<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Claudia+casanovas</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Claudia+casanovas"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Claudia_casanovas"/>
		<updated>2026-05-01T09:58:14Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Project_Reviews_2018&amp;diff=240404</id>
		<title>OWASP Project Reviews 2018</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Project_Reviews_2018&amp;diff=240404"/>
				<updated>2018-05-04T14:22:49Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== '''&amp;lt;u&amp;gt;[[Project Reviews Guideline|Overview of Project Reviews:]]&amp;lt;/u&amp;gt;''' ===&lt;br /&gt;
OWASP is reviewing projects who wish to graduate from Incubator to Lab to Flagship.  The purpose of this assessment is to determine whether a project meets the minimum criteria to graduate as outlined in the Project Health Assessment Criteria Document.  The review process begins with an initial self-assessment done by the project leader and reviewed by Harold Blankenship.  Next, the assessment enters the peer review phase where we ask volunteers in our OWASP Community to participate and finalize the results. I have included a [https://docs.google.com/document/d/1NQSHshTxK1AWTkD4WgYluxSafgO-XGDHZnwE9Qvt7TE/edit '''Sample of a Project Assessmen'''t] for your review and consideration.&lt;br /&gt;
&lt;br /&gt;
'''OWASP Project Reviews @ APPSEC  USA 2017'''&lt;br /&gt;
* Harold Blackenship (Director of Technology and Projects)&lt;br /&gt;
* Claudia Aviles Casanovas (Project Coordinator)&lt;br /&gt;
OWASP Volunteers:&lt;br /&gt;
&lt;br /&gt;
[[External|Alex Goncharov]]&lt;br /&gt;
&lt;br /&gt;
'''Description of Scope of Work:''' &lt;br /&gt;
&lt;br /&gt;
'''Lab to Flagship Status'''&lt;br /&gt;
&lt;br /&gt;
OWASP Juiceshop Project&lt;br /&gt;
&lt;br /&gt;
OWASP DefectDojo Project&lt;br /&gt;
&lt;br /&gt;
'''Incubator to Lab Status'''&lt;br /&gt;
&lt;br /&gt;
OWASP Glue Tool Project &lt;br /&gt;
&lt;br /&gt;
OWASP Lab/Incubator Projects Deep Dive Health Checks&lt;br /&gt;
&lt;br /&gt;
=== '''&amp;lt;u&amp;gt;OWASP Project Health Checks:&amp;lt;/u&amp;gt;''' ===&lt;br /&gt;
'''Review Forms:''' [https://docs.google.com/a/owasp.org/document/d/1jUXt9M9u9Kq1JLaDSdbh6s0p5G_EqFSoaKpzDRures4/edit?usp=sharing Code Health Check]  [https://docs.google.com/a/owasp.org/document/d/1aDdcBm3v-DMraVKmsBiNA4YzBmlGFLvOddj5nvPd--Q/edit?usp=sharing Tool Health Check] [https://docs.google.com/a/owasp.org/document/d/17kJlpupi2nmKKRMMBpxgyj1JWxvt23iT8fWULm4SW6k/edit?usp=sharing Documentation Health Check]&lt;br /&gt;
&lt;br /&gt;
'''Lab Projects:'''&lt;br /&gt;
&lt;br /&gt;
[[OWASP Hackademic Challenges Project|OWASP Hackademic Challenges  Project]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP Mantra - Security Framework|OWASP Mantra Security Framwork]]&lt;br /&gt;
&lt;br /&gt;
[[:Category:OWASP Security Ninjas AppSec Training Program|OWASP Security Ninjas  AppSec Training Program]]&lt;br /&gt;
&lt;br /&gt;
OWASP Security Knowledge Framework Project&lt;br /&gt;
&lt;br /&gt;
'''Lab Documentation Projects:'''&lt;br /&gt;
&lt;br /&gt;
[[OWASP Application Security Guide For CISOs Project|OWASP Application Security Guide for Cisos Project]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP CISO Survey|OWASP Cisco Survey]]&lt;br /&gt;
&lt;br /&gt;
'''Incubator Projects'''&lt;br /&gt;
&lt;br /&gt;
Graduation Project: OWASP Mobile Security Testing Guide Project&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Secure_Headers_Project - Response on needed on request to get an external host&amp;lt;nowiki/&amp;gt;https://www.owasp.org/index.php/OWASP_WASC_Distributed_Web_Honeypots_Project - No updates since 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Faux_Bank_Project - No updates since 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Droid10_Project - No updates since March 15&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_WAP-Web_Application_Protection - no updates since 2015 and no repository still in salesforge&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Mutillidae_2_Project - No updates since 2015 still using salesforge&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_WebSpa_Project - no updates since March 2015 last update in salesforge 2/21/2016&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Rainbow_Maker_Project - Last release 12/11/2015 and no updates since May 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Category:OWASP_.NET_Project - No updates March 23, 2016&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_WASC_Web_Hacking_Incidents_Database_Project - no updated since March 12, 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Application_Security_Program_Quick_Start_Guide_Project - no updates since january 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Secure_Configuration_Guide#tab=Main - No updates since April 2016 - no updates to guide&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_RFP-Criteria - no updates since March 2016&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Category:OWASP_Top_10_fuer_Entwickler - no real updates on news since 2013 some updates to the wiki&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Project_Reviews_2018&amp;diff=240403</id>
		<title>OWASP Project Reviews 2018</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Project_Reviews_2018&amp;diff=240403"/>
				<updated>2018-05-04T14:21:51Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== '''&amp;lt;u&amp;gt;[[Project Reviews Guideline|Overview of Project Reviews:]]&amp;lt;/u&amp;gt;''' ===&lt;br /&gt;
OWASP is reviewing projects who wish to graduate from Incubator to Lab to Flagship.  The purpose of this assessment is to determine whether a project meets the minimum criteria to graduate as outlined in the Project Health Assessment Criteria Document.  The review process begins with an initial self-assessment done by the project leader and reviewed by Matt Tesauro.  Next, the assessment enters the peer review phase where we ask volunteers in our OWASP Community to participate and finalize the results. I have included a [https://docs.google.com/document/d/1NQSHshTxK1AWTkD4WgYluxSafgO-XGDHZnwE9Qvt7TE/edit '''Sample of a Project Assessmen'''t] for your review and consideration.&lt;br /&gt;
&lt;br /&gt;
'''OWASP Project Reviews @ APPSEC  USA 2017'''&lt;br /&gt;
* Harold Blackenship (Director of Technology and Projects)&lt;br /&gt;
* Claudia Aviles Casanovas (Project Coordinator)&lt;br /&gt;
OWASP Volunteers:&lt;br /&gt;
&lt;br /&gt;
[[External|Alex Goncharov]]&lt;br /&gt;
&lt;br /&gt;
'''Description of Scope of Work:''' &lt;br /&gt;
&lt;br /&gt;
'''Lab to Flagship Status'''&lt;br /&gt;
&lt;br /&gt;
OWASP Juiceshop Project&lt;br /&gt;
&lt;br /&gt;
OWASP DefectDojo Project&lt;br /&gt;
&lt;br /&gt;
'''Incubator to Lab Status'''&lt;br /&gt;
&lt;br /&gt;
OWASP Glue Tool Project &lt;br /&gt;
&lt;br /&gt;
OWASP Lab/Incubator Projects Deep Dive Health Checks&lt;br /&gt;
&lt;br /&gt;
=== '''&amp;lt;u&amp;gt;OWASP Project Health Checks:&amp;lt;/u&amp;gt;''' ===&lt;br /&gt;
'''Review Forms:''' [https://docs.google.com/a/owasp.org/document/d/1jUXt9M9u9Kq1JLaDSdbh6s0p5G_EqFSoaKpzDRures4/edit?usp=sharing Code Health Check]  [https://docs.google.com/a/owasp.org/document/d/1aDdcBm3v-DMraVKmsBiNA4YzBmlGFLvOddj5nvPd--Q/edit?usp=sharing Tool Health Check] [https://docs.google.com/a/owasp.org/document/d/17kJlpupi2nmKKRMMBpxgyj1JWxvt23iT8fWULm4SW6k/edit?usp=sharing Documentation Health Check]&lt;br /&gt;
&lt;br /&gt;
'''Lab Projects:'''&lt;br /&gt;
&lt;br /&gt;
[[OWASP Hackademic Challenges Project|OWASP Hackademic Challenges  Project]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP Mantra - Security Framework|OWASP Mantra Security Framwork]]&lt;br /&gt;
&lt;br /&gt;
[[:Category:OWASP Security Ninjas AppSec Training Program|OWASP Security Ninjas  AppSec Training Program]]&lt;br /&gt;
&lt;br /&gt;
OWASP Security Knowledge Framework Project&lt;br /&gt;
&lt;br /&gt;
'''Lab Documentation Projects:'''&lt;br /&gt;
&lt;br /&gt;
[[OWASP Application Security Guide For CISOs Project|OWASP Application Security Guide for Cisos Project]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP CISO Survey|OWASP Cisco Survey]]&lt;br /&gt;
&lt;br /&gt;
'''Incubator Projects'''&lt;br /&gt;
&lt;br /&gt;
Graduation Project: OWASP Mobile Security Testing Guide Project&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Secure_Headers_Project - Response on needed on request to get an external host&amp;lt;nowiki/&amp;gt;https://www.owasp.org/index.php/OWASP_WASC_Distributed_Web_Honeypots_Project - No updates since 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Faux_Bank_Project - No updates since 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Droid10_Project - No updates since March 15&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_WAP-Web_Application_Protection - no updates since 2015 and no repository still in salesforge&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Mutillidae_2_Project - No updates since 2015 still using salesforge&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_WebSpa_Project - no updates since March 2015 last update in salesforge 2/21/2016&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Rainbow_Maker_Project - Last release 12/11/2015 and no updates since May 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Category:OWASP_.NET_Project - No updates March 23, 2016&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_WASC_Web_Hacking_Incidents_Database_Project - no updated since March 12, 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Application_Security_Program_Quick_Start_Guide_Project - no updates since january 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Secure_Configuration_Guide#tab=Main - No updates since April 2016 - no updates to guide&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_RFP-Criteria - no updates since March 2016&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Category:OWASP_Top_10_fuer_Entwickler - no real updates on news since 2013 some updates to the wiki&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Project_Reviews_2018&amp;diff=240389</id>
		<title>OWASP Project Reviews 2018</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Project_Reviews_2018&amp;diff=240389"/>
				<updated>2018-05-03T15:24:13Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* Overview of Project Reviews: */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== '''&amp;lt;u&amp;gt;[[Project Reviews Guideline|Overview of Project Reviews:]]&amp;lt;/u&amp;gt;''' ===&lt;br /&gt;
OWASP is reviewing projects who wish to graduate from Incubator to Lab to Flagship.  The purpose of this assessment is to determine whether a project meets the minimum criteria to graduate as outlined in the Project Health Assessment Criteria Document.  The review process begins with an initial self-assessment done by the project leader and reviewed by Matt Tesauro.  Next, the assessment enters the peer review phase where we ask volunteers in our OWASP Community to participate and finalize the results. I have included a [https://docs.google.com/document/d/1NQSHshTxK1AWTkD4WgYluxSafgO-XGDHZnwE9Qvt7TE/edit '''Sample of a Project Assessmen'''t] for your review and consideration.&lt;br /&gt;
&lt;br /&gt;
'''OWASP Project Reviews @ APPSEC  USA 2017'''&lt;br /&gt;
* Harold Blackenship (Director of Technology and Projects)&lt;br /&gt;
* Claudia Aviles Casanovas (Project Coordinator)&lt;br /&gt;
'''Description of Scope of Work:''' &lt;br /&gt;
&lt;br /&gt;
'''Lab to Flagship Status'''&lt;br /&gt;
&lt;br /&gt;
OWASP Juiceshop Project&lt;br /&gt;
&lt;br /&gt;
OWASP DefectDojo Project&lt;br /&gt;
&lt;br /&gt;
'''Incubator to Lab Status'''&lt;br /&gt;
&lt;br /&gt;
OWASP Glue Tool Project &lt;br /&gt;
&lt;br /&gt;
OWASP Lab/Incubator Projects Deep Dive Health Checks&lt;br /&gt;
&lt;br /&gt;
=== '''&amp;lt;u&amp;gt;OWASP Project Health Checks:&amp;lt;/u&amp;gt;''' ===&lt;br /&gt;
'''Review Forms:''' [https://docs.google.com/a/owasp.org/document/d/1jUXt9M9u9Kq1JLaDSdbh6s0p5G_EqFSoaKpzDRures4/edit?usp=sharing Code Health Check]  [https://docs.google.com/a/owasp.org/document/d/1aDdcBm3v-DMraVKmsBiNA4YzBmlGFLvOddj5nvPd--Q/edit?usp=sharing Tool Health Check] [https://docs.google.com/a/owasp.org/document/d/17kJlpupi2nmKKRMMBpxgyj1JWxvt23iT8fWULm4SW6k/edit?usp=sharing Documentation Health Check]&lt;br /&gt;
&lt;br /&gt;
'''Lab Projects:'''&lt;br /&gt;
&lt;br /&gt;
[[OWASP Hackademic Challenges Project|OWASP Hackademic Challenges  Project]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP Mantra - Security Framework|OWASP Mantra Security Framwork]]&lt;br /&gt;
&lt;br /&gt;
[[:Category:OWASP Security Ninjas AppSec Training Program|OWASP Security Ninjas  AppSec Training Program]]&lt;br /&gt;
&lt;br /&gt;
OWASP Security Knowledge Framework Project&lt;br /&gt;
&lt;br /&gt;
'''Lab Documentation Projects:'''&lt;br /&gt;
&lt;br /&gt;
[[OWASP Application Security Guide For CISOs Project|OWASP Application Security Guide for Cisos Project]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP CISO Survey|OWASP Cisco Survey]]&lt;br /&gt;
&lt;br /&gt;
'''Incubator Projects'''&lt;br /&gt;
&lt;br /&gt;
Graduation Project: OWASP Mobile Security Testing Guide Project&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Secure_Headers_Project - Response on needed on request to get an external host&amp;lt;nowiki/&amp;gt;https://www.owasp.org/index.php/OWASP_WASC_Distributed_Web_Honeypots_Project - No updates since 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Faux_Bank_Project - No updates since 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Droid10_Project - No updates since March 15&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_WAP-Web_Application_Protection - no updates since 2015 and no repository still in salesforge&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Mutillidae_2_Project - No updates since 2015 still using salesforge&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_WebSpa_Project - no updates since March 2015 last update in salesforge 2/21/2016&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Rainbow_Maker_Project - Last release 12/11/2015 and no updates since May 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Category:OWASP_.NET_Project - No updates March 23, 2016&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_WASC_Web_Hacking_Incidents_Database_Project - no updated since March 12, 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Application_Security_Program_Quick_Start_Guide_Project - no updates since january 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Secure_Configuration_Guide#tab=Main - No updates since April 2016 - no updates to guide&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_RFP-Criteria - no updates since March 2016&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Category:OWASP_Top_10_fuer_Entwickler - no real updates on news since 2013 some updates to the wiki&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Project_Reviews_2018&amp;diff=240388</id>
		<title>OWASP Project Reviews 2018</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Project_Reviews_2018&amp;diff=240388"/>
				<updated>2018-05-03T15:20:19Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Created page with &amp;quot;=== '''&amp;lt;u&amp;gt;Overview of Project Reviews:&amp;lt;/u&amp;gt;''' === OWASP is reviewing projects who wish to graduate from Incubator to Lab to Flagship.  The purpo...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== '''&amp;lt;u&amp;gt;[[Project Reviews Guideline|Overview of Project Reviews:]]&amp;lt;/u&amp;gt;''' ===&lt;br /&gt;
OWASP is reviewing projects who wish to graduate from Incubator to Lab to Flagship.  The purpose of this assessment is to determine whether a project meets the minimum criteria to graduate as outlined in the Project Health Assessment Criteria Document.  The review process begins with an initial self-assessment done by the project leader and reviewed by Matt Tesauro.  Next, the assessment enters the peer review phase where we ask volunteers in our OWASP Community to participate and finalize the results. I have included a [https://docs.google.com/document/d/1NQSHshTxK1AWTkD4WgYluxSafgO-XGDHZnwE9Qvt7TE/edit '''Sample of a Project Assessmen'''t] for your review and consideration.&lt;br /&gt;
&lt;br /&gt;
'''OWASP Project Reviews @ APPSEC  USA 2017'''&lt;br /&gt;
* Matt Tesauro (Sr. Project Coordinator)&lt;br /&gt;
* Claudia Aviles Casanovas (Project Coordinator)&lt;br /&gt;
'''Description of Scope of Work:''' &lt;br /&gt;
&lt;br /&gt;
List of Project Reviews:&lt;br /&gt;
&lt;br /&gt;
OWASP Security Knowledge Framework Project&lt;br /&gt;
&lt;br /&gt;
OWASP Security Mobile Testing Guide Project&lt;br /&gt;
&lt;br /&gt;
OWASP Lab/Incubator Projects Deep Dive Health Checks&lt;br /&gt;
&lt;br /&gt;
=== '''&amp;lt;u&amp;gt;OWASP Project Health Checks:&amp;lt;/u&amp;gt;''' ===&lt;br /&gt;
'''Review Forms:''' [https://docs.google.com/a/owasp.org/document/d/1jUXt9M9u9Kq1JLaDSdbh6s0p5G_EqFSoaKpzDRures4/edit?usp=sharing Code Health Check]  [https://docs.google.com/a/owasp.org/document/d/1aDdcBm3v-DMraVKmsBiNA4YzBmlGFLvOddj5nvPd--Q/edit?usp=sharing Tool Health Check] [https://docs.google.com/a/owasp.org/document/d/17kJlpupi2nmKKRMMBpxgyj1JWxvt23iT8fWULm4SW6k/edit?usp=sharing Documentation Health Check]&lt;br /&gt;
&lt;br /&gt;
'''Lab Projects:'''&lt;br /&gt;
&lt;br /&gt;
[[OWASP Hackademic Challenges Project|OWASP Hackademic Challenges  Project]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP Mantra - Security Framework|OWASP Mantra Security Framwork]]&lt;br /&gt;
&lt;br /&gt;
[[:Category:OWASP Security Ninjas AppSec Training Program|OWASP Security Ninjas  AppSec Training Program]]&lt;br /&gt;
&lt;br /&gt;
OWASP Security Knowledge Framework Project&lt;br /&gt;
&lt;br /&gt;
'''Lab Documentation Projects:'''&lt;br /&gt;
&lt;br /&gt;
[[OWASP Application Security Guide For CISOs Project|OWASP Application Security Guide for Cisos Project]]&lt;br /&gt;
&lt;br /&gt;
[[OWASP CISO Survey|OWASP Cisco Survey]]&lt;br /&gt;
&lt;br /&gt;
'''Incubator Projects'''&lt;br /&gt;
&lt;br /&gt;
Graduation Project: OWASP Mobile Security Testing Guide Project&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Secure_Headers_Project - Response on needed on request to get an external host&amp;lt;nowiki/&amp;gt;https://www.owasp.org/index.php/OWASP_WASC_Distributed_Web_Honeypots_Project - No updates since 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Faux_Bank_Project - No updates since 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Droid10_Project - No updates since March 15&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_WAP-Web_Application_Protection - no updates since 2015 and no repository still in salesforge&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Mutillidae_2_Project - No updates since 2015 still using salesforge&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_WebSpa_Project - no updates since March 2015 last update in salesforge 2/21/2016&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Rainbow_Maker_Project - Last release 12/11/2015 and no updates since May 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Category:OWASP_.NET_Project - No updates March 23, 2016&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_WASC_Web_Hacking_Incidents_Database_Project - no updated since March 12, 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Application_Security_Program_Quick_Start_Guide_Project - no updates since january 2015&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_Secure_Configuration_Guide#tab=Main - No updates since April 2016 - no updates to guide&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/OWASP_RFP-Criteria - no updates since March 2016&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Category:OWASP_Top_10_fuer_Entwickler - no real updates on news since 2013 some updates to the wiki&lt;br /&gt;
&lt;br /&gt;
=== '''[https://2017.appsec.eu/program/project-reviews OWASP Project Reviews @ APPSEC Belfast 2017]''' ===&lt;br /&gt;
* Matt Tesauro (Sr. Project Coordinator)&lt;br /&gt;
* Johanna Curiel (Program Leader)&lt;br /&gt;
* Claudia Aviles Casanovas (Project Coordinator)&lt;br /&gt;
* Talal Albacha&lt;br /&gt;
* Enrico Branca&lt;br /&gt;
* Nabin Kc&lt;br /&gt;
'''Description of Scope of Work: Additional [[Project Reviews Guideline|Information here]].'''&lt;br /&gt;
&lt;br /&gt;
'''Tool Projects'''&lt;br /&gt;
* [https://docs.google.com/document/d/1zO_9apf6470q9fR76F6Ms9NgGg_1HN2-DwZcRuHI7mg/edit?usp=sharing OWASP Benchmark Project] &lt;br /&gt;
* [https://docs.google.com/a/owasp.org/document/d/1X_n_70BA4cvSAoj78i30VtryiaTRvXsJaQzYLncV7nc/edit?usp=sharing OWASP Juiceshop Project]&lt;br /&gt;
'''Code Projects:'''&lt;br /&gt;
* [https://docs.google.com/a/owasp.org/document/d/1w2A8OJmir2ZSYdYgcrYs578ldo74s7i3EdipkLxgXes/edit?usp=sharing OWASP DefectDojo Project] &lt;br /&gt;
* [https://docs.google.com/a/owasp.org/document/d/198-SYlHl2g0FFE3GcJeOUIS1Sw26gxXKbk3tK1x23js/edit?usp=sharing OWASP Node.js Goat Project]&lt;br /&gt;
'''Documentation Projects:'''&lt;br /&gt;
* [https://docs.google.com/a/owasp.org/document/d/1HPpSF7vaZEFhO2mRxqJT2KTmtxp7yxkFmm5jbzliuy4/edit?usp=sharing OWASP Automated Threats to Web Applications] &lt;br /&gt;
* [https://docs.google.com/a/owasp.org/document/d/15gEcVHJDcbJQysCTHww3vD_LH2BQoKvE3wBp3LI5cAY/edit?usp=sharing OWASP Snakes and Ladder] &lt;br /&gt;
* [https://docs.google.com/a/owasp.org/document/d/1j3RWsL5SYxw6vx9PCsWikrvKmbj97XicMlJW6xhdhjY/edit?usp=sharing OWASP Embedded Application Security]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_AppSensor_Project&amp;diff=240346</id>
		<title>OWASP AppSensor Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_AppSensor_Project&amp;diff=240346"/>
				<updated>2018-05-01T19:37:00Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:120px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:Appsensor-header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:90px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File: flagship_big.jpg|link=OWASP_Project_Stages#tab=Flagship_Projects]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== OWASP AppSensor ==&lt;br /&gt;
&lt;br /&gt;
The AppSensor project defines a conceptual framework and methodology that offers prescriptive guidance to implement [https://www.owasp.org/index.php/ApplicationLayerIntrustionDetection intrusion detection and automated response] into applications.&lt;br /&gt;
&lt;br /&gt;
The project offers a comprehensive guide and a reference implementation. These resources can be used by architects, developers, security analyst and system administrators to plan, implement and monitor an AppSensor system.&lt;br /&gt;
&lt;br /&gt;
== Introduction ==&lt;br /&gt;
&lt;br /&gt;
If you walk into a bank and try opening random doors, you will be identified, led out of the building and possibly arrested. However, if you log into an online banking application and start looking for vulnerabilities no one will say anything. This needs to change!  As critical applications continue to become more accessible and inter-connected, it is paramount that critical information is sufficiently protected. We must also realize that our defenses may not be perfect. Given enough time, attackers can identify security flaws in the design or implementation of an application. &lt;br /&gt;
&lt;br /&gt;
In addition to implementing layers of defense within an application, we must identify malicious individuals before they are able to identify any gaps in our defenses. The best place to identify malicious activity against the application is within the application itself. Network based intrusion detection systems are not appropriate to handle the custom and intricate workings of an enterprise application and are ill-suited to detect attacks focusing on application logic such as authentication, access control, etc. This project delivers a framework which can be used to build a robust system of attack detection, analysis, and response within an enterprise application.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Detect and Respond to Attacks from Within the Application ==&lt;br /&gt;
&lt;br /&gt;
=== Detection ===&lt;br /&gt;
AppSensor defines over 50 different detection points which can be used to identify a malicious attacker.&lt;br /&gt;
=== Response===&lt;br /&gt;
AppSensor provides guidance on how to respond once a malicious attacker has been identified. Possible actions include: logging out the user, locking the account or notifying an administrator. More than a dozen response actions are described.&lt;br /&gt;
===Defending the Application===&lt;br /&gt;
An attacker often requires numerous probes and attack attempts in order to locate an exploitable vulnerability within the application. By using AppSensor it is possible to identify and eliminate the threat of an attacker before they are able to successfully identify an exploitable flaw.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Citations==&lt;br /&gt;
&lt;br /&gt;
* [http://www.crosstalkonline.org/ CrossTalk], The Journal of Defense Software Engineering&lt;br /&gt;
** Creating Attack-Aware Software Applications with Real Time Defenses, Vol. 24, No. 5, Sep/Oct 2011&lt;br /&gt;
&lt;br /&gt;
* Norwegian University of Science and Technology in Tronheim&lt;br /&gt;
** [https://brage.bibsys.no/xmlui/handle/11250/252956 AppSensor: Attack-Aware Applications Compared Against a Web Application Firewall and an Intrusion Detection System], Thomassen P, 2012&lt;br /&gt;
&lt;br /&gt;
*US Department of Homeland Security&lt;br /&gt;
** [https://buildsecurityin.us-cert.gov/swa/topics/resilient-software/ Resilient Software]&lt;br /&gt;
** [https://buildsecurityin.us-cert.gov/swa/resources Software Assurance Resources]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
OWASP AppSensor is free to use. &lt;br /&gt;
&lt;br /&gt;
=== Guide ===&lt;br /&gt;
The guide is licensed under the [http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
=== Reference Implementation ===&lt;br /&gt;
The reference implementation is licensed under the [http://opensource.org/licenses/MIT MIT License], which is a permissive (commercial-friendly) license only requiring you to include a copy of the license upon distribution or copying.&lt;br /&gt;
&lt;br /&gt;
&amp;amp;copy; OWASP Foundation&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is AppSensor? ==&lt;br /&gt;
&lt;br /&gt;
Detect and respond to attacks from within the application. This project includes both a well documented idea (the Guide) and a reference implementation (the Code). &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Intro for Developers ==&lt;br /&gt;
&lt;br /&gt;
[[File:Appsensor-developer-small.jpg|link=https://www.owasp.org/index.php/File:Appsensor_intro_for_developers.pdf]]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/File:Appsensor_intro_for_developers.pdf Two-sided US Letter or A4]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== AppSensor Website ==&lt;br /&gt;
&lt;br /&gt;
[[File:Appsensor-website-small.jpg|link=http://appsensor.org/]]&lt;br /&gt;
&lt;br /&gt;
See the [http://appsensor.org/ AppSensor website] for an introduction and quick start instructions.&lt;br /&gt;
&lt;br /&gt;
== Overview ==&lt;br /&gt;
&lt;br /&gt;
[[File:Appsensor-cisobriefing-small.jpg|link=https://www.owasp.org/index.php/File:Appsensor-ciso-briefing.pdf]]&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/index.php/File:Appsensor-ciso-briefing.pdf 12-page US Letter booklet]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Founder ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:MichaelCoates Michael Coates] [mailto:michael.coates@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves] [mailto:dennis.groves@owasp.org @]&lt;br /&gt;
* [https://www.owasp.org/index.php/User:John_Melton John Melton] [mailto:john.melton@owasp.org @]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[:Category:OWASP_ModSecurity_Core_Rule_Set_Project|OWASP ModSecurity Core Rule Set]]&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;padding-left:25px;width:200px;&amp;quot; valign=&amp;quot;top&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
* OWASP AppSensor Guide v2 EN&lt;br /&gt;
** [https://www.owasp.org/index.php/File:Owasp-appsensor-guide-v2.pdf PDF]&lt;br /&gt;
** [https://www.owasp.org/index.php/File:Owasp-appensor-guide-v2.doc DOC]&lt;br /&gt;
** [http://www.lulu.com/shop/owasp-foundation/appsensor-guide/paperback/product-21608107.html Hard copy]&lt;br /&gt;
* OWASP AppSensor Reference Implementation&lt;br /&gt;
** [https://github.com/jtmelton/appsensor v2 Code]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
* [25 Sep 2015] [http://appsecusa2015.sched.org/event/09495faf5cced352cb4a2acc16ce9158#.VaOSoHhfk2w Presentation] at AppSec USA 2015&lt;br /&gt;
* [27 Jul 2015] [https://www.owasp.org/index.php/File:Owasp-appensor-guide-v2.doc AppSensor Guide v2.0.2] published&lt;br /&gt;
* [09 Jun 2015] AppSensor Code v2.1.0 [https://github.com/jtmelton/appsensor/releases/tag/v2.1.0 released]&lt;br /&gt;
* [20 May 2015] Working session at [http://2015.appsec.eu/project-summit/ OWASP Project Summit] - Code&lt;br /&gt;
* [19 May 2015] Working session at [http://2015.appsec.eu/project-summit/ OWASP Project Summit] - Documentation&lt;br /&gt;
* [09 Apr 2015] [https://www.owasp.org/index.php/File:Appsensor-ciso-briefing.pdf CISO Briefing] booklet published&lt;br /&gt;
* [22 Feb 2015] Proposal for [https://www.owasp.org/index.php/GSoC2015_Ideas#OWASP_AppSensor Google Summer of Code 2015]&lt;br /&gt;
* [13 Feb 2015] [https://www.owasp.org/index.php/File:Appsensor_intro_for_developers.pdf Introduction for Developers] flyer published&lt;br /&gt;
* [13 Feb 2015] AppSensor project awarded OWASP flagship status&lt;br /&gt;
* [28 Jan 2015] AppSensor Code v2.0.0 final [https://github.com/jtmelton/appsensor/releases/tag/v2.0.0 released]&lt;br /&gt;
&lt;br /&gt;
== Code Repository ==&lt;br /&gt;
* AppSensor v2 https://github.com/jtmelton/appsensor (Current)&lt;br /&gt;
* Note: LEGACY AppSensor v1 https://code.google.com/p/appsensor/&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
[[File:AppSensor2_small.jpg|link=]]&lt;br /&gt;
&lt;br /&gt;
The [http://www.lulu.com/shop/owasp-foundation/appsensor-guide/paperback/product-22290600.html AppSensor Guide] and [http://www.lulu.com/shop/owasp-foundation/appsensor-ciso-briefing/paperback/product-22121723.html CISO Briefing] can be purchased at cost as print on demand books.&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| cellpadding=&amp;quot;2&amp;quot; width=&amp;quot;200&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Mature projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; width=&amp;quot;50%&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
== Volunteers ==&lt;br /&gt;
&lt;br /&gt;
All OWASP projects rely on the voluntary efforts of people in the software development and information security sectors. They have contributed their time and energy to make suggestions, provide feedback, write, review and edit documentation, give encouragement, make introductions, produce demonstration code, promote the concept, and provide OWASP support. They participated via the project’s mailing lists, by developing code, by updating the wiki, by undertaking research studies, and through contributions during the AppSensor working session at the OWASP Summit 2011 in Portugal and the AppSensor Summit at AppSec USA 2011. Without all their efforts, the project would not have progressed to this point, and this guide would not have been completed.&lt;br /&gt;
&lt;br /&gt;
{| cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;left&amp;quot; width=&amp;quot;200&amp;quot; valign=&amp;quot;top&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
*Josh Amishav-Zlatin&lt;br /&gt;
*Ryan Barnett&lt;br /&gt;
*Simon Bennetts&lt;br /&gt;
*Joe Bernik&lt;br /&gt;
*Rex Booth&lt;br /&gt;
*Luke Briner&lt;br /&gt;
*Rauf Butt&lt;br /&gt;
*Juan C Calderon&lt;br /&gt;
*Fabio Cerullo&lt;br /&gt;
*Marc Chisinevski&lt;br /&gt;
*Robert Chojnacki&lt;br /&gt;
*Michael Coates&lt;br /&gt;
*Dinis Cruz&lt;br /&gt;
*Sumanth Damaria&lt;br /&gt;
*August Detlefsen&lt;br /&gt;
*Ryan Dewhurst&lt;br /&gt;
*Sean Fay&lt;br /&gt;
&lt;br /&gt;
   | align=&amp;quot;left&amp;quot; width=&amp;quot;200&amp;quot; valign=&amp;quot;top&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
*Timo Goosen&lt;br /&gt;
*Dennis Groves&lt;br /&gt;
*Randy Janida&lt;br /&gt;
*Chetan Karande&lt;br /&gt;
*Eoin Keary&lt;br /&gt;
*Alex Lauerman&lt;br /&gt;
*Junior Lazuardi&lt;br /&gt;
*Benjamin-Hugo LeBlanc&lt;br /&gt;
*Jason Li&lt;br /&gt;
*Manuel López Arredondo&lt;br /&gt;
*Bob Maier&lt;br /&gt;
*Jim Manico&lt;br /&gt;
*Sherif Mansour Farag&lt;br /&gt;
*John Melton&lt;br /&gt;
*Mark Miller&lt;br /&gt;
* Rich Mogull&lt;br /&gt;
*Craig Munson&lt;br /&gt;
&lt;br /&gt;
   | align=&amp;quot;left&amp;quot; width=&amp;quot;200&amp;quot; valign=&amp;quot;top&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
*Louis Nadeau&lt;br /&gt;
*Giri Nambari&lt;br /&gt;
*Erlend Oftedal&lt;br /&gt;
*Jay Reynolds&lt;br /&gt;
*Chris Schmidt&lt;br /&gt;
*Sahil Shah&lt;br /&gt;
*Eric Sheridan&lt;br /&gt;
*John Steven&lt;br /&gt;
*Raphael Taban&lt;br /&gt;
*Alex Thissen&lt;br /&gt;
*Don Thomas&lt;br /&gt;
*Christopher Tidball&lt;br /&gt;
*Stephen de Vries&lt;br /&gt;
*Kevin W Wall&lt;br /&gt;
*Colin Watson&lt;br /&gt;
*Mehmet Yilmaz&lt;br /&gt;
&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
==OWASP Summer of Code 2008==&lt;br /&gt;
The AppSensor Project  was initially supported by the [https://www.owasp.org/index.php/OWASP_Summer_of_Code_2008 OWASP Summer of Code 2008], leading to the publication of the book AppSensor v1.1.&lt;br /&gt;
&lt;br /&gt;
==Google Summer of Code 2012==&lt;br /&gt;
Additional development work on [http://www.google-melange.com/gsoc/project/google/gsoc2012/edil/60002 SOAP web services] was kindly supported by the [http://www.google-melange.com/gsoc/program/home/google/gsoc2012 Google Summer of Code 2012].&lt;br /&gt;
&lt;br /&gt;
==OWASP Code Sprint 2015==&lt;br /&gt;
Development work was also supported by the [https://www.owasp.org/index.php/Summer_Code_Sprint2015 OWASP Summer Code Sprint 2015].&lt;br /&gt;
&lt;br /&gt;
== Other Acknowledgements ==&lt;br /&gt;
The project has also benefitted greatly from the generous contribution of time and effort by many volunteers in the OWASP community including those listed above, and contributors to the OWASP ESAPI project, members of the former OWASP Global Projects Committee, the OWASP Board, OWASP staff and support from the OWASP Project Reboot initiative. The v2 code and documentation were conceived during the AppSensor Summit held during AppSec USA 2011 in Minneapolis.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
Please join the project's mailing lists to keep up-to-date with what's going on, and to contribute your ideas, feedback, and experience:&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo/owasp-appsensor-project General project]&lt;br /&gt;
* [https://lists.owasp.org/mailman/listinfo/owasp-appsensor-dev Code development]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Current activities ==&lt;br /&gt;
&lt;br /&gt;
=== Non code ===&lt;br /&gt;
&lt;br /&gt;
* Update AppSensor Guide to keep in step with code changes and improvements to ideas ([http://lists.owasp.org/pipermail/owasp-appsensor-project/2015-February/000855.html see discussion and editable list of changes])&lt;br /&gt;
* Create demo&lt;br /&gt;
* Develop training materials&lt;br /&gt;
&lt;br /&gt;
=== v2 Code ===&lt;br /&gt;
&lt;br /&gt;
The current code being worked on is located on [https://github.com/jtmelton/appsensor GitHub]&lt;br /&gt;
&lt;br /&gt;
The code has been fully rewritten. &lt;br /&gt;
v2.0.0 final was released in late January 2015.&lt;br /&gt;
v2.1.0 final was released in June 2015.&lt;br /&gt;
v2.2.0 final was released in September 2015&lt;br /&gt;
&lt;br /&gt;
The main reason for the rewrite was to allow a client-server style model as opposed to requiring AppSensor be fully embedded in the application. You can now have a central server collecting events from multiple applications and performing analysis. These front-end applications can be in any language as long as they speak rest/soap. There's been a host of other changes, but this was the primary one. A number of starter ideas for coding, user interface and documentation have been outlined via the mailing list at [http://lists.owasp.org/pipermail/owasp-appsensor-project/2014-March/000682.html 17th March 2014].&lt;br /&gt;
&lt;br /&gt;
if you want to work on ANYTHING, please let jtmelton[@]gmail.com know.&lt;br /&gt;
&lt;br /&gt;
== Code Roadmap ==&lt;br /&gt;
&lt;br /&gt;
=== Q4 2015 (2.0) === &lt;br /&gt;
* &amp;lt;strike&amp;gt;Jan - v 2.0.0 final release &amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
&lt;br /&gt;
=== Q4 2014 (2.0) === &lt;br /&gt;
* &amp;lt;strike&amp;gt;Oct - v 2.0.0 release candidate&amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
* &amp;lt;strike&amp;gt;Jan 2015 (delay due to bug) - v 2.0.0 final &amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
* &amp;lt;strike&amp;gt;Additional unit tests&amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
* &amp;lt;strike&amp;gt;Move appsensor.org site over from static html to python&amp;lt;/strike&amp;gt; -&amp;gt; NOT NECESSARY&lt;br /&gt;
* &amp;lt;strike&amp;gt;Finish up user documentation at appsensor.org&amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
&lt;br /&gt;
=== June 2015 (2.1) === &lt;br /&gt;
* &amp;lt;strike&amp;gt;Add at least 1 attack emitter for DEVOPS visualization (JMX -&amp;gt; SNMP, syslog, SNMP, .. something)&amp;lt;/strike&amp;gt; ([https://github.com/jtmelton/appsensor/issues/19 github issue]) -&amp;gt; DONE&lt;br /&gt;
* &amp;lt;strike&amp;gt;Sample application / demo&amp;lt;/strike&amp;gt; ([https://github.com/jtmelton/appsensor/issues/9 github issue]) -&amp;gt; DONE&lt;br /&gt;
* &amp;lt;strike&amp;gt;Finish up developer documentation on github and appsensor.org&amp;lt;/strike&amp;gt; ([https://github.com/jtmelton/appsensor/issues/12 github issue]) -&amp;gt; DONE&lt;br /&gt;
* &amp;lt;strike&amp;gt;Preparation for GSOC 2015 submission&amp;lt;/strike&amp;gt; -&amp;gt; DONE - see [[GSoC2015_Ideas]] - Update - OWASP not selected&lt;br /&gt;
&lt;br /&gt;
=== September 2015 (2.2) === &lt;br /&gt;
* &amp;lt;strike&amp;gt;First version of administration UI for appsensor (monitoring UI) (github issues [https://github.com/jtmelton/appsensor/issues/10 here] and [https://github.com/jtmelton/appsensor/issues/11 here])&amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
&lt;br /&gt;
=== January 2016 (2.3) === &lt;br /&gt;
* &amp;lt;strike&amp;gt;Get CI server (cloudbees?) setup ([https://github.com/jtmelton/appsensor/issues/15 github issue])&amp;lt;/strike&amp;gt; -&amp;gt; DONE&lt;br /&gt;
* Video demo of setting up appsensor (screen capture) (related to sample apps)&lt;br /&gt;
* New detection point implementations ([https://github.com/jtmelton/appsensor/issues/8 github issue])&lt;br /&gt;
* AOP examples of detection point implementations&lt;br /&gt;
&lt;br /&gt;
=== May 2016 (2.4) === &lt;br /&gt;
* Trend monitoring implementation ([https://github.com/jtmelton/appsensor/issues/6 github issue])&lt;br /&gt;
* Additional integrations for reporting (graphite, ganglia -&amp;gt; see list supported by codahale metrics)&lt;br /&gt;
&lt;br /&gt;
== Past activities ==&lt;br /&gt;
&lt;br /&gt;
'''September 2015''' Final release v2.2.0 code&lt;br /&gt;
&lt;br /&gt;
'''June 2015''' Final release v2.1.0 code&lt;br /&gt;
&lt;br /&gt;
'''April 2015''' CISO Briefing booklet published&lt;br /&gt;
&lt;br /&gt;
'''February 2015''' Introduction for Developers flyer published&lt;br /&gt;
&lt;br /&gt;
'''January 2015''' Final release v2.0.0 code&lt;br /&gt;
&lt;br /&gt;
'''May 2014''' Finalisation and publication of the AppSensor Guide v2.0&lt;br /&gt;
&lt;br /&gt;
'''November, 2013''' - AppSensor 2.0 hackathon, and document writing &amp;amp; review at AppSecUSA 2013, New York&lt;br /&gt;
&lt;br /&gt;
'''2012-2013''' - Active Development of next AppSensor book&lt;br /&gt;
&lt;br /&gt;
'''September, 2011''' - AppSensor Summit at AppSec USA 2011, Minneapolis&lt;br /&gt;
&lt;br /&gt;
'''September, 2010''' - Presented at AppSecUSA [http://www.slideshare.net/michael_coates/real-time-application-defenses-the-reality-of-appsensor-esapi-5181743 slides]&lt;br /&gt;
&lt;br /&gt;
'''June, 2010''' - Active ESAPI Integration Underway&lt;br /&gt;
&lt;br /&gt;
'''November, 2009''' [http://www.owasp.org/images/0/06/Defend_Yourself-Integrating_Real_Time_Defenses_into_Online_Applications-Michael_Coates.pdf OWASP DC, November 2009]&lt;br /&gt;
&lt;br /&gt;
'''2009''' v1.2 in the works, demo application in development &lt;br /&gt;
&lt;br /&gt;
'''May, 2009''' - AppSec EU Poland - Presentation ([http://www.owasp.org/images/b/b7/AppsecEU09_MichaelCoates.pptx PPT]) ([http://blip.tv/file/2198771 Video]) &lt;br /&gt;
&lt;br /&gt;
'''January, 2009''' - v1.1 Released - Beta Status &lt;br /&gt;
&lt;br /&gt;
'''November, 2008''' - AppSensor Talk at OWASP Portugal &lt;br /&gt;
&lt;br /&gt;
'''November, 2008''' - v1.0 Released - Beta Status &lt;br /&gt;
&lt;br /&gt;
'''April 16, 2008''' - Project Begins&lt;br /&gt;
&lt;br /&gt;
= Detection Points =&lt;br /&gt;
&lt;br /&gt;
Below are the primary detection points defined within AppSensor. These are just the titles; the document contains descriptions, examples and considerations for implementing these detection points. &lt;br /&gt;
&lt;br /&gt;
 '''[http://www.owasp.org/index.php/AppSensor_DetectionPoints Detailed Detection Point Information Here] '''&lt;br /&gt;
&lt;br /&gt;
 '''[http://www.owasp.org/index.php/AppSensor_ResponseActions Response Action Information Here]'''&lt;br /&gt;
&lt;br /&gt;
'''Summary of Information'''&lt;br /&gt;
'''Detection Categories:''' &lt;br /&gt;
&lt;br /&gt;
RE - Request&lt;br /&gt;
&lt;br /&gt;
AE - Authentication&lt;br /&gt;
&lt;br /&gt;
SE - Session&lt;br /&gt;
&lt;br /&gt;
ACE - Access Control&lt;br /&gt;
&lt;br /&gt;
IE - Input&lt;br /&gt;
&lt;br /&gt;
EE - Encoding&lt;br /&gt;
&lt;br /&gt;
CIE - Command Injection&lt;br /&gt;
&lt;br /&gt;
FIO - File IO&lt;br /&gt;
&lt;br /&gt;
HT - Honey Trap&lt;br /&gt;
&lt;br /&gt;
UT - User Trend&lt;br /&gt;
&lt;br /&gt;
STE - System Trend&lt;br /&gt;
&lt;br /&gt;
RP - Reputation&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
'''Signature Based Event Titles''' &lt;br /&gt;
&lt;br /&gt;
ID Event&lt;br /&gt;
&lt;br /&gt;
RE1 Unexpected HTTP Command&lt;br /&gt;
&lt;br /&gt;
RE2 Attempt to Invoke Unsupported HTTP Method&lt;br /&gt;
&lt;br /&gt;
RE3 GET When Expecting POST&lt;br /&gt;
&lt;br /&gt;
RE4 POST When Expecting GET&lt;br /&gt;
&lt;br /&gt;
RE5 Additional/Duplicated Data in Request&lt;br /&gt;
&lt;br /&gt;
RE6 Data Missing from Request&lt;br /&gt;
&lt;br /&gt;
RE7 Unexpected Quantity of Characters in Parameter&lt;br /&gt;
&lt;br /&gt;
RE8 Unexpected Type of Characters in Parameter&lt;br /&gt;
&lt;br /&gt;
AE1 Use Of Multiple Usernames&lt;br /&gt;
&lt;br /&gt;
AE2 Multiple Failed Passwords&lt;br /&gt;
&lt;br /&gt;
AE3 High Rate of Login Attempts&lt;br /&gt;
&lt;br /&gt;
AE4 Unexpected Quantity of Characters in Username&lt;br /&gt;
&lt;br /&gt;
AE5 Unexpected Quantity of Characters in Password&lt;br /&gt;
&lt;br /&gt;
AE6 Unexpected Type of Character in Username&lt;br /&gt;
&lt;br /&gt;
AE7 Unexpected Type of Character in Password&lt;br /&gt;
&lt;br /&gt;
AE8 Providing Only the Username&lt;br /&gt;
&lt;br /&gt;
AE9 Providing Only the Password&lt;br /&gt;
&lt;br /&gt;
AE10 Adding POST Variable&lt;br /&gt;
&lt;br /&gt;
AE11 Missing POST Variable&lt;br /&gt;
&lt;br /&gt;
AE12 Utilization of Common Usernames&lt;br /&gt;
&lt;br /&gt;
SE1 Modifying Existing Cookie&lt;br /&gt;
&lt;br /&gt;
SE2 Adding New Cookie&lt;br /&gt;
&lt;br /&gt;
SE3 Deleting Existing Cookie&lt;br /&gt;
&lt;br /&gt;
SE4 Substituting Another User's Valid Session ID or Cookie&lt;br /&gt;
&lt;br /&gt;
SE5 Source IP Address Changes During Session&lt;br /&gt;
&lt;br /&gt;
SE6 Change Of User Agent Mid Session&lt;br /&gt;
&lt;br /&gt;
ACE1 Modifying URL Argument Within a GET for Direct Object Access Attempt&lt;br /&gt;
&lt;br /&gt;
ACE2 Modifying Parameter Within a POST for Direct Object Access Attempt&lt;br /&gt;
&lt;br /&gt;
ACE3 Force Browsing Attempt&lt;br /&gt;
&lt;br /&gt;
ACE4 Evading Presentation Access Control Through Custom POST&lt;br /&gt;
&lt;br /&gt;
IE1 Cross Site Scripting Attempt&lt;br /&gt;
&lt;br /&gt;
IE2 Violation of Implemented White Lists&lt;br /&gt;
&lt;br /&gt;
IE3 Violation Of Implemented Black Lists&lt;br /&gt;
&lt;br /&gt;
IE4 Violation of Input Data Integrity&lt;br /&gt;
&lt;br /&gt;
IE5 Violation of Stored Business Data Integrity&lt;br /&gt;
&lt;br /&gt;
IE6 Violation of Security Log Integrity&lt;br /&gt;
&lt;br /&gt;
EE1 Double Encoded Character&lt;br /&gt;
&lt;br /&gt;
EE2 Unexpected Encoding Used&lt;br /&gt;
&lt;br /&gt;
CIE1 Blacklist Inspection for Common SQL Injection Values&lt;br /&gt;
&lt;br /&gt;
CIE2 Detect Abnormal Quantity of Returned Records&lt;br /&gt;
&lt;br /&gt;
CIE3 Null Byte Character in File Request&lt;br /&gt;
&lt;br /&gt;
CIE4 Carriage Return or Line Feed Character In File Request&lt;br /&gt;
&lt;br /&gt;
FIO1 Detect Large Individual File &lt;br /&gt;
&lt;br /&gt;
FIO2 Detect Large Number of File Uploads&lt;br /&gt;
&lt;br /&gt;
HT1 Alteration to Honey Trap Data&lt;br /&gt;
&lt;br /&gt;
HT2 Honey Trap Resource Requested&lt;br /&gt;
&lt;br /&gt;
HT3 Honey Trap Data Used&lt;br /&gt;
&lt;br /&gt;
'''Behavior Based Event Titles'''&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
UT1 Irregular Use of Application&lt;br /&gt;
&lt;br /&gt;
UT2 Speed of Application Use&lt;br /&gt;
&lt;br /&gt;
UT3 Frequency of Site Use&lt;br /&gt;
&lt;br /&gt;
UT4 Frequency of Feature Use&lt;br /&gt;
&lt;br /&gt;
STE1 High Number of Logouts Across The Site&lt;br /&gt;
&lt;br /&gt;
STE2 High Number of Logins Across The Site&lt;br /&gt;
&lt;br /&gt;
STE3 Significant Change in Usage of Same Transaction Across The Site&lt;br /&gt;
&lt;br /&gt;
RP1 Suspicious or Disallowed User IP Address&lt;br /&gt;
&lt;br /&gt;
RP2 Suspicious External User Behavior&lt;br /&gt;
&lt;br /&gt;
RP3 Suspicious Client-Side Behavior&lt;br /&gt;
&lt;br /&gt;
RP4 Change to Environment Threat Level&lt;br /&gt;
&lt;br /&gt;
= Media =&lt;br /&gt;
&lt;br /&gt;
== Introductory Briefings ==&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
| align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; | Developers&lt;br /&gt;
|&lt;br /&gt;
| align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; | Architects&lt;br /&gt;
|&lt;br /&gt;
| align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; | CISOs&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;left&amp;quot; width=&amp;quot;200&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Appsensor-developer-small.jpg|link=https://www.owasp.org/index.php/File:Appsensor_intro_for_developers.pdf]]&lt;br /&gt;
| width=&amp;quot;20&amp;quot; |&lt;br /&gt;
| align=&amp;quot;left&amp;quot; width=&amp;quot;200&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Appsensor_crosstalk_small.jpg|link=http://www.crosstalkonline.org/storage/issue-archives/2011/201109/201109-Watson.pdf]]&lt;br /&gt;
| width=&amp;quot;20&amp;quot; |&lt;br /&gt;
| align=&amp;quot;center&amp;quot; width=&amp;quot;200&amp;quot; valign=&amp;quot;top&amp;quot; | [[File:Appsensor-cisobriefing-small.jpg|link=https://www.owasp.org/index.php/File:Appsensor-ciso-briefing.pdf]]&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
The CISO briefing is also available to [http://www.lulu.com/shop/owasp-foundation/appsensor-ciso-briefing/paperback/product-22121723.html buy at cost in print].&lt;br /&gt;
&lt;br /&gt;
== AppSensor Website ==&lt;br /&gt;
&lt;br /&gt;
[[File:Appsensor-website-large.jpg|link=http://appsensor.org/]]&lt;br /&gt;
&lt;br /&gt;
http://appsensor.org/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Code ==&lt;br /&gt;
&lt;br /&gt;
*v2 [https://github.com/jtmelton/appsensor Github Code]&lt;br /&gt;
* (LEGACY) v1 [http://code.google.com/p/appsensor/ Google Code]&lt;br /&gt;
&lt;br /&gt;
== AppSensor Guide ==&lt;br /&gt;
&lt;br /&gt;
* OWASP AppSensor Guide &lt;br /&gt;
** v2.0 EN&lt;br /&gt;
*** [https://www.owasp.org/index.php/File:Owasp-appsensor-guide-v2.pdf PDF]&lt;br /&gt;
*** [https://www.owasp.org/index.php/File:Owasp-appensor-guide-v2.doc DOC]&lt;br /&gt;
*** [http://www.lulu.com/shop/owasp-foundation/appsensor-guide/paperback/product-21608107.html Print on demand at cost hard copy]&lt;br /&gt;
** v1.1 EN&lt;br /&gt;
*** [https://www.owasp.org/images/2/2f/OWASP_AppSensor_Beta_1.1.pdf PDF]&lt;br /&gt;
*** [https://www.owasp.org/images/b/b0/OWASP_AppSensor_Beta_1.1.doc DOC]&lt;br /&gt;
&lt;br /&gt;
== Presentations ==&lt;br /&gt;
&lt;br /&gt;
[http://www.brighttalk.com/webcast/20680 Automated Application Defenses to Thwart Advanced Attackers (Slides &amp;amp; Audio)]&lt;br /&gt;
&lt;br /&gt;
July, 2010 - OWASP London (UK) - [http://www.owasp.org/index.php/File:Owasp-london-20100715-appsensor-3.pdf Real Time Application Attack Detection and Response with OWASP AppSensor]&lt;br /&gt;
&lt;br /&gt;
June, 2010 - OWASP Leeds/North (UK) - OWASP AppSensor - The Self-Aware Web Application&lt;br /&gt;
&lt;br /&gt;
June, 2010 - Video presentation - [http://michael-coates.blogspot.com/2010/06/online-presentation-thursday-automated.html Automated Application Defenses to Thwart Advanced Attackers]&lt;br /&gt;
&lt;br /&gt;
November, 2009 -  AppSec DC - [http://www.owasp.org/images/0/06/Defend_Yourself-Integrating_Real_Time_Defenses_into_Online_Applications-Michael_Coates.pdf Defend Yourself: Integrating Real Time Defenses into Online Applications]&lt;br /&gt;
&lt;br /&gt;
May, 2009 - [http://www.owasp.org/download/jmanico/owasp_podcast_51.mp3 OWASP Podcast #51]&lt;br /&gt;
&lt;br /&gt;
May, 2009 - AppSec EU Poland - [https://www.owasp.org/images/b/b7/AppsecEU09_MichaelCoates.pptx Real Time Defenses against Application Worms and Malicious Attackers]&lt;br /&gt;
&lt;br /&gt;
November, 2008 - [https://www.owasp.org/images/7/77/Presentation_AppSensor.ppt OWASP Summit Portugal 2008 PPT]&lt;br /&gt;
&lt;br /&gt;
==Video Demos of AppSensor==&lt;br /&gt;
&lt;br /&gt;
[http://www.youtube.com/watch?v=8ItfuwvLxRk Detecting Multiple Attacks &amp;amp; Logging Out Attacker]&lt;br /&gt;
&lt;br /&gt;
[http://www.youtube.com/watch?v=CekUMk_VRV8 Detecting XSS Probes]&lt;br /&gt;
&lt;br /&gt;
[http://www.youtube.com/watch?v=LfD4y67qdWE Detecting URL Tampering]&lt;br /&gt;
&lt;br /&gt;
[http://www.youtube.com/watch?v=1D6nTlmYjhY Detecting Verb Tampering]&lt;br /&gt;
&lt;br /&gt;
==Source Documents / Artwork==&lt;br /&gt;
&lt;br /&gt;
