<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Dr.+Emin+Tatl%C4%B1</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Dr.+Emin+Tatl%C4%B1"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Dr._Emin_Tatl%C4%B1"/>
		<updated>2026-05-21T09:27:49Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196666</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196666"/>
				<updated>2015-06-29T20:32:50Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat]&lt;br /&gt;
&lt;br /&gt;
Web Page: http://www.webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
Twitter: https://twitter.com/owasptr&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, Eskişehir 2015, Conference ==&lt;br /&gt;
&lt;br /&gt;
Slides to download: [http://www.appsectr.org/?page_id=53 Application Security Day, Eskişehir 2015]&lt;br /&gt;
&lt;br /&gt;
== Chapter Meeting, İstanbul, 26th May 2014 ==&lt;br /&gt;
&lt;br /&gt;
== Attendance at Cyber Security Conference, İstanbul, 13 May 2014 ==&lt;br /&gt;
[http://www.siberguvenlikkonferansi.org/p/sponsorlar.html Cyber Security Conference 2014]&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2013, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/2013/ Application Security Day, İstanbul 2013]&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196665</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196665"/>
				<updated>2015-06-29T20:29:11Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat]&lt;br /&gt;
&lt;br /&gt;
Web Page: http://www.webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
Twitter: https://twitter.com/owasptr&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, Eskişehir 2015, Conference ==&lt;br /&gt;
&lt;br /&gt;
Slides to download: [http://www.appsectr.org/?page_id=53 Application Security Day, Eskişehir 2015]&lt;br /&gt;
&lt;br /&gt;
== Chapter Meeting, İstanbul, 26th May 2014 ==&lt;br /&gt;
&lt;br /&gt;
== Attendance at Cyber Security Conference, İstanbul, 13 May 2014 ==&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2013, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/2013/ Application Security Day, İstanbul 2013]&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196664</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196664"/>
				<updated>2015-06-29T20:23:47Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat]&lt;br /&gt;
&lt;br /&gt;
Web Page: http://www.webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
Twitter: https://twitter.com/owasptr&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, Eskişehir 2015, Conference ==&lt;br /&gt;
&lt;br /&gt;
Slides to download: [http://www.appsectr.org/?page_id=53 Application Security Day, Eskişehir 2015]&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2013, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/2013/ Application Security Day, İstanbul 2013]&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196663</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196663"/>
				<updated>2015-06-29T20:22:20Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat]&lt;br /&gt;
&lt;br /&gt;
Web Page: http://www.webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
Twitter: https://twitter.com/owasptr&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, Eskişehir 2015, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/?page_id=53 Application Security Day, Eskişehir 2015]&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2013, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/2013/ Application Security Day, İstanbul 2013]&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196662</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196662"/>
				<updated>2015-06-29T20:21:47Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat]&lt;br /&gt;
&lt;br /&gt;
Web Page: http://www.webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
Twitter: https://twitter.com/owasptr&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, Eskişehir 2015, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/?page_id=53 Application Security Day, Eskişehir 2015]&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2013, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/2013/ Application Security Day, İstanbul 2013]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196661</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196661"/>
				<updated>2015-06-29T20:20:49Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat]&lt;br /&gt;
&lt;br /&gt;
Web Page: http://www.webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
Twitter: https://twitter.com/owasptr&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, Eskişehir 2015, Conference ==&lt;br /&gt;
&lt;br /&gt;
[www.appsectr.org/?page_id=53 Application Security Day, Eskişehir 2015]&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2013, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/2013/ Application Security Day, İstanbul 2013]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196660</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196660"/>
				<updated>2015-06-29T20:15:43Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat]&lt;br /&gt;
&lt;br /&gt;
Web Page: http://www.webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
Twitter: https://twitter.com/owasptr&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196659</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196659"/>
				<updated>2015-06-29T20:14:15Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat]&lt;br /&gt;
&lt;br /&gt;
Web Page: http://www.webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196658</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196658"/>
				<updated>2015-06-29T19:59:26Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196657</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196657"/>
				<updated>2015-06-29T19:58:05Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;Webpage:&amp;lt;/b&amp;gt; http://www.webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196656</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=196656"/>
				<updated>2015-06-29T19:56:50Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Webpage: http://www.webguvenligi.org&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=189786</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=189786"/>
				<updated>2015-02-17T11:34:21Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: /* Personal &amp;amp; Work */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Assist.Prof. at İstanbul Medipol University in Turkey, http://cybersec.medipol.edu.tr&lt;br /&gt;
* Studied and worked in Germany between 2001-2013 (Ex-IBM and Ex-Daimler TSS Employee)&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design and coding trainings, compliance and risk management&lt;br /&gt;
* Research Publications @ Scholar: https://scholar.google.com.tr/citations?user=dru7fS0AAAAJ&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Involved with OWASP since 2005&lt;br /&gt;
* Since 2010 Board Member of [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of [[Germany|German Chapter]]&lt;br /&gt;
* Organisation and Program Committee of OWASP Conferences in Germany and Turkey&lt;br /&gt;
* Speaker at OWASP Turkey Web Application Security Days (http://www.appsectr.org)&lt;br /&gt;
&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
* Articles about OWASP projects &lt;br /&gt;
** [http://www.architectingsecurity.com/wp-content/uploads/papers/SAMM-Tatli-Ocak11.pdf Secure Application Development with OpenSAMM] (in Turkish)&lt;br /&gt;
** OWASP Guidelines and Tools for Secure SDLC (in German)&lt;br /&gt;
&lt;br /&gt;
* Software/Tools &lt;br /&gt;
** Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
** ccrawl - Code Review Tool: [https://code.google.com/p/ccrawl/]&lt;br /&gt;
&lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=189785</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=189785"/>
				<updated>2015-02-17T11:33:50Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: /* Personal &amp;amp; Work */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Assist.Prof. at İstanbul Medipol University in Turkey, http://cybersec.medipol.edu.tr&lt;br /&gt;
* Studied and worked in Germany between 2001-2013 (Ex-IBM and Ex-Daimler TSS Employee)&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design and coding trainings, compliance and risk management&lt;br /&gt;
* Research Publications: [Google Scholar, https://scholar.google.com.tr/citations?user=dru7fS0AAAAJ&amp;amp;hl=tr]&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Involved with OWASP since 2005&lt;br /&gt;
* Since 2010 Board Member of [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of [[Germany|German Chapter]]&lt;br /&gt;
* Organisation and Program Committee of OWASP Conferences in Germany and Turkey&lt;br /&gt;
* Speaker at OWASP Turkey Web Application Security Days (http://www.appsectr.org)&lt;br /&gt;
&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
* Articles about OWASP projects &lt;br /&gt;
** [http://www.architectingsecurity.com/wp-content/uploads/papers/SAMM-Tatli-Ocak11.pdf Secure Application Development with OpenSAMM] (in Turkish)&lt;br /&gt;
** OWASP Guidelines and Tools for Secure SDLC (in German)&lt;br /&gt;
&lt;br /&gt;
* Software/Tools &lt;br /&gt;
** Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
** ccrawl - Code Review Tool: [https://code.google.com/p/ccrawl/]&lt;br /&gt;
&lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=189784</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=189784"/>
				<updated>2015-02-17T11:33:11Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: /* Personal &amp;amp; Work */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Assist.Prof. at İstanbul Medipol University in Turkey, http://cybersec.medipol.edu.tr&lt;br /&gt;
* Studied and worked in Germany between 2001-2013 (Ex-IBM and Ex-Daimler TSS Employee)&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design and coding trainings, compliance and risk management&lt;br /&gt;
* Research Publications: [Google Scholar][https://scholar.google.com.tr/citations?user=dru7fS0AAAAJ&amp;amp;hl=tr]&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Involved with OWASP since 2005&lt;br /&gt;
* Since 2010 Board Member of [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of [[Germany|German Chapter]]&lt;br /&gt;
* Organisation and Program Committee of OWASP Conferences in Germany and Turkey&lt;br /&gt;
* Speaker at OWASP Turkey Web Application Security Days (http://www.appsectr.org)&lt;br /&gt;
&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
* Articles about OWASP projects &lt;br /&gt;
** [http://www.architectingsecurity.com/wp-content/uploads/papers/SAMM-Tatli-Ocak11.pdf Secure Application Development with OpenSAMM] (in Turkish)&lt;br /&gt;
** OWASP Guidelines and Tools for Secure SDLC (in German)&lt;br /&gt;
&lt;br /&gt;
* Software/Tools &lt;br /&gt;
** Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
** ccrawl - Code Review Tool: [https://code.google.com/p/ccrawl/]&lt;br /&gt;
&lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=189783</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=189783"/>
				<updated>2015-02-17T11:31:07Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: /* Personal &amp;amp; Work */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Assist.Prof. at İstanbul Medipol University in Turkey, http://cybersec.medipol.edu.tr&lt;br /&gt;
* Studied and worked in Germany between 2001-2013 (Ex-IBM and Ex-Daimler TSS Employee)&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design and coding trainings, compliance and risk management&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Involved with OWASP since 2005&lt;br /&gt;
* Since 2010 Board Member of [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of [[Germany|German Chapter]]&lt;br /&gt;
* Organisation and Program Committee of OWASP Conferences in Germany and Turkey&lt;br /&gt;
* Speaker at OWASP Turkey Web Application Security Days (http://www.appsectr.org)&lt;br /&gt;
&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
* Articles about OWASP projects &lt;br /&gt;
** [http://www.architectingsecurity.com/wp-content/uploads/papers/SAMM-Tatli-Ocak11.pdf Secure Application Development with OpenSAMM] (in Turkish)&lt;br /&gt;
** OWASP Guidelines and Tools for Secure SDLC (in German)&lt;br /&gt;
&lt;br /&gt;
* Software/Tools &lt;br /&gt;
** Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
** ccrawl - Code Review Tool: [https://code.google.com/p/ccrawl/]&lt;br /&gt;
&lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=189782</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=189782"/>
				<updated>2015-02-17T11:28:25Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Born in Turkey &amp;amp; Living since 2001 in Germany&lt;br /&gt;
* Ex-IBMer and working now as Security Architect and Researcher by Daimler TSS&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design and coding trainings, compliance and risk management&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Involved with OWASP since 2005&lt;br /&gt;
* Since 2010 Board Member of [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of [[Germany|German Chapter]]&lt;br /&gt;
* Organisation and Program Committee of OWASP Conferences in Germany and Turkey&lt;br /&gt;
* Speaker at OWASP Turkey Web Application Security Days (http://www.appsectr.org)&lt;br /&gt;
&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
* Articles about OWASP projects &lt;br /&gt;
** [http://www.architectingsecurity.com/wp-content/uploads/papers/SAMM-Tatli-Ocak11.pdf Secure Application Development with OpenSAMM] (in Turkish)&lt;br /&gt;
** OWASP Guidelines and Tools for Secure SDLC (in German)&lt;br /&gt;
&lt;br /&gt;
* Software/Tools &lt;br /&gt;
** Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
** ccrawl - Code Review Tool: [https://code.google.com/p/ccrawl/]&lt;br /&gt;
&lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:OWASP_Application_Security_Verification_Standard_Project&amp;diff=189781</id>
		<title>Category:OWASP Application Security Verification Standard Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:OWASP_Application_Security_Verification_Standard_Project&amp;diff=189781"/>
				<updated>2015-02-17T11:25:27Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: /* Acknowledgements */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Home =&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|2400x160px|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== What is ASVS? ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Application Security Verification Standard (ASVS) Project provides a basis for testing web application technical security controls.&lt;br /&gt;
&lt;br /&gt;
The primary aim of the '''OWASP Application Security Verification Standard (ASVS) Project''' is to normalize the range in the coverage and level of rigor available in the market when it comes to performing Web application security verification using a commercially-workable open standard. The standard provides a basis for testing application technical security controls, as well as any technical security controls in the environment, that are relied on to protect against vulnerabilities such as Cross-Site Scripting (XSS) and SQL injection. This standard can be used to establish a level of confidence in the security of Web applications. The requirements were developed with the following objectives in mind: &lt;br /&gt;
&lt;br /&gt;
*'''Use as a metric''' - Provide application developers and application owners with a yardstick with which to assess the degree of trust that can be placed in their Web applications, &lt;br /&gt;
*'''Use as guidance''' - Provide guidance to security control developers as to what to build into security controls in order to satisfy application security requirements, and &lt;br /&gt;
*'''Use during procurement''' - Provide a basis for specifying application security verification requirements in contracts.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Email List ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Asvs-bulb.jpg]] [https://lists.owasp.org/mailman/listinfo/owasp-application-security-verification-standard Project Email List]&lt;br /&gt;
&lt;br /&gt;
== Project Leaders ==&lt;br /&gt;
&lt;br /&gt;
Sahba Kazerooni&amp;lt;br/&amp;gt;&lt;br /&gt;
Daniel Cuthbert&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&lt;br /&gt;
[[Image:Asvs-satellite.jpg]]'''OWASP Resources''' &lt;br /&gt;
&lt;br /&gt;
*[http://www.owasp.org/index.php/Category:OWASP_Top_Ten_Project OWASP Top Ten] &lt;br /&gt;
*[http://www.owasp.org/index.php/Category:OWASP_Guide_Project OWASP Development Guide] &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&lt;br /&gt;
[https://www.owasp.org/images/5/58/OWASP_ASVS_Version_2.pdf Download] the standard in English.&lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
* [11 Aug 2014] Version 2.0 released!&lt;br /&gt;
* [28 Mar 2014] List of contributors added&lt;br /&gt;
* [27 Mar 2014] New wiki template!&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-flagship-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Flagship_Projects]]&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-builders-small.png|link=]]  &lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Cc-button-y-sa-small.png|link=http://creativecommons.org/licenses/by-sa/3.0/]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_DOC.jpg|link=]]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Downloads =&lt;br /&gt;
&lt;br /&gt;
'''Application Security Verification Standard 2.0 (final)'''&lt;br /&gt;
&lt;br /&gt;
* ASVS 2.0  in English ([[Media:OWASP_ASVS_Version_2.pdf|download PDF - 1.6 MB]])&lt;br /&gt;
* ASVS 2.0 in English ([[Media:OWASP_ASVS_Version_2.docx|download Word - 1.0MB]])&lt;br /&gt;
&lt;br /&gt;
We are looking for translators for this version. If you can help us, please contact the project mail list!&lt;br /&gt;
&lt;br /&gt;
'''Contributed'''&lt;br /&gt;
* Simple English Excel Reporting ([[Media:Asvs_v2_items.xlsx|download Excel - 50KB]])&lt;br /&gt;
* Simple French Excel Reporting ([[Media:Asvs_v2_items_fr.xlsx|download Excel - 35KB]])&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
== Volunteers ==&lt;br /&gt;
&lt;br /&gt;
=== Version 2 (2014) ===&lt;br /&gt;
&lt;br /&gt;
Project leaders&lt;br /&gt;
*Sahba Kazerooni&lt;br /&gt;
*Daniel Cuthbert&lt;br /&gt;
&lt;br /&gt;
Lead authors&lt;br /&gt;
*Andrew van der Stock&lt;br /&gt;
*Sahba Kazerooni&lt;br /&gt;
*Daniel Cuthbert&lt;br /&gt;
*Krishna Raja&lt;br /&gt;
&lt;br /&gt;
Other reviewers and contributors&lt;br /&gt;
*Jerome Athias&lt;br /&gt;
*Boy Baukema&lt;br /&gt;
*Archangel Cuison&lt;br /&gt;
*Sebastien.Deleersnyder&lt;br /&gt;
*Antonio Fontes&lt;br /&gt;
*Evan Gaustad&lt;br /&gt;
*Safuat Hamdy&lt;br /&gt;
*Ari Kesäniemi&lt;br /&gt;
*Scott Luc&lt;br /&gt;
*Jim Manico&lt;br /&gt;
*Mait Peekma&lt;br /&gt;
*Pekka Sillanpää&lt;br /&gt;
*Jeff Sergeant&lt;br /&gt;
*Etienne Stalmans&lt;br /&gt;
*Colin Watson&lt;br /&gt;
*Dr. Emin İslam Tatlı&lt;br /&gt;
&lt;br /&gt;
=== Version 2009 ===&lt;br /&gt;
&lt;br /&gt;
Project leader&lt;br /&gt;
*Mike Boberski&lt;br /&gt;
&lt;br /&gt;
Lead authors&lt;br /&gt;
*Mike Boberski&lt;br /&gt;
*Jeff Williams&lt;br /&gt;
*Dave Wichers&lt;br /&gt;
&lt;br /&gt;
Other reviewers and contributors&lt;br /&gt;
&lt;br /&gt;
Pierre Parrend (OWASP Summer of Code), Andrew van der Stock, Nam Nguyen, John Martin, Gaurang Shah, Theodore Winograd, Stan Wisseman, Barry Boyd, Steve Coyle, Paul Douthit, Ken Huang, Dave Hausladen, Mandeep Khera Scott Matsumoto, John Steven, Stephen de Vries, Dan Cornell, Shouvik Bardhan, Dr. Sarbari Gupta, Eoin Keary, Richard Campbell, Matt Presson, Jeff LoSapio, Liz Fong, George Lawless, Dave van Stein, Terrie Diaz, Ketan Dilipkumar Vyas, Bedirhan Urgun, Dr. Thomas Braun, Colin Watson, Jeremiah Grossman.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== OWASP Summer of Code 2008 ==&lt;br /&gt;
&lt;br /&gt;
The OWASP Foundation sponsored the OWASP Application Security Verification Standard Project during the OWASP Summer of Code 2008.&lt;br /&gt;
&lt;br /&gt;
= Glossary =&lt;br /&gt;
&lt;br /&gt;
[[Image:Asvs-letters.jpg]]'''ASVS Terminology''' &lt;br /&gt;
&lt;br /&gt;
*'''Access Control''' – A means of restricting access to files, referenced functions, URLs, and data based on the identity of users and/or groups to which they belong. &lt;br /&gt;
*'''Application Component''' – An individual or group of source files, libraries, and/or executables, as defined by the verifier for a particular application. &lt;br /&gt;
*'''Application Security''' – Application-level security focuses on the analysis of components that comprise the application layer of the Open Systems Interconnection Reference Model (OSI Model), rather than focusing on for example the underlying operating system or connected networks. &lt;br /&gt;
*'''Application Security Verification''' – The technical assessment of an application against the OWASP ASVS. &lt;br /&gt;
*'''Application Security Verification Report''' – A report that documents the overall results and supporting analysis produced by the verifier for a particular application. &lt;br /&gt;
*'''Application Security Verification Standard (ASVS)''' – An OWASP standard that defines four levels of application security verification for applications. &lt;br /&gt;
*'''Authentication''' – The verification of the claimed identity of an application user. &lt;br /&gt;
*'''Automated Verification''' – The use of automated tools (either dynamic analysis tools, static analysis tools, or both) that use vulnerability signatures to find problems. &lt;br /&gt;
*'''Back Doors''' – A type of malicious code that allows unauthorized access to an application. &lt;br /&gt;
*'''Blacklist''' – A list of data or operations that are not permitted, for example a list of characters that are not allowed as input. &lt;br /&gt;
*'''Common Criteria (CC)''' – A multipart standard that can be used as the basis for the verification of the design and implementation of security controls in IT products. &lt;br /&gt;
*'''Communication Security''' – The protection of application data when it is transmitted between application components, between clients and servers, and between external systems and the application. &lt;br /&gt;
*'''Design Verification''' – The technical assessment of the security architecture of an application. &lt;br /&gt;
*'''Internal Verification''' – The technical assessment of specific aspects of the security architecture of an application as defined in the OWASP ASVS. &lt;br /&gt;
*'''Cryptographic module''' – Hardware, software, and/or firmware that implements cryptographic algorithms and/or generates cryptographic keys. &lt;br /&gt;
*'''Denial of Service (DOS) Attacks''' – The flooding of an application with more requests than it can handle. &lt;br /&gt;
*'''Dynamic Verification''' – The use of automated tools that use vulnerability signatures to find problems during the execution of an application. &lt;br /&gt;
*'''Easter Eggs''' – A type of malicious code that does not run until a specific user input event occurs. &lt;br /&gt;
*'''External Systems''' – A server-side application or service that is not part of the application. &lt;br /&gt;
*'''FIPS 140-2''' – A standard that can be used as the basis for the verification of the design and implementation of cryptographic modules &lt;br /&gt;
*'''Input Validation''' – The canonicalization and validation of untrusted user input. &lt;br /&gt;
*'''Malicious Code''' – Code introduced into an application during its development unbeknownst to the application owner which circumvents the application’s intended security policy. Not the same as malware such as a virus or worm! &lt;br /&gt;
*'''Malware''' – Executable code that is introduced into an application during runtime without the knowledge of the application user or administrator. &lt;br /&gt;
*'''Open Web Application Security Project (OWASP)''' – The Open Web Application Security Project (OWASP) is a worldwide free and open community focused on improving the security of application software. Our mission is to make application security &amp;quot;visible,&amp;quot; so that people and organizations can make informed decisions about application security risks. See: http://www.owasp.org/ &lt;br /&gt;
*'''Output Validation''' – The canonicalization and validation of application output to Web browsers and to external systems. &lt;br /&gt;
*'''OWASP Enterprise Security API (ESAPI)''' – A free and open collection of all the security methods that developers need to build secure Web applications. See: http://www.owasp.org/index.php/ESAPI &lt;br /&gt;
*'''OWASP Risk Rating Methodology''' – A risk rating methodology that has been customized for application security. See: http://www.owasp.org/index.php/How_to_value_the_real_risk &lt;br /&gt;
*'''OWASP Testing Guide''' – A document designed to help organizations understand what comprises a testing program, and to help them identify the steps needed to build and operate that testing program. See: http://www.owasp.org/index.php/Category:OWASP_Testing_Project &lt;br /&gt;
*'''OWASP Top Ten''' – A document that represents a broad consensus about what the most critical Web application security flaws are. See: http://www.owasp.org/index.php/Top10 &lt;br /&gt;
*'''Positive''' – See whitelist. &lt;br /&gt;
*'''Salami Attack''' – A type of malicious code that is used to redirect small amounts of money without detection in financial transactions. &lt;br /&gt;
*'''Security Architecture''' – An abstraction of an application’s design that identifies and describes where and how security controls are used, and also identifies and describes the location and sensitivity of both user and application data. &lt;br /&gt;
*'''Security Control''' – A function or component that performs a security check (e.g. an access control check) or when called results in a security effect (e.g. generating an audit record). &lt;br /&gt;
*'''Security Configuration''' – The runtime configuration of an application that affects how security controls are used. &lt;br /&gt;
*'''Static Verification''' – The use of automated tools that use vulnerability signatures to find problems in application source code. &lt;br /&gt;
*'''Target of Verification (TOV)''' – If you are performing an application security verification according to the OWASP ASVS requirements, the verification will be of a particular application. This application is called the &amp;quot;Target of Verification&amp;quot; or simply the TOV. &lt;br /&gt;
*'''Threat Modeling''' - A technique consisting of developing increasingly refined security architectures to identify threat agents, security zones, security controls, and important technical and business assets. &lt;br /&gt;
*'''Time Bomb''' – A type of malicious code that does not run until a preconfigured time or date elapses. &lt;br /&gt;
*'''Verifier''' - The person or team that is reviewing an application against the OWASP ASVS requirements. &lt;br /&gt;
*'''Whitelist''' – A list of permitted data or operations, for example a list of characters that are allowed to perform input validation.&lt;br /&gt;
&lt;br /&gt;
= ASVS Users  =&lt;br /&gt;
[[Image:Asvs-handshake.JPG]]&lt;br /&gt;
&lt;br /&gt;
