<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Gaurav+Kumar</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Gaurav+Kumar"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Gaurav_Kumar"/>
		<updated>2026-05-08T13:07:04Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121832</id>
		<title>OWASP OVAL Content Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121832"/>
				<updated>2011-12-26T10:56:13Z</updated>
		
		<summary type="html">&lt;p&gt;Gaurav Kumar: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
This project’s goal is to create standardized assesment documents (in OVAL XML format) for various application platforms such as .NET, Java, PHP etc. For example, there are several settings like Web.Config file which impacts security of ASP.NET web application. Likewise, PHP.INI has several security related settings. By creating OVAL definitions for these checks, it will enable any OVAL compatible tool (including the free OVAL Interpreter) to perform these checks. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== PHP Security Settings&amp;lt;br&amp;gt;  ====&lt;br /&gt;
&lt;br /&gt;
'''PHP OVAL definitions''' can be downloaded from [http://owasp-oval.googlecode.com/files/php.xml here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre style=&amp;quot;color:blue&amp;quot;&amp;gt;&lt;br /&gt;
Please note that current definitions are designed to work on PHP Module loaded by Apache2 web server running on Linux OS&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Details on these definitions can be found [https://docs.google.com/spreadsheet/pub?hl=en_US&amp;amp;key=0AhyObjO7VTMDdHlxbHFrN2VUdHp1NWZUQ0sxNGZOb1E&amp;amp;hl=en_US&amp;amp;gid=0 here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP OVAL Content Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|OVAL Content Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Download]] [[Category:OWASP_Alpha_Quality_Tool]]&lt;/div&gt;</summary>
		<author><name>Gaurav Kumar</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121831</id>
		<title>OWASP OVAL Content Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121831"/>
				<updated>2011-12-26T10:46:02Z</updated>
		
		<summary type="html">&lt;p&gt;Gaurav Kumar: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
This project’s goal is to create standardized assesment documents (in OVAL XML format) for various application platforms such as .NET, Java, PHP etc. For example, there are several settings like Web.Config file which impacts security of ASP.NET web application. Likewise, PHP.INI has several security related settings. By creating OVAL definitions for these checks, it will enable any OVAL compatible tool (including the free OVAL Interpreter) to perform these checks. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== PHP Security Settings&amp;lt;br&amp;gt;  ====&lt;br /&gt;
&lt;br /&gt;
'''PHP OVAL definitions''' can be downloaded from [http://owasp-oval.googlecode.com/files/php.xml here]&lt;br /&gt;
&lt;br /&gt;
Please note that these are designed to work on PHP Module loaded by Apache2 web server running on Linux OS &lt;br /&gt;
&lt;br /&gt;
Details on these definitions can be found [https://docs.google.com/spreadsheet/pub?hl=en_US&amp;amp;key=0AhyObjO7VTMDdHlxbHFrN2VUdHp1NWZUQ0sxNGZOb1E&amp;amp;hl=en_US&amp;amp;gid=0 here]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP OVAL Content Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|OVAL Content Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Download]] [[Category:OWASP_Alpha_Quality_Tool]]&lt;/div&gt;</summary>
		<author><name>Gaurav Kumar</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121227</id>
		<title>OWASP OVAL Content Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121227"/>
				<updated>2011-12-08T19:36:48Z</updated>
		
		<summary type="html">&lt;p&gt;Gaurav Kumar: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
This project’s goal is to create standardized assesment documents (in OVAL XML format) for various application platforms such as .NET, Java, PHP etc. For example, there are several settings like Web.Config file which impacts security of ASP.NET web application. Likewise, PHP.INI has several security related settings. By creating OVAL definitions for these checks, it will enable any OVAL compatible tool (including the free OVAL Interpreter) to perform these checks. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
PHP Related Security Definitions. &lt;br /&gt;