* Guide&lt;br /&gt;
** [https://www.owasp.org/index.php/File:Owasp-appensor-guide-v2.doc Word (content only)], DOC 11Mb&lt;br /&gt;
** [https://4ed64fe7f7e3f627b8d0-bc104063a9fe564c2d8a75b1e218477a.ssl.cf2.rackcdn.com/appsensor-guide-2v0-owasp.zip Word, images, Lulu covers, diagrams], ZIP 96Mb&lt;br /&gt;
* Introduction for Developers&lt;br /&gt;
** [https://www.owasp.org/index.php/File:Appsensor-intro-for-developers-a4.zip A4 Illustrator and PDF exports], ZIP 19Mb&lt;br /&gt;
** [https://www.owasp.org/index.php/File:Appsensor-intro-for-developers-usletter.zip US letter Illustrator and PDF exports], ZIP 19Mb&lt;br /&gt;
* Poster&lt;br /&gt;
** [https://www.owasp.org/index.php/File:Owasp-appsensor-poster-a1.zip A1 Illustrator and PDF export] ZIP, 18Mb&lt;br /&gt;
&lt;br /&gt;
= Project About =&lt;br /&gt;
{{:Projects/OWASP_AppSensor_Project | Project About}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;nowiki&amp;gt;}} &amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project|AppSensor Project]] &lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]] &lt;br /&gt;
[[Category:OWASP_Document]] &lt;br /&gt;
[[Category:OWASP_Download]] &lt;br /&gt;
[[Category:SAMM-EH-3]] &lt;br /&gt;
[[Category:SAMM-SA-2]] &lt;br /&gt;
[[Category:SAMM-VM-3]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Honeypot_Project&amp;diff=240317</id>
		<title>OWASP Honeypot Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Honeypot_Project&amp;diff=240317"/>
				<updated>2018-04-30T12:36:09Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP Tool Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Tool project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Tool Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [12 Feb 2013] Support for Spanish is now available with this release.&lt;br /&gt;
* [11 Jan 2014] The 1.0 stable version has been released! Thanks everyone for your feedback and code fixes that made this happen!&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Project Template is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Tool Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Tool Project Template&lt;br /&gt;
* Get other people to review the Tool Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Tool Project Template&lt;br /&gt;
* Finalize the Tool Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Tool_Project_Template Tool Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
Addtional Instructions for making changes:&lt;br /&gt;
&lt;br /&gt;
The About 'tab' on that page is done with a MediaWiki template.  If you log into the wiki page for your project and click the &amp;quot;Edit&amp;quot; button/link/tab in the top-right between 'Read' and 'View History', you'll see the edit page for the main body of your project page.&lt;br /&gt;
&lt;br /&gt;
If you scroll down below the form to edit that page (below the &amp;quot;Save page&amp;quot;, &amp;quot;Show preview&amp;quot;, &amp;quot;Show changes&amp;quot; buttons, you'll see some text with a triangle in front of it reading &amp;quot;Templates used on this page:&amp;quot;  A list will expand if you click on the triangle/text to show the templates that make up this page.  The one you want is the &amp;quot;Projects/OWASP Example Project About Page&amp;quot; - click the (edit) next to this to edit that template.  The direct link is: https://www.owasp.org/index.php?title=Projects/OWASP_Example_Project_About_Page&amp;amp;action=edit&lt;br /&gt;
&lt;br /&gt;
The template takes 'input' that are key/value pairs where you'll need to edit the stuff after the equals (=) like:&lt;br /&gt;
project_name =Place your project name here. &lt;br /&gt;
&lt;br /&gt;
You'd edit the bold bit.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Honeypot_Project&amp;diff=240316</id>
		<title>OWASP Honeypot Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Honeypot_Project&amp;diff=240316"/>
				<updated>2018-04-30T12:35:21Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Created page with &amp;quot;Main        Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Main&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
OWASP Tool Project Template&lt;br /&gt;
&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
Description&lt;br /&gt;
&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Tool project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Tool Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
Licensing&lt;br /&gt;
&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see OWASP Licenses. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the link GNU Affero General Public License 3.0 as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright © by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 Project Resources &lt;br /&gt;
&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Installation Package&lt;br /&gt;
&lt;br /&gt;
Source Code&lt;br /&gt;
&lt;br /&gt;
What's New (Revision History)&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
Wiki Home Page&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
Slide Presentation&lt;br /&gt;
&lt;br /&gt;
Video&lt;br /&gt;
&lt;br /&gt;
 Project Leader &lt;br /&gt;
&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
 Related Projects &lt;br /&gt;
&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&lt;br /&gt;
 OWASP_Code_Project_Template&lt;br /&gt;
 OWASP_Documentation_Project_Template&lt;br /&gt;
&lt;br /&gt;
Classifications&lt;br /&gt;
&lt;br /&gt;
   &lt;br /&gt;
   &lt;br /&gt;
    &lt;br /&gt;
   &lt;br /&gt;
    &lt;br /&gt;
      &lt;br /&gt;
   &lt;br /&gt;
    &lt;br /&gt;
   &lt;br /&gt;
    &lt;br /&gt;
   &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
 News and Events &lt;br /&gt;
&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&lt;br /&gt;
 [12 Feb 2013] Support for Spanish is now available with this release.&lt;br /&gt;
 [11 Jan 2014] The 1.0 stable version has been released! Thanks everyone for your feedback and code fixes that made this happen!&lt;br /&gt;
 [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
 [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
 [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
FAQs&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. The point of a document like this are the answers. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
How can I participate in your project?&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
If I am not a programmer can I participate in your project?&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
 Acknowledgements &lt;br /&gt;
Contributors&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Project Template is developed by a worldwide team of volunteers. A live update of project  contributors is found here. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
 Colin Watson who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
 Chuck Cooper who edited the template to convert it from a documentation project to a Tool Project Template&lt;br /&gt;
 YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES&lt;br /&gt;
&lt;br /&gt;
 Road Map and Getting Involved &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Roadmap&lt;br /&gt;
As of November, 2013, the highest priorities for the next 6 months are:&lt;br /&gt;
&lt;br /&gt;
 Complete the first draft of the Tool Project Template&lt;br /&gt;
 Get other people to review the Tool Project Template and provide feedback&lt;br /&gt;
 Incorporate feedback into changes in the Tool Project Template&lt;br /&gt;
 Finalize the Tool Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&lt;br /&gt;
 Internationalization Support&lt;br /&gt;
 Additional Unit Tests&lt;br /&gt;
 Automated Regression tests&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Getting Involved&lt;br /&gt;
Involvement in the development and promotion of Tool Project Template is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
Coding&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
Localization&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the Tool Project Template into that language?&lt;br /&gt;
Testing&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
Feedback&lt;br /&gt;
Please use the Tool Project Template project mailing list for feedback about:&lt;br /&gt;
&lt;br /&gt;
What do like?&lt;br /&gt;
What don't you like?&lt;br /&gt;
What features would you like to see prioritized on the roadmap?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Minimum Viable Product&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
Project About&lt;br /&gt;
Addtional Instructions for making changes:&lt;br /&gt;
&lt;br /&gt;
The About 'tab' on that page is done with a MediaWiki template.  If you log into the wiki page for your project and click the &amp;quot;Edit&amp;quot; button/link/tab in the top-right between 'Read' and 'View History', you'll see the edit page for the main body of your project page.&lt;br /&gt;
&lt;br /&gt;
If you scroll down below the form to edit that page (below the &amp;quot;Save page&amp;quot;, &amp;quot;Show preview&amp;quot;, &amp;quot;Show changes&amp;quot; buttons, you'll see some text with a triangle in front of it reading &amp;quot;Templates used on this page:&amp;quot;  A list will expand if you click on the triangle/text to show the templates that make up this page.  The one you want is the &amp;quot;Projects/OWASP Example Project About Page&amp;quot; - click the (edit) next to this to edit that template.  The direct link is: https://www.owasp.org/index.php?title=Projects/OWASP_Example_Project_About_Page&amp;amp;action=edit&lt;br /&gt;
&lt;br /&gt;
The template takes 'input' that are key/value pairs where you'll need to edit the stuff after the equals (=) like:&lt;br /&gt;
project_name =Place your project name here. &lt;br /&gt;
&lt;br /&gt;
You'd edit the bold bit.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 PROJECT INFO What does this OWASP project offer you?&lt;br /&gt;
 RELEASE(S) INFO What releases are available for this project?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
 what&lt;br /&gt;
 is this project?&lt;br /&gt;
&lt;br /&gt;
 Name: OWASP SecureTea Tool Project&lt;br /&gt;
&lt;br /&gt;
  Purpose:  The OWASP SecureTea Project is a application designed to help Secure a person's laptop or computer with IoT (Internet Of Things) for notify users via twitter, whenever anyone accessing his laptop or computer. This application work using the touchpad / mouse / wireless mouse and developed in python. The purpose of this application is to warn the user (on twitter) whenever her laptop accessible. This small application was developed and tested in python in linux machine likely to be working well in the Raspberry Pi as well.&lt;br /&gt;
&lt;br /&gt;
  License: OWASP SecureTea Project is free software, released under the GNU GPL v3 License.&lt;br /&gt;
&lt;br /&gt;
 who&lt;br /&gt;
 is working on this project?&lt;br /&gt;
&lt;br /&gt;
 Project Leader(s): &lt;br /&gt;
  Gustavo Nieves Arreaza @         &lt;br /&gt;
                  &lt;br /&gt;
&lt;br /&gt;
 how&lt;br /&gt;
 can you learn more?&lt;br /&gt;
&lt;br /&gt;
 Project Pamphlet: Not Yet Created&lt;br /&gt;
&lt;br /&gt;
 Project Presentation: &lt;br /&gt;
&lt;br /&gt;
 Mailing list: N/A&lt;br /&gt;
&lt;br /&gt;
 Project Roadmap: Not Yet Created&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Key Contacts&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 Contact  Gustavo Nieves Arreaza @ to contribute to this project&lt;br /&gt;
&lt;br /&gt;
 Contact  Gustavo Nieves Arreaza @ to review or sponsor this project&lt;br /&gt;
&lt;br /&gt;
 Contact the GPC to report a problem or concern about this project or to update information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
   current release&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 1.0 &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
  last reviewed release&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 1.0 &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
 other releases&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:OWASP_WASC_Distributed_Web_Honeypots_Project&amp;diff=240315</id>
		<title>Talk:OWASP WASC Distributed Web Honeypots Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:OWASP_WASC_Distributed_Web_Honeypots_Project&amp;diff=240315"/>
				<updated>2018-04-30T12:33:47Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Created page with &amp;quot;Main        Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Main&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
OWASP Tool Project Template&lt;br /&gt;
&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
Description&lt;br /&gt;
&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Tool project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Tool Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
Licensing&lt;br /&gt;
&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see OWASP Licenses. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the link GNU Affero General Public License 3.0 as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright © by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 Project Resources &lt;br /&gt;
&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Installation Package&lt;br /&gt;
&lt;br /&gt;
Source Code&lt;br /&gt;
&lt;br /&gt;
What's New (Revision History)&lt;br /&gt;
&lt;br /&gt;
Documentation&lt;br /&gt;
&lt;br /&gt;
Wiki Home Page&lt;br /&gt;
&lt;br /&gt;
Issue Tracker&lt;br /&gt;
&lt;br /&gt;
Slide Presentation&lt;br /&gt;
&lt;br /&gt;
Video&lt;br /&gt;
&lt;br /&gt;
 Project Leader &lt;br /&gt;
&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
 Related Projects &lt;br /&gt;
&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&lt;br /&gt;
 OWASP_Code_Project_Template&lt;br /&gt;
 OWASP_Documentation_Project_Template&lt;br /&gt;
&lt;br /&gt;
Classifications&lt;br /&gt;
&lt;br /&gt;
   &lt;br /&gt;
   &lt;br /&gt;
    &lt;br /&gt;
   &lt;br /&gt;
    &lt;br /&gt;
      &lt;br /&gt;
   &lt;br /&gt;
    &lt;br /&gt;
   &lt;br /&gt;
    &lt;br /&gt;
   &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
 News and Events &lt;br /&gt;
&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&lt;br /&gt;
 [12 Feb 2013] Support for Spanish is now available with this release.&lt;br /&gt;
 [11 Jan 2014] The 1.0 stable version has been released! Thanks everyone for your feedback and code fixes that made this happen!&lt;br /&gt;
 [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
 [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
 [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
FAQs&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. The point of a document like this are the answers. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
How can I participate in your project?&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
If I am not a programmer can I participate in your project?&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
 Acknowledgements &lt;br /&gt;
Contributors&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Project Template is developed by a worldwide team of volunteers. A live update of project  contributors is found here. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
 Colin Watson who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
 Chuck Cooper who edited the template to convert it from a documentation project to a Tool Project Template&lt;br /&gt;
 YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES&lt;br /&gt;
&lt;br /&gt;
 Road Map and Getting Involved &lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Roadmap&lt;br /&gt;
As of November, 2013, the highest priorities for the next 6 months are:&lt;br /&gt;
&lt;br /&gt;
 Complete the first draft of the Tool Project Template&lt;br /&gt;
 Get other people to review the Tool Project Template and provide feedback&lt;br /&gt;
 Incorporate feedback into changes in the Tool Project Template&lt;br /&gt;
 Finalize the Tool Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&lt;br /&gt;
 Internationalization Support&lt;br /&gt;
 Additional Unit Tests&lt;br /&gt;
 Automated Regression tests&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Getting Involved&lt;br /&gt;
Involvement in the development and promotion of Tool Project Template is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
Coding&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
Localization&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the Tool Project Template into that language?&lt;br /&gt;
Testing&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
Feedback&lt;br /&gt;
Please use the Tool Project Template project mailing list for feedback about:&lt;br /&gt;
&lt;br /&gt;
What do like?&lt;br /&gt;
What don't you like?&lt;br /&gt;
What features would you like to see prioritized on the roadmap?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Minimum Viable Product&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
Project About&lt;br /&gt;
Addtional Instructions for making changes:&lt;br /&gt;
&lt;br /&gt;
The About 'tab' on that page is done with a MediaWiki template.  If you log into the wiki page for your project and click the &amp;quot;Edit&amp;quot; button/link/tab in the top-right between 'Read' and 'View History', you'll see the edit page for the main body of your project page.&lt;br /&gt;
&lt;br /&gt;
If you scroll down below the form to edit that page (below the &amp;quot;Save page&amp;quot;, &amp;quot;Show preview&amp;quot;, &amp;quot;Show changes&amp;quot; buttons, you'll see some text with a triangle in front of it reading &amp;quot;Templates used on this page:&amp;quot;  A list will expand if you click on the triangle/text to show the templates that make up this page.  The one you want is the &amp;quot;Projects/OWASP Example Project About Page&amp;quot; - click the (edit) next to this to edit that template.  The direct link is: https://www.owasp.org/index.php?title=Projects/OWASP_Example_Project_About_Page&amp;amp;action=edit&lt;br /&gt;
&lt;br /&gt;
The template takes 'input' that are key/value pairs where you'll need to edit the stuff after the equals (=) like:&lt;br /&gt;
project_name =Place your project name here. &lt;br /&gt;
&lt;br /&gt;
You'd edit the bold bit.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 PROJECT INFO What does this OWASP project offer you?&lt;br /&gt;
 RELEASE(S) INFO What releases are available for this project?&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
 what&lt;br /&gt;
 is this project?&lt;br /&gt;
&lt;br /&gt;
 Name: OWASP SecureTea Tool Project&lt;br /&gt;
&lt;br /&gt;
  Purpose:  The OWASP SecureTea Project is a application designed to help Secure a person's laptop or computer with IoT (Internet Of Things) for notify users via twitter, whenever anyone accessing his laptop or computer. This application work using the touchpad / mouse / wireless mouse and developed in python. The purpose of this application is to warn the user (on twitter) whenever her laptop accessible. This small application was developed and tested in python in linux machine likely to be working well in the Raspberry Pi as well.&lt;br /&gt;
&lt;br /&gt;
  License: OWASP SecureTea Project is free software, released under the GNU GPL v3 License.&lt;br /&gt;
&lt;br /&gt;
 who&lt;br /&gt;
 is working on this project?&lt;br /&gt;
&lt;br /&gt;
 Project Leader(s): &lt;br /&gt;
  Gustavo Nieves Arreaza @         &lt;br /&gt;
                  &lt;br /&gt;
&lt;br /&gt;
 how&lt;br /&gt;
 can you learn more?&lt;br /&gt;
&lt;br /&gt;
 Project Pamphlet: Not Yet Created&lt;br /&gt;
&lt;br /&gt;
 Project Presentation: &lt;br /&gt;
&lt;br /&gt;
 Mailing list: N/A&lt;br /&gt;
&lt;br /&gt;
 Project Roadmap: Not Yet Created&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Key Contacts&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 Contact  Gustavo Nieves Arreaza @ to contribute to this project&lt;br /&gt;
&lt;br /&gt;
 Contact  Gustavo Nieves Arreaza @ to review or sponsor this project&lt;br /&gt;
&lt;br /&gt;
 Contact the GPC to report a problem or concern about this project or to update information.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
   current release&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 1.0 &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
  last reviewed release&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 1.0 &lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
 other releases&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Glue_Tool_Project&amp;diff=240254</id>
		<title>OWASP Glue Tool Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Glue_Tool_Project&amp;diff=240254"/>
				<updated>2018-04-26T15:46:32Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* Project Resources */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP Glue Tool Project==&lt;br /&gt;
&lt;br /&gt;
The OWASP Glue Tool Project is a tools based project intended to make security automation easier.  It is essentially a ruby gem that co-ordinates the running of different analysis tools and reporting from those tools.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
The purpose of the project is to make it easy to run static analysis tools, live analysis tools (ZAP) etc. as part of an automated build process and to report the findings to JIRA or other tracking systems.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
Apache 2.0 License&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.apache.org/licenses/LICENSE-2.0 link Apache 2.0 License] as published by the Apache Software Foundation.  Any contributions are Copyright &amp;amp;copy; by OWASP 2015.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/glue Source Code]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
Matt Konda&lt;br /&gt;
&lt;br /&gt;
Omer Levi Hevroni&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_AppSec_Pipeline]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [27 Aug 2015] Initial Release.&lt;br /&gt;
* [14 Sep 2016] Renamed to Glue from Pipeline.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
==What does Glue do?==&lt;br /&gt;
The OWASP Glue tool attempts to make it very easy to run different types of security tools at various stages of the software development process and produce unified issues that can be used in other contexts to track or remediate issues.&lt;br /&gt;
&lt;br /&gt;
==Why would I use Glue?==&lt;br /&gt;
To help get security feedback into your developers hands faster.&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
Reach out to matt.konda@owasp.org with any questions or ideas or ideas about how to participate.  We are welcoming input.  We are following standard github workflow so you can fork the code and submit a pull request if you prefer.  Alternatively, you can get more deeply involved and talk with us about roadmap and other items.&lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
To this point, project contributors include: &lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Matt_Konda Matt Konda]&lt;br /&gt;
* Rafael Zambrano&lt;br /&gt;
* Alex Lock&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
Deliverable: Pipeline is delivered as a ruby gem (executable binary) and in a docker image with required tools already bundled.&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;September, 2016, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Stronger Jenkins workflow integration&lt;br /&gt;
* Integrate ZAP&lt;br /&gt;
* Stronger JIRA integration&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Additional Tools...&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Pipeline&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Tool_Project_Template Tool Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
== Pipeline needs ==&lt;br /&gt;
1.  Pull from github or a specified location on the file system&lt;br /&gt;
2.  Run tools like brakeman, bundler-audit and owasp-dependency-check on the code.  &lt;br /&gt;
3.  Standardizes the format of results then reports them in text, csv, json or via JIRA's REST API.  &lt;br /&gt;
4.  Detect duplicates and won't report the same thing more than once.&lt;br /&gt;
&lt;br /&gt;
It also needs to be easy to set up the security tools and digest results.  Hence a focus on docker.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
Detail around this project can be found at:  https://github.com/owasp/pipeline&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Project&amp;diff=240252</id>
		<title>Category:OWASP Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Project&amp;diff=240252"/>
				<updated>2018-04-26T15:42:33Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* Tools [Reviewed last: January 2017] */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;700&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
| align=&amp;quot;right&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
= Welcome  =&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
&amp;lt;font size=2pt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Welcome to the OWASP Global Projects Page ===&lt;br /&gt;
&lt;br /&gt;
(The Projects pages are constantly being updated.  Some pages may contain outdated information.  You can help OWASP to keep these pages current by visiting [[:Category:FIXME|FixME]])  Please contact Claudia Aviles Casanovas with questions using the [https://www.tfaforms.com/308703 Contact Us form]&lt;br /&gt;
&lt;br /&gt;
An OWASP project is a collection of related tasks that have a defined roadmap and team members. OWASP project leaders are responsible for defining the vision, roadmap, and tasks for the project. The project leader also promotes the project and builds the team. OWASP currently has ''''''over ''''''93'''''' active projects'''''', and new project applications are submitted every week.  &lt;br /&gt;
&lt;br /&gt;
This is one of the most popular divisions of OWASP as it gives members an opportunity to freely test theories and ideas with the professional advice and support of the OWASP community. Every project has an associated mail list. You can view all the lists, examine their archives, and subscribe to any project by visiting the [http://lists.owasp.org/mailman/listinfo OWASP Project Mailing Lists] page. A summary of recent project announcements is available on the [[OWASP Updates]] page. &lt;br /&gt;
&lt;br /&gt;
Download the '''[[Media:PROJECT_LEADER-HANDBOOK_2014.pdf|OWASP Project Handbook 2014]]''' &lt;br /&gt;
- 2016 Project handbook updates are in progress, [https://www.tfaforms.com/308703 Contact US] to join the collaboration team and improve the process&lt;br /&gt;
&lt;br /&gt;
'''[[OWASP_2014_Project_Handbook|OWASP Project Handbook Wiki 2014]]'''&lt;br /&gt;
&lt;br /&gt;
'''[[Project_Online_Resources|Project Online Resources]]'''&lt;br /&gt;
&lt;br /&gt;
=== Who Should Start an OWASP Project? ===&lt;br /&gt;
&lt;br /&gt;
*Application Developers. &lt;br /&gt;
*Software Architects. &lt;br /&gt;
* Information Security Authors.  &lt;br /&gt;
*Those who would like the support of a world wide professional community to develop or test an idea.&lt;br /&gt;
*Anyone wishing to take advantage of the professional body of knowledge OWASP has to offer.&lt;br /&gt;
&lt;br /&gt;
=== Contact Us===&lt;br /&gt;
&lt;br /&gt;
If you have any questions, please do not hesitate to  [http://owasp4.owasp.org/contactus.html Contact Us] by using the form provided here. Please allow five working days for your question or comment to be answered. This is due to the large amount of queries the foundation staff receive every day. We thank you for your patience.&lt;br /&gt;
&lt;br /&gt;
=== Fund Information ===&lt;br /&gt;
&lt;br /&gt;
https://www.owasp.org/index.php/Funding&lt;br /&gt;
&lt;br /&gt;
=== OWASP Project Inventory ===&lt;br /&gt;
&lt;br /&gt;
All OWASP tools, document, and code library projects are organized into the following [[OWASP_Project_Stages|categories:]] &lt;br /&gt;
&lt;br /&gt;
* '''[[OWASP_Project_Inventory#Flagship_Projects|Flagship Projects:]]''' The OWASP Flagship designation is given to projects that have demonstrated strategic value to OWASP and application security as a whole. &lt;br /&gt;
&lt;br /&gt;
* '''[[OWASP_Project_Inventory#Labs_Projects|Lab Projects:]]''' OWASP Labs projects represent projects that have produced an OWASP reviewed deliverable of value. &lt;br /&gt;
&lt;br /&gt;
* '''[[OWASP_Project_Inventory#Incubator_Projects|Incubator Projects:]]''' OWASP Incubator projects represent the experimental playground where projects are still being fleshed out, ideas are still being proven, and development is still underway.&lt;br /&gt;
&lt;br /&gt;
=== Social Media ===&lt;br /&gt;
&lt;br /&gt;
We recommend using the links below to find our official OWASP social media channels. These are a great way to keep in touch with the different initiatives going on at OWASP throughout the world. They are all updated regularly by chapter leaders, project leaders, the OWASP Board Members, and our OWASP Staff. If you have any questions or concerns about any of these accounts, please drop us a line using our [https://www.tfaforms.com/308703 &amp;quot;Contact Us&amp;quot;] form found above.  &lt;br /&gt;
&lt;br /&gt;
[[Image:Blogger-32x32.png|32px|link=http://owasp.blogspot.co.uk/]] [[Image:Twitter-32x32.png|32px|link=https://twitter.com/OWASP]] [[Image:Facebook-32x32.png|32px|link=https://www.facebook.com/groups/172892372831444/]] [[Image:Linkedin-32x32.png|32px|link=http://www.linkedin.com/groups/Global-OWASP-Foundation-36874]] [[Image:Google-32x32.png|32px|link=https://plus.google.com/u/0/communities/105181517914716500346?cfem=1]] [[Image:Ning-32x32.png|32px|link=http://myowasp.ning.com/]]&lt;br /&gt;
&amp;lt;!-- Twitter Box --&amp;gt; &lt;br /&gt;
&amp;lt;/font&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;border: 3px solid rgb(204, 204, 204); vertical-align: top; width: 95%; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; |  &lt;br /&gt;
&amp;lt;div style=&amp;quot;padding:2em;padding-bottom:0px;&amp;quot;&amp;gt;&amp;lt;!-- DON'T REMOVE ME, I'M STRUCTURAL; also 2 empty lines between images --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Image:New_initiatives.png|center|300px| link=http://owasp.force.com/volunteers/GW_Volunteers__VolunteersJobListing]] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:Donate_here_banner.png|center|300px| link=http://www.regonline.com/Register/Checkin.aspx?EventID=1044369]]&lt;br /&gt;
&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{|&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
| style=&amp;quot;width: 110px; font-size: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
|}&lt;br /&gt;
&amp;lt;!-- End Banner --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Project Inventory  =&lt;br /&gt;
&amp;lt;font size=2pt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
(The Projects pages are constantly being updated.  Some pages may contain outdated information.  You can help OWASP to keep these pages current by visiting [[:Category:FIXME|FixME]])  Please contact Claudia Aviles Casanovas with questions using the [https://www.tfaforms.com/308703 contact us form]&lt;br /&gt;
&lt;br /&gt;
==Quick Guide to Projects==&lt;br /&gt;
&lt;br /&gt;
===Quick Guide for Developers===&lt;br /&gt;
&lt;br /&gt;
This is a Quick Guide for Developers new to OWASP projects:&lt;br /&gt;
&lt;br /&gt;
Infographic containing Hyperlinks to projects:&lt;br /&gt;
https://magic.piktochart.com/output/6400107-untitled-infographic&lt;br /&gt;
&lt;br /&gt;
Downloadable Images:&lt;br /&gt;
[[File:Owasp_Dev_Guide.pdf ]]&lt;br /&gt;
&lt;br /&gt;
==Flagship Projects==&lt;br /&gt;
[[File:Flagship_banner.jpg]]&lt;br /&gt;
&lt;br /&gt;
The OWASP Flagship designation is given to projects that have demonstrated strategic value to OWASP and application security as a whole.&lt;br /&gt;
After a major review process [[LAB_Projects_Code_Analysis_Report|More info here]] the following projects are considered to be flagship candidate projects. These project have been evaluated more deeply to confirm their flagship status:&lt;br /&gt;
&lt;br /&gt;
====Tools [Health Check January 2017]====&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Zed_Attack_Proxy_Project|OWASP Zed Attack Proxy]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Web_Testing_Environment_Project|OWASP Web Testing Environment Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_OWTF|OWASP OWTF]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Dependency_Check|OWASP Dependency Check]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Security_Shepherd|OWASP Security Shepherd]][[File:Thumbsup.png|15px]]&lt;br /&gt;
&lt;br /&gt;
====Code [Health Check January 2017]====&lt;br /&gt;
* [[:Category:OWASP_ModSecurity_Core_Rule_Set_Project|OWASP ModSecurity Core Rule Set Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[:Category:OWASP_CSRFGuard_Project|OWASP CSRFGuard Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_AppSensor_Project|OWASP AppSensor Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
&lt;br /&gt;
====Documentation[Health Check January 2017] ====&lt;br /&gt;
* [[:Category:OWASP_Application_Security_Verification_Standard_Project|OWASP Application Security Verification Standard Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[:Category:Software_Assurance_Maturity_Model|OWASP Software Assurance Maturity Model (SAMM)]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_AppSensor_Project|OWASP AppSensor Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[:Category:OWASP_Top_Ten_Project|OWASP Top Ten Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Testing_Project|OWASP Testing Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
&lt;br /&gt;
==Labs Projects==&lt;br /&gt;
[[File:Lab banner.jpg]]&lt;br /&gt;
&lt;br /&gt;
OWASP Labs projects represent projects that have produced a deliverable of value. While these projects are typically not production ready, the OWASP community expects that an OWASP Labs project leader is producing releases that are at least ready for mainstream usage.&lt;br /&gt;
&lt;br /&gt;
===Thumbs up===&lt;br /&gt;
Thumbs up are given to LAB projects showing a steady progress in their development, had very active and continuous releases and commits, regular update of information on their wiki page and have quite complete documentation. These projects are almost ready to become flagship&lt;br /&gt;
&lt;br /&gt;
====Tools [Reviewed Janaury 2017]====&lt;br /&gt;
* [[O-Saft|O-Saft]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Dependency_Track_Project|OWASP Dependency Track Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[:Category:OWASP_EnDe|OWASP EnDe Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Hackademic_Challenges_Project|OWASP Hackademic Challenges Project]]*[[Review Needed]]&lt;br /&gt;
* [[OWASP_Mantra_-_Security_Framework|OWASP Mantra Security Framework]]*[[Review Needed]]&lt;br /&gt;
* [[OWASP_Mobile_Security_Project|OWASP Mobile Security Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_O2_Platform|OWASP O2 Platform]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Passfault|OWASP Passfault]] [[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[:Category:OWASP_Security_Ninjas_AppSec_Training_Program|OWASP Security Ninjas Appsec Training Program]]*[[Review Needed]]&lt;br /&gt;
* [[:Category:OWASP WebGoat Project|OWASP WebGoat Project]] [[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Xenotix_XSS_Exploit_Framework|OWASP Xenotix XSS Exploit Framework]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Code_Pulse_Project|OWASP Code Pulse Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Security_Knowledge_Framework#tab=Main | OWASP Security Knowledge Framework]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_SeraphimDroid_Project|OWASP SeraphimDroid Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_DefectDojo_Project|OWASP DefectDojo Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_Juice_Shop_Project|OWASP Juice Shop Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
&lt;br /&gt;
====Documentation [Health Check January 2017]====&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Application_Security_Guide_For_CISOs_Project|OWASP Application Security Guide For CISOs]]*[[Review Needed]]&lt;br /&gt;
* [[Cheat_Sheets|OWASP Cheat Sheets Project]] [[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_CISO_Survey|OWASP CISO Survey]] [[File:Thumbsup.png|15px]]*[[Review Needed]]&lt;br /&gt;
* [[:Category:OWASP_Code_Review_Project|OWASP Code Review Guide Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Codes_of_Conduct|OWASP Codes of Conduct]][[File:Thumbsup.png|15px]] *[[Review Needed]]&lt;br /&gt;
* [[OWASP_Cornucopia|OWASP Cornucopia]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[:Category:OWASP_Guide_Project|OWASP Guide Project]][[File:Thumbsup.png|15px]]*[[Review Needed]]&lt;br /&gt;
* [[OWASP_Podcast|OWASP Podcast Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Proactive_Controls|OWASP Proactive Controls]] [[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Internet_of_Things_Top_Ten_Project|OWASP Internet of Things Top Ten Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Top_10_Privacy_Risks_Project|OWASP Top 10 Privacy Risks Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Reverse_Engineering_and_Code_Modification_Prevention_Project|OWASP Reverse Engineering and Code Modification Prevention Project]]*[[Review Needed]]&lt;br /&gt;
* [[OWASP_Snakes_and_Ladders|OWASP Snakes and Ladders Project]] [[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP Automated Threats to Web Applications]] [[File:Thumbsup.png|15px]]&lt;br /&gt;
&lt;br /&gt;
====Contests - Health Check February 2016====&lt;br /&gt;
*[[OWASP_University_Challenge|OWASP University Challenge]] [[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[:Category:OWASP_CTF_Project|OWASP CTF Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
&lt;br /&gt;
====Code [Reviewed January 2017====&lt;br /&gt;
* [[:Category:OWASP_Enterprise_Security_API|OWASP Enterprise Security API]]*[[Review Needed]]&lt;br /&gt;
* [[OWASP_Python_Security_Project|OWASP Python Security Project]]*[[Review Needed]]&lt;br /&gt;
* [[OWASP_Security_Logging_Project|OWASP Security Logging Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
&lt;br /&gt;
==Incubator Projects==&lt;br /&gt;
[[File:Incubator_banner.jpg]]&lt;br /&gt;
&lt;br /&gt;
OWASP Incubator projects represent the experimental playground where projects are still being fleshed out, ideas are still being proven, and development is still underway.  The “OWASP Incubator” label allows OWASP consumers to readily identify a project’s maturity. The label also allows project leaders to leverage the OWASP name while their project is still maturing.&lt;br /&gt;
&lt;br /&gt;
===Thumbs up===&lt;br /&gt;
Thumbs up are given to incubator projects showing a steady progress in their development, had continuous releases and commits or have delivered a complete product, including open source repository location, basic user guidelines and documentation&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====Code [Reviewed January 2017]====&lt;br /&gt;
* [[OWASP_Java_Encoder_Project|OWASP Java Encoder Project]] [[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Java_HTML_Sanitizer|OWASP Java HTML Sanitizer Project]] [[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[Projects/OWASP_Node_js_Goat_Project|OWASP Node.js Goat Project]] [[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Mth3l3m3nt_Framework_Project|OWASP Mth3l3m3nt Framework Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[CSRFProtector_Project|OWASP CSRFProtector Project]][[needs review]]&lt;br /&gt;
* [[WebGoatPHP|OWASP WebGoat PHP Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Secure_Headers_Project|OWASP Secure Headers Project]]*[[Review Needed]]&lt;br /&gt;
* [[OWASP_Vicnum_Project | OWASP Vicnum Projct]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_DeepViolet_TLS/SSL_Scanner|OWASP DeepViolet TLS/SSL_Scanner]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Off_the_record_4_Java_Project|OWASP Off the record 4 Java Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Learning_Gateway_Project|OWASP Learning Gateway Project]] [[NEW!]]&lt;br /&gt;
&lt;br /&gt;
====Research====&lt;br /&gt;
&lt;br /&gt;
====Tools [Reviewed last: January 2017]====&lt;br /&gt;
* [[Benchmark|OWASP Benchmark]][[File:Thumbsup.png|15px]] &lt;br /&gt;
* [[OWASP_Wordpress_Vulnerability_Scanner_Project | OWASP Wordpress Vulnerability Scanner]]*[[Review Needed]]&lt;br /&gt;
* [[OWASP_Threat_Dragon | OWASP Threat Dragon]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Faux_Bank_Project|OWASP Faux Bank Project]]*[[Review Needed]]&lt;br /&gt;
* [[OWASP_Droid10_Project|OWASP Droid]][[File:Thumbsup.png|15px]]*[[Review Needed]]&lt;br /&gt;
*[[OWASP_WAP-Web_Application_Protection|WAP Web Application_Protection]]*[[Review Needed]]&lt;br /&gt;
*[[OWASP_Mutillidae_2_Project|OWASP Mutillidae 2 Project]]*[[Review Needed]]&lt;br /&gt;
*[[OWASP_WebSpa_Project|OWASP WebSpa Project]]*[[Review Needed]]&lt;br /&gt;
*[[OWASP_Pyttacker_Project|OWASP Pyttacker Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP Rainbow Maker Project | OWASP Rainbow Maker Project]] *[[Review Needed]]&lt;br /&gt;
* [[OWASP_ZSC_Tool_Project|OWASP ZSC Tool Project]] [[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_Web_Malware_Scanner_Project|OWASP_Web Malware Scanner Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_Basic_Expression_%26_Lexicon_Variation_Algorithms_(BELVA)_Project| OWASP Basic Expression Lexicon Variation Algorithms (Belva) Project]]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_VBScan_Project| OWASP VBScan]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_AppSec_Pipeline|OWASP Appsec Pipeline]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_Bug_Logging_Tool|OWASP Bug Logging Tool]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_iGoat_Tool_Project|OWASP iGoat Tool Project]]&lt;br /&gt;
*[[OWASP_Risk_Rating_Management|OWASP Risk Rating Management]]&lt;br /&gt;
*[[OWASP_DevSlop_Project|OWASP DevSlop Project]] [[New!]]&lt;br /&gt;
*[[OWASP_SecurityRAT_Project|OWASP SecurityRAT Project]] [[New!]]&lt;br /&gt;
*[[OWASP_Glue_Tool_Project|OWASP Glue Tool Project]] [[New]]&lt;br /&gt;
&lt;br /&gt;
====Documentation[Review: May 2015 - Health Check January 2017]====&lt;br /&gt;
*[[OWASP_Vulnerable_Web_Applications_Directory_Project|OWASP Vulnerable Web Applications Directory Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[:Category:OWASP_.NET_Project|OWASP .NET Project]]*[[Review Needed]]&lt;br /&gt;
*[[OWASP_WASC_Web_Hacking_Incidents_Database_Project|OWASP WASC Web Hacking Incidents Database Project]]*[[Review Needed]]&lt;br /&gt;
*[[OWASP_Incident_Response_Project|OWASP Incident Response Project]][[File:Thumbsup.png|15px]]*&lt;br /&gt;
*[[OWASP KALP Mobile Project | OWASP KALP Mobile Project]][[File:Thumbsup.png|15px]]*[[Review Needed]]&lt;br /&gt;
*[[OWASP_Application_Security_Program_Quick_Start_Guide_Project|OWSP_Application_Security_Program_Quick_Start_Guide_Project]]*[[Review Needed]]&lt;br /&gt;
*[[OWASP_Secure_Configuration_Guide|OWASP_Secure_Configuration_Guide]]*[[Review Needed]]&lt;br /&gt;
*[[OWASP_Knowledge_Based_Authentication_Performance_Metrics_Project|OWASP Knowledge Based Authentication Performance Metrics Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_RFP-Criteria|OWASP RFP Criteria]]*[[Review Needed]]&lt;br /&gt;
*[[OWASP_Web_Mapper_Project|OWASP Web Mapper Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_Top_10_fuer_Entwickler|OWASP 10 Fuer Entwickler]]*[[Review Needed]]&lt;br /&gt;
*[[WASC_OWASP_Web_Application_Firewall_Evaluation_Criteria_Project |WASC_OWASP_Web_Application_Firewall_Evaluation_Criteria_Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_Secure_Software_Development_Lifecycle_Project]]&lt;br /&gt;
*[[OWASP_Mobile_Security_Testing_Guide|OWASP Mobile Security Testing Guide]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_Anti-Ransomware_Guide_Project|OWASP Ransomeware Guide Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_Cyber_Defense_Matrix|OWASP Cyber Defense Matrix]]&lt;br /&gt;
*[[OWASP_Top_5_Machine_Learning_Risks|OWASP Top 5 Machine Learning Risks]] [[New]]&lt;br /&gt;
*[[OWASP_Security_Operations_Center_(SOC)_Framework_Project|OWASP Security Operations Center SOC Framework Project]][[New]]&lt;br /&gt;
&lt;br /&gt;
==Educational Initiatives==&lt;br /&gt;
====Health Check February 2017====&lt;br /&gt;
*[[OWASP_Student_Chapters_Program|OWASP Student Chapters Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[:Category:OWASP_Education_Project|OWASP Education Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[:Category:OWASP_Speakers_Project|OWASP Speakers Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_Media_Project|OWASP Media Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_PHP_Security_Training_Project|OWASP PHP Security Training Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_Online_Academy#tab=Main | OWASP Online Academy]][[File:Thumbsup.png|15px]]&lt;br /&gt;
&lt;br /&gt;
== Low Activity Projects ==&lt;br /&gt;
[[File:low_activity.jpg]]&lt;br /&gt;
======Low Activity (LABS)[Reviewed July 2015] Health Check February 2016======&lt;br /&gt;
&lt;br /&gt;
These projects had no releases in at least a year, however have shown to be valuable tools&lt;br /&gt;
'''Code [Low Activity]'''  Health Check February 2016&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Broken_Web_Applications_Project|OWASP Broken Web Applications Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
&lt;br /&gt;
'''Tools Health Check February 2016'''&lt;br /&gt;
*[[:Category:OWASP_WebScarab_Project|WebScarab]][[File:Thumbsup.png|15px]]&lt;br /&gt;
*[[OWASP_HTTP_Post_Tool|OWASP HTTP POST Tool]][[File:Thumbsup.png|15px]]&lt;br /&gt;
&lt;br /&gt;
'''Documentation [Low Activity]'''  '''Health Check February 2016'''&lt;br /&gt;
* [[OWASP_Appsec_Tutorial_Series|OWASP AppSec Tutorial Series]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[:Category:OWASP_Legal_Project|OWASP Legal Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[Virtual_Patching_Best_Practices|Virtual Patching Best Practices]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_Secure_Coding_Practices_-_Quick_Reference_Guide|OWASP Secure Coding Practices - Quick Reference Guide]][[File:Thumbsup.png|15px]]&lt;br /&gt;
&lt;br /&gt;
==Donated Projects==&lt;br /&gt;
&lt;br /&gt;
OWASP Donated Projects are inactive projects that have been donated to the OWASP Projects Infrastructure. &lt;br /&gt;
&lt;br /&gt;
====Tools====&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Excess_XSS_Project|OWASP Excess XSS Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
* [[OWASP_JOTP_Project|OWASP jOTP Project]][[File:Thumbsup.png|15px]]&lt;br /&gt;
&lt;br /&gt;
==OWASP Archived Projects==&lt;br /&gt;
OWASP Archived Projects are projects that have developed outside OWASP umbrella or have become inactive. If you are interested in pursuing any of the inactive projects (click hyperlink for list), please contact us and let us know of your interest.&lt;br /&gt;
&lt;br /&gt;
'''Added New Project on February 2016'''&lt;br /&gt;
&lt;br /&gt;
[[:Category:OWASP_Project_Archived_Projects]]&lt;br /&gt;
&lt;br /&gt;
= Former Project Task Force =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====OWASP Project Task Force====&lt;br /&gt;
(The Projects pages are constantly being updated.  Some pages may contain outdated information.  You can help OWASP to keep these pages current by visiting [[:Category:FIXME|FixME]])  Please contact Claudia Aviles Casanovas with questions using the [https://www.tfaforms.com/308703 contact us form]&lt;br /&gt;
&lt;br /&gt;
{{:Task_Force/OWASP_Projects}}&lt;br /&gt;
&lt;br /&gt;
= Online Resources =&lt;br /&gt;
&lt;br /&gt;
===Project Online Resources===&lt;br /&gt;
&lt;br /&gt;
* [https://docs.google.com/a/owasp.org/spreadsheets/d/13QM6yCqpirNuURbBdB5YZ_30mfQGbLjzBTGx0CTSNWw/edit?usp=sharing|OWASP Open Source Project Resources &amp;amp; Services]&lt;br /&gt;
&lt;br /&gt;
Please note that some services are 100% free and some have nominal cost.&lt;br /&gt;
&lt;br /&gt;
{{:Project_Online_Resources}}&lt;br /&gt;
&lt;br /&gt;
= Starting a New Project  =&lt;br /&gt;
&amp;lt;font size=2pt&amp;gt;&lt;br /&gt;
== So you want to start a project... ==&lt;br /&gt;
&lt;br /&gt;
Starting an OWASP project is quite easy, and your desire to contribute and make it happen is essential.&lt;br /&gt;
[[File:HowToStartProjectoWasp.png | 600px | right]]&lt;br /&gt;
&lt;br /&gt;
Here are some of the guidelines for running a successful OWASP project:&lt;br /&gt;
&lt;br /&gt;
-Start exploring the actual OWASP projects Inventory. Many projects handle specific areas of security it is a good idea to start looking how other successful projects do this (LABS/Flagship)&lt;br /&gt;
&lt;br /&gt;
-Place your idea or project on the [[Project_Ideas_Board#From_Idea_to_Project_Incubator|Project Ideas Board]]. This phase will help you to define the project goals and also explore and exchange with other OWASP leaders and volunteers how to develop the idea into a tangible project&lt;br /&gt;
&lt;br /&gt;
-Explore and research if your idea covers a unique segment in the Security arena. Think of your project as a product, if you really want people using it, think how this project will cover a necessity in the security area you are working on &lt;br /&gt;
&lt;br /&gt;
-Define what kind of project you would like to start. Is it a code, tool or documentation?&lt;br /&gt;
&lt;br /&gt;
-Communicate through the Project leader mailing list about your idea and get feedback and  meet potential contributors&lt;br /&gt;
&lt;br /&gt;
-Develop your project based on the type of project. For example if you are willing to start a documentation project, begin by defining a Table of Content and work it through with potential contributors. First of all begin by creating a Road-map for your project. This is essential to submit your project. We highly recommend to read  documentation such as &amp;quot;[http://www2.econ.iastate.edu/tesfatsi/ProducingOSS.KarlFogel2005.pdf How to start /run a successful Open Source Projects]&amp;quot;. &lt;br /&gt;
&lt;br /&gt;
[[File:RoadmapIncubatorProjectExample2.PNG | 500px | left]]&lt;br /&gt;
&lt;br /&gt;
Some recommendations on how to start a documentation project&lt;br /&gt;
[[:File:Document_Guide_(1).png| Document Guide Project]]&lt;br /&gt;
&lt;br /&gt;
===Importance of a well thought out Road-map===&lt;br /&gt;
