<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Greg+Foss</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Greg+Foss"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Greg_Foss"/>
		<updated>2026-05-16T23:39:42Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Greg_Foss&amp;diff=177449</id>
		<title>User:Greg Foss</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Greg_Foss&amp;diff=177449"/>
				<updated>2014-06-24T18:16:15Z</updated>
		
		<summary type="html">&lt;p&gt;Greg Foss: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;AppSecUSA 2014 CTF Developer and Volunteer.&lt;br /&gt;
&lt;br /&gt;
Lead developer of the [[Front_Range_OWASP_Conference_2013|SnowFROC 2013 CTF]] challenge.&lt;br /&gt;
&lt;br /&gt;
Greg is a father to two awesome kids, husband to an amazing wife. He's a native Coloradan who received his bachelor’s degree in Computer Information Systems from Colorado State University - Pueblo. While attending college, he owned and operated a small business where he designed, developed, and administered Web applications for local businesses. Greg is currently working as a Senior Security Research Engineer at the LogRhythm Labs threat intelligence team, where he focuses on developing defensive strategies, tools and methodologies to counteract advanced attack scenarios. He has over 7 years of experience in the Information Security industry with an extensive background in Security Operations, focusing on Penetration Testing and Web Application Security. He frequently presents at local security groups such as OWASP and is very active in the Denver security community. Before joining LogRhythm, Greg directed the Red Team at NREL and was tasked with leading the Application Security, Network Penetration Testing and Identity Access Management initiatives. In his free time, Greg enjoys snowboarding, mountain biking, hiking, and spending time with his family and friends.&lt;br /&gt;
&lt;br /&gt;
----------&lt;br /&gt;
Offensive Security Certified Professional (OSCP), Certified Ethical Hacker (C|EH),  GIAC Penetration Tester (GPEN),  GIAC Web Application Penetration Tester (GWAPT),  GIAC Certified Incident Handler (GCIH),  LogRhythm Certified Professional, NeXpose Certified Administrator, Security+,  Information Technology Infrastructure Library (ITIL) v3&lt;/div&gt;</summary>
		<author><name>Greg Foss</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Greg_Foss&amp;diff=148916</id>
		<title>User:Greg Foss</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Greg_Foss&amp;diff=148916"/>
				<updated>2013-03-30T16:05:09Z</updated>
		
		<summary type="html">&lt;p&gt;Greg Foss: blah&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Lead developer of the [[Front_Range_OWASP_Conference_2013|SnowFROC 2013 CTF]] challenge.&lt;br /&gt;
&lt;br /&gt;
Greg is a father to one awesome son, husband to an amazing wife :-) and has been heavily involved in Information Security and Web Application Development for the past 7+ years. He's a native Coloradan who received his bachelor’s degree in Computer Information Systems from Colorado State University. While attending college, he owned and operated a small business where he designed, developed, and administered Web applications for local businesses. Greg is currently working as a Senior Cyber Security Engineer at the National Renewable Energy Laboratory where he directs the Security Services team; tasked with leading the Application Security, Network Penetration Testing and Identity Access Management initiatives. In his free time, Greg enjoys snowboarding, mountain biking, hiking, and spending time with his family and friends.&lt;br /&gt;
&lt;br /&gt;
----------&lt;br /&gt;
Certified Ethical Hacker (C|EH),  GIAC Penetration Tester (GPEN),  GIAC Web Application Penetration Tester (GWAPT),  GIAC Certified Incident Handler (GCIH),  Security+,  Information Technology Infrastructure Library (ITIL) v3&lt;/div&gt;</summary>
		<author><name>Greg Foss</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Front_Range_OWASP_Conference_2013/CTF&amp;diff=148215</id>
		<title>Front Range OWASP Conference 2013/CTF</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Front_Range_OWASP_Conference_2013/CTF&amp;diff=148215"/>
				<updated>2013-03-20T15:00:18Z</updated>
		