A broad range of companies and agencies around the globe have added ASVS to their software assurance tool boxes, including [http://www.aspectsecurity.com Aspect Security], [http://www.astyran.com Astyran], [http://www.boozallen.com Booz Allen Hamilton], [http://casabasecurity.com Casaba Security], [http://www.cgi.com/web/en/industries/governments/us_federal/services_solutions.htm CGI Federal], [http://denimgroup.com Denim Group], [http://etebaran.com Etebaran Informatics], [http://www.mindedsecurity.com Minded Security], [http://www.nixu.com Nixu], [http://www.pstestware.com/ ps_testware], [http://www.proactiverisk.com Proactive Risk], [http://quince.co.uk Quince Associates Limited (SeeMyData)], [http://www.serpro.gov.br/ Serviço Federal de Processamento de Dados (SERPRO)], [http://www.udistrital.edu.co/ Universidad Distrital Francisco José de Caldas] Organizations listed are not accredited by OWASP. Neither their products or services have been endorsed by OWASP. Use of ASVS may include for example providing verification services using the standard. Use of ASVS may also include for example performing internal evaluation of products with the OWASP ASVS in mind, and NOT making any claims of meeting any given level in the standard. Please let us know how your organization is using OWASP ASVS. Include your name, organization's name, and brief description of how you use the standard. The project lead can be reached [mailto:sahba@securitycompass.com here].&lt;br /&gt;
&lt;br /&gt;
= Precedents-Interpretations =&lt;br /&gt;
&lt;br /&gt;
'''PI-0001: Are there levels between the levels?''' &lt;br /&gt;
&lt;br /&gt;
*Issue: Are there levels between the levels for the cases where &amp;quot;The specification for an application may require OWASP ASVS Level N, but it could also include other additional detailed requirements such as from a higher ASVS level&amp;quot;? &lt;br /&gt;
*Resolution: No. Use of alternate level definitions or notations such as &amp;quot;ASVS Level 1B+&amp;quot; is discouraged. &lt;br /&gt;
*References: ASVS section &amp;quot;Application Security Verification Levels&amp;quot;&lt;br /&gt;
&lt;br /&gt;
'''PI-0002: Is use of a master key simply another level of indirection?''' &lt;br /&gt;
&lt;br /&gt;
*Issue: If a master key is stored as plaintext, isn't using a master key simply another level of indirection? &lt;br /&gt;
*Resolution: No. There is a strong rationale for having a &amp;quot;master key&amp;quot; stored in a secure location that is used to encrypt all other secrets. In many applications, there are lots of secrets stored in many different locations. This greatly increases the likelihood that one of them will be compromised. Having a single master key makes managing the protection considerably simpler and is not simply a level of indirection. &lt;br /&gt;
*References: ASVS verification requirement V2.14&lt;br /&gt;
&lt;br /&gt;
'''PI-0003: What is a &amp;quot;TOV&amp;quot; or &amp;quot;Target of Verification&amp;quot;?''' &lt;br /&gt;
&lt;br /&gt;
*Issue: New terminology &lt;br /&gt;
*Resolution: If you are performing an application security verification according to ASVS, the verification will be of a particular application. This application is called the &amp;quot;Target of Verification&amp;quot; or simply the TOV. The TOV should be identified in verification documentation as follows: &lt;br /&gt;
**TOV Identification – &amp;amp;lt;name and version of the application&amp;amp;gt; or &amp;amp;lt;Application name&amp;amp;gt;, &amp;amp;lt;application version&amp;amp;gt;, dynamic testing was performed in a staging environment, not the production environment &lt;br /&gt;
**TOV Developer – &amp;amp;lt;insert name of the developer or verification customer&amp;amp;gt; &lt;br /&gt;
*References: ASVS section &amp;quot;Approach&amp;quot;&lt;br /&gt;
&lt;br /&gt;
= Internationalization =&lt;br /&gt;
&lt;br /&gt;
[[Image:Asvs-writing.JPG]]&lt;br /&gt;
&lt;br /&gt;
The ASVS project is always on the lookout for volunteers who are interested in translating ASVS into another language. &lt;br /&gt;
&lt;br /&gt;
[http://owasp-project-management.googlecode.com/svn/trunk/documentation/asvs-translating.pdf Translation Onboarding Instructions]&lt;br /&gt;
&lt;br /&gt;
= Archive - Previous Version =&lt;br /&gt;
&lt;br /&gt;
'''*Please note that ASVS is currently on version 2.0.  The information on this page is for archival purposes only.*'''&lt;br /&gt;
&lt;br /&gt;
[[Image:Asvs-step1.jpg]]'1. About ASVS 1.0' &lt;br /&gt;
&lt;br /&gt;
*Video presentation in English [https://www.youtube.com/watch?v=Ba6ncpIfaJA (YouTube)] &lt;br /&gt;
*ASVS vs. WASC et al [http://www.owasp.org/index.php/ASVS_vs_WASC_Et_Al (Wiki)]&lt;br /&gt;
&lt;br /&gt;
[[Image:Asvs-step2.jpg]]'2. Get ASVS 1.0' &lt;br /&gt;
&lt;br /&gt;
*ASVS in Bahasa Indonesia (Indonesian language) ([http://owasp-asvs.googlecode.com/files/asvs-webapp-release-2009-id.pdf PDF])&lt;br /&gt;
*ASVS in Bahasa Malaysia (Malay) (Currently under development!)&lt;br /&gt;
*ASVS in Chinese(Currently under development!) &lt;br /&gt;
*ASVS in English ([http://www.owasp.org/images/4/4e/OWASP_ASVS_2009_Web_App_Std_Release.pdf PDF], [http://www.owasp.org/images/3/35/OWASP_ASVS_2009_Web_App_Std_Release.doc Word], [http://code.google.com/p/owasp-asvs/wiki/ASVS '''Online'''], [http://owasp-asvs.googlecode.com/svn/trunk/documentation/asvs-xml.zip XML]) &lt;br /&gt;
*ASVS in French ([http://owasp-asvs.googlecode.com/svn/trunk/documentation/asvs-webapp-release-2009-fr.pdf PDF], [http://owasp-asvs.googlecode.com/svn/trunk/documentation/asvs-webapp-release-2009-fr.odt OpenOffice]) &lt;br /&gt;
*ASVS in German ([http://owasp-asvs.googlecode.com/svn/trunk/documentation/asvs-webapp-release-2009-de.pdf PDF], [http://owasp-asvs.googlecode.com/svn/trunk/documentation/asvs-webapp-release-2009-de.doc Word])&lt;br /&gt;
*ASVS in Hungarian (Currently under development!) &lt;br /&gt;
*ASVS in Japanese ([http://owasp-asvs.googlecode.com/svn/trunk/documentation/asvs-webapp-release-2009-jp.pdf PDF], [http://owasp-asvs.googlecode.com/svn/trunk/documentation/asvs-webapp-release-2009-jp.doc Word]) &lt;br /&gt;
*ASVS in Persian (Farsi) ([http://abiusx.com/archive/document/OWASP-ASVS-fa-20111115.pdf PDF]) beta 0.7&lt;br /&gt;
*ASVS in Polish ([http://owasp-asvs.googlecode.com/files/asvs-webapp-release-2009-pl.pdf PDF])&lt;br /&gt;
*ASVS in Portuguese-Brazil ([http://owasp-asvs.googlecode.com/files/asvs-webapp-release-2009-pt-br.pdf PDF])&lt;br /&gt;
*ASVS in Spanish (Currently under development!)&lt;br /&gt;
*ASVS in Thai (Currently under development!)&lt;br /&gt;
&lt;br /&gt;
[[Image:Asvs-step3.jpg]]'3. Learn ASVS 1.0' &lt;br /&gt;
&lt;br /&gt;
*ASVS Article: Getting Started Using ASVS ([http://www.owasp.org/images/f/f8/OWASP_ASVS_Article_-_Getting_Started_Using_ASVS.pdf PDF]) &lt;br /&gt;
*ASVS Article: Code Reviews and Other Verification Activities: USELESS Unless Acted Upon IMMEDIATELY [http://www.owasp.org/index.php/Code_Reviews_and_Other_Verification_Activities:_USELESS_Unless_Acted_Upon_IMMEDIATELY (Wiki)] &lt;br /&gt;
*ASVS Article: Agile Software Development: Don't Forget EVIL User Stories ([http://www.owasp.org/index.php/Agile_Software_Development:_Don%27t_Forget_EVIL_User_Stories Wiki]) &lt;br /&gt;
*ASVS Article: Man vs. Code ([http://www.owasp.org/index.php/Man_vs._Code Wiki]) &lt;br /&gt;
*ASVS Article: Getting started designing for a level of assurance ([http://www.owasp.org/images/0/01/Getting_started_designing_for_a_level_of_assurance.pdf PDF]) &lt;br /&gt;
*ASVS Template: Sample verification fee schedule template ([http://www.owasp.org/index.php/Image:Sample_ASVS_Fee_Schedule_Template.xls Excel]) &lt;br /&gt;
*ASVS Template: Sample verification report template ([http://www.owasp.org/index.php/Image:Sample_ASVS_Report_Template.doc Word]) &lt;br /&gt;
*ASVS Training: An ASVS training presentation ([http://www.owasp.org/index.php/Image:OWASP_AU_Secure_Architecture_and_Coding.ppt PowerPoint]) &lt;br /&gt;
*ASVS Presentation: Executive-Level Presentation ([http://www.owasp.org/images/9/99/About_OWASP_ASVS_Executive_Presentation.ppt PowerPoint]) &lt;br /&gt;
*ASVS Presentation: Presentation Abstract ([http://www.owasp.org/images/1/10/OWASP_ASVS_Presentation_Abstract.doc Word]) &lt;br /&gt;
*Articles [http://www.owasp.org/index.php/Category:OWASP_Application_Security_Verification_Standard_Project#Articles_Below_-_More_About_ASVS_and_Using_It (More About ASVS and Using It)]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|Application Security Verification Standard Project]]&lt;br /&gt;
[[Category:OWASP_Document]]&lt;br /&gt;
[[Category:OWASP_Download]]&lt;br /&gt;
[[Category:OWASP_Release_Quality_Document|OWASP Stable Quality Document]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=141611</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=141611"/>
				<updated>2012-12-29T15:35:41Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Born in Turkey &amp;amp; Living since 2001 in Germany&lt;br /&gt;
* Ex-IBMer and working now as Security Architect and Researcher by Daimler TSS&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design and coding trainings, compliance and risk management&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Involved with OWASP since 2005&lt;br /&gt;
* Since 2010 Board Member of [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of [[Germany|German Chapter]]&lt;br /&gt;
* Organisation and Program Committee of OWASP Conferences in Germany and Turkey&lt;br /&gt;
&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
* Articles about OWASP projects &lt;br /&gt;
** [http://www.architectingsecurity.com/wp-content/uploads/papers/SAMM-Tatli-Ocak11.pdf Secure Application Development with OpenSAMM] (in Turkish)&lt;br /&gt;
** OWASP Guidelines and Tools for Secure SDLC (in German)&lt;br /&gt;
&lt;br /&gt;
* Software/Tools &lt;br /&gt;
** Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
** ccrawl - Code Review Tool: [https://code.google.com/p/ccrawl/]&lt;br /&gt;
&lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=141610</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=141610"/>
				<updated>2012-12-29T15:31:56Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Born in Turkey &amp;amp; Living since 2001 in Germany&lt;br /&gt;
* Ex-IBMer and working now as Security Architect and Researcher by Daimler TSS&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design&amp;amp;coding trainings, risk management&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Involved with OWASP since 2005&lt;br /&gt;
* Since 2010 Board Member of [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of [[Germany|German Chapter]]&lt;br /&gt;
* Organisation and Program Committee of OWASP Conferences in Germany and Turkey&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
* Articles about OWASP projects &lt;br /&gt;
** [http://www.architectingsecurity.com/wp-content/uploads/papers/SAMM-Tatli-Ocak11.pdf Secure Application Development with OpenSAMM] (in Turkish)&lt;br /&gt;
** OWASP Guidelines and Tools for Secure SDLC (in German)&lt;br /&gt;
&lt;br /&gt;
* Software/Tools &lt;br /&gt;
** Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
** ccrawl - Code Review Tool: [https://code.google.com/p/ccrawl/]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Category:Europe&amp;diff=140936</id>
		<title>Category:Europe</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Category:Europe&amp;diff=140936"/>
				<updated>2012-12-09T19:51:38Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{columns-list|3|&lt;br /&gt;
;'''[[Armenia]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Austria]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Belgium]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Bulgaria]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Croatia]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Cyprus]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[:Category:Czech Republic|Czech Republic]]''':[[Czech Republic]]&amp;lt;br/&amp;gt;[[Prague]]&lt;br /&gt;
----&lt;br /&gt;
;'''[[Denmark]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[:Category:Finland|Finland]]''':[[Helsinki]]&lt;br /&gt;
----&lt;br /&gt;
;'''[[France]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Germany]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Gibraltar]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Greece]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Hungary]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[:Category:Ireland|Ireland]]''':[[Ireland-Limerick|Limerick]]&amp;lt;br/&amp;gt;[[Ireland-Dublin|Dublin]]&amp;lt;br/&amp;gt;[[Galway]]&lt;br /&gt;
----&lt;br /&gt;
;'''[[:Category:Israel|Israel]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Italy]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Latvia]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Luxembourg]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Netherlands]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[:Category:Norway|Norway]]''':[[Medlemsmøter 2010]]&amp;lt;br/&amp;gt;[[Norway]]&lt;br /&gt;
----&lt;br /&gt;
;'''[[Poland]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Portugal|Portugal]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Romania]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Rostov]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[:Category:Russia|Russia]]''':[[Rostov]]&amp;lt;br/&amp;gt;[[Russia]]&lt;br /&gt;
----&lt;br /&gt;
;'''[[Scotland]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Serbia]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Slovakia]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[Slovenia]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[:Category:Spain|Spain]]''':[[Andalucia]]&amp;lt;br/&amp;gt;[[Spain]]&lt;br /&gt;
----&lt;br /&gt;
;'''[[:Category:Sweden|Sweden]]''':[[Sweden]]&amp;lt;br/&amp;gt;[[Gothenburg]]&lt;br /&gt;
----&lt;br /&gt;
;'''[[:Category:Switzerland|Switzerland]]''':[[Geneva]]&amp;lt;br/&amp;gt;[[Switzerland]]&lt;br /&gt;
----&lt;br /&gt;
;'''[[Turkey]]'''&lt;br /&gt;