Many Incubator project leaders struggle with creating a realistic planning, which should be based on their available resources and time. A well thought out plan makes a difference between a procrastinating project and a successful one. The important aspect of this is, that the project leader is able to create a plan based on his situation. The following is an example of a Roadmap, which has focused to produce a Documentation first release in a year and a basic outline how they plan to cover 4 essential aspects which are Research &amp;amp; Development, Marketing, Planning and Goals.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Your [project] roadmap should tell a coherent story about the likely growth of your product. Each release should build on the previous one and move you closer towards your vision. Your roadmap should be convincing and realistic: Don’t speculate or oversell your [project]. Be clear who your audience is: An internal roadmap talks to development, marketing, sales, service, and the other groups involved in making your [project] a success; and external one talks to existing and prospective customers.&amp;quot;&lt;br /&gt;
Extracted from : &amp;quot;[[http://www.romanpichler.com/blog/10-tips-creating-agile-product-roadmap/ 10 Tips for Creating an Agile Product Roadmap]]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
* Start defining a development, documentation and marketing plan for your project. Set short , medium and long term plans. Include promotion of your project, this is very important in order to engage users and consumers of your project. Contact project coordinator and the Project Task Force to help you achieve this goal. You ''can'' run a single person project, but it's usually best to get the community involved.  You should be prepared to support a mailing list, build a team, speak at conferences, and promote your project.&lt;br /&gt;
&lt;br /&gt;
* You can contribute existing documents or tools to OWASP! Assuming you have the intellectual property rights to a work, you can open it to the world as an OWASP Project.  Please coordinate this with OWASP by contacting owasp(at)owasp.org.&lt;br /&gt;
&lt;br /&gt;
* Available Grants to consider if you need funding - [[Grants|Click Here]]&lt;br /&gt;
&lt;br /&gt;
* You should promote your project through the OWASP channels as well as by outside means.  Get people to blog about it!&lt;br /&gt;
&lt;br /&gt;
== '''Creating a New Project''' ==&lt;br /&gt;
Once you have passed the Project Ideas phase, then you will be ready to start a new project&lt;br /&gt;
&lt;br /&gt;
'''[https://www.tfaforms.com/263506 Please submit a new project application here].''''''&lt;br /&gt;
&lt;br /&gt;
'''2016 OWASP Project Process'''&lt;br /&gt;
&lt;br /&gt;
'''Existing WORKFLOW''' [https://docs.google.com/viewer?a=v&amp;amp;pid=forums&amp;amp;srcid=MDM4NTc0NDY0NjkwMzEwMTMzMzkBMDIxODM3MDc5ODA4OTMxNjAzNjkBSFlWTDZaTE5Ed0FKATAuMQFvd2FzcC5vcmcBdjI Incubator Project Flow]&lt;br /&gt;
&lt;br /&gt;
'''Step 1:''' &lt;br /&gt;
New Project Leader submits New Project Request Form it is logged in the system and an alert is sent  to the Project Coordinator &lt;br /&gt;
&lt;br /&gt;
'''Step 2:'''&lt;br /&gt;
New Project Request is received and reviewed by Project Coordinator for complete information .It must contain the following information to qualify as an acceptable submission:&lt;br /&gt;
You will need to gather the following information together for your application:&lt;br /&gt;
&lt;br /&gt;
*Project Name,&lt;br /&gt;
*Project purpose / overview,&lt;br /&gt;
*Project Roadmap,&lt;br /&gt;
*Project links (if any) to external sites,&lt;br /&gt;
*[[Guidelines_for_OWASP_Projects#Project_Licensing|Project License],]&lt;br /&gt;
*Project Leader name,&lt;br /&gt;
*Project Leader email address,&lt;br /&gt;
*Project Leader wiki account - the username (you'll need this to edit the wiki),&lt;br /&gt;
*Project Contributor(s) (if any) - name email and wiki account (if any),&lt;br /&gt;
*Project Main Links (if any).&lt;br /&gt;
*==&amp;gt;For Documentation: A table of Contents&lt;br /&gt;
*==&amp;gt;For Code: A prototype hosted in an open source repository of your choice. &lt;br /&gt;
&lt;br /&gt;
'''Step 3:''' &lt;br /&gt;
If all information is completed following the minimum criteria for Projects (Code/Tool/documentation), The Project Coordinator notifies the Project Leader that the request has been accepted, and at the same time notifies the Review team that a new project has been submitted, including all the information requested in the project criteria &lt;br /&gt;
&lt;br /&gt;
'''Step 4:''' &lt;br /&gt;
Project Coordinator proceeds to create a new Wiki page for the project including all the information sent by the project leader. project coordinator uses one of these project wiki template:&lt;br /&gt;
*For Docs: https://www.owasp.org/index.php/OWASP_Documentation_Project_Template&lt;br /&gt;
*For Code: https://www.owasp.org/index.php/OWASP_Code_Project_Template&lt;br /&gt;
*For Tool:  https://www.owasp.org/index.php/OWASP_Tool_Project_Template&lt;br /&gt;
Also Project coordinator creates a mailing list for the project leader and sets him as admin&lt;br /&gt;
&lt;br /&gt;
'''Step 5:''' &lt;br /&gt;
Project Coordinator notifies project leader and Review team about the created wiki page, providing the link to the wiki page.&lt;br /&gt;
*Review team might provide comments for further improvement of the wiki page if necessary&lt;br /&gt;
*Project leader should request a wiki account to be able to update his own wiki page afterwards if he has not one yet&lt;br /&gt;
&lt;br /&gt;
'''Step 6:''' &lt;br /&gt;
Project coordinator updates the Wiki project inventory, Dashboard and open hub with the information regarding the new created project&lt;br /&gt;
&lt;br /&gt;
'''Step 7:''' &lt;br /&gt;
Project is set in the agenda by the Project Coordinator for monitoring over the next 3 months to check how has been developing.&lt;br /&gt;
&lt;br /&gt;
'''Step 8:'''&lt;br /&gt;
Every 3 months, project coordinator monitors the activity on the wiki page for new updates and on the Openhub for commits and level of activity . Findings are then reported on the Dashboard as comments and CC through email to the review team&lt;br /&gt;
&lt;br /&gt;
'''Step 9:''' &lt;br /&gt;
if the project has not been updated and has no activities after six months of creation, project coordinator sends an email to the project leader requesting an update and status to see how has been developing, CC: project review team regarding the lack of activity .Findings are then updated on the dashboard. &lt;br /&gt;
&lt;br /&gt;
'''Step 10:'''&lt;br /&gt;
Over the next 6 months the project is monitored again for activity. If no updates have occurred since its inception after 12 months, project is then set as inactive and project leader and review team is notified about the status.&lt;br /&gt;
Project coordinators updates :&lt;br /&gt;
* Wiki page of the project is labeled as 'inactive' (inactive banner)&lt;br /&gt;
*The Project is set under the 'inactive category'&lt;br /&gt;
*Dashboard is updated with comments and set as inactive&lt;br /&gt;
&lt;br /&gt;
&amp;lt;hr&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Reference Material'''&lt;br /&gt;
&lt;br /&gt;
[https://www.openhub.net/orgs/OWASP Openhub]&lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/spreadsheets/d/1lO8UoQgIFET3MC5v2OVVdtkTe1IbWiJLMnINx6Hm2jE/edit?ts=56a159b7#gid=0 Dashboard]&lt;br /&gt;
&lt;br /&gt;
[[Project_Reviews_Guideline|Project Review Guidelines]]&lt;br /&gt;
&lt;br /&gt;
[http://owasp.github.io/ProjectReviews/index.html GITHUB OWASP] &lt;br /&gt;
&lt;br /&gt;
[https://docs.google.com/presentation/d/1tGdmgzDGjoHVtHZbV9dqGR2XQVlT8TR1cet-4r0C8RY/edit?ts=56a16be2#slide=id.gee0716e2f_0_1 Projects Slides]&lt;br /&gt;
&lt;br /&gt;
* Check out the '''[[Guidelines for OWASP Projects]]'''.&lt;br /&gt;
* [[Grant_Spending_Policy|Grant Spending Policy]]&lt;br /&gt;
* [[Project_Spending_Policy|Project Spending Policy]]&lt;br /&gt;
* [[Project_Sponsorship_Operational_Guidelines|Project Sponsorship Operational Guidelines]]&lt;br /&gt;
&lt;br /&gt;
==OWASP	Recommended Licenses==&lt;br /&gt;
&lt;br /&gt;
{{Recommended_Licenses}}&lt;br /&gt;
&lt;br /&gt;
==Funding your Project==&lt;br /&gt;
An OWASP project does not receive any funding for development at project inception; however, a new project does have the opportunity to submit a request to receive funds if they are available for the year. Additionally, project leaders have the option of seeking sponsorship from outside organizations, but project leaders are required to seek funding through their own initiative. Please contact the OWASP Projects Manager for more information. &lt;br /&gt;
&lt;br /&gt;
== Project Release ==&lt;br /&gt;
&lt;br /&gt;
As your project reaches a point that you'd like OWASP to assist in its promotion, the will need the following information to help spread the word about your project:&lt;br /&gt;
&lt;br /&gt;
# Short 5 sentence paragraph outlining what your project is about, what you hope to accomplish with your project, what value your project brings to software security, and contributor and project leader names and contact information.&lt;br /&gt;
# Link to your wiki page.&lt;br /&gt;
# Link to your code repository or a link to where readers can download your project.&lt;br /&gt;
# Latest Release description answering the following questions: What is it?, What does it do?, Where can I get it?, Who should I contact if something goes wrong?.&lt;br /&gt;
&lt;br /&gt;
==Project Process Forms==&lt;br /&gt;
These forms were created to help project leaders, and those interested in a going through a process in the OWASP projects infrastructure. They facilitate the management of each query based on the specific task an applicant will need help with. The forms are described below, and they are linked with their designated online application form. &lt;br /&gt;
&lt;br /&gt;
* [https://www.tfaforms.com/264422 Project Transition Application]:The OWASP project transition form gives current project leaders an easy way of handing over project administration information to individuals wishing to take over a project.  &lt;br /&gt;
&lt;br /&gt;
* [https://www.tfaforms.com/264413 Project Review Application]:This form is for current project leaders to request a review of their project based on OWASP graduation criteria. The aim is to designate an OWASP volunteer to review these projects within 3 months time. &lt;br /&gt;
&lt;br /&gt;
* [http://www.tfaforms.com/264418 Project Donation Application]:This form is for projects outside of the OWASP project infrastructure. Project Leaders for these open source projects can choose to partner or give their project to OWASP directly through this form.&lt;br /&gt;
&lt;br /&gt;
* [https://www.tfaforms.com/264428 Project Adoption Request]:This form is used when someone is interested in adopting an archived project. &lt;br /&gt;
&lt;br /&gt;
* [https://www.tfaforms.com/264426 Project Abandonment Request]:The OWASP project abandonment form gives current project leaders an easy way of letting the OWASP Foundation know that they wish to resign their project leader duties. This form should be used when no replacement project leader exists to take over these duties.&lt;br /&gt;
&lt;br /&gt;
* [https://www.tfaforms.com/264392 Incubator Project Graduation Application]:This application form is for Incubator Projects to apply for Labs Project status.&lt;br /&gt;
&lt;br /&gt;
= Participating in a Project =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;font size=2pt&amp;gt;&lt;br /&gt;
== Joining a Project... ==&lt;br /&gt;
&lt;br /&gt;
OWASP projects are community driven and most projects are open for anyone motivated to join. &lt;br /&gt;
&lt;br /&gt;
The first step is to find a project you are interested to be part of. The list of all projects can be found in the {{#switchtablink:Project_Inventory|Project Inventory}}. Further steps then depend on the status of the project you selected.&lt;br /&gt;
&lt;br /&gt;
If the project is active, the best way is to join the mailing list and get in touch with the people actively participating. Other ways would be contacting the project leader team or just starting to participate by testing the software, writing blogs or documentation, report issues via tracker or even propose code modifications. In general, the more you show your interest and motivation, the easier it is to find yourself as a member of the team.&lt;br /&gt;
&lt;br /&gt;
Some projects are of low activity or even inactive. In this case there is no possibility to join an existing team, but it would rather be a re-boot. If you feel eager to do this, please contact the general OWASP administrators. It is however important that you are sure about the commitment you are about to make. &lt;br /&gt;
&lt;br /&gt;
Some things are important: &lt;br /&gt;
&lt;br /&gt;
- Don’t be shy. If you wish to be part of the OWASP initiative, you will find a task that suits your experience and your level of possible time investment. &lt;br /&gt;
&lt;br /&gt;
- Baby steps are easier than huge commitments. Just start helping with small tasks and get known by the project team. You will grow into the project in a natural way.&lt;br /&gt;
&lt;br /&gt;
Please read more about the general project workflow on the {{#switchtablink:Starting_a_New_Project|Starting a New Project}} page.&lt;br /&gt;
&lt;br /&gt;
== Archives ==&lt;br /&gt;
&lt;br /&gt;
[[Projects_Reboot_2012_Homepage|Archive of the 'Project Reboot 2012' page]]&lt;br /&gt;
&lt;br /&gt;
= Project Assessments  =&lt;br /&gt;
&amp;lt;font size=2pt&amp;gt;&lt;br /&gt;
==OWASP Project Lifecycle==&lt;br /&gt;
The OWASP Projects Lifecycle represents a balance between keeping a very loose structure around OWASP projects, and ensuring that OWASP consumers are not confused about a project’s maturity and quality. The lifecycle stage allows consumers to easily identify mature projects, and projects that are proofs of concept, experimental, and classified as prototypes in their current state. The greater the maturity of the project, the greater the level of responsibility for the project leader. These responsibilities are not trivial as OWASP provides incentives and benefits (Section 7) for projects who take on these added responsibilities.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
====The OWASP Project Lifecycle is broken down into the following stages:====&lt;br /&gt;
&lt;br /&gt;
'''Incubator Projects''': OWASP Incubator projects represent the experimental playground where projects are still being designed, ideas are still being proven, and development is still underway.  The “OWASP Incubator” label allows OWASP consumers to readily identify a project’s maturity; moreover, the label allows project leaders to leverage the OWASP name while their project is still maturing. OWASP Incubator projects are given a place on the OWASP Projects Portal to leverage the organizations' infrastructure, and establish their presence and project history.&lt;br /&gt;
&lt;br /&gt;
'''Lab Projects''': OWASP Labs projects represent projects that have produced a deliverable of significant value. Leaders of OWASP Labs projects are expected to stand behind the quality of their projects as these projects have matured to the point where they are accepted by a significant portion of the OWASP community. While these projects are typically not production ready, the OWASP community expects that an OWASP Labs project leader is producing releases that are ready for mainstream usage. OWASP Labs Projects are meant to be the collection of established projects that have gained community support and acclaim by undergoing the project review process. &lt;br /&gt;
&lt;br /&gt;
'''Flagship Projects''': The OWASP Flagship designation is given to projects that have demonstrated superior maturity, established quality, and strategic value to OWASP and application security as a whole. Eligible projects are selected from the OWASP Labs project pool. This selection process generally ensures that there is only one project of each type covering any particular security space. OWASP Flagship projects represent projects that are not only mature, but are also projects that OWASP as an organization provides direct support to maintaining. The core mission of OWASP is to make application security visible and so as an organization, OWASP has a vested interest in the success of its Flagship projects. Since Flagship projects have such high visibility, these projects are expected to uphold the most stringent requirements of all OWASP Projects.&lt;br /&gt;
&lt;br /&gt;
'''Code Projects''': OWASP code projects are very important for the cyber security solutions. Because these projects are used to find out the application security problems and try to solve those problems.&lt;br /&gt;
&lt;br /&gt;
== OWASP Project Stage Benefits==&lt;br /&gt;
This section outlines the benefits of starting an OWASP project, and the benefits of being at each different stage in the projects lifecycle. In my short time here at OWASP as the PM, I have had several potential project leaders ask me what the benefits are of starting their project with OWASP. Below is my proposal for each Stage’s benefits.&lt;br /&gt;
&lt;br /&gt;
'''Incubator'''&lt;br /&gt;
* Financial Donation Management Assistance &lt;br /&gt;
* Project Review Support&lt;br /&gt;
* WASPY Awards Nominations&lt;br /&gt;
* OWASP OSS and OPT Participation&lt;br /&gt;
* Opportunity to submit proposal: $500 for Development.&lt;br /&gt;
* Community Engagement and Support&lt;br /&gt;
* Recognition and visibility of being associated with the OWASP Brand.&lt;br /&gt;
&lt;br /&gt;
'''Labs'''&lt;br /&gt;
* All benefits given to Incubator Projects &lt;br /&gt;
* Technical Writing Support&lt;br /&gt;
* Graphic Design Support&lt;br /&gt;
* Project Promotion Support&lt;br /&gt;
* OWASP OSS and OPT: Preference&lt;br /&gt;
&lt;br /&gt;
'''Flagship'''&lt;br /&gt;
* All benefits given to Incubator &amp;amp; Labs Projects&lt;br /&gt;
* Grant finding and proposal writing help&lt;br /&gt;
* Yearly marketing plan development&lt;br /&gt;
* OWASP OSS and OPT participation preference&lt;br /&gt;
&lt;br /&gt;
For more detailed information on OWASP Project Stage Benefits, please see the Project Handbook.&lt;br /&gt;
&lt;br /&gt;
== Project Monitoring Incubator/Documentation ==&lt;br /&gt;
Every 6 months, a project monitoring assessment takes place to evaluate if projects had any releases during this period.A warning will be sent to projects without any activity in 90 days and after 180 days, the project will be set automatically as inactive.&lt;br /&gt;
You can set your project active at any time, as long as:&lt;br /&gt;
* There has been commits to the project's open repository or&lt;br /&gt;
* There has been a beta release of the documentation produced so far or&lt;br /&gt;
* Provide a detailed Roadmap &lt;br /&gt;
&lt;br /&gt;
===Importance of a well thought out Roadmap===&lt;br /&gt;
Many Incubator project leaders struggle with creating a realistic planning, which should be based on their available resources and time. A well thought out plan makes a difference between a procrastinating project and a successful one. The important aspect of this is, that the project leader is able to create a plan based on his situation. The following is an example of a Roadmap, which has focused to produce a Documentation first release in a year and a basic outline how they plan to cover 4 essential aspects which are Research &amp;amp; Development, Marketing, Planning and Goals.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:RoadmapIncubatorProjectExample2.PNG | 600px]]&lt;br /&gt;
&lt;br /&gt;
&amp;quot;Your [project] roadmap should tell a coherent story about the likely growth of your product. Each release should build on the previous one and move you closer towards your vision. Your roadmap should be convincing and realistic: Don’t speculate or oversell your [project]. Be clear who your audience is: An internal roadmap talks to development, marketing, sales, service, and the other groups involved in making your [project] a success; and external one talks to existing and prospective customers.&amp;quot;&lt;br /&gt;
Extracted from : &amp;quot;[[http://www.romanpichler.com/blog/10-tips-creating-agile-product-roadmap/ 10 Tips for Creating an Agile Product Roadmap]]&amp;quot;&lt;br /&gt;
&lt;br /&gt;
==Project Monitoring for LABS/Flagship==&lt;br /&gt;
These project represent the best OWASP has to offer, therefore monitoring of these projects is closely supervised.&lt;br /&gt;
===For Code and Tools===&lt;br /&gt;
For projects holding Flagship status, we closely monitor their health every 6 months on the following, among other key indicators:&lt;br /&gt;
*Can the project be built correctly?&lt;br /&gt;
*Does the project has any activity(commits) in the last 6 months?&lt;br /&gt;
*Does the project had any releases in the last 6 months?&lt;br /&gt;
*Has the project leaders updated his wiki or website to reflect latest releases?&lt;br /&gt;
===For Documentation===&lt;br /&gt;
For this part, we are working on the development of an adequate assessment criteria&lt;br /&gt;
The following is a draft of the new process proposal: [[:File:Qualitative_and_Quantitative_Content_Audit.pdf|Proposal for Reviewing OWASP Document projects]]&lt;br /&gt;
&lt;br /&gt;
== OWASP Project Graduation==&lt;br /&gt;
The Project Graduation Process is an optional process undertaken at the request of a project leader using the Incubator Graduation Form. The purpose of this process is to move a project from the OWASP Incubator into the OWASP Labs. In order to be considered for OWASP Labs, an Incubator project must have submitted an OWASP reviewed deliverable, and obtained at least two (2) positive responses for each of the core criteria project health questions.&lt;br /&gt;
&lt;br /&gt;
The review centers around the following core questions. Each core question has three (3) specific questions made up of binary queries. A project must receive at least two (2) positive responses from each reviewer in two of the binary questions, to warrant a postive response for the core question. Each core question must receive a positive response from both project reviewers to pass the Project Health Assessment for Incubator Projects. &lt;br /&gt;
&lt;br /&gt;
* [https://docs.google.com/spreadsheet/ccc?key=0AllOCxlYdf1AdG5NZGhzTjZpT1RDcnRibjd0aXhfOUE Project Graduation Criteria Checklist]&lt;br /&gt;
&lt;br /&gt;
==OWASP Project Health Assessment==&lt;br /&gt;
The Project Health Assessment is an optional process undertaken at the request of a project leader when he/she applies for Project Graduation for projects going from Incubator to LAB and from LAB to Flagship. The purpose of this assessment is to determine whether a project meets the minimum criteria of an OWASP Project outlined in the [https://docs.google.com/spreadsheet/ccc?key=0AllOCxlYdf1AdG5NZGhzTjZpT1RDcnRibjd0aXhfOUE Project Health Assessment Criteria Document]. If a project passes the assessment, it then becomes eligible to graduate into the OWASP Labs Project stage. In order to be considered for OWASP Labs, an Incubator project must have submitted an OWASP reviewed deliverable, and obtained at least two (2) positive responses for each of the core criteria project health questions.&lt;br /&gt;
&lt;br /&gt;
==OWASP Project Deliverable/Release Assessment==&lt;br /&gt;
The Project Deliverable/Release Review is an optional process undertaken at the request of a project leader using the Project Deliverable Review Form. The purpose of this process is to  review a project’s progress, and to make sure the project is heading in the right direction based on the roadmap they provided at project inception. &lt;br /&gt;
&lt;br /&gt;
Reviews must be performed by two (2) OWASP Chapter or Project Leaders, and their review must answer affirmatively to at least the first two (2) core Project Deliverable/Release Review questions. A project must pass the OWASP Project Deliverable/Release Assessment in order to graduate into the OWASP Labs Project stage. &lt;br /&gt;
&lt;br /&gt;
* [https://docs.google.com/spreadsheet/ccc?key=0AllOCxlYdf1AdG5NZGhzTjZpT1RDcnRibjd0aXhfOUE Project Deliverable/Release Assessment Criteria Checklist]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Brand Resources  =&lt;br /&gt;
&amp;lt;font size=2pt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==The Brand Usage Rules==&lt;br /&gt;
See OWASP's [[Marketing/Resources#tab=BRAND_GUIDELINES|The Brand Usage Rules]] for details.&lt;br /&gt;
&lt;br /&gt;
==Project Icons &amp;amp; Templates==&lt;br /&gt;
See OWASP'S [[Marketing/Resources#PROJECT_RESOURCES|Project Icons &amp;amp; Templates]] for details.&lt;br /&gt;
&lt;br /&gt;
(Following links and images are provided for a quick overview only, the primary page is [[Marketing/Resources#PROJECT_RESOURCES|Project Icons &amp;amp; Templates]]).&lt;br /&gt;
&lt;br /&gt;
If you require more assistance with these files and/or templates, please contact the OWASP staff for assistance &lt;br /&gt;
&lt;br /&gt;
'''[[OWASP_Operations_Project_Template|OWASP Operational Wiki Template]]'''&lt;br /&gt;
&lt;br /&gt;
'''[[OWASP_Documentation_Project_Template|OWASP Example Template: DO NOT EDIT]]'''&lt;br /&gt;
&lt;br /&gt;
[[Image:OWASP_Project_Header.jpg|Owasp logo|500px]]&lt;br /&gt;
&lt;br /&gt;
[[Image:Project_Type_Files_TOOL.jpg|Owasp logo|200px]] [[Image:Project_Type_Files_DOC.jpg||Owasp logo 1c|200px]]  &lt;br /&gt;
&lt;br /&gt;
[[Image:Project_Type_Files_CODE.jpg|Owasp logo|200px]] [[Image:Owasp-defenders-small.png|Owasp logo|100px]] [[Image:Owasp-builders-small.png|Owasp logo|100px]] [[Image:Owasp-breakers-small.png|Owasp logo|100px]] &lt;br /&gt;
&lt;br /&gt;
[[Image:Owasp-incubator-trans-200.png|Owasp logo rev icon|100px]] [[Image:Owasp-labs-trans-85.png|Owasp logo flat|100px]] [[Image:Owasp-flagship-trans-85.png|Owasp logo icon|100px]]&lt;br /&gt;
&lt;br /&gt;
===OpenSAMM===&lt;br /&gt;
'''[[Media:OpenSAMM_icons.zip|OpenSAMM Icons]]'''&lt;br /&gt;
&lt;br /&gt;
'''Construction:'''&lt;br /&gt;
&lt;br /&gt;
[[Image:Construction black.png| Construction black| 100px]]  [[Image:Construction blue.png| Construction blue| 100px]]  [[image:Construction olive.png |construction olive|100px]]&lt;br /&gt;
&lt;br /&gt;
'''Deployment:'''&lt;br /&gt;
&lt;br /&gt;
[[image:Deployment black.png| Deployment black| 100px]]  [[image:Deployment blue.png| Deployment blue| 100px]]  [[image:Deployment olive.png | Deployment olive| 100px]]&lt;br /&gt;
&lt;br /&gt;
'''Governance:'''&lt;br /&gt;
&lt;br /&gt;
[[image:Governance black.png| governance black| 100px]]  [[image:Governance blue.png | governance blue | 100px]]  [[image:Governance olive.png | governance olive| 100px]]&lt;br /&gt;
&lt;br /&gt;
'''Verification:'''&lt;br /&gt;
&lt;br /&gt;
[[image:Verification black.png | Verification black | 100px]]  [[image:Verification blue.png | verification blue | 100px]]  [[image: Verification olive.png | Verification olive | 100px]]&lt;br /&gt;
&lt;br /&gt;
==Book Cover Files==&lt;br /&gt;
See OWASP's [[Marketing/Resources#PROJECT_RESOURCES|Project Icons &amp;amp; Templates]] for details.&lt;br /&gt;
&lt;br /&gt;
[[Media:Lulu-guide.pdf|Lulu Guide]]&lt;br /&gt;
&lt;br /&gt;
'''[https://www.dropbox.com/s/h27gsbe5m7idg0y/Finished%20Covers.zip Download the Book Cover Zip File]'''&lt;br /&gt;
{|&lt;br /&gt;
|-&lt;br /&gt;
! width=&amp;quot;500&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt; &lt;br /&gt;
! width=&amp;quot;300&amp;quot; align=&amp;quot;center&amp;quot; | &amp;lt;br&amp;gt;&lt;br /&gt;
|-&lt;br /&gt;
| align=&amp;quot;center&amp;quot; | [[Image:BookImage_01.jpg‎|500px| link=https://www.dropbox.com/s/h27gsbe5m7idg0y/Finished%20Covers.zip]] &lt;br /&gt;
| align=&amp;quot;center&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Terminology =&lt;br /&gt;
&amp;lt;font size=2pt&amp;gt;&lt;br /&gt;
== OWASP Project Infrastructure ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''OWASP Project Lifecycle:''' The OWASP Projects Lifecycle represents a balance between keeping a very loose structure around OWASP projects, and ensuring that OWASP consumers are not confused about a project’s maturity and quality. The lifecycle stage allows consumers to easily identify mature projects, and projects that are proofs of concept, experimental, and classified as prototypes in their current state.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Incubator Project:''' OWASP Incubator projects represent the experimental playground where projects are still being fleshed out, ideas are still being proven, and development is still underway. The “OWASP Incubator” label allows OWASP consumers to readily identify a project’s maturity. The label also allows project leaders to leverage the OWASP name while their project is still maturing.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Labs Project:''' OWASP Labs projects represent projects that have produced a deliverable of value. While these projects are typically not production ready, the OWASP community expects that an OWASP Labs project leader is producing releases that are at least ready for mainstream usage.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Flagship Project:''' The OWASP Flagship designation is given to projects that have demonstrated strategic value to OWASP and application security as a whole. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Project Benefits:''' The standard list of resources and incentives made available to project leaders based on their project's current maturity level. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Project Reviews ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Project Reviews:''' Project reviews are the method OWASP uses to establish a minimal baseline of project characteristics and release quality. Reviews are not mandatory, but they are necessary if a project leader wishes to graduate to the next level of maturity within the OWASP Global Projects infrastructure. Projects can be reviewed when an Incubator project wishes to graduate into the OWASP Labs designation, and project releases can be reviewed if they want the quality of their deliverable to be vouched for by OWASP. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Project Reviewer Pool:''' The project reviewer pool is made up of veteran reviewers who have proven themselves dedicated to executing quality reviews of projects. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Project Graduation:''' The Project Graduation Process is an optional process undertaken at the request of a project leader using the Incubator Graduation Form. The purpose of this process is to move a project from the OWASP Incubator into the OWASP Labs.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Project Health Assessment:''' The Project Health Assessment is an optional process undertaken at the request of a project leader when he/she applies for Project Graduation The purpose of this assessment is to determine whether a project meets the minimum criteria of an OWASP Project outlined in the [https://docs.google.com/a/owasp.org/spreadsheet/ccc?key=0AllOCxlYdf1AdG5NZGhzTjZpT1RDcnRibjd0aXhfOUE#gid=1 Project Health Assessment Criteria Document].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Project Release:''' A project release refers to the final deliverable a project produces. It is the final product of the project. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Project Deliverable/Release Review:''' The Project Deliverable/Release Review is an optional process undertaken at the request of a project leader using the Project Deliverable Review Form. The purpose of this process is to review a project’s progress, and to make sure the project is heading in the right direction based on the roadmap they provided at project inception.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects Processes == &lt;br /&gt;
&lt;br /&gt;
*'''Project Processes:''' The set of streamlined processes that exist to help projects move smoothly through the OWASP Project Lifecycle.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Project Inception Process:''' The Project Inception Process is how a brand new idea becomes an OWASP Project. Such projects are labeled as OWASP Incubator projects. The process involves submitting the proposed project name, project leader information, project description, project roadmap, and selecting an appropriate open-source license for the project using the New Project Form on the Projects Portal.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Project Donation Process:''' The Project Donation Process is used for a project that has an existing functional release, but is not currently associated with OWASP. This process is the primary mechanism by which individuals or organizations can transfer the ownership of their project’s copyright to OWASP.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Project Transition Process:''' The Project Transition Process is used to transition leadership of a project to a new project leader. This is a simple automated process to transfer the relevant accounts, mailing lists, and other project resources to the new project leader.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Project Abandonment Process:''' The Project Abandonment Process was put in place for those occasions in which a project leader is no longer able to manage their project, and has not been able to find a suitable replacement for the leader role. Project Abandonment can also occur when the project leader feels his/her project has become obsolete. Under these circumstances, the acting project leader is encourage do submit the Project Abandonment Form found in the Projects Portal.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Incubator Graduation Process:''' The Incubator Graduation Process is an optional process undertaken at the request of a project leader using the Incubator Graduation Form. The purpose of this process is to move a project from the OWASP Incubator into the OWASP Labs.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Projects at Conferences == &lt;br /&gt;
&lt;br /&gt;
*'''AppSec Conferences:''' OWASP AppSec conferences bring together industry, government, security researchers, and practitioners to discuss the state of the art in application security. This series was launched in the United States in 2004 and Europe in 2005. Global AppSec conferences are held annually in North America, Latin America, Europe, and Asia Pacific.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''Open Source Showcase:''' The Open Source Showcase is an OWASP AppSec Conference event module designed to give Open Source project leaders the opportunity to demo their projects.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
*'''OWASP Project Track:''' The OWASP Project Track is an OWASP AppSec Conference event module designed to give OWASP Project leaders the opportunity to showcase their projects as an official conference presenter. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Projects General ==  &lt;br /&gt;
&lt;br /&gt;
*'''OWASP Code of Ethics:''' The OWASP Code of Ethics are the set of guidelines and principles that the OWASP Foundation expects all of its members and conference attendees to abide by. A copy of the Code of Ethics can be found here in the [[About_The_Open_Web_Application_Security_Project#Code_of_Ethics|OWASP About page]]. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Sponsorships and Donations  =&lt;br /&gt;
&amp;lt;font size=2pt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Donate to OWASP Global Projects ==&lt;br /&gt;
OWASP Projects, a global division of the OWASP Foundation, is run under the same world wide not-for-profit charitable status as all the foundation strategic groups. OWASP provides a platform for contributors to share their work while providing them with the project and community support they need throughout their project development. All OWASP Projects are run by volunteers and they rely on personal donations and sponsorship to continue their development. Donate to OWASP Projects, and we promise to spend your money wisely on open source initiatives.&lt;br /&gt;
&lt;br /&gt;
'''This is how your money can help:'''&lt;br /&gt;
&lt;br /&gt;
* $20 could help us spread the word on the importance of open source initiatives in the Application Security industry.&lt;br /&gt;
* $100 could help fund OWASP project demos at major conferences.&lt;br /&gt;
* $250 could help get our volunteer Project Leaders to speaking engagements.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Image:Donate_Button.jpg | link=http://www.regonline.com/Register/Checkin.aspx?EventID=1044369]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Contact US  =&lt;br /&gt;
&amp;lt;font size=2pt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
If you need any help with anything projects related, or if you simply need some more information, please do not hesitate to [https://www.tfaforms.com/308703  Contact Us].&lt;br /&gt;
&amp;lt;/font&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= Current Project Review Guidelines =&lt;br /&gt;
&amp;lt;font size=3pt&amp;gt;&lt;br /&gt;
&lt;br /&gt;
PROJECT REVIEWS RESTART November 2016&lt;br /&gt;
&lt;br /&gt;
Steps for Project Graduation Review:&lt;br /&gt;
 &lt;br /&gt;
Process Starts when Project Leader Requests a Graduation Review this is done through a [https://www.tfaforms.com/308703| contact us form].&lt;br /&gt;
&lt;br /&gt;
Project Coordinator send link to the the Project Review Form for the Project Leader to provide the assessment.&lt;br /&gt;
&lt;br /&gt;
Senior Techinical Coordinator reviews the assessment received and works with the Project Leader if there are any questions. Once reviewed the assessment is passed to the Project Coordinator..&lt;br /&gt;
&lt;br /&gt;
Project Coordinator Reviews the request and adds to the Volunteer Job Board for outreach to the community - http://owasp.force.com/volunteers/GW_Volunteers__Volunteerhttps://www.tfaforms.com/393806sJobListing&lt;br /&gt;
Once volunteer signs up and chooses a project review then the Project Coordinator sends the link to the Volunteer with instructions to the google doc for the Project Review (Sample DOC)&lt;br /&gt;
&lt;br /&gt;
There will need to be at least two reviewers for each Project Review along with the Senior Technical Coordinator to finalize the results. &lt;br /&gt;
&lt;br /&gt;
Senior Technical Coordinator could process a review if the there is lack of reviewers.&lt;br /&gt;
&lt;br /&gt;
Senior Technical Coordinator/Volunteers has about 2-4 weeks to complete the Project Review . &lt;br /&gt;
&lt;br /&gt;
Senior Technical/ Volunteer works with the Project Leader on any  information or questions.&lt;br /&gt;
&lt;br /&gt;
The time to complete can be extended to up to a an additional week.&lt;br /&gt;
&lt;br /&gt;
Senior Technical Coordinator provides recommendations.&lt;br /&gt;
&lt;br /&gt;
Project Coordinator sends Project Review to the community for feedback. &lt;br /&gt;
&lt;br /&gt;
Community Leaders can also process a review if they choose to disagree with the review.&lt;br /&gt;
&lt;br /&gt;
Project Graduation is announced by Connector and other social media &lt;br /&gt;
&lt;br /&gt;
Current OWASP Project Review Guidelines Link below:&lt;br /&gt;
[[Project Reviews Guideline]]&lt;br /&gt;
&amp;lt;/font&amp;gt;&lt;br /&gt;
&amp;lt;headertabs /&amp;gt;&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Talk:OWASP_A%26D_Project&amp;diff=239865</id>
		<title>Talk:OWASP A&amp;D Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Talk:OWASP_A%26D_Project&amp;diff=239865"/>
				<updated>2018-04-13T15:26:41Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Created page with &amp;quot;Reach back to the leaders for completion of the wiki page criteria&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Reach back to the leaders for completion of the wiki page criteria&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Jonathan_carter&amp;diff=239822</id>
		<title>User:Jonathan carter</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Jonathan_carter&amp;diff=239822"/>
				<updated>2018-04-13T02:21:00Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Creating user page for new user.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hi,&lt;br /&gt;
It looks like I haven't logged into my OWASP account in quite some time and I'd like to re-activate my account. I have a new OWASP project on the horizon...&lt;br /&gt;
It looks like I haven't logged into my OWASP account in quite some time and I'd like to re-activate my account. I have a new OWASP project on the horizon...&lt;br /&gt;
It looks like I haven't logged into my OWASP account in quite some time and I'd like to re-activate my account. I have a new OWASP project on the horizon...&lt;br /&gt;
It looks like I haven't logged into my OWASP account in quite some time and I'd like to re-activate my account. I have a new OWASP project on the horizon...&lt;br /&gt;
It looks like I haven't logged into my OWASP account in quite some time and I'd like to re-activate my account. I have a new OWASP project on the horizon...&lt;br /&gt;
It looks like I haven't logged into my OWASP account in quite some time and I'd like to re-activate my account. I have a new OWASP project on the horizon...&lt;br /&gt;
It looks like I haven't logged into my OWASP account in quite some time and I'd like to re-activate my account. I have a new OWASP project on the horizon...&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User_talk:Jonathan_carter&amp;diff=239823</id>
		<title>User talk:Jonathan carter</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User_talk:Jonathan_carter&amp;diff=239823"/>
				<updated>2018-04-13T02:21:00Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Welcome!&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Welcome to ''OWASP''!'''&lt;br /&gt;
We hope you will contribute much and well.&lt;br /&gt;
You will probably want to read the [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents help pages].&lt;br /&gt;
Again, welcome and have fun! [[User:Claudia casanovas|Claudia Aviles-Casanovas]] ([[User talk:Claudia casanovas|talk]]) 21:21, 12 April 2018 (CDT)&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239820</id>
		<title>OWASP DevSecOps Studio Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239820"/>
				<updated>2018-04-13T00:24:08Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* Licensing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP Tool Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This project creates multiple VMs to simulate entire DevSecOps pipeline.&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
DevSecOps Studio is one of its kind, self contained DevSecOps environment/distribution to help individuals in learning DevSecOps concepts. It takes lots of efforts to setup the environment for training/demos and more often, its error prone when done manually. DevSecOps Studio is easy to get started, mostly automatic and battle tested during our Free Practical DevSecOps Course&lt;br /&gt;
&lt;br /&gt;
DevSecOps Studio project aims to reduce the time to bootstrap the environment and help you in concentrating on learning/teaching DevSecOps practices.&lt;br /&gt;
&lt;br /&gt;
Features:&lt;br /&gt;
&lt;br /&gt;
Easy to setup environment with just one command “vagrant up”&lt;br /&gt;
&lt;br /&gt;
Teaches Security as Code, Compliance as Code, Infrastructure as Code&lt;br /&gt;
&lt;br /&gt;
With built-in support for CI/CD pipeline&lt;br /&gt;
&lt;br /&gt;
OS hardening using ansible&lt;br /&gt;
&lt;br /&gt;
Compliance as code using Inspec&lt;br /&gt;
&lt;br /&gt;
QA security using ZAP, BDD-Security and Gauntlt&lt;br /&gt;
&lt;br /&gt;
Static tools like bandit, brakeman, windbags, gitrob, gitsecrets&lt;br /&gt;
&lt;br /&gt;
Security Monitoring using ELK stack.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Tool project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Tool Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The documentation for this project is available online - https://dso-studio.teachera.io/&lt;br /&gt;
&lt;br /&gt;
Github User ID: secfigo&lt;br /&gt;
&lt;br /&gt;
''Please add all the links below as the source code one has been done for you.''&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/teacheraio/DevSecOps-Studio Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name: [[Secfigo@gmail.com|Imran Mohammed A.]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [12 Feb 2013] Support for Spanish is now available with this release.&lt;br /&gt;
* [11 Jan 2014] The 1.0 stable version has been released! Thanks everyone for your feedback and code fixes that made this happen!&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Project Template is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Tool Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;April, 2018, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
1. Provision the stack on AWS using vagrant and terraform&lt;br /&gt;
&lt;br /&gt;
2. Build Images using Packer and upload to vagrant cloud.&lt;br /&gt;
&lt;br /&gt;
3. Build entire stack using docker for ease/&lt;br /&gt;
&lt;br /&gt;
4. Add Container scanning using clair&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Tool Project Template&lt;br /&gt;
* Get other people to review the Tool Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Tool Project Template&lt;br /&gt;
* Finalize the Tool Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Tool_Project_Template Tool Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
Addtional Instructions for making changes:&lt;br /&gt;
&lt;br /&gt;
The About 'tab' on that page is done with a MediaWiki template.  If you log into the wiki page for your project and click the &amp;quot;Edit&amp;quot; button/link/tab in the top-right between 'Read' and 'View History', you'll see the edit page for the main body of your project page.&lt;br /&gt;
&lt;br /&gt;
If you scroll down below the form to edit that page (below the &amp;quot;Save page&amp;quot;, &amp;quot;Show preview&amp;quot;, &amp;quot;Show changes&amp;quot; buttons, you'll see some text with a triangle in front of it reading &amp;quot;Templates used on this page:&amp;quot;  A list will expand if you click on the triangle/text to show the templates that make up this page.  The one you want is the &amp;quot;Projects/OWASP Example Project About Page&amp;quot; - click the (edit) next to this to edit that template.  The direct link is: https://www.owasp.org/index.php?title=Projects/OWASP_Example_Project_About_Page&amp;amp;action=edit&lt;br /&gt;
&lt;br /&gt;
The template takes 'input' that are key/value pairs where you'll need to edit the stuff after the equals (=) like:&lt;br /&gt;
project_name =Place your project name here. &lt;br /&gt;
&lt;br /&gt;
You'd edit the bold bit.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239819</id>
		<title>OWASP DevSecOps Studio Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239819"/>
				<updated>2018-04-13T00:23:25Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* Project Resources */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP Tool Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This project creates multiple VMs to simulate entire DevSecOps pipeline.&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
DevSecOps Studio is one of its kind, self contained DevSecOps environment/distribution to help individuals in learning DevSecOps concepts. It takes lots of efforts to setup the environment for training/demos and more often, its error prone when done manually. DevSecOps Studio is easy to get started, mostly automatic and battle tested during our Free Practical DevSecOps Course&lt;br /&gt;
&lt;br /&gt;
DevSecOps Studio project aims to reduce the time to bootstrap the environment and help you in concentrating on learning/teaching DevSecOps practices.&lt;br /&gt;
&lt;br /&gt;
Features:&lt;br /&gt;
&lt;br /&gt;
Easy to setup environment with just one command “vagrant up”&lt;br /&gt;
&lt;br /&gt;
Teaches Security as Code, Compliance as Code, Infrastructure as Code&lt;br /&gt;
&lt;br /&gt;
With built-in support for CI/CD pipeline&lt;br /&gt;
&lt;br /&gt;
OS hardening using ansible&lt;br /&gt;
&lt;br /&gt;
Compliance as code using Inspec&lt;br /&gt;
&lt;br /&gt;
QA security using ZAP, BDD-Security and Gauntlt&lt;br /&gt;
&lt;br /&gt;
Static tools like bandit, brakeman, windbags, gitrob, gitsecrets&lt;br /&gt;
&lt;br /&gt;
Security Monitoring using ELK stack.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Tool project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Tool Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The documentation for this project is available online - https://dso-studio.teachera.io/&lt;br /&gt;
&lt;br /&gt;
Github User ID: secfigo&lt;br /&gt;
&lt;br /&gt;
''Please add all the links below as the source code one has been done for you.''&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/teacheraio/DevSecOps-Studio Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name: [[Imran Mohammed A.]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [12 Feb 2013] Support for Spanish is now available with this release.&lt;br /&gt;
* [11 Jan 2014] The 1.0 stable version has been released! Thanks everyone for your feedback and code fixes that made this happen!&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Project Template is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Tool Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;April, 2018, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
1. Provision the stack on AWS using vagrant and terraform&lt;br /&gt;
&lt;br /&gt;
2. Build Images using Packer and upload to vagrant cloud.&lt;br /&gt;
&lt;br /&gt;
3. Build entire stack using docker for ease/&lt;br /&gt;
&lt;br /&gt;
4. Add Container scanning using clair&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Tool Project Template&lt;br /&gt;
* Get other people to review the Tool Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Tool Project Template&lt;br /&gt;
* Finalize the Tool Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Tool_Project_Template Tool Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
Addtional Instructions for making changes:&lt;br /&gt;
&lt;br /&gt;
The About 'tab' on that page is done with a MediaWiki template.  If you log into the wiki page for your project and click the &amp;quot;Edit&amp;quot; button/link/tab in the top-right between 'Read' and 'View History', you'll see the edit page for the main body of your project page.&lt;br /&gt;
&lt;br /&gt;
If you scroll down below the form to edit that page (below the &amp;quot;Save page&amp;quot;, &amp;quot;Show preview&amp;quot;, &amp;quot;Show changes&amp;quot; buttons, you'll see some text with a triangle in front of it reading &amp;quot;Templates used on this page:&amp;quot;  A list will expand if you click on the triangle/text to show the templates that make up this page.  The one you want is the &amp;quot;Projects/OWASP Example Project About Page&amp;quot; - click the (edit) next to this to edit that template.  The direct link is: https://www.owasp.org/index.php?title=Projects/OWASP_Example_Project_About_Page&amp;amp;action=edit&lt;br /&gt;