		<summary type="html">&lt;p&gt;Greg Foss: adding proxy to tools and parallels to the list of VM tools&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Capture the Flag Overview==&lt;br /&gt;
Test your skills with a capture the flag (CTF) hacking competition created specifically for SnowFROC by members of the Boulder OWASP chapter.&lt;br /&gt;
&lt;br /&gt;
Competitors will be provided a series of web applications containing a variety of vulnerabilities. Each discovered vulnerability will earn points. The harder the hack, the more points earned. At the end of the day, the team with the most points wins.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Basic plot intro, other background information? --&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Rules==&lt;br /&gt;
All conference attendees may participate in the CTF tournament for no additional cost. If you would prefer to attend the general conference proceedings, the competition will be made available to attendees after SnowFROC ends.&lt;br /&gt;
&lt;br /&gt;
===Format===&lt;br /&gt;
Contestants will be provided a virtual machine which will run locally on self-provided devices. This is a BYOD event and all contestants are responsible for providing their own machine. No &amp;quot;loaners&amp;quot; will be made available.&lt;br /&gt;
&lt;br /&gt;
All contestant machines should have:&lt;br /&gt;
* A virtual machine player such as [http://www.vmware.com/products/player/ VMware Player], [https://www.virtualbox.org/wiki/Downloads VirtualBox], or [http://www.parallels.com/ Parallels].&lt;br /&gt;
* Appropriate penetration testing tool ([http://www.backtrack-linux.org BackTrack], [http://samurai.inguardians.com/ SamuraiWTF], [[OWASP_Mantra_OS|Mantra OS]], and [[ZAP|OWASP ZAP]] will fit in well).&lt;br /&gt;
&lt;br /&gt;
===Acceptable behavior===&lt;br /&gt;
Competitors are only permitted to attack targets running on their local systems. Network traffic will be monitored to ensure there will be:&lt;br /&gt;
* No attacking the scoreboard. Misuse will result in punitive action.&lt;br /&gt;
* No targeting the VM. Do not mount the VM and harvest flags from within.&lt;br /&gt;
* No attacking other teams, whether through coercion, DoS, theft, sabotage, or other malicious activity.&lt;br /&gt;
* No collusion. Work only within your own team.&lt;br /&gt;
&lt;br /&gt;
===Prizes===&lt;br /&gt;
Small prizes will be awarded to winners. People Anyone who worked on the project or who has access project-related repositories are ineligible to win prizes.&lt;br /&gt;
&lt;br /&gt;
Team prizes will be awarded to:&lt;br /&gt;
* The team with the most points;&lt;br /&gt;
* The team who completed the story first (or, as a tiebreaker, the team with the most plot-specific points);&lt;br /&gt;
* The team who took the shortest amount of time to complete Acts I-IV;&lt;br /&gt;
&lt;br /&gt;
Individual prizes will be awarded to:&lt;br /&gt;
* The person who solved the hardest challenge (worth the most points);&lt;br /&gt;
* The person who solved the most challenges (raw number);&lt;br /&gt;
* The person who scored the most points (total sum);&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Getting Started==&lt;br /&gt;
===Content acquisition===&lt;br /&gt;
&amp;lt;!-- Where to download the competitor VM as well as VM players, etc.. --&amp;gt;&lt;br /&gt;
This information will be released closer to the day of the event.&lt;br /&gt;
&lt;br /&gt;
===Installation instructions===&lt;br /&gt;
&amp;lt;!-- How to install the competitor VM, including VM players, etc.. --&amp;gt;&lt;br /&gt;
Coming soon.&lt;br /&gt;
&lt;br /&gt;
===Registration instructions===&lt;br /&gt;
&amp;lt;!-- Registration/scoreboard location; team sizes and naming conventions; etc. --&amp;gt;&lt;br /&gt;
Coming soon.&lt;br /&gt;
&lt;br /&gt;
===Gameplay instructions===&lt;br /&gt;
&amp;lt;!-- How to use the scoreboard; where to get help; etc. --&amp;gt;&lt;br /&gt;
Coming soon.&lt;/div&gt;</summary>
		<author><name>Greg Foss</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=Front_Range_OWASP_Conference_2013/Introduction&amp;diff=147896</id>
		<title>Front Range OWASP Conference 2013/Introduction</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=Front_Range_OWASP_Conference_2013/Introduction&amp;diff=147896"/>
				<updated>2013-03-15T06:08:20Z</updated>
		