----&lt;br /&gt;
;'''[[:Category:Ukraine|Ukraine]]''':[[Lviv]]&amp;lt;br/&amp;gt;[[Ukraine]]&lt;br /&gt;
----&lt;br /&gt;
;'''[[:Category:United Kingdom|United Kingdom]]''':[[Birmingham]]&amp;lt;br/&amp;gt;[[Bristol]]&amp;lt;br/&amp;gt;[[Cambridge]]&amp;lt;br/&amp;gt;[[East Midlands]]&amp;lt;br/&amp;gt;[[Leeds UK]]&amp;lt;br/&amp;gt;[[London]]&amp;lt;br/&amp;gt;[[Newcastle]]&amp;lt;br/&amp;gt;[[Royal Holloway]]&amp;lt;br/&amp;gt;[[Manchester|Manchester (UK)]]&amp;lt;br/&amp;gt;[[Scotland]]&amp;lt;br/&amp;gt;[[South Wales]]&lt;br /&gt;
&lt;br /&gt;
}}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;noinclude&amp;gt;&lt;br /&gt;
This [[:Special:Categories|category]] is meant to contain all [[:Category:OWASP Chapter|OWASP Chapters]] in Europe.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Chapter]]&lt;br /&gt;
&amp;lt;/noinclude&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=140935</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=140935"/>
				<updated>2012-12-09T19:49:26Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat], [mailto:denizcev@gmail.com Deniz Cevik]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Turkey]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Turkey&amp;diff=140934</id>
		<title>Turkey</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Turkey&amp;diff=140934"/>
				<updated>2012-12-09T19:48:54Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&amp;lt;center&amp;gt;[[File:Owasptr.png]] &amp;lt;/center&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== About OWASP/TR ====&lt;br /&gt;
 &lt;br /&gt;
{{Chapter Template|chaptername=Turkey|extra=The chapter leader is [mailto:bunyamindemir~gmail.com Bunyamin Demir], Co-leader is [mailto:urgunb~hotmail.com Bedirhan Urgun]&lt;br /&gt;
&lt;br /&gt;
Board Members:  [mailto:ferruh~mavituna.com Ferruh Mavituna], [mailto:mesut_timur~hotmail.com Mesut Timur], [mailto:contact~onuryilmaz.info Onur Yılmaz], [mailto:emin.tatli@owasp.org Emin Islam Tatli], [mailto:oguzhantopgul@gmail.com Oguzhan TOPGUL], [mailto:sertan@gmail.com Sertan Kolat], [mailto:denizcev@gmail.com Deniz Cevik]&lt;br /&gt;
&lt;br /&gt;
|mailinglistsite=http://lists.owasp.org/mailman/listinfo/owasp-turkey|emailarchives=http://lists.owasp.org/pipermail/owasp-turkey}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;paypal&amp;gt;Turkey&amp;lt;/paypal&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Chapter Brochure ==&lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/docs/WGT_brosur.pdf Here you can view a brochure] explaining in Turkish the action highlights of OWASP/Türkiye during the last one and a half year [obsolete for over two years].&lt;br /&gt;
&lt;br /&gt;
== Application Security Day, İstanbul 2012, Conference ==&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
The event aims to present an environment where key and popular application security topics will be discussed and shared. Hundreds of developers, business owners and security practitioners will be ready to increase local application security awareness. Join us!&lt;br /&gt;
&lt;br /&gt;
== Local News ==&lt;br /&gt;
Conference&lt;br /&gt;
&lt;br /&gt;
[http://www.appsectr.org/ Application Security Day, İstanbul 2012] will be held on 9 June, Saturday, in Marmara Üniversitesi Rektörlük Binası, Sultanahmet, İstanbul. &lt;br /&gt;
 &lt;br /&gt;
Published &lt;br /&gt;
&lt;br /&gt;
[http://www.webguvenligi.org/dokuman/web-uygulama-guvenligi-kontrol-listesi-2012.html Web App Security Check List 2012 in Turkish].&lt;br /&gt;
&lt;br /&gt;
== Projects/Tools/Translations ==&lt;br /&gt;
&lt;br /&gt;
Here are some of the projects produced by OWASP/Türkiye;&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/droidalert/ DroidAlert] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A proactive approach on finding fake android applications on some of the biggest android stores. Just enter a term, and droidalert searches it for you in android stores.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/chiasma/ Chiasma] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
Instead of having a structured penetration test report (docx, pdf, html v.b.) from 3rd parties, why not getting them produce a semi-structured report (xml) that is understood well. Chiasma is a Java desktop application producing XML vulnerability report.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/docs/web_uygulama_guvenligi_kontrol_listesi_2010.pdf Web Uygulama Güvenliği Kontrol Listesi 2010- WebAppSec Checklist] by OWASP-Turkey&lt;br /&gt;
&lt;br /&gt;
A complete set of controls related to security of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/piknik/ Piknik] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A compilation of a study on analyzing the possible behavior of a malicious developer...Inspired by [http://www.blackhat.com/presentations/bh-usa-09/WILLIAMS/BHUSA09-Williams-EnterpriseJavaRootkits-PAPER.pdf Jeff Williams's Work] &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/finddomains/ FindDomains] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
FindDomains is a multithreaded search engine discovery tool that will be very useful for penetration testers dealing with discovering domain names/web sites/virtual hosts which are located on too many IP addresses.&lt;br /&gt;
&lt;br /&gt;
* [http://dergi.webguvenligi.org/ WGT E-Magazine] by OWASP/TR and Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
An online web security related magazine in Turkish with a 2 months per-issue period&lt;br /&gt;
&lt;br /&gt;
* [http://ctf.webguvenligi.org/ CTF contest] by Onur Yilmaz&lt;br /&gt;
&lt;br /&gt;
A CTF contest where researchers, professionals and hackers can show off their skills in an ethical way &lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/jarvinen Jarvinen] by Gökhan Alkan &amp;amp; Yusuf Çeri &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A simple yet effective web based audit log monitoring service for Modsecurity v2. It consists of two basic parts; a (bash) shell script that parses serial logs into the mysql database and a php web application.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/cammp CAMMP] by Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
Aims to provide (bash) shell scripts in order to automatize the source code installations of apache (php and modsecurity) and mysql under chroot (for RedHat based systems for now).&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/secureimage SecureImage] by Mesut Timur &amp;amp; Bedirhan Urgun &amp;amp; Kerem Küsmezer&lt;br /&gt;
&lt;br /&gt;
A Java,PHP and .NET based image validator that can be used for validating image files on upload systems (such as photo galleries,forums,etc ..) against the threats for XSS issues with IE and LFI attacks. Individual project pages; [http://code.google.com/p/psecureimage PSecureImage] for PHP, [http://code.google.com/p/jsecureimage JSecureImage] for Java and [http://www.codeplex.com/owaspturkey/Release/ProjectReleases.aspx?ReleaseId=18008 NSecureImage] for .NET&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/securetomcat SecureTomcat] by Bedirhan Urgun &amp;amp; Deniz Çevik &amp;amp; Gökhan Alkan&lt;br /&gt;
&lt;br /&gt;
A collection of three components; an audit documentation in Turkish, a basic remote vulnerability scanner and an audit shell script fully aligned with the audit documentation. All for auditing and testing Apache Tomcat partial J2EE container.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/webekci/ WeBekci] by Bünyamin Demir&lt;br /&gt;
&lt;br /&gt;
WeBekci is a graphical user end for ModSecurity 2.x web application firewall.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/?page_id=16 Web Security Turkish Translation Project] by [http://www.webguvenligi.org/?page_id=16 great volunteers] &amp;amp; Bedirhan Urgun &lt;br /&gt;
&lt;br /&gt;
Turkish translations of OWASP guides and other web application security related documents '''over 500 pages''' and counting&lt;br /&gt;
 &lt;br /&gt;
* [http://code.google.com/p/wivet/ WIVET] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A benchmarking project that aims to statistically analyze web link extractors. It provides a good sum of input vectors to any extractor and presents the results. Check out the live app [http://www.webguvenligi.org/wivet/ here].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/sqlibench/ SqliBench] by Mesut Timur &amp;amp; Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
SQLiBENCH is a benchmarking project of automatic sql injectors related to dumping databases. Check out the live app [http://www.webguvenligi.org/sqlibench/web/ here]. The project is sponsored by [http://www.owasp.org/index.php/Category:OWASP_Sqlibench_Project OWASP SoC 08].&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalparser MSALParser] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALParser (pronounced \mi-säl\) implements necessary parsers and model objects to represent a ModSecurity Single Audit Log, hence the name MSAL. MSALParser is a PHP RPC end that will get mlogc's calls and parses them into objects and eventually write to a persistent data store.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/apachelive ApacheLive] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
ApacheLive (aka Haydar) project consists of a python script which was aimed to stress Apache web servers (httpd) using Keep-Alive parameters.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/anticsurf AntiCsurf] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
For most of the languages and frameworks, developers have to implement their own functions to defend against CSRF. AntiCsrf is a basic and light library for defending against CSRF for PHP applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/fm-fsf FM-FSF] by Ferruh Mavituna&lt;br /&gt;
&lt;br /&gt;
FSF is a plug-in based freakin' simple fuzzer for fuzzing web applications and scraping data. It supports some basic stuff and missing some features however it has got some advanced RegEx capturing features for scraping data out of web applications.&lt;br /&gt;
&lt;br /&gt;
* [http://code.google.com/p/msalmobile MSALMobile] &amp;amp; [http://code.google.com/p/msalservice MSALService] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
MSALMobile, a basic windows mobile application and consuming MSALService, is a simple mobile ModSecurity log analyzer for Windows Mobile environment. See [http://www.webguvenligi.org/software/msalmobile/msalmobile_video.rar a video of MSALMobile in action] on www.webguvenligi.org.&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/xsstb/reflected.php XSS TestBed] by Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
A playground for reflected xss test cases. The live project includes seven test cases ready to exploit. A legal and solid way to learn and apply xss skills. Moreover, a good way to test web application scanners on reflected xss testing...&lt;br /&gt;
&lt;br /&gt;
* [http://www.webguvenligi.org/projeler/wcsa Web.config Security Analyzer] by Mesut Timur&lt;br /&gt;
&lt;br /&gt;
Web.config file holds settings about related ASP.NET web application. This project analyzes a given Web.config file for security vulnerabilities with its 30+ checks. It's a command line too for now and produces a neat html based report.&lt;br /&gt;
&lt;br /&gt;
== Translations ==&lt;br /&gt;
&lt;br /&gt;
Çeviri projesine yardım etmek isteyen arkadaşlar, lütfen [mailto:bunyamindemir@gmail.com bunyamin] veya [mailto:urgunb@hotmail.com bedirhan] ''(proje lideri)'' ile iletişime geçiniz. Şu ana kadar yayınlanan çevirilere [http://www.webguvenligi.org/?page_id=16 buradan] ulaşabilirsiniz. ''You can find Turkish translations of OWASP and other web security related documents [http://www.webguvenligi.org/?page_id=16 here].''&lt;br /&gt;
&lt;br /&gt;
==== Meetings/Conferences ====&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Android Developer Days 2012 in ODTU Ankara ==&lt;br /&gt;
&lt;br /&gt;
Bedirhan Urgun of OWASP/TR will give a presentation on &amp;quot;Developing Secure Android Days&amp;quot; on 22 May from 15:30-16:00 in Android Developer Days, 2012. The presentation will take place in ODTU, Ankara.&lt;br /&gt;
&lt;br /&gt;
Location: ODTÜ Kültür ve Kongre Merkezi, Ankara&lt;br /&gt;
&lt;br /&gt;
Date: 22 May 2012, Tuesday&lt;br /&gt;
&lt;br /&gt;
Time: 15:30 – 16:00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in ReadMee Internet Zirvesi, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Seyfullah Kılıç will give a presentation titled &amp;quot;Web Güvenliği ve Korunma Yolları&amp;quot; on 07 April Saturday from 14:00-14:45 in ReadMee Internet Zirvesi, 2012. The presentation will take place in Eskişehir Osmangazi Üniversitesi, Eskişehir.&lt;br /&gt;
&lt;br /&gt;
Location: Eskişehir Osmangazi Üniversitesi Meşelik Kampüsü, Eskişehir&lt;br /&gt;
&lt;br /&gt;
Date: 7 April 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 14:00 – 14:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Presentation in Özgür Yazılım ve Linux Günleri, 2012 ==&lt;br /&gt;
&lt;br /&gt;
Bünyamin Demir of OWASP/TR will give a presentation titled as &amp;quot;&lt;br /&gt;
Güvenli Kod Geliştirme&amp;quot; and will hold a chapter meeting &amp;quot;OWASP Türkiye Chapter Meeting (Çalışma Toplantısı)&amp;quot; on 31 March Saturday from 10:00-13:00 in Özgür Yazılım ve Linux Günleri, 2012. The presentations will take place in İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul.&lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Bilgi Üniversitesi Dolapdere Kampüsü, İstanbul&lt;br /&gt;
&lt;br /&gt;
Date: 31 March 2012 Saturday&lt;br /&gt;
&lt;br /&gt;
Time: 10:00 – 13:00&lt;br /&gt;
&lt;br /&gt;
Location 1: 1. Salon&lt;br /&gt;