&lt;br /&gt;
The template takes 'input' that are key/value pairs where you'll need to edit the stuff after the equals (=) like:&lt;br /&gt;
project_name =Place your project name here. &lt;br /&gt;
&lt;br /&gt;
You'd edit the bold bit.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239818</id>
		<title>OWASP DevSecOps Studio Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239818"/>
				<updated>2018-04-13T00:21:24Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* Licensing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP Tool Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This project creates multiple VMs to simulate entire DevSecOps pipeline.&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
DevSecOps Studio is one of its kind, self contained DevSecOps environment/distribution to help individuals in learning DevSecOps concepts. It takes lots of efforts to setup the environment for training/demos and more often, its error prone when done manually. DevSecOps Studio is easy to get started, mostly automatic and battle tested during our Free Practical DevSecOps Course&lt;br /&gt;
&lt;br /&gt;
DevSecOps Studio project aims to reduce the time to bootstrap the environment and help you in concentrating on learning/teaching DevSecOps practices.&lt;br /&gt;
&lt;br /&gt;
Features:&lt;br /&gt;
&lt;br /&gt;
Easy to setup environment with just one command “vagrant up”&lt;br /&gt;
&lt;br /&gt;
Teaches Security as Code, Compliance as Code, Infrastructure as Code&lt;br /&gt;
&lt;br /&gt;
With built-in support for CI/CD pipeline&lt;br /&gt;
&lt;br /&gt;
OS hardening using ansible&lt;br /&gt;
&lt;br /&gt;
Compliance as code using Inspec&lt;br /&gt;
&lt;br /&gt;
QA security using ZAP, BDD-Security and Gauntlt&lt;br /&gt;
&lt;br /&gt;
Static tools like bandit, brakeman, windbags, gitrob, gitsecrets&lt;br /&gt;
&lt;br /&gt;
Security Monitoring using ELK stack.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Tool project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Tool Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The documentation for this project is available online - https://dso-studio.teachera.io/&lt;br /&gt;
&lt;br /&gt;
Github User ID: secfigo&lt;br /&gt;
&lt;br /&gt;
''Please add all the links below as the source code one has been done for you.''&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/teacheraio/DevSecOps-Studio Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [12 Feb 2013] Support for Spanish is now available with this release.&lt;br /&gt;
* [11 Jan 2014] The 1.0 stable version has been released! Thanks everyone for your feedback and code fixes that made this happen!&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Project Template is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Tool Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;April, 2018, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
1. Provision the stack on AWS using vagrant and terraform&lt;br /&gt;
&lt;br /&gt;
2. Build Images using Packer and upload to vagrant cloud.&lt;br /&gt;
&lt;br /&gt;
3. Build entire stack using docker for ease/&lt;br /&gt;
&lt;br /&gt;
4. Add Container scanning using clair&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Tool Project Template&lt;br /&gt;
* Get other people to review the Tool Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Tool Project Template&lt;br /&gt;
* Finalize the Tool Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Tool_Project_Template Tool Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
Addtional Instructions for making changes:&lt;br /&gt;
&lt;br /&gt;
The About 'tab' on that page is done with a MediaWiki template.  If you log into the wiki page for your project and click the &amp;quot;Edit&amp;quot; button/link/tab in the top-right between 'Read' and 'View History', you'll see the edit page for the main body of your project page.&lt;br /&gt;
&lt;br /&gt;
If you scroll down below the form to edit that page (below the &amp;quot;Save page&amp;quot;, &amp;quot;Show preview&amp;quot;, &amp;quot;Show changes&amp;quot; buttons, you'll see some text with a triangle in front of it reading &amp;quot;Templates used on this page:&amp;quot;  A list will expand if you click on the triangle/text to show the templates that make up this page.  The one you want is the &amp;quot;Projects/OWASP Example Project About Page&amp;quot; - click the (edit) next to this to edit that template.  The direct link is: https://www.owasp.org/index.php?title=Projects/OWASP_Example_Project_About_Page&amp;amp;action=edit&lt;br /&gt;
&lt;br /&gt;
The template takes 'input' that are key/value pairs where you'll need to edit the stuff after the equals (=) like:&lt;br /&gt;
project_name =Place your project name here. &lt;br /&gt;
&lt;br /&gt;
You'd edit the bold bit.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239817</id>
		<title>OWASP DevSecOps Studio Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239817"/>
				<updated>2018-04-13T00:20:34Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* Licensing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP Tool Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This project creates multiple VMs to simulate entire DevSecOps pipeline.&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
DevSecOps Studio is one of its kind, self contained DevSecOps environment/distribution to help individuals in learning DevSecOps concepts. It takes lots of efforts to setup the environment for training/demos and more often, its error prone when done manually. DevSecOps Studio is easy to get started, mostly automatic and battle tested during our Free Practical DevSecOps Course&lt;br /&gt;
&lt;br /&gt;
DevSecOps Studio project aims to reduce the time to bootstrap the environment and help you in concentrating on learning/teaching DevSecOps practices.&lt;br /&gt;
&lt;br /&gt;
Features:&lt;br /&gt;
&lt;br /&gt;
Easy to setup environment with just one command “vagrant up”&lt;br /&gt;
&lt;br /&gt;
Teaches Security as Code, Compliance as Code, Infrastructure as Code&lt;br /&gt;
&lt;br /&gt;
With built-in support for CI/CD pipeline&lt;br /&gt;
&lt;br /&gt;
OS hardening using ansible&lt;br /&gt;
&lt;br /&gt;
Compliance as code using Inspec&lt;br /&gt;
&lt;br /&gt;
QA security using ZAP, BDD-Security and Gauntlt&lt;br /&gt;
&lt;br /&gt;
Static tools like bandit, brakeman, windbags, gitrob, gitsecrets&lt;br /&gt;
&lt;br /&gt;
Security Monitoring using ELK stack.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Tool project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Tool Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The documentation for this project is available online - https://dso-studio.teachera.io/&lt;br /&gt;
&lt;br /&gt;
''Please add all the links below as the source code one has been done for you.''&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/teacheraio/DevSecOps-Studio Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [12 Feb 2013] Support for Spanish is now available with this release.&lt;br /&gt;
* [11 Jan 2014] The 1.0 stable version has been released! Thanks everyone for your feedback and code fixes that made this happen!&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Project Template is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Tool Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;April, 2018, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
1. Provision the stack on AWS using vagrant and terraform&lt;br /&gt;
&lt;br /&gt;
2. Build Images using Packer and upload to vagrant cloud.&lt;br /&gt;
&lt;br /&gt;
3. Build entire stack using docker for ease/&lt;br /&gt;
&lt;br /&gt;
4. Add Container scanning using clair&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Tool Project Template&lt;br /&gt;
* Get other people to review the Tool Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Tool Project Template&lt;br /&gt;
* Finalize the Tool Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Tool_Project_Template Tool Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
Addtional Instructions for making changes:&lt;br /&gt;
&lt;br /&gt;
The About 'tab' on that page is done with a MediaWiki template.  If you log into the wiki page for your project and click the &amp;quot;Edit&amp;quot; button/link/tab in the top-right between 'Read' and 'View History', you'll see the edit page for the main body of your project page.&lt;br /&gt;
&lt;br /&gt;
If you scroll down below the form to edit that page (below the &amp;quot;Save page&amp;quot;, &amp;quot;Show preview&amp;quot;, &amp;quot;Show changes&amp;quot; buttons, you'll see some text with a triangle in front of it reading &amp;quot;Templates used on this page:&amp;quot;  A list will expand if you click on the triangle/text to show the templates that make up this page.  The one you want is the &amp;quot;Projects/OWASP Example Project About Page&amp;quot; - click the (edit) next to this to edit that template.  The direct link is: https://www.owasp.org/index.php?title=Projects/OWASP_Example_Project_About_Page&amp;amp;action=edit&lt;br /&gt;
&lt;br /&gt;
The template takes 'input' that are key/value pairs where you'll need to edit the stuff after the equals (=) like:&lt;br /&gt;
project_name =Place your project name here. &lt;br /&gt;
&lt;br /&gt;
You'd edit the bold bit.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239816</id>
		<title>OWASP DevSecOps Studio Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239816"/>
				<updated>2018-04-13T00:15:41Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* If I am not a programmer can I participate in your project? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP Tool Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
DevSecOps Studio is one of its kind, self contained DevSecOps environment/distribution to help individuals in learning DevSecOps concepts. It takes lots of efforts to setup the environment for training/demos and more often, its error prone when done manually. DevSecOps Studio is easy to get started, mostly automatic and battle tested during our Free Practical DevSecOps Course&lt;br /&gt;
&lt;br /&gt;
DevSecOps Studio project aims to reduce the time to bootstrap the environment and help you in concentrating on learning/teaching DevSecOps practices.&lt;br /&gt;
&lt;br /&gt;
Features:&lt;br /&gt;
&lt;br /&gt;
Easy to setup environment with just one command “vagrant up”&lt;br /&gt;
&lt;br /&gt;
Teaches Security as Code, Compliance as Code, Infrastructure as Code&lt;br /&gt;
&lt;br /&gt;
With built-in support for CI/CD pipeline&lt;br /&gt;
&lt;br /&gt;
OS hardening using ansible&lt;br /&gt;
&lt;br /&gt;
Compliance as code using Inspec&lt;br /&gt;
&lt;br /&gt;
QA security using ZAP, BDD-Security and Gauntlt&lt;br /&gt;
&lt;br /&gt;
Static tools like bandit, brakeman, windbags, gitrob, gitsecrets&lt;br /&gt;
&lt;br /&gt;
Security Monitoring using ELK stack.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Tool project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Tool Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [12 Feb 2013] Support for Spanish is now available with this release.&lt;br /&gt;
* [11 Jan 2014] The 1.0 stable version has been released! Thanks everyone for your feedback and code fixes that made this happen!&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Project Template is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Tool Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;April, 2018, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&lt;br /&gt;
1. Provision the stack on AWS using vagrant and terraform&lt;br /&gt;
&lt;br /&gt;
2. Build Images using Packer and upload to vagrant cloud.&lt;br /&gt;
&lt;br /&gt;
3. Build entire stack using docker for ease/&lt;br /&gt;
&lt;br /&gt;
4. Add Container scanning using clair&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Tool Project Template&lt;br /&gt;
* Get other people to review the Tool Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Tool Project Template&lt;br /&gt;
* Finalize the Tool Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Tool_Project_Template Tool Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
Addtional Instructions for making changes:&lt;br /&gt;
&lt;br /&gt;
The About 'tab' on that page is done with a MediaWiki template.  If you log into the wiki page for your project and click the &amp;quot;Edit&amp;quot; button/link/tab in the top-right between 'Read' and 'View History', you'll see the edit page for the main body of your project page.&lt;br /&gt;
&lt;br /&gt;
If you scroll down below the form to edit that page (below the &amp;quot;Save page&amp;quot;, &amp;quot;Show preview&amp;quot;, &amp;quot;Show changes&amp;quot; buttons, you'll see some text with a triangle in front of it reading &amp;quot;Templates used on this page:&amp;quot;  A list will expand if you click on the triangle/text to show the templates that make up this page.  The one you want is the &amp;quot;Projects/OWASP Example Project About Page&amp;quot; - click the (edit) next to this to edit that template.  The direct link is: https://www.owasp.org/index.php?title=Projects/OWASP_Example_Project_About_Page&amp;amp;action=edit&lt;br /&gt;
&lt;br /&gt;
The template takes 'input' that are key/value pairs where you'll need to edit the stuff after the equals (=) like:&lt;br /&gt;
project_name =Place your project name here. &lt;br /&gt;
&lt;br /&gt;
You'd edit the bold bit.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239815</id>
		<title>OWASP DevSecOps Studio Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239815"/>
				<updated>2018-04-13T00:14:40Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* OWASP Tool Project Template */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP Tool Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
DevSecOps Studio is one of its kind, self contained DevSecOps environment/distribution to help individuals in learning DevSecOps concepts. It takes lots of efforts to setup the environment for training/demos and more often, its error prone when done manually. DevSecOps Studio is easy to get started, mostly automatic and battle tested during our Free Practical DevSecOps Course&lt;br /&gt;
&lt;br /&gt;
DevSecOps Studio project aims to reduce the time to bootstrap the environment and help you in concentrating on learning/teaching DevSecOps practices.&lt;br /&gt;
&lt;br /&gt;
Features:&lt;br /&gt;
&lt;br /&gt;
Easy to setup environment with just one command “vagrant up”&lt;br /&gt;
&lt;br /&gt;
Teaches Security as Code, Compliance as Code, Infrastructure as Code&lt;br /&gt;
&lt;br /&gt;
With built-in support for CI/CD pipeline&lt;br /&gt;
&lt;br /&gt;
OS hardening using ansible&lt;br /&gt;
&lt;br /&gt;
Compliance as code using Inspec&lt;br /&gt;
&lt;br /&gt;
QA security using ZAP, BDD-Security and Gauntlt&lt;br /&gt;
&lt;br /&gt;
Static tools like bandit, brakeman, windbags, gitrob, gitsecrets&lt;br /&gt;
&lt;br /&gt;
Security Monitoring using ELK stack.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Tool project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Tool Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [12 Feb 2013] Support for Spanish is now available with this release.&lt;br /&gt;
* [11 Jan 2014] The 1.0 stable version has been released! Thanks everyone for your feedback and code fixes that made this happen!&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Project Template is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Tool Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Tool Project Template&lt;br /&gt;
* Get other people to review the Tool Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Tool Project Template&lt;br /&gt;
* Finalize the Tool Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Tool_Project_Template Tool Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
Addtional Instructions for making changes:&lt;br /&gt;
&lt;br /&gt;
The About 'tab' on that page is done with a MediaWiki template.  If you log into the wiki page for your project and click the &amp;quot;Edit&amp;quot; button/link/tab in the top-right between 'Read' and 'View History', you'll see the edit page for the main body of your project page.&lt;br /&gt;
&lt;br /&gt;
If you scroll down below the form to edit that page (below the &amp;quot;Save page&amp;quot;, &amp;quot;Show preview&amp;quot;, &amp;quot;Show changes&amp;quot; buttons, you'll see some text with a triangle in front of it reading &amp;quot;Templates used on this page:&amp;quot;  A list will expand if you click on the triangle/text to show the templates that make up this page.  The one you want is the &amp;quot;Projects/OWASP Example Project About Page&amp;quot; - click the (edit) next to this to edit that template.  The direct link is: https://www.owasp.org/index.php?title=Projects/OWASP_Example_Project_About_Page&amp;amp;action=edit&lt;br /&gt;
&lt;br /&gt;
The template takes 'input' that are key/value pairs where you'll need to edit the stuff after the equals (=) like:&lt;br /&gt;
project_name =Place your project name here. &lt;br /&gt;
&lt;br /&gt;
You'd edit the bold bit.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239557</id>
		<title>OWASP DevSecOps Studio Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_DevSecOps_Studio_Project&amp;diff=239557"/>
				<updated>2018-04-10T19:12:47Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Created page with &amp;quot;=Main=  &amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;link=&amp;lt;/div&amp;gt;  {| style=&amp;quot;padding: 0;margin:0;margin-top:10px;t...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP Tool Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Tool project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Tool Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
Contextual custom dictionary builder with character substitution and word variations for pen-testers&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Installation Package]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves What's New (Revision History)]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [[OWASP_Code_Project_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [12 Feb 2013] Support for Spanish is now available with this release.&lt;br /&gt;
* [11 Jan 2014] The 1.0 stable version has been released! Thanks everyone for your feedback and code fixes that made this happen!&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator.   See the Road Map and Getting Involved tab for more details.&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Tool Project Template is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Tool Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Tool Project Template&lt;br /&gt;
* Get other people to review the Tool Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Tool Project Template&lt;br /&gt;
* Finalize the Tool Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Tool Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Tool_Project_Template Tool Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Tool Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
Addtional Instructions for making changes:&lt;br /&gt;
&lt;br /&gt;
The About 'tab' on that page is done with a MediaWiki template.  If you log into the wiki page for your project and click the &amp;quot;Edit&amp;quot; button/link/tab in the top-right between 'Read' and 'View History', you'll see the edit page for the main body of your project page.&lt;br /&gt;
&lt;br /&gt;
If you scroll down below the form to edit that page (below the &amp;quot;Save page&amp;quot;, &amp;quot;Show preview&amp;quot;, &amp;quot;Show changes&amp;quot; buttons, you'll see some text with a triangle in front of it reading &amp;quot;Templates used on this page:&amp;quot;  A list will expand if you click on the triangle/text to show the templates that make up this page.  The one you want is the &amp;quot;Projects/OWASP Example Project About Page&amp;quot; - click the (edit) next to this to edit that template.  The direct link is: https://www.owasp.org/index.php?title=Projects/OWASP_Example_Project_About_Page&amp;amp;action=edit&lt;br /&gt;
&lt;br /&gt;
The template takes 'input' that are key/value pairs where you'll need to edit the stuff after the equals (=) like:&lt;br /&gt;
project_name =Place your project name here. &lt;br /&gt;
&lt;br /&gt;
You'd edit the bold bit.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Spending_Policy&amp;diff=239514</id>
		<title>Project Spending Policy</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Spending_Policy&amp;diff=239514"/>
				<updated>2018-04-09T20:05:38Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
Successful global outreach and community support are critical activities that support our purpose of driving visibility and evolution of safety and security of the worlds software.  To this end, some guidelines have been established for the OWASP community leadership to follow as they support the OWASP Foundation and it’s core purpose.&lt;br /&gt;
*Note: this is an expansion of the [https://www.owasp.org/index.php/OWASP_on_the_Move OWASP on the Move Program]&lt;br /&gt;
*If you would like help with funding for an activity that fits the spirit of community engagement, but is not specifically outlined below - please feel free to [mailto:support@owasp.org email us] for clarification.&lt;br /&gt;
*Payments are [https://www.owasp.org/index.php/Community_Engagement_-_Payments tracked online]&lt;br /&gt;
&lt;br /&gt;
Be sure to read the full process below to ensure a smooth and timely transaction.&lt;br /&gt;
&lt;br /&gt;
*Ready to make a request? '''[https://owasporg.atlassian.net/servicedesk/customer/portal/4/group/14 REQUEST FUNDING BEFORE YOU SPEND HERE]''' &lt;br /&gt;
*Already approved? Submit receipts for reimbursement with our  '''[https://owasporg.atlassian.net/servicedesk/customer/portal/4/group/9 REIMBURSEMENT SUBMISSION FORM]''' &lt;br /&gt;
&lt;br /&gt;
Below you will find a series of guidelines aimed at assisting OWASP Project Leaders with OWASP Project spending related questions. In order to avoid any problems or misunderstandings in the future, we have developed these guidelines to provide clear expectations of how OWASP Projects should spend project funds, and what are appropriate project expenses. &lt;br /&gt;
&lt;br /&gt;
If you do not find it listed please use [https://www.tfaforms.com/308703|contact us form].&lt;br /&gt;
&lt;br /&gt;
==Guidelines==&lt;br /&gt;
# OWASP Project funds are to be spent on project related expenses ONLY. If your project has more than one Project Leader, then all Project Leaders must agree to the expense before the purchase.&lt;br /&gt;
# Before a purchase is made, the Project Leader must make sure that his/her project actually has the funds to cover the purchase. The easiest way to do this is to communicate your purchase needs to the OWASP Projects Manager, or you can look at the running funds list provided by the foundation.&lt;br /&gt;
# Project expenses exceeding $500 USD must be communicated to the OWASP Projects Manager before the purchase.&lt;br /&gt;
# All project expenses will preferably be managed via a reimbursement process. Once a purchase is made, the purchaser must submit a reimbursement request using our reimbursement form. Note: A receipt is required for the reimbursement process to be successful. &lt;br /&gt;
# If reimbursement is not possible for a project, fill out the Contact Us form and request assistance with payment from the staff.&lt;br /&gt;
# Appropriate Project Expenses encompass the following: Graphic Design; Technical Contractor; Web Design; Printing; Software Purchase; Hardware Purchase; Intern Stipends; Team Travel Expenses (for project related work ONLY); Venue Hire (project related work only); Food and Drink (if used to meet with other project leaders, contributors, OWASP staff, or an OWASP related function); Project Contractor. Please check with the OWASP Projects Manager before you move forward with a purchase if your expense falls outside of the items listed above.&lt;br /&gt;
# All OWASP Projects are started with the understanding that they will be volunteer run, and they must remain volunteer run.&lt;br /&gt;
# In the event that a project’s Leaders decide they would like to hire a contractor to work on a particular aspect of the project, then the Project Leaders must manage the recruitment and payment on a task/work assignment basis. Contractors must be paid upon satisfactory completion of the task/work assignment. Additionally, the OWASP Projects Manager must be be informed that project funds will be used to hire a contractor for project development.&lt;br /&gt;
# Hiring Project Leaders as Contractors: If a project’s Leaders decide to hire another Leader as a contractor for a project task/work assignment, then the OWASP Projects Manager must be informed before work begins. Leaders must demonstrate to the OWASP PM that they have searched for 3rd party contractors, before the decision was reached to hire the Project Leader(s) as contractors.The contracted Leader(s) will be paid upon satisfactory completion of the work.&lt;br /&gt;
# As of Jan 01, 2014, OWASP will add a disclaimer to the donation page which states that the foundation reserves the right to reallocate funds to the general Foundation income account. For all money received for projects prior to Jan 1st - OWASP will make best efforts to contact donors in respect to their donor intent before reallocating funds in the instance of inactive projects.&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Project_Spending_Policy&amp;diff=239513</id>
		<title>Project Spending Policy</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Project_Spending_Policy&amp;diff=239513"/>
				<updated>2018-04-09T19:54:11Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
Successful global outreach and community support are critical activities that support our purpose of driving visibility and evolution of safety and security of the worlds software.  To this end, some guidelines have been established for the OWASP community leadership to follow as they support the OWASP Foundation and it’s core purpose.&lt;br /&gt;
*Note: this is an expansion of the [https://www.owasp.org/index.php/OWASP_on_the_Move OWASP on the Move Program]&lt;br /&gt;
*If you would like help with funding for an activity that fits the spirit of community engagement, but is not specifically outlined below - please feel free to [mailto:support@owasp.org email us] for clarification.&lt;br /&gt;
*Payments are [https://www.owasp.org/index.php/Community_Engagement_-_Payments tracked online]&lt;br /&gt;
&lt;br /&gt;
Be sure to read the full process below to ensure a smooth and timely transaction.&lt;br /&gt;
&lt;br /&gt;
*Ready to make a request? &lt;br /&gt;
*Already approved? Submit receipts for reimbursement with our &lt;br /&gt;
&lt;br /&gt;
Below you will find a series of guidelines aimed at assisting OWASP Project Leaders with OWASP Project spending related questions. In order to avoid any problems or misunderstandings in the future, we have developed these guidelines to provide clear expectations of how OWASP Projects should spend project funds, and what are appropriate project expenses. &lt;br /&gt;
&lt;br /&gt;
If you do not find it listed please use [https://www.tfaforms.com/308703|contact us form].&lt;br /&gt;
&lt;br /&gt;
==Guidelines==&lt;br /&gt;
# OWASP Project funds are to be spent on project related expenses ONLY. If your project has more than one Project Leader, then all Project Leaders must agree to the expense before the purchase.&lt;br /&gt;
# Before a purchase is made, the Project Leader must make sure that his/her project actually has the funds to cover the purchase. The easiest way to do this is to communicate your purchase needs to the OWASP Projects Manager, or you can look at the running funds list provided by the foundation.&lt;br /&gt;
# Project expenses exceeding $500 USD must be communicated to the OWASP Projects Manager before the purchase.&lt;br /&gt;
# All project expenses will preferably be managed via a reimbursement process. Once a purchase is made, the purchaser must submit a reimbursement request using our reimbursement form. Note: A receipt is required for the reimbursement process to be successful. &lt;br /&gt;
# If reimbursement is not possible for a project, fill out the Contact Us form and request assistance with payment from the staff.&lt;br /&gt;
# Appropriate Project Expenses encompass the following: Graphic Design; Technical Contractor; Web Design; Printing; Software Purchase; Hardware Purchase; Intern Stipends; Team Travel Expenses (for project related work ONLY); Venue Hire (project related work only); Food and Drink (if used to meet with other project leaders, contributors, OWASP staff, or an OWASP related function); Project Contractor. Please check with the OWASP Projects Manager before you move forward with a purchase if your expense falls outside of the items listed above.&lt;br /&gt;
# All OWASP Projects are started with the understanding that they will be volunteer run, and they must remain volunteer run.&lt;br /&gt;
# In the event that a project’s Leaders decide they would like to hire a contractor to work on a particular aspect of the project, then the Project Leaders must manage the recruitment and payment on a task/work assignment basis. Contractors must be paid upon satisfactory completion of the task/work assignment. Additionally, the OWASP Projects Manager must be be informed that project funds will be used to hire a contractor for project development.&lt;br /&gt;
# Hiring Project Leaders as Contractors: If a project’s Leaders decide to hire another Leader as a contractor for a project task/work assignment, then the OWASP Projects Manager must be informed before work begins. Leaders must demonstrate to the OWASP PM that they have searched for 3rd party contractors, before the decision was reached to hire the Project Leader(s) as contractors.The contracted Leader(s) will be paid upon satisfactory completion of the work.&lt;br /&gt;
# As of Jan 01, 2014, OWASP will add a disclaimer to the donation page which states that the foundation reserves the right to reallocate funds to the general Foundation income account. For all money received for projects prior to Jan 1st - OWASP will make best efforts to contact donors in respect to their donor intent before reallocating funds in the instance of inactive projects.&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Security_Pins_Project&amp;diff=239371</id>
		<title>OWASP Security Pins Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Security_Pins_Project&amp;diff=239371"/>
				<updated>2018-04-05T05:22:34Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* How can I participate in your project? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==The OWASP Security Principles==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, and project leaders should ensure that the description is meaningful.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Oftentimes motivating security champions is a challenge. Most of the time, they're not willing&lt;br /&gt;
&lt;br /&gt;
to dedicate the time and effort to the invisible part of security. The product owners themselves focus on pushing&lt;br /&gt;
&lt;br /&gt;
the developement of features therefore the nessecity of security is often neglected or almost completely overlooked.&lt;br /&gt;
&lt;br /&gt;
That is why there is a need to visualize the investment in security, made by a champion or an entire team.&lt;br /&gt;
&lt;br /&gt;
One solution would be to give out corresponding buttons for every security event the champions attend.&lt;br /&gt;
&lt;br /&gt;
Those events could be something along the lines of a threat modeling session with OWASP Cornucopia or any other&lt;br /&gt;
&lt;br /&gt;
relevant topics.&lt;br /&gt;
&lt;br /&gt;
The buttons can be seen as a reward given to the representatives of each team, showcased in the team rooms.&lt;br /&gt;
&lt;br /&gt;
Preferably on a white hat or a sash. This concept could also be implemented with stickers.&lt;br /&gt;
&lt;br /&gt;
Benefits:&lt;br /&gt;
&lt;br /&gt;
- A teams effort in security is visible and therefore measureable&lt;br /&gt;
&lt;br /&gt;
- teams are able to compare each others achievements, especially with different skill levels (e.g. XSS Basics and XSS Advanced events)&lt;br /&gt;
&lt;br /&gt;
- Security Champions are able to get some kind of certification&lt;br /&gt;
&lt;br /&gt;
- This project could help engange others in the topic of security&lt;br /&gt;
&lt;br /&gt;
Inevitably applications are designed with security principles architects knew about, security folks included. However, as this project demonstrates there are far more than just a 'few' principles, most of which never make it into the design.&lt;br /&gt;
&lt;br /&gt;
For example, security design happens with perhaps a handful of principles:&lt;br /&gt;
&lt;br /&gt;
* Least Privilege&lt;br /&gt;
* Perimeter Security&lt;br /&gt;
* Defence in Depth&lt;br /&gt;
&lt;br /&gt;
However, we regularly see designs without '''separation of privilege'''!&lt;br /&gt;
&lt;br /&gt;
Think about that, most web applications today have all their eggs in a single basket. The business logic, the identities, passwords, products, policy enforcement, security rules are all found in the same application database that makes up the typical website! It is little wonder then, that attacks on the database have been so completely devastating, since there is no separation of privilege!&lt;br /&gt;
&lt;br /&gt;
The aim of this project, is to identify and describe a minimum functional set of principles that must be present in a secure design.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section must include a shorter description of what the project is, why the project was started, and what security issue is being helped by the project deliverable. This description will be used to promote the project so make sure the description represents your project in the best way possible. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Although this is a sample template, the project is real! [http://owasp.github.io/Security-Principles Please contribute to this project.]'''&lt;br /&gt;
&lt;br /&gt;
Over the course of my career, I have come across and collected a number of security ''aphorisms.'' These aphorisms constitute the fundamental principles of information security.&lt;br /&gt;
&lt;br /&gt;
None of the ideas or truths are mine, and unfortunately, I did not collect the citations. Initially, I would like to identify the correct citations for each aphorism.&lt;br /&gt;
&lt;br /&gt;
Additionally, many are re-statements of the same idea; thus, the 'collection of ideas' defines a fundamental principle. As such, I would also like to reverse engineer the principles from the aphorisms where appropriate, as well.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP Security Principles are free to use. In fact it is encouraged!!!'''&lt;br /&gt;
'' Additionally, I also encourage you to contribute back to the project. I have no monopoly on this knowledge; however, we all have pieces of this knowledge from our experience. Let's begin by putting our individual pieces together to make something great. Great things happen when people work together.''&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles are licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Security Principles Project? ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Here you should add a short description of what your project actually does. What is the primary goal of your project, and why is it important?&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The end goal is to identify, cite, and document the fundamental principles of information security. Once this is well organised, I think it would be great to publish this through the [http://scriptogr.am/dennis-groves/post/owasp-press OWASP Press]. Of course, it will always remain freely available, and any money collected will go directly into the project to absorb costs with any remaining funds going to the OWASP Foundation.&lt;br /&gt;
&lt;br /&gt;
This document should serve as a guide to technical architects and designers outlining the fundamental principles of security.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to slide presentations related to your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
AppSec USA 2013 [https://github.com/OWASP/Security-Principles/tree/master/Presentations/AppSec%20NYC%202013]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
== Openhub ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.openhub.net/orgs/OWASP OWASP Project Openhub]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;A preview can be found here: &amp;lt;nowiki&amp;gt;https://nextcloud.fhunii.com/s/WYfC43RDE8KZXQK&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Please not that they are using not allowed logo combinations and non open source fonts at the moment.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to your repository.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The home of the OWASP Security Principles is on [https://github.com/OWASP/Security-Principles GitHub.] You are encourged to fork, edit and push your changes back to the project through git or edit the project directly on github.&lt;br /&gt;
&lt;br /&gt;
However, if you like you may also download the master repository from the following links:&lt;br /&gt;
* [https://github.com/OWASP/Security-Principles/zipball/master .zip file.]&lt;br /&gt;
* [https://github.com/OWASP/Security-Principles/tarball/master .tgz file.]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to press your project has been a part of. Appropriate press includes: Project Leader interviews, articles written about your project, and videos about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [20 Nov 2013] News 2&lt;br /&gt;
* [30 Sep 2013] News 1&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you place links to where your project product can be downloaded or purchased, in the case of a book. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Here is where you can let the community know what project stage your project is currently in, whether the project is a builder, breaker, or defender project, and what type of project you are running. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Design of more buttons&lt;br /&gt;
&lt;br /&gt;
Please provide more detail and timeline of deliverables you would like to meet.&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book. &lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Security_Pins_Project&amp;diff=239370</id>
		<title>OWASP Security Pins Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Security_Pins_Project&amp;diff=239370"/>
				<updated>2018-04-05T05:21:40Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==The OWASP Security Principles==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, and project leaders should ensure that the description is meaningful.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Oftentimes motivating security champions is a challenge. Most of the time, they're not willing&lt;br /&gt;
&lt;br /&gt;
to dedicate the time and effort to the invisible part of security. The product owners themselves focus on pushing&lt;br /&gt;
&lt;br /&gt;
the developement of features therefore the nessecity of security is often neglected or almost completely overlooked.&lt;br /&gt;
&lt;br /&gt;
That is why there is a need to visualize the investment in security, made by a champion or an entire team.&lt;br /&gt;
&lt;br /&gt;
One solution would be to give out corresponding buttons for every security event the champions attend.&lt;br /&gt;
&lt;br /&gt;
Those events could be something along the lines of a threat modeling session with OWASP Cornucopia or any other&lt;br /&gt;
&lt;br /&gt;
relevant topics.&lt;br /&gt;
&lt;br /&gt;
The buttons can be seen as a reward given to the representatives of each team, showcased in the team rooms.&lt;br /&gt;
&lt;br /&gt;
Preferably on a white hat or a sash. This concept could also be implemented with stickers.&lt;br /&gt;
&lt;br /&gt;
Benefits:&lt;br /&gt;
&lt;br /&gt;
- A teams effort in security is visible and therefore measureable&lt;br /&gt;
&lt;br /&gt;
- teams are able to compare each others achievements, especially with different skill levels (e.g. XSS Basics and XSS Advanced events)&lt;br /&gt;
&lt;br /&gt;
- Security Champions are able to get some kind of certification&lt;br /&gt;
&lt;br /&gt;
- This project could help engange others in the topic of security&lt;br /&gt;
&lt;br /&gt;
Inevitably applications are designed with security principles architects knew about, security folks included. However, as this project demonstrates there are far more than just a 'few' principles, most of which never make it into the design.&lt;br /&gt;
&lt;br /&gt;
For example, security design happens with perhaps a handful of principles:&lt;br /&gt;
&lt;br /&gt;
* Least Privilege&lt;br /&gt;
* Perimeter Security&lt;br /&gt;
* Defence in Depth&lt;br /&gt;
&lt;br /&gt;
However, we regularly see designs without '''separation of privilege'''!&lt;br /&gt;
&lt;br /&gt;
Think about that, most web applications today have all their eggs in a single basket. The business logic, the identities, passwords, products, policy enforcement, security rules are all found in the same application database that makes up the typical website! It is little wonder then, that attacks on the database have been so completely devastating, since there is no separation of privilege!&lt;br /&gt;
&lt;br /&gt;
The aim of this project, is to identify and describe a minimum functional set of principles that must be present in a secure design.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section must include a shorter description of what the project is, why the project was started, and what security issue is being helped by the project deliverable. This description will be used to promote the project so make sure the description represents your project in the best way possible. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Although this is a sample template, the project is real! [http://owasp.github.io/Security-Principles Please contribute to this project.]'''&lt;br /&gt;
&lt;br /&gt;
Over the course of my career, I have come across and collected a number of security ''aphorisms.'' These aphorisms constitute the fundamental principles of information security.&lt;br /&gt;
&lt;br /&gt;
None of the ideas or truths are mine, and unfortunately, I did not collect the citations. Initially, I would like to identify the correct citations for each aphorism.&lt;br /&gt;
&lt;br /&gt;
Additionally, many are re-statements of the same idea; thus, the 'collection of ideas' defines a fundamental principle. As such, I would also like to reverse engineer the principles from the aphorisms where appropriate, as well.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP Security Principles are free to use. In fact it is encouraged!!!'''&lt;br /&gt;
'' Additionally, I also encourage you to contribute back to the project. I have no monopoly on this knowledge; however, we all have pieces of this knowledge from our experience. Let's begin by putting our individual pieces together to make something great. Great things happen when people work together.''&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles are licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Security Principles Project? ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Here you should add a short description of what your project actually does. What is the primary goal of your project, and why is it important?&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The end goal is to identify, cite, and document the fundamental principles of information security. Once this is well organised, I think it would be great to publish this through the [http://scriptogr.am/dennis-groves/post/owasp-press OWASP Press]. Of course, it will always remain freely available, and any money collected will go directly into the project to absorb costs with any remaining funds going to the OWASP Foundation.&lt;br /&gt;
&lt;br /&gt;
This document should serve as a guide to technical architects and designers outlining the fundamental principles of security.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to slide presentations related to your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
AppSec USA 2013 [https://github.com/OWASP/Security-Principles/tree/master/Presentations/AppSec%20NYC%202013]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
== Openhub ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.openhub.net/orgs/OWASP OWASP Project Openhub]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to your repository.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The home of the OWASP Security Principles is on [https://github.com/OWASP/Security-Principles GitHub.] You are encourged to fork, edit and push your changes back to the project through git or edit the project directly on github.&lt;br /&gt;
&lt;br /&gt;
However, if you like you may also download the master repository from the following links:&lt;br /&gt;
* [https://github.com/OWASP/Security-Principles/zipball/master .zip file.]&lt;br /&gt;
* [https://github.com/OWASP/Security-Principles/tarball/master .tgz file.]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to press your project has been a part of. Appropriate press includes: Project Leader interviews, articles written about your project, and videos about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [20 Nov 2013] News 2&lt;br /&gt;
* [30 Sep 2013] News 1&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you place links to where your project product can be downloaded or purchased, in the case of a book. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Here is where you can let the community know what project stage your project is currently in, whether the project is a builder, breaker, or defender project, and what type of project you are running. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Design of more buttons&lt;br /&gt;
&lt;br /&gt;
Please provide more detail and timeline of deliverables you would like to meet.&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book. &lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Security_Pins_Project&amp;diff=239369</id>
		<title>OWASP Security Pins Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Security_Pins_Project&amp;diff=239369"/>
				<updated>2018-04-05T05:20:23Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* The OWASP Security Principles */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==The OWASP Security Principles==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, and project leaders should ensure that the description is meaningful.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Oftentimes motivating security champions is a challenge. Most of the time, they're not willing&lt;br /&gt;
&lt;br /&gt;
to dedicate the time and effort to the invisible part of security. The product owners themselves focus on pushing&lt;br /&gt;
&lt;br /&gt;
the developement of features therefore the nessecity of security is often neglected or almost completely overlooked.&lt;br /&gt;
&lt;br /&gt;
That is why there is a need to visualize the investment in security, made by a champion or an entire team.&lt;br /&gt;
&lt;br /&gt;
One solution would be to give out corresponding buttons for every security event the champions attend.&lt;br /&gt;
&lt;br /&gt;
Those events could be something along the lines of a threat modeling session with OWASP Cornucopia or any other&lt;br /&gt;
&lt;br /&gt;
relevant topics.&lt;br /&gt;
&lt;br /&gt;
The buttons can be seen as a reward given to the representatives of each team, showcased in the team rooms.&lt;br /&gt;
&lt;br /&gt;
Preferably on a white hat or a sash. This concept could also be implemented with stickers.&lt;br /&gt;
&lt;br /&gt;
Benefits:&lt;br /&gt;
&lt;br /&gt;
- A teams effort in security is visible and therefore measureable&lt;br /&gt;
&lt;br /&gt;
- teams are able to compare each others achievements, especially with different skill levels (e.g. XSS Basics and XSS Advanced events)&lt;br /&gt;
&lt;br /&gt;
- Security Champions are able to get some kind of certification&lt;br /&gt;
&lt;br /&gt;
- This project could help engange others in the topic of security&lt;br /&gt;
&lt;br /&gt;
Inevitably applications are designed with security principles architects knew about, security folks included. However, as this project demonstrates there are far more than just a 'few' principles, most of which never make it into the design.&lt;br /&gt;
&lt;br /&gt;
For example, security design happens with perhaps a handful of principles:&lt;br /&gt;
&lt;br /&gt;
* Least Privilege&lt;br /&gt;
* Perimeter Security&lt;br /&gt;
* Defence in Depth&lt;br /&gt;
&lt;br /&gt;
However, we regularly see designs without '''separation of privilege'''!&lt;br /&gt;
&lt;br /&gt;
Think about that, most web applications today have all their eggs in a single basket. The business logic, the identities, passwords, products, policy enforcement, security rules are all found in the same application database that makes up the typical website! It is little wonder then, that attacks on the database have been so completely devastating, since there is no separation of privilege!&lt;br /&gt;
&lt;br /&gt;
The aim of this project, is to identify and describe a minimum functional set of principles that must be present in a secure design.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section must include a shorter description of what the project is, why the project was started, and what security issue is being helped by the project deliverable. This description will be used to promote the project so make sure the description represents your project in the best way possible. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Although this is a sample template, the project is real! [http://owasp.github.io/Security-Principles Please contribute to this project.]'''&lt;br /&gt;
&lt;br /&gt;
Over the course of my career, I have come across and collected a number of security ''aphorisms.'' These aphorisms constitute the fundamental principles of information security.&lt;br /&gt;
&lt;br /&gt;
None of the ideas or truths are mine, and unfortunately, I did not collect the citations. Initially, I would like to identify the correct citations for each aphorism.&lt;br /&gt;