		<summary type="html">&lt;p&gt;Greg Foss: :-P&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;====Welcome to SnowFROC 2013 - the 5th Annual Front Range OWASP Security Conference====&lt;br /&gt;
&lt;br /&gt;
[[Image:SnowFROC_Register.png|256px |link=http://www.cvent.com/d/dcqr8m |alt=Click here to register |Register]]&lt;br /&gt;
&lt;br /&gt;
The Colorado OWASP chapters are proud to present the 5th annual SnowFROC. Join 300 other developers, business owners, and security professionals for a day-and-a-half of presentations, training, and Birds-of-a-Feather (BoaF) sessions. The SnowFROC 2013 keynote speaker is Neal Ziring, Technical Director of InfoProtection at NSA.&lt;br /&gt;
&lt;br /&gt;
The conference will occur on Thursday, March 28th at the [[Front_Range_OWASP_Conference_2013#Venue | Denver Marriott City Center]] and will feature four primary tracks:&lt;br /&gt;
*High-Level Technical&lt;br /&gt;
*Deep-Dive / Hands-on Technical&lt;br /&gt;
*Management&lt;br /&gt;
*Legal&lt;br /&gt;
&lt;br /&gt;
Running in parallel to the conference proceedings will be a capture the flag (CTF) hacking competition developed exclusively for SnowFROC by Boulder OWASP chapter members. The day will conclude with a moderated panel discussion featuring top industry leaders.&lt;br /&gt;
&lt;br /&gt;
On Friday, March 28, [[Jim_Manico|Jim Manico]] will teach a course in secure coding. '''This training is free to SnowFROC attendees!'''&lt;br /&gt;
&lt;br /&gt;
Friday will also offer BoaF sessions. Join like-minded industry leaders and discuss pressing issues facing the industry and you. BoaF sessions are self-lead and may address and issue you would like. Pitch your idea and get the ball rolling!&lt;br /&gt;
&lt;br /&gt;
Finally, Friday will feature a postmortem of the CTF tournament. In addition to discussing solutions, techniques, and tools, we will encourage participants to attack the previously out-of-bounds CTF framework. Itching to break into the scoreboard and rack up the points? The gloves come off Friday morning.&lt;br /&gt;
&lt;br /&gt;
==Conference Committee==&lt;br /&gt;
[[User:Mark_Major|Mark Major]]: Director&lt;br /&gt;
&lt;br /&gt;
[[User:Brad_Carvalho|Brad Carvalho]]: Sponsorship, Executive events&lt;br /&gt;
&amp;lt;br /&amp;gt;[[User:Craig_Klosterman|Craig Klosterman]]: Merchandise&lt;br /&gt;
&amp;lt;br /&amp;gt;[[User:Steve_Kosten|Steve Kosten]]: Sponsorship, Executive events&lt;br /&gt;
&amp;lt;br /&amp;gt;[[User:Glen Matthes|Glen Matthes]]: Planning&lt;br /&gt;
&amp;lt;br /&amp;gt;[[User:Chris_Rossi|Chris Rossi]]: CTF, Networking events&lt;br /&gt;
&amp;lt;br /&amp;gt;[[User:Greg_Foss|Greg Foss]]: CTF&lt;br /&gt;
&lt;br /&gt;
==Colorado Chapter Hosts==&lt;br /&gt;
[[Boulder|OWASP Boulder chapter]]: [[User:Mark_Major|Mark Major]]&lt;br /&gt;
&amp;lt;br /&amp;gt;[[Denver|OWASP Denver chapter]]: [[User:Steve_Kosten|Steve Kosten]], [[User:Brad_Carvalho|Brad Carvalho]] (acting)&lt;/div&gt;</summary>
		<author><name>Greg Foss</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Greg_Foss&amp;diff=147895</id>
		<title>User:Greg Foss</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Greg_Foss&amp;diff=147895"/>
				<updated>2013-03-15T06:06:32Z</updated>
		
		<summary type="html">&lt;p&gt;Greg Foss: blah&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Building and breaking things... Lead developer of the [[Front_Range_OWASP_Conference_2013|SnowFROC 2013 CTF]] challenge.&lt;br /&gt;
&lt;br /&gt;
Greg is a father to one awesome son, husband to an amazing wife :-) and has been heavily involved in Information Security and Web Application Development for the past 7+ years. He's a native Coloradan who received his bachelor’s degree in Computer Information Systems from Colorado State University. While attending college, he owned and operated a small business where he designed, developed, and administered Web applications for local businesses. Greg is currently working as a Senior Cyber Security Engineer at the National Renewable Energy Laboratory where he directs the Security Services team; tasked with leading the Application Security, Network Penetration Testing and Identity Access Management initiatives. In his free time, Greg enjoys snowboarding, mountain biking, hiking, and spending time with his family and friends.&lt;br /&gt;
&lt;br /&gt;
----------&lt;br /&gt;
Certified Ethical Hacker (C|EH),  GIAC Penetration Tester (GPEN),  GIAC Web Application Penetration Tester (GWAPT),  GIAC Certified Incident Handler (GCIH),  Security+,  Information Technology Infrastructure Library (ITIL) v3&lt;/div&gt;</summary>
		<author><name>Greg Foss</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Greg_Foss&amp;diff=146756</id>
		<title>User:Greg Foss</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Greg_Foss&amp;diff=146756"/>
				<updated>2013-03-06T05:59:23Z</updated>
		