&lt;br /&gt;
Below is a sample OVAL definition file which detects if Apache web server is running &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;?xml version =&amp;quot;1.0&amp;quot; encoding=&amp;quot;utf-8&amp;quot;?&amp;amp;gt; &amp;amp;lt;oval_definitions xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5&amp;quot; xmlns:xsi=&amp;quot;http://www.w3.org/2001/XMLSchema-instance&amp;quot; xmlns:oval=&amp;quot;http://oval.mitre.org/XMLSchema/oval-common-5&amp;quot; xmlns:oval-def=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5&amp;quot; xsi:schemaLocation=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd&amp;quot;&amp;amp;gt; &lt;br /&gt;
&lt;br /&gt;
 &amp;amp;lt;generator&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;oval:product_name&amp;amp;gt;OWASP OVAL Content Project&amp;amp;lt;/oval:product_name&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;oval:schema_version&amp;amp;gt;5.10&amp;amp;lt;/oval:schema_version&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;oval:timestamp&amp;amp;gt;2011-12-07T11:18:10.417-04:00&amp;amp;lt;/oval:timestamp&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/generator&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;definitions&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;definition id =&amp;quot;oval:org.owasp.oval:def:1&amp;quot; class =&amp;quot;compliance&amp;quot; version=&amp;quot;1&amp;quot;&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;metadata&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;title&amp;amp;gt;Apache2 is running&amp;amp;lt;/title&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;description&amp;amp;gt;Apache2 has been found to be running&amp;amp;lt;/description&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/metadata&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;criteria&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;criterion comment=&amp;quot;test&amp;quot; test_ref=&amp;quot;oval:org.owasp.oval:tst:1&amp;quot;/&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/criteria&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/definition&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/definitions&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
  &amp;amp;lt;tests&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;process58_test xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5#unix&amp;quot; id=&amp;quot;oval:org.owasp.oval:tst:1&amp;quot; version=&amp;quot;1&amp;quot; comment=&amp;quot;Apache2 running&amp;quot; check_existence=&amp;quot;at_least_one_exists&amp;quot; check=&amp;quot;at least one&amp;quot;&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;object object_ref=&amp;quot;oval:org.owasp.oval:obj:1&amp;quot;/&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/process58_test&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/tests&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
  &amp;amp;lt;objects&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;process58_object xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5#unix&amp;quot; id=&amp;quot;oval:org.owasp.oval:obj:1&amp;quot; version=&amp;quot;1&amp;quot;&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;command_line operation=&amp;quot;pattern match&amp;quot;&amp;amp;gt;.*apache2 .*&amp;amp;lt;/command_line&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;pid datatype=&amp;quot;int&amp;quot; operation=&amp;quot;greater than&amp;quot;&amp;amp;gt;0&amp;amp;lt;/pid&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/process58_object&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/objects&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;/oval_definitions&amp;amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== PHP Security Settings&amp;lt;br&amp;gt;  ====&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;200&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | No &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | Setting &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | Recommended Value &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | Description &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | OVAL Definition&lt;br /&gt;
|-&lt;br /&gt;
| 1 &lt;br /&gt;
| register_globals &lt;br /&gt;
| &amp;lt;span class=&amp;quot;Apple-tab-span&amp;quot; style=&amp;quot;white-space:pre&amp;quot;&amp;gt;	&amp;lt;/span&amp;gt;Off &lt;br /&gt;
| http://www.php.net/manual/en/security.globals.php &lt;br /&gt;