&lt;br /&gt;
Additionally, many are re-statements of the same idea; thus, the 'collection of ideas' defines a fundamental principle. As such, I would also like to reverse engineer the principles from the aphorisms where appropriate, as well.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP Security Principles are free to use. In fact it is encouraged!!!'''&lt;br /&gt;
'' Additionally, I also encourage you to contribute back to the project. I have no monopoly on this knowledge; however, we all have pieces of this knowledge from our experience. Let's begin by putting our individual pieces together to make something great. Great things happen when people work together.''&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles are licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Security Principles Project? ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Here you should add a short description of what your project actually does. What is the primary goal of your project, and why is it important?&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The end goal is to identify, cite, and document the fundamental principles of information security. Once this is well organised, I think it would be great to publish this through the [http://scriptogr.am/dennis-groves/post/owasp-press OWASP Press]. Of course, it will always remain freely available, and any money collected will go directly into the project to absorb costs with any remaining funds going to the OWASP Foundation.&lt;br /&gt;
&lt;br /&gt;
This document should serve as a guide to technical architects and designers outlining the fundamental principles of security.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to slide presentations related to your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
AppSec USA 2013 [https://github.com/OWASP/Security-Principles/tree/master/Presentations/AppSec%20NYC%202013]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
== Openhub ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.openhub.net/orgs/OWASP OWASP Project Openhub]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to your repository.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The home of the OWASP Security Principles is on [https://github.com/OWASP/Security-Principles GitHub.] You are encourged to fork, edit and push your changes back to the project through git or edit the project directly on github.&lt;br /&gt;
&lt;br /&gt;
However, if you like you may also download the master repository from the following links:&lt;br /&gt;
* [https://github.com/OWASP/Security-Principles/zipball/master .zip file.]&lt;br /&gt;
* [https://github.com/OWASP/Security-Principles/tarball/master .tgz file.]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to press your project has been a part of. Appropriate press includes: Project Leader interviews, articles written about your project, and videos about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [20 Nov 2013] News 2&lt;br /&gt;
* [30 Sep 2013] News 1&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you place links to where your project product can be downloaded or purchased, in the case of a book. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Here is where you can let the community know what project stage your project is currently in, whether the project is a builder, breaker, or defender project, and what type of project you are running. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book. &lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_Security_Pins_Project&amp;diff=239368</id>
		<title>OWASP Security Pins Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_Security_Pins_Project&amp;diff=239368"/>
				<updated>2018-04-05T05:18:53Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Created page with &amp;quot;=Main= &amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt; &amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;link=&amp;lt;/...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==The OWASP Security Principles==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, and project leaders should ensure that the description is meaningful.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Inevitably applications are designed with security principles architects knew about, security folks included. However, as this project demonstrates there are far more than just a 'few' principles, most of which never make it into the design.&lt;br /&gt;
&lt;br /&gt;
For example, security design happens with perhaps a handful of principles:&lt;br /&gt;
&lt;br /&gt;
* Least Privilege&lt;br /&gt;
* Perimeter Security&lt;br /&gt;
* Defence in Depth&lt;br /&gt;
&lt;br /&gt;
However, we regularly see designs without '''separation of privilege'''!&lt;br /&gt;
&lt;br /&gt;
Think about that, most web applications today have all their eggs in a single basket. The business logic, the identities, passwords, products, policy enforcement, security rules are all found in the same application database that makes up the typical website! It is little wonder then, that attacks on the database have been so completely devastating, since there is no separation of privilege!&lt;br /&gt;
&lt;br /&gt;
The aim of this project, is to identify and describe a minimum functional set of principles that must be present in a secure design.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section must include a shorter description of what the project is, why the project was started, and what security issue is being helped by the project deliverable. This description will be used to promote the project so make sure the description represents your project in the best way possible. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Although this is a sample template, the project is real! [http://owasp.github.io/Security-Principles Please contribute to this project.]&lt;br /&gt;
'''&lt;br /&gt;
&lt;br /&gt;
Over the course of my career, I have come across and collected a number of security ''aphorisms.'' These aphorisms constitute the fundamental principles of information security.&lt;br /&gt;
&lt;br /&gt;
None of the ideas or truths are mine, and unfortunately, I did not collect the citations. Initially, I would like to identify the correct citations for each aphorism.&lt;br /&gt;
&lt;br /&gt;
Additionally, many are re-statements of the same idea; thus, the 'collection of ideas' defines a fundamental principle. As such, I would also like to reverse engineer the principles from the aphorisms where appropriate, as well.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''The OWASP Security Principles are free to use. In fact it is encouraged!!!&lt;br /&gt;
'' Additionally, I also encourage you to contribute back to the project. I have no monopoly on this knowledge; however, we all have pieces of this knowledge from our experience. Let's begin by putting our individual pieces together to make something great. Great things happen when people work together.&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles are licensed under the http://creativecommons.org/licenses/by-sa/3.0/ Creative Commons Attribution-ShareAlike 3.0 license], so you can copy, distribute and transmit the work, and you can adapt it, and use it commercially, but all provided that you attribute the work and if you alter, transform, or build upon this work, you may distribute the resulting work only under the same or similar license to this one.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is OWASP Security Principles Project? ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Here you should add a short description of what your project actually does. What is the primary goal of your project, and why is it important?&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The end goal is to identify, cite, and document the fundamental principles of information security. Once this is well organised, I think it would be great to publish this through the [http://scriptogr.am/dennis-groves/post/owasp-press OWASP Press]. Of course, it will always remain freely available, and any money collected will go directly into the project to absorb costs with any remaining funds going to the OWASP Foundation.&lt;br /&gt;
&lt;br /&gt;
This document should serve as a guide to technical architects and designers outlining the fundamental principles of security.&lt;br /&gt;
&lt;br /&gt;
== Presentation ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to slide presentations related to your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
AppSec USA 2013 [https://github.com/OWASP/Security-Principles/tree/master/Presentations/AppSec%20NYC%202013]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_CISO_Survey]]&lt;br /&gt;
&lt;br /&gt;
== Openhub ==&lt;br /&gt;
&lt;br /&gt;
* [https://www.openhub.net/orgs/OWASP OWASP Project Openhub]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to your repository.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The home of the OWASP Security Principles is on [https://github.com/OWASP/Security-Principles GitHub.] You are encourged to fork, edit and push your changes back to the project through git or edit the project directly on github.&lt;br /&gt;
&lt;br /&gt;
However, if you like you may also download the master repository from the following links:&lt;br /&gt;
* [https://github.com/OWASP/Security-Principles/zipball/master .zip file.]&lt;br /&gt;
* [https://github.com/OWASP/Security-Principles/tarball/master .tgz file.]&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to press your project has been a part of. Appropriate press includes: Project Leader interviews, articles written about your project, and videos about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [20 Nov 2013] News 2&lt;br /&gt;
* [30 Sep 2013] News 1&lt;br /&gt;
&lt;br /&gt;
== In Print ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you place links to where your project product can be downloaded or purchased, in the case of a book. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This project can be purchased as a print on demand book from Lulu.com&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Here is where you can let the community know what project stage your project is currently in, whether the project is a builder, breaker, or defender project, and what type of project you are running. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:New projects.png|100px|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]] &lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]   &lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Dennis_Groves Dennis Groves]&lt;br /&gt;
* [https://github.com/sublimino Andrew Martin]&lt;br /&gt;
* [https://github.com/Lambdanaut Josh Thomas]&lt;br /&gt;
* '''YOUR NAME BELONGS HERE'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
&amp;lt;/span&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
As of October 2013, the priorities are:&lt;br /&gt;
* Finish the referencing for each principle.&lt;br /&gt;
* Update the Project Template.&lt;br /&gt;
* Use the OWASP Press to develop a book.&lt;br /&gt;
* Finish and publish the book on Lulu.&lt;br /&gt;
&lt;br /&gt;
Involvement in the development and promotion of the OWASP Security Principles Project is actively encouraged!&lt;br /&gt;
You do not have to be a security expert in order to contribute.&lt;br /&gt;
Some of the ways you can help:&lt;br /&gt;
* Helping find references to some of the principles.&lt;br /&gt;
* Project administration support. &lt;br /&gt;
* Wiki editing support.&lt;br /&gt;
* Writing support for the book. &lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- DO NOT ALTER OR REMOVE THE TEXT ON NEXT LINE --&amp;gt;&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Document]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239244</id>
		<title>OWASP A&amp;D Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239244"/>
				<updated>2018-04-02T20:46:57Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* Licensing */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP A&amp;amp;D Code Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Code Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP A&amp;amp;D project provides an environment where participants can experience attacks and defenses of web application security. The project aim is participants to acquire skills of web application security.&lt;br /&gt;
&lt;br /&gt;
The Code Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Code project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Code Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Compiled DLLs]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/OWASP/A-D-Project Source Code] Link to Github &lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name: [[Takaharu.Ogasa@owasp.org|Takaharu Ogasa]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Code_Tool_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Code Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&amp;lt;/strong&amp;gt;&lt;br /&gt;
* Develop score server for A&amp;amp;D event.&lt;br /&gt;
* Develop 3 insecure server for A&amp;amp;D event.&lt;br /&gt;
* Create A&amp;amp;D event Quick Start Guide.&lt;br /&gt;
* Finalize the A&amp;amp;D project and have it reviewed to be promoted from an&lt;br /&gt;
* Incubator Project to a Lab Project.&lt;br /&gt;
Deliverables:&lt;br /&gt;
* Attack and Defence event Quick Start Guide(PDF).&lt;br /&gt;
* Score server's source code, docker image, and vm image.&lt;br /&gt;
* Insecure server's source code, docker image, and vm image.&lt;br /&gt;
** Complete the first draft of the Code Project Template&lt;br /&gt;
* Get other people to review the Code Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Code Project Template&lt;br /&gt;
* Finalize the Code Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Code_Project_Template Code Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Code]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239243</id>
		<title>OWASP A&amp;D Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239243"/>
				<updated>2018-04-02T20:45:30Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* If I am not a programmer can I participate in your project? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP A&amp;amp;D Code Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Code Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP A&amp;amp;D project provides an environment where participants can experience attacks and defenses of web application security. The project aim is participants to acquire skills of web application security.&lt;br /&gt;
&lt;br /&gt;
The Code Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Code project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Code Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Compiled DLLs]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name: [[Takaharu.Ogasa@owasp.org|Takaharu Ogasa]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Code_Tool_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Code Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&amp;lt;/strong&amp;gt;&lt;br /&gt;
* Develop score server for A&amp;amp;D event.&lt;br /&gt;
* Develop 3 insecure server for A&amp;amp;D event.&lt;br /&gt;
* Create A&amp;amp;D event Quick Start Guide.&lt;br /&gt;
* Finalize the A&amp;amp;D project and have it reviewed to be promoted from an&lt;br /&gt;
* Incubator Project to a Lab Project.&lt;br /&gt;
Deliverables:&lt;br /&gt;
* Attack and Defence event Quick Start Guide(PDF).&lt;br /&gt;
* Score server's source code, docker image, and vm image.&lt;br /&gt;
* Insecure server's source code, docker image, and vm image.&lt;br /&gt;
** Complete the first draft of the Code Project Template&lt;br /&gt;
* Get other people to review the Code Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Code Project Template&lt;br /&gt;
* Finalize the Code Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Code_Project_Template Code Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Code]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239240</id>
		<title>OWASP A&amp;D Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239240"/>
				<updated>2018-04-02T19:25:50Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* Project Resources */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP A&amp;amp;D Code Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Code Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP A&amp;amp;D project provides an environment where participants can experience attacks and defenses of web application security. The project aim is participants to acquire skills of web application security.&lt;br /&gt;
&lt;br /&gt;
The Code Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Code project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Code Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Compiled DLLs]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name: [[Takaharu.Ogasa@owasp.org|Takaharu Ogasa]]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Code_Tool_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Code Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&amp;lt;/strong&amp;gt;&lt;br /&gt;
* Develop score server for A&amp;amp;D event.&lt;br /&gt;
* Develop 3 insecure server for A&amp;amp;D event.&lt;br /&gt;
* Create A&amp;amp;D event Quick Start Guide.&lt;br /&gt;
* Finalize the A&amp;amp;D project and have it reviewed to be promoted from an&lt;br /&gt;
* Incubator Project to a Lab Project.&lt;br /&gt;
** Complete the first draft of the Code Project Template&lt;br /&gt;
* Get other people to review the Code Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Code Project Template&lt;br /&gt;
* Finalize the Code Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Code_Project_Template Code Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Code]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239239</id>
		<title>OWASP A&amp;D Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239239"/>
				<updated>2018-04-02T19:24:05Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* OWASP Code Project Template */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP A&amp;amp;D Code Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Code Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
OWASP A&amp;amp;D project provides an environment where participants can experience attacks and defenses of web application security. The project aim is participants to acquire skills of web application security.&lt;br /&gt;
&lt;br /&gt;
The Code Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Code project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Code Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Compiled DLLs]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Code_Tool_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Code Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&amp;lt;/strong&amp;gt;&lt;br /&gt;
* Develop score server for A&amp;amp;D event.&lt;br /&gt;
* Develop 3 insecure server for A&amp;amp;D event.&lt;br /&gt;
* Create A&amp;amp;D event Quick Start Guide.&lt;br /&gt;
* Finalize the A&amp;amp;D project and have it reviewed to be promoted from an&lt;br /&gt;
* Incubator Project to a Lab Project.&lt;br /&gt;
** Complete the first draft of the Code Project Template&lt;br /&gt;
* Get other people to review the Code Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Code Project Template&lt;br /&gt;
* Finalize the Code Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Code_Project_Template Code Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Code]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239238</id>
		<title>OWASP A&amp;D Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239238"/>
				<updated>2018-04-02T19:22:51Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* If I am not a programmer can I participate in your project? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP Code Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Code Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Code project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Code Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Compiled DLLs]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Code_Tool_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Code Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&amp;lt;/strong&amp;gt;&lt;br /&gt;
* Develop score server for A&amp;amp;D event.&lt;br /&gt;
* Develop 3 insecure server for A&amp;amp;D event.&lt;br /&gt;
* Create A&amp;amp;D event Quick Start Guide.&lt;br /&gt;
* Finalize the A&amp;amp;D project and have it reviewed to be promoted from an&lt;br /&gt;
* Incubator Project to a Lab Project.&amp;lt;/strong&amp;gt;&lt;br /&gt;
** Complete the first draft of the Code Project Template&amp;lt;/strong&amp;gt;&lt;br /&gt;
* Get other people to review the Code Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Code Project Template&lt;br /&gt;
* Finalize the Code Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&amp;lt;/strong&amp;gt;&amp;lt;/strong&amp;gt;&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Code_Project_Template Code Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Code]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239237</id>
		<title>OWASP A&amp;D Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239237"/>
				<updated>2018-04-02T19:21:32Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP Code Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Code Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Code project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Code Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Compiled DLLs]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Code_Tool_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Code Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Code Project Template&lt;br /&gt;
* Get other people to review the Code Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Code Project Template&lt;br /&gt;
* Finalize the Code Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Code_Project_Template Code Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Code]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239236</id>
		<title>OWASP A&amp;D Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239236"/>
				<updated>2018-04-02T19:19:34Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* OWASP A&amp;amp;D Code Project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt; =Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP A&amp;amp;D Code Project ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
A&amp;amp;D stands for Attack and Defense. The local chapters in the region(Natori, Kyushu, Sendai) have been co-operated to hold two A&amp;amp;D CTF events during the past 4 month. We think it is good idea to lift this to OWASP project and make souce codes, documents, etc to open to the public help building realistic web apps security skills.&lt;br /&gt;
&lt;br /&gt;
The OWASP Code Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Code project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Code Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Compiled DLLs]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name: [[Takaharu.ogasa@owasp.org|Takaharu Ogasa]]&lt;br /&gt;
&lt;br /&gt;
Any other leaders?&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Code_Tool_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Code Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Code Project Template&lt;br /&gt;
* Get other people to review the Code Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Code Project Template&lt;br /&gt;
* Finalize the Code Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Code_Project_Template Code Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Code]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239235</id>
		<title>OWASP A&amp;D Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239235"/>
				<updated>2018-04-02T19:15:58Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* OWASP Code Project Template */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt; =Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP A&amp;amp;D Code Project ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Code Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Code project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Code Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Compiled DLLs]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name: [[Takaharu.ogasa@owasp.org|Takaharu Ogasa]]&lt;br /&gt;
&lt;br /&gt;
Any other leaders?&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Code_Tool_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Code Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Code Project Template&lt;br /&gt;
* Get other people to review the Code Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Code Project Template&lt;br /&gt;
* Finalize the Code Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Code_Project_Template Code Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Code]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239234</id>
		<title>OWASP A&amp;D Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239234"/>
				<updated>2018-04-02T19:15:32Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* Project Leader */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt; =Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP Code Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Code Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Code project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Code Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Compiled DLLs]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name: [[Takaharu.ogasa@owasp.org|Takaharu Ogasa]]&lt;br /&gt;
&lt;br /&gt;
Any other leaders?&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Code_Tool_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | rowspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; | [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot; | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot; style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Code Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Code Project Template&lt;br /&gt;
* Get other people to review the Code Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Code Project Template&lt;br /&gt;
* Finalize the Code Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Code_Project_Template Code Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  &lt;br /&gt;
[[Category:OWASP_Builders]] &lt;br /&gt;
[[Category:OWASP_Defenders]]  &lt;br /&gt;
[[Category:OWASP_Code]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239228</id>
		<title>OWASP A&amp;D Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_A%26D_Project&amp;diff=239228"/>
				<updated>2018-04-02T17:11:40Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Created page with &amp;quot; =Main=  &amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;link=&amp;lt;/div&amp;gt;  {| style=&amp;quot;padding: 0;margin:0;margin-top:10px;...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt; =Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP Code Project Template==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This section should include an overview of what the project is, why the project was started, and what security issue is being addressed by the project deliverable. Some readers may be discouraged from looking further at the project if they do not understand the significance of the security concern that is being addressed, so provide enough context so the average reader will continue on with reading the description. You shouldn't assume the reader will understand the objective by providing security terminology, e.g. this project builds cryptographic algorithms, but should also endeavor to explain what they are used for.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Code Template Project is a template designed to help Project Leaders create suitable project pages for OWASP Projects.  By following the instructional text in red (and then deleting it) it should be easier to understand what information OWASP and the project users are looking for.  And it's easy to get started by simply creating a new project from the appropriate project template.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you need to add your more robust project description. A project description should outline the purpose of the project, how it is used, and the value it provides to application security. Ideally, project descriptions should be written in such a way that there is no question what value the project provides to the software security community. This section will be seen and used in various places within the Projects Portal. Poorly written project descriptions therefore detract from a project’s visibility, so project leaders should ensure that the description is meaningful.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template is simply a sample project that was developed for instructional purposes that can be used to create default project pages for a Code project.  After copying this template to your new project, all you have to do is follow the instructions in red, replace the sample text with text suited for your project, and then delete the sections in red.  Doing so should make it clearer to both consumers of this project, as well as OWASP reviewers who are trying to determine if the project can be promoted to the next category.  The information requested is also intended to help Project Leaders think about the roadmap and feature priorities, and give guidance to the reviews as a result of that effort.&lt;br /&gt;
&lt;br /&gt;
Creating a new set of project pages from scratch can be a challenging task.  By providing a sample layout, with instructional text and examples, the OWASP Code Project Template makes it easier for Project Leaders to create effective security projects and hence helps promote security.&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
A project must be licensed under a community friendly or open source license.  For more information on OWASP recommended licenses, please see [https://www.owasp.org/index.php/OWASP_Licenses OWASP Licenses]. While OWASP does not promote any particular license over another, the vast majority of projects have chosen a Creative Commons license variant for documentation projects, or a GNU General Public License variant for tools and code projects.  This example assumes that you want to use the AGPL 3.0 license.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This program is free software: you can redistribute it and/or modify it under the terms of the [http://www.gnu.org/licenses/agpl-3.0.html link GNU Affero General Public License 3.0] as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.  OWASP XXX and any contributions are Copyright &amp;amp;copy; by {the Project Leader(s) or OWASP} {Year(s)}.  &lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Project Resources ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to the key locations for project files, including setup programs, the source code repository, online documentation, a Wiki Home Page, threaded discussions about the project, and Issue Tracking system, etc. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Compiled DLLs]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Source Code]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Documentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Wiki Home Page]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Issue Tracker]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Slide Presentation]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/SamanthaGroves Video]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project leader is the individual who decides to lead the project throughout its lifecycle. The project leader is responsible for communicating the project’s progress to the OWASP Foundation, and he/she is ultimately responsible for the project’s deliverables. The project leader must provide OWASP with his/her real name and contact e-mail address for his/her project application to be accepted, as OWASP prides itself on the openness of its products, operations, and members.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Project leader's name&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
* [[OWASP_Code_Tool_Template]]&lt;br /&gt;
* [[OWASP_Documentation_Project_Template]]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_CODE.jpg|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=Builders]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Agplv3-155x51.png|link=http://www.gnu.org/licenses/agpl-3.0.html|Affero General Public License 3.0]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
* [18 Dec 2013] 1.0 Release Candidate is available for download.  This release provides final bug fixes and product stabilization.  Any feedback (good or bad) in the next few weeks would be greatly appreciated.&lt;br /&gt;
* [20 Nov 2013] 1.0 Beta 2 Release is available for download. This release offers several bug fixes, a few performance improvements, and addressed all outstanding issues from a security audit of the code.&lt;br /&gt;
* [30 Sep 2013] 1.0 Beta 1 Release is available for download.  This release offers the first version with all of the functionality for a minimum viable product.     &lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==How can I participate in your project?==&lt;br /&gt;
All you have to do is make the Project Leader's aware of your available time to contribute to the project. It is also important to let the Leader's know how you would like to contribute and pitch in to help the project meet it's goals and milestones. There are many different ways you can contribute to an OWASP Project, but communication with the leads is key. &lt;br /&gt;
&lt;br /&gt;
==If I am not a programmer can I participate in your project?==&lt;br /&gt;
Yes, you can certainly participate in the project if you are not a programmer or technical. The project needs different skills and expertise and different times during its development. Currently, we are looking for researchers, writers, graphic designers, and a project administrator. &lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
==Volunteers==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	The success of OWASP is due to a community of enthusiasts and contributors that work to make our projects great. This is also true for the success of your project. &lt;br /&gt;
Be sure to give credit where credit is due, no matter how small! This should be a brief list of the most amazing people involved in your project. &lt;br /&gt;
Be sure to provide a link to a complete list of all the amazing people in your project's community as well.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The OWASP Security Principles project is developed by a worldwide team of volunteers. A live update of project  [https://github.com/OWASP/Security-Principles/graphs/contributors contributors is found here]. &lt;br /&gt;
&lt;br /&gt;
The first contributors to the project were:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Clerkendweller Colin Watson] who created the OWASP Cornucopia project that the template was derived from&lt;br /&gt;
* [https://www.owasp.org/index.php/User:Chuck_Cooper Chuck Cooper] who edited the template to convert it from a documentation project to a Code Project Template&lt;br /&gt;
* '''YOUR NAME BELONGS HERE AND YOU SHOULD REMOVE THE PRIOR 3 NAMES'''&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	A project roadmap is the envisioned plan for the project. The purpose of the roadmap is to help others understand where the project is going as well as areas that volunteers may contribute. It gives the community a chance to understand the context and the vision for the goal of the project. Additionally, if a project becomes inactive, or if the project is abandoned, a roadmap can help ensure a project can be adopted and continued under new leadership.&lt;br /&gt;
	Roadmaps vary in detail from a broad outline to a fully detailed project charter. Generally speaking, projects with detailed roadmaps have tended to develop into successful projects. Some details that leaders may consider placing in the roadmap include: envisioned milestones, planned feature enhancements, essential conditions, project assumptions, development timelines, etc. You are required to have at least 4 milestones for every year the project is active. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
==Roadmap==&lt;br /&gt;
As of &amp;lt;strong&amp;gt;November, 2013, the highest priorities for the next 6 months&amp;lt;/strong&amp;gt; are:&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Complete the first draft of the Code Project Template&lt;br /&gt;
* Get other people to review the Code Project Template and provide feedback&lt;br /&gt;
* Incorporate feedback into changes in the Code Project Template&lt;br /&gt;
* Finalize the Code Project template and have it reviewed to be promoted from an Incubator Project to a Lab Project&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Subsequent Releases will add&lt;br /&gt;
&amp;lt;strong&amp;gt;&lt;br /&gt;
* Internationalization Support&lt;br /&gt;
* Additional Unit Tests&lt;br /&gt;
* Automated Regression tests&lt;br /&gt;
&amp;lt;/strong&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
Involvement in the development and promotion of &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; is actively encouraged!&lt;br /&gt;
You do not have to be a security expert or a programmer to contribute.&lt;br /&gt;
Some of the ways you can help are as follows:&lt;br /&gt;
&lt;br /&gt;
===Coding===&lt;br /&gt;
We could implement some of the later items on the roadmap sooner if someone wanted to help out with unit or automated regression tests&lt;br /&gt;
===Localization===&lt;br /&gt;
Are you fluent in another language? Can you help translate the text strings in the &amp;lt;strong&amp;gt;Code Project Template&amp;lt;/strong&amp;gt; into that language?&lt;br /&gt;
===Testing===&lt;br /&gt;
Do you have a flair for finding bugs in software? We want to product a high quality product, so any help with Quality Assurance would be greatly appreciated. Let us know if you can offer your help.&lt;br /&gt;
===Feedback===&lt;br /&gt;
Please use the [https://lists.owasp.org/mailman/listinfo/OWASP_Code_Project_Template Code Project Template project mailing list] for feedback about:&lt;br /&gt;
&amp;lt;ul&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What do like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What don't you like?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;li&amp;gt;What features would you like to see prioritized on the roadmap?&amp;lt;/li&amp;gt;&lt;br /&gt;
&amp;lt;/ul&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
This page is where you should indicate what is the minimum set of functionality that is required to make this a useful product that addresses your core security concern.&lt;br /&gt;
Defining this information helps the project leader to think about what is the critical functionality that a user needs for this project to be useful, thereby helping determine what the priorities should be on the roadmap.  And it also helps reviewers who are evaluating the project to determine if the functionality sufficiently provides the critical functionality to determine if the project should be promoted to the next project category.  &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The Code Project Template must specify the minimum set of tabs a project should have, provide some an example layout on each tab, provide instructional text on how a project leader should modify the tab, and give some example text that illustrates how to create an actual project.&lt;br /&gt;
&lt;br /&gt;
It would also be ideal if the sample text was translated into different languages.&lt;br /&gt;
&lt;br /&gt;
=Project About=&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This page is where you need to place your legacy project template page if your project was created before October 2013. To edit this page you will need to edit your project information template. You can typically find this page by following this address and substituting your project name where it says &amp;quot;OWASP_Example_Project&amp;quot;. When in doubt, ask the OWASP Projects Manager. &lt;br /&gt;
Example template page: https://www.owasp.org/index.php/Projects/OWASP_Example_Project&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP_Example_Project_About_Page}} &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Code]]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Funding&amp;diff=238809</id>
		<title>Funding</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Funding&amp;diff=238809"/>
				<updated>2018-03-21T20:06:28Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The purpose of this page is to outline how OWASP Community Members can request funding to support the mission of OWASP. If you can't find what you are looking for, please [https://www.tfaforms.com/308703 Contact Us].&lt;br /&gt;
=Community Engagement Funding=&lt;br /&gt;
&lt;br /&gt;
Successful global outreach and community support are critical activities that support our purpose of driving visibility and evolution of safety and security of the worlds software.  To this end, some guidelines have been established for the OWASP community leadership to follow as they support the OWASP Foundation and it’s core purpose.&lt;br /&gt;
*If you would like help with funding for an activity that fits the spirit of community engagement, but is not specifically outlined below - please feel free to [mailto:support@owasp.org email us] for clarification.&lt;br /&gt;
*Payments are [https://www.owasp.org/index.php/Community_Engagement_-_Payments tracked online]&lt;br /&gt;
*Note: this is an replacement and expansion of the OWASP on the Move Program.&lt;br /&gt;
&lt;br /&gt;
Be sure to read the full process below to ensure a smooth and timely transaction.&lt;br /&gt;
&lt;br /&gt;
*First check the [[Donation Scoreboard]] to make sure you know what is in your Project or Chapter's budget&lt;br /&gt;
*Ready to make a request? '''[https://www.tfaforms.com/308703 REQUEST FUNDING BEFORE YOU SPEND HERE]'''&lt;br /&gt;
*Already approved? Submit receipts for reimbursement with our '''[https://owasporg.atlassian.net/servicedesk/customer/portals REIMBURSEMENT SUBMISSION FORM]'''&lt;br /&gt;
*There's a new and improved reimbursement process - [[Reimbursement Process Details|full details including screenshots for every role]].&lt;br /&gt;
'''Please note:  Reimbursements are sent out in batches twice per month, on or before the 15th of the month and on or before the last day of the month.  Reimbursements must be approved at least 24 hrs before the bi-monthly batch is processes.''' &lt;br /&gt;
&lt;br /&gt;
==Types of Activity Supported==&lt;br /&gt;
&lt;br /&gt;
The Board of Directors approved a motion at the October 14, 2015 board meeting that any request for funding that has been approved for one chapter or project, can be considered an acceptable expense for all chapters or projects. If you have an account balance which covers that expense in full, then the item should be considered pre-approved for spending. Please view below acceptable expense categories and view '''[https://www.owasp.org/index.php/Community_Engagement_-_Payments#2015_Community_Engagement_Allocations.2FPayments 2017 Community Engagement Payments]''' for a list of previously approved expenses. If you do not see a comparable expense or expense category or aren't sure your expense is pre-approved, you must submit a request for approval via the [https://www.tfaforms.com/308703 Contact Us] form before requesting reimbursement.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Category&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;250&amp;quot; | Type of Event or Activity&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;450&amp;quot; | Funding Purpose&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Funding Limit&lt;br /&gt;
|-&lt;br /&gt;
| [https://www.owasp.org/index.php/OWASP_Initiatives_Global_Strategic_Focus Initiatives] || Starting/Facilitating an OWASP Initiative || An OWASP Initiative is a specific task   with a defined deliverable or expected outcome. An initiative can also be a group of people (task force) with a specific function.  Funding request should include the details of the initiative and what the money will be spent on. || $500 USD&lt;br /&gt;
|-&lt;br /&gt;
| [https://www.owasp.org/index.php/OWASP_Chapter Chapters]||Local Chapter Meeting|| Bringing great speakers to local chapters continues to be a priority of the organization.  Although there are opportunities for remote participation and speakers, face to face contact and engagement is a catalyst to inject enthusiasm and energy into a local area. &amp;lt;br&amp;gt;Note: If you're looking for OWASP merchandise for chapters you can submit on the [https://www.owasp.org/index.php/OWASP_Merchandise merchandise page]|| $500 USD&lt;br /&gt;
|-&lt;br /&gt;
| [https://www.owasp.org/index.php/OWASP_Chapter Chapters]||Multiple Chapter Meeting Engagement||Through coordination of several local chapters, it is possible to ignite an entire geographic region through a series of presentations at several local chapters in a relatively short period of time.||$1000 USD&lt;br /&gt;
|-&lt;br /&gt;
| Outreach||Outreach Speaking Engagement (Non OWASP Conference)|| Presenting an introduction to OWASP at events that are attended by professionals who will benefit from awareness of software security builds our global community and spreads security awareness.||$500 USD&lt;br /&gt;
|-&lt;br /&gt;
|Outreach||Non - OWASP Event Outreach (OWASP Representation usually a booth or stand)|| Physical representation of the OWASP Foundation at conferences managed by other organizations provides opportunities to engage individuals and companies through visual, tangible, and verbal communication. This also included funding for merchandise to support the booth. ||$500 USD&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.owasp.org/index.php/Category:OWASP_Project Project] || OWASP Track or Summit || Project Leader that is an accepted speaker taking part in the Open Source Showcase, the OWASP Project Talks, or leading an OWASP Summit Session at the conference they are asking to attend with OWASP Track funding. Preference given to Leaders  traveling from the same region that the Global AppSec Conference is taking place in. ||$1000 USD&lt;br /&gt;
|-&lt;br /&gt;
|[https://www.owasp.org/index.php/Category:OWASP_Project Project] || Project Engagement Funding|| Funding for marketing, graphic design, website hosting, or other project related expenses. [https://docs.google.com/a/owasp.org/document/d/15XuKIezpBpNH4BQYwSJ8i9125ga8IBE0IpvkO14RukI/edit Details] ||$500 USD&lt;br /&gt;
|-&lt;br /&gt;
|Chapter/Project/Outreach/Initiative || Merchandise || OWASP branded merchandise used to promote OWASP through a booth at a non-owasp event, chapter meeting, or other community building opportunity ||$500 USD&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Community Engagement Funding Rules==&lt;br /&gt;
&lt;br /&gt;
The following rules apply for community engagement funding:&lt;br /&gt;
* All funding requests MUST be pre-approved, this is necessary for global budgeting.  The funding thresholds have been established based on historic request amounts. &lt;br /&gt;
*Primary funding would be deducted from the local chapter budget (if the activity is supporting the local chapter).&lt;br /&gt;
*A chapter without sufficient funds (or initiative not tied to the chapter) may request funding from the foundation &amp;quot;Community Engagement&amp;quot; fund.  These funds are available on a first come-first serve basis.&lt;br /&gt;
*The standard funding thresholds are listed above based on the type of activity.&lt;br /&gt;
*In special circumstances the maximum amount per event can be raised to a maximum of $1000 USD.&lt;br /&gt;
*There is a proposed limit of 2,000 USD on the amount of $ provided to any individual per year (*see 'further funding' below)&lt;br /&gt;
*There is a proposed limit of 2,000 USD on the amount of $ provided to any chapter per year (*see 'further funding' below)&lt;br /&gt;
*A chapter/initiative can use the sponsorship 4 times a year, with a maximum of 2 speakers sponsored by the Community Engagement Fund for one single event.&lt;br /&gt;
*Further funding: for active chapters or speakers who have reach the proposed financial limits, further funding is possible but will depend on available budget, since priority would be given to chapters below these thresholds.&lt;br /&gt;
*Community Engagement funds are not to be used by speakers to attend OWASP conferences. If assistance is needed to attend a conference, contact the conference chair.&lt;br /&gt;
==Application Process==&lt;br /&gt;
The way it works is really easy.&lt;br /&gt;
&lt;br /&gt;
# '''Upfront''' the chapter leader, speaker, or person leading the initiative submits a community engagement request (event details, who to cover, etc...) '''[https://www.tfaforms.com/308703 REQUEST FUNDING HERE]''' The request will be reviewed by the OWASP Staff.  If the request is within the rules (see above) it will be rapidly approved.&lt;br /&gt;
#The speaker who made the travel/lodging expenses, or the chapter leader who paid for meeting space, food or supplies, submits a [https://owasporg.atlassian.net/servicedesk/customer/portals reimbursement request], including receipts, after the presentation is performed. Chapter leaders may also use this form to request direct payment to vendors (with prior approval) by supplying a copy of the invoice and payee details. Note: Travel can also be booked through the Foundation's travel management system.&lt;br /&gt;
#If the funds required to support the event exceed the documented threshold, then a request should be submitted for the entire anticipated amount.&lt;br /&gt;
#The Reimbursement is approved and processed.&lt;br /&gt;
That's it!&lt;br /&gt;
&lt;br /&gt;
===Application Resources===&lt;br /&gt;
&lt;br /&gt;
View [https://www.owasp.org/index.php/Community_Engagement_-_Payments 2016 Community Engagement Payments] (includes Pending payments)&lt;br /&gt;
&lt;br /&gt;
Your Chapter/Project Balances:&lt;br /&gt;