Location 2: Toplantı Salonu&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Talk in Open Source Code Days in Yeditepe University ==&lt;br /&gt;
&lt;br /&gt;
Bunyamin Demir talked about OWASP and OWASP/Turkey introduction. After intro, he did a presentation about [http://seminer.linux.org.tr/wp-content/uploads/guvenli_kod_gelistirme_ve_yasam_dongusu.ppt &amp;quot;Secure Coding and Chaotic Life Cycle&amp;quot;].&lt;br /&gt;
&lt;br /&gt;
Location: Yeditepe University, 26 Agustos Yerlesimi,  Salon 2&lt;br /&gt;
&lt;br /&gt;
Date: 14 October 2011, Friday&lt;br /&gt;
&lt;br /&gt;
Time: 15:00 – 15:45&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Bahçeşehir Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Bahçeşehir Üniversitesi, Beşiktaş Kampüsü, D-404 Salonu&lt;br /&gt;
&lt;br /&gt;
Date: 10 Mart 2010 Çarşamba&lt;br /&gt;
&lt;br /&gt;
Time: 18.30 – 19.30&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Introductory Meetings and Seminar @ Işık Üniversitesi, March 2010 ==&lt;br /&gt;
&lt;br /&gt;
[http://www.shibumidojo.org/ Kubilay Onur Güngör] will start with OWASP and OWASP/Turkey introduction. After intro, cyber security concept, web application security, social theories of criminal behaviors and many other topics will be discussed.  So don't miss the events if you're around. &lt;br /&gt;
&lt;br /&gt;
Location: Işık Üniversitesi, Şile Kampüsü&lt;br /&gt;
Registration: http://bilisimgunleri.isikun.edu.tr&lt;br /&gt;
Date: 8 Mart 2010 Pazartesi&lt;br /&gt;
Time: 15.00 - 16.00&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Meeting in Turkcell Akademi with OISF Team, February 2010 ==&lt;br /&gt;
&lt;br /&gt;
With 7 [http://www.openinfosecfoundation.org OISF] members we had our 23 February meeting. Brian [http://vimeo.com/9825055 talked about ModSecurity] and Victor &amp;amp; Will [http://vimeo.com/9825622 talked about Suricata ].&lt;br /&gt;
&lt;br /&gt;
As always, check out the photos on [http://www.flickr.com/photos/webguvenligi flickr-webguvenligi]!!&lt;br /&gt;
&lt;br /&gt;
Thanks to our sponsor for this meeting [http://www.guvenlikegitimleri.com GuvenlikEgitimleri.Com]&lt;br /&gt;
&lt;br /&gt;
== OWASP/TR Seminar in İstanbul Kültür Universitesi, 29 December 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in İstanbul Kültür Üniversitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu. Topics will include &amp;quot;introduction to OWASP/TR&amp;quot;, &amp;quot;siber security&amp;quot;, &amp;quot;security best practices and standards&amp;quot;. It will also include a demo on digital investigation.&lt;br /&gt;
&lt;br /&gt;
Presenter: [http://www.shibumidojo.org/ Kubilay Onur Güngör]&lt;br /&gt;
&lt;br /&gt;
Date: Tuesday, December 29, 2009 &lt;br /&gt;
&lt;br /&gt;
Time: 12:00pm - 1:30pm &lt;br /&gt;
&lt;br /&gt;
Location: İstanbul Kültür Üniersitesi, Ataköy Kampüsü, Önder Öztunalı Konferans Salonu&lt;br /&gt;
&lt;br /&gt;
== October 11, 2009 OWASP/TR on the Green Field ==&lt;br /&gt;
&lt;br /&gt;
Teams formed by OWASP-Turkey mailing list members will play a soccer match on Sunday, 18:00 October the 11th. We'll seek our Messis, Zidanes, Kakas, Lampards, Chechs stemmed from the Anatolian land... National team may not be qualified for the 2010 World Championship, which is a shame, but we'll do better next time.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP-Turkey Meeting in September 26, 2009 ==&lt;br /&gt;
&lt;br /&gt;
30 people gathered for the OWASP/TR meeting. Here's the [http://www.webguvenligi.org/docs/26_Eylul_OWASPTR_Bulusma.ppt agenda of the meeting]. Moreover, Ibrahim Saruhan gave a [http://www.webguvenligi.org/docs/Facebook_Twitter_Botnets.ppt presentation] on his experiences writing a PoC Facebook botnet. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
See the [http://www.flickr.com/webguvenligi/ pictures] and listen to the DimDim [http://recp.dimdim.com/view/dimdim/1a9400f2-fbdb-102c-9515-003048642bd7 recording].&lt;br /&gt;
&lt;br /&gt;
== September 26 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting for anyone interested in web/software security. It will take place in Istanbul, Taksim at 14:00, on 26 September.  &lt;br /&gt;
&lt;br /&gt;
== Artifacts - 06 May/13 May 2009 OWASP-TR Talks in Kocaeli &amp;amp; Gazi Universities ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Onur Yılmaz at &amp;quot;Information Techonology Days&amp;quot; in [http://www.kocaeli.edu.tr/ Kocaeli University] and [http://www.gazi.edu.tr/ Gazi University], [http://www.webguvenligi.org/docs/kocaeli09owasptr.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/docs/gaziuni09owasptr.ppt Basic Web App Security Presentation] respectively. &lt;br /&gt;
&lt;br /&gt;
Pictures are on [http://www.flickr.com/photos/webguvenligi flicker] as always.&lt;br /&gt;
&lt;br /&gt;
== Web Application Security Talk in Gazi University, 13 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Information Days&amp;quot; event at Gazi University about code/sql injection attack vectors and prevention techniques on 13th (Wednesday) of May 2009, between 10:30-11:20. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/web-uygulamalari-guvenligi-sunumu-gazi-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== OWASP-TR Seminar in Kocaeli University, 06 May 2009 ==&lt;br /&gt;
&lt;br /&gt;
We'll be hosting a free seminar in Math. Department of Kocaeli University about OWASP and OWASP/Turkey including the basics of well known attack vectors and prevention techniques on 6th (Wednesday) of May 2009, starting from 15:30. &lt;br /&gt;
&lt;br /&gt;
Reach out the details [http://www.webguvenligi.org/haberler/owasp-tr-ve-wgt-semineri-kocaeli-universitesi.html here]&lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 19 2009 OWASP-TR Talk in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Gökhan Alkan at &amp;quot;Information Techonology Days&amp;quot; in [http://www.sau.edu.tr/ Sakarya University], [http://www.webguvenligi.org/sau_bilisim_gunleri09/sakarya_bilisim_gunleri.ppt OWASP-TR &amp;amp; WebGoat Presentation] and [http://www.webguvenligi.org/sau_bilisim_gunleri09/Recel_Krallagindan_Webe.ppt Jarvinen Presentation] respectively. We'd like to thank [http://www.bilisimk.sau.edu.tr/ Sakarya Universitesi Bilişim Kulubü] for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Information Techonology Days '09 in Sakarya University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving two talks in &amp;quot;Information Techonology Days&amp;quot; about OWASP and OWASP/Turkey in [http://www.sau.edu.tr/ Sakarya University] on 19th of March 2009. The talk will include an introduction to OWASP, OWASP/Turkey as a community. Plus, Jarvinen, an OWASP/TR project, will be presented.&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fifth OWASP-Turkey Meeting in March 08, 2009 ==&lt;br /&gt;
&lt;br /&gt;
We had close to 35 people gathered. Here's the [http://www.webguvenligi.org/docs/WGT_OWASP-TR_08_Mart_2009_Bulusmasi_Ajanda.pptx agenda of the meeting]. Moreover, Fatih Emiral gave a [http://www.webguvenligi.org/docs/Yazilim_Guvenligi.ppt presentation] comparing three main Software Security models. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fifth OWASP-Turkey Meeting in March 08, 2009  ==&lt;br /&gt;
&lt;br /&gt;
A regular meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. The meeting will take place in Istanbul, Maltepe, beween 13:00-15:00, on 08th of March, Sunday. &lt;br /&gt;
Here's the map for the [http://www.gencgirisimciler.org/bpi.asp?caid=161&amp;amp;cid=17 meeting place]&lt;br /&gt;
If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun)&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Kocaeli December 2008 ==&lt;br /&gt;
&lt;br /&gt;
With over 50 attendees we had our 4th Web Security Days in Kocaeli University at Umuttepe Campus.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; SlideShows &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_intro.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_owasptr_wgt.ppt WGT/OWASPTR] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_www.ppt WWW Introduction] - Uğur Yıldız&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_csrf.ppt CSRF] - Yusuf Çeri&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_graphics.ppt Graphic Attacks] - Mesut Timur &lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_chroot.ppt Secure Web Production Environments] - Gökhan Alkan&lt;br /&gt;
* [http://www.flickr.com/webguvenligi/ Pictures] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
* [http://www.webguvenligi.org/docs/kocaeli/wgg4_slideshow.ppt  OWASP Top 10 Slide Show] - Bedirhan Urgun&lt;br /&gt;
&lt;br /&gt;
== Next Event - 4th Web Security Days Kocaeli - December 23 (Turkey 2008) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the fourth of &amp;quot;Web Security Days&amp;quot; and will take place on 23rd of December 2008 in Kocaeli. The agenda of the event is [http://www.owasp.org/index.php/4th_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - Fourth OWASP-Turkey Meeting in October 18, 2008 ==&lt;br /&gt;
&lt;br /&gt;
Here's the [http://www.webguvenligi.org/wp-content/uploads/2008/10/WGT&amp;amp;OWASP-TR_18_Ekim_2008_Bulusmasi_Ajanda.ppt agenda of the meeting]. We also had two small discussion and presentation of a simple demo overview of recent clickjacking vulnerability and [http://www.webguvenligi.org/wp-content/uploads/2008/10/sqlibench-presentation.ppt sqlibench SoC 2008 OWASP project]. Thanks everyone for participating.&lt;br /&gt;
&lt;br /&gt;
Moreover, all of the OWASP sent books (~30)/pens(~15) were distributed freely! &lt;br /&gt;
&lt;br /&gt;
For the photos take a look at [http://www.flickr.com/photos/webguvenligi/ here].&lt;br /&gt;
&lt;br /&gt;
== Fourth OWASP-Turkey Meeting in October 18, 2008  ==&lt;br /&gt;
&lt;br /&gt;
A catch up meeting on web/software security related issues&amp;amp;techniques&amp;amp;news. Moreover, OWASP sent goodies (to the most active chapters) will be distributed (This includes 27 OWASP books and 19 pens). It will take place in Istanbul, İstiklal Cad.Emir Nevruz Sok. No: 1/11 Galatasaray Beyoğlu beween 14:00-16:00, on 18th of October. If you want to attend the event, please send an e-mail to: urgunb at hotmail.com  (Bedirhan Urgun) &lt;br /&gt;
&lt;br /&gt;
== Artifacts - June 21 2008 OWASP-TR Talk in &amp;quot;Free Software Conference&amp;quot; ==&lt;br /&gt;
&lt;br /&gt;
Here is the presentation given by Mesut Timur and keynote submitted at [http://konferans.linux.org.tr/ &amp;quot;Free Software Conference&amp;quot;] in [http://www.etu.edu.tr/ TOBB University of Economics and Technology]; &lt;br /&gt;
[http://www.webguvenligi.org/wp-content/uploads/2008/06/owasp_wgt_lkd_21062008.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/06/webguvenligi_bildiri_lkd_21062008.pdf Web Security and Free Software Keynote] (in Turkish) respectively.&lt;br /&gt;
&lt;br /&gt;
== Talk in Free Software Conference in Ankara ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Free Software Conference&amp;quot; about OWASP and OWASP/Turkey in [http://www.etu.edu.tr/ TOBB University of Economics and Technology] on 21st (Saturday) of June 2008. The talk will include an introduction to OWASP, OWASP/Turkey, as well as web/application security projects achieved in Turkey. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk, which will be presented by [http://www.h-labs.org Mesut Timur], will be between 15.00-15.30. You can skim the programme [http://konferans.linux.org.tr/etkinlik-programi/ here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - April 19 2008 OWASP-TR Talk in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
Here are the presentations given by Bünyamin Demir and Yusuf Çeri at &amp;quot;Open Source Code Day&amp;quot; in [http://www.yildiz.edu.tr/english Yildiz Technical University], [http://www.webguvenligi.org/wp-content/uploads/2008/04/owasp-wgt-ytu-19nisan08.ppt OWASP-TR Presentation] and [http://www.webguvenligi.org/wp-content/uploads/2008/04/sqlmapdemo-wgt-ytu-19nisan08.ppt SqlDemo Presentation] respectively. We'd like to thank YTÜ Bilişim Kulubü for inviting us.&lt;br /&gt;
&lt;br /&gt;
And never the least, here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604620396950/ pictures] taken during the day.&lt;br /&gt;
&lt;br /&gt;
== Talk in Open Source Code Day in Yildiz Technical University ==&lt;br /&gt;
&lt;br /&gt;
We'll be giving a talk in &amp;quot;Open Source Code Day&amp;quot; about OWASP and OWASP/Turkey in [http://www.yildiz.edu.tr/english Yildiz Technical University] on 19th of April 2008. The talk will include an introduction to OWASP, OWASP/Turkey, web/application security community in Turkey, the 1st OWASP Day video by Jeff and a live application insecurity demo. &lt;br /&gt;
&lt;br /&gt;
The Day will start at 09:30 and our talk will be the last one before the noon. &lt;br /&gt;
&lt;br /&gt;
== Artifacts - March 09 2008 Meeting ==&lt;br /&gt;
&lt;br /&gt;
It was a nice Sunday in Istanbul and we had 16 people talking about SPoC 08, April OWASP Week and web application security in general. Here are the [http://www.flickr.com/photos/webguvenligi/sets/72157604077351886/ pictures] taken during the meeting.&lt;br /&gt;
&lt;br /&gt;
== March 09 Meeting ==&lt;br /&gt;
&lt;br /&gt;
A casual meeting for anyone interested in web/software security. It will take place in Istanbul, Kadikoy at 14:30, on 09 March. To chat and enjoy the [http://www.flickr.com/photos/jrogivue/21918611/ Bosphorus]! &lt;br /&gt;
&lt;br /&gt;
== Artifacts - Web Security Days Ankara &amp;amp; İzmir November 2007 ==&lt;br /&gt;
&lt;br /&gt;
Through a foggy, and therefore a hard flight, we've managed to realize Web Security Days 2 &amp;amp; 3 in Ankara and Izmir, respectively. Having a total of ~130 attendees (most of them in Izmir), we hope WSD to be traditional and become more qualitysome.&lt;br /&gt;