| TBD&lt;br /&gt;
|-&lt;br /&gt;
| 2 &lt;br /&gt;
| magic_quotes_gpc &lt;br /&gt;
| &amp;lt;span class=&amp;quot;Apple-tab-span&amp;quot; style=&amp;quot;white-space:pre&amp;quot;&amp;gt;	&amp;lt;/span&amp;gt;On &lt;br /&gt;
| http://us3.php.net/manual/en/security.magicquotes.whynot.php &lt;br /&gt;
| TBD&lt;br /&gt;
|-&lt;br /&gt;
| 3 &lt;br /&gt;
| expose_php &lt;br /&gt;
| &amp;lt;span class=&amp;quot;Apple-tab-span&amp;quot; style=&amp;quot;white-space:pre&amp;quot;&amp;gt;	&amp;lt;/span&amp;gt;Off &lt;br /&gt;
| Reduce the amount of information available which includes the PHP version within the HTTP header (e.g., X-Powered-By: PHP/5.3.7). &lt;br /&gt;
| TBD&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP OVAL Content Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|OVAL Content Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Download]] [[Category:OWASP_Alpha_Quality_Tool]]&lt;/div&gt;</summary>
		<author><name>Gaurav Kumar</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121226</id>
		<title>OWASP OVAL Content Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121226"/>
				<updated>2011-12-08T19:35:07Z</updated>
		
		<summary type="html">&lt;p&gt;Gaurav Kumar: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
This project’s goal is to create standardized assesment documents (in OVAL XML format) for various application platforms such as .NET, Java, PHP etc. For example, there are several settings like Web.Config file which impacts security of ASP.NET web application. Likewise, PHP.INI has several security related settings. By creating OVAL definitions for these checks, it will enable any OVAL compatible tool (including the free OVAL Interpreter) to perform these checks. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
PHP Related Security Definitions. &lt;br /&gt;
&lt;br /&gt;
Below is a sample OVAL definition file which detects if Apache web server is running &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;?xml version =&amp;quot;1.0&amp;quot; encoding=&amp;quot;utf-8&amp;quot;?&amp;amp;gt; &amp;amp;lt;oval_definitions xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5&amp;quot; xmlns:xsi=&amp;quot;http://www.w3.org/2001/XMLSchema-instance&amp;quot; xmlns:oval=&amp;quot;http://oval.mitre.org/XMLSchema/oval-common-5&amp;quot; xmlns:oval-def=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5&amp;quot; xsi:schemaLocation=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd&amp;quot;&amp;amp;gt; &lt;br /&gt;
&lt;br /&gt;
 &amp;amp;lt;generator&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;oval:product_name&amp;amp;gt;OWASP OVAL Content Project&amp;amp;lt;/oval:product_name&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;oval:schema_version&amp;amp;gt;5.10&amp;amp;lt;/oval:schema_version&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;oval:timestamp&amp;amp;gt;2011-12-07T11:18:10.417-04:00&amp;amp;lt;/oval:timestamp&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/generator&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;definitions&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;definition id =&amp;quot;oval:org.owasp.oval:def:1&amp;quot; class =&amp;quot;compliance&amp;quot; version=&amp;quot;1&amp;quot;&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;metadata&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;title&amp;amp;gt;Apache2 is running&amp;amp;lt;/title&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;description&amp;amp;gt;Apache2 has been found to be running&amp;amp;lt;/description&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/metadata&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;criteria&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;criterion comment=&amp;quot;test&amp;quot; test_ref=&amp;quot;oval:org.owasp.oval:tst:1&amp;quot;/&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/criteria&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/definition&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/definitions&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
  &amp;amp;lt;tests&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;process58_test xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5#unix&amp;quot; id=&amp;quot;oval:org.owasp.oval:tst:1&amp;quot; version=&amp;quot;1&amp;quot; comment=&amp;quot;Apache2 running&amp;quot; check_existence=&amp;quot;at_least_one_exists&amp;quot; check=&amp;quot;at least one&amp;quot;&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;object object_ref=&amp;quot;oval:org.owasp.oval:obj:1&amp;quot;/&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/process58_test&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/tests&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