* [https://docs.google.com/spreadsheet/pub?hl=en_US&amp;amp;hl=en_US&amp;amp;key=0Atu4kyR3ljftdEdQWTczbUxoMUFnWmlTODZ2ZFZvaXc&amp;amp;output=html Donation Scoreboard]&lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1SBcSNfJ4HqkrrpSZOrVL6NUcqbDpXIpjw2QRBOi_jFg/edit?usp=sharing Chapter Transactions - US (Amounts shown in USD) - '''UNDER CONSTRUCTION'''].&lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1P-IH7_J4fK0J2Pxs27w9sprDs-nZTmv8-4yF8MTxIcs/edit?usp=sharing Chapter Transactions - EU (Amounts shown in Euros) - '''UNDER CONSTRUCTION'''].&lt;br /&gt;
&lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1XdzwDh4Hoy37C9wbcfR2_jvb-1W0Pnk7ST7YHc24u74/edit?usp=sharing Project Transactions - US (Amount shown in USD) - '''UNDER CONSTRUCTION''']&lt;br /&gt;
* [https://docs.google.com/spreadsheets/d/1c7m5duSmv1XX21ks1bjKkY3wVy1lLISZg74P5BaLzWw/edit?usp=sharing Project Transactions - EU (Amount shown in Euros) - '''UNDER CONSTRUCTION''']&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Community_Engagement_-_Payments&amp;diff=238807</id>
		<title>Community Engagement - Payments</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Community_Engagement_-_Payments&amp;diff=238807"/>
				<updated>2018-03-21T20:03:04Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
Summary of Funding Requests that are sourced from the Foundation's OWASP On The Move 'Community Engagement' Budget, or, from Chapters or Projects with Budgets who have graciously and generously donated a portion of their own budget to assist under-funded chapters &amp;amp; projects in the OWASP Community.&lt;br /&gt;
&lt;br /&gt;
This page contains the original request and its status. For questions on how this funding is approved or how to request funding, visit: the [[Funding|OWASP Funding]] page.  Note only WIKI Admins can edit this page.&lt;br /&gt;
&lt;br /&gt;
=2017 Community &amp;amp; Project Engagement Payments=&lt;br /&gt;
==2017 Community Engagement Allocations / Payments==&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Date&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;190&amp;quot; | Name (Requester)&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;450&amp;quot; | Chapter/Project Name&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;450&amp;quot; | Event or Activity&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Approved Amt&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;80&amp;quot; | Funding Request #&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Funded From&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Paid Amt &amp;amp; Reimbursement #&lt;br /&gt;
|-&lt;br /&gt;
|12/21/17&lt;br /&gt;
|Volodymyr Styran&lt;br /&gt;
|OWASP Kyiv&lt;br /&gt;
|Chapter Meetings&lt;br /&gt;
|399.6&lt;br /&gt;
|378&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|11/21/17&lt;br /&gt;
|Dawn Aitken&lt;br /&gt;
|Co-Marketing Agreement #1572&lt;br /&gt;
|IoT Tech Expo North America - #1572 - flyers and shipping&lt;br /&gt;
|$102.40&lt;br /&gt;
|N/A&lt;br /&gt;
|Event Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|11/16/17&lt;br /&gt;
|Prashant Kv&lt;br /&gt;
|OWASP Bangalore&lt;br /&gt;
|Children's track at Null Con&lt;br /&gt;
|$1,000&lt;br /&gt;
|266&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|11/14/17&lt;br /&gt;
|Takaharu Ogasa&lt;br /&gt;
|OWASP Hokushinetsu&lt;br /&gt;
|Bring a speaker to the chapter&lt;br /&gt;
|$337.34&lt;br /&gt;
|261&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|11/8/17&lt;br /&gt;
|Apollin Moyo&lt;br /&gt;
|OWASP Cotonou&lt;br /&gt;
|Bring a trainer to teach an Opensource security project&lt;br /&gt;
|$1,000&lt;br /&gt;
|n/a&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|11/02/17&lt;br /&gt;
|Satyam Rastogi&lt;br /&gt;
|OWASP Kumaun Region&lt;br /&gt;
|owasp kumaum meet 2017&lt;br /&gt;
|$1,000&lt;br /&gt;
|142&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|9/29/17&lt;br /&gt;
|Dawn Aitken&lt;br /&gt;
|Co-marketing Agreement #1623&lt;br /&gt;
|EDGE2017 - flyers and shipping cost&lt;br /&gt;
|$53.38&lt;br /&gt;
|N/A&lt;br /&gt;
|Event Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|8/23/17&lt;br /&gt;
|Ade Yoseman Putra &lt;br /&gt;
|OWASP Jakarta&lt;br /&gt;
|OWASP Jakarta Chapter&lt;br /&gt;
|$500&lt;br /&gt;
|&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|7/27/17&lt;br /&gt;
|Andrew Smith&lt;br /&gt;
|OWASP Knoxville&lt;br /&gt;
|Chapter meetings&lt;br /&gt;
|$500&lt;br /&gt;
|117&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|7/10/17&lt;br /&gt;
|Janine Medina&lt;br /&gt;
|OWASP Brooklyn&lt;br /&gt;
|Represent at Defcon (x2)&lt;br /&gt;
|$1000 ($500 each)&lt;br /&gt;
|114&lt;br /&gt;
|&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|6/29/17&lt;br /&gt;
|Ankit Dixit&lt;br /&gt;
|OWASP Varanasi&lt;br /&gt;
|Camera to film meetings&lt;br /&gt;
|$200&lt;br /&gt;
|101&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|6/29/17&lt;br /&gt;
|Markus Örebrand&lt;br /&gt;
|OWASP Northern Sweden&lt;br /&gt;
|Bring in a speaker&lt;br /&gt;
|$400&lt;br /&gt;
|100&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|6/29/17&lt;br /&gt;
|Harsh Bothra&lt;br /&gt;
|OWASP Jaipur&lt;br /&gt;
|OWASP Chapter Event&lt;br /&gt;
|$500&lt;br /&gt;
|108&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
|6/29/17&lt;br /&gt;
|Urvin Mistry&lt;br /&gt;
|OWASP Surat&lt;br /&gt;
|OWASP Chapter meetings and swag&lt;br /&gt;
|$500&lt;br /&gt;
|0110&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|6/27/17&lt;br /&gt;
|Prashant Venkatesh&lt;br /&gt;
|OWASP Bangalore&lt;br /&gt;
|OWASP track at c0c0n&lt;br /&gt;
|$1,000.00&lt;br /&gt;
|106&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|6/12/17&lt;br /&gt;
|Dawn Aitken&lt;br /&gt;
|Co-Marketing Agreement - #1504&lt;br /&gt;
|Goto Amsterdam - swag and shipping - pens, stickers, stress balls, bee beanies, notepads, drawstring backpacks, flyers&lt;br /&gt;
|$422.02&lt;br /&gt;
|N/A&lt;br /&gt;
|Event Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|6/7/17&lt;br /&gt;
|Dawn Aitken&lt;br /&gt;
|Co-Marketing Agreement - #1532&lt;br /&gt;
|BSides London - swag and shipping - rockets, stress balls, stickers, drawstring backpacks, bee beanies, pens&lt;br /&gt;
|$407.16&lt;br /&gt;
|N/A&lt;br /&gt;
|Event Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|6/5/17&lt;br /&gt;
|Dawn Aitken&lt;br /&gt;
|Co-Marketing Agreement - #1538&lt;br /&gt;
|Cyber Resilience Summit, Brussels &lt;br /&gt;
|$29.09&lt;br /&gt;
|N/A&lt;br /&gt;
|Event Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|6/4/17&lt;br /&gt;
|Dawn Aitken&lt;br /&gt;
|Co-Marketing Agreement - #1417&lt;br /&gt;
|Techno Security &amp;amp; Digital Forensics Conference - flyers and shipping&lt;br /&gt;
|$142.24&lt;br /&gt;
|N/A&lt;br /&gt;
|Event Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|6/1/17&lt;br /&gt;
|Dawn Aitken&lt;br /&gt;
|Co-Marketing Agreement - #1588&lt;br /&gt;
|IoT Tech Expo Europe 2017, Berlin &lt;br /&gt;
|$62.97&lt;br /&gt;
|N/A&lt;br /&gt;
|Event Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|5/22/17&lt;br /&gt;
|Tiffany Long&lt;br /&gt;
|OWASP El Salvador &lt;br /&gt;
|LatAm Tour&lt;br /&gt;
|$193.13&lt;br /&gt;
|n/a&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|193.13 &lt;br /&gt;
&amp;lt;nowiki&amp;gt;#&amp;lt;/nowiki&amp;gt;2826 &lt;br /&gt;
|-&lt;br /&gt;
|5/31/17&lt;br /&gt;
|Dawn Aitken&lt;br /&gt;
|Co-Marketing Agreement - #1526&lt;br /&gt;
|(ISC)2 Secure Summit NORDICS - Flyers and Shipping&lt;br /&gt;
|$25.14&lt;br /&gt;
|N/A&lt;br /&gt;
|Event Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|5/27/17&lt;br /&gt;
|Dawn Aitken&lt;br /&gt;
|Co-Marketing Agreement - #1573&lt;br /&gt;
|Darkmira Tour PHP 2017 - Swag and Shipping  - pens, stress balls, bee beanies, drawstring backpacks, water bottles, stickers, polo shirt&lt;br /&gt;
|$490.50&lt;br /&gt;
|N/A&lt;br /&gt;
|Event Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|5/25/17&lt;br /&gt;
|Dawn Aitken&lt;br /&gt;
|Co-Marketing Agreement - #1480&lt;br /&gt;
|SECON 2017 - Swag and Shipping - stress balls, pens, bee beanies, drawstring backpacks, water bottles, stickers&lt;br /&gt;
|$219.07&lt;br /&gt;
|N/A&lt;br /&gt;
|Event Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|5/15/2017&lt;br /&gt;
|Magno Logan&lt;br /&gt;
|OWASP Sao Paulo&lt;br /&gt;
|London Project Summit&lt;br /&gt;
|$1000&lt;br /&gt;
|57&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|5/12/17&lt;br /&gt;
|Dawn Aitken&lt;br /&gt;
|Co-Marketing Agreement - #1575&lt;br /&gt;
|CyberPortex - Software Assurance &amp;amp; Application Security Conference - swag and shipping- postcards and shirt&lt;br /&gt;
|$51.16&lt;br /&gt;
|N/A&lt;br /&gt;
|Event Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|5/2/2017&lt;br /&gt;
|Koffi   Lamgnane&lt;br /&gt;
|OWASP Burkina Faso&lt;br /&gt;
|Camera for meetings&lt;br /&gt;
|$1194&lt;br /&gt;
|n/a&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|1194 &lt;br /&gt;
&amp;lt;nowiki&amp;gt;#&amp;lt;/nowiki&amp;gt;2797&lt;br /&gt;
|-&lt;br /&gt;
|5/2/2017&lt;br /&gt;
|Paulino Calderon&lt;br /&gt;
|OWASP Riviera Maya&lt;br /&gt;
|LatAm Tour Speaker supplement&lt;br /&gt;
|$64.20&lt;br /&gt;
|n/a&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|4/27/2017&lt;br /&gt;
|Mohd Fazli Azran&lt;br /&gt;
|OWASP Malaysia&lt;br /&gt;
|OWASP Chapter&lt;br /&gt;
|$320&lt;br /&gt;
|0075&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|4/27/2017&lt;br /&gt;
|Mane Piperevski&lt;br /&gt;
|OWASP Macedonia&lt;br /&gt;
|MeetUp acct&lt;br /&gt;
|$30&lt;br /&gt;
|0078&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|4/13/2017&lt;br /&gt;
|Ade Yoseman Putra&lt;br /&gt;
|OWASP Jakarta&lt;br /&gt;
|Black Hat Asia&lt;br /&gt;
|$461.37&lt;br /&gt;
|2902&lt;br /&gt;
|Community Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
&amp;lt;nowiki&amp;gt;#&amp;lt;/nowiki&amp;gt;2902&lt;br /&gt;
|-&lt;br /&gt;
|4/12/2017&lt;br /&gt;
|Dawn Aitken&lt;br /&gt;
|OWASP Macedonia &lt;br /&gt;
|Swag for chapter &lt;br /&gt;
|$142.72&lt;br /&gt;
|70&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|4/12/2017&lt;br /&gt;
|Matt Tesauro&lt;br /&gt;
|Outreach&lt;br /&gt;
|STEM exibition&lt;br /&gt;
|$200/USD&lt;br /&gt;
|0072&lt;br /&gt;
|Event Outreach&lt;br /&gt;
|&lt;br /&gt;
|-&lt;br /&gt;
| 4/4/2017 || Dawn Aitken || Co-Marketing Agreement - #1381 || QuBit Conference 2017 - 160 OWASP &amp;quot;About Us&amp;quot; flyers and shipping cost || $47.81/USD || N/A || Event Outreach || Approved&lt;br /&gt;
|-&lt;br /&gt;
| 4/4/2017 || Dawn Aitken || Co-Marketing Agreement - #1294 || Cyber Central - 200 OWASP &amp;quot;About Us&amp;quot; flyers and shipping cost || $55.68/USD || N/A || Event Outreach || Approved &lt;br /&gt;
|-&lt;br /&gt;
|3/28/2017&lt;br /&gt;
|Mane Pipervski&lt;br /&gt;
|OWASP Macedonia&lt;br /&gt;
|meet up&lt;br /&gt;
|$30&lt;br /&gt;
|61&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|3/28/2017&lt;br /&gt;
|Debolina Khasnobish&lt;br /&gt;
|OWASP Durgapur&lt;br /&gt;
|Chapter event &lt;br /&gt;
|$500&lt;br /&gt;
|53&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|3/28/2017&lt;br /&gt;
|Avi Douglin&lt;br /&gt;
|OWASP Israel&lt;br /&gt;
|Project Summit London&lt;br /&gt;
|$1000&lt;br /&gt;
|9651&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
| 3/28/2017 || Dawn Aitken || Co-Marketing Agreement - #1487 || Black Hat Asia 2017 - Swag - $293.95, DHL Shipping - $72.21 - Printing Flyers - $493.74 - OWASP Tablecloth - $174.00, Lead Scanner - $400.00 || $1,433.90/USD || N/A || Event Outreach || Approved&lt;br /&gt;
|-&lt;br /&gt;
|3/27/2017&lt;br /&gt;
|Magno Logan&lt;br /&gt;
|Sao Paulo&lt;br /&gt;
|Project Summit London&lt;br /&gt;
|$1000&lt;br /&gt;
|9720&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
| 3/21/2017 || Dawn Aitken || Co-Marketing Agreement - #1511 || (ISC)2 Secure Summit Benelux - 200 OWASP &amp;quot;About Us&amp;quot; flyers and shipping cost || $51.56/USD || N/A || Event Outreach || Approved &lt;br /&gt;
|-&lt;br /&gt;
| 3/7/2017 || Sven Schleiere || OWASP Mobile Security Guide || Project Summit London || $1,000.00/USD  || #56 || Project Outreach ||Approved&lt;br /&gt;
|-&lt;br /&gt;
| 3/7/2017 || Bernhard Mueller|| OWASP Mobile Security Guide || Project Summit London || $1,000.00/USD  || #56 || Project Outreach ||Approved&lt;br /&gt;
|-&lt;br /&gt;
|3/1/2017&lt;br /&gt;
|Harsh Bothra&lt;br /&gt;
|OWASP Jaipur&lt;br /&gt;
|OWASP-Jaipur WAPT '17 Event and other spending.&lt;br /&gt;
|$500&lt;br /&gt;
|47&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|2/27/2017&lt;br /&gt;
|Adrian Winkles&lt;br /&gt;
|OWASP Cambridge&lt;br /&gt;
|London Summit&lt;br /&gt;
|$1,400&lt;br /&gt;
|9603&lt;br /&gt;
|Chapter Outreach&lt;br /&gt;
|Approve&lt;br /&gt;
|-&lt;br /&gt;
| 2/6/2017&lt;br /&gt;
| Dawn Aitken&lt;br /&gt;
| Co-Marketing Agreement - #1395&lt;br /&gt;
| SC Congress London - Swag (stickers, pens, stress balls, rockets, bee beanies, pint glasses) and shipping costs&lt;br /&gt;
| $250.35 USD&lt;br /&gt;
| N/A&lt;br /&gt;
| Event Outreach&lt;br /&gt;
| Approved&lt;br /&gt;
|-&lt;br /&gt;
|2/3/2017&lt;br /&gt;
|Trevor Sibanda&lt;br /&gt;
|OWASP Bulawayo&lt;br /&gt;
|OWASP Bulawayo Chapter Cybersecurity Indaba&lt;br /&gt;
|$500&lt;br /&gt;
|42&lt;br /&gt;
|Event Outreach&lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
| 1/23/17 || Dawn Aitken || Co-Marketing Agreement - #1212 || IoT Tech Expo - London - OWASP Flyers printing and shipping costs || $39.58/USD || N/A || Event Outreach || Approved &lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=2016 Community &amp;amp; Project Engagement Payments=&lt;br /&gt;
==2016 Community Engagement Allocations / Payments==&lt;br /&gt;
'''2016 Budget''' = $45,000 (Fund availability by quarter is $10-12K).&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Date&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;190&amp;quot; | Name (Requestor)&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;450&amp;quot; | Event or Activity&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Approved Amt&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Funded From&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Paid Amt&lt;br /&gt;
|-&lt;br /&gt;
| Jan 11, 2016 || Azeddine Islam Mennouchi || Speaking at [http://www.droidcon.tn/owasp-top-10-security-for-mobile/ DroidCon Tunisia] || $500 USD || Comm Engagement||Pending&lt;br /&gt;
|-&lt;br /&gt;
| Jan 17, 2016 || Ahmed M Neil ||Speaking presentation in Prague during 6-7 April to represent OWASP.  Reviewed &amp;amp; approved by P.Ritchie || $500 USD || Comm Engagement||$500&lt;br /&gt;
|-&lt;br /&gt;
| Feb 2, 2016 || Rahul Yadav ||Funding for a conference room and refreshments for attendees of up to $500. Reviewed &amp;amp; approved by N.Whysel || $500 USD || Comm Engagement||$512.64&lt;br /&gt;
|-&lt;br /&gt;
| Feb 12, 2016 || Nitin Pandey ||Funding for OWASP Lucknow International InfoSec Meet on January 10, 2016 at PNBIIT, Lucknow. ~ 60Attendees, photos sent. Reviewed &amp;amp; approved by P.Ritchie || $1000 USD || Comm Engagement||$1030&lt;br /&gt;
|-&lt;br /&gt;
| Feb 22, 2016 || EU Leadership ||Merchandise &amp;amp; DHL Shipping, 1000 Rockets for EU events. Approved by K.Hartmann || $2632 USD || Comm Engagement||$2632.26&lt;br /&gt;
|-&lt;br /&gt;
| Feb 23, 2016 ||Martin Knobloch || OWASP merchandise to be printed locally by the KNURE Student Chapter in Kharkiv. Reimbursement request will come from Vadym Chaikian of the KNURE Student Chapter. Approved by N.Whysel || $200-250 USD || OWASP Netherlands Chapter allocation||Pending&lt;br /&gt;
|-&lt;br /&gt;
| Feb 25, 2016||Trevor Sibanda||Travel expenses (accommodations in Harare and bus rental) for university tour. Approved by N.Whysel||$1000 USD||Split between OWASP Bulawayo and Austin-Africa allocation || Pending&lt;br /&gt;
|-&lt;br /&gt;
| Feb. 29, 2016 ||Kelly Santalucia || AppSecEU 2016 post cards for outreach event (#1041) Approved by K. Santalucia || $200 USD || Comm Engagement ||Pending&lt;br /&gt;
|-&lt;br /&gt;
| Mar 4, 2016 ||Narenda Choyal || Up to $500 USD for Meetup Account, Business Cards(500), OWASP Shirt(2), Stickers(Quantity 125), OWASP TShirts(Quantity 30). Approved by N.Whysel || $500 USD || OWASP Mumbai allocation || Pending&lt;br /&gt;
|-&lt;br /&gt;
| Mar 9, 2016 ||John-Patrick Lita || Request for $9500USD by JP to support 3 day Conference in Philipphines. Paul &amp;amp; Staff reviewed, proposal incomplete.  Returned request to JP asking for complete budget on Income &amp;amp; expense before determining what amount is needed from Foundation to make it 'break-even'. || $9500 USD || TBD || Pending better info.&lt;br /&gt;
|-&lt;br /&gt;
| Mar 14, 2016||Katy Anton||Request for up to $500 for speaker travel for a chapter event approved by N. Whysel||$500||OWASP Bristol plus balance from Community Engagement||Pending&lt;br /&gt;
|-&lt;br /&gt;
| Mar 16, 2016||Jatin Sethi||The expenditure for 'First Meet (Venue, Stationary &amp;amp; Refreshment) Dehradun Chapter India'||$200||Community Engagement||Approved&lt;br /&gt;
|-&lt;br /&gt;
| Mar 17, 2016||Adrian Winckles||Merchandise order for ISC(2) EMEA Secure event in Cambridge, UK. Approved by N.Whysel||$500||Cambridge chapter allocation and Comm Engagement || Pending&lt;br /&gt;
|-&lt;br /&gt;
| Mar 23, 2016||Sumit Ojha||Business Cards for 2 People, 20 OWASP printed Tshirt for members and volunteers. stationary and refreshment for attendees. and gifts for speakers. Approved by N.Whysel||Up to $500||Gwalior chapter allocation||Pending&lt;br /&gt;
|-&lt;br /&gt;
|-&lt;br /&gt;
| Mar 23, 2016||John Eto||$90 for 6 months Meetup.com account. Approved by N. Whysel||$90||OWASP Saint Louis Allocation||Pending&lt;br /&gt;
|-&lt;br /&gt;
| Mar 31, 2016||Debolina Khasnobish||Up to $500 USD for chapter meeting Approved by K Hartmann||$500||Community Funding||Pending&lt;br /&gt;
|-&lt;br /&gt;
| March 31, 2016||Kelly Santalucia||About Us flyers for outreach at Connected Security Expo in Las Vegas, NV||$27.45||Community Engagement||Approved&lt;br /&gt;
|-&lt;br /&gt;
| April 15, 2016||Tony Turner||Up to $500 USD after chapter portion for May chapter meeting Approved by K Hartmann||$500||Community Funding||Pending&lt;br /&gt;
|-&lt;br /&gt;
| April 15, 2016||Aditya Kushwaha||Up to $500 USD after chapter portion for chapter meeting Approved by K Hartmann||$500||Community Funding||Pending&lt;br /&gt;
|-&lt;br /&gt;
| April 18, 2016||Trevor Sibanda||Up to $100 USD for Bulawayo Approved by K Hartmann||$100||Community Funding||Pending&lt;br /&gt;
|-&lt;br /&gt;
| April 18, 2016||Trevor Sibanda||Up to $300 USD for Bulawayo Approved by K Hartmann||$300||Community Funding||Pending&lt;br /&gt;
|-&lt;br /&gt;
| May 4, 2016||Kelly Santalucia||AppSecEU 2016 post cards for outreach at for MIS Training 13th Annual CISCO Summit &amp;amp; Roundtable in Denmark||$64.50||Community Engagement||Approved&lt;br /&gt;
|-&lt;br /&gt;
| May 11, 2016||Kelly Santalucia||AppSecUSA 2016 postcards for outreach at One2One Summit in New Orleans, LA||$22.53||Community Engagement||Approved&lt;br /&gt;
|-&lt;br /&gt;
| May 11, 2016||Kelly Santalucia||AppSecEU 2016 post cards for outreach at (ISC)2 Secure Zurich||$67.10||Community Engagement||Approved&lt;br /&gt;
|-&lt;br /&gt;
| May 17, 2016||Kelly Santalucia||AppSecEU 2016 post cards for outreach at (ISC)2 Secure Scandinavia||$38.29||Community Engagement||Approved&lt;br /&gt;
|-&lt;br /&gt;
| May 17, 2016||Kelly Santalucia||AppSecEU 2016 post cards for outreach at Questex Asia Info Security Conference in Singapore||$38.04||Community Engagement||Approved&lt;br /&gt;
|-&lt;br /&gt;
| June 5, 2016 ||Kelly Santalucia||Flyers for Techno Security &amp;amp; Forensics Investigation Conference in Myrtle Beach, SC||$69.45||Community Engagement||Approved&lt;br /&gt;
|-&lt;br /&gt;
| June 14, 2016||Ahmed Neil||$500 funding approved to speak at Nordic IT Security conference October 26 - KBH||$500||Community Engagement||Approved&lt;br /&gt;
|-&lt;br /&gt;
| June 22, 2016||Kelly Santalucia||AppSecEU 2016 post cards (ISC)2 SecureFrance||$36.45||Community Engagement||Approved&lt;br /&gt;
|-&lt;br /&gt;
| June 30, 2016||Kelly Santalucia||OWASP Flyers for (ISC)2 SecureAustria||$46.95||Community Engagement||Approved&lt;br /&gt;
|-&lt;br /&gt;
| June 30, 2016||Kelly Santalucia||OWASP Flyers, AppSecUSA 2016 post cards, swag for Cyber Security Summit in Washington,DC ||$ ||Community Engagement||Approved&lt;br /&gt;
|-&lt;br /&gt;
| July 8, 2016||Falgun Rathod||Chapter meeting Gandhinagar chapter ||$500 ||Community Engagement||Approved KBH&lt;br /&gt;
|-&lt;br /&gt;
|December 16, 2016&lt;br /&gt;
|Sherif Koussa&lt;br /&gt;
|OWASP Ottowa&lt;br /&gt;
|$450&lt;br /&gt;
|Community Engagement &lt;br /&gt;
|Approved&lt;br /&gt;
|-&lt;br /&gt;
|December 20, 2016&lt;br /&gt;
|Jatin Sethi&lt;br /&gt;
|OWASP Dehradun AppSec Enthusiast Event&lt;br /&gt;
|$100&lt;br /&gt;
|Community Engagement&lt;br /&gt;
|Approved &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==2016 Project Funding Allocations / Payments==&lt;br /&gt;
'''2016 Budget''' = $36,000 (Fund availability by quarter is $9-10K). By policy, Projects with approved budgets will always have spending pulled from that source first.  This funding is for new or under-funded projects.&lt;br /&gt;
See [https://docs.google.com/spreadsheet/pub?hl=en_US&amp;amp;key=0Atu4kyR3ljftdEdQWTczbUxoMUFnWmlTODZ2ZFZvaXc&amp;amp;hl=en_US&amp;amp;gid=3 Project Budgets] on the Wiki for current status of approved Project Budgets.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Date&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;190&amp;quot; | Name (Requestor)&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Project&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;350&amp;quot; | Event or Activity&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Approved Amt&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Funded From&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Paid Amt&lt;br /&gt;
|-&lt;br /&gt;
| Jan.15, 2016 || Abraham Aranguren ||OWTF|| Development Contractor for OWTF Quality Release project. Proposal submitted, Claudia &amp;amp; P.Ritchie reviewed &amp;amp; approved || $1,500 USD ||OOTM-Projects||Pending&lt;br /&gt;
|-&lt;br /&gt;
| Feb 22, 2016 || Larry Conklin ||Code Review Guide|| Graphics work &amp;amp; edits by Hugo.  P.Ritchie approved || $1,008 USD ||Comm Engagement||$1008&lt;br /&gt;
|-&lt;br /&gt;
| Mar 1, 2016 || Azzeddine Ramrami ||CSRFGuard|| Speaker travel, Paris to Qatar, to The Underground Economy 2016.  N.Whysel approved || $1000 USD ||$500 from CSRFGuard Project and $500 from Comm Engagement||Pending&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=2015 Community Engagement Payments=&lt;br /&gt;
==2015 Community Engagement Allocations/Payments==&lt;br /&gt;
'''2015 Budget''' = $60,000 (Fund availability by quarter is $15,000).&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Date&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;250&amp;quot; | Name (Requestor)&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;450&amp;quot; | Event or Activity&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Amount&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;130&amp;quot; | Funded From&lt;br /&gt;
|-&lt;br /&gt;
| Jan 6, 2015 || Kelly Santalucia || CodeMash 2015 || $481.24 USD || Comm Engagement&lt;br /&gt;
|-&lt;br /&gt;
| Jan 8, 2015 || Kelly Santalucia || ICCS 2015 || $637.87 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| Jan 12, 2015 || Nitin Pandey || Speaker Support for OWASP Lucknow / DEFCON event, 2 Speakers x $500  || $1,000.00 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| Jan 13, 2015 || John Patrick Lita-Chapter Founder || Support for OWASP Manila Chapter Meeting, Q1 2015.  Merchandise and multi-city tour/training to recruit participation  || $1022.00 USD|| CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| Feb. 6, 2015 || Jim Manico || Speaker &amp;amp; Trainer travel expenses for Philippines Chapter  || $500.00 USD|| CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| Feb. 6, 2015 || Minhaz AV || Speaker &amp;amp; Travel expense for OWASP &amp;amp; CSRF talk at FOSSASIA 15 at Singapore || $500 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| Feb. 10, 2015 || Yousif Hussin || OWASP Merchandise for new Sheffield Chapter || $300 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| Feb. 19, 2015 || Israel Bryski || New Chapter 'JumpStart' funding for Brooklyn || $500 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| Feb. 20, 2015 || Jim Manico || Speaker role @CodeMash2015-Airfare reimbursement || $1000 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| Feb. 23 - 27, 2015 || Kelly Santalucia || SecAppDev 2015 || $ ||CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| March 3, 2015 || Kelly Santalucia || SC Congress London 2015 || $218.68 USD || Comm Engagement&lt;br /&gt;
|-&lt;br /&gt;
| March 16 -17, 2015 || Kelly Santalucia || Insider Threat Summit 2015 || $25.90 USD || CommEngagement &lt;br /&gt;
|-&lt;br /&gt;
| March 24 - 27, 2015 || Kelly Santalucia || BlackHat Asia 2015 || $286.00 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| March 25, 2015 || Rio Okada || Expense for 4 volunteers dinner at BlackHat Asia 2015 in Singapore || $247.10 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| March 31, 2015 || Kelly Santalucia || (ISC)2 SecureIreland || $50.11 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| April 8, 2015 || Kelly Santalucia || Cyber Secure Pakistan 2015 || $270.00 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| April 16, 2015 || Yousif Hussin || Funding for new Chapter meet &amp;amp; speakers || $250 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| April 22 - 23, 2015 || Kelly Santalucia || AppsWorld Germany || $275.26 USD || CommEngagement &lt;br /&gt;
|-&lt;br /&gt;
| April 30, 2015 || Ahmed Mohamed Neil || Speakers Reimbursement for Prague event || $500 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| May 12 - 13, 2015 || Kelly Santalucia || AppsWorld North America || $20.40 USD || CommEngagement &lt;br /&gt;
|-&lt;br /&gt;
| May 13, 2015 || Kelly Santalucia || Dev Talks 2015 Cluj || $154.97 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| May 15, 2015 || Kelly Santalucia || BSides Knoxville || $240.08 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| May 16 -17, 2015 || Kelly Santalucia || ICCS 2015 || $24.45 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| May 19 - 21, 2015 || Kelly Santalucia || Cloud Security World 2015 || $16.26 USD || CommEngagement &lt;br /&gt;
|-&lt;br /&gt;
| May 21, 2015 || Azzeddine Ramrami ||  Speaker travel expense for BDCA2015 || $400 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| May 26 - 29, 2015 || Kelly Santalucia || Hack in the Box || $508.57USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| June 8, 2015 || Fabio Cerullo ||  Speaker travel expense for Barcelona Chapter meeting || $685 Euro || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| June 10 -11, 2015 || Kelly Santaluica || SC Congress Toronto || $536.03 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| June 11, 2015 || Kelly Santalucia || Dev Talks 2015 Romania || $500.00 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| June 11 - 12 2015 || Kelly Santalucia || Cybit || $189.30 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| June 12 2015 || Yune Sung || Korea Day || $500 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| June 12 2015 || Laura Guazzelli || Gainesville, FL chapter || $500 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| June 12 2015 || Bill Semph || Speaker accommodation expense outreach speaking engagement || $400 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| June 12 2015 || Siva Kumar || New Chapter Support for Madurai Chapter || $400 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| July 5 2015 || Akshay Sharma || New Chapter Support for Bhopal Chapter || $500 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| July 6, 2015 || Azzeddine Ramrami ||  Speaker travel expense for Project Summit at AppSec-USA.  Project summit to fund $1000, Foundation to fund balance of $250 || $250 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| July 8, 2015 || Timur kHrotko ||  Speaker travel expenses for up to 2 speakers at OWASP Track at Hackivity - non OWASP event.  Update Sept.29 only ~$120USD of this amount needed. || $1000 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| July 9, 2015 || Magno Logan ||  Speaker travel expenses for up to 2 speakers at JampaSec 2015 - non OWASP event. Approved at $1k, actual expense $847 || $847 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| July 28 - 29, 2015 || Kelly Santalucia &amp;amp; John Patrick Lita || (ISC)2 Security Congress APAC 2015 || $659.21 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| July 13, 2015 || Johanna Curiel/Projects || Shutterstock subscription to create flyers || $249 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| July 20 - 26, 2015 || Kelly Santalucia || EuroPython 2015 || $300.92 || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| July 16, 2015 || Colin Watson || 20 decks of Cards to be used to promote project || $191 || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| July 31, 2015 || Kelly Santalucia || Africahackon || $494.98 USD ||Comm Engagement&lt;br /&gt;
|-&lt;br /&gt;
| August 3, 2015 || Kelly Santalucia || BSides LV 2015 || $ ||CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| August 3, 2015 || Kelly Santalucia ||Blackhat USA 2015 || $ ||CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| August 12 2015 || Bill Semph || Bringing in Speaker for Chapter meeting || $500 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| August 27 2015 || Mateo Martinez || Special funding request for bringing underfunded LATAM Chapter leaders to the Rio de la Plata OWASP event.  Up to $1,000 not to exceed $500 per person. Nov.9 released $500 to 1st requestor, Camilo. || $1,000 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| August 31, 2015 || Timothy DeBlock || New Chapter-Columbia, So.Carolina 1st meeting reimbursement || $50 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| September 4, 2015 || Kate Hartmann || Summer of Code shirts for students and mentors || $400 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| September 9, 2015 || Jonathan Carter || Mobile Top 10 business cards || $30 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| September 14, 2015 || Gary Robinson || Belfast chapter meeting space. Actual expense 106GBP || $160 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| September 14, 2015 || Trevor Sibanda || New Chapter Support for Bulawayo Chapter.  OWASP Merchandise. P.Ritchie Approved || $442 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| September 14, 2015 || Nitin Pandey || Chapter Support for Lucknow Chapter on-site meeting.   P.Ritchie Approved. Actual = $490 || $340 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| September 15, 2015 || Matt Tesauro || Travel expense-OWASP Speaker @ Velocity Conf. for Developers &amp;amp; DevOps.  Requested $1,970, P.Ritchie Approved $1000 || $1.000 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| September 28, 2015 || Nitin Pandey || Travel expense-OWASP Speaker @ HAKON Requested $450, K. Hartmann approved $500 - request cancelled by Nitin 10/02/2015 KH|| $450 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| September 29, 2015 ||Aurelijus Stanislovaitis|| Speaker Travel expense for Lithuania Chapter. Requested $750, P.Ritchie approved $500 per policy from Foundation funds. Other funding possible from owasp EEE event sponsorships || $500 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| October 7, 2015 ||Apollin Moya|| New Chapter Meeting Expense-Cotoun, Benin Africa held Sep30. Approved N.Whysel per OWASP policy || $498 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| October 8, 2015 || Kelly Santalucia || Daggercon 2015 || $503.91 USD || Community Engagement&lt;br /&gt;
|-&lt;br /&gt;
| October 9, 2015 ||Alexander Antukh|| Speaker travel to EEE event - expenses above Russia chapter balance - KBH|| $250 || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| October 9, 2015 ||John Patrick Lita|| Speaker travel &amp;amp; booth costs for 'Hack the North' event, Philippines. Pre-Approved P.Ritchie|| $500 || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| October 12, 2015 ||Jerry Gamblin|| New Chapter meeting expenses. Pre-Approved KBH. Actual expense $504|| $500 || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| October 12-13, 2015 ||Kelly Santalucia|| Middle East Information Security Summit 2015 || $71.84 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| October 14, 2015 || Bill Sempf || Presenting OWASP to [http://www.meetup.com/VTCode/events/226027008/ .NET Developers group]   || $400 || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| October 14-15, 2015 || Kelly Santalucia || Source Seattle 2015 || $237.75 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| October 20, 2015 || Kelly Santalucia || SC Congress New York || $258.48 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| October 20-21, 2015 || Kelly Santalucia || (ISC)2 Security Congress EMEA 2015 || $79.61 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| October 20 - 21, 2015 || Kelly Santalucia ||SecTor || $928.64 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| November 10-13, 2015 || Kelly Santalucia || Blackhat EU 2015 || $962.01 USD  || CommEngagement &lt;br /&gt;
|-&lt;br /&gt;
| November 17, 2015 || Kelly Santalucia || SC Congress Chicago || $206.17 USD || CommEngagement &lt;br /&gt;
|-&lt;br /&gt;
| November 26, 2015 || Patrick LeClerc || Quebec City reach-out events (4). Split cost, Quebec Chapter 66%/Foundation 33%.  Approved P.Ritchie, foundation commitment=150 || ~$ 150 USD || CommEngagement &lt;br /&gt;
|-&lt;br /&gt;
| November 25, 2015 || Gary Robinson || Security Shepherd chapter meeting - KBH|| $300 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| November 17, 2015 || Christo Goosen || Merchandise request for CapeTown chapter - KBH|| $530 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| December 8, 2015 || Tony Turner || Merchandise for Orlando chapter - KBH|| $500 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| December 8, 2015 || Tony Turner || Assistance with venue, food beverages for local developer outreach event - KBH|| $500 USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| December 14, 2015 || Gagan Shrivastava || Catering ( snacks, tea and coffee), conference stationary, Banner and some other costs for OWASP Indore's first 3 day OWASP workshop in January 24-26, 2016 || $330 USD ||CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| December 27, 2015 || Rahul Yadav || Chapter Meeting support || $500 USD ||CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
| January 5, 2016 || Kelly Santalucia || CodeMash || $741.17/USD || CommEngagement&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
''2015 Balance Remaining'' = 'about $34,500' subject to actual expenses as reimbursed from these pre-approvals.&lt;br /&gt;
&lt;br /&gt;
Balance Remaining includes actual spend as well as approved spend pending reimbursement&lt;br /&gt;
&lt;br /&gt;
==2015 Project Funding Allocations / Payments==&lt;br /&gt;
'''2015 Budget''' = $50,000 (Fund availability by quarter is $12,500). By policy, Projects with approved budgets will always have spending pulled from that source first.  This funding is for new or under-funded projects.&lt;br /&gt;
See [https://docs.google.com/spreadsheet/pub?hl=en_US&amp;amp;key=0Atu4kyR3ljftdEdQWTczbUxoMUFnWmlTODZ2ZFZvaXc&amp;amp;hl=en_US&amp;amp;gid=3 Project Budgets] on the Wiki for current status of approved Project Budgets.&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Date&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;150&amp;quot; | Name (Requestor)&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;150&amp;quot; | Project Name&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;450&amp;quot; | Event or Activity&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Amount&lt;br /&gt;
|-&lt;br /&gt;
| Feb.17, 2015 || Florian Stahl |||| Publication/Printing of Top 10 Privacy Risks doc for presentation at Global Privacy Summit in Washington DC and at the AppSecEU  || 100 Euro&lt;br /&gt;
|-&lt;br /&gt;
| March 3, 2015 || Johanna Curiel |||| Funding for Project Summit at AppSec-EU May 2015 || $10,000 USD || Foundation funded Project Support&lt;br /&gt;
|-&lt;br /&gt;
| April, 2015 || Fabio Cerullo|||| Funding for 2015 Summer of Code.  Approved at April Board meeting || $12,000 USD || Foundation funded Project Support&lt;br /&gt;
|-&lt;br /&gt;
| June 10, 2015 || Jim Manico / Andrew van der Stock|||| Funding for ASVS Project Documentation || $1,250 USD || Foundation funded Project Support&lt;br /&gt;
|-&lt;br /&gt;
| June 24, 2015 || Johanna Curiel||||Funding for Project Summit @ AppSec US 2015 || $10,400 USD || Foundation funded Project Support&lt;br /&gt;
|-&lt;br /&gt;
| July 2, 2015 || Dinis Cruz||||Funding for Google Cloud Compute instances, i.e. to host the Owbot (as seen on OWASP's Slack) and help with ZaaS (Zap as a Service)Project Summit @ AppSec US 2015. $500 startup, $500 phase 2 || $1,000 USD || Foundation funded Project Support &lt;br /&gt;
|-&lt;br /&gt;
| Sept 4, 2015 || Claudia Casanovas|| ||Special Volunteer funding request to provide 'Thank You Amazon Cards' to Volunteers participating in Oct-Nov Project Review Jump-Start Program. Approved by P.Ritchie || $1,000 USD Total || Foundation funded Project Support &lt;br /&gt;
|-&lt;br /&gt;
| Sept 10, 2015 || Steven van der Baan||CTF ||Hardware purchase to support CTF Project &amp;amp; CTF events for OWASP.  Approved by P.Ritchie per project leader handbook guidelines || $810 USD || Foundation funded Project Support &lt;br /&gt;
|-&lt;br /&gt;
| Sept 21, 2015 || M.Coates/J.Marcil||Media Project ||Laptop purchase (3) to support AppSec Conf, Events via Media Project.  Approved by P.Ritchie || $2750 USD || Foundation funded Project Support &lt;br /&gt;
|-&lt;br /&gt;
| || ||Balance Remaining|| ~$10,000|| Balance Remaining&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=2014 Community Engagement Payments=&lt;br /&gt;
&lt;br /&gt;
'''2014 Budget''' = $60,000 (Fund availability by quarter is $15,000).&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Date&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;250&amp;quot; | Name (Requestor)&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;450&amp;quot; | Event or Activity&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Amount&lt;br /&gt;
|-&lt;br /&gt;
| Jan 21, 2014 || Purple Phoenix Media ||Venue for EU Tour 2013 || $463.74 USD (342.83 Euros)&lt;br /&gt;
|-&lt;br /&gt;
| Jan 23, 2014 || OWASP Foundation ||Venue Deposit for OWASP Free Training at Jillian's in SFO || $5,000.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| Jan 24, 2014 || OWASP Foundation ||Membership Flyers and Supplies for OWASP Free Training in SFO || $257.48 USD&lt;br /&gt;
|-&lt;br /&gt;
| Feb 18, 2014 || OWASP Foundation || Amazon gift card for Connector Puzzle Winner || $10.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| Feb 18, 2014 || Tony Turner || OWASP Lanyards for Bsides Orlando (Orlando OWASP Chapter) || $428.16 USD&lt;br /&gt;
|-&lt;br /&gt;
| March 11, 2014 || Jonathan Marcil || Banner and Merchandise for Confoo Conference (Montreal OWASP Chapter) || $837.91 USD&lt;br /&gt;
|-&lt;br /&gt;
| March 17, 2014 || Eoin Keary || Hotel Room for OWASP Free Training at Jillian's in SFO || $975.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| March 28, 2014 || Tony Turner || OWASP Lanyards for Bsides Orlando (Orlando OWASP Chapter) || $500 USD&lt;br /&gt;
|-&lt;br /&gt;
| March 28, 2014 || OWASP Foundation || Membership Flyers for Info Sec World Conference &amp;amp; Expo 2014 (Co-Marketing Agreement) || $261.99 USD&lt;br /&gt;
|-&lt;br /&gt;
| March 28, 2014 || PR with Brains || PR and media support for foundation annoucements || $500.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| March 31, 2014 || Jonathan Marcil || Notepads, rockets, stressballs, and stickers for NorthSec 2014 || $824.35 USD&lt;br /&gt;
|-&lt;br /&gt;
| April 11, 2014 || Ahmed Neil || Flight &amp;amp; Hotel for outreach event in Prague || $1098.86 USD&lt;br /&gt;
|-&lt;br /&gt;
| April 15, 2014 || Mario Heiderich || Projected reimbursement for travel and lodging to speak at OWASP Edinburgh || $500.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| May 1, 2014 || Glib Pakharenko || Projected reimbursement for travel and lodging for speaker at OWASP Ukraine || $500.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| May 7, 2014 || Martin Knobloch || Merchandise for HITB 2014 Outreach || $500.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| May 19, 2014 ||  Justin Clarke|| Printing Flyers for Outreach Event || $308.53 (180.42 GBP)&lt;br /&gt;
|-&lt;br /&gt;
| May 22, 2014 || Azzeddine RAMRAMI|| Flight from Paris to Rabat, Morocco to facilitate as an OWASP Partner to the Moroccan Cyber Security Challenge 4th Edition || $514.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| May 27, 2014 || Mat Caughron|| Merch sent to Kansas City for Kansas City Developer's Conference (Outreach) || $500.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| June 11, 2014 || Oana Cornea|| Flyers for DevTalks 2014 || $160.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| July 7, 2014 || Anurag Agarwal|| Reimbursement for flight and travel expenses to speak at Columbus, Ohio chapter meeting || $437.49&lt;br /&gt;
|-&lt;br /&gt;
| July 8, 2014 || Fabio Cerullo|| [https://www.owasp.org/index.php/Winter_Code_Sprint Initiative - Fall/Winer Code Spring (to be spent by March 2015)] || $5000.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| Fall 2014 || Asia Tour || Fall 2014 - China (3 chapters), Haerbin, Wuhan, Chengdu, Indonesia, Singapore, Malaysia, Korea, Thailand|| $12,000 USD&lt;br /&gt;
|-&lt;br /&gt;
| Sept 23, 2014 || Josh Sokol|| OWASP Presence at Univ. of Texas Cybersecurity Awareness event || $500.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| Sept 29, 2014 || Alexandre Sobrinho|| Speaker funds-Mario Heiderich's visit to Scotland community for a talk on mXSS || $412.30 USD&lt;br /&gt;
|-&lt;br /&gt;
| Oct 10, 2014 || Azzeddine Ramrami|| OWASP Local Chapter Representation at Morocco Java User Group JMaghreb, Booth &amp;amp; Travel || $1,000.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| Oct 14, 2014 || Theo Sagoe - OWASP Ghana || Ghana Regional OWASP event - Speakers, Venue, Merchandise-POSTPONED.  Merchandise sent for regional community engagement || $1,000.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| Oct 17, 2014 || Patrick Leclerc-Quebec Chapter w/Ottawa || Presence &amp;amp; Merchandise @ Canadian Hackfest(400) &amp;amp; ICCE (400) || $800.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| Nov 3, 2014 || Florian Stahl-Project Lead Top 10 Privacy Risks || Speaker/Travel funds- IAPP Global Privacy Summit 4-6 March 2015 in Washington DC.  || $500.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| Nov 25, 2014 || John Patrick Lita-Chapter Founder || Support for OWASP Manila Day - New Chapter support - Funding &amp;amp; Merchandise  || $500.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| Nov 26, 2014 || Carlos Allendes - Honduras Chapter Leader || Speaker Support for OWASP Honduras Day, 2 Speakers x $500  || $1,000.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| Jan 12, 2015 || Nitin Pandey || Speaker Support for OWASP Lucknow / DEFCON event, 2 Speakers x $500  || $1,000.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| Jan 13, 2015 || John Patrick Lita-Chapter Founder || Support for OWASP Manila Chapter Meeting, Q1 2015  || $500.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| Jan 13, 2015 || Fabio Cerullo || Speaker &amp;amp; Trainer travel expenses for FOSSASIA 2015  || $500.00 USD&lt;br /&gt;
|}&lt;br /&gt;
''2014 Balance Remaining'' = $20,710.19&lt;br /&gt;
&lt;br /&gt;
==2014 Project Payments==&lt;br /&gt;
'''2014 Budget''' = $46,000 (Fund availability by quarter is $11,500).&lt;br /&gt;
&lt;br /&gt;
{| border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Date&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;250&amp;quot; | Name (Requestor)&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;450&amp;quot; | Event or Activity&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; width=&amp;quot;100&amp;quot; | Amount&lt;br /&gt;
|-&lt;br /&gt;
| Jan 9, 2014 || Samantha Groves (Operations) || Apple Developer Registration || $99.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| March 26, 2014 || Mordecai Kraushar || Project Speaker at AppSec APAC 2014: Tokyo, Japan || $1,588.08 USD&lt;br /&gt;
|-&lt;br /&gt;
| March 26, 2014 || Dennis Groves || Project Speaker at AppSec APAC 2014: Tokyo, Japan || $1,515.40 USD&lt;br /&gt;
|-&lt;br /&gt;
| April 29, 2014 || Hugo Costa || Graphic Design - New Project Icons || $90.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| May 9, 2014 || Marios Kourtesis || OWTF Project Presenter for Open Source Showcase at AppSec EU 2014: Cambridge, UK || $701.55 USD&lt;br /&gt;
|-&lt;br /&gt;
| June 3, 2014 || Hugo Costa || Graphic Design - Projects || $270.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| June 5, 2014 || Johanna Curiel || [https://www.owasp.org/index.php/Proposal_Project_Review_QA_Approach Project Review Framework Beta Testing] || ~$7,000 USD&lt;br /&gt;
|-&lt;br /&gt;
| June 6, 2014 || Johanna Curiel || Air and Hotel for Project Summit at AppSec Europe 2014: Cambridge, UK ||  $836.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| June 18, 2014 || Oana Cornea || Project Flyers for Outreach || $53.34 USD&lt;br /&gt;
|-&lt;br /&gt;
| June 2014 || AppSec EU || Project Summit Facilities Costs and Food|| ~$14,000.00 USD &lt;br /&gt;
|-&lt;br /&gt;
| July 11, 2014 || Jonathan Marcil || Travel and Hotel for Project Summit at AppSec Europe 2014: Cambridge, UK ||  $738.98&lt;br /&gt;
|-&lt;br /&gt;
| July 11, 2014 || Enrico Branca || Travel and Hotel for Project Summit at AppSec Europe 2014: Cambridge, UK ||  $902.94 USD&lt;br /&gt;
|-&lt;br /&gt;
| July 11, 2014 ||Ivan Buetler || Travel and Hotel for Project Summit at AppSec Europe 2014: Cambridge, UK ||  ~$633.32 USD&lt;br /&gt;
|-&lt;br /&gt;
| July 11, 2014 ||Neil Gernon || Travel and Hotel for Project Summit at AppSec Europe 2014: Cambridge, UK || $577.65 USD&lt;br /&gt;
|-&lt;br /&gt;
| July 11, 2014 || Matt Tesauro || Travel and Hotel for Project Summit at AppSec Europe 2014: Cambridge, UK ||  $2,259.66 USD &lt;br /&gt;
|-&lt;br /&gt;
| July 11, 2014 || Gary Robinson || Travel and Hotel for Project Summit at AppSec Europe 2014: Cambridge, UK ||  $646.52 USD&lt;br /&gt;
|-&lt;br /&gt;
| July 11, 2014 || Spyros Gasteratos || Travel and Hotel for Project Summit at AppSec Europe 2014: Cambridge, UK ||  ~$668.32 USD&lt;br /&gt;
|-&lt;br /&gt;
| July 11, 2014 || Hugo Costa || Graphic Design - Projects || $270.00 USD&lt;br /&gt;
|-&lt;br /&gt;
| July 31, 2014 || Richard Stallman || AppSec Europe 2014: Cambridge, UK - Speaker/Summit|| ??&lt;br /&gt;
|-&lt;br /&gt;
| Oct 3, 2014 || Jane O'Connor || Testing guide v4 writing|| $ 771.00&lt;br /&gt;
|-&lt;br /&gt;
| Oct 3, 2014 || Hugo Costa || Testing guide v4 publication &amp;amp; LuLu placement|| $ 500&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
''2014 Balance Remaining'' = $11,878.24&lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs&amp;gt;&amp;lt;/headertabs&amp;gt;&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:EPaul&amp;diff=238617</id>
		<title>User:EPaul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:EPaul&amp;diff=238617"/>
				<updated>2018-03-14T20:35:54Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Creating user page for new user.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;I'm a senior software developer for (company internal) web applications at Zalando, but not a security specialist in any means.&lt;br /&gt;
&lt;br /&gt;
I was moderator for Cryptography Stack Exchange for almost 4 years (Aug 2011 – June 2015), picking up some cryptography knowledge then.&lt;br /&gt;
(https://crypto.meta.stackexchange.com/questions/80/moderator-pro-tem-announcement)&lt;br /&gt;
&lt;br /&gt;
I just wanted to correct some mistakes in the website I noted, not write a full biography here.&lt;br /&gt;
For example, the Java class name validation regex in https://www.owasp.org/index.php/OWASP_Validation_Regex_Repository is not just vulnerable to regex DOS attacks (as noted on https://www.owasp.org/index.php/Regular_expression_Denial_of_Service_-_ReDoS#Examples and in Wikipedia), but also simply wrong, and fixing the wrongness (escaping the dot) also fixes the evilness of the regex.&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User_talk:EPaul&amp;diff=238618</id>
		<title>User talk:EPaul</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User_talk:EPaul&amp;diff=238618"/>
				<updated>2018-03-14T20:35:54Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Welcome!&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Welcome to ''OWASP''!'''&lt;br /&gt;
We hope you will contribute much and well.&lt;br /&gt;
You will probably want to read the [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents help pages].&lt;br /&gt;
Again, welcome and have fun! [[User:Claudia casanovas|Claudia Aviles-Casanovas]] ([[User talk:Claudia casanovas|talk]]) 15:35, 14 March 2018 (CDT)&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=March_7,_2018&amp;diff=238424</id>
		<title>March 7, 2018</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=March_7,_2018&amp;diff=238424"/>
				<updated>2018-03-07T17:14:46Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
Meeting Date: March 7 2018&lt;br /&gt;
&lt;br /&gt;
3:00pm - 4:00pm EST [https://www.timeanddate.com/worldclock/converted.html?iso=20180307T21&amp;amp;p1=16&amp;amp;p2=16&amp;amp;p3=676&amp;amp;p4=136&amp;amp;p5=78&amp;amp;p6=179&amp;amp;p7=224&amp;amp;p8=240&amp;amp;p9=102 Time Converter]&lt;br /&gt;
&lt;br /&gt;
Meeting Location: Virtual&lt;br /&gt;
&lt;br /&gt;
Virtual: GoToMeeting Meeting ID: 861-328-838 - https://global.gotomeeting.com/join/861328838  &lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
 AGENDA&lt;br /&gt;
&lt;br /&gt;
 CALL TO ORDER&lt;br /&gt;
&lt;br /&gt;
 CHANGES TO THE AGENDA&lt;br /&gt;
&lt;br /&gt;
 APPROVAL OF MINUTES&lt;br /&gt;
[https://docs.google.com/document/d/1Wu0Pmlsqqp74WnVB8NEvhRP-EHz-jOjZsSzRtm_c-Bw/edit?usp=sharing prior meeting minutes]&lt;br /&gt;
&lt;br /&gt;
 REPORTS&lt;br /&gt;
&lt;br /&gt;
 OLD BUSINESS&lt;br /&gt;
&lt;br /&gt;
 NEW BUSINESS&lt;br /&gt;
* Approve SAFEcode.org future cooperation - AJV (Sherif Mansour to discuss, ajv vote to be proxied by Sherif)&lt;br /&gt;
* Approve SAFEcode.org document - AJV (Sherif Mansour to discuss, ajv vote to be proxied with Sherif) &lt;br /&gt;