&lt;br /&gt;
Presentations &amp;amp; Code &amp;amp; Photos:&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/init_ankara.ppt Giris] - Bedirhan Urgun&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/wgt.ppt WGT Giris] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/ulakcsirt.pdf ULAK-CSIRT Giris] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/burak_sc.ppt Yazılım Geliştirme Sürecinde Güvenlik Testleri] - Burak Dayıoğlu&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/enis_web.ppt Kurumsal Web Güvenliği Yapısı] - Enis Karaarslan&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/tahsin_did.ppt Uygulamalarda Katmanlı Güvenlik Anlayışı] - Tahsin Türköz&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/oguzhan_php.ppt PHP ve Güvenli Kodlama] - Oğuzhan Yalçın&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bunyamin_pl.ppt Perl'de Guvenlik Modulu] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/izmir/security_pm.rar Perl'de Guvenlik Modulu - Kod] - Bünyamin Demir&lt;br /&gt;
* [http://www.webguvenligi.org/docs/ankara/bedirhan_js.ppt Web 2.0 Savunma Dili: Javascript] - Bedirhan Urgun&lt;br /&gt;
* [http://www.flickr.com/photos/webguvenligi/sets/72157603311164597/ Photos] - Bedirhan &amp;amp; Bünyamin&lt;br /&gt;
&lt;br /&gt;
== Next Event - 3rd Web Security Days İzmir - November 26 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the third of &amp;quot;Web Security Days&amp;quot; and will take place on 26th of November 2007 in İzmir. The agenda of the event is [https://www.owasp.org/index.php/3rd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Next Event - 2nd Web Security Days Ankara - November 24 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
This event will be the second of &amp;quot;Web Security Days&amp;quot; and will take place on 24th of November 2007 in Ankara. &lt;br /&gt;
The agenda of the event is [https://www.owasp.org/index.php/2nd_Web_Security_Days_OWASP_Turkey here].&lt;br /&gt;
&lt;br /&gt;
== Artifacts - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
Presentations:&lt;br /&gt;
&lt;br /&gt;
* [https://www.owasp.org/images/6/66/OWASP_DAY_TR.sub.ppt Turkish Subtitle] for [http://www.owasp.org/downloads/OWASP_Day.wmv  Jeff's OWASP Day Intro movie] (delete .ppt extension)&lt;br /&gt;
* [https://www.owasp.org/images/b/bc/OWASP2007_KamudaPrivacy.ppt OWASP2007_KamudaPrivacy.ppt‎]&lt;br /&gt;
* [https://www.owasp.org/images/4/4b/Guvenli_Web_Uygulamalarinin_Gelistirilmesi2.ppt Guvenli_Web_Uygulamalarinin_Gelistirilmesi.ppt] &lt;br /&gt;
&lt;br /&gt;
Discussion Answers:&lt;br /&gt;
&lt;br /&gt;
Q1.&lt;br /&gt;
What is the current state of Privacy on Web Application Security? Does it really matter? Is privacy what will drive radical changes in web application's security (ala PCI)? &lt;br /&gt;
&lt;br /&gt;
A1.&lt;br /&gt;
During the meeting an effort was made to clarify the meaning of privacy;&lt;br /&gt;
 - what are the key items that builds up to &amp;quot;privacy&amp;quot;?&lt;br /&gt;
 - are we talking about the privacy of real people or should we also include the privacy of legal entities?&lt;br /&gt;
 - is there really a solid line (or even a vague line) between confidentiality and privacy?&lt;br /&gt;
We defined privacy as confidentiality of the data; be it of a real person or a legal entity.&lt;br /&gt;
But the key part is that privacy is &amp;quot;the ability to control the flow of one's own data&amp;quot;. And which brings another principle: &amp;quot;need to know&amp;quot;. Privacy is directly related to an individual or an organization. Confidentiality, however, is directly related to &amp;quot;information&amp;quot;... Privacy is a &amp;quot;result&amp;quot; and confidentiality is a tenet or a security mechanism. &lt;br /&gt;
&lt;br /&gt;
Enough of these convulsions;&lt;br /&gt;
The answer to the first question was a definite &amp;quot;YES&amp;quot;. Participants were all agreed that &amp;quot;privacy&amp;quot; plays and will play the most important role in web security and its future.&lt;br /&gt;
&lt;br /&gt;
Q2.&lt;br /&gt;
Application side: what the data owner should be doing to protect the user's privacy? Should there be a law that states how to protect this information? What can we do to improve it?&lt;br /&gt;
&lt;br /&gt;
A2.&lt;br /&gt;
Most of the participants agreed that a law is a necessity.&lt;br /&gt;
But, maybe, more important thing is to raise the awareness of the customers.&lt;br /&gt;
Here we also had a discussion on the current status of the law on privacy? There are mainly three &lt;br /&gt;
documents on privacy in Turkish law;&lt;br /&gt;
 * a directive on privacy in telecommunication, which happened to be inadequate (an assertion of a lawyer)&lt;br /&gt;
 * a draft law on privacy from Department of Justice, which is still in the process of approval&lt;br /&gt;
 * a recent (May 2007) law on siber crimes which happens to be similiar to the &amp;quot;Directive 2006/24/EC of the &lt;br /&gt;
   European Parliament and of the Council&amp;quot; on the data retention. This law, however, still needs a few&lt;br /&gt;
   directives, which are about to be published.&lt;br /&gt;
&lt;br /&gt;
Q3.&lt;br /&gt;
Client side: what is the client's perception of privacy? How can a user trust a site about his own data treatment? Is the client nowadays safeguarded about a possible loss of privacy?&lt;br /&gt;
&lt;br /&gt;
A3.&lt;br /&gt;
As a first step there should be an &amp;quot;agreement&amp;quot; presented to the user by the application side.&lt;br /&gt;
This wouldn't be enough so there should be regular inspections (a third eye) on these services.&lt;br /&gt;
About &amp;quot;is the client nowadays safeguarded about a possible loss of privacy?&amp;quot; question, the answer&lt;br /&gt;
was a definite &amp;quot;NO&amp;quot;. Especially with the banks. Yes, there are a few cases of trials where the courts&lt;br /&gt;
dictated a bank to compansate the loss of the victim, however, mostly this is not the case. Even there is&lt;br /&gt;
a domain serving, founded by the victims of online banking crimes in Turkey.&lt;br /&gt;
&lt;br /&gt;
Q4.&lt;br /&gt;
What should OWASP be focusing on?&lt;br /&gt;
&lt;br /&gt;
A4.&lt;br /&gt;
As a suggestion, OWASP may provide a &amp;quot;web security tips&amp;quot; page, which can include a searchable gui &lt;br /&gt;
on small programming tips to avoid security holes in web applications.&lt;br /&gt;
&lt;br /&gt;
And a great idea of producing a &amp;quot;FixmeBank&amp;quot; application to cover the developer side of the story, as opposed to tester/attacker side (via WebGoat or HacmeBank), was suggested by Taygun Alban.&lt;br /&gt;
&lt;br /&gt;
Q5.&lt;br /&gt;
What would OWASP spend it's grant money? (note that new OWASP members can allocate some or all of their membership fees to specific projects)&lt;br /&gt;
&lt;br /&gt;
A5.&lt;br /&gt;
Some suggestions;&lt;br /&gt;
. Printed booklets of Guide and Testing Guide. &lt;br /&gt;
. OWASP CD with shiny labels&lt;br /&gt;
. I'm afraid to say but... t-shirts&lt;br /&gt;
&lt;br /&gt;
Q6.&lt;br /&gt;
Should OWASP organize such 'OWASP Weeks' every quarter?&lt;br /&gt;
&lt;br /&gt;
A6.&lt;br /&gt;
OWASP should organize these events every 6 months or so :)&lt;br /&gt;
&lt;br /&gt;
== Next Event - OWASP DAY: on the topic of &amp;quot;Privacy in the 21st Century&amp;quot; - September 8 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
As a part of the Global Security Week, OWASP Turkey chapter will be holding a humble meeting on Saturday, 8 September 2007. Less technical and time taking compared to last event ([http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days]) we will be focusing on the current snapshot of the privacy related issues in the govermental/quasi-governmental and private institutions of Turkey.&lt;br /&gt;
&lt;br /&gt;
Here's the &amp;quot;still in process&amp;quot; agenda:&lt;br /&gt;
&lt;br /&gt;
* 14:00 - 14:10 Prelude. Introduction of OWASP DAY and OWASP Turkey projects&lt;br /&gt;
&lt;br /&gt;
A small introduction to OWASP Day meeting and its goals, plus explanation of some of the lightweight projects of OWASP Turkey.&lt;br /&gt;
&lt;br /&gt;
Bedirhan URGUN, Bunyamin DEMİR&lt;br /&gt;
&lt;br /&gt;
* 14:20 - 14:50 Privacy in Governmental Insitutions - A Current State Analysis&lt;br /&gt;
&lt;br /&gt;
Presentation will discuss the understanding of the privacy concept settled in governmental institutions and deliberate on general information security problems related with privacy issues.&lt;br /&gt;
&lt;br /&gt;
Getting off with general privacy problems, in specific, information about the privacy issues related to web applications will be given. Moreover, concrete suggestions on providing a solid privacy in these institutions will be presented.&lt;br /&gt;
&lt;br /&gt;
Hayrettin BAHŞİ&lt;br /&gt;
Chief Researcher CC Lab-UEKAE TUBITAK&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 15:50 Secure Web Application Development&lt;br /&gt;
&lt;br /&gt;
Korhan GÜRLER&lt;br /&gt;
Chief Researcher PRO-G&lt;br /&gt;
&lt;br /&gt;
* 15:00 - 16:00 A Panel on Privacy in Turkey &lt;br /&gt;
&lt;br /&gt;
OWASP-Turkey Members&lt;br /&gt;
&lt;br /&gt;
== Last Event - 1st Web Security Days - July 14 (Turkey 2007) ==&lt;br /&gt;
&lt;br /&gt;
First of the [http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey Web Security Days] has been realized by Owasp-Turkey chapter on 14th of July 2007 in İstanbul. With a ~70 registered attendees, it was great to have a pack of web security oriented people for a five hours of mostly technical presentations.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[http://www.owasp.org/index.php/1st_Web_Security_Days_OWASP_Turkey For details...]&lt;br /&gt;
&lt;br /&gt;
== Last Meetings ==&lt;br /&gt;
&lt;br /&gt;
'''Sunday 6 May 2007'''&amp;lt;br&amp;gt;&lt;br /&gt;
'''Time:''' 11:15-12:30&amp;lt;BR&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Address''' to the meeting are:&lt;br /&gt;
&lt;br /&gt;
[http://www.metu.edu.tr Middle East Technical University]&amp;lt;br/&amp;gt;&lt;br /&gt;
Ankara-Turkey&amp;lt;br/&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
'''Presentation'''&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
     Web Application Security with ModSecurity and OWASP&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &lt;br /&gt;
&lt;br /&gt;
&amp;lt;headertabs/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Germany]] [[Category:Europe]]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=AppSecEU2013&amp;diff=140901</id>
		<title>AppSecEU2013</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=AppSecEU2013&amp;diff=140901"/>
				<updated>2012-12-09T12:25:12Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
&amp;lt;!-- please no headertabs!! --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Welcome  ===&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;width: 100%;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 100%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
{| style=&amp;quot;border: 0px solid ; background: transparent none repeat scroll 0% 0%; width: 100%; -moz-background-clip: border; -moz-background-origin: padding; -moz-background-inline-policy: continuous;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| style=&amp;quot;width: 95%; color: rgb(0, 0, 0);&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
We are pleased to announce that the [http://www.owasp.org/index.php/Germany German OWASP Chapter] will host the OWASP AppSec Europe Research 2013 global conference in beautiful [http://en.wikipedia.org/wiki/Hamburg Hamburg], Germany from August 20-23. Hamburg is basically the [http://travel.nytimes.com/2012/01/22/travel/36-hours-hamburg-germany.html sleepy beauty] of Germany, in the very north of it.&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The AppSec Europe 2013 conference will be a premier gathering of Information Security leaders, also the AppSec Europe 2013 is going to have a Research part.&lt;br /&gt;
&lt;br /&gt;
Executives from Fortune 500 firms along with technical thought leaders such as security architects and lead developers will be traveling to hear the cutting-edge ideas presented by Information Security’s top talent. OWASP events attract a worldwide audience interested in “what’s next”. The conference is expected to draw 400-500 technologists from Government, Financial Services, Media, Pharmaceuticals, Healthcare, Technology, and many other verticals. &lt;br /&gt;
&lt;br /&gt;
On the research side OWASPs AppSecEU Research will give you an excellent chance to present your cutting edge research, including a paper for the proceedings.&lt;br /&gt;
&lt;br /&gt;
The conference will be held from August 20-23, 2013 at the [http://www.emporio-hamburg.de Emporio Hamburg]. It' [https://maps.google.de/maps?q=emporio+hamburg&amp;amp;hl=en&amp;amp;sll=53.561418,10.01215&amp;amp;sspn=0.043996,0.082397&amp;amp;hq=emporio+hamburg&amp;amp;t=m&amp;amp;z=15 centrally located in the city of Hamburg] with a splendid [http://www.emporio-hamburg.de/uploads/tx_templavoila/09_20101026-_mg_8051_hdr_02.jpg view] over Binnen-, Aussenalster and River Elbe. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
=== Teams ===&lt;br /&gt;
&lt;br /&gt;
==== Conference Orga ====&lt;br /&gt;
Dirk Wetter (Chair) &amp;lt;br/&amp;gt;&lt;br /&gt;
Kai Jendrian (Co-Chair)  &amp;lt;br/&amp;gt;&lt;br /&gt;
Birgit Bernskötter (External) &amp;lt;br/&amp;gt;&lt;br /&gt;
Boris Hemkemeier &amp;lt;br/&amp;gt;&lt;br /&gt;
Achim Hoffmann &amp;lt;br/&amp;gt;&lt;br /&gt;
Ingo Hanke &amp;lt;br/&amp;gt;&lt;br /&gt;
Martin Johns &amp;lt;br/&amp;gt;&lt;br /&gt;
Tobias Glemser &amp;lt;br/&amp;gt;&lt;br /&gt;
Sebastien Deleersnyder  &amp;lt;br/&amp;gt;&lt;br /&gt;