  &amp;amp;lt;objects&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;process58_object xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5#unix&amp;quot; id=&amp;quot;oval:org.owasp.oval:obj:1&amp;quot; version=&amp;quot;1&amp;quot;&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;command_line operation=&amp;quot;pattern match&amp;quot;&amp;amp;gt;.*apache2 .*&amp;amp;lt;/command_line&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;pid datatype=&amp;quot;int&amp;quot; operation=&amp;quot;greater than&amp;quot;&amp;amp;gt;0&amp;amp;lt;/pid&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/process58_object&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/objects&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;/oval_definitions&amp;amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== PHP Security Settings&amp;lt;br&amp;gt;  ====&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;200&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | No &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | Setting &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | Recommended Value &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | Description &lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | OVAL Definition&lt;br /&gt;
|-&lt;br /&gt;
| [[1]] &lt;br /&gt;
| register_globals &lt;br /&gt;
| &amp;lt;span class=&amp;quot;Apple-tab-span&amp;quot; style=&amp;quot;white-space:pre&amp;quot;&amp;gt;	&amp;lt;/span&amp;gt;Off &lt;br /&gt;
| http://www.php.net/manual/en/security.globals.php &lt;br /&gt;
| TBD&lt;br /&gt;
|-&lt;br /&gt;
| [[2]] &lt;br /&gt;
| magic_quotes_gpc &lt;br /&gt;
| &amp;lt;span class=&amp;quot;Apple-tab-span&amp;quot; style=&amp;quot;white-space:pre&amp;quot;&amp;gt;	&amp;lt;/span&amp;gt;On &lt;br /&gt;
| http://us3.php.net/manual/en/security.magicquotes.whynot.php &lt;br /&gt;
| TBD&lt;br /&gt;
|-&lt;br /&gt;
| [[3]] &lt;br /&gt;
| expose_php &lt;br /&gt;
| &amp;lt;span class=&amp;quot;Apple-tab-span&amp;quot; style=&amp;quot;white-space:pre&amp;quot;&amp;gt;	&amp;lt;/span&amp;gt;Off &lt;br /&gt;
| Reduce the amount of information available which includes the PHP version within the HTTP header (e.g., X-Powered-By: PHP/5.3.7). &lt;br /&gt;
| TBD&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP OVAL Content Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|OVAL Content Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Download]] [[Category:OWASP_Alpha_Quality_Tool]]&lt;/div&gt;</summary>
		<author><name>Gaurav Kumar</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121225</id>
		<title>OWASP OVAL Content Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121225"/>
				<updated>2011-12-08T19:27:35Z</updated>
		
		<summary type="html">&lt;p&gt;Gaurav Kumar: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
This project’s goal is to create standardized assesment documents (in OVAL XML format) for various application platforms such as .NET, Java, PHP etc. For example, there are several settings like Web.Config file which impacts security of ASP.NET web application. Likewise, PHP.INI has several security related settings. By creating OVAL definitions for these checks, it will enable any OVAL compatible tool (including the free OVAL Interpreter) to perform these checks. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
PHP Related Security Definitions. &lt;br /&gt;
&lt;br /&gt;
Below is a sample OVAL definition file which detects if Apache web server is running &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;?xml version =&amp;quot;1.0&amp;quot; encoding=&amp;quot;utf-8&amp;quot;?&amp;amp;gt; &amp;amp;lt;oval_definitions xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5&amp;quot; xmlns:xsi=&amp;quot;http://www.w3.org/2001/XMLSchema-instance&amp;quot; xmlns:oval=&amp;quot;http://oval.mitre.org/XMLSchema/oval-common-5&amp;quot; xmlns:oval-def=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5&amp;quot; xsi:schemaLocation=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd&amp;quot;&amp;amp;gt; &lt;br /&gt;
&lt;br /&gt;