* Approve development of an OWASP Global Event Strategy which includes AppSec Asia (Chenxi) &lt;br /&gt;
* Approve development of an OWASP Service catalogue for Chapters and Projects. This includes access to short term technical resources such as web designers, technical writers and developers. (Sherif) &lt;br /&gt;
* Status update from staff on DefCon cooperation with Jon McCoy. (AJV)&lt;br /&gt;
* Status update from staff on AppSec Au Day with Julian Berton. (AJV)&lt;br /&gt;
* AppSec Eu 2018 Sponsorship update (Kelly)&lt;br /&gt;
** Sold 1 Diamond (sold out), 2 Gold, 5 Silver, 1 Capture the Flag &amp;amp; 1 Lanyard (sold out)&lt;br /&gt;
** Total amount sold to date: €62,450.00&lt;br /&gt;
*AppSec USA 2018 Sponsorship update (Kelly)&lt;br /&gt;
**Sold 1 Diamond (sold out), 3 Platinum, 5 Gold, 2 Silver, &amp;amp; 1 Lanyard&lt;br /&gt;
**Total amount sold to date: $211,450&lt;br /&gt;
*2018 Corporate Membership (Kelly)&lt;br /&gt;
**13 Corporate Membership payments&lt;br /&gt;
***2 Premier Members $40k&lt;br /&gt;
***11 Contributor Members $55k&lt;br /&gt;
***Total amount collected to date: $95k&lt;br /&gt;
**3 Contributor Corp Member invoices sent (waiting for payment) $15k&lt;br /&gt;
**2 Contributor Corp Member invoice requests submitted. Waiting for Virtual to send invoices $10k&lt;br /&gt;
*2018 Project &amp;amp; Program Update&lt;br /&gt;
**Google Summer of Code accepted OWASP Foundation to participate for GSOC 2018&lt;br /&gt;
***12 OWASP Project Ideas options for Students  - [[GSOC2018 Ideas|GSOC 2018 Ideas]]&lt;br /&gt;
****Student start to submit their applications on March 12th &lt;br /&gt;
****Discussions have kick started between the Project Leaders and Students&lt;br /&gt;
***24 Mentors have signed up to support the GSOC 2018 &lt;br /&gt;
***OWASP RailsGoat Project Restart Kick off will utilize the GSOC 2018 Progra&lt;br /&gt;
**Project Reviews:&lt;br /&gt;
***2 Project Reviews are listed for APPSEC EU 2018&lt;br /&gt;
****OWASP Juiceshop Project&lt;br /&gt;
****OWASP DefectDojo Project&lt;br /&gt;
**New Project on Boarding was on hold awaiting Harold Blankenship joining OWASP&lt;br /&gt;
***Looking forward to working on new project requests with Harold among other exciting improvements to Projects.&lt;br /&gt;
 COMMENTS, ANNOUNCEMENTS, AND OTHER BUSINESS&lt;br /&gt;
&lt;br /&gt;
 ADJOURNMENT&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=March_7,_2018&amp;diff=238423</id>
		<title>March 7, 2018</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=March_7,_2018&amp;diff=238423"/>
				<updated>2018-03-07T16:56:43Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
Meeting Date: March 7 2018&lt;br /&gt;
&lt;br /&gt;
3:00pm - 4:00pm EST [https://www.timeanddate.com/worldclock/converted.html?iso=20180307T21&amp;amp;p1=16&amp;amp;p2=16&amp;amp;p3=676&amp;amp;p4=136&amp;amp;p5=78&amp;amp;p6=179&amp;amp;p7=224&amp;amp;p8=240&amp;amp;p9=102 Time Converter]&lt;br /&gt;
&lt;br /&gt;
Meeting Location: Virtual&lt;br /&gt;
&lt;br /&gt;
Virtual: GoToMeeting Meeting ID: 861-328-838 - https://global.gotomeeting.com/join/861328838  &lt;br /&gt;
&lt;br /&gt;
[[International Toll Free Calling Information]]&lt;br /&gt;
&lt;br /&gt;
 AGENDA&lt;br /&gt;
&lt;br /&gt;
 CALL TO ORDER&lt;br /&gt;
&lt;br /&gt;
 CHANGES TO THE AGENDA&lt;br /&gt;
&lt;br /&gt;
 APPROVAL OF MINUTES&lt;br /&gt;
[https://docs.google.com/document/d/1Wu0Pmlsqqp74WnVB8NEvhRP-EHz-jOjZsSzRtm_c-Bw/edit?usp=sharing prior meeting minutes]&lt;br /&gt;
&lt;br /&gt;
 REPORTS&lt;br /&gt;
&lt;br /&gt;
 OLD BUSINESS&lt;br /&gt;
&lt;br /&gt;
 NEW BUSINESS&lt;br /&gt;
* Approve SAFEcode.org future cooperation - AJV (Sherif Mansour to discuss, ajv vote to be proxied by Sherif)&lt;br /&gt;
* Approve SAFEcode.org document - AJV (Sherif Mansour to discuss, ajv vote to be proxied with Sherif) &lt;br /&gt;
* Approve development of an OWASP Global Event Strategy which includes AppSec Asia (Chenxi) &lt;br /&gt;
* Approve development of an OWASP Service catalogue for Chapters and Projects. This includes access to short term technical resources such as web designers, technical writers and developers. (Sherif) &lt;br /&gt;
* Status update from staff on DefCon cooperation with Jon McCoy. (AJV)&lt;br /&gt;
* Status update from staff on AppSec Au Day with Julian Berton. (AJV)&lt;br /&gt;
* AppSec Eu 2018 Sponsorship update (Kelly)&lt;br /&gt;
** Sold 1 Diamond (sold out), 2 Gold, 5 Silver, 1 Capture the Flag &amp;amp; 1 Lanyard (sold out)&lt;br /&gt;
** Total amount sold to date: €62,450.00&lt;br /&gt;
*AppSec USA 2018 Sponsorship update (Kelly)&lt;br /&gt;
**Sold 1 Diamond (sold out), 3 Platinum, 5 Gold, 2 Silver, &amp;amp; 1 Lanyard&lt;br /&gt;
**Total amount sold to date: $211,450&lt;br /&gt;
*2018 Corporate Membership (Kelly)&lt;br /&gt;
**13 Corporate Membership payments&lt;br /&gt;
***2 Premier Members $40k&lt;br /&gt;
***11 Contributor Members $55k&lt;br /&gt;
***Total amount collected to date: $95k&lt;br /&gt;
**3 Contributor Corp Member invoices sent (waiting for payment) $15k&lt;br /&gt;
**2 Contributor Corp Member invoice requests submitted. Waiting for Virtual to send invoices $10k&lt;br /&gt;
*2018 Project &amp;amp; Program Update&lt;br /&gt;
**Google Summer of Code accepted OWASP Foundation to participate for GSOC 2018&lt;br /&gt;
***12 OWASP Project Ideas options for Students  - [[GSOC2018 Ideas|GSOC 2018 Ideas]]&lt;br /&gt;
****Student start to submit their applications on March 12th &lt;br /&gt;
****Discussion have kick started between the Project Leaders and Students&lt;br /&gt;
***24 Mentors have signed up to support the GSOC 2018 &lt;br /&gt;
***OWASP RailsGoat Project Restart Kick off will utilize the GSOC 2018 Progra&lt;br /&gt;
**Project Reviews:&lt;br /&gt;
***2 Project Reviews are listed for APPSEC EU 2018&lt;br /&gt;
****OWASP Juiceshop Project&lt;br /&gt;
****OWASP DefectDojo Project&lt;br /&gt;
**New Project on Boarding was on hold awaiting Harold Blankenship joining OWASP&lt;br /&gt;
***Looking forward to working on new project requests with Harold among other exciting improvements to Projects.&lt;br /&gt;
 COMMENTS, ANNOUNCEMENTS, AND OTHER BUSINESS&lt;br /&gt;
&lt;br /&gt;
 ADJOURNMENT&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===&lt;br /&gt;
&lt;br /&gt;
==Old Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;br /&gt;
&lt;br /&gt;
==New Business==&lt;br /&gt;
All active board proposals are listed [https://drive.google.com/folderview?id=0BxSfMVkfLvslVXdvUFV3NkxucWc&amp;amp;usp=sharing here]&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSoC&amp;diff=238160</id>
		<title>GSoC</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSoC&amp;diff=238160"/>
				<updated>2018-02-27T07:38:47Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* Subscribing as mentor */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''OWASP is applying to be a Google Summer of Code (“GSoC”) mentoring organization in 2018!'''&lt;br /&gt;
&lt;br /&gt;
Open source software is changing the world and creating the future.&lt;br /&gt;
&lt;br /&gt;
Want to help shaping it? We’re looking for students to join us in making 2018 the best Summer of Code yet!&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#FF0000&amp;quot;&amp;gt;'''STUDENTS: THE PROPOSAL SUBMISSION PERIOD WILL BE OPEN FROM MARCH 12th thru 27th 2018'''&amp;lt;/span&amp;gt;&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|March 12 16:00 UTC&lt;br /&gt;
|Student application period begins&lt;br /&gt;
|-&lt;br /&gt;
|March 27 16:00 UTC&lt;br /&gt;
|Student application deadline&lt;br /&gt;
|}&lt;br /&gt;
[https://summerofcode.withgoogle.com/ '''Google Summer of Code Program Site''']&lt;br /&gt;
* OWASP is an open community dedicated to enabling organizations to conceive, develop, acquire, operate, and maintain applications that can be trusted.&lt;br /&gt;
* All students currently enrolled in an accredited institution are welcome to participate in the Google Summer of Code 2018 program, hopefully along with the OWASP Foundation.&lt;br /&gt;
* Below you could find all the instructions on how to participate.&lt;br /&gt;
&lt;br /&gt;
== What is GSOC? ==&lt;br /&gt;
&lt;br /&gt;
The [https://developers.google.com/open-source/gsoc/ Google Summer of Code program] (“GSoC”) is designed to encourage student participation in open source development. Through GSoC, accepted student applicants will be paired with OWASP mentors that will guide them through their coding tasks.&lt;br /&gt;
&lt;br /&gt;
Benefits to students include:&lt;br /&gt;
&lt;br /&gt;
* Gaining exposure to real-world software development scenarios&lt;br /&gt;
* An opportunity for employment in areas related to their academic pursuits and&lt;br /&gt;
* Google will be offering successful student contributors a 5,500 USD stipend, enabling them to focus on their coding projects for three months. &lt;br /&gt;
&lt;br /&gt;
This program is done completely online. Students and mentors from more than 100 countries have participated in past years.&lt;br /&gt;
==Instructions common to all participants==&lt;br /&gt;
&lt;br /&gt;
All participants should take a look at the [https://developers.google.com/open-source/gsoc/faq Google Summer of Code Program Site] every now and then to be informed about updates and advice. It is also important to read the [https://developers.google.com/open-source/gsoc/faq Summer of Code FAQ], as it contains useful information.&lt;br /&gt;
All participants will need a Google account in order to join the program. You'll save some time if you create one now. Please review the [https://developers.google.com/open-source/gsoc/timeline GSOC 2018 TimeLine]&lt;br /&gt;
&lt;br /&gt;
===Programming Language===&lt;br /&gt;
&lt;br /&gt;
While the majority of OWASP tools are developed using C++/Java, we do accept other languages, including (but not limited to) Python, Ruby and C#. C++ will be accepted for any project. Submissions and ideas for projects in any other language should specifically mention the choice.&lt;br /&gt;
&lt;br /&gt;
==Instructions for students==&lt;br /&gt;
&lt;br /&gt;
Are you a student and want to code for an OWASP project? &lt;br /&gt;
Here are the steps and some tips on getting started:&lt;br /&gt;
&lt;br /&gt;
1) Think of a good idea – For reference see&lt;br /&gt;
[https://www.owasp.org/index.php/GSOC2018_Ideas GSOC 2018 Ideas].&lt;br /&gt;
&lt;br /&gt;
2) Do some research yourself based on the idea, write up a proposal draft &lt;br /&gt;
&lt;br /&gt;
3) Post it to the mailing list at [https://groups.google.com/forum/#!forum/owasp-gsoc https://groups.google.com/d/forum/owasp-gsoc] for initial discussions with OWASP mentors.&lt;br /&gt;
&lt;br /&gt;
4) Based on feedback, write a full proposal – See template below:&lt;br /&gt;
https://www.owasp.org/index.php/GSoC_SAT&lt;br /&gt;
&lt;br /&gt;
5) Submit your proposal to Google from March 12th to March 27th 2018.&lt;br /&gt;
&lt;br /&gt;
Students wishing to participate in GSoC must realize this is a formal commitment to produce code for the selected OWASP Project during three months. You will also take some resources from OWASP project leaders, who will dedicate a portion of their time to mentor you. Therefore, we'd like to have candidates who are committed to helping OWASP mission. You don't have to be a proven developer -- in fact, this whole program is meant to facilitate joining OWASP and other Open Source communities. However, experience in coding and applications are welcome.&lt;br /&gt;
&lt;br /&gt;
You should start familiarising yourself with the components that you plan on working on before the start date. OWASP Project Mentors are available on the mailing list https://groups.google.com/d/forum/owasp-gsoc for help. &lt;br /&gt;
&lt;br /&gt;
===General instructions===&lt;br /&gt;
First of all, please read the instructions common to all participants and the [https://developers.google.com/open-source/gsoc/faq GSoC FAQ]. Pay special attention to the '''Eligibility''' section of the FAQ.&lt;br /&gt;
&lt;br /&gt;
===Getting in touch===&lt;br /&gt;
* Google Group: OWASP Organization Administrators and Mentors are available at https://groups.google.com/d/forum/owasp-gsoc ready to answer any questions and discuss any idea.&lt;br /&gt;
* Mailing list: Each project has its own development mailing list (eg. ESAPI: http://lists.owasp.org/pipermail/esapi-dev/). Feel free to subscribe in order to discuss your ideas directly with the project's contributors.&lt;br /&gt;
* IRC channel: You can find us at irc.freenode.net channel #owasp-gsoc&lt;br /&gt;
&lt;br /&gt;
===Recommended steps===&lt;br /&gt;
* Read Google's instructions for participating&lt;br /&gt;
* Take a look at the list of ideas&lt;br /&gt;
* Come up with project that you're interested in&lt;br /&gt;
* Write a first draft proposal and get someone to review it for you&lt;br /&gt;
* Submit it using Google's web interface&lt;br /&gt;
&lt;br /&gt;
Coming up with an interesting idea is probably the most difficult part of all. It should be something interesting for an OWASP Project, and more importantly for you. It also has to be something that you can realistically achieve in the time available to you.&lt;br /&gt;
&lt;br /&gt;
Finding out what the most pressing issues are in the projects you're interested in is a good start. You can optionally join the mailing lists for that project: you can make acquaintance with developers and your potential mentor, as well as start learning the codebase. We recommend strongly doing that and we will look favourably on applications from students who have started to act like Open Source developers.&lt;br /&gt;
&lt;br /&gt;
===Student proposal guidelines===&lt;br /&gt;
A project proposal is what you will be judged upon. So, as a general recommendation, write a clear proposal on what you plan to do, what your project is and what it is not, etc. Several websites now contain hints and other useful information on writing up such proposals.&lt;br /&gt;
OWASP does not require a specific format or specific list of information, but there is an application template on the OWASP page in Google Melange with some specific points that you should address in your application:&lt;br /&gt;
* Who are you? What are you studying?&lt;br /&gt;
* What exactly do you intend to do? What will not be done?&lt;br /&gt;
* Why are you the right person for this task?&lt;br /&gt;
* To what extent are you familiar with the software you're proposing to work with? Have you used it? Have you read the source? Have  you modified the source?&lt;br /&gt;
* How many hours are you going to work on this a week? 10? 20? 30? 40?&lt;br /&gt;
* Do you have other commitments that we should know about? If so, please suggest a way to compensate if it will take much time away from Summer of Code.&lt;br /&gt;
* Are you comfortable working independently under a supervisor or mentor who is several thousand miles away, not to mention 12 time zones away? How will you work with your mentor to track your work? Have you worked in this style before?&lt;br /&gt;
* If your native language is not English, are you comfortable working closely with a supervisor whose native language is English? What is your native language, as that may help us find a mentor who has the same native language?&lt;br /&gt;
* Where do you live, and can we assign a mentor who is local to you so you can meet in a coffee shop for lunch?&lt;br /&gt;
&lt;br /&gt;
After you have written your proposal, you should get it reviewed. Do not rely on the OWASP mentors to do it for you via the web interface: they will only send back a proposal if they find it lacking. Instead, ask a colleague or a developer to do it for you.&lt;br /&gt;
&lt;br /&gt;
===Hints===&lt;br /&gt;
'''Submit your proposal early:''' early submissions get more attention from developers for the simple fact that they have more time to dedicate to reading them. The more people see it, the more it'll get known.&lt;br /&gt;
&lt;br /&gt;
'''Do not leave it all to the last minute:''' while it is Google that is operating the webserver, it would be wise to expect a last-minute overload on the server. So, make sure you send your application before the final rush. Also, note that the applications submitted very late will get the least attention from mentors, so you may get a low vote because of that.&lt;br /&gt;
&lt;br /&gt;
'''Keep it simple:''' we don't need a 10-page essay on the project and on you (Google won't even let you submit a text that long). You just need to be concise and precise.&lt;br /&gt;
&lt;br /&gt;
'''Know what you are talking about:''' the last thing we need is for students to submit ideas that cannot be accomplished realistically or ideas that aren't even remotely related to OWASP Projects. If your idea is unusual, be sure to explain why you have chosen OWASP to be your mentoring organisation.&lt;br /&gt;
&lt;br /&gt;
'''Aim wide:''' submit more than one proposal, to different OWASP Projects. We also recommend submitting to more than one organisation too. This will increase your chances of being chosen.&lt;br /&gt;
&lt;br /&gt;
The PostgreSQL project has also released a list of [http://www.postgresql.org/developer/summerofcodeadvice.html hints] that you can take a look.&lt;br /&gt;
&lt;br /&gt;
==Instructions for mentors==&lt;br /&gt;
===Ideas===&lt;br /&gt;
If you're a developer and you wish to participate in Summer of Code, you can do it in two ways: the first and easiest is to make a proposal in the [https://www.owasp.org/index.php/GSOC2016_Ideas ideas] page. Take a look at what the different OWASP Projects needs or what you feel should have. Feel free to submit ideas even if you cannot elaborate too much on them.&lt;br /&gt;
&lt;br /&gt;
The second possibility is to be a mentor for a more specific idea. If you wish to do that, please read the instructions common to all participants and the Summer of Code FAQ. Also, please contact the project leader for your application or module and get the go-ahead from him/her. Then edit the ideas page, adding your idea.&lt;br /&gt;
&lt;br /&gt;
Your idea proposal should be a brief description of what the project is, what the desired goals would be, what the student should know and your email address for contact. Please note, though, that the students are not required to follow your idea to the letter, so regard your proposal as just a suggestion.&lt;br /&gt;
&lt;br /&gt;
===Mentoring===&lt;br /&gt;
If you wish to help us even more, you can be an OWASP mentor. We will potentially assign a student to you who has never worked on such a large project and will need some help. Make sure you're up for the task.&lt;br /&gt;
When subscribing yourself as a mentor, please make sure that your application or module maintainer is aware of that. Ask him/her to send the Summer of Code OWASP Administrators an email confirming to know you. This is just a formality to make sure you are a real person we can trust -- the administrators cannot know all active developers by their Google account ID.&lt;br /&gt;
&lt;br /&gt;
If you would like to get an idea of what is involved in being a good mentor, be sure to read the [http://write.flossmanuals.net/gsoc-mentoring/about-this-manual/ mentoring guide]. &lt;br /&gt;
&lt;br /&gt;
You will be subscribed to a mailing list to discuss ideas. We will also require you to read the proposals as they come in and you will be allowed to vote on the proposals, according to rules we will publish later.&lt;br /&gt;
&lt;br /&gt;
Finally, know that we will never assign you to a project you do not want to work on. We will not assign you more projects than you can/want to take on either. And you will have a backup mentor, just in case something unforeseen takes place.&lt;br /&gt;
&lt;br /&gt;
===Subscribing as mentor===&lt;br /&gt;
To subscribe as mentor, you need to complete a few easy steps.&lt;br /&gt;
* Contact the OWASP GSoC administrators to let them know which project you want to mentor for&lt;br /&gt;
* Log in to [https://summerofcode.withgoogle.com/ Google Summer of Code Program Site]&lt;br /&gt;
* Apply as a mentor for OWASP&lt;br /&gt;
* Subscribe to https://groups.google.com/d/forum/owasp-gsoc&lt;br /&gt;
&lt;br /&gt;
'''The current list of GSOC 2018 Mentors are:'''&lt;br /&gt;
* Fabio Cerullo&lt;br /&gt;
* Kostas Papapanagiotou&lt;br /&gt;
* Spyros Gasteratos&lt;br /&gt;
* Bjoern Kimminich&lt;br /&gt;
* Timo Pagel &lt;br /&gt;
*Glenn ten Cate&lt;br /&gt;
*Riccardo Ten Cate&lt;br /&gt;
*Minhaz&lt;br /&gt;
*Ali Razmjo &lt;br /&gt;
*Abbas Naderi&lt;br /&gt;
*Abraham Aranguren &lt;br /&gt;
*Viyat Bhalodia &lt;br /&gt;
*Bharadwaj Machiraju &lt;br /&gt;
*Sean Auriti&lt;br /&gt;
*Sourav Badami Frank Rietta&lt;br /&gt;
*Ken Johnson&lt;br /&gt;
*Al Snow&lt;br /&gt;
*Simon Bennetts&lt;br /&gt;
*Rick Mitchell&lt;br /&gt;
*Ricardo Pereira&lt;br /&gt;
*Spyros Gasteratos&lt;br /&gt;
&lt;br /&gt;
==Instructions for OWASP Project Leaders==&lt;br /&gt;
If you are an OWASP Project Leader, you may be contacted by developers in your project about an idea he wants to submit. &lt;br /&gt;
You should judge whether the idea being proposed coincides with the general goals for your OWASP Project. If you feel that is not the case, you should reply to your developer and suggest that he modify the proposal.&lt;br /&gt;
You do not need yourself to be a mentor, but we would like you to.&lt;br /&gt;
&lt;br /&gt;
==Contact OWASP GSoC Admininstrators==&lt;br /&gt;
To reach the OWASP administrators for Summer of Code, please send an email to the GSOC Administrators below.&lt;br /&gt;
&lt;br /&gt;
'''The GSOC 2018 Administrators are:'''&lt;br /&gt;
&lt;br /&gt;
* Kostas Papapanagiotou (konstantinos@owasp.org)&lt;br /&gt;
* Claudia Casanovas (claudia.aviles-casanovas@owasp.org)&lt;br /&gt;
* Fabio Cerullo (fcerullo@owasp.org)&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Al.snow&amp;diff=237996</id>
		<title>User:Al.snow</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Al.snow&amp;diff=237996"/>
				<updated>2018-02-22T14:44:54Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Creating user page for new user.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Long time contributer to GitHub repo OWASP RailsGoat project.&lt;br /&gt;
This project was a perfect cross-section of my past web development in Ruby-on-Rails and my new interest in infosec/cybersecurity.&lt;br /&gt;
&lt;br /&gt;
I have attended local OWASP meeting for many years and have learned a lot about the web, open source security, prevention, and attacks.&lt;br /&gt;
&lt;br /&gt;
Previously I focused on working on upstream components (OWASP Top Ten/A9) on Ruby-on-Rails projects.&lt;br /&gt;
 * Fixing/monitoring security (cve)/static analysis issues,&lt;br /&gt;
 * Upgrading Rails apps,&lt;br /&gt;
 * Upgrading gems&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User_talk:Al.snow&amp;diff=237997</id>
		<title>User talk:Al.snow</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User_talk:Al.snow&amp;diff=237997"/>
				<updated>2018-02-22T14:44:54Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Welcome!&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Welcome to ''OWASP''!'''&lt;br /&gt;
We hope you will contribute much and well.&lt;br /&gt;
You will probably want to read the [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents help pages].&lt;br /&gt;
Again, welcome and have fun! [[User:Claudia casanovas|Claudia Aviles-Casanovas]] ([[User talk:Claudia casanovas|talk]]) 08:44, 22 February 2018 (CST)&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Souravbadami&amp;diff=237594</id>
		<title>User:Souravbadami</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Souravbadami&amp;diff=237594"/>
				<updated>2018-02-15T15:10:46Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Creating user page for new user.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Open Source Contributor @oppia, @zulip, @duckduckgo. CodeSprint 2017 Student @OWASP . Past @RiteKit, @linkbynet. I love to create things which works and saves at least few minutes of someone's day. I'm not getting more content on the web to right here in this highlighted box. Please bare with me for the shit I've written here ;)&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User_talk:Souravbadami&amp;diff=237595</id>
		<title>User talk:Souravbadami</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User_talk:Souravbadami&amp;diff=237595"/>
				<updated>2018-02-15T15:10:46Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: Welcome!&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''Welcome to ''OWASP''!'''&lt;br /&gt;
We hope you will contribute much and well.&lt;br /&gt;
You will probably want to read the [https://www.mediawiki.org/wiki/Special:MyLanguage/Help:Contents help pages].&lt;br /&gt;
Again, welcome and have fun! [[User:Claudia casanovas|Claudia Aviles-Casanovas]] ([[User talk:Claudia casanovas|talk]]) 09:10, 15 February 2018 (CST)&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=237516</id>
		<title>GSOC2018 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=237516"/>
				<updated>2018-02-12T23:13:22Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''OWASP Foundation has been selected as an organization to be part of the GOOGLE SUMMER CODE 2018''' &lt;br /&gt;
&lt;br /&gt;
=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:'''  &lt;br /&gt;
 '''* Read [https://developers.google.com/open-source/gsoc/ Google Summer of Code Program(GSOC)]`'''&lt;br /&gt;
 '''* Read the [[GSoC SAT]] '''&lt;br /&gt;
 * Read the [https://www.owasp.org/index.php/GSoC GSOC Student Guidelines]&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/OWASP github organization]&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
We have just included a few of the ideas we have here, for a more complete list see the issues on the ZAP bug tracker with the [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3Aproject project] label.&lt;br /&gt;
===Active Scanning WebSockets===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP has good support for websockets, and allows them to be intercepted, changed and fuzzed. Unfortunately it doesnt current support active scanning (automated attacking) of websockets.&lt;br /&gt;
&lt;br /&gt;
We would like to add active scanning support to websockets, ideally in a generic way which would allow us to reuse as many of our existing rules as are relevant. Adding additional websocket specific attacks would also be very useful.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* An plugable infrastructure that allows us to active scan websockets&lt;br /&gt;
* Converting the relevant existing scan rules to work with websockets&lt;br /&gt;
* Implementing new websocket specific scan rules&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== React Handling  ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP doesnt understand React applications as well as it should be able to.&lt;br /&gt;
&lt;br /&gt;
It would be great if ZAP had a much better understanding of such applications, including how to explore and attack them more effectively.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* ZAP able to explore React applications more effectively&lt;br /&gt;
* ZAP able to attack React applications more effectively&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* As React is written in JavaScript, good knowledge of this language is recommended. ZAP is written in Java, so some knowledge of this language would be useful. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Automated authentication detection and configuration  ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Currently a user must manually configure ZAP to handle authentication, eg as per &amp;lt;nowiki&amp;gt;https://github.com/zaproxy/zaproxy/wiki/FAQformauth&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This is time consuming and error prone.&lt;br /&gt;
&lt;br /&gt;
Ideally ZAP would help detect login and registration pages and provide more assistance when configuring authentication, ideally being able to completely automate the task for as many sort of webapps as possible.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Detect login and registration pages&lt;br /&gt;
* Provide a wizard to walk users through the process of setting up authentication, with as much assistance as possible&lt;br /&gt;
* An option to completely automate the authentication process, for as many authentication mechanisms as possible&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Zest Text Representation and Parser ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Zest is a graphical scripting language from the Mozilla Security team, and is used as the ZAP macro language.&lt;br /&gt;
&lt;br /&gt;
A standardized text representation and parser would be very useful and help its adoption.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A documented definition of a text representation for Zest&lt;br /&gt;
* A parser that converts the text representation into a working Zest script&lt;br /&gt;
* An option in the Zest java implementation to output Zest scripts text format&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* The Zest reference implementation is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Develop Bamboo Addon ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
It would be great to have an official ZAP add-on for [https://www.atlassian.com/software/bamboo Bamboo], equivalent to the one we now have for [https://wiki.jenkins.io/display/JENKINS/zap+plugin Jenkins]&lt;br /&gt;
&lt;br /&gt;
For more information about Bamboo plugins see the [https://developer.atlassian.com/server/bamboo/bamboo-plugin-guide/ Bamboo plugin guide].&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
A Bamboo addon that supports:&lt;br /&gt;
* Spidering (using the traditional and Ajax spiders)&lt;br /&gt;
* Active Scanning&lt;br /&gt;
* Authentication&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP and Bamboo are written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Your Idea ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP is a great framework for building new and innovative security testing solutions. If you have an idea that is not on this list then don't worry, you can still submit it, we have accepted original projects in previous years and have even paid a student to work on their idea when we did not get enough GSoC slots to accept all of the projects we wanted.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes ZAP even better&lt;br /&gt;
* Code that conforms to our Development Rules and Guidelines&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and AngularJS. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2018 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
Coming up with additional ideas for challenges would be part of the project scope, as the list of pre-existing ideas might not be sufficient for a GSoC project.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges in, e.g. the [https://github.com/bkimminich/juice-shop/issues/244 Order Dashboard] user story])&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) AngularJS (1.x) and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* [[User:Timo Pagel|Timo Pagel]] - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== Frontend Technology Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Development of OWASP Juice Shop started in 2014 and was based on - back then - quite recent Javascript frontend framework AngularJS 1.x along with Bootstrap 3. Several major releases later, there now are [https://github.com/bkimminich/juice-shop/issues/165 Angular 5] and [https://github.com/bkimminich/juice-shop/issues/400 Bootstrap 4] available as well as other mature web frontend frameworks. Migrating the OWASP Juice Shop to the latest version of Angular and Bootstrap is an important step to keep the application relevant as ''the most modern'' intentionally broken web application. Moving to entirely different frameworks might be taken into considerationas well.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* High-level target client-architecture overview including a migration plan with intermediary milestones&lt;br /&gt;
* Execution of migration without breaking functionality or losing tests along the way&lt;br /&gt;
* Code follows existing (or new) styleguides and passes all existing (or new) quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, experience with latest Javascript frameworks for frontend, testing and building&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== UI/Graphics Design Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The UI of OWASP Juice Shop was written following recommendations from Twitter Bootstrap to be responsive, but it never had an actual designer or graphics artist take a look or add some insight. Currently the look &amp;amp; feel comes &amp;quot;out of the box&amp;quot; from a [https://bootswatch.com Bootswatch] theme and [https://fontawesome.com Font Awesome 5] icons. This gives it a quite modern look, but also leaves it very generic. The project could greatly benefit from involvement of someone with actual UI/UX Design expertise. Having a matching theme for [https://ctfd.io CTFd] would be another big achievement for the Juice Shop.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Design concepts to pick or have the user community vote on (including color schemes, sample screens, icons etc.)&lt;br /&gt;
* Overhauling the overall UI look &amp;amp; feel, e.g. by making an individual Bootswatch theme or designing some individual icons&lt;br /&gt;
* Getting rid of the stock images by providing individually designed product images for the standard inventory of the shop&lt;br /&gt;
* Add more flexibility and options to the existing theming/customization of the UI (see [https://github.com/bkimminich/juice-shop/issues/379 #379])&lt;br /&gt;
* Design a [https://github.com/bkimminich/juice-shop-ctf/issues/9 &amp;quot;Juice Shop&amp;quot; CTFd-theme] playing well with the look &amp;amp; feel of the application&lt;br /&gt;
* Execution of migration without breaking functionality or client-side unit and end-to-end tests along the way&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the existing HTML views and CSS of the frontend&lt;br /&gt;
* Get a feeling for the high quality bar by inspecting the existing client-side unit and e2e test suites&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Strong web and graphic design experience&lt;br /&gt;
* Sophisticated HTML and CSS experience&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* [[User:Timo Pagel|Timo Pagel]] - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
You have an awesome idea to improve OWASP Juice Shop that is not on this list? Great, please submit it!&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich]&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes OWASP Juice Shop even better&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) AngularJS and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
==OWASP Security Knowledge Framework - Chatbot machine learning feature==&lt;br /&gt;
&lt;br /&gt;
=== Brief Explanation ===&lt;br /&gt;
We want to create a SKF Chatbot service using the knowledge already inside SKF like the knowledge base items, code examples and the security controls like ASVS and PCI DSS.&lt;br /&gt;
&lt;br /&gt;
The chatbot service and core of this new feature can be consumed by website’s as an addon, IDE of developers and website chat channels like Gitter.im.&lt;br /&gt;
&lt;br /&gt;
The core of the SKF Chatbot will be using machine learning to accomplish the hard task of correlating data and merging different sources as a response/answer.&lt;br /&gt;
&lt;br /&gt;
=== Expected Results ===&lt;br /&gt;
# A Defined Knowledge Base (Data Structure / DB) which can be used to define and search for entities. For example: if a query is:&lt;br /&gt;
## How to mitigate CSRF in PHP   the system should be able to understand or translate it to:  {How: intent} to {mitigate: solution} {CSRF: attack} in {PHP: programming language}  This kind of query can be further user to fetch right information in the knowledge base and provide right solution (code example) for mitigating CSRF in PHP.&lt;br /&gt;
## What is CSRF?   the system should be able to understand or translate it to:  {What: intent} is {CSRF: attack/defense}  This kind of query can be further user to fetch right information in the knowledge base that explains CSRF and provide the security control from example ASVS&lt;br /&gt;
# An ETL process to convert existing SKF Knowledge data and ASVS data to above mentioned data structure.&lt;br /&gt;
# A Chatbot (using existing frameworks) to:&lt;br /&gt;
## Understand at least two intent like (How to, What is …..) and be able to enrich the user query as mentioned above.&lt;br /&gt;
## Based on enriched query fetch relevant information from knowledge base and return.&lt;br /&gt;
# An integration to some chat system like Gitter.im, IRC, Slack etc.&lt;br /&gt;
&lt;br /&gt;
=== Knowledge Prerequisites ===&lt;br /&gt;
* Programming languages:&lt;br /&gt;
** OWASP-SKF API is build in Python 3.6/3.7&lt;br /&gt;
** OWASP-SKF Frontend is build with Angular 4 TS&lt;br /&gt;
* Machine learning enthusiastic/interest&lt;br /&gt;
&lt;br /&gt;
=== Proposal from student ===&lt;br /&gt;
* We want to ask from the student to write a proposal on how to approach the problem we described.&lt;br /&gt;
'''Mentors''':&lt;br /&gt;
&lt;br /&gt;
Riccardo ten Cate [mailto:riccardo.ten.cate@owasp.org] Glenn ten Cate [mailto:glenn.ten.cate@owasp.org] Minhaz [mailto:minhaz@owasp.org]&lt;br /&gt;
&lt;br /&gt;
==OWASP Nettacker==&lt;br /&gt;
===Brief Explanation===&lt;br /&gt;
OWASP Nettacker project is created to automate information gathering, vulnerability scanning and eventually generating a report for networks, including services, bugs, vulnerabilities, misconfigurations, and other information. This software will utilize TCP SYN, ACK, ICMP and many other protocols in order to detect and bypass Firewall/IDS/IPS devices. By leveraging a unique method in OWASP Nettacker for discovering protected services and devices such as SCADA. It would make a competitive edge compared to other scanner making it one of the bests.&lt;br /&gt;
&lt;br /&gt;
if you need more details please visit the [https://github.com/viraintel/OWASP-Nettacker GitHub page] or contact a leader([mailto:ali.razmjoo@owasp.org Ali Razmjoo Qalaei], [mailto:reza.espargham@owasp.org Reza Espargham]).&lt;br /&gt;
&lt;br /&gt;
===Getting started===&lt;br /&gt;
&lt;br /&gt;
* You may read the available documents in the [https://github.com/viraintel/OWASP-Nettacker/wiki wiki page]. Developers and users documents are separated.&lt;br /&gt;
&lt;br /&gt;
'''A Better Penetration Testing Automated Framework'''&lt;br /&gt;
&lt;br /&gt;
===Expected Results===&lt;br /&gt;
The expected results are to contribute the OWASP Nettacker framework [https://github.com/viraintel/OWASP-Nettacker/issues issues] (mostly help wanted or enhancement). Please check the GitHub repo to learn more.&lt;br /&gt;
&lt;br /&gt;
===Knowledge Prerequisites===&lt;br /&gt;
&lt;br /&gt;
* The whole framework was written in Python language. You must be familiar with Python 2.x, 3.x.&lt;br /&gt;
* Good knowledge of computer security (and penetration testing)&lt;br /&gt;
* Knowledge of OS (Linux, Windows, Mac...) and Services&lt;br /&gt;
* Familiar with IDS/IPS/Firewalls and ...&lt;br /&gt;
* To develop the API you should be familiar with HTTP, Database...&lt;br /&gt;
&lt;br /&gt;
===Mentors===&lt;br /&gt;
Mentors are: [mailto:ali.razmjoo@owasp.org Ali Razmjoo Qalaei], [mailto:abiusx@owasp.org Abbas Naderi Afooshteh]&lt;br /&gt;
&lt;br /&gt;
==OWASP OWTF==&lt;br /&gt;
'''[https://github.com/owtf/owtf Offensive Web Testing Framework (OWTF)]''' is a project focused on penetration testing efficiency and alignment of security tests to security standards like the OWASP Testing Guide (v3 and v4), the OWASP Top 10, PTES and NIST. Most of the ideas below focus on rewrite of some major components of OWTF to make it more modular. OWTF is moving to a fresh codebase with a fully Docker testing and deployment environment. If you want to get a jumpstart, check out https://github.com/owtf/owtf/tree/new-arch.&lt;br /&gt;
===OWASP OWTF - MiTM proxy interception and replay capabilities===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The OWTF man-in-the-middle proxy is written completely in Python (based on the excellent Tornado framework) and was benchmarked to be the fastest MiTM python proxy. However it lacks the useful and much need interception and replay capabilities of mitmproxy (https://github.com/mitmproxy/mitmproxy).&lt;br /&gt;
&lt;br /&gt;
The current implementation of the MiTM proxy serves its purpose very well. Its fast but its not extensible. There are a number of good use cases for being extensible&lt;br /&gt;
*ability to intercept the transactions&lt;br /&gt;
*modify or replay transaction on the fly&lt;br /&gt;
*add additional capabilities to the proxy (such as session marking/changing) without polluting the main proxy code&lt;br /&gt;
Bonus:&lt;br /&gt;
*Design and implement a proxy plugin (middleware) architecture so that the plugins can be defined separately and the user can choose what plugins to include dynamically (from the web interface).&lt;br /&gt;
*Replace the current Requester (based on urllib, urllib2) with a more robust Requester based on the new urllib3 with support for a real headless browser factory. The typical flow when requested for an authenticated browser instance (using PhantomJS)&lt;br /&gt;
&lt;br /&gt;
*The &amp;quot;Requester&amp;quot; module checks if there is any login parameters provided (i.e form-based or script - look at https://github.com/owtf/login-sessions-plugin)&lt;br /&gt;
*Create a browser instance and do the necessary login procedure&lt;br /&gt;
*Handle the browser for the URI&lt;br /&gt;
*When called to close the browser, do a clean logout and kill the browser instance.&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
'''Knowledge Prerequisite:''' Python proficiency, some previous exposure to security concepts and penetration testing is welcome but not strictly necessary as long as there is will to learn.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - Web interface enhancements===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current web interface is a mixture of Tornado Jinja templates and ReactJS. A complete UI change to a stable ReactJS-based interface should be the deliverable for this project.  Most of the hard part for the change has already been done and added in a separate branch at https://github.com/owtf/owtf/tree/develop.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT:Clean, maintainable (ES6 compatible and using recommended design patterns) React (JavaScript) code. ([https://github.com/getsentry/zeus/tree/master/webapp This] is a good example!)'''&lt;br /&gt;
*'''IMPORTANT: Thoroughly documented code along with API examples and example future components.'''&lt;br /&gt;
*'''CRITICAL''': Excellent reliability and performance.&lt;br /&gt;
*Unit tests / Functional tests and easy to setup testing environment (preferably automated).&lt;br /&gt;
'''Knowledge Prerequisite:''' Python (reading API source code and endpoints), React.JS (high proficiency) and general JavaScript proficiency.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - New plugin architecture===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current plugin system is not very useful and it is painful to browse many plugins. Most of the plugins do have much code and most of is repeated - much refactoring needed there.&lt;br /&gt;
&lt;br /&gt;
This issue is documented in detail at https://github.com/owtf/owtf/issues/905.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
&lt;br /&gt;
== OWASP CSRF Protector ==&lt;br /&gt;
[[CSRFProtector Project|OWASP CSRF Protector Project]] is a project started with the goal to help developer to mitigate CSRF in web applications with ease. It's based on [[Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet|Synchronizer Token Pattern]] and leverages an injected java-script code to provide CSRF mitigation without much developer intervention. So far it has been implemented as a [https://github.com/mebjas/CSRF-Protector-PHP PHP Library] and an [[CSRFProtector Project|Apache 2.2.x module]]. Although different libraries and frameworks provide CSRF mitigation these days - all of them require developer to explicitly inject tokens with every form. &lt;br /&gt;
===OWASP CSRF Protector - Extending the design as a python package to work with Flask and an Express JS (Node.JS) middleware===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The design of CSRF Protector involves a server side middle-ware that intercepts every incoming request and validates them for CSRF attacks. If the validation is successful the flow of control goes to business logic and the tokens are refreshed. In case of failed validation configured actions are taken. Post that, another middle ware takes care of injecting a JavaScript code (refer [https://github.com/mebjas/CSRF-Protector-PHP/blob/master/js/csrfprotector.js CSRF Protector PHP JS Code]) to HTML output. On the client side this code ensures that, for every request that require validation - the correct token is sent along with the request.&lt;br /&gt;
&lt;br /&gt;
Check [https://github.com/mebjas/CSRF-Protector-PHP/wiki GitHub Wiki] for some reference;&lt;br /&gt;
&lt;br /&gt;
The goal of this project would be to:&lt;br /&gt;
# Port this design to a python module that can be used easily with Flask - [https://github.com/mebjas/CSRF-Protector-py/projects/1?add_cards_query=is%3Aopen Kanban Board]&lt;br /&gt;
# Port this design to a node js module that can work well with express js (a popular Node.JS based framework). - [https://github.com/mebjas/CSRF-Protector-JS Initial Repo Link]&lt;br /&gt;
# Fix some outstanding issues with java-script code used in library: [https://github.com/mebjas/CSRF-Protector-PHP/issues?q=is%3Aopen+is%3Aissue+label%3AJS Issues] &lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: Clean, maintainable (ES6 compatible and using recommended design patterns) in case of Node.JS'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: Thoroughly documented code along with API examples and example future components.'''&lt;br /&gt;
*'''CRITICAL''': Excellent reliability and performance.&lt;br /&gt;
*Unit tests / Functional tests and easy to setup testing environment (preferably automated).&lt;br /&gt;
'''Knowledge Prerequisite:''' Javascript (Client Side), Python (having worked with flask preferable), Node.JS (having worked with node.js and middle wares preferable)&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Contact: [mailto:minhaz@owasp.org;minhazv@microsoft.com Minhaz A V]&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Review Guide ==&lt;br /&gt;
===Brief Explanation:===&lt;br /&gt;
&lt;br /&gt;
OWASP Code Review Guide is a technical book written for those responsible for code reviews (management, developers, security professionals). The primarily focus of this book has been divided into two main sections. Section one is why and how of code reviews and sections two is devoted to what vulnerabilities need to be to look for during a manual code review. While security scanners are improving every day the need for manual security code reviews still needs to have a prominent place in organizations SDLC (Secure development life cycle) that desires good secure code in production.&lt;br /&gt;
&lt;br /&gt;
Check OWASP Code Review Guide [https://www.owasp.org/index.php/Category:OWASP_Code_Review_Project] for some reference;&lt;br /&gt;
&lt;br /&gt;
===Needs:===&lt;br /&gt;
'''Techincal writers'''&lt;br /&gt;
&lt;br /&gt;
===Expected Results:===&lt;br /&gt;
* Move work in pdf and Adobe InDesign to OWASP wiki. See OWASP Testing Guide&lt;br /&gt;
* Move work in pdf and Adobe InDesign to GitBook format&lt;br /&gt;
* Move work in pdf and Adobe InDesign to OWASP OWASP lulu eBook format&lt;br /&gt;
&lt;br /&gt;
===Knowledge Prerequisite:===&lt;br /&gt;
Good techincal writting skills, Adode InDesign&lt;br /&gt;
&lt;br /&gt;
===Proposals from student:===&lt;br /&gt;
* Proposal on different formats to use to help increase the awareness and use of the OWASP Code Review Guide&lt;br /&gt;
* Recommendations on how to use social applications to promote OWASP Code Review Guide to developers and IT management&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* Gary Robinson [mailto:Gary.Robinson@owasp.org]  - OWASP Code Review Guide Project Leader&lt;br /&gt;
 &lt;br /&gt;
* Larry Conklin [mailto:Larry.Conklin@owasp.org] Larry Conklin - OWASP Code Review Guide Project Leader&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=237515</id>
		<title>GSOC2018 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=237515"/>
				<updated>2018-02-12T23:12:04Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* OWASP Project Requests */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;'''OWASP HAS BEEN SELECTED BY GOOGLE SUMMER CODE 2018'''&lt;br /&gt;
&lt;br /&gt;
=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order:'''  &lt;br /&gt;
 '''* Read [https://developers.google.com/open-source/gsoc/ Google Summer of Code Program(GSOC)]`'''&lt;br /&gt;
 '''* Read the [[GSoC SAT]] '''&lt;br /&gt;
 * Read the [https://www.owasp.org/index.php/GSoC GSOC Student Guidelines]&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/OWASP github organization]&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
We have just included a few of the ideas we have here, for a more complete list see the issues on the ZAP bug tracker with the [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3Aproject project] label.&lt;br /&gt;
===Active Scanning WebSockets===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP has good support for websockets, and allows them to be intercepted, changed and fuzzed. Unfortunately it doesnt current support active scanning (automated attacking) of websockets.&lt;br /&gt;
&lt;br /&gt;
We would like to add active scanning support to websockets, ideally in a generic way which would allow us to reuse as many of our existing rules as are relevant. Adding additional websocket specific attacks would also be very useful.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* An plugable infrastructure that allows us to active scan websockets&lt;br /&gt;
* Converting the relevant existing scan rules to work with websockets&lt;br /&gt;
* Implementing new websocket specific scan rules&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== React Handling  ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP doesnt understand React applications as well as it should be able to.&lt;br /&gt;
&lt;br /&gt;
