07-12T12:09:46Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: /* Next Event - 1st Web Security Days - July 14 (Turkey 2007) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir@gmail.com Bunyamin Demir], [mailto:ferruh@mavituna.com Ferruh Mavituna], [mailto:urgunb@hotmail.com Bedirhan Urgun] |mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
&lt;br /&gt;
Ceviri projesine yardim etmek isteyen arkadaslar lutfen [mailto:bunyamindemir@gmail.com iletisime] geciniz.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Next Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Everyone is welcome to join us at our chapter event. We will meet at the conference room at [http://www.gelisimplatformu.org/ Gelisim Platformu].&lt;br /&gt;
&lt;br /&gt;
'''Saturday 14 July 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:00-18:00&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.gelisimplatformu.org Gelisim Platformu] - Gayrettepe 80310 Istanbul - Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
For registration [http://www.webguvenligi.org/owaspKayit/kayit.php please].&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width:80%&amp;quot; border=&amp;quot;0&amp;quot; align=&amp;quot;center&amp;quot;&lt;br /&gt;
 ! colspan=&amp;quot;3&amp;quot; align=&amp;quot;center&amp;quot; style=&amp;quot;background:#4058A0; color:white&amp;quot; | Agenda&lt;br /&gt;
 |-&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:00-11:05 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Registration and Opening - ''OWASP-Turkey''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 11:05-12:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | OWASP World (tools, documents, projects,etc..) - ''Dinis Cruz (Chief Evangelist)''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:10-12:30 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | HTTP Response Splitting, Demo (Web Cache Poisoning and a little more) - ''Bedirhan Urgun''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 12:30-13:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:80%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Lunch&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 13:45-14:25 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | XSS Tunnelling - ''Ferruh Mavituna''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 14:35-15:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Web Application Security With ModSecurity - ''Bunyamin Demir''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 15:10-16:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Security Practices In Java - ''GP Bilisim Kulubu''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:50-16:10 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Break&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 16:10-16:50 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Live Demo Of An WebApplication Security Review (And Source Code Analysis) - ''Dinis Cruz''&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 17:00-17:45 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#F2F2F2&amp;quot; align=&amp;quot;left&amp;quot; | Q&amp;amp;A and What can we do for OWASP?&lt;br /&gt;
 |-&lt;br /&gt;
 | style=&amp;quot;width:10%; background:#7B8ABD&amp;quot; | 17:45-18:00 || colspan=&amp;quot;2&amp;quot; style=&amp;quot;width:40%; background:#C2C2C2&amp;quot; align=&amp;quot;left&amp;quot; | Closing - ''OWASP-Turkey''&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Template:Latest_Newsletter&amp;diff=19562</id>
		<title>Template:Latest Newsletter</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Template:Latest_Newsletter&amp;diff=19562"/>
				<updated>2007-07-03T14:41:56Z</updated>
		
		<summary type="html">&lt;p&gt;Bunyamin: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;; '''Apr 17 - [[OWASP Newsletter 8]]'''&lt;br /&gt;
: OWASP SpoC projects selected, new OWASP WeBekci tool, OWASP Code Review project, OWASP updates and much more&lt;/div&gt;</summary>
		<author><name>Bunyamin</name></author>	</entry>

	</feed>