 &amp;amp;lt;generator&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;oval:product_name&amp;amp;gt;OWASP OVAL Content Project&amp;amp;lt;/oval:product_name&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;oval:schema_version&amp;amp;gt;5.10&amp;amp;lt;/oval:schema_version&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;oval:timestamp&amp;amp;gt;2011-12-07T11:18:10.417-04:00&amp;amp;lt;/oval:timestamp&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/generator&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;definitions&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;definition id =&amp;quot;oval:org.owasp.oval:def:1&amp;quot; class =&amp;quot;compliance&amp;quot; version=&amp;quot;1&amp;quot;&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;metadata&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;title&amp;amp;gt;Apache2 is running&amp;amp;lt;/title&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;description&amp;amp;gt;Apache2 has been found to be running&amp;amp;lt;/description&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/metadata&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;criteria&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;criterion comment=&amp;quot;test&amp;quot; test_ref=&amp;quot;oval:org.owasp.oval:tst:1&amp;quot;/&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/criteria&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/definition&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/definitions&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
  &amp;amp;lt;tests&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;process58_test xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5#unix&amp;quot; id=&amp;quot;oval:org.owasp.oval:tst:1&amp;quot; version=&amp;quot;1&amp;quot; comment=&amp;quot;Apache2 running&amp;quot; check_existence=&amp;quot;at_least_one_exists&amp;quot; check=&amp;quot;at least one&amp;quot;&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;object object_ref=&amp;quot;oval:org.owasp.oval:obj:1&amp;quot;/&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/process58_test&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/tests&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
  &amp;amp;lt;objects&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;process58_object xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5#unix&amp;quot; id=&amp;quot;oval:org.owasp.oval:obj:1&amp;quot; version=&amp;quot;1&amp;quot;&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;command_line operation=&amp;quot;pattern match&amp;quot;&amp;amp;gt;.*apache2 .*&amp;amp;lt;/command_line&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;pid datatype=&amp;quot;int&amp;quot; operation=&amp;quot;greater than&amp;quot;&amp;amp;gt;0&amp;amp;lt;/pid&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/process58_object&amp;amp;gt;&lt;br /&gt;
 &amp;amp;lt;/objects&amp;amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;amp;lt;/oval_definitions&amp;amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== PHP Security Settings&amp;lt;br&amp;gt;  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| width=&amp;quot;200&amp;quot; border=&amp;quot;1&amp;quot; cellpadding=&amp;quot;1&amp;quot; cellspacing=&amp;quot;1&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | No&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | Setting&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | Recommended Value&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | Description&lt;br /&gt;
! scope=&amp;quot;col&amp;quot; | OVAL Definition&lt;br /&gt;
|-&lt;br /&gt;
| 1&lt;br /&gt;
| register_globals &lt;br /&gt;
| &amp;lt;span class=&amp;quot;Apple-tab-span&amp;quot; style=&amp;quot;white-space:pre&amp;quot;&amp;gt;	&amp;lt;/span&amp;gt;Off&lt;br /&gt;
| http://www.php.net/manual/en/security.globals.php&lt;br /&gt;
| TBD&lt;br /&gt;
|-&lt;br /&gt;
| 2&lt;br /&gt;
| magic_quotes_gpc &lt;br /&gt;
| &amp;lt;span class=&amp;quot;Apple-tab-span&amp;quot; style=&amp;quot;white-space:pre&amp;quot;&amp;gt;	&amp;lt;/span&amp;gt;On&lt;br /&gt;
| http://us3.php.net/manual/en/security.magicquotes.whynot.php&lt;br /&gt;
| TBD&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP OVAL Content Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|OVAL Content Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Download]] [[Category:OWASP_Alpha_Quality_Tool]]&lt;/div&gt;</summary>
		<author><name>Gaurav Kumar</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121224</id>