It would be great if ZAP had a much better understanding of such applications, including how to explore and attack them more effectively.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* ZAP able to explore React applications more effectively&lt;br /&gt;
* ZAP able to attack React applications more effectively&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* As React is written in JavaScript, good knowledge of this language is recommended. ZAP is written in Java, so some knowledge of this language would be useful. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Automated authentication detection and configuration  ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Currently a user must manually configure ZAP to handle authentication, eg as per &amp;lt;nowiki&amp;gt;https://github.com/zaproxy/zaproxy/wiki/FAQformauth&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This is time consuming and error prone.&lt;br /&gt;
&lt;br /&gt;
Ideally ZAP would help detect login and registration pages and provide more assistance when configuring authentication, ideally being able to completely automate the task for as many sort of webapps as possible.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Detect login and registration pages&lt;br /&gt;
* Provide a wizard to walk users through the process of setting up authentication, with as much assistance as possible&lt;br /&gt;
* An option to completely automate the authentication process, for as many authentication mechanisms as possible&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Zest Text Representation and Parser ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Zest is a graphical scripting language from the Mozilla Security team, and is used as the ZAP macro language.&lt;br /&gt;
&lt;br /&gt;
A standardized text representation and parser would be very useful and help its adoption.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A documented definition of a text representation for Zest&lt;br /&gt;
* A parser that converts the text representation into a working Zest script&lt;br /&gt;
* An option in the Zest java implementation to output Zest scripts text format&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* The Zest reference implementation is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Develop Bamboo Addon ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
It would be great to have an official ZAP add-on for [https://www.atlassian.com/software/bamboo Bamboo], equivalent to the one we now have for [https://wiki.jenkins.io/display/JENKINS/zap+plugin Jenkins]&lt;br /&gt;
&lt;br /&gt;
For more information about Bamboo plugins see the [https://developer.atlassian.com/server/bamboo/bamboo-plugin-guide/ Bamboo plugin guide].&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
A Bamboo addon that supports:&lt;br /&gt;
* Spidering (using the traditional and Ajax spiders)&lt;br /&gt;
* Active Scanning&lt;br /&gt;
* Authentication&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP and Bamboo are written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Your Idea ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP is a great framework for building new and innovative security testing solutions. If you have an idea that is not on this list then don't worry, you can still submit it, we have accepted original projects in previous years and have even paid a student to work on their idea when we did not get enough GSoC slots to accept all of the projects we wanted.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes ZAP even better&lt;br /&gt;
* Code that conforms to our Development Rules and Guidelines&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and AngularJS. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2018 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
Coming up with additional ideas for challenges would be part of the project scope, as the list of pre-existing ideas might not be sufficient for a GSoC project.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges in, e.g. the [https://github.com/bkimminich/juice-shop/issues/244 Order Dashboard] user story])&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) AngularJS (1.x) and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* [[User:Timo Pagel|Timo Pagel]] - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== Frontend Technology Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Development of OWASP Juice Shop started in 2014 and was based on - back then - quite recent Javascript frontend framework AngularJS 1.x along with Bootstrap 3. Several major releases later, there now are [https://github.com/bkimminich/juice-shop/issues/165 Angular 5] and [https://github.com/bkimminich/juice-shop/issues/400 Bootstrap 4] available as well as other mature web frontend frameworks. Migrating the OWASP Juice Shop to the latest version of Angular and Bootstrap is an important step to keep the application relevant as ''the most modern'' intentionally broken web application. Moving to entirely different frameworks might be taken into considerationas well.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* High-level target client-architecture overview including a migration plan with intermediary milestones&lt;br /&gt;
* Execution of migration without breaking functionality or losing tests along the way&lt;br /&gt;
* Code follows existing (or new) styleguides and passes all existing (or new) quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, experience with latest Javascript frameworks for frontend, testing and building&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== UI/Graphics Design Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The UI of OWASP Juice Shop was written following recommendations from Twitter Bootstrap to be responsive, but it never had an actual designer or graphics artist take a look or add some insight. Currently the look &amp;amp; feel comes &amp;quot;out of the box&amp;quot; from a [https://bootswatch.com Bootswatch] theme and [https://fontawesome.com Font Awesome 5] icons. This gives it a quite modern look, but also leaves it very generic. The project could greatly benefit from involvement of someone with actual UI/UX Design expertise. Having a matching theme for [https://ctfd.io CTFd] would be another big achievement for the Juice Shop.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Design concepts to pick or have the user community vote on (including color schemes, sample screens, icons etc.)&lt;br /&gt;
* Overhauling the overall UI look &amp;amp; feel, e.g. by making an individual Bootswatch theme or designing some individual icons&lt;br /&gt;
* Getting rid of the stock images by providing individually designed product images for the standard inventory of the shop&lt;br /&gt;
* Add more flexibility and options to the existing theming/customization of the UI (see [https://github.com/bkimminich/juice-shop/issues/379 #379])&lt;br /&gt;
* Design a [https://github.com/bkimminich/juice-shop-ctf/issues/9 &amp;quot;Juice Shop&amp;quot; CTFd-theme] playing well with the look &amp;amp; feel of the application&lt;br /&gt;
* Execution of migration without breaking functionality or client-side unit and end-to-end tests along the way&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the existing HTML views and CSS of the frontend&lt;br /&gt;
* Get a feeling for the high quality bar by inspecting the existing client-side unit and e2e test suites&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Strong web and graphic design experience&lt;br /&gt;
* Sophisticated HTML and CSS experience&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* [[User:Timo Pagel|Timo Pagel]] - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
You have an awesome idea to improve OWASP Juice Shop that is not on this list? Great, please submit it!&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich]&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes OWASP Juice Shop even better&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) AngularJS and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
==OWASP Security Knowledge Framework - Chatbot machine learning feature==&lt;br /&gt;
&lt;br /&gt;
=== Brief Explanation ===&lt;br /&gt;
We want to create a SKF Chatbot service using the knowledge already inside SKF like the knowledge base items, code examples and the security controls like ASVS and PCI DSS.&lt;br /&gt;
&lt;br /&gt;
The chatbot service and core of this new feature can be consumed by website’s as an addon, IDE of developers and website chat channels like Gitter.im.&lt;br /&gt;
&lt;br /&gt;
The core of the SKF Chatbot will be using machine learning to accomplish the hard task of correlating data and merging different sources as a response/answer.&lt;br /&gt;
&lt;br /&gt;
=== Expected Results ===&lt;br /&gt;
# A Defined Knowledge Base (Data Structure / DB) which can be used to define and search for entities. For example: if a query is:&lt;br /&gt;
## How to mitigate CSRF in PHP   the system should be able to understand or translate it to:  {How: intent} to {mitigate: solution} {CSRF: attack} in {PHP: programming language}  This kind of query can be further user to fetch right information in the knowledge base and provide right solution (code example) for mitigating CSRF in PHP.&lt;br /&gt;
## What is CSRF?   the system should be able to understand or translate it to:  {What: intent} is {CSRF: attack/defense}  This kind of query can be further user to fetch right information in the knowledge base that explains CSRF and provide the security control from example ASVS&lt;br /&gt;
# An ETL process to convert existing SKF Knowledge data and ASVS data to above mentioned data structure.&lt;br /&gt;
# A Chatbot (using existing frameworks) to:&lt;br /&gt;
## Understand at least two intent like (How to, What is …..) and be able to enrich the user query as mentioned above.&lt;br /&gt;
## Based on enriched query fetch relevant information from knowledge base and return.&lt;br /&gt;
# An integration to some chat system like Gitter.im, IRC, Slack etc.&lt;br /&gt;
&lt;br /&gt;
=== Knowledge Prerequisites ===&lt;br /&gt;
* Programming languages:&lt;br /&gt;
** OWASP-SKF API is build in Python 3.6/3.7&lt;br /&gt;
** OWASP-SKF Frontend is build with Angular 4 TS&lt;br /&gt;
* Machine learning enthusiastic/interest&lt;br /&gt;
&lt;br /&gt;
=== Proposal from student ===&lt;br /&gt;
* We want to ask from the student to write a proposal on how to approach the problem we described.&lt;br /&gt;
'''Mentors''':&lt;br /&gt;
&lt;br /&gt;
Riccardo ten Cate [mailto:riccardo.ten.cate@owasp.org] Glenn ten Cate [mailto:glenn.ten.cate@owasp.org] Minhaz [mailto:minhaz@owasp.org]&lt;br /&gt;
&lt;br /&gt;
==OWASP Nettacker==&lt;br /&gt;
===Brief Explanation===&lt;br /&gt;
OWASP Nettacker project is created to automate information gathering, vulnerability scanning and eventually generating a report for networks, including services, bugs, vulnerabilities, misconfigurations, and other information. This software will utilize TCP SYN, ACK, ICMP and many other protocols in order to detect and bypass Firewall/IDS/IPS devices. By leveraging a unique method in OWASP Nettacker for discovering protected services and devices such as SCADA. It would make a competitive edge compared to other scanner making it one of the bests.&lt;br /&gt;
&lt;br /&gt;
if you need more details please visit the [https://github.com/viraintel/OWASP-Nettacker GitHub page] or contact a leader([mailto:ali.razmjoo@owasp.org Ali Razmjoo Qalaei], [mailto:reza.espargham@owasp.org Reza Espargham]).&lt;br /&gt;
&lt;br /&gt;
===Getting started===&lt;br /&gt;
&lt;br /&gt;
* You may read the available documents in the [https://github.com/viraintel/OWASP-Nettacker/wiki wiki page]. Developers and users documents are separated.&lt;br /&gt;
&lt;br /&gt;
'''A Better Penetration Testing Automated Framework'''&lt;br /&gt;
&lt;br /&gt;
===Expected Results===&lt;br /&gt;
The expected results are to contribute the OWASP Nettacker framework [https://github.com/viraintel/OWASP-Nettacker/issues issues] (mostly help wanted or enhancement). Please check the GitHub repo to learn more.&lt;br /&gt;
&lt;br /&gt;
===Knowledge Prerequisites===&lt;br /&gt;
&lt;br /&gt;
* The whole framework was written in Python language. You must be familiar with Python 2.x, 3.x.&lt;br /&gt;
* Good knowledge of computer security (and penetration testing)&lt;br /&gt;
* Knowledge of OS (Linux, Windows, Mac...) and Services&lt;br /&gt;
* Familiar with IDS/IPS/Firewalls and ...&lt;br /&gt;
* To develop the API you should be familiar with HTTP, Database...&lt;br /&gt;
&lt;br /&gt;
===Mentors===&lt;br /&gt;
Mentors are: [mailto:ali.razmjoo@owasp.org Ali Razmjoo Qalaei], [mailto:abiusx@owasp.org Abbas Naderi Afooshteh]&lt;br /&gt;
&lt;br /&gt;
==OWASP OWTF==&lt;br /&gt;
'''[https://github.com/owtf/owtf Offensive Web Testing Framework (OWTF)]''' is a project focused on penetration testing efficiency and alignment of security tests to security standards like the OWASP Testing Guide (v3 and v4), the OWASP Top 10, PTES and NIST. Most of the ideas below focus on rewrite of some major components of OWTF to make it more modular. OWTF is moving to a fresh codebase with a fully Docker testing and deployment environment. If you want to get a jumpstart, check out https://github.com/owtf/owtf/tree/new-arch.&lt;br /&gt;
===OWASP OWTF - MiTM proxy interception and replay capabilities===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The OWTF man-in-the-middle proxy is written completely in Python (based on the excellent Tornado framework) and was benchmarked to be the fastest MiTM python proxy. However it lacks the useful and much need interception and replay capabilities of mitmproxy (https://github.com/mitmproxy/mitmproxy).&lt;br /&gt;
&lt;br /&gt;
The current implementation of the MiTM proxy serves its purpose very well. Its fast but its not extensible. There are a number of good use cases for being extensible&lt;br /&gt;
*ability to intercept the transactions&lt;br /&gt;
*modify or replay transaction on the fly&lt;br /&gt;
*add additional capabilities to the proxy (such as session marking/changing) without polluting the main proxy code&lt;br /&gt;
Bonus:&lt;br /&gt;
*Design and implement a proxy plugin (middleware) architecture so that the plugins can be defined separately and the user can choose what plugins to include dynamically (from the web interface).&lt;br /&gt;
*Replace the current Requester (based on urllib, urllib2) with a more robust Requester based on the new urllib3 with support for a real headless browser factory. The typical flow when requested for an authenticated browser instance (using PhantomJS)&lt;br /&gt;
&lt;br /&gt;
*The &amp;quot;Requester&amp;quot; module checks if there is any login parameters provided (i.e form-based or script - look at https://github.com/owtf/login-sessions-plugin)&lt;br /&gt;
*Create a browser instance and do the necessary login procedure&lt;br /&gt;
*Handle the browser for the URI&lt;br /&gt;
*When called to close the browser, do a clean logout and kill the browser instance.&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
'''Knowledge Prerequisite:''' Python proficiency, some previous exposure to security concepts and penetration testing is welcome but not strictly necessary as long as there is will to learn.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - Web interface enhancements===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current web interface is a mixture of Tornado Jinja templates and ReactJS. A complete UI change to a stable ReactJS-based interface should be the deliverable for this project.  Most of the hard part for the change has already been done and added in a separate branch at https://github.com/owtf/owtf/tree/develop.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT:Clean, maintainable (ES6 compatible and using recommended design patterns) React (JavaScript) code. ([https://github.com/getsentry/zeus/tree/master/webapp This] is a good example!)'''&lt;br /&gt;
*'''IMPORTANT: Thoroughly documented code along with API examples and example future components.'''&lt;br /&gt;
*'''CRITICAL''': Excellent reliability and performance.&lt;br /&gt;
*Unit tests / Functional tests and easy to setup testing environment (preferably automated).&lt;br /&gt;
'''Knowledge Prerequisite:''' Python (reading API source code and endpoints), React.JS (high proficiency) and general JavaScript proficiency.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - New plugin architecture===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current plugin system is not very useful and it is painful to browse many plugins. Most of the plugins do have much code and most of is repeated - much refactoring needed there.&lt;br /&gt;
&lt;br /&gt;
This issue is documented in detail at https://github.com/owtf/owtf/issues/905.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
&lt;br /&gt;
== OWASP CSRF Protector ==&lt;br /&gt;
[[CSRFProtector Project|OWASP CSRF Protector Project]] is a project started with the goal to help developer to mitigate CSRF in web applications with ease. It's based on [[Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet|Synchronizer Token Pattern]] and leverages an injected java-script code to provide CSRF mitigation without much developer intervention. So far it has been implemented as a [https://github.com/mebjas/CSRF-Protector-PHP PHP Library] and an [[CSRFProtector Project|Apache 2.2.x module]]. Although different libraries and frameworks provide CSRF mitigation these days - all of them require developer to explicitly inject tokens with every form. &lt;br /&gt;
===OWASP CSRF Protector - Extending the design as a python package to work with Flask and an Express JS (Node.JS) middleware===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The design of CSRF Protector involves a server side middle-ware that intercepts every incoming request and validates them for CSRF attacks. If the validation is successful the flow of control goes to business logic and the tokens are refreshed. In case of failed validation configured actions are taken. Post that, another middle ware takes care of injecting a JavaScript code (refer [https://github.com/mebjas/CSRF-Protector-PHP/blob/master/js/csrfprotector.js CSRF Protector PHP JS Code]) to HTML output. On the client side this code ensures that, for every request that require validation - the correct token is sent along with the request.&lt;br /&gt;
&lt;br /&gt;
Check [https://github.com/mebjas/CSRF-Protector-PHP/wiki GitHub Wiki] for some reference;&lt;br /&gt;
&lt;br /&gt;
The goal of this project would be to:&lt;br /&gt;
# Port this design to a python module that can be used easily with Flask - [https://github.com/mebjas/CSRF-Protector-py/projects/1?add_cards_query=is%3Aopen Kanban Board]&lt;br /&gt;
# Port this design to a node js module that can work well with express js (a popular Node.JS based framework). - [https://github.com/mebjas/CSRF-Protector-JS Initial Repo Link]&lt;br /&gt;
# Fix some outstanding issues with java-script code used in library: [https://github.com/mebjas/CSRF-Protector-PHP/issues?q=is%3Aopen+is%3Aissue+label%3AJS Issues] &lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: Clean, maintainable (ES6 compatible and using recommended design patterns) in case of Node.JS'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: Thoroughly documented code along with API examples and example future components.'''&lt;br /&gt;
*'''CRITICAL''': Excellent reliability and performance.&lt;br /&gt;
*Unit tests / Functional tests and easy to setup testing environment (preferably automated).&lt;br /&gt;
'''Knowledge Prerequisite:''' Javascript (Client Side), Python (having worked with flask preferable), Node.JS (having worked with node.js and middle wares preferable)&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Contact: [mailto:minhaz@owasp.org;minhazv@microsoft.com Minhaz A V]&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Review Guide ==&lt;br /&gt;
===Brief Explanation:===&lt;br /&gt;
&lt;br /&gt;
OWASP Code Review Guide is a technical book written for those responsible for code reviews (management, developers, security professionals). The primarily focus of this book has been divided into two main sections. Section one is why and how of code reviews and sections two is devoted to what vulnerabilities need to be to look for during a manual code review. While security scanners are improving every day the need for manual security code reviews still needs to have a prominent place in organizations SDLC (Secure development life cycle) that desires good secure code in production.&lt;br /&gt;
&lt;br /&gt;
Check OWASP Code Review Guide [https://www.owasp.org/index.php/Category:OWASP_Code_Review_Project] for some reference;&lt;br /&gt;
&lt;br /&gt;
===Needs:===&lt;br /&gt;
'''Techincal writers'''&lt;br /&gt;
&lt;br /&gt;
===Expected Results:===&lt;br /&gt;
* Move work in pdf and Adobe InDesign to OWASP wiki. See OWASP Testing Guide&lt;br /&gt;
* Move work in pdf and Adobe InDesign to GitBook format&lt;br /&gt;
* Move work in pdf and Adobe InDesign to OWASP OWASP lulu eBook format&lt;br /&gt;
&lt;br /&gt;
===Knowledge Prerequisite:===&lt;br /&gt;
Good techincal writting skills, Adode InDesign&lt;br /&gt;
&lt;br /&gt;
===Proposals from student:===&lt;br /&gt;
* Proposal on different formats to use to help increase the awareness and use of the OWASP Code Review Guide&lt;br /&gt;
* Recommendations on how to use social applications to promote OWASP Code Review Guide to developers and IT management&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* Gary Robinson [mailto:Gary.Robinson@owasp.org]  - OWASP Code Review Guide Project Leader&lt;br /&gt;
 &lt;br /&gt;
* Larry Conklin [mailto:Larry.Conklin@owasp.org] Larry Conklin - OWASP Code Review Guide Project Leader&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=237514</id>
		<title>GSOC2018 Ideas</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=GSOC2018_Ideas&amp;diff=237514"/>
				<updated>2018-02-12T23:11:29Z</updated>
		
		<summary type="html">&lt;p&gt;Claudia casanovas: /* OWASP Project Requests */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=OWASP Project Requests=&lt;br /&gt;
&lt;br /&gt;
'''Tips to get you started in no particular order: OWASP HAS BEEN SELECTED BY GOOGLE SUMMER CODE 2018!''' &lt;br /&gt;
 '''* Read [https://developers.google.com/open-source/gsoc/ Google Summer of Code Program(GSOC)]`'''&lt;br /&gt;
 '''* Read the [[GSoC SAT]] '''&lt;br /&gt;
 * Read the [https://www.owasp.org/index.php/GSoC GSOC Student Guidelines]&lt;br /&gt;
 * Contact us through the mailing list or irc channel.&lt;br /&gt;
 * Check our [https://github.com/OWASP github organization]&lt;br /&gt;
==OWASP ZAP==&lt;br /&gt;
[[OWASP Zed Attack Proxy Project]] (ZAP) The OWASP Zed Attack Proxy (ZAP) is one of the world’s most popular free security tools and is actively maintained by hundreds of international volunteers. Previous GSoC students have implemented key parts of the ZAP core functionality and have been offered (and accepted) jobs based on their work on ZAP.&lt;br /&gt;
&lt;br /&gt;
We have just included a few of the ideas we have here, for a more complete list see the issues on the ZAP bug tracker with the [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3Aproject project] label.&lt;br /&gt;
===Active Scanning WebSockets===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP has good support for websockets, and allows them to be intercepted, changed and fuzzed. Unfortunately it doesnt current support active scanning (automated attacking) of websockets.&lt;br /&gt;
&lt;br /&gt;
We would like to add active scanning support to websockets, ideally in a generic way which would allow us to reuse as many of our existing rules as are relevant. Adding additional websocket specific attacks would also be very useful.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* An plugable infrastructure that allows us to active scan websockets&lt;br /&gt;
* Converting the relevant existing scan rules to work with websockets&lt;br /&gt;
* Implementing new websocket specific scan rules&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== React Handling  ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP doesnt understand React applications as well as it should be able to.&lt;br /&gt;
&lt;br /&gt;
It would be great if ZAP had a much better understanding of such applications, including how to explore and attack them more effectively.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* ZAP able to explore React applications more effectively&lt;br /&gt;
* ZAP able to attack React applications more effectively&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* As React is written in JavaScript, good knowledge of this language is recommended. ZAP is written in Java, so some knowledge of this language would be useful. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Automated authentication detection and configuration  ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Currently a user must manually configure ZAP to handle authentication, eg as per &amp;lt;nowiki&amp;gt;https://github.com/zaproxy/zaproxy/wiki/FAQformauth&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
&lt;br /&gt;
This is time consuming and error prone.&lt;br /&gt;
&lt;br /&gt;
Ideally ZAP would help detect login and registration pages and provide more assistance when configuring authentication, ideally being able to completely automate the task for as many sort of webapps as possible.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Detect login and registration pages&lt;br /&gt;
* Provide a wizard to walk users through the process of setting up authentication, with as much assistance as possible&lt;br /&gt;
* An option to completely automate the authentication process, for as many authentication mechanisms as possible&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Zest Text Representation and Parser ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Zest is a graphical scripting language from the Mozilla Security team, and is used as the ZAP macro language.&lt;br /&gt;
&lt;br /&gt;
A standardized text representation and parser would be very useful and help its adoption.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A documented definition of a text representation for Zest&lt;br /&gt;
* A parser that converts the text representation into a working Zest script&lt;br /&gt;
* An option in the Zest java implementation to output Zest scripts text format&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* The Zest reference implementation is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Develop Bamboo Addon ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
It would be great to have an official ZAP add-on for [https://www.atlassian.com/software/bamboo Bamboo], equivalent to the one we now have for [https://wiki.jenkins.io/display/JENKINS/zap+plugin Jenkins]&lt;br /&gt;
&lt;br /&gt;
For more information about Bamboo plugins see the [https://developer.atlassian.com/server/bamboo/bamboo-plugin-guide/ Bamboo plugin guide].&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
&lt;br /&gt;
A Bamboo addon that supports:&lt;br /&gt;
* Spidering (using the traditional and Ajax spiders)&lt;br /&gt;
* Active Scanning&lt;br /&gt;
* Authentication&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP and Bamboo are written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
=== Your Idea ===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
ZAP is a great framework for building new and innovative security testing solutions. If you have an idea that is not on this list then don't worry, you can still submit it, we have accepted original projects in previous years and have even paid a student to work on their idea when we did not get enough GSoC slots to accept all of the projects we wanted.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes ZAP even better&lt;br /&gt;
* Code that conforms to our Development Rules and Guidelines&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
&lt;br /&gt;
* Have a look at the ZAP [https://github.com/zaproxy/zaproxy/blob/develop/CONTRIBUTING.md CONTRIBUTING.md] file, especially the 'Coding section.&lt;br /&gt;
* We like to see students who have already contributed to ZAP, so try fixing one of the bugs flagged as [https://github.com/zaproxy/zaproxy/issues?q=is%3Aopen+is%3Aissue+label%3AIdealFirstBug IdealFirstBug].&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* ZAP is written in Java, so a good knowledge of this language is recommended. Some knowledge of application security would be useful, but not essential.&lt;br /&gt;
'''Mentors:''' [https://www.owasp.org/index.php/User:Psiinon Simon Bennetts] [mailto:psiinon@gmail.com @] and the rest of the ZAP Core Team&lt;br /&gt;
&lt;br /&gt;
== OWASP Juice Shop ==&lt;br /&gt;
&lt;br /&gt;
[[OWASP Juice Shop Project]] is an intentionally insecure webapp for security trainings written entirely in Javascript which encompasses the entire OWASP Top Ten and other severe security flaws. Juice Shop is written in Node.js, Express and AngularJS. The application contains more than 30 challenges of varying difficulty where the user is supposed to exploit the underlying vulnerabilities. Apart from the hacker and awareness training use case, pentesting proxies or security scanners can use Juice Shop as a &amp;quot;guinea pig&amp;quot;-application to check how well their tools cope with Javascript-heavy application frontends and REST APIs.&lt;br /&gt;
&lt;br /&gt;
=== Challenge Pack 2018 ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Ideas for potential new hacking challenges are collected in [https://github.com/bkimminich/juice-shop/issues?q=is%3Aissue+is%3Aopen+label%3Achallenge GitHub issues labeled &amp;quot;challenge&amp;quot;]. This project could implement a whole bunch of challenges one by one and release them over the course of several small releases. This would allow the student to work in a professional Continuous Delivery kind of way while bringing benefit to the Juice Shop over the duration of the project.&lt;br /&gt;
&lt;br /&gt;
Coming up with additional ideas for challenges would be part of the project scope, as the list of pre-existing ideas might not be sufficient for a GSoC project.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* 10 or more new challenges for OWASP Juice Shop (including required functional enhancements to place the challenges in, e.g. the [https://github.com/bkimminich/juice-shop/issues/244 Order Dashboard] user story])&lt;br /&gt;
* Each challenge comes with full functional unit and integration tests&lt;br /&gt;
* Each challenge is verified to be exploitable by corresponding end-to-end tests&lt;br /&gt;
* Hint and solution sections for each new challenge are added to the &amp;quot;Pwning OWASP Juice Shop&amp;quot; ebook&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) AngularJS (1.x) and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* [[User:Timo Pagel|Timo Pagel]] - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== Frontend Technology Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
Development of OWASP Juice Shop started in 2014 and was based on - back then - quite recent Javascript frontend framework AngularJS 1.x along with Bootstrap 3. Several major releases later, there now are [https://github.com/bkimminich/juice-shop/issues/165 Angular 5] and [https://github.com/bkimminich/juice-shop/issues/400 Bootstrap 4] available as well as other mature web frontend frameworks. Migrating the OWASP Juice Shop to the latest version of Angular and Bootstrap is an important step to keep the application relevant as ''the most modern'' intentionally broken web application. Moving to entirely different frameworks might be taken into considerationas well.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* High-level target client-architecture overview including a migration plan with intermediary milestones&lt;br /&gt;
* Execution of migration without breaking functionality or losing tests along the way&lt;br /&gt;
* Code follows existing (or new) styleguides and passes all existing (or new) quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the architecture and code base of the application's rich Javascript frontend and RESTful backend&lt;br /&gt;
* Get a feeling for the high code &amp;amp; test quality bar by inspecting the existing test suites and static code analysis results&lt;br /&gt;
* Get familiar with the CI/CD process based on Travis-CI and several associated 3rd party services&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, experience with latest Javascript frameworks for frontend, testing and building&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== UI/Graphics Design Update ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The UI of OWASP Juice Shop was written following recommendations from Twitter Bootstrap to be responsive, but it never had an actual designer or graphics artist take a look or add some insight. Currently the look &amp;amp; feel comes &amp;quot;out of the box&amp;quot; from a [https://bootswatch.com Bootswatch] theme and [https://fontawesome.com Font Awesome 5] icons. This gives it a quite modern look, but also leaves it very generic. The project could greatly benefit from involvement of someone with actual UI/UX Design expertise. Having a matching theme for [https://ctfd.io CTFd] would be another big achievement for the Juice Shop.&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* Design concepts to pick or have the user community vote on (including color schemes, sample screens, icons etc.)&lt;br /&gt;
* Overhauling the overall UI look &amp;amp; feel, e.g. by making an individual Bootswatch theme or designing some individual icons&lt;br /&gt;
* Getting rid of the stock images by providing individually designed product images for the standard inventory of the shop&lt;br /&gt;
* Add more flexibility and options to the existing theming/customization of the UI (see [https://github.com/bkimminich/juice-shop/issues/379 #379])&lt;br /&gt;
* Design a [https://github.com/bkimminich/juice-shop-ctf/issues/9 &amp;quot;Juice Shop&amp;quot; CTFd-theme] playing well with the look &amp;amp; feel of the application&lt;br /&gt;
* Execution of migration without breaking functionality or client-side unit and end-to-end tests along the way&lt;br /&gt;
&lt;br /&gt;
''' Getting started: '''&lt;br /&gt;
* Get familiar with the existing HTML views and CSS of the frontend&lt;br /&gt;
* Get a feeling for the high quality bar by inspecting the existing client-side unit and e2e test suites&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Strong web and graphic design experience&lt;br /&gt;
* Sophisticated HTML and CSS experience&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
* [[User:Timo Pagel|Timo Pagel]] - OWASP Juice Shop Project Collaborator&lt;br /&gt;
* Jannik Hollenbach - OWASP Juice Shop Project Collaborator&lt;br /&gt;
&lt;br /&gt;
=== Your idea ===&lt;br /&gt;
&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
You have an awesome idea to improve OWASP Juice Shop that is not on this list? Great, please submit it!&lt;br /&gt;
&lt;br /&gt;
''' Getting started '''&lt;br /&gt;
* Get in touch with [https://www.owasp.org/index.php/User:Bjoern_Kimminich Bjoern Kimminich]&lt;br /&gt;
&lt;br /&gt;
'''Expected Results:'''&lt;br /&gt;
* A new feature that makes OWASP Juice Shop even better&lt;br /&gt;
* Code follows existing styleguides and passes all existing quality gates regarding code smells, test coverage etc.&lt;br /&gt;
&lt;br /&gt;
'''Knowledge Prerequisites:'''&lt;br /&gt;
* Javascript, Unit/Integration testing, experience with (or willingness to learn) AngularJS and NodeJS/Express, some security knowledge would be preferable.&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' &lt;br /&gt;
* [[User:Bjoern_Kimminich|Bjoern Kimminich]] - OWASP Juice Shop Project Leader&lt;br /&gt;
&lt;br /&gt;
==OWASP Security Knowledge Framework - Chatbot machine learning feature==&lt;br /&gt;
&lt;br /&gt;
=== Brief Explanation ===&lt;br /&gt;
We want to create a SKF Chatbot service using the knowledge already inside SKF like the knowledge base items, code examples and the security controls like ASVS and PCI DSS.&lt;br /&gt;
&lt;br /&gt;
The chatbot service and core of this new feature can be consumed by website’s as an addon, IDE of developers and website chat channels like Gitter.im.&lt;br /&gt;
&lt;br /&gt;
The core of the SKF Chatbot will be using machine learning to accomplish the hard task of correlating data and merging different sources as a response/answer.&lt;br /&gt;
&lt;br /&gt;
=== Expected Results ===&lt;br /&gt;
# A Defined Knowledge Base (Data Structure / DB) which can be used to define and search for entities. For example: if a query is:&lt;br /&gt;
## How to mitigate CSRF in PHP   the system should be able to understand or translate it to:  {How: intent} to {mitigate: solution} {CSRF: attack} in {PHP: programming language}  This kind of query can be further user to fetch right information in the knowledge base and provide right solution (code example) for mitigating CSRF in PHP.&lt;br /&gt;
## What is CSRF?   the system should be able to understand or translate it to:  {What: intent} is {CSRF: attack/defense}  This kind of query can be further user to fetch right information in the knowledge base that explains CSRF and provide the security control from example ASVS&lt;br /&gt;
# An ETL process to convert existing SKF Knowledge data and ASVS data to above mentioned data structure.&lt;br /&gt;
# A Chatbot (using existing frameworks) to:&lt;br /&gt;
## Understand at least two intent like (How to, What is …..) and be able to enrich the user query as mentioned above.&lt;br /&gt;
## Based on enriched query fetch relevant information from knowledge base and return.&lt;br /&gt;
# An integration to some chat system like Gitter.im, IRC, Slack etc.&lt;br /&gt;
&lt;br /&gt;
=== Knowledge Prerequisites ===&lt;br /&gt;
* Programming languages:&lt;br /&gt;
** OWASP-SKF API is build in Python 3.6/3.7&lt;br /&gt;
** OWASP-SKF Frontend is build with Angular 4 TS&lt;br /&gt;
* Machine learning enthusiastic/interest&lt;br /&gt;
&lt;br /&gt;
=== Proposal from student ===&lt;br /&gt;
* We want to ask from the student to write a proposal on how to approach the problem we described.&lt;br /&gt;
'''Mentors''':&lt;br /&gt;
&lt;br /&gt;
Riccardo ten Cate [mailto:riccardo.ten.cate@owasp.org] Glenn ten Cate [mailto:glenn.ten.cate@owasp.org] Minhaz [mailto:minhaz@owasp.org]&lt;br /&gt;
&lt;br /&gt;
==OWASP Nettacker==&lt;br /&gt;
===Brief Explanation===&lt;br /&gt;
OWASP Nettacker project is created to automate information gathering, vulnerability scanning and eventually generating a report for networks, including services, bugs, vulnerabilities, misconfigurations, and other information. This software will utilize TCP SYN, ACK, ICMP and many other protocols in order to detect and bypass Firewall/IDS/IPS devices. By leveraging a unique method in OWASP Nettacker for discovering protected services and devices such as SCADA. It would make a competitive edge compared to other scanner making it one of the bests.&lt;br /&gt;
&lt;br /&gt;
if you need more details please visit the [https://github.com/viraintel/OWASP-Nettacker GitHub page] or contact a leader([mailto:ali.razmjoo@owasp.org Ali Razmjoo Qalaei], [mailto:reza.espargham@owasp.org Reza Espargham]).&lt;br /&gt;
&lt;br /&gt;
===Getting started===&lt;br /&gt;
&lt;br /&gt;
* You may read the available documents in the [https://github.com/viraintel/OWASP-Nettacker/wiki wiki page]. Developers and users documents are separated.&lt;br /&gt;
&lt;br /&gt;
'''A Better Penetration Testing Automated Framework'''&lt;br /&gt;
&lt;br /&gt;
===Expected Results===&lt;br /&gt;
The expected results are to contribute the OWASP Nettacker framework [https://github.com/viraintel/OWASP-Nettacker/issues issues] (mostly help wanted or enhancement). Please check the GitHub repo to learn more.&lt;br /&gt;
&lt;br /&gt;
===Knowledge Prerequisites===&lt;br /&gt;
&lt;br /&gt;
* The whole framework was written in Python language. You must be familiar with Python 2.x, 3.x.&lt;br /&gt;
* Good knowledge of computer security (and penetration testing)&lt;br /&gt;
* Knowledge of OS (Linux, Windows, Mac...) and Services&lt;br /&gt;
* Familiar with IDS/IPS/Firewalls and ...&lt;br /&gt;
* To develop the API you should be familiar with HTTP, Database...&lt;br /&gt;
&lt;br /&gt;
===Mentors===&lt;br /&gt;
Mentors are: [mailto:ali.razmjoo@owasp.org Ali Razmjoo Qalaei], [mailto:abiusx@owasp.org Abbas Naderi Afooshteh]&lt;br /&gt;
&lt;br /&gt;
==OWASP OWTF==&lt;br /&gt;
'''[https://github.com/owtf/owtf Offensive Web Testing Framework (OWTF)]''' is a project focused on penetration testing efficiency and alignment of security tests to security standards like the OWASP Testing Guide (v3 and v4), the OWASP Top 10, PTES and NIST. Most of the ideas below focus on rewrite of some major components of OWTF to make it more modular. OWTF is moving to a fresh codebase with a fully Docker testing and deployment environment. If you want to get a jumpstart, check out https://github.com/owtf/owtf/tree/new-arch.&lt;br /&gt;
===OWASP OWTF - MiTM proxy interception and replay capabilities===&lt;br /&gt;
'''Brief Explanation:'''&lt;br /&gt;
&lt;br /&gt;
The OWTF man-in-the-middle proxy is written completely in Python (based on the excellent Tornado framework) and was benchmarked to be the fastest MiTM python proxy. However it lacks the useful and much need interception and replay capabilities of mitmproxy (https://github.com/mitmproxy/mitmproxy).&lt;br /&gt;
&lt;br /&gt;
The current implementation of the MiTM proxy serves its purpose very well. Its fast but its not extensible. There are a number of good use cases for being extensible&lt;br /&gt;
*ability to intercept the transactions&lt;br /&gt;
*modify or replay transaction on the fly&lt;br /&gt;
*add additional capabilities to the proxy (such as session marking/changing) without polluting the main proxy code&lt;br /&gt;
Bonus:&lt;br /&gt;
*Design and implement a proxy plugin (middleware) architecture so that the plugins can be defined separately and the user can choose what plugins to include dynamically (from the web interface).&lt;br /&gt;
*Replace the current Requester (based on urllib, urllib2) with a more robust Requester based on the new urllib3 with support for a real headless browser factory. The typical flow when requested for an authenticated browser instance (using PhantomJS)&lt;br /&gt;
&lt;br /&gt;
*The &amp;quot;Requester&amp;quot; module checks if there is any login parameters provided (i.e form-based or script - look at https://github.com/owtf/login-sessions-plugin)&lt;br /&gt;
*Create a browser instance and do the necessary login procedure&lt;br /&gt;
*Handle the browser for the URI&lt;br /&gt;
*When called to close the browser, do a clean logout and kill the browser instance.&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
'''Knowledge Prerequisite:''' Python proficiency, some previous exposure to security concepts and penetration testing is welcome but not strictly necessary as long as there is will to learn.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - Web interface enhancements===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current web interface is a mixture of Tornado Jinja templates and ReactJS. A complete UI change to a stable ReactJS-based interface should be the deliverable for this project.  Most of the hard part for the change has already been done and added in a separate branch at https://github.com/owtf/owtf/tree/develop.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT:Clean, maintainable (ES6 compatible and using recommended design patterns) React (JavaScript) code. ([https://github.com/getsentry/zeus/tree/master/webapp This] is a good example!)'''&lt;br /&gt;
*'''IMPORTANT: Thoroughly documented code along with API examples and example future components.'''&lt;br /&gt;
*'''CRITICAL''': Excellent reliability and performance.&lt;br /&gt;
*Unit tests / Functional tests and easy to setup testing environment (preferably automated).&lt;br /&gt;
'''Knowledge Prerequisite:''' Python (reading API source code and endpoints), React.JS (high proficiency) and general JavaScript proficiency.&lt;br /&gt;
&lt;br /&gt;
'''OWASP OWTF Mentors:''' Contact: [mailto:Abraham.Aranguren@owasp.org Abraham Aranguren][mailto:viyat.bhalodia@owasp.org Viyat Bhalodia][mailto:bharadwaj.machiraju@gmail.com Bharadwaj Machiraju] OWASP OWTF Project Leaders&lt;br /&gt;
===OWASP OWTF - New plugin architecture===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The current plugin system is not very useful and it is painful to browse many plugins. Most of the plugins do have much code and most of is repeated - much refactoring needed there.&lt;br /&gt;
&lt;br /&gt;
This issue is documented in detail at https://github.com/owtf/owtf/issues/905.&lt;br /&gt;
&lt;br /&gt;
For background on OWASP OWTF please see: https://www.owasp.org/index.php/OWASP_OWTF&lt;br /&gt;
&lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: [https://github.com/7a/owtf/wiki/Contributor%27s-README OWTF contributor README compliant code]'''&lt;br /&gt;
*'''IMPORTANT: [http://sphinx-doc.org/ Sphinx-friendly python comments] [http://owtf.github.io/ptp/_modules/ptp/tools/w3af/parser.html#W3AFXMLParser example Sphinx-friendly python comments here]'''&lt;br /&gt;
*CRITICAL: Excellent reliability&lt;br /&gt;
*Good performance&lt;br /&gt;
*Unit tests / Functional tests&lt;br /&gt;
*Good documentation&lt;br /&gt;
&lt;br /&gt;
== OWASP CSRF Protector ==&lt;br /&gt;
[[CSRFProtector Project|OWASP CSRF Protector Project]] is a project started with the goal to help developer to mitigate CSRF in web applications with ease. It's based on [[Cross-Site Request Forgery (CSRF) Prevention Cheat Sheet|Synchronizer Token Pattern]] and leverages an injected java-script code to provide CSRF mitigation without much developer intervention. So far it has been implemented as a [https://github.com/mebjas/CSRF-Protector-PHP PHP Library] and an [[CSRFProtector Project|Apache 2.2.x module]]. Although different libraries and frameworks provide CSRF mitigation these days - all of them require developer to explicitly inject tokens with every form. &lt;br /&gt;
===OWASP CSRF Protector - Extending the design as a python package to work with Flask and an Express JS (Node.JS) middleware===&lt;br /&gt;
'''Brief explanation:'''&lt;br /&gt;
&lt;br /&gt;
The design of CSRF Protector involves a server side middle-ware that intercepts every incoming request and validates them for CSRF attacks. If the validation is successful the flow of control goes to business logic and the tokens are refreshed. In case of failed validation configured actions are taken. Post that, another middle ware takes care of injecting a JavaScript code (refer [https://github.com/mebjas/CSRF-Protector-PHP/blob/master/js/csrfprotector.js CSRF Protector PHP JS Code]) to HTML output. On the client side this code ensures that, for every request that require validation - the correct token is sent along with the request.&lt;br /&gt;
&lt;br /&gt;
Check [https://github.com/mebjas/CSRF-Protector-PHP/wiki GitHub Wiki] for some reference;&lt;br /&gt;
&lt;br /&gt;
The goal of this project would be to:&lt;br /&gt;
# Port this design to a python module that can be used easily with Flask - [https://github.com/mebjas/CSRF-Protector-py/projects/1?add_cards_query=is%3Aopen Kanban Board]&lt;br /&gt;
# Port this design to a node js module that can work well with express js (a popular Node.JS based framework). - [https://github.com/mebjas/CSRF-Protector-JS Initial Repo Link]&lt;br /&gt;
# Fix some outstanding issues with java-script code used in library: [https://github.com/mebjas/CSRF-Protector-PHP/issues?q=is%3Aopen+is%3Aissue+label%3AJS Issues] &lt;br /&gt;
'''Expected results:'''&lt;br /&gt;
*'''IMPORTANT: Clean, maintainable (ES6 compatible and using recommended design patterns) in case of Node.JS'''&lt;br /&gt;
*'''IMPORTANT: [http://legacy.python.org/dev/peps/pep-0008/ PEP-8 compliant code] in all modified code and surrounding areas.'''&lt;br /&gt;
*'''IMPORTANT: Thoroughly documented code along with API examples and example future components.'''&lt;br /&gt;
*'''CRITICAL''': Excellent reliability and performance.&lt;br /&gt;
*Unit tests / Functional tests and easy to setup testing environment (preferably automated).&lt;br /&gt;
'''Knowledge Prerequisite:''' Javascript (Client Side), Python (having worked with flask preferable), Node.JS (having worked with node.js and middle wares preferable)&lt;br /&gt;
&lt;br /&gt;
'''Mentors:''' Contact: [mailto:minhaz@owasp.org;minhazv@microsoft.com Minhaz A V]&lt;br /&gt;
&lt;br /&gt;
== OWASP Code Review Guide ==&lt;br /&gt;
===Brief Explanation:===&lt;br /&gt;
&lt;br /&gt;
OWASP Code Review Guide is a technical book written for those responsible for code reviews (management, developers, security professionals). The primarily focus of this book has been divided into two main sections. Section one is why and how of code reviews and sections two is devoted to what vulnerabilities need to be to look for during a manual code review. While security scanners are improving every day the need for manual security code reviews still needs to have a prominent place in organizations SDLC (Secure development life cycle) that desires good secure code in production.&lt;br /&gt;
&lt;br /&gt;
Check OWASP Code Review Guide [https://www.owasp.org/index.php/Category:OWASP_Code_Review_Project] for some reference;&lt;br /&gt;
&lt;br /&gt;
===Needs:===&lt;br /&gt;
'''Techincal writers'''&lt;br /&gt;
&lt;br /&gt;
===Expected Results:===&lt;br /&gt;
* Move work in pdf and Adobe InDesign to OWASP wiki. See OWASP Testing Guide&lt;br /&gt;
* Move work in pdf and Adobe InDesign to GitBook format&lt;br /&gt;
* Move work in pdf and Adobe InDesign to OWASP OWASP lulu eBook format&lt;br /&gt;
&lt;br /&gt;
===Knowledge Prerequisite:===&lt;br /&gt;
Good techincal writting skills, Adode InDesign&lt;br /&gt;
&lt;br /&gt;
===Proposals from student:===&lt;br /&gt;
* Proposal on different formats to use to help increase the awareness and use of the OWASP Code Review Guide&lt;br /&gt;
* Recommendations on how to use social applications to promote OWASP Code Review Guide to developers and IT management&lt;br /&gt;
&lt;br /&gt;
'''Mentors:'''&lt;br /&gt;
* Gary Robinson [mailto:Gary.Robinson@owasp.org]  - OWASP Code Review Guide Project Leader&lt;br /&gt;
 &lt;br /&gt;
* Larry Conklin [mailto:Larry.Conklin@owasp.org] Larry Conklin - OWASP Code Review Guide Project Leader&lt;/div&gt;</summary>
		<author><name>Claudia casanovas</name></author>	</entry>

	</feed>