Sarah Baso &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Program Committee (to be completed) ====&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Hannes Federath (Research) &amp;lt;br/&amp;gt; --&amp;gt;&lt;br /&gt;
John Wilander (Research + Industry) &amp;lt;br/&amp;gt;&lt;br /&gt;
Sebastian Schinzel (Research + Industry) &amp;lt;br/&amp;gt;&lt;br /&gt;
Achim Hoffmann &amp;lt;br/&amp;gt;&lt;br /&gt;
Boris Hemkemeier &amp;lt;br/&amp;gt;&lt;br /&gt;
Diniz Cruz &amp;lt;br/&amp;gt;&lt;br /&gt;
Emin Tatli &amp;lt;br /&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Martin Johns &amp;lt;br/&amp;gt;&lt;br /&gt;
Dirk Wetter &amp;lt;br/&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
;Twitter: &lt;br /&gt;
[https://twitter.com/#!/search/OWASP_de Twitter: @OWASP_de]&lt;br /&gt;
(at a certain time we'll take over the appseceu account)&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135791</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135791"/>
				<updated>2012-09-13T17:56:35Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Born in Turkey &amp;amp; Living since 2001 in Germany&lt;br /&gt;
* Ex-IBMer and working now as Security Architect and Researcher by Daimler TSS&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design&amp;amp;coding trainings, risk management&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Involved with OWASP since 2005&lt;br /&gt;
* Since 2010 Board Member of [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of [[Germany|German Chapter]]&lt;br /&gt;
* Organisation and Program Committee of OWASP Conferences in Germany and Turkey&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
* Written articles about OWASP projects &lt;br /&gt;
** [http://www.architectingsecurity.com/wp-content/uploads/papers/SAMM-Tatli-Ocak11.pdf Secure Application Development with OpenSAMM] (in Turkish)&lt;br /&gt;
** OWASP Guidelines and Tools for Secure SDLC (in German)&lt;br /&gt;
* Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
 &lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=German_OWASP_Day_2012/CfP&amp;diff=135790</id>
		<title>German OWASP Day 2012/CfP</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=German_OWASP_Day_2012/CfP&amp;diff=135790"/>
				<updated>2012-09-13T17:55:13Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{|&lt;br /&gt;
|&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;!-- das TOC ist doppelt FIXME --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]] [[Category:Germany]] [[Category:Europe]] [[Category:German OWASP Day]]&lt;br /&gt;
&lt;br /&gt;
Die deutsche Sektion des Open Web Application Security Project (OWASP) richtet die zum fünften Mal eine deutsche OWASP-Konferenz aus: den German OWASP Day. Das German OWASP Chapter ruft für die diesjährige Konferenz auch wieder einen Call for Presentations (CfP) aus. Die Konferenz richtet sich primär an ein deutschsprachiges Publikum; die Konferenzsprache ist Deutsch, Vorträge in Englisch sind auch willkommen. Der German OWASP Day 2012 ist eine klassische Security-Konferenz, mit Fachvorträgen zu sicherer Entwicklung, Betrieb, Test und Managment im Umfeld von webbasierten Anwendungen bietet. Auch fachübergreifende, nicht-technische Themen sind willkommen. Bitte keine Marketingvorträge.&lt;br /&gt;
|&lt;br /&gt;
The German Chapter of the Open Web Application Security Project (OWASP) is again organizing a German OWASP Conference, for the 5th time this year: the German OWASP Day. &lt;br /&gt;
&lt;br /&gt;
There is a call for presentations (CfP), see below for details. The target group consists of German speaking people, and correspondingly the conference language is German, but English presentations are welcome as well. The German OWASP Day is a true security conference, with expected talks and presentations on secure software development, usage, test and management, all around web based applications. Non-technical talks are welcome as well. Please refrain from submitting plain marketing pitches.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
== Fachliches ==&lt;br /&gt;
&lt;br /&gt;
Für Vortragsvorschläge bitten wir um eine Kurzzusammenfassung oder eine Vorabversion des Vortrags. Die Zusammenfassung sollte nicht weniger als 500 (maximal: 4000) Zeichen lang sein, damit das Programmkomitee eine gute Entscheidungsgrundlage hat. (Bitte auf Orthographie achten, da die Zusammenfassung so wie sie ist ggf. im Programm erscheint). Die gilt ebenso für die obligatorische Kurzbiographie (150-800 Zeichen). Die Präsentationen werden voraussichtlich 40 Minuten dauern, plus 5 Minuten Diskussion. &lt;br /&gt;
&lt;br /&gt;
Erwünscht sind alle Themen mit Bezug zu Webapplikationssicherheit und OWASP, insbesondere: &lt;br /&gt;
&lt;br /&gt;
*Praxisrelevante technische Vorträge&lt;br /&gt;
*Sichere Webanwendungen in der Cloud &lt;br /&gt;
*Mobile Security&lt;br /&gt;
*Browser-Sicherheit&lt;br /&gt;
*HTML5 Security&lt;br /&gt;
*Sicherheit bei Web Services (REST, XML)&lt;br /&gt;
*Sichere / Sicherheit bei Development Frameworks &lt;br /&gt;
*Security-Awareness und Education&lt;br /&gt;
*Vulnerability analysis und Application Security Testing: Code Review, Pentest, SCA&lt;br /&gt;
*Secure Development Lifecycle &lt;br /&gt;
*OWASP in Ihrem Unternehmen, Ihrer Hochschule etc.&lt;br /&gt;
*Anwendungssicherheit bei Outsourcing- und Offshoring-Projekten  &lt;br /&gt;
*Anwendungssicherheit und Metriken &lt;br /&gt;
*Datenschutz bei Webanwendungen&lt;br /&gt;
*Neues zu OWASP-Projekten/Standards/Tools&lt;br /&gt;
&lt;br /&gt;
Abhängig von der Anzahl eingehender Vorträge bieten wir ein oder zwei Tracks an. Folien der Vorträge werden unter der freien [[OWASP Licenses#Licensing_of_OWASP_Website_Content|OWASP Lizenz]] auf der Konferenzwebseite veröffentlicht. Daher muss spätestens bei Annahme des Beitrags durch das Programmkomitee das [[Speaker Agreement|OWASP Speaker Agreement]] ohne Änderung akzeptiert und unterschrieben werden. Das Speaker Agreements sieht vor, dass die Standardfoliensätze von OWASP verwendet werden ([[Media:OWASP_Presentation_template.ppt|PPT]], [[Media:OWASP_Presentation_template.pptx|PPTX]], [[Media:OWASP_Presentation_template.odp|ODF/OpenOffice]]). &lt;br /&gt;
&lt;br /&gt;
Kosten (für Reise und Unterkunft) können wir leider nicht übernehmen. &lt;br /&gt;
&lt;br /&gt;
'''Alle Teilnehmer sowie Vortragende sind herzlich eingeladen zur Abendveranstaltung am 6.11.2012.''' &lt;br /&gt;
|&lt;br /&gt;
== CfP in detail ==&lt;br /&gt;
&lt;br /&gt;
To submit a proposal, please submit online (LINK) an abstract of the presentation (500 to 4000 chararters) and a brief biography (150 to 800 characters). The planned presentation time is 40 minutes (excl. 5 minutes for discussion). You can also attach a preliminary version of your presentation. (Please watch out for mistakes as we take your abstract and publish it 1:1 together with our program).&lt;br /&gt;
&lt;br /&gt;
We are interested in all topics related to Web Application Security and OWASP, in particular:&lt;br /&gt;
&lt;br /&gt;
*Technical presentations related to (security) operations&lt;br /&gt;
*Frameworks and best practices for secure development&lt;br /&gt;
*Mobile Security&lt;br /&gt;
*Cloud Security, specifically secure Cloud Apps&lt;br /&gt;
*Browser Security&lt;br /&gt;
*HTML5 Security&lt;br /&gt;
*Privacy in Web Applications and Web Services (REST, XML)&lt;br /&gt;
*Secure Development Lifecycle&lt;br /&gt;
*Metrics for application security&lt;br /&gt;
*Privacy protection in web based apps&lt;br /&gt;
*Security awareness programs for developers, testers, architects and project owners&lt;br /&gt;
*Security management for applications in the corporate environment&lt;br /&gt;
*Application security in Outsourcing and Offshoring projects&lt;br /&gt;
*Field reports from corporations regarding the institution of Web Application Security processes, internal and external auditing etc.&lt;br /&gt;
*OWASP in your workplace, university, etc.&lt;br /&gt;
&lt;br /&gt;
Depending on the number of submissions we will offer either one or two tracks. All presentations will be published on the conference website under the OWSAP license. Therefore all speakers must accept and sign the OWASP Speaker Agreement without changes prior to the conference. It requires that you use one of the following templates: ([[Media:OWASP_Presentation_template.ppt|PPT]], [[Media:OWASP_Presentation_template.pptx|PPTX]], [[Media:OWASP_Presentation_template.odp|ODF/OpenOffice]]). &lt;br /&gt;
&lt;br /&gt;
Unfortunately we can't cover any travel expenses or costs for accomodations.&lt;br /&gt;
&lt;br /&gt;
'''Participants and speakers are all warmly invited to attend the evening program on November 6, 2012'''.&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
== Programmkomitee  ==&lt;br /&gt;
&lt;br /&gt;
*Boris Hemkemeier &lt;br /&gt;
*Martin Johns (koordinierend)&lt;br /&gt;
*[[User:Kai Jendrian|Kai Jendrian]]&lt;br /&gt;
*Holger Junker&lt;br /&gt;
*Sachar Paulus&lt;br /&gt;
*Michael Schaefer&lt;br /&gt;
*[[User:Dr._Emin_Tatlı|Emin Tatli]]&lt;br /&gt;
*[[User:Dirk_Wetter|Dirk Wetter]] (koordinierend)&lt;br /&gt;
&lt;br /&gt;
|&lt;br /&gt;
== Program Committee ==&lt;br /&gt;
&lt;br /&gt;
*Boris Hemkemeier &lt;br /&gt;
*Martin Johns (coordinating)&lt;br /&gt;
*[[User:Kai Jendrian|Kai Jendrian]]&lt;br /&gt;
*Holger Junker&lt;br /&gt;
*Sachar Paulus&lt;br /&gt;
*Michael Schaefer&lt;br /&gt;
*[[User:Dr._Emin_Tatlı|Emin Tatli]]&lt;br /&gt;
*[[User:Dirk_Wetter|Dirk Wetter]] (coordinating)&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
== Termine / Einreichung ==&lt;br /&gt;
&lt;br /&gt;
*Einreichungen ausschließlich online bis zum ''15.8.2012''  über https://www.easychair.org/conferences/?conf=owaspger12 . &lt;br /&gt;
*Bitte geben sie alle vortragsrelevanten Informationen an (siehe Call for Presentations oben): &lt;br /&gt;
** Abstract&lt;br /&gt;
** Bio&lt;br /&gt;
** Länge&lt;br /&gt;
** ggf. Foliensätze &lt;br /&gt;
*Benachrichtigung der Einreicher 29.8.2012 (+1 Woche)&lt;br /&gt;
*Programm online: 1.9.2012 (+1 Woche)&lt;br /&gt;
*Einreichung prefinaler Foliensätze: 22.10.2012&lt;br /&gt;
*Konferenz: 7.11.2012&lt;br /&gt;
|&lt;br /&gt;
== Deadlines ==&lt;br /&gt;
&lt;br /&gt;
*Submissions no later than '''August 15, 2012''' only online via https://www.easychair.org/conferences/?conf=owaspger12 &lt;br /&gt;
*Please read and follow the requirements above: Abstract, bio, length and maybe slides!&lt;br /&gt;
*Notification of acceptance by August 29, 2012 (delay: one week)&lt;br /&gt;
*Program to be online: September 1, 2012 (delay: one week)&lt;br /&gt;
*Prefinal submission of the slides by October 22, 2012&lt;br /&gt;
*Conference: November 7, 2012&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=German_OWASP_Day_2012/CfP&amp;diff=135789</id>
		<title>German OWASP Day 2012/CfP</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=German_OWASP_Day_2012/CfP&amp;diff=135789"/>
				<updated>2012-09-13T17:53:35Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{|&lt;br /&gt;
|&lt;br /&gt;
__NOTOC__&lt;br /&gt;
&amp;lt;!-- das TOC ist doppelt FIXME --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_AppSec_Conference]] [[Category:Germany]] [[Category:Europe]] [[Category:German OWASP Day]]&lt;br /&gt;
&lt;br /&gt;
Die deutsche Sektion des Open Web Application Security Project (OWASP) richtet die zum fünften Mal eine deutsche OWASP-Konferenz aus: den German OWASP Day. Das German OWASP Chapter ruft für die diesjährige Konferenz auch wieder einen Call for Presentations (CfP) aus. Die Konferenz richtet sich primär an ein deutschsprachiges Publikum; die Konferenzsprache ist Deutsch, Vorträge in Englisch sind auch willkommen. Der German OWASP Day 2012 ist eine klassische Security-Konferenz, mit Fachvorträgen zu sicherer Entwicklung, Betrieb, Test und Managment im Umfeld von webbasierten Anwendungen bietet. Auch fachübergreifende, nicht-technische Themen sind willkommen. Bitte keine Marketingvorträge.&lt;br /&gt;
|&lt;br /&gt;
The German Chapter of the Open Web Application Security Project (OWASP) is again organizing a German OWASP Conference, for the 5th time this year: the German OWASP Day. &lt;br /&gt;
&lt;br /&gt;
There is a call for presentations (CfP), see below for details. The target group consists of German speaking people, and correspondingly the conference language is German, but English presentations are welcome as well. The German OWASP Day is a true security conference, with expected talks and presentations on secure software development, usage, test and management, all around web based applications. Non-technical talks are welcome as well. Please refrain from submitting plain marketing pitches.&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
== Fachliches ==&lt;br /&gt;
&lt;br /&gt;
Für Vortragsvorschläge bitten wir um eine Kurzzusammenfassung oder eine Vorabversion des Vortrags. Die Zusammenfassung sollte nicht weniger als 500 (maximal: 4000) Zeichen lang sein, damit das Programmkomitee eine gute Entscheidungsgrundlage hat. (Bitte auf Orthographie achten, da die Zusammenfassung so wie sie ist ggf. im Programm erscheint). Die gilt ebenso für die obligatorische Kurzbiographie (150-800 Zeichen). Die Präsentationen werden voraussichtlich 40 Minuten dauern, plus 5 Minuten Diskussion. &lt;br /&gt;
&lt;br /&gt;
Erwünscht sind alle Themen mit Bezug zu Webapplikationssicherheit und OWASP, insbesondere: &lt;br /&gt;
&lt;br /&gt;
*Praxisrelevante technische Vorträge&lt;br /&gt;
*Sichere Webanwendungen in der Cloud &lt;br /&gt;
*Mobile Security&lt;br /&gt;
*Browser-Sicherheit&lt;br /&gt;
*HTML5 Security&lt;br /&gt;
*Sicherheit bei Web Services (REST, XML)&lt;br /&gt;
*Sichere / Sicherheit bei Development Frameworks &lt;br /&gt;
*Security-Awareness und Education&lt;br /&gt;
*Vulnerability analysis und Application Security Testing: Code Review, Pentest, SCA&lt;br /&gt;