		<title>OWASP OVAL Content Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121224"/>
				<updated>2011-12-08T18:54:30Z</updated>
		
		<summary type="html">&lt;p&gt;Gaurav Kumar: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
This project’s goal is to create standardized assesment documents (in OVAL XML format) for various application platforms such as .NET, Java, PHP etc. For example, there are several settings like Web.Config file which impacts security of ASP.NET web application. Likewise, PHP.INI has several security related settings. By creating OVAL definitions for these checks, it will enable any OVAL compatible tool (including the free OVAL Interpreter) to perform these checks. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
PHP Related Security Definitions. &lt;br /&gt;
&lt;br /&gt;
Below is a sample OVAL definition file which detects if Apache web server is running &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;?xml version =&amp;quot;1.0&amp;quot; encoding=&amp;quot;utf-8&amp;quot;?&amp;gt;&lt;br /&gt;
&amp;lt;oval_definitions xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5&amp;quot; xmlns:xsi=&amp;quot;http://www.w3.org/2001/XMLSchema-instance&amp;quot; xmlns:oval=&amp;quot;http://oval.mitre.org/XMLSchema/oval-common-5&amp;quot; xmlns:oval-def=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5&amp;quot; xsi:schemaLocation=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;generator&amp;gt;&lt;br /&gt;
    &amp;lt;oval:product_name&amp;gt;OWASP OVAL Content Project&amp;lt;/oval:product_name&amp;gt;&lt;br /&gt;
    &amp;lt;oval:schema_version&amp;gt;5.10&amp;lt;/oval:schema_version&amp;gt;&lt;br /&gt;
    &amp;lt;oval:timestamp&amp;gt;2011-12-07T11:18:10.417-04:00&amp;lt;/oval:timestamp&amp;gt;&lt;br /&gt;
  &amp;lt;/generator&amp;gt;&lt;br /&gt;
  &amp;lt;definitions&amp;gt;&lt;br /&gt;
    &amp;lt;definition id =&amp;quot;oval:org.owasp.oval:def:1&amp;quot; class =&amp;quot;compliance&amp;quot; version=&amp;quot;1&amp;quot;&amp;gt;&lt;br /&gt;
      &amp;lt;metadata&amp;gt;&lt;br /&gt;
        &amp;lt;title&amp;gt;Apache2 is running&amp;lt;/title&amp;gt;&lt;br /&gt;
        &amp;lt;description&amp;gt;Apache2 has been found to be running&amp;lt;/description&amp;gt;&lt;br /&gt;
      &amp;lt;/metadata&amp;gt;&lt;br /&gt;
      &amp;lt;criteria&amp;gt;&lt;br /&gt;
        &amp;lt;criterion comment=&amp;quot;test&amp;quot; test_ref=&amp;quot;oval:org.owasp.oval:tst:1&amp;quot;/&amp;gt;&lt;br /&gt;
      &amp;lt;/criteria&amp;gt;&lt;br /&gt;
    &amp;lt;/definition&amp;gt;&lt;br /&gt;
  &amp;lt;/definitions&amp;gt;&lt;br /&gt;
&lt;br /&gt;
  &amp;lt;tests&amp;gt;&lt;br /&gt;
    &amp;lt;process58_test xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5#unix&amp;quot; id=&amp;quot;oval:org.owasp.oval:tst:1&amp;quot; version=&amp;quot;1&amp;quot; comment=&amp;quot;Apache2 running&amp;quot; check_existence=&amp;quot;at_least_one_exists&amp;quot; check=&amp;quot;at least one&amp;quot;&amp;gt;&lt;br /&gt;
      &amp;lt;object object_ref=&amp;quot;oval:org.owasp.oval:obj:1&amp;quot;/&amp;gt;&lt;br /&gt;
    &amp;lt;/process58_test&amp;gt;&lt;br /&gt;
  &amp;lt;/tests&amp;gt;&lt;br /&gt;
&lt;br /&gt;
  &amp;lt;objects&amp;gt;&lt;br /&gt;
    &amp;lt;process58_object xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5#unix&amp;quot; id=&amp;quot;oval:org.owasp.oval:obj:1&amp;quot; version=&amp;quot;1&amp;quot;&amp;gt;&lt;br /&gt;
      &amp;lt;command_line operation=&amp;quot;pattern match&amp;quot;&amp;gt;.*apache2 .*&amp;lt;/command_line&amp;gt;&lt;br /&gt;
      &amp;lt;pid datatype=&amp;quot;int&amp;quot; operation=&amp;quot;greater than&amp;quot;&amp;gt;0&amp;lt;/pid&amp;gt;&lt;br /&gt;
    &amp;lt;/process58_object&amp;gt;&lt;br /&gt;
  &amp;lt;/objects&amp;gt;&lt;br /&gt;
&amp;lt;/oval_definitions&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== PHP Security Settings  ====&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP OVAL Content Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|OVAL Content Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Download]] [[Category:OWASP_Alpha_Quality_Tool]]&lt;/div&gt;</summary>
		<author><name>Gaurav Kumar</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121212</id>
		<title>OWASP OVAL Content Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=121212"/>
				<updated>2011-12-08T06:05:03Z</updated>
		
		<summary type="html">&lt;p&gt;Gaurav Kumar: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