		<summary type="html">&lt;p&gt;Greg Foss: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hacker by day, coder by night...&lt;br /&gt;
&lt;br /&gt;
Greg is a father to one awesome son, husband to an amazing wife :-) and has been heavily involved in Information Security and Web Application Development for the past 7+ years. He's a native Coloradan who received his bachelor’s degree in Computer Information Systems from Colorado State University. While attending college, he owned and operated a small business where he designed, developed, and administered Web applications for local businesses. Greg is currently working as a Senior Cyber Security Engineer at the National Renewable Energy Laboratory where he directs the Security Services team; tasked with leading the Application Security, Network Penetration Testing and Identity Access Management initiatives. In his free time, Greg enjoys snowboarding, mountain biking, hiking, and spending time with his family and friends.&lt;br /&gt;
&lt;br /&gt;
----------&lt;br /&gt;
Certified Ethical Hacker (C|EH),  GIAC Penetration Tester (GPEN),  GIAC Web Application Penetration Tester (GWAPT),  GIAC Certified Incident Handler (GCIH),  Security+,  Information Technology Infrastructure Library (ITIL) v3&lt;/div&gt;</summary>
		<author><name>Greg Foss</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Greg_Foss&amp;diff=146755</id>
		<title>User:Greg Foss</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Greg_Foss&amp;diff=146755"/>
				<updated>2013-03-06T05:58:40Z</updated>
		
		<summary type="html">&lt;p&gt;Greg Foss: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hacker by day, coder by night...&lt;br /&gt;
&lt;br /&gt;
Greg is a father to one awesome son, husband to an amazing wife :-) and has been heavily involved in Information Security and Web Application Development for the past 7+ years. He's a native Coloradan who received his bachelor’s degree in Computer Information Systems from Colorado State University. While attending college, he owned and operated a small business where he designed, developed, and administered Web applications for local businesses. Greg is currently working as a Senior Cyber Security Engineer at the National Renewable Energy Laboratory where he directs the Security Services team; tasked with leading the Application Security, Network Penetration Testing and Identity Access Management initiatives. In his free time, Greg enjoys snowboarding, mountain biking, hiking, and spending time with his family and friends.&lt;br /&gt;
&lt;br /&gt;
Certifications:     Certified Ethical Hacker (C|EH),  GIAC Penetration Tester (GPEN),  GIAC Web Application Penetration Tester (GWAPT),  GIAC Certified Incident Handler (GCIH),  Security+,  Information Technology Infrastructure Library (ITIL) v3&lt;/div&gt;</summary>
		<author><name>Greg Foss</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=User:Greg_Foss&amp;diff=146754</id>
		<title>User:Greg Foss</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=User:Greg_Foss&amp;diff=146754"/>
				<updated>2013-03-06T05:57:58Z</updated>
		
		<summary type="html">&lt;p&gt;Greg Foss: Certified information security professional with over 7 years of experience specializing in web development and network security&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Hacker by day, coder by night...&lt;br /&gt;
&lt;br /&gt;
Greg is a father to one awesome son, husband to an amazing wife :-) and has been heavily involved in Information Security and Web Application Development for the past 7+ years. He's a native Coloradan who received his bachelor’s degree in Computer Information Systems from Colorado State University. While attending college, he owned and operated a small business where he designed, developed, and administered Web applications for local businesses. Greg is currently working as a Senior Cyber Security Engineer at the National Renewable Energy Laboratory where he directs the Security Services team; tasked with leading the Application Security, Network Penetration Testing and Identity Access Management initiatives. In his free time, Greg enjoys snowboarding, mountain biking, hiking, and spending time with his family and friends.&lt;br /&gt;
&lt;br /&gt;
Certifications:&lt;br /&gt;
-Certified Ethical Hacker (C|EH)&lt;br /&gt;
-GIAC Penetration Tester (GPEN)&lt;br /&gt;
-GIAC Web Application Penetration Tester (GWAPT)&lt;br /&gt;
-GIAC Certified Incident Handler (GCIH)&lt;br /&gt;
-Security+&lt;br /&gt;
-Information Technology Infrastructure Library (ITIL) v3&lt;/div&gt;</summary>
		<author><name>Greg Foss</name></author>	</entry>

	</feed>