*Secure Development Lifecycle &lt;br /&gt;
*OWASP in Ihrem Unternehmen, Ihrer Hochschule etc.&lt;br /&gt;
*Anwendungssicherheit bei Outsourcing- und Offshoring-Projekten  &lt;br /&gt;
*Anwendungssicherheit und Metriken &lt;br /&gt;
*Datenschutz bei Webanwendungen&lt;br /&gt;
*Neues zu OWASP-Projekten/Standards/Tools&lt;br /&gt;
&lt;br /&gt;
Abhängig von der Anzahl eingehender Vorträge bieten wir ein oder zwei Tracks an. Folien der Vorträge werden unter der freien [[OWASP Licenses#Licensing_of_OWASP_Website_Content|OWASP Lizenz]] auf der Konferenzwebseite veröffentlicht. Daher muss spätestens bei Annahme des Beitrags durch das Programmkomitee das [[Speaker Agreement|OWASP Speaker Agreement]] ohne Änderung akzeptiert und unterschrieben werden. Das Speaker Agreements sieht vor, dass die Standardfoliensätze von OWASP verwendet werden ([[Media:OWASP_Presentation_template.ppt|PPT]], [[Media:OWASP_Presentation_template.pptx|PPTX]], [[Media:OWASP_Presentation_template.odp|ODF/OpenOffice]]). &lt;br /&gt;
&lt;br /&gt;
Kosten (für Reise und Unterkunft) können wir leider nicht übernehmen. &lt;br /&gt;
&lt;br /&gt;
'''Alle Teilnehmer sowie Vortragende sind herzlich eingeladen zur Abendveranstaltung am 6.11.2012.''' &lt;br /&gt;
|&lt;br /&gt;
== CfP in detail ==&lt;br /&gt;
&lt;br /&gt;
To submit a proposal, please submit online (LINK) an abstract of the presentation (500 to 4000 chararters) and a brief biography (150 to 800 characters). The planned presentation time is 40 minutes (excl. 5 minutes for discussion). You can also attach a preliminary version of your presentation. (Please watch out for mistakes as we take your abstract and publish it 1:1 together with our program).&lt;br /&gt;
&lt;br /&gt;
We are interested in all topics related to Web Application Security and OWASP, in particular:&lt;br /&gt;
&lt;br /&gt;
*Technical presentations related to (security) operations&lt;br /&gt;
*Frameworks and best practices for secure development&lt;br /&gt;
*Mobile Security&lt;br /&gt;
*Cloud Security, specifically secure Cloud Apps&lt;br /&gt;
*Browser Security&lt;br /&gt;
*HTML5 Security&lt;br /&gt;
*Privacy in Web Applications and Web Services (REST, XML)&lt;br /&gt;
*Secure Development Lifecycle&lt;br /&gt;
*Metrics for application security&lt;br /&gt;
*Privacy protection in web based apps&lt;br /&gt;
*Security awareness programs for developers, testers, architects and project owners&lt;br /&gt;
*Security management for applications in the corporate environment&lt;br /&gt;
*Application security in Outsourcing and Offshoring projects&lt;br /&gt;
*Field reports from corporations regarding the institution of Web Application Security processes, internal and external auditing etc.&lt;br /&gt;
*OWASP in your workplace, university, etc.&lt;br /&gt;
&lt;br /&gt;
Depending on the number of submissions we will offer either one or two tracks. All presentations will be published on the conference website under the OWSAP license. Therefore all speakers must accept and sign the OWASP Speaker Agreement without changes prior to the conference. It requires that you use one of the following templates: ([[Media:OWASP_Presentation_template.ppt|PPT]], [[Media:OWASP_Presentation_template.pptx|PPTX]], [[Media:OWASP_Presentation_template.odp|ODF/OpenOffice]]). &lt;br /&gt;
&lt;br /&gt;
Unfortunately we can't cover any travel expenses or costs for accomodations.&lt;br /&gt;
&lt;br /&gt;
'''Participants and speakers are all warmly invited to attend the evening program on November 6, 2012'''.&lt;br /&gt;
&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
== Programmkomitee  ==&lt;br /&gt;
&lt;br /&gt;
*Boris Hemkemeier &lt;br /&gt;
*Martin Johns (koordinierend)&lt;br /&gt;
*[[User:Kai Jendrian|Kai Jendrian]]&lt;br /&gt;
*Holger Junker&lt;br /&gt;
*Sachar Paulus&lt;br /&gt;
*Michael Schaefer&lt;br /&gt;
*[[User:DrEminTatli|Emin Tatli]]Emin Tatlı&lt;br /&gt;
*[[User:Dirk_Wetter|Dirk Wetter]] (koordinierend)&lt;br /&gt;
&lt;br /&gt;
|&lt;br /&gt;
== Program Committee ==&lt;br /&gt;
&lt;br /&gt;
*Boris Hemkemeier &lt;br /&gt;
*Martin Johns (coordinating)&lt;br /&gt;
*[[User:Kai Jendrian|Kai Jendrian]]&lt;br /&gt;
*Holger Junker&lt;br /&gt;
*Sachar Paulus&lt;br /&gt;
*Michael Schaefer&lt;br /&gt;
*Emin Tatlı&lt;br /&gt;
*[[User:Dirk_Wetter|Dirk Wetter]] (coordinating)&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
&lt;br /&gt;
== Termine / Einreichung ==&lt;br /&gt;
&lt;br /&gt;
*Einreichungen ausschließlich online bis zum ''15.8.2012''  über https://www.easychair.org/conferences/?conf=owaspger12 . &lt;br /&gt;
*Bitte geben sie alle vortragsrelevanten Informationen an (siehe Call for Presentations oben): &lt;br /&gt;
** Abstract&lt;br /&gt;
** Bio&lt;br /&gt;
** Länge&lt;br /&gt;
** ggf. Foliensätze &lt;br /&gt;
*Benachrichtigung der Einreicher 29.8.2012 (+1 Woche)&lt;br /&gt;
*Programm online: 1.9.2012 (+1 Woche)&lt;br /&gt;
*Einreichung prefinaler Foliensätze: 22.10.2012&lt;br /&gt;
*Konferenz: 7.11.2012&lt;br /&gt;
|&lt;br /&gt;
== Deadlines ==&lt;br /&gt;
&lt;br /&gt;
*Submissions no later than '''August 15, 2012''' only online via https://www.easychair.org/conferences/?conf=owaspger12 &lt;br /&gt;
*Please read and follow the requirements above: Abstract, bio, length and maybe slides!&lt;br /&gt;
*Notification of acceptance by August 29, 2012 (delay: one week)&lt;br /&gt;
*Program to be online: September 1, 2012 (delay: one week)&lt;br /&gt;
*Prefinal submission of the slides by October 22, 2012&lt;br /&gt;
*Conference: November 7, 2012&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135747</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135747"/>
				<updated>2012-09-13T16:45:12Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Born in Turkey &amp;amp; Living since 2001 in Germany&lt;br /&gt;
* Ex-IBMer and working now as Security Architect and Researcher by Daimler TSS&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design&amp;amp;coding trainings, risk management&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Since 2010 Board Member of [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of [[Germany|German Chapter]]&lt;br /&gt;
* Organisation and Program Committee of OWASP Conferences in Germany and Turkey&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
* Written articles about OWASP projects &lt;br /&gt;
** [http://www.architectingsecurity.com/wp-content/uploads/papers/SAMM-Tatli-Ocak11.pdf Secure Application Development with OpenSAMM] (in Turkish)&lt;br /&gt;
** OWASP Guidelines and Tools for Secure SDLC (in German)&lt;br /&gt;
* Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
 &lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135745</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135745"/>
				<updated>2012-09-13T16:44:00Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Born in Turkey &amp;amp; Living since 2001 in Germany&lt;br /&gt;
* Ex-IBMer and working now as Security Architect and Researcher by Daimler TSS&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design&amp;amp;coding trainings, risk management&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Since 2010 Board Member of [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of [[Germany|German Chapter]]&lt;br /&gt;
* OWASP German Conferences, Program Committee and more&lt;br /&gt;
&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
* Written articles about OWASP projects &lt;br /&gt;
** [http://www.architectingsecurity.com/wp-content/uploads/papers/SAMM-Tatli-Ocak11.pdf Secure Application Development with OpenSAMM] (in Turkish)&lt;br /&gt;
** OWASP Guidelines and Tools for Secure SDLC (in German)&lt;br /&gt;
* Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
 &lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135744</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135744"/>
				<updated>2012-09-13T16:42:10Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Born in Turkey &amp;amp; Living since 2001 in Germany&lt;br /&gt;
* Ex-IBMer and working now as Security Architect and Researcher by Daimler TSS&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design&amp;amp;coding trainings, risk management&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Since 2010 Board Member of [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of [[Germany|German Chapter]]&lt;br /&gt;
* OWASP German Conferences, Program Committee and more&lt;br /&gt;
&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
* Written articles about OWASP projects &lt;br /&gt;
** [http://www.architectingsecurity.com/wp-content/uploads/papers/SAMM-Tatli-Ocak11.pdf Secure Application Development with SAMM] (in Turkish)&lt;br /&gt;
* Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
 &lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135743</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135743"/>
				<updated>2012-09-13T16:39:47Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Born in Turkey &amp;amp; Living since 2001 in Germany&lt;br /&gt;
* Ex-IBMer and working now as Security Architect and Researcher by Daimler TSS&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design&amp;amp;coding trainings, risk management&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Since 2010 Board Member of [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of [[Germany|German Chapter]]&lt;br /&gt;
* OWASP German Conferences, Program Committee and more&lt;br /&gt;
&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
* Written articles about OWASP projects &lt;br /&gt;
** &lt;br /&gt;
* Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
 &lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135742</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135742"/>
				<updated>2012-09-13T16:37:45Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Born in Turkey &amp;amp; Living since 2001 in Germany&lt;br /&gt;
* Ex-IBMer and working now as Security Architect and Researcher by Daimler TSS&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design&amp;amp;coding trainings, risk management&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Since 2010 Board Member of [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of [[Germany|German Chapter]]&lt;br /&gt;
* OWASP German Conferences, Program Committee and more&lt;br /&gt;
&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
&lt;br /&gt;
* Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
 &lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135741</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135741"/>
				<updated>2012-09-13T16:36:36Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Born in Turkey &amp;amp; Living since 2001 in Germany&lt;br /&gt;
* Ex-IBMer and working now as Security Architect and Researcher by Daimler TSS&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design&amp;amp;coding trainings, risk management&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Since 2010 Board Member of Turkey Chapter [[Turkey|Turkey Chapter]]&lt;br /&gt;
* Since 2012 Board Member of German Chapter [[Germany|German Chapter]]&lt;br /&gt;
* OWASP German Conferences, Program Committee and more&lt;br /&gt;
&lt;br /&gt;
=== OWASP Contributions===&lt;br /&gt;
&lt;br /&gt;
* Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
 &lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135740</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135740"/>
				<updated>2012-09-13T16:33:01Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Born in Turkey &amp;amp; Living since 2001 in Germany&lt;br /&gt;
* Ex-IBMer and working now as Security Architect and Researcher by Daimler TSS&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design&amp;amp;coding trainings, risk management&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/ wasclist]&lt;br /&gt;
 &lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: [https://twitter.com/eitatli @eitatli]&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135739</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135739"/>
				<updated>2012-09-13T16:31:36Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Born in Turkey &amp;amp; Living since 2001 in Germany&lt;br /&gt;
* Ex-IBMer and working now as Security Architect and Researcher by Daimler TSS&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design&amp;amp;coding trainings, risk management&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/]&lt;br /&gt;
 &lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org &lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: @eitatli&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135738</id>
		<title>User:Dr. Emin Tatlı</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Dr._Emin_Tatl%C4%B1&amp;diff=135738"/>
				<updated>2012-09-13T16:30:04Z</updated>
		
		<summary type="html">&lt;p&gt;Dr. Emin Tatlı: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=== Personal &amp;amp; Work ===&lt;br /&gt;
&lt;br /&gt;
* Born in Turkey &amp;amp; Living since 2001 in Germany&lt;br /&gt;
* Ex-IBMer and working now as Security Architect and Researcher by Daimler TSS&lt;br /&gt;
* Focusing on penetration testing, security analysis of architectures, secure design&amp;amp;coding trainings, risk management&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=== OWASP Activities ===&lt;br /&gt;
&lt;br /&gt;
* Managing OWASP-Turkey's Web Application Security Check List project: [http://code.google.com/p/wasclist/]&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
=== Contact ===&lt;br /&gt;
* Blog: [http://www.architectingsecurity.com]&lt;br /&gt;
* E-mail: emin.tatli @ owasp dot org&lt;br /&gt;
* [http://www.linkedin.com/in/tatli LinkedIn]&lt;br /&gt;
* Twitter: @eitatli&lt;/div&gt;</summary>
		<author><name>Dr. Emin Tatlı</name></author>	</entry>

	</feed>