This project’s goal is to create standardized assesment documents (in OVAL XML format) for various application platforms such as .NET, Java, PHP etc. For example, there are several settings like Web.Config file which impacts security of ASP.NET web application. Likewise, PHP.INI has several security related settings. By creating OVAL definitions for these checks, it will enable any OVAL compatible tool (including the free OVAL Interpreter) to perform these checks. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
PHP Related Security Definitions. &lt;br /&gt;
&lt;br /&gt;
Below is a sample OVAL definition file which detects if Apache web server is running &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&amp;lt;?xml version =&amp;quot;1.0&amp;quot; encoding=&amp;quot;utf-8&amp;quot;?&amp;gt;&lt;br /&gt;
&amp;lt;oval_definitions xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5&amp;quot; xmlns:xsi=&amp;quot;http://www.w3.org/2001/XMLSchema-instance&amp;quot; xmlns:oval=&amp;quot;http://oval.mitre.org/XMLSchema/oval-common-5&amp;quot; xmlns:oval-def=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5&amp;quot; xsi:schemaLocation=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5 oval-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#solaris solaris-definitions-schema.xsd http://oval.mitre.org/XMLSchema/oval-common-5 oval-common-schema.xsd http://oval.mitre.org/XMLSchema/oval-definitions-5#unix unix-definitions-schema.xsd&amp;quot;&amp;gt;&lt;br /&gt;
&lt;br /&gt;
 &amp;lt;generator&amp;gt;&lt;br /&gt;
    &amp;lt;oval:product_name&amp;gt;OWASP OVAL Content Project&amp;lt;/oval:product_name&amp;gt;&lt;br /&gt;
    &amp;lt;oval:schema_version&amp;gt;5.10&amp;lt;/oval:schema_version&amp;gt;&lt;br /&gt;
    &amp;lt;oval:timestamp&amp;gt;2011-12-07T11:18:10.417-04:00&amp;lt;/oval:timestamp&amp;gt;&lt;br /&gt;
  &amp;lt;/generator&amp;gt;&lt;br /&gt;
  &amp;lt;definitions&amp;gt;&lt;br /&gt;
    &amp;lt;definition id =&amp;quot;oval:org.owasp.oval:def:1&amp;quot; class =&amp;quot;compliance&amp;quot; version=&amp;quot;1&amp;quot;&amp;gt;&lt;br /&gt;
      &amp;lt;metadata&amp;gt;&lt;br /&gt;
        &amp;lt;title&amp;gt;Apache2 is running&amp;lt;/title&amp;gt;&lt;br /&gt;
        &amp;lt;description&amp;gt;Apache2 has been found to be running&amp;lt;/description&amp;gt;&lt;br /&gt;
      &amp;lt;/metadata&amp;gt;&lt;br /&gt;
      &amp;lt;criteria&amp;gt;&lt;br /&gt;
        &amp;lt;criterion comment=&amp;quot;test&amp;quot; test_ref=&amp;quot;oval:org.owasp.oval:tst:1&amp;quot;/&amp;gt;&lt;br /&gt;
      &amp;lt;/criteria&amp;gt;&lt;br /&gt;
    &amp;lt;/definition&amp;gt;&lt;br /&gt;
  &amp;lt;/definitions&amp;gt;&lt;br /&gt;
&lt;br /&gt;
  &amp;lt;tests&amp;gt;&lt;br /&gt;
    &amp;lt;process58_test xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5#unix&amp;quot; id=&amp;quot;oval:org.owasp.oval:tst:1&amp;quot; version=&amp;quot;1&amp;quot; comment=&amp;quot;Apache2 running&amp;quot; check_existence=&amp;quot;at_least_one_exists&amp;quot; check=&amp;quot;at least one&amp;quot;&amp;gt;&lt;br /&gt;
      &amp;lt;object object_ref=&amp;quot;oval:org.owasp.oval:obj:1&amp;quot;/&amp;gt;&lt;br /&gt;
    &amp;lt;/process58_test&amp;gt;&lt;br /&gt;
  &amp;lt;/tests&amp;gt;&lt;br /&gt;
&lt;br /&gt;
  &amp;lt;objects&amp;gt;&lt;br /&gt;
    &amp;lt;process58_object xmlns=&amp;quot;http://oval.mitre.org/XMLSchema/oval-definitions-5#unix&amp;quot; id=&amp;quot;oval:org.owasp.oval:obj:1&amp;quot; version=&amp;quot;1&amp;quot;&amp;gt;&lt;br /&gt;
      &amp;lt;command_line operation=&amp;quot;pattern match&amp;quot;&amp;gt;.*apache2 .*&amp;lt;/command_line&amp;gt;&lt;br /&gt;
      &amp;lt;pid datatype=&amp;quot;int&amp;quot; operation=&amp;quot;greater than&amp;quot;&amp;gt;0&amp;lt;/pid&amp;gt;&lt;br /&gt;
    &amp;lt;/process58_object&amp;gt;&lt;br /&gt;
  &amp;lt;/objects&amp;gt;&lt;br /&gt;
&amp;lt;/oval_definitions&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP OVAL Content Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|OVAL Content Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Download]] [[Category:OWASP_Alpha_Quality_Tool]]&lt;/div&gt;</summary>
		<author><name>Gaurav Kumar</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=118501</id>
		<title>OWASP OVAL Content Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=118501"/>
				<updated>2011-10-04T00:00:39Z</updated>
		
		<summary type="html">&lt;p&gt;Gaurav Kumar: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
This project’s goal is to create standardized assesment documents (in OVAL XML format) for various application platforms such as .NET, Java, PHP etc. For example, there are several settings like Web.Config file which impacts security of ASP.NET web application. Likewise, PHP.INI has several security related settings. By creating OVAL definitions for these checks, it will enable any OVAL compatible tool (including the free OVAL Interpreter) to perform these checks. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
ASP.NET Web.Config &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP OVAL Content Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|OVAL Content Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Download]] [[Category:OWASP_Alpha_Quality_Tool]]&lt;/div&gt;</summary>
		<author><name>Gaurav Kumar</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=118497</id>
		<title>OWASP OVAL Content Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=118497"/>
				<updated>2011-10-03T23:55:42Z</updated>
		
		<summary type="html">&lt;p&gt;Gaurav Kumar: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
This project’s goal is to create standardized assesment documents (in OVAL XML format) for various application platforms such as .NET, Java, PHP etc. For example, there are several settings like Web.Config file which impacts security of ASP.NET web application. Likewise, PHP.INI has several security related settings. By creating OVAL definitions for these checks, it will enable any OVAL compatible tool (including the free OVAL Interpreter) to perform these checks. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ASP.NET Web.Config&lt;br /&gt;
&lt;br /&gt;
PHP.INI&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; &lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP OVAL Content Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|OVAL Content Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Download]] [[Category:OWASP_Alpha_Quality_Tool]]&lt;/div&gt;</summary>
		<author><name>Gaurav Kumar</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=116031</id>
		<title>OWASP OVAL Content Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=116031"/>
				<updated>2011-08-20T17:23:05Z</updated>
		
		<summary type="html">&lt;p&gt;Gaurav Kumar: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
This project’s goal is to create standardized assesment documents (in OVAL XML format) for various application platforms such as .NET, Java, PHP etc. For example, there are several settings like Web.Config file which impacts security of ASP.NET web application. Likewise, PHP.INI has several security related settings. By creating OVAL definitions for these checks, it will enable any OVAL compatible tool (including the free OVAL Interpreter) to perform these checks.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP OVAL Content Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|OVAL Content Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Download]] [[Category:OWASP_Alpha_Quality_Tool]]&lt;/div&gt;</summary>
		<author><name>Gaurav Kumar</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=115660</id>
		<title>OWASP OVAL Content Project</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_OVAL_Content_Project&amp;diff=115660"/>
				<updated>2011-08-14T16:45:14Z</updated>
		
		<summary type="html">&lt;p&gt;Gaurav Kumar: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==== Main  ====&lt;br /&gt;
&lt;br /&gt;
This proejct's goal is to create standardized assesment documents (in [http://oval.mitre.org OVAL XML format]) for various applicaiton platforms such as .NET, Java, PHP etc. For example, there are several settings like Web.Config file which impacts security of ASP.NET web application. Likewise, PHP.INI has several security related settings. By creating OVAL definitions for these checks, it will enable any OVAL compatible tool (inclduing the free [http://oval.mitre.org/language/interpreter.html OVAL Interpreter]) to peform these checks.&amp;amp;nbsp;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==== Project About  ====&lt;br /&gt;
&lt;br /&gt;
{{:Projects/OWASP OVAL Content Project | Project About}} &lt;br /&gt;
&lt;br /&gt;
&amp;lt;br&amp;gt; __NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP_Project|OVAL Content Project]] [[Category:OWASP_Tool]] [[Category:OWASP_Download]] [[Category:OWASP_Alpha_Quality_Tool]]&lt;/div&gt;</summary>
		<author><name>Gaurav Kumar</name></author>	</entry>

	